Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2014-1881EPSS 11% Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev… Cordova after 3.3.0 Fix from $1,9502014-03-03 HIGH 7.5 CVE-2014-1882EPSS 12% Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev… Cordova after 3.3.0 Fix from $1,9502014-03-03 HIGH 7.5 CVE-2014-1884EPSS 8% Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allo… Cordova after 3.3.0 Fix from $1,9502014-03-03 MEDIUM 5.8 CVE-2013-4286EPSS 17% Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle c… Tomcat Mitigation only Fix from $1,6002014-02-26 MEDIUM 5.0 CVE-2013-2055 Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive… Wicket Mitigation only Fix from $1,6002014-02-10 HIGH 7.5 CVE-2013-2185EPSS 7% The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Re… Tomcat after 7.0.39 Fix from $1,9502014-01-19 HIGH 7.5 CVE-2012-6612EPSS 10% The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via… Solr after 4.0.0 Fix from $1,9502013-12-07 MEDIUM 6.8 CVE-2013-4212EPSS 81% Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions vi… Roller after 5.0.1 Fix from $1,6002013-12-07 MEDIUM 6.4 CVE-2013-6407EPSS 11% The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external … Solr after 4.0.0 Fix from $1,6002013-12-07 MEDIUM 6.4 CVE-2013-6408EPSS 11% The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have a… Solr after 4.3.0 Fix from $1,6002013-12-07 MEDIUM 6.8 CVE-2013-6357 Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the … Tomcat after 5.5.25 Fix from $1,6002013-11-13 MEDIUM 5.8 CVE-2013-4390 Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Slin… Sling after 1.1.2 Fix from $1,6002013-10-24 MEDIUM 5.0 CVE-2013-4295EPSS 12% The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an externa… Shindig Patch available Fix from $1,6002013-10-24 HIGH 7.5 CVE-2013-4365EPSS 13% Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server… Mod Fcgid 2.3.9+ Fix from $1,9502013-10-17 MEDIUM 5.0 CVE-2013-2254 The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache S… Org.apache.sling.servlets.post Patch available Fix from $1,6002013-10-17 MEDIUM 6.8 CVE-2013-4330EPSS 9% Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expres… Camel after 2.9.6 Fix from $1,6002013-10-04 HIGH 10.0 CVE-2013-4316EPSS 8% Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors. Struts after 3.0.4 Fix from $1,9502013-09-30 MEDIUM 5.8 CVE-2013-4310EPSS 8% Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix. Struts Patch available Fix from $1,6002013-09-30 HIGH 7.5 CVE-2013-2210EPSS 6% Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 al… Xml Security For C\+\+ after 1.7.1 Fix from $1,9502013-08-20 HIGH 7.5 CVE-2013-2154EPSS 8% Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka … Xml Security For C\+\+ after 1.7.0 Fix from $1,9502013-08-20 HIGH 7.5 CVE-2013-2156EPSS 8% Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++… Xml Security For C\+\+ after 1.7.0 Fix from $1,9502013-08-20 MEDIUM 5.8 CVE-2013-2155EPSS 6% Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to ca… Xml Security For C\+\+ after 1.7.0 Fix from $1,6002013-08-20 MEDIUM 6.4 CVE-2012-5575EPSS 6% Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowe… Cxf Mitigation only Fix from $1,6002013-08-19 MEDIUM 5.0 CVE-2013-2160EPSS 32% The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of s… Cxf Patch available Fix from $1,6002013-08-19 HIGH 10.0 CVE-2013-2250EPSS 12% Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar… Ofbiz Patch available Fix from $1,9502013-08-15 MEDIUM 6.8 CVE-2013-4156 Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other im… Openoffice 4.0.0+ Fix from $1,6002013-07-31 MEDIUM 6.8 CVE-2013-2189 Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other im… Openoffice 4.0.0+ Fix from $1,6002013-07-31 HIGH 7.8 CVE-2013-2112 The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a con… Subversion after 1.6.21 Fix from $1,9502013-07-31 HIGH 7.1 CVE-2013-2088EPSS 31% contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary … Subversion after 1.6.21 Fix from $1,9502013-07-31 MEDIUM 5.5 CVE-2013-1968 Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a ne… Subversion after 1.6.21 Fix from $1,6002013-07-31