Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2012-2733EPSS 9%
java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not…
Tomcat
Mitigation only
MEDIUM 5.9
CVE-2012-3446
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the su…
Libcloud
0.11.0+
MEDIUM 5.8
CVE-2012-5783EPSS 9%
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the serve…
Httpclient
Patch available
MEDIUM 5.8
CVE-2012-5784EPSS 6%
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service impleme…
Activemq
after 5.7.0
MEDIUM 5.8
CVE-2012-5785
Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…
Axis2
after 1.6.2
MEDIUM 5.8
CVE-2012-5786
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that …
Cxf
after 2.6.17
HIGH 10.0
CVE-2012-4501EPSS 8%
Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc…
Cloudstack
Mitigation only
HIGH 10.0
CVE-2012-3506EPSS 7%
Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
Ofbiz
Patch available
MEDIUM 6.4
CVE-2012-5351EPSS 5%
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur…
Axis2
Mitigation only
MEDIUM 5.8
CVE-2012-4418EPSS 6%
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
Axis2
No fix yet
MEDIUM 5.0
CVE-2012-2145
Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file…
Qpid
after 0.17
MEDIUM 6.8
CVE-2012-4386
The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote…
Struts
Mitigation only
MEDIUM 5.0
CVE-2012-4387EPSS 8%
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processe…
Struts
Patch available
MEDIUM 5.0
CVE-2012-3467EPSS 6%
Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remo…
Qpid
after 0.16
MEDIUM 5.0
CVE-2012-0213EPSS 8%
The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial…
Poi
after 3.8
HIGH 7.5
CVE-2012-2665EPSS 7%
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow re…
Openoffice
3.4.1+
HIGH 7.5
CVE-2012-3376
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same B…
Hadoop
Mitigation only
MEDIUM 5.0
CVE-2012-2138EPSS 14%
The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to co…
Org.apache.sling.servlets.post
after 2.1.0
MEDIUM 5.0
CVE-2012-2098EPSS 13%
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress b…
Commons Compress
1.4.1+
MEDIUM 6.8
CVE-2012-2380
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack…
Roller
after 5.0
MEDIUM 6.8
CVE-2012-2334EPSS 13%
Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, al…
Openoffice.org
after 3.5.2
MEDIUM 6.5
CVE-2012-0037EPSS 14%
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other produ…
Openoffice
Patch available
HIGH 7.5
CVE-2011-3620EPSS 5%
Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin…
Qpid
Mitigation only
MEDIUM 6.9
CVE-2012-0883
envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users…
HTTP Server
2.2.23+
MEDIUM 6.5
CVE-2012-1574
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used i…
Hadoop
Mitigation only
MEDIUM 5.0
CVE-2012-0256
Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to ca…
Traffic Server
Patch available
MEDIUM 5.0
CVE-2012-1089EPSS 5%
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-applicati…
Wicket
Mitigation only
MEDIUM 5.0
CVE-2012-1181
fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual h…
Mod Fcgid
Patch available
HIGH 10.0
CVE-2012-0838EPSS 14%
Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to m…
Struts
after 2.2.3
MEDIUM 5.0
CVE-2012-0840EPSS 43%
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash col…
Portable Runtime
after 1.4.5