Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2012-2733EPSS 9% java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not… Tomcat Mitigation only Fix from $1,6002012-11-16 MEDIUM 5.9 CVE-2012-3446 Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the su… Libcloud 0.11.0+ Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5783EPSS 9% Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the serve… Httpclient Patch available Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5784EPSS 6% Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service impleme… Activemq after 5.7.0 Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5785 Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam… Axis2 after 1.6.2 Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5786 The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that … Cxf after 2.6.17 Fix from $1,6002012-11-04 HIGH 10.0 CVE-2012-4501EPSS 8% Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc… Cloudstack Mitigation only Fix from $1,9502012-10-26 HIGH 10.0 CVE-2012-3506EPSS 7% Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors. Ofbiz Patch available Fix from $1,9502012-10-25 MEDIUM 6.4 CVE-2012-5351EPSS 5% Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur… Axis2 Mitigation only Fix from $1,6002012-10-09 MEDIUM 5.8 CVE-2012-4418EPSS 6% Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." Axis2 No fix yet Fix from $1,6002012-10-09 MEDIUM 5.0 CVE-2012-2145 Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file… Qpid after 0.17 Fix from $1,6002012-09-28 MEDIUM 6.8 CVE-2012-4386 The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote… Struts Mitigation only Fix from $1,6002012-09-05 MEDIUM 5.0 CVE-2012-4387EPSS 8% Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processe… Struts Patch available Fix from $1,6002012-09-05 MEDIUM 5.0 CVE-2012-3467EPSS 6% Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remo… Qpid after 0.16 Fix from $1,6002012-08-27 MEDIUM 5.0 CVE-2012-0213EPSS 8% The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial… Poi after 3.8 Fix from $1,6002012-08-07 HIGH 7.5 CVE-2012-2665EPSS 7% Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow re… Openoffice 3.4.1+ Fix from $1,9502012-08-06 HIGH 7.5 CVE-2012-3376 DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same B… Hadoop Mitigation only Fix from $1,9502012-07-12 MEDIUM 5.0 CVE-2012-2138EPSS 14% The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to co… Org.apache.sling.servlets.post after 2.1.0 Fix from $1,6002012-07-09 MEDIUM 5.0 CVE-2012-2098EPSS 13% Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress b… Commons Compress 1.4.1+ Fix from $1,6002012-06-29 MEDIUM 6.8 CVE-2012-2380 Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack… Roller after 5.0 Fix from $1,6002012-06-26 MEDIUM 6.8 CVE-2012-2334EPSS 13% Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, al… Openoffice.org after 3.5.2 Fix from $1,6002012-06-19 MEDIUM 6.5 CVE-2012-0037EPSS 14% Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other produ… Openoffice Patch available Fix from $1,6002012-06-17 HIGH 7.5 CVE-2011-3620EPSS 5% Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin… Qpid Mitigation only Fix from $1,9502012-05-03 MEDIUM 6.9 CVE-2012-0883 envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users… HTTP Server 2.2.23+ Fix from $1,6002012-04-18 MEDIUM 6.5 CVE-2012-1574 The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used i… Hadoop Mitigation only Fix from $1,6002012-04-12 MEDIUM 5.0 CVE-2012-0256 Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to ca… Traffic Server Patch available Fix from $1,6002012-03-26 MEDIUM 5.0 CVE-2012-1089EPSS 5% Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-applicati… Wicket Mitigation only Fix from $1,6002012-03-23 MEDIUM 5.0 CVE-2012-1181 fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual h… Mod Fcgid Patch available Fix from $1,6002012-03-19 HIGH 10.0 CVE-2012-0838EPSS 14% Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to m… Struts after 2.2.3 Fix from $1,9502012-03-02 MEDIUM 5.0 CVE-2012-0840EPSS 43% tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash col… Portable Runtime after 1.4.5 Fix from $1,6002012-02-10