Search

Found 390 results in 90ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-15701 high 7.5 7.5 apache 9y ago Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption
CVE-2017-12631 high 8.8 8.8 apache 9y ago Moderate severity vulnerability that affects org.apache.cxf.fediz:fediz-spring, org.apache.cxf.fediz:fediz-spring2, and org.apache.cxf.fediz:fediz-spring3
CVE-2017-12608 high 7.8 7.8 FIX debian debian apache 9y ago A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory…
CVE-2017-12607 high 7.8 7.8 FIX debian debian apache 9y ago A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and appl…
CVE-2017-9806 high 7.8 7.8 FIX debian debian apache 9y ago A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory…
CVE-2016-6804 high 7.8 7.8 apache 9y ago The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated pr…
CVE-2017-12634 critical 9.8 9.8 apache 9y ago Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
CVE-2017-12633 critical 9.8 9.8 apache 9y ago Apache Camel camel-hessian component vulnerable to Java object deserialization
CVE-2017-12636 high 7.2 8.2 EXPFIX arch arch sles apache 9y ago multiple issues in couchdb
CVE-2017-12635 critical 9.8 10.0 EXPFIX slesarch arch apache 9y ago multiple issues in couchdb
CVE-2017-3166 high 7.8 7.8 apache 9y ago Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main
CVE-2016-6803 high 7.8 7.8 apache 9y ago An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The PC must have previously been infected by a Trojan …
CVE-2014-0073 critical 9.8 9.8 apache 9y ago The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 throug…
CVE-2014-0072 high 7.5 7.5 apache 9y ago ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9…
CVE-2013-4366 critical 9.8 9.8 FIX debian debian apache 9y ago Hostname verification in Apache HttpClient 4.3 was disabled by default
CVE-2012-4449 critical 9.8 9.8 apache 9y ago Use of a Broken or Risky Cryptographic Algorithm in Apache Hadoop
CVE-2014-0115 high 7.5 7.5 apache 9y ago Apache Storm log viewer path traversal vulnerability
CVE-2012-0881 high 7.5 7.5 debian debian apache 9y ago Denial of service in Apache Xerces2
CVE-2016-3090 high 8.8 8.8 apache 9y ago Apache Struts RCE Vulnerability
CVE-2015-3249 critical 9.8 9.8 FIX debian debian apache 9y ago The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary …
CVE-2015-0226 high 7.5 7.5 FIX debian debian apache 9y ago Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
CVE-2015-0224 high 7.5 7.5 apache 9y ago qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted protocol sequence set. NOTE: this vulnerability exists because of an incomplet…
CVE-2014-3624 critical 9.8 9.8 FIX debian debian apache 9y ago Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
CVE-2014-3526 high 7.5 7.5 apache 9y ago Apache Wicket Sensitive Data Exposure
CVE-2013-4246 high 8.8 8.8 FIX debian debian apache 9y ago libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive i…
CVE-2014-3600 critical 9.8 9.8 FIX debian debian apache 9y ago Improper Restriction of XML External Entity Reference in Apache ActiveMQ
CVE-2014-3579 critical 9.8 9.8 apache 9y ago Apache ActiveMQ Apollo XXE Vulnerability
CVE-2016-5003 critical 9.8 9.8 apache 9y ago Apache XML-RPC vulnerable to Deserialization of Untrusted Data
CVE-2016-5002 high 7.8 7.8 apache 9y ago Apache XML-RPC XXE Vulnerability
CVE-2012-1622 critical 9.8 9.8 apache 9y ago Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2017-12613 high 7.1 7.1 FIX debian debian slesarch arch apacheredhat 9y ago When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting t…
CVE-2010-2232 high 7.5 7.5 FIX debian debian apache 9y ago Improper Access Control in Apache Derby
CVE-2017-12628 high 7.8 7.8 apache 9y ago Apache James Privilege Escalation
CVE-2017-5636 critical 9.8 9.8 apache 9y ago Injection in Apache NiFi
CVE-2017-5635 high 7.5 7.5 apache 9y ago Improper Authentication In Apache NiFi
CVE-2016-4461 high 8.8 8.8 apachenetapp 9y ago Apache Struts forced double OGNL evaluation
CVE-2017-12629 critical 9.8 10.0 EXPFIX debian debianubuntu ubuntu rhel apacheredhat 9y ago Remote code execution occurs in Apache Solr
CVE-2016-8736 critical 9.8 9.8 apache 9y ago Apache OpenMeetings RCE
CVE-2017-5637 high 7.5 8.5 EXPFIX debian debian apache 9y ago Uncontrolled Resource Consumption in Apache ZooKeeper
CVE-2014-0030 critical 9.8 10.0 EXP apache 9y ago The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
CVE-2017-12620 critical 9.8 9.8 apache 9y ago Improper Restriction of XML External Entity Reference in Apache OpenNLP
CVE-2016-6806 high 8.8 8.8 apache 9y ago Apache Wicket vulnerable to CSRF attacks
CVE-2016-4434 high 7.8 7.8 FIX debian debian apache 9y ago Apache Tika does not properly initialize the XML parser or choose handlers
CVE-2017-9790 high 7.5 7.5 apache 9y ago Use after free in Apache Mesos
CVE-2017-7687 high 7.5 7.5 apache 9y ago Denial of service in Apache Mesos
CVE-2017-12621 critical 9.8 9.8 apache 9y ago Improper Restriction of XML External Entity Reference in Jelly
CVE-2017-9804 high 7.5 7.5 apache 9y ago Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
CVE-2017-9793 high 7.5 7.5 apache 9y ago The REST Plugin in Apache Struts is using an outdated XStream library
CVE-2017-12611 critical 9.8 10.0 EXP apache 9y ago Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal
CVE-2016-6795 critical 9.8 9.8 apache 9y ago Path Traversal in Apache Struts
CVE-2017-12616 high 7.5 7.5 sles apache 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2017-9803 high 7.5 7.5 FIX debian debian apache 9y ago Apache Solr Kerberos delegation token functionality flaws
CVE-2017-9798 high 7.5 8.5 EXPFIX debian debianarch arch sles apache 9y ago Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsb…
CVE-2014-7808 high 7.5 7.5 apache 9y ago Apache Wicket insecure defaults
CVE-2017-12612 high 7.8 7.8 apache 9y ago Apache Spark Deserialization of Untrusted Data vulnerability
CVE-2016-8744 high 8.8 8.8 apache 9y ago Deserialization of Untrusted Data in Apache Brooklyn
CVE-2016-8737 high 8.8 8.8 apache 9y ago Apache Brooklyn is vulnerable to cross-site request forgery (CSRF)
CVE-2015-5206 critical 9.8 9.8 FIX debian debian apache 9y ago Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.
CVE-2015-5168 critical 9.8 9.8 FIX debian debian apache 9y ago Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.
CVE-2015-3250 high 7.5 7.5 FIX debian debian apache 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Directory LDAP API
CVE-2016-3086 critical 9.8 9.8 apache 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2016-4462 high 8.8 8.8 apache 9y ago By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Fr…
CVE-2017-3163 high 7.5 7.5 FIX debian debian apache 9y ago Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
CVE-2017-3154 high 7.5 7.5 apache 9y ago Apache Atlas produces Stack trace in error response
CVE-2016-8752 high 7.5 7.5 apache 9y ago Path Traversal in Apache Atlas
CVE-2015-5209 high 7.5 7.5 apache 9y ago Special top object can be used to access Struts' internals
CVE-2016-4460 critical 9.8 9.8 apache 9y ago Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
CVE-2017-9800 critical 9.8 9.8 FIX arch arch slesdebian debian apache 9y ago A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be ge…
CVE-2017-7675 high 7.5 7.5 FIX slesdebian debian apache 9y ago The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypa…
CVE-2016-6796 high 7.5 7.5 slesdebian debian rhel apachenetapporacle 9y ago Apache Tomcat vulnerable to SecurityManager bypass
CVE-2016-8745 high 7.5 7.5 FIX slesdebian debian apache 9y ago A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0.39, 7.0.0 to 7.0.73 and 6.0.16 to 6.0.48 resulted…
CVE-2016-6817 high 7.5 7.5 FIX debian debian apache 9y ago The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of s…
CVE-2016-6797 high 7.5 7.5 slesdebian debian rhel apacheoraclenetapp 9y ago Incorrect Authorization in Apache Tomcat
CVE-2017-3156 high 7.5 7.5 apache 9y ago Covert Timing Channel in Apache CXF
CVE-2016-8739 high 7.5 7.5 apache 9y ago Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
CVE-2016-5018 critical 9.1 9.1 slesdebian debian rhel apachenetappredhat 9y ago Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
CVE-2017-9799 high 8.8 8.8 sles apache 9y ago Apache Storm it is possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user
CVE-2012-0880 high 7.5 7.5 slesdebian debian apache 9y ago Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions.
CVE-2012-0803 critical 9.8 9.8 apache 9y ago Improper Authentication in Apache CXF
CVE-2011-4343 high 7.5 7.5 apache 9y ago Apache MyFaces Vulnerable to EL Injection
CVE-2010-2245 high 7.4 7.4 apache 9y ago XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
CVE-2017-9801 high 7.5 7.5 FIX debian debian apache 9y ago Improper Input Validation in Apache Commons Email
CVE-2016-8743 high 7.5 7.5 FIX debian debian sles rhel apachenetappredhat 9y ago Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors repres…
CVE-2016-2161 high 7.5 7.5 FIX debian debian sles apache 9y ago In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
CVE-2016-0736 high 7.5 8.5 EXPFIX slesdebian debian apache 9y ago In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by defaul…
CVE-2017-7659 high 7.5 7.5 FIX debian debianarch arch sles apache 9y ago A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process.
CVE-2016-6798 critical 9.8 9.8 apache 9y ago XML External Entity Reference in Apache Sling
CVE-2017-7688 high 7.5 7.5 apache 9y ago Apache OpenMeetings updates user password in insecure manner
CVE-2017-7684 high 7.5 7.5 apache 9y ago Apache OpenMeetings vulnerable to Uncontrolled Resource Consumption
CVE-2017-7683 high 7.5 7.5 apache 9y ago Apache OpenMeetings displays Tomcat version and detailed error stack trace
CVE-2017-7682 high 8.2 8.2 apache 9y ago Apache OpenMeetings vulnerable to parameter manipulation attacks
CVE-2017-7681 high 8.8 8.8 apache 9y ago Apache OpenMeetings vulnerable to SQL injection
CVE-2017-7680 high 7.5 7.5 apache 9y ago Apache OpenMeetings allows flash content to be loaded from untrusted domains
CVE-2017-7673 critical 9.8 9.8 apache 9y ago Apache OpenMeetings has Inadequate Encryption Strength
CVE-2017-7666 high 8.8 8.8 apache 9y ago Apache OpenMeetings vulnerable to Cross-Site Request Forgery
CVE-2017-7664 critical 10.0 10.0 apache 9y ago Apache OpenMeetings does not correctly validate uploaded XML documents
CVE-2016-6793 critical 9.1 9.1 apache 9y ago The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the pe…
CVE-2015-0249 high 7.2 7.2 apache 9y ago The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka…
CVE-2017-9789 high 7.5 7.5 FIX debian debianarch arch sles apache 9y ago When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
CVE-2017-9788 critical 9.1 9.1 FIX debian debianarch arch sles apachenetappredhat 9y ago In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assi…