Search

Found 573 results in 97ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-3157 medium 5.5 5.5 FIX slesdebian debian rhel apache 9y ago By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrie…
CVE-2014-0219 medium 5.5 5.5 apache 9y ago Improper Input Validation in Apache Karaf
CVE-2017-12634 critical 9.8 9.8 apache 9y ago Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
CVE-2017-12633 critical 9.8 9.8 apache 9y ago Apache Camel camel-hessian component vulnerable to Java object deserialization
CVE-2017-12635 critical 9.8 10.0 EXPFIX slesarch arch apache 9y ago multiple issues in couchdb
CVE-2017-12624 medium 5.5 5.5 apache 9y ago Improper Input Validation in Apache CXF
CVE-2017-12625 medium 4.3 4.3 apache 9y ago Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
CVE-2014-0073 critical 9.8 9.8 apache 9y ago The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 throug…
CVE-2013-4366 critical 9.8 9.8 FIX debian debian apache 9y ago Hostname verification in Apache HttpClient 4.3 was disabled by default
CVE-2012-5636 medium 6.1 6.1 apache 9y ago Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vector…
CVE-2012-4449 critical 9.8 9.8 apache 9y ago Use of a Broken or Risky Cryptographic Algorithm in Apache Hadoop
CVE-2009-1198 medium 6.1 6.1 apache 9y ago Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname parameter to happyjuddi.jsp.
CVE-2009-1197 medium 5.3 5.3 apache 9y ago Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.
CVE-2015-3249 critical 9.8 9.8 FIX debian debian apache 9y ago The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary …
CVE-2014-3624 critical 9.8 9.8 FIX debian debian apache 9y ago Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
CVE-2015-1835 medium 5.3 5.3 apache 9y ago Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables…
CVE-2014-3600 critical 9.8 9.8 FIX debian debian apache 9y ago Improper Restriction of XML External Entity Reference in Apache ActiveMQ
CVE-2014-3579 critical 9.8 9.8 apache 9y ago Apache ActiveMQ Apollo XXE Vulnerability
CVE-2016-5003 critical 9.8 9.8 apache 9y ago Apache XML-RPC vulnerable to Deserialization of Untrusted Data
CVE-2012-1622 critical 9.8 9.8 apache 9y ago Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2017-12618 medium 4.7 4.7 FIX debian debian slesarch arch apache 9y ago Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A loc…
CVE-2010-5312 medium 6.1 6.1 FIX debian debianfedora fedora jqueryuinetappapache 9y ago Cross-site Scripting in jquery-ui
CVE-2017-5636 critical 9.8 9.8 apache 9y ago Injection in Apache NiFi
CVE-2016-8748 medium 5.4 5.4 apache 9y ago Cross-site Scripting in Apache NiFi
CVE-2016-8734 medium 6.5 6.5 FIX slesdebian debian apache 9y ago Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The a…
CVE-2017-12629 critical 9.8 10.0 EXPFIX debian debianubuntu ubuntu rhel apacheredhat 9y ago Remote code execution occurs in Apache Solr
CVE-2016-6815 medium 6.5 6.5 apache 9y ago Moderate severity vulnerability that affects org.apache.ranger:ranger
CVE-2016-8736 critical 9.8 9.8 apache 9y ago Apache OpenMeetings RCE
CVE-2017-12623 medium 6.5 6.5 apache 9y ago XML External Entity Reference in Apache NiFi
CVE-2014-0030 critical 9.8 10.0 EXP apache 9y ago The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
CVE-2017-9792 medium 6.5 6.5 apache 9y ago In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" a…
CVE-2017-9797 medium 6.5 6.5 apache 9y ago Apache Geode vulnerable to Exposure of Sensitive Information
CVE-2017-12620 critical 9.8 9.8 apache 9y ago Improper Restriction of XML External Entity Reference in Apache OpenNLP
CVE-2014-0043 medium 5.3 5.3 apache 9y ago Apache Wicket allows attackers to check for third-party libraries
CVE-2017-9794 medium 4.3 4.3 apache 9y ago Apache Geode gfsh query vulnerability
CVE-2017-12621 critical 9.8 9.8 apache 9y ago Improper Restriction of XML External Entity Reference in Jelly
CVE-2015-5169 medium 6.1 6.1 apache 9y ago Cross-site Scripting in Apache Struts
CVE-2017-12611 critical 9.8 10.0 EXP apache 9y ago Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal
CVE-2016-8738 medium 5.9 5.9 apache 9y ago Apache Struts vulnerable to possible DoS attack when using URLValidator
CVE-2016-6795 critical 9.8 9.8 apache 9y ago Path Traversal in Apache Struts
CVE-2017-3165 medium 5.4 5.4 apache 9y ago Cross-site Scripting In Apache Brooklyn
CVE-2015-5206 critical 9.8 9.8 FIX debian debian apache 9y ago Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.
CVE-2015-5168 critical 9.8 9.8 FIX debian debian apache 9y ago Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.
CVE-2014-9635 medium 5.3 5.3 jenkinsapache 9y ago Jenkins HttpOnly flag not Set for session cookies
CVE-2014-9634 medium 5.3 5.3 jenkinsapache 9y ago Jenkins secure flag not set on session cookies
CVE-2016-3086 critical 9.8 9.8 apache 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2016-5001 medium 5.5 5.5 apache 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2016-6800 medium 6.1 6.1 apache 9y ago The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creatio…
CVE-2017-3155 medium 6.1 6.1 apache 9y ago Cross-site Scripting in Apache Atlas
CVE-2017-3153 medium 6.1 6.1 apache 9y ago Cross-site Scripting in Apache Atlas
CVE-2017-3152 medium 6.1 6.1 apache 9y ago Cross-site Scripting in Apache Atlas
CVE-2017-3151 medium 6.1 6.1 apache 9y ago Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.
CVE-2017-3150 medium 6.1 6.1 apache 9y ago Insecure cookie storage in Apache Atlas
CVE-2016-4460 critical 9.8 9.8 apache 9y ago Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
CVE-2017-9802 medium 6.1 6.1 apache 9y ago Improper Neutralization of Input During Web Page Generation Apache Sling Servlets Post
CVE-2017-9800 critical 9.8 9.8 FIX arch arch slesdebian debian apache 9y ago A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be ge…
CVE-2017-7674 medium 4.3 4.3 FIX slesdebian debian apache 9y ago The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Orig…
CVE-2016-6812 medium 6.1 6.1 apache 9y ago Improper Neutralization of Input During Web Page Generation in Apache CXF
CVE-2016-6794 medium 5.3 5.3 slesdebian debian rhel apacheredhatnetapp 9y ago System Property Disclosure in Apache Tomcat
CVE-2016-5018 critical 9.1 9.1 slesdebian debian rhel apachenetappredhat 9y ago Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
CVE-2016-0762 medium 5.9 5.9 slesdebian debian rhel apacheredhatnetapp 9y ago Observable Discrepancy in Apache Tomcat
CVE-2012-0803 critical 9.8 9.8 apache 9y ago Improper Authentication in Apache CXF
CVE-2016-6798 critical 9.8 9.8 apache 9y ago XML External Entity Reference in Apache Sling
CVE-2016-5394 medium 6.1 6.1 apache 9y ago Cross site scripting in Apache Sling
CVE-2017-7685 medium 5.3 5.3 apache 9y ago Apache OpenMeetings responds to insecure HTTP methods
CVE-2017-7673 critical 9.8 9.8 apache 9y ago Apache OpenMeetings has Inadequate Encryption Strength
CVE-2017-7664 critical 10.0 10.0 apache 9y ago Apache OpenMeetings does not correctly validate uploaded XML documents
CVE-2017-7663 medium 6.1 6.1 apache 9y ago Apache OpenMeetings Cross-site Scripting vulnerability
CVE-2016-6793 critical 9.1 9.1 apache 9y ago The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the pe…
CVE-2017-9788 critical 9.1 9.1 FIX debian debianarch arch sles apachenetappredhat 9y ago In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assi…
CVE-2017-7672 medium 5.9 5.9 apache 9y ago Apache Struts Improper Input Validation vulnerability
CVE-2017-7678 medium 6.1 6.1 apache 9y ago Moderate severity vulnerability that affects org.apache.spark:spark-core_2.10 and org.apache.spark:spark-core_2.11
CVE-2017-5640 critical 9.8 9.8 apache 9y ago It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (…
CVE-2017-7679 critical 9.8 9.8 FIX debian debianarch arch sles apache 9y ago In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
CVE-2017-3169 critical 9.8 9.8 FIX debian debianarch arch sles apache 9y ago In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
CVE-2017-3167 critical 9.8 9.8 FIX debian debianarch arch sles apachenetappredhat 9y ago In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being…
CVE-2015-3254 medium 6.5 6.5 apache 9y ago The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
CVE-2017-7677 medium 5.9 5.9 apache 9y ago Moderate severity vulnerability that affects org.apache.ranger:ranger
CVE-2017-7676 critical 9.8 9.8 apache 9y ago Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '' wildcard character
CVE-2016-8751 medium 4.8 4.8 apache 9y ago Apache Ranger admin users can store some arbitrary javascript code to be executed when normal users login and access policies
CVE-2016-8746 medium 5.9 5.9 apache 9y ago Apache Ranger policy engine incorrectly matches paths in certain conditions
CVE-2017-7665 medium 6.1 6.1 apache 9y ago Cross-site Scripting in Apache NiFi
CVE-2016-5004 medium 6.5 6.5 apache 9y ago ws-xmlrpc DoS Vulnerability
CVE-2017-5646 medium 6.8 6.8 apache 9y ago Apache Knox allows impersonation of users
CVE-2015-5241 medium 6.1 6.1 apache 9y ago Moderate severity vulnerability that affects org.apache.juddi:juddi-client
CVE-2017-5655 medium 6.5 6.5 apache 9y ago In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the ho…
CVE-2016-4467 medium 5.9 5.9 FIX debian debian apache 9y ago The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name …
CVE-2017-3161 medium 6.1 6.1 apache 9y ago Improper Neutralization of Input During Web Page Generation in Apache Hadoop
CVE-2017-5653 medium 5.3 5.3 apache 9y ago Improper Certificate Validation in Apache CXF
CVE-2017-5645 critical 9.8 9.8 FIX debian debian sles rhel apachenetappredhat 9y ago Deserialization of Untrusted Data in Log4j
CVE-2017-5651 critical 9.8 9.8 FIX slesdebian debian apache 9y ago In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, …
CVE-2017-5648 critical 9.1 9.1 FIX slesdebian debian apache 9y ago While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use th…
CVE-2016-6808 critical 9.8 9.8 FIX debian debian apache 9y ago Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
CVE-2016-0779 critical 9.8 9.8 apache 9y ago The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.
CVE-2016-6805 medium 5.9 5.9 apache 9y ago Moderate severity vulnerability that affects org.apache.ignite:ignite-core
CVE-2016-6809 critical 9.8 9.8 FIX debian debian apache 9y ago Apache Tika allows Java code execution for serialized objects embedded in MATLAB files
CVE-2017-5642 critical 9.8 9.8 apache 9y ago During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
CVE-2016-4976 medium 5.5 5.5 apache 9y ago Apache Ambari reveals administrator passwords
CVE-2014-3582 critical 9.8 9.8 apache 9y ago In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.
CVE-2016-6807 critical 9.8 9.8 apache 9y ago Apache Ambari Improper Access Control