Search

Found 834 results in 108ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-5003 critical 9.8 9.8 apache 9y ago Apache XML-RPC vulnerable to Deserialization of Untrusted Data
CVE-2016-5002 high 7.8 7.8 apache 9y ago Apache XML-RPC XXE Vulnerability
CVE-2012-1622 critical 9.8 9.8 apache 9y ago Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2017-12618 medium 4.7 4.7 FIX debian debian slesarch arch apache 9y ago Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A loc…
CVE-2017-12613 high 7.1 7.1 FIX debian debian slesarch arch apacheredhat 9y ago When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting t…
CVE-2010-5312 medium 6.1 6.1 FIX debian debianfedora fedora jqueryuinetappapache 9y ago Cross-site Scripting in jquery-ui
CVE-2010-2232 high 7.5 7.5 FIX debian debian apache 9y ago Improper Access Control in Apache Derby
CVE-2017-12628 high 7.8 7.8 apache 9y ago Apache James Privilege Escalation
CVE-2017-5636 critical 9.8 9.8 apache 9y ago Injection in Apache NiFi
CVE-2017-5635 high 7.5 7.5 apache 9y ago Improper Authentication In Apache NiFi
CVE-2016-8748 medium 5.4 5.4 apache 9y ago Cross-site Scripting in Apache NiFi
CVE-2016-4461 high 8.8 8.8 apachenetapp 9y ago Apache Struts forced double OGNL evaluation
CVE-2016-8734 medium 6.5 6.5 FIX slesdebian debian apache 9y ago Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The a…
CVE-2017-12629 critical 9.8 10.0 EXPFIX debian debianubuntu ubuntu rhel apacheredhat 9y ago Remote code execution occurs in Apache Solr
CVE-2016-6815 medium 6.5 6.5 apache 9y ago Moderate severity vulnerability that affects org.apache.ranger:ranger
CVE-2016-8736 critical 9.8 9.8 apache 9y ago Apache OpenMeetings RCE
CVE-2017-12623 medium 6.5 6.5 apache 9y ago XML External Entity Reference in Apache NiFi
CVE-2017-5637 high 7.5 8.5 EXPFIX debian debian apache 9y ago Uncontrolled Resource Consumption in Apache ZooKeeper
CVE-2014-0030 critical 9.8 10.0 EXP apache 9y ago The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
CVE-2017-9792 medium 6.5 6.5 apache 9y ago In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" a…
CVE-2017-9797 medium 6.5 6.5 apache 9y ago Apache Geode vulnerable to Exposure of Sensitive Information
CVE-2017-12620 critical 9.8 9.8 apache 9y ago Improper Restriction of XML External Entity Reference in Apache OpenNLP
CVE-2016-6806 high 8.8 8.8 apache 9y ago Apache Wicket vulnerable to CSRF attacks
CVE-2014-0043 medium 5.3 5.3 apache 9y ago Apache Wicket allows attackers to check for third-party libraries
CVE-2017-9794 medium 4.3 4.3 apache 9y ago Apache Geode gfsh query vulnerability
CVE-2016-4434 high 7.8 7.8 FIX debian debian apache 9y ago Apache Tika does not properly initialize the XML parser or choose handlers
CVE-2017-9790 high 7.5 7.5 apache 9y ago Use after free in Apache Mesos
CVE-2017-7687 high 7.5 7.5 apache 9y ago Denial of service in Apache Mesos
CVE-2017-12621 critical 9.8 9.8 apache 9y ago Improper Restriction of XML External Entity Reference in Jelly
CVE-2015-5169 medium 6.1 6.1 apache 9y ago Cross-site Scripting in Apache Struts
CVE-2017-9804 high 7.5 7.5 apache 9y ago Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
CVE-2017-9793 high 7.5 7.5 apache 9y ago The REST Plugin in Apache Struts is using an outdated XStream library
CVE-2017-12611 critical 9.8 10.0 EXP apache 9y ago Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal
CVE-2016-8738 medium 5.9 5.9 apache 9y ago Apache Struts vulnerable to possible DoS attack when using URLValidator
CVE-2016-6795 critical 9.8 9.8 apache 9y ago Path Traversal in Apache Struts
CVE-2017-12616 high 7.5 7.5 sles apache 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2017-9803 high 7.5 7.5 FIX debian debian apache 9y ago Apache Solr Kerberos delegation token functionality flaws
CVE-2017-9798 high 7.5 8.5 EXPFIX debian debianarch arch sles apache 9y ago Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsb…
CVE-2014-7808 high 7.5 7.5 apache 9y ago Apache Wicket insecure defaults
CVE-2017-3165 medium 5.4 5.4 apache 9y ago Cross-site Scripting In Apache Brooklyn
CVE-2017-12612 high 7.8 7.8 apache 9y ago Apache Spark Deserialization of Untrusted Data vulnerability
CVE-2016-8744 high 8.8 8.8 apache 9y ago Deserialization of Untrusted Data in Apache Brooklyn
CVE-2016-8737 high 8.8 8.8 apache 9y ago Apache Brooklyn is vulnerable to cross-site request forgery (CSRF)
CVE-2015-5206 critical 9.8 9.8 FIX debian debian apache 9y ago Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.
CVE-2015-5168 critical 9.8 9.8 FIX debian debian apache 9y ago Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.
CVE-2014-9635 medium 5.3 5.3 jenkinsapache 9y ago Jenkins HttpOnly flag not Set for session cookies
CVE-2014-9634 medium 5.3 5.3 jenkinsapache 9y ago Jenkins secure flag not set on session cookies
CVE-2015-3250 high 7.5 7.5 FIX debian debian apache 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Directory LDAP API
CVE-2016-3086 critical 9.8 9.8 apache 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2016-5001 medium 5.5 5.5 apache 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2016-6800 medium 6.1 6.1 apache 9y ago The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creatio…
CVE-2016-4462 high 8.8 8.8 apache 9y ago By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Fr…
CVE-2017-3163 high 7.5 7.5 FIX debian debian apache 9y ago Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
CVE-2017-3155 medium 6.1 6.1 apache 9y ago Cross-site Scripting in Apache Atlas
CVE-2017-3154 high 7.5 7.5 apache 9y ago Apache Atlas produces Stack trace in error response
CVE-2017-3153 medium 6.1 6.1 apache 9y ago Cross-site Scripting in Apache Atlas
CVE-2017-3152 medium 6.1 6.1 apache 9y ago Cross-site Scripting in Apache Atlas
CVE-2017-3151 medium 6.1 6.1 apache 9y ago Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.
CVE-2017-3150 medium 6.1 6.1 apache 9y ago Insecure cookie storage in Apache Atlas
CVE-2016-8752 high 7.5 7.5 apache 9y ago Path Traversal in Apache Atlas
CVE-2015-5209 high 7.5 7.5 apache 9y ago Special top object can be used to access Struts' internals
CVE-2016-4460 critical 9.8 9.8 apache 9y ago Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
CVE-2017-9802 medium 6.1 6.1 apache 9y ago Improper Neutralization of Input During Web Page Generation Apache Sling Servlets Post
CVE-2017-9800 critical 9.8 9.8 FIX arch arch slesdebian debian apache 9y ago A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be ge…
CVE-2017-7675 high 7.5 7.5 FIX slesdebian debian apache 9y ago The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypa…
CVE-2017-7674 medium 4.3 4.3 FIX slesdebian debian apache 9y ago The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Orig…
CVE-2016-6796 high 7.5 7.5 slesdebian debian rhel apachenetapporacle 9y ago Apache Tomcat vulnerable to SecurityManager bypass
CVE-2016-8745 high 7.5 7.5 FIX slesdebian debian apache 9y ago A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0.39, 7.0.0 to 7.0.73 and 6.0.16 to 6.0.48 resulted…
CVE-2016-6817 high 7.5 7.5 FIX debian debian apache 9y ago The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of s…
CVE-2016-6797 high 7.5 7.5 slesdebian debian rhel apacheoraclenetapp 9y ago Incorrect Authorization in Apache Tomcat
CVE-2017-3156 high 7.5 7.5 apache 9y ago Covert Timing Channel in Apache CXF
CVE-2016-8739 high 7.5 7.5 apache 9y ago Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
CVE-2016-6812 medium 6.1 6.1 apache 9y ago Improper Neutralization of Input During Web Page Generation in Apache CXF
CVE-2016-6794 medium 5.3 5.3 slesdebian debian rhel apacheredhatnetapp 9y ago System Property Disclosure in Apache Tomcat
CVE-2016-5018 critical 9.1 9.1 slesdebian debian rhel apachenetappredhat 9y ago Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
CVE-2016-0762 medium 5.9 5.9 slesdebian debian rhel apacheredhatnetapp 9y ago Observable Discrepancy in Apache Tomcat
CVE-2017-9799 high 8.8 8.8 sles apache 9y ago Apache Storm it is possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user
CVE-2012-0880 high 7.5 7.5 slesdebian debian apache 9y ago Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions.
CVE-2012-0803 critical 9.8 9.8 apache 9y ago Improper Authentication in Apache CXF
CVE-2011-4343 high 7.5 7.5 apache 9y ago Apache MyFaces Vulnerable to EL Injection
CVE-2010-2245 high 7.4 7.4 apache 9y ago XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
CVE-2017-9801 high 7.5 7.5 FIX debian debian apache 9y ago Improper Input Validation in Apache Commons Email
CVE-2016-8743 high 7.5 7.5 FIX debian debian sles rhel apachenetappredhat 9y ago Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors repres…
CVE-2016-2161 high 7.5 7.5 FIX debian debian sles apache 9y ago In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
CVE-2016-0736 high 7.5 8.5 EXPFIX slesdebian debian apache 9y ago In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by defaul…
CVE-2017-7659 high 7.5 7.5 FIX debian debianarch arch sles apache 9y ago A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process.
CVE-2016-6798 critical 9.8 9.8 apache 9y ago XML External Entity Reference in Apache Sling
CVE-2016-5394 medium 6.1 6.1 apache 9y ago Cross site scripting in Apache Sling
CVE-2017-7688 high 7.5 7.5 apache 9y ago Apache OpenMeetings updates user password in insecure manner
CVE-2017-7685 medium 5.3 5.3 apache 9y ago Apache OpenMeetings responds to insecure HTTP methods
CVE-2017-7684 high 7.5 7.5 apache 9y ago Apache OpenMeetings vulnerable to Uncontrolled Resource Consumption
CVE-2017-7683 high 7.5 7.5 apache 9y ago Apache OpenMeetings displays Tomcat version and detailed error stack trace
CVE-2017-7682 high 8.2 8.2 apache 9y ago Apache OpenMeetings vulnerable to parameter manipulation attacks
CVE-2017-7681 high 8.8 8.8 apache 9y ago Apache OpenMeetings vulnerable to SQL injection
CVE-2017-7680 high 7.5 7.5 apache 9y ago Apache OpenMeetings allows flash content to be loaded from untrusted domains
CVE-2017-7673 critical 9.8 9.8 apache 9y ago Apache OpenMeetings has Inadequate Encryption Strength
CVE-2017-7666 high 8.8 8.8 apache 9y ago Apache OpenMeetings vulnerable to Cross-Site Request Forgery
CVE-2017-7664 critical 10.0 10.0 apache 9y ago Apache OpenMeetings does not correctly validate uploaded XML documents
CVE-2017-7663 medium 6.1 6.1 apache 9y ago Apache OpenMeetings Cross-site Scripting vulnerability
CVE-2016-6793 critical 9.1 9.1 apache 9y ago The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the pe…