imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2015-2992
Medium 6.1

Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.

apache struts
0.06EPSS
CVE-2019-10095
Critical 9.8

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

apache zeppelin
0.06EPSS
CVE-2016-6497
High 7.5

main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.

apache groovy_ldap
0.06EPSS
CVE-2020-13959
Medium 6.1

The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being executed. XSS vu…

apache velocity_tools · debian debian_linux
0.06EPSS
CVE-2012-5784
Medium 5.8

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name …

apache activemq · apache axis · paypal mass_pay · paypal payments_pro · and 1 more
0.06EPSS
CVE-2018-11804
High 7.5

Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including master. This server will accept connections fr…

apache spark
0.06EPSS
CVE-2015-5253
Medium 4.0

The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."

apache cxf
0.06EPSS
CVE-2021-40146
Critical 9.8

A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or i…

apache any23
0.06EPSS
CVE-2020-11995
Critical 9.8

A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protool, during Hessian2 deserializing the HashMap object,…

apache dubbo
0.06EPSS
CVE-2016-3090
High 8.8

The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.

apache struts
0.06EPSS
CVE-2014-10022
Medium 5.0

Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.

apache traffic_server
0.06EPSS
CVE-2014-8152
Medium 5.0

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.

apache santuario_xml_security_for_java
0.06EPSS
CVE-2017-7660
High 7.5

Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster and point it to a malicious node. This can trick the nodes in …

apache solr
0.06EPSS
CVE-2019-14892
Critical 9.8

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbi…

apache geode · fasterxml jackson-databind · redhat decision_manager · redhat jboss_data_grid · and 4 more
0.06EPSS
CVE-2008-6682
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in …

apache struts
0.06EPSS
CVE-2016-6813
Critical 9.8

Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the AP…

apache cloudstack
0.06EPSS
CVE-2017-6891
High 8.8

Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utili…

apache bookkeeper · debian debian_linux · gnu libtasn1
0.06EPSS
CVE-2014-3522
Medium 4.0

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof serv…

apache subversion · apple xcode · canonical ubuntu_linux · opensuse opensuse
0.06EPSS
CVE-2003-0987
High 7.5

mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.

apache http_server
0.06EPSS
CVE-2018-1282
Critical 9.1

This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.

apache hive
0.06EPSS
CVE-2018-8027
Critical 9.8

Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.

apache camel
0.06EPSS
CVE-2020-11972
Critical 9.8

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

apache camel · oracle communications_diameter_signaling_router · oracle enterprise_manager_base_platform · oracle flexcube_private_banking
0.06EPSS
CVE-2015-0226
High 7.5

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series …

apache wss4j
0.06EPSS
CVE-2003-0973
Medium 5.0

Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.

apache mod_python
0.05EPSS
CVE-2014-0074
High 7.5

Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.

apache shiro
0.05EPSS