imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2018-11765
High 7.5

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

apache hadoop
0.05EPSS
CVE-2015-7520
Medium 6.1

Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HTML via a c…

apache wicket
0.05EPSS
CVE-2016-8750
Medium 6.5

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.

apache karaf
0.05EPSS
CVE-2018-1337
Critical 9.8

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connecti…

apache directory_ldap_api
0.05EPSS
CVE-2007-5342
Medium 6.4

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite ar…

apache tomcat
0.05EPSS
CVE-2019-0224
Medium 6.1

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on it…

apache jspwiki
0.05EPSS
CVE-2019-10085
Medium 6.1

In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page.

apache allura
0.05EPSS
CVE-2010-4539
Medium 6.8

The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that tr…

apache subversion
0.05EPSS
CVE-2012-5351
Medium 6.4

Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.

apache axis2
0.05EPSS
CVE-2019-0218
Medium 6.1

A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.

apache pony_mail
0.05EPSS
CVE-2015-3250
High 7.5

Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.

apache directory_ldap_api
0.05EPSS
CVE-2021-44548
Critical 9.8

An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network. If the attacker has wider access to t…

apache solr
0.05EPSS
CVE-2008-0002
Medium 5.8

Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this p…

apache tomcat
0.05EPSS
CVE-2021-26461
Critical 9.8

Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code in…

apache nuttx
0.05EPSS
CVE-2020-13923
Medium 5.3

IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04

apache ofbiz
0.05EPSS
CVE-2018-17200
Critical 9.8

The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it using XStream…

apache ofbiz
0.05EPSS
CVE-2009-2696
Medium 4.3

Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web …

apache tomcat
0.05EPSS
CVE-2012-1622
Critical 9.8

Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.

apache ofbiz
0.05EPSS
CVE-2022-30556
High 7.5

Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.

apache http_server · fedoraproject fedora · netapp clustered_data_ontap
0.05EPSS
CVE-2008-6879
Medium 4.3

Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.

apache roller
0.05EPSS
CVE-2020-1963
Critical 9.1

Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.

apache ignite
0.05EPSS
CVE-2018-11793
High 7.5

When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor can therefore cause …

apache mesos
0.05EPSS
CVE-2014-3502
Medium 4.3

Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.

apache cordova
0.05EPSS
CVE-2017-12619
High 8.1

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".

apache zeppelin
0.05EPSS
CVE-2021-30245
High 8.8

The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The problem has existed since about 2006 and the issue is also in 4.1.9. If the link is specifically crafted this could lead to untrusted code e…

apache openoffice
0.05EPSS