imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2020-9492
High 8.8

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.

apache hadoop · apache solr · oracle financial_services_crime_and_compliance_management_studio
0.04EPSS
CVE-2012-0880
High 7.5

Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions.

apache xerces-c\+\+
0.04EPSS
CVE-2018-8003
Medium 5.3

Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides read-only access to any file on the filesystem of the host the Ambari Server runs on that is accessi…

apache ambari
0.04EPSS
CVE-2017-15701
High 7.5

In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventual…

apache qpid_broker-j
0.04EPSS
CVE-2013-4131
Medium 4.0

The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE reques…

apache subversion
0.04EPSS
CVE-2021-23901
Critical 9.1

An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere wit…

apache nutch · netapp snap_creator_framework
0.04EPSS
CVE-2020-27216
High 7.0

In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the pro…

apache beam · debian debian_linux · eclipse jetty · netapp snap_creator_framework · and 14 more
0.04EPSS
CVE-2020-13932
Medium 6.1

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in …

apache artemis
0.04EPSS
CVE-2021-41973
Medium 6.5

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update M…

apache mina · oracle banking_payments · oracle banking_trade_finance_process_management · oracle banking_treasury_management · and 5 more
0.04EPSS
CVE-2020-17513
Medium 5.3

In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.

apache airflow
0.04EPSS
CVE-2001-1072
Medium 5.0

Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.

apache http_server
0.04EPSS
CVE-2022-23223
High 7.5

On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.

apache shenyu
0.04EPSS
CVE-2021-39239
High 7.5

A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.

apache jena
0.04EPSS
CVE-2010-0684
Low 3.5

Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.

apache activemq
0.04EPSS
CVE-2016-2166
Medium 6.5

The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might al…

apache qpid_proton · fedoraproject fedora
0.04EPSS
CVE-2004-2680
Medium 5.0

mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.

apache mod_python
0.04EPSS
CVE-2021-23937
High 7.5

A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized. This DNS lookup can be engineered to ov…

apache wicket
0.04EPSS
CVE-2026-50229
Medium 6.1

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through …

apache tomcat
0.04EPSS
CVE-2012-2145
Medium 5.0

Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.

apache qpid
0.04EPSS
CVE-2022-25371
Critical 9.8

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution …

apache ofbiz
0.04EPSS
CVE-2009-1198
Medium 6.1

Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname parameter to happyjuddi.jsp.

apache juddi
0.04EPSS
CVE-2015-5256
Medium 4.3

Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a crafted URI.

apache cordova
0.04EPSS
CVE-2010-3315
Medium 6.0

authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows …

apache subversion
0.04EPSS
CVE-2002-0257
High 7.5

Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRE…

apache http_server · usanet_creations makebid_auction_deluxe
0.04EPSS
CVE-2018-8020
High 7.4

Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified,…

apache tomcat_native · debian debian_linux
0.04EPSS