imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2017-3163
Alta 7.5

When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to cra…

apache solr
0.07EPSS
CVE-2012-5649
Media 6.8

Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adobe Flash.

apache couchdb
0.07EPSS
CVE-2018-11768
Alta 7.5

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.

apache hadoop
0.07EPSS
CVE-2016-4436
Critica 9.8

Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.

apache struts
0.07EPSS
CVE-2011-1419
Media 5.8

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exist…

apache tomcat
0.07EPSS
CVE-2012-4458
Media 5.0

The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the client-properties map in a connection.start-ok message.

apache qpid
0.07EPSS
CVE-2015-3271
Media 5.3

Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.

apache tika
0.07EPSS
CVE-2005-3164
Bassa 2.6

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can…

apache tomcat · hitachi cosminexus_application_server
0.07EPSS
CVE-2015-3187
Media 4.0

The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been…

apache subversion · apple xcode
0.07EPSS
CVE-2014-0116
Media 5.8

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted requ…

apache struts
0.07EPSS
CVE-2014-0048
Critica 9.8

An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

apache geode · docker docker
0.07EPSS
CVE-2013-2071
Bassa 2.6

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request infor…

apache tomcat
0.07EPSS
CVE-2016-5004
Media 6.5

The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.

apache ws-xmlrpc
0.06EPSS
CVE-2013-2758
Media 5.0

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force attack.

apache cloudstack · citrix cloudplatform
0.06EPSS
CVE-2018-1295
Critica 9.8

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulner…

apache ignite
0.06EPSS
CVE-2005-0088
Alta 7.5

The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.

apache mod_python
0.06EPSS
CVE-2020-1931
Alta 8.1

A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. This issue is less stealthy and attempts to exploit the issue w…

apache spamassassin
0.06EPSS
CVE-2011-1088
Media 5.8

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

apache tomcat
0.06EPSS
CVE-2012-3467
Media 5.0

Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.

apache qpid
0.06EPSS
CVE-2016-8734
Media 6.5

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive …

apache subversion · debian debian_linux
0.06EPSS
CVE-2015-5348
Alta 8.1

Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HT…

apache camel
0.06EPSS
CVE-2012-5575
Media 6.4

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force …

apache cxf · redhat jboss_enterprise_application_platform · redhat jboss_enterprise_portal_platform · redhat jboss_enterprise_soa_platform · e altri 2
0.06EPSS
CVE-2017-3156
Alta 7.5

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

apache cxf
0.06EPSS
CVE-2015-1831
Alta 7.5

The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.

apache struts
0.06EPSS
CVE-2013-3060
Media 6.4

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.

apache activemq
0.06EPSS