imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2019-10078
Media 6.1

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were v…

apache jspwiki
0.05EPSS
CVE-2019-0213
Media 6.5

In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communicatio…

apache archiva
0.05EPSS
CVE-2001-1563
Alta 7.5

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

apache tomcat · hp secure_os
0.05EPSS
CVE-2012-4446
Media 6.8

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via…

apache qpid
0.05EPSS
CVE-2019-12426
Media 5.3

an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06

apache ofbiz
0.05EPSS
CVE-2017-15707
Media 6.2

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

apache struts · netapp oncommand_balance · oracle agile_plm_framework · oracle enterprise_manager_for_virtualization · e altri 8
0.05EPSS
CVE-2018-8035
Media 6.1

This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended exec…

apache uimaducc
0.05EPSS
CVE-2018-11798
Media 6.5

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

apache thrift
0.05EPSS
CVE-2019-0214
Media 6.5

In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the …

apache archiva
0.05EPSS
CVE-2017-9799
Alta 8.8

It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst…

apache storm
0.05EPSS
CVE-2019-0191
Media 6.5

Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validati…

apache karaf
0.05EPSS
CVE-2016-3089
Media 6.1

Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the swf parameter.

apache openmeetings
0.05EPSS
CVE-2015-0265
Media 6.1

Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header.

apache ranger
0.05EPSS
CVE-2023-23638
Media 5.0

A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x…

apache dubbo
0.05EPSS
CVE-2019-10088
Alta 8.8

A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.

apache tika
0.05EPSS
CVE-2010-3449
Media 6.8

Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attacke…

apache archiva · jesse_mcconnell redback
0.05EPSS
CVE-2018-8036
Media 6.5

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

apache pdfbox
0.05EPSS
CVE-2017-15697
Critica 9.8

A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x rele…

apache nifi
0.05EPSS
CVE-2004-0940
Alta 7.8

Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.

apache http_server · hp hp-ux · openpkg openpkg · slackware slackware_linux · e altri 2
0.05EPSS
CVE-2012-1574
Media 6.5

The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allo…

apache hadoop · cloudera cloudera_cdh · cloudera hadoop
0.05EPSS
CVE-2020-1959
Critica 9.8

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR …

apache syncope
0.05EPSS
CVE-2020-1964
Critica 9.8

It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: De…

apache heron
0.05EPSS
CVE-2012-1181
Media 5.0

fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series …

apache mod_fcgid
0.05EPSS
CVE-2008-3271
Media 4.3

Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variab…

apache tomcat
0.05EPSS
CVE-2022-22728
Alta 7.5

A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

apache libapreq2 · debian debian_linux · fedoraproject fedora
0.05EPSS