imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2018-1288
Media 5.4

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

apache kafka · oracle database · oracle primavera_p6_enterprise_project_portfolio_management · oracle timesten_in-memory_database · e altri 1
0.05EPSS
CVE-2017-7670
Alta 7.5

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain in the ESTABLISHED state until the client explicitly closes t…

apache traffic_control
0.05EPSS
CVE-2022-25167
Critica 9.8

Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JND…

apache flume
0.05EPSS
CVE-2016-5005
Media 4.8

Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via the connector.sourceRepoId parameter to admin/addProxyConnector_commit.action.

apache archiva
0.05EPSS
CVE-2016-2175
Alta 7.8

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

apache pdfbox · debian debian_linux
0.05EPSS
CVE-2026-40466
Alta 8.8

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an…

apache activemq · apache activemq_broker
0.05EPSS
CVE-2017-15692
Critica 9.8

In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the …

apache geode
0.05EPSS
CVE-2016-8736
Critica 9.8

Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.

apache openmeetings
0.05EPSS
CVE-2013-2153
Media 4.3

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference elements i…

apache xml_security_for_c\+\+
0.05EPSS
CVE-2019-10076
Media 6.1

A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

apache jspwiki
0.05EPSS
CVE-2022-28614
Media 5.3

The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distribu…

apache http_server · fedoraproject fedora · netapp clustered_data_ontap
0.05EPSS
CVE-2020-5529
Alta 8.1

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specifi…

apache camel · canonical ubuntu_linux · debian debian_linux · htmlunit htmlunit
0.05EPSS
CVE-2011-3607
Media 4.4

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf di…

apache http_server
0.05EPSS
CVE-2010-3083
Media 4.3

sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in a…

apache qpid · redhat enterprise_mrg
0.05EPSS
CVE-2014-3628
Media 4.3

Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.

apache solr
0.05EPSS
CVE-2019-10077
Media 6.1

A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

apache jspwiki
0.05EPSS
CVE-2013-0239
Media 5.0

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that…

apache cxf
0.05EPSS
CVE-2018-1317
Alta 8.8

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.

apache zeppelin
0.05EPSS
CVE-2019-12425
Alta 7.5

Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

apache ofbiz
0.05EPSS
CVE-2017-1000190
Critica 9.1

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

apache solr · simplexml_project simplexml
0.05EPSS
CVE-2020-1961
Critica 9.8

Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered.

apache syncope
0.05EPSS
CVE-2015-5208
Media 4.4

Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.

apache cordova
0.05EPSS
CVE-2019-12410
Alta 7.5

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R impl…

apache arrow
0.05EPSS
CVE-2024-34750
Alta 7.5

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 st…

apache tomcat · netapp ontap_tools
0.05EPSS
CVE-2017-5644
Media 5.5

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

apache poi
0.05EPSS