imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2017-7676
Critica 9.8

Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.

apache ranger
0.04EPSS
CVE-2011-0533
Media 4.3

Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.22 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to the…

apache archiva · apache continuum
0.04EPSS
CVE-2007-4548
Alta 10.0

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sendi…

apache geronimo
0.04EPSS
CVE-2008-4482
Alta 7.8

The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large maxOccurs value, which triggers excessive memory consumption during validation of …

apache xerces-c\+\+
0.04EPSS
CVE-2021-28163
Bassa 2.7

In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and …

apache ignite · apache solr · eclipse jetty · fedoraproject fedora · e altri 19
0.04EPSS
CVE-2017-9795
Alta 7.5

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access to objects within unauthorized regions. In addition a user could…

apache geode
0.04EPSS
CVE-2022-26612
Critica 9.8

In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A sub…

apache hadoop
0.04EPSS
CVE-2024-40725
Media 5.3

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result i…

apache http_server
0.04EPSS
CVE-2002-0185
Alta 7.5

mod_python version 2.7.6 and earlier allows a module indirectly imported by a published module to then be accessed via the publisher, which allows remote attackers to call possibly dangerous functions from the imported module.

apache mod_python
0.04EPSS
CVE-2016-5000
Media 5.5

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

apache poi
0.04EPSS
CVE-2018-17198
Critica 9.8

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTY…

apache roller
0.04EPSS
CVE-2015-5210
Media 5.8

Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter.

apache ambari
0.04EPSS
CVE-2017-5662
Alta 7.3

In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application …

apache batik
0.04EPSS
CVE-2022-25168
Critica 9.8

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run b…

apache hadoop
0.04EPSS
CVE-2021-37578
Critica 9.8

Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI invocati…

apache juddi
0.04EPSS
CVE-2020-11969
Critica 9.8

If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache TomEE 7.1…

apache tomee
0.04EPSS
CVE-2012-2379
Alta 10.0

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and atta…

apache cxf
0.04EPSS
CVE-2014-3500
Media 6.4

Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.

apache cordova
0.04EPSS
CVE-2013-2254
Media 5.0

The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root…

apache org.apache.sling.servlets.post
0.04EPSS
CVE-2009-5006
Media 4.0

The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a d…

apache qpid · redhat enterprise_mrg
0.04EPSS
CVE-2021-30179
Critica 9.8

Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are handled by the GenericFilter which will find the service and method specified in the first arguments of the invoc…

apache dubbo
0.04EPSS
CVE-2018-8019
Alta 7.4

When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate wi…

apache tomcat_native · debian debian_linux
0.04EPSS
CVE-2013-2136
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache CloudStack before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Physical network name to the Zone wizard; (2) New network name, (3) instance name, or (4) group to t…

apache cloudstack
0.04EPSS
CVE-2025-31651
Critica 9.8

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effective…

apache tomcat
0.04EPSS
CVE-2020-13924
Alta 7.5

In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.

apache ambari
0.04EPSS