imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2017-15699
Media 6.5

A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user must be able to establish an AMQP connection to the Qpid Dispatch Router and send a specifically crafted AMQP fram…

apache qpid_dispatch
0.03EPSS
CVE-2013-2055
Media 5.0

Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and reading the i…

apache wicket
0.03EPSS
CVE-2014-9593
Media 5.0

Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

apache cloudstack
0.03EPSS
CVE-2012-4460
Media 5.0

The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an …

apache qpid
0.03EPSS
CVE-2018-1310
Alta 7.5

Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was appl…

apache nifi
0.03EPSS
CVE-2007-3384
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.

apache tomcat
0.03EPSS
CVE-2019-17565
Critica 9.8

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

apache traffic_server · debian debian_linux
0.03EPSS
CVE-2019-17559
Critica 9.8

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

apache traffic_server · debian debian_linux
0.03EPSS
CVE-2020-5499
Critica 9.8

Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.

apache rust_sgx_sdk
0.03EPSS
CVE-2024-38477
Alta 7.5

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

apache http_server · netapp clustered_data_ontap
0.03EPSS
CVE-2014-3504
Media 4.0

The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, …

apache subversion · canonical ubuntu_linux · serf_project serf
0.03EPSS
CVE-2024-23946
Media 5.3

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

apache ofbiz
0.03EPSS
CVE-2007-5797
Alta 7.5

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.

apache geronimo
0.03EPSS
CVE-2012-3353
Alta 7.5

The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.…

apache sling_jcr_contentloader
0.03EPSS
CVE-2016-5393
Alta 8.8

In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.

apache hadoop
0.03EPSS
CVE-2020-17528
Critica 9.1

Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the…

apache nuttx
0.03EPSS
CVE-2010-4008
Media 4.3

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a deni…

apache openoffice · apple iphone_os · apple itunes · apple mac_os_x · e altri 11
0.03EPSS
CVE-2024-56512
Media 5.4

Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to …

apache nifi
0.03EPSS
CVE-2020-1942
Alta 7.5

In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both…

apache nifi
0.03EPSS
CVE-2017-3157
Media 5.5

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store …

apache openoffice · debian debian_linux · redhat enterprise_linux_desktop · redhat enterprise_linux_server · e altri 4
0.03EPSS
CVE-2020-13948
Alta 8.8

While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web application proces…

apache superset
0.03EPSS
CVE-2011-4415
Bassa 1.2

The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial…

apache http_server
0.03EPSS
CVE-2010-2057
Media 5.0

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modification…

apache myfaces
0.03EPSS
CVE-2012-5636
Media 6.1

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to <script> tags in a rendered response.

apache wicket
0.03EPSS
CVE-2019-0207
Alta 7.5

Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.

apache tapestry
0.03EPSS