imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2003-1581
Bassa 2.6

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, r…

apache http_server
0.03EPSS
CVE-2021-37404
Critica 9.8

There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or…

apache hadoop
0.03EPSS
CVE-2016-0711
Media 6.1

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.

apache jetspeed
0.03EPSS
CVE-2016-0733
Critica 9.8

The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid username.

apache ranger
0.03EPSS
CVE-2018-8023
Media 5.9

Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT impl…

apache mesos
0.03EPSS
CVE-2013-4390
Media 5.8

Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in th…

apache sling · apache sling_auth_core_component
0.03EPSS
CVE-2021-31812
Media 5.5

In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

apache pdfbox · fedoraproject fedora · oracle banking_corporate_lending_process_management · oracle banking_credit_facilities_process_management · e altri 3
0.03EPSS
CVE-2021-41561
Alta 7.5

Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.

apache parquet_java
0.03EPSS
CVE-2020-9487
Alta 7.5

In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content. An unauthenticated user co…

apache nifi
0.03EPSS
CVE-2021-26296
Alta 7.5

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possi…

apache myfaces · netapp oncommand_insight
0.03EPSS
CVE-2016-6804
Alta 7.8

The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated privileges. This requires that the location in which the instal…

apache openoffice
0.03EPSS
CVE-2023-50292
Alta 7.5

Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0. The Schema Designer was introduce…

apache solr
0.03EPSS
CVE-2023-45802
Media 5.9

When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping th…

apache http_server · debian debian_linux · fedoraproject fedora
0.03EPSS
CVE-2008-2717
Media 6.5

TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or cond…

apache apache_webserver · typo3 typo3
0.03EPSS
CVE-2017-12620
Critica 9.8

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 t…

apache opennlp
0.03EPSS
CVE-2014-0043
Media 5.3

In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in us…

apache wicket
0.03EPSS
CVE-2023-31122
Alta 7.5

Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.

apache http_server · debian debian_linux · fedoraproject fedora
0.03EPSS
CVE-2014-3627
Media 5.0

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive,…

apache hadoop
0.03EPSS
CVE-2018-1299
Alta 7.5

In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with Allura, such as Nginx, Apache/mod_wsgi or paster may prevent the attack from succeeding. Others, such as gunicor…

apache allura
0.03EPSS
CVE-2020-1950
Media 5.5

A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.

apache tika · canonical ubuntu_linux · debian debian_linux · oracle business_process_management_suite · e altri 2
0.03EPSS
CVE-2022-44621
Critica 9.8

Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.

apache kylin
0.03EPSS
CVE-2019-17572
Media 5.3

In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers…

apache rocketmq
0.03EPSS
CVE-2017-12610
Media 6.8

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations …

apache kafka
0.03EPSS
CVE-2021-27807
Media 5.5

A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

apache pdfbox · fedoraproject fedora · oracle banking_trade_finance_process_management · oracle banking_treasury_management · e altri 11
0.03EPSS
CVE-2022-36364
Alta 8.8

Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, which can lead…

apache apache_calcite_avatica
0.03EPSS