imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2018-11758
Alta 8.1

This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shipped with Apache Cayenne and intended for editing Cayenne ORM models stored as XML files. If an attacker tricks a …

apache cayenne
0.03EPSS
CVE-2018-17194
Alta 7.5

When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than 0, the receivin…

apache nifi
0.03EPSS
CVE-2017-7688
Alta 7.5

Apache OpenMeetings 1.0.0 updates user password in insecure manner.

apache openmeetings
0.03EPSS
CVE-2017-7686
Alta 7.5

Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http…

apache ignite
0.03EPSS
CVE-2013-4171
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.

apache roller
0.03EPSS
CVE-2012-0047
Media 4.3

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.

apache wicket
0.03EPSS
CVE-2019-12397
Media 6.1

Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.

apache ranger
0.03EPSS
CVE-2021-43045
Alta 7.5

A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to …

apache avro
0.03EPSS
CVE-2017-5661
Alta 7.3

In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is r…

apache formatting_objects_processor
0.03EPSS
CVE-2017-5659
Alta 7.5

Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.

apache traffic_server
0.03EPSS
CVE-2015-1775
Media 5.5

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.

apache ambari
0.03EPSS
CVE-2020-13946
Media 5.9

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle att…

apache cassandra · netapp oncommand_insight
0.03EPSS
CVE-2019-17562
Critica 9.8

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an …

apache cloudstack
0.03EPSS
CVE-2019-12407
Media 6.1

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the vict…

apache jspwiki
0.03EPSS
CVE-2019-12404
Media 6.1

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some s…

apache jspwiki
0.03EPSS
CVE-2019-10087
Media 6.1

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and …

apache jspwiki
0.03EPSS
CVE-2017-15717
Media 6.1

A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected version…

apache sling_xss_protection_api · apache sling_xss_protection_api_compat
0.03EPSS
CVE-2021-32824
Critica 9.8

Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Hand…

apache dubbo
0.03EPSS
CVE-2020-1951
Media 5.5

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

apache tika · canonical ubuntu_linux · debian debian_linux · oracle business_process_management_suite · e altri 2
0.03EPSS
CVE-2012-0031
Media 4.6

scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment,…

apache http_server · debian debian_linux · opensuse opensuse · redhat enterprise_linux_desktop · e altri 8
0.03EPSS
CVE-2021-31522
Critica 9.8

Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

apache kylin
0.03EPSS
CVE-2019-10089
Media 6.1

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get som…

apache jspwiki
0.03EPSS
CVE-2021-34797
Alta 7.5

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "jav…

apache geode
0.03EPSS
CVE-2017-12608
Alta 7.8

A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in a…

apache openoffice · debian debian_linux
0.03EPSS
CVE-2019-10090
Media 6.1

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some …

apache jspwiki
0.03EPSS