imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2020-1944
Critica 9.8

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

apache traffic_server · debian debian_linux
0.03EPSS
CVE-2016-8746
Media 5.9

Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.

apache ranger
0.03EPSS
CVE-2023-47804
Alta 8.8

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject…

apache openoffice
0.03EPSS
CVE-2020-13958
Alta 7.8

A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target users file system. These hyperlinks can be triggered unconditionally. In fixed versions no internal pr…

apache openoffice
0.03EPSS
CVE-2015-3270
Media 6.5

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords.

apache ambari
0.03EPSS
CVE-2019-12416
Media 6.1

we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default.

apache deltaspike
0.03EPSS
CVE-2019-0204
Alta 7.8

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A …

apache mesos · redhat fuse
0.03EPSS
CVE-2021-35474
Critica 9.8

Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

apache traffic_server · debian debian_linux
0.03EPSS
CVE-2019-0187
Critica 9.8

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This o…

apache jmeter
0.03EPSS
CVE-2021-33190
Media 5.3

In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made i…

apache apisix_dashboard
0.03EPSS
CVE-2015-8795
Media 6.1

Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/…

apache solr
0.03EPSS
CVE-2024-52577
Critica 9.0

In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose cla…

apache ignite
0.03EPSS
CVE-2018-17192
Media 6.5

The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently appl…

apache nifi
0.03EPSS
CVE-2020-1952
Critica 9.8

An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.

apache iotdb
0.03EPSS
CVE-2018-20243
Alta 7.5

The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.

apache fineract
0.03EPSS
CVE-2018-1289
Alta 8.8

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with SQL statem…

apache fineract
0.03EPSS
CVE-2012-2945
Alta 7.5

Hadoop 1.0.3 contains a symlink vulnerability.

apache hadoop
0.03EPSS
CVE-2020-1937
Alta 8.8

Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.

apache kylin
0.03EPSS
CVE-2017-7663
Media 6.1

Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.

apache openmeetings
0.03EPSS
CVE-2019-0216
Media 4.8

A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

apache airflow
0.03EPSS
CVE-2023-46589
Alta 7.5

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that ex…

apache tomcat
0.03EPSS
CVE-2020-13953
Media 5.3

In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.

apache tapestry
0.03EPSS
CVE-2018-1339
Media 5.5

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.

apache tika
0.03EPSS
CVE-2021-36374
Media 5.5

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly u…

apache ant · oracle agile_engineering_data_management · oracle agile_plm · oracle banking_trade_finance · e altri 32
0.03EPSS
CVE-2017-15695
Alta 8.8

When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployment should be restrict…

apache geode
0.03EPSS