Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2015-1836

Published Dec 21, 2015

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1772

Published Dec 21, 2015

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mish…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5204

Published Dec 17, 2015

CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6420

Published Dec 15, 2015

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Con…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-8320

Published Nov 23, 2015

Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5256

Published Nov 23, 2015

Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to by…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5253

Published Nov 18, 2015

The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML respo…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4940

Published Nov 8, 2015

Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain s…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-4928

Published Nov 8, 2015

Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to ob…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5210

Published Nov 2, 2015

Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3270

Published Nov 2, 2015

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing password…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3186

Published Nov 2, 2015

Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-1775

Published Nov 2, 2015

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and acc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6524

Published Aug 24, 2015

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3612

Published Aug 24, 2015

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authenticatio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1972

Published Aug 22, 2015

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of serv…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1830

Published Aug 19, 2015

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to cre…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3253

Published Aug 13, 2015

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a cra…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2015-3187

Published Aug 12, 2015

The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,476-2,500 of 3,142 CVEsPage 100 of 126