Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2015-3183

Published Jul 20, 2015

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smu…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1831

Published Jul 16, 2015

The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0230

Published Jun 7, 2015

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire req…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0264

Published Jun 3, 2015

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0263

Published Jun 3, 2015

XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attacke…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1833

Published May 29, 2015

XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8111

Published Apr 21, 2015

Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0251

Published Apr 8, 2015

The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protoco…

CVSS 4.0 · Medium

CVE-2015-0248

Published Apr 8, 2015

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and…

CVSS 5.0 · Medium

CVE-2015-0202

Published Apr 8, 2015

The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which tr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1773

Published Apr 8, 2015

Cross-site scripting (XSS) vulnerability in asdoc/templates/index.html in Apache Flex before 4.14.1 allows remote attackers to inject arbitrary web script or HTML by providing a c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0225

Published Apr 3, 2015

The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2091

Published Mar 13, 2015

The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is set, which allows remote attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0254

Published Mar 9, 2015

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse>…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0227

Published Feb 16, 2015

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to cont…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0227

Published Feb 12, 2015

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,501-2,525 of 3,142 CVEsPage 101 of 126