Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2014-8110

Published Feb 12, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0223

Published Feb 2, 2015

Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related to 0-10 connection handling.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8152

Published Jan 21, 2015

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9593

Published Jan 15, 2015

Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10022

Published Jan 13, 2015

Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9527

Published Jan 6, 2015

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3628

Published Jan 6, 2015

Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7809

Published Dec 10, 2014

Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7807

Published Dec 10, 2014

Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthentica…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3627

Published Dec 5, 2014

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3629

Published Nov 17, 2014

XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0228

Published Nov 16, 2014

Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remo…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3502

Published Nov 15, 2014

Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3501

Published Nov 15, 2014

Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3500

Published Nov 15, 2014

Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3623

Published Oct 30, 2014

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3584

Published Oct 30, 2014

The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3581

Published Oct 10, 2014

The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of ser…

CVSS 5.0 · Medium

CVE-2014-0074

Published Oct 6, 2014

Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) passw…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6107

Published Sep 29, 2014

Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,526-2,550 of 3,142 CVEsPage 102 of 126