Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2013-4444

Published Sep 12, 2014

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3574

Published Sep 4, 2014

Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3529

Published Sep 4, 2014

The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6153

Published Sep 4, 2014

http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3596

Published Aug 27, 2014

The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3524

Published Aug 26, 2014

Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3525

Published Aug 22, 2014

Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health ch…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0232

Published Aug 22, 2014

Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3577

Published Aug 21, 2014

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname match…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3528

Published Aug 19, 2014

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier…

CVSS 4.0 · Medium

CVE-2013-7393

Published Jul 28, 2014

The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4262

Published Jul 28, 2014

svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3523

Published Jul 20, 2014

Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is en…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0231

Published Jul 20, 2014

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a requ…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0117

Published Jul 20, 2014

The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4352

Published Jul 20, 2014

The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3503

Published Jul 11, 2014

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1621

Published Jun 19, 2014

Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,551-2,575 of 3,142 CVEsPage 103 of 126