Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2011-4367

Published Jun 19, 2014

Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arb…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0119

Published May 31, 2014

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0099

Published May 31, 2014

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0096

Published May 31, 2014

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSL…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0095

Published May 31, 2014

java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Conten…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0075

Published May 31, 2014

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x befor…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2193

Published May 29, 2014

Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2758

Published May 23, 2014

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2756

Published May 23, 2014

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5649

Published May 23, 2014

Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adobe Flash.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0110

Published May 8, 2014

Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0109

Published May 8, 2014

Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/ht…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0116

Published May 8, 2014

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote atta…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0114

Published Apr 30, 2014

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, do…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7372

Published Apr 29, 2014

The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom imple…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0113

Published Apr 29, 2014

CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attacker…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0112

Published Apr 29, 2014

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and ex…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-2187

Published Apr 22, 2014

Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0111

Published Apr 17, 2014

Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "deriv…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0107

Published Apr 15, 2014

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2668

Published Mar 28, 2014

Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0003

Published Mar 21, 2014

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafte…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0002

Published Mar 21, 2014

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML doc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 2,576-2,600 of 3,142 CVEsPage 104 of 126