Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2012-5650

Published Mar 18, 2014

Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5641

Published Mar 18, 2014

Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0094

Published Mar 11, 2014

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2014-1882

Published Mar 3, 2014

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1881

Published Mar 3, 2014

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6637

Published Mar 3, 2014

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0033

Published Feb 26, 2014

org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, whic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4322

Published Feb 26, 2014

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4286

Published Feb 26, 2014

Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP reque…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0346

Published Feb 15, 2014

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One T…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0032

Published Feb 14, 2014

The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attacker…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2055

Published Feb 10, 2014

Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1880

Published Feb 5, 2014

Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0177

Published Jan 30, 2014

Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2192

Published Jan 24, 2014

The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in…

CVSS 3.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0031

Published Jan 15, 2014

The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted reque…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6398

Published Jan 15, 2014

The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass int…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4517

Published Jan 11, 2014

Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6480

Published Jan 7, 2014

Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6612

Published Dec 7, 2013

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an extern…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 2,601-2,625 of 3,142 CVEsPage 105 of 126