Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2013-6408

Published Dec 7, 2013

The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML d…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6407

Published Dec 7, 2013

The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunct…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6397

Published Dec 7, 2013

Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4558

Published Dec 7, 2013

The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabl…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4505

Published Dec 7, 2013

The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4212

Published Dec 7, 2013

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second paramete…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4171

Published Dec 7, 2013

Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6357

Published Nov 13, 2013

Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrato…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6348

Published Nov 2, 2013

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) acti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4295

Published Oct 24, 2013

The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external entity declaration in conjun…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4330

Published Oct 4, 2013

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}"…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4310

Published Sep 30, 2013

Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4277

Published Sep 16, 2013

Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1909

Published Aug 23, 2013

The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 c…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2210

Published Aug 20, 2013

Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2172

Published Aug 20, 2013

jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2156

Published Aug 20, 2013

Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2155

Published Aug 20, 2013

Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or byp…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2154

Published Aug 20, 2013

Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2153

Published Aug 20, 2013

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,626-2,650 of 3,142 CVEsPage 106 of 126