Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,106 CVEs tagged to vendor apache557 Critical, 1,108 High, 1,342 Medium, 97 Low, 2 Unrated.

CVE-2013-3060

Published Apr 21, 2013

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTT…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6551

Published Apr 21, 2013

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6092

Published Apr 21, 2013

Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0253

Published Apr 9, 2013

The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middl…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0248

Published Mar 15, 2013

The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to o…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4460

Published Mar 14, 2013

The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4459

Published Mar 14, 2013

Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted m…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4458

Published Mar 14, 2013

The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width e…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4446

Published Mar 14, 2013

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allow…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1814

Published Mar 14, 2013

The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0239

Published Mar 12, 2013

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authenticatio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5633

Published Mar 12, 2013

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4558

Published Feb 26, 2013

Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apach…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3499

Published Feb 26, 2013

Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5616

Published Jan 22, 2013

Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local u…

CVSS 1.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-2378

Published Jan 5, 2013

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the clie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2379

Published Jan 3, 2013

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4534

Published Dec 19, 2012

org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4431

Published Dec 19, 2012

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CS…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3546

Published Dec 19, 2012

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-con…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5568

Published Nov 30, 2012

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4557

Published Nov 30, 2012

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5887

Published Nov 17, 2012

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5886

Published Nov 17, 2012

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5885

Published Nov 17, 2012

The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 trac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,651-2,675 of 3,106 CVEsPage 107 of 125