Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,106 CVEs tagged to vendor apache557 Critical, 1,108 High, 1,342 Medium, 97 Low, 2 Unrated.

CVE-2012-2733

Published Nov 16, 2012

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5786

Published Nov 4, 2012

The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5785

Published Nov 4, 2012

Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifica…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5783

Published Nov 4, 2012

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain na…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3446

Published Nov 4, 2012

Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or su…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4501

Published Oct 26, 2012

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3506

Published Oct 25, 2012

Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5351

Published Oct 9, 2012

Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a differe…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4418

Published Oct 9, 2012

Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2145

Published Sep 28, 2012

Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3451

Published Sep 24, 2012

Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action Str…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3373

Published Sep 19, 2012

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors inv…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4360

Published Sep 15, 2012

Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4001

Published Sep 15, 2012

The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary ho…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4387

Published Sep 5, 2012

Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4386

Published Sep 5, 2012

The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-si…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3526

Published Sep 5, 2012

The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3467

Published Aug 27, 2012

Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authent…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3502

Published Aug 22, 2012

The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2012-2687

Published Aug 22, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4…

CVSS 2.6 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2012-0213

Published Aug 7, 2012

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2665

Published Aug 6, 2012

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a deni…

CVSS 7.5 · High

CVE-2012-3376

Published Jul 12, 2012

DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 2,676-2,700 of 3,106 CVEsPage 108 of 125