Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,177 CVEs tagged to vendor apache570 Critical, 1,151 High, 1,357 Medium, 97 Low, 2 Unrated.

CVE-2017-5659

Published Apr 17, 2017

Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5651

Published Apr 17, 2017

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5650

Published Apr 17, 2017

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5648

Published Apr 17, 2017

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5647

Published Apr 17, 2017

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-0779

Published Apr 11, 2017

The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6811

Published Apr 11, 2017

In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6805

Published Apr 7, 2017

Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6809

Published Apr 6, 2017

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5649

Published Apr 4, 2017

Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ perm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5642

Published Apr 3, 2017

During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4976

Published Mar 29, 2017

Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3582

Published Mar 29, 2017

In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6807

Published Mar 28, 2017

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying syst…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-8749

Published Mar 28, 2017

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5644

Published Mar 24, 2017

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0229

Published Mar 23, 2017

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6816

Published Mar 20, 2017

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid char…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5643

Published Mar 16, 2017

Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 2,376-2,400 of 3,177 CVEsPage 96 of 128