Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,154 CVEs tagged to vendor apache567 Critical, 1,138 High, 1,350 Medium, 97 Low, 2 Unrated.

CVE-2016-0760

Published Aug 19, 2016

Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) reflect, (2) reflect2, or (3) ja…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0782

Published Aug 5, 2016

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripti…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5000

Published Aug 5, 2016

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunct…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1513

Published Aug 5, 2016

The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted Me…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5005

Published Jul 28, 2016

Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via the connector.so…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4469

Published Jul 28, 2016

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of administrators for requests t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5388

Published Jul 19, 2016

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the prese…

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-4979

Published Jul 6, 2016

The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request author…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1546

Published Jul 6, 2016

The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote a…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2016-4465

Published Jul 4, 2016

The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4438

Published Jul 4, 2016

The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4433

Published Jul 4, 2016

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4431

Published Jul 4, 2016

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4430

Published Jul 4, 2016

Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1182

Published Jul 4, 2016

ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0899

Published Jul 4, 2016

The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-2174

Published Jun 13, 2016

SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime p…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3085

Published Jun 10, 2016

Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote atta…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3093

Published Jun 7, 2016

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,401-2,425 of 3,154 CVEsPage 97 of 127