Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,154 CVEs tagged to vendor apache567 Critical, 1,138 High, 1,350 Medium, 97 Low, 2 Unrated.

CVE-2016-3087

Published Jun 7, 2016

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-7611

Published Jun 7, 2016

Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4432

Published Jun 1, 2016

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via v…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3094

Published Jun 1, 2016

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker ter…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3088

Published Jun 1, 2016

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
72.7
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2016-2175

Published Jun 1, 2016

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attack…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0731

Published May 18, 2016

The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0707

Published May 18, 2016

The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allows local users to ob…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2099

Published May 13, 2016

Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5208

Published May 9, 2016

Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5207

Published May 9, 2016

Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2168

Published May 5, 2016

The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2167

Published May 5, 2016

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attack…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3082

Published Apr 26, 2016

XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet locati…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3081

Published Apr 26, 2016

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method:…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1776

Published Apr 19, 2016

Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data en…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5348

Published Apr 15, 2016

Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote atta…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5343

Published Apr 14, 2016

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (s…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7520

Published Apr 12, 2016

Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x b…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5347

Published Apr 12, 2016

Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4003

Published Apr 12, 2016

Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows r…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2162

Published Apr 12, 2016

Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0785

Published Apr 12, 2016

Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,426-2,450 of 3,154 CVEsPage 98 of 127