Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2016-0784

Published Apr 11, 2016

Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0783

Published Apr 11, 2016

The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user pas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0712

Published Apr 11, 2016

Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to portal.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0711

Published Apr 11, 2016

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when addi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0710

Published Apr 11, 2016

Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2)…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0709

Published Apr 11, 2016

Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0734

Published Apr 7, 2016

The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct click…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8797

Published Feb 15, 2016

Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8796

Published Feb 15, 2016

Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web scrip…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8795

Published Feb 15, 2016

Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3252

Published Feb 8, 2016

Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3251

Published Feb 8, 2016

Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vecto…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5344

Published Feb 3, 2016

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7521

Published Jan 29, 2016

The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass int…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5259

Published Jan 8, 2016

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// pro…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7430

Published Jan 2, 2016

The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to read or write to arbitrary GP…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort
Showing 2,451-2,475 of 3,142 CVEsPage 99 of 126