Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2018-09-17 CVE-2018-8041 Path Traversal vulnerability in Apache Camel
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
network
low complexity
apache CWE-22
5.3
2018-09-17 CVE-2018-11781 Code Injection vulnerability in multiple products
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
local
low complexity
apache redhat debian canonical CWE-94
7.8
2018-09-17 CVE-2018-11780 Code Injection vulnerability in multiple products
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
network
low complexity
apache pdfinfo-project debian canonical CWE-94
critical
9.8
2018-09-17 CVE-2017-15705 Improper Input Validation vulnerability in multiple products
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2.
network
low complexity
apache redhat debian canonical CWE-20
5.3
2018-09-13 CVE-2018-1330 Improper Input Validation vulnerability in Apache Mesos
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception.
network
low complexity
apache CWE-20
7.5
2018-09-10 CVE-2018-11775 Improper Certificate Validation vulnerability in multiple products
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server.
network
high complexity
apache oracle CWE-295
7.4
2018-08-29 CVE-2018-8040 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access.
network
low complexity
apache debian CWE-668
5.3
2018-08-29 CVE-2018-8022 Improper Input Validation vulnerability in Apache Traffic Server
A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault.
network
low complexity
apache CWE-20
7.5
2018-08-29 CVE-2018-8005 Resource Exhaustion vulnerability in multiple products
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache.
network
low complexity
apache debian CWE-400
5.3
2018-08-29 CVE-2018-8004 HTTP Request Smuggling vulnerability in multiple products
There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS).
network
low complexity
apache debian CWE-444
6.5