Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2017-10-27 CVE-2014-3579 XXE vulnerability in Apache Activemq Apollo
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
network
low complexity
apache CWE-611
critical
9.8
2017-10-27 CVE-2016-5003 Deserialization of Untrusted Data vulnerability in Apache Ws-Xmlrpc 3.1.3
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
network
low complexity
apache CWE-502
critical
9.8
2017-10-27 CVE-2016-5002 XXE vulnerability in Apache Xml-Rpc 3.1.3
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.
local
low complexity
apache CWE-611
7.8
2017-10-26 CVE-2012-1622 Unspecified vulnerability in Apache Ofbiz 10.04
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
apache
critical
9.8
2017-10-24 CVE-2017-12618 Out-of-bounds Read vulnerability in Apache Portable Runtime Utility
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access.
local
apache CWE-125
1.9
2017-10-24 CVE-2017-12613 Out-of-bounds Read vulnerability in multiple products
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
local
low complexity
apache debian redhat CWE-125
7.1
2017-10-23 CVE-2010-2232 Improper Access Control vulnerability in Apache Derby
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
network
low complexity
apache CWE-284
5.0
2017-10-20 CVE-2017-12628 Deserialization of Untrusted Data vulnerability in Apache James Server 2.3.2/2.3.2.1/3.0.0
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands.
local
low complexity
apache CWE-502
7.8
2017-10-19 CVE-2017-5636 Injection vulnerability in Apache Nifi
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a replicated request to another node.
network
low complexity
apache CWE-74
7.5
2017-10-19 CVE-2017-5635 Improper Authentication vulnerability in Apache Nifi
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.
network
low complexity
apache CWE-287
5.0