Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2017-11-15 CVE-2017-12634 Deserialization of Untrusted Data vulnerability in Apache Camel
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability.
network
low complexity
apache CWE-502
critical
9.8
2017-11-15 CVE-2017-12633 Deserialization of Untrusted Data vulnerability in Apache Camel
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability.
network
low complexity
apache CWE-502
critical
9.8
2017-11-14 CVE-2017-12636 OS Command Injection vulnerability in Apache Couchdb
CouchDB administrative users can configure the database server via HTTP(S).
network
low complexity
apache CWE-78
7.2
2017-11-14 CVE-2017-12635 Improper Privilege Management vulnerability in Apache Couchdb
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users.
network
low complexity
apache CWE-269
critical
9.8
2017-11-14 CVE-2017-12624 Unspecified vulnerability in Apache CXF
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications.
local
low complexity
apache
5.5
2017-11-13 CVE-2017-3166 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Hadoop
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.
local
low complexity
apache CWE-732
7.8
2017-11-13 CVE-2016-6803 Untrusted Search Path vulnerability in Apache Openoffice
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows.
local
low complexity
apache CWE-426
7.8
2017-11-01 CVE-2017-12625 Information Exposure vulnerability in Apache Hive
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger.
network
low complexity
apache CWE-200
4.3
2017-10-30 CVE-2014-0073 Permissions, Privileges, and Access Controls vulnerability in Apache Cordova and Cordova In-App-Browser
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript in the host page and consequently gain privileges via a crafted gap-iab: URI.
network
low complexity
apache CWE-264
critical
9.8
2017-10-30 CVE-2014-0072 Improper Input Validation vulnerability in Apache Cordova and Cordova File Transfer
ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9.0 might allow remote attackers to spoof SSL servers by leveraging a default value of true for the trustAllHosts option.
network
low complexity
apache CWE-20
7.5