Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2017-10-30 CVE-2013-4366 Improper Input Validation vulnerability in Apache Httpclient 4.3
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
network
low complexity
apache CWE-20
critical
9.8
2017-10-30 CVE-2012-5636 Cross-site Scripting vulnerability in Apache Wicket
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to <script> tags in a rendered response.
network
low complexity
apache CWE-79
6.1
2017-10-30 CVE-2012-4449 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Apache Hadoop
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.
network
low complexity
apache CWE-327
critical
9.8
2017-10-30 CVE-2014-0115 Path Traversal vulnerability in Apache Storm 0.9.0.1
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a ..
network
low complexity
apache CWE-22
7.5
2017-10-30 CVE-2012-0881 Resource Management Errors vulnerability in Apache Xerces2 Java 2.10.0/2.11.0/2.9.1
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
network
low complexity
apache CWE-399
7.5
2017-10-30 CVE-2009-1198 Cross-site Scripting vulnerability in Apache Juddi
Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname parameter to happyjuddi.jsp.
network
low complexity
apache CWE-79
6.1
2017-10-30 CVE-2009-1197 Improper Input Validation vulnerability in Apache Juddi 0.9/2.0
Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.
network
low complexity
apache CWE-20
5.3
2017-10-30 CVE-2016-3090 Improper Input Validation vulnerability in Apache Struts
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
network
low complexity
apache CWE-20
8.8
2017-10-30 CVE-2015-3249 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apache Traffic Server 5.3.0
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers array or (2) set_dynamic_table_size function.
network
low complexity
apache CWE-119
critical
9.8
2017-10-30 CVE-2015-0226 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Apache Wss4J
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages.
network
low complexity
apache CWE-327
7.5