Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2017-10-30 CVE-2015-0224 Data Processing Errors vulnerability in Apache Qpid
qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted protocol sequence set.
network
low complexity
apache CWE-19
7.5
2017-10-30 CVE-2014-3624 Improper Access Control vulnerability in Apache Traffic Server 5.1.0
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
network
low complexity
apache CWE-284
critical
9.8
2017-10-30 CVE-2014-3526 Information Exposure vulnerability in Apache Wicket
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
network
low complexity
apache CWE-200
7.5
2017-10-30 CVE-2013-4246 Improper Access Control vulnerability in Apache Subversion 1.8.0/1.8.1
libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties.
network
low complexity
apache CWE-284
8.8
2017-10-27 CVE-2015-1835 Improper Input Validation vulnerability in Apache Cordova
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
network
high complexity
apache CWE-20
5.3
2017-10-27 CVE-2014-3600 XXE vulnerability in Apache Activemq
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
network
low complexity
apache CWE-611
critical
9.8
2017-10-27 CVE-2014-3579 XXE vulnerability in Apache Activemq Apollo
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
network
low complexity
apache CWE-611
critical
9.8
2017-10-27 CVE-2016-5003 Deserialization of Untrusted Data vulnerability in Apache Ws-Xmlrpc 3.1.3
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
network
low complexity
apache CWE-502
critical
9.8
2017-10-27 CVE-2016-5002 XXE vulnerability in Apache Xml-Rpc 3.1.3
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.
local
low complexity
apache CWE-611
7.8
2017-10-26 CVE-2012-1622 Unspecified vulnerability in Apache Ofbiz 10.04
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
apache
critical
9.8