Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-7681 SQL Injection vulnerability in Apache Openmeetings
Apache OpenMeetings 1.0.0 is vulnerable to SQL injection.
network
low complexity
apache CWE-89
8.8
2017-07-17 CVE-2017-7680 Unspecified vulnerability in Apache Openmeetings
Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file.
network
low complexity
apache
7.5
2017-07-17 CVE-2017-7673 Improper Restriction of Excessive Authentication Attempts vulnerability in Apache Openmeetings
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
network
low complexity
apache CWE-307
critical
9.8
2017-07-17 CVE-2017-7666 Cross-site Scripting vulnerability in Apache Openmeetings
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.
network
low complexity
apache CWE-79
8.8
2017-07-17 CVE-2017-7664 XXE vulnerability in Apache Openmeetings
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
network
low complexity
apache CWE-611
critical
10.0
2017-07-17 CVE-2017-7663 Cross-site Scripting vulnerability in Apache Openmeetings 3.2.0/3.2.1
Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.
network
low complexity
apache CWE-79
6.1
2017-07-17 CVE-2016-6793 Deserialization of Untrusted Data vulnerability in Apache Wicket
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.
network
low complexity
apache CWE-502
critical
9.1
2017-07-17 CVE-2015-0249 Code Injection vulnerability in Apache Roller 5.1.0/5.1.1
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
network
low complexity
apache CWE-94
7.2
2017-07-13 CVE-2017-9789 Use After Free vulnerability in Apache Http Server 2.4.26
When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
network
low complexity
apache CWE-416
7.5
2017-07-13 CVE-2017-9788 Improper Input Validation vulnerability in multiple products
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest.
network
low complexity
apache debian apple netapp redhat oracle CWE-20
critical
9.1