Vulnerabilities > Apache > High

DATE CVE VULNERABILITY TITLE RISK
2019-12-09 CVE-2019-19603 SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
network
low complexity
sqlite oracle siemens apache netapp
7.5
2019-12-05 CVE-2012-1592 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Struts 2.0.0
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
network
low complexity
apache CWE-434
8.8
2019-12-04 CVE-2019-17555 Improper Input Validation vulnerability in Apache Olingo
The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check.
network
low complexity
apache CWE-20
7.5
2019-12-03 CVE-2016-1000104 Improper Input Validation vulnerability in multiple products
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
network
low complexity
apache opensuse CWE-20
8.8
2019-11-27 CVE-2011-2177 Unspecified vulnerability in Apache Openoffice 3.3.0
OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.
local
low complexity
apache
7.8
2019-11-26 CVE-2011-3600 XXE vulnerability in Apache Ofbiz
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem.
network
low complexity
apache CWE-611
7.5
2019-11-19 CVE-2019-12421 Insufficient Session Expiration vulnerability in Apache Nifi
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side.
network
low complexity
apache CWE-613
8.8
2019-11-18 CVE-2019-12422 Unspecified vulnerability in Apache Shiro
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
network
low complexity
apache
7.5
2019-11-18 CVE-2019-10172 A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries.
network
low complexity
fasterxml redhat debian apache
7.5
2019-11-08 CVE-2019-12410 Missing Initialization of Resource vulnerability in Apache Arrow
While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet.
network
low complexity
apache CWE-909
7.5