Vulnerabilities > Apache > High

DATE CVE VULNERABILITY TITLE RISK
2019-10-04 CVE-2018-11768 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apache Hadoop
In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.
network
low complexity
apache CWE-119
7.5
2019-10-01 CVE-2019-0231 Cleartext Transmission of Sensitive Information vulnerability in Apache Mina 2.0.20/2.1.1
Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward.
network
low complexity
apache CWE-319
7.5
2019-09-26 CVE-2019-10097 NULL Pointer Dereference vulnerability in multiple products
In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference.
network
low complexity
apache oracle CWE-476
7.2
2019-09-26 CVE-2019-0203 Improper Handling of Exceptional Conditions vulnerability in Apache Subversion
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands.
network
low complexity
apache CWE-755
7.5
2019-09-16 CVE-2019-0207 Path Traversal vulnerability in Apache Tapestry 5.4.0
Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.
network
low complexity
apache CWE-22
7.5
2019-09-10 CVE-2019-12401 XML Entity Expansion vulnerability in Apache Solr
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a.
network
low complexity
apache CWE-776
7.5
2019-08-30 CVE-2019-12402 Infinite Loop vulnerability in multiple products
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs.
network
low complexity
apache fedoraproject oracle CWE-835
7.5
2019-08-28 CVE-2019-15752 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.
local
low complexity
docker apache CWE-732
7.8
2019-08-26 CVE-2019-15544 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
An issue was discovered in the protobuf crate before 2.6.0 for Rust.
network
low complexity
rust-protobuf-project apache CWE-770
7.5
2019-08-20 CVE-2019-10086 Deserialization of Untrusted Data vulnerability in multiple products
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects.
7.3