Vulnerabilities > Apache > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-18 CVE-2018-8011 NULL Pointer Dereference vulnerability in multiple products
By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault.
network
low complexity
apache netapp CWE-476
7.5
2018-07-11 CVE-2018-8007 Improper Input Validation vulnerability in Apache Couchdb
Apache CouchDB administrative users can configure the database server via HTTP(S).
network
low complexity
apache CWE-20
7.2
2018-07-10 CVE-2018-1331 Unspecified vulnerability in Apache Storm
In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.
network
low complexity
apache
8.8
2018-07-05 CVE-2018-8038 Improper Input Validation vulnerability in Apache CXF Fediz
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.
network
low complexity
apache CWE-20
7.5
2018-07-02 CVE-2018-8039 Improper Handling of Exceptional Conditions vulnerability in multiple products
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'.
network
high complexity
apache redhat CWE-755
8.1
2018-06-27 CVE-2018-1306 Information Exposure vulnerability in Apache Pluto 3.0.0
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload.
network
low complexity
apache CWE-200
7.5
2018-06-27 CVE-2018-8025 Race Condition vulnerability in Apache Hbase
CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP.
network
high complexity
apache CWE-362
8.1
2018-06-20 CVE-2018-8030 Improper Input Validation vulnerability in Apache Qpid Broker-J
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default).
network
low complexity
apache CWE-20
7.5
2018-06-18 CVE-2018-1333 Resource Exhaustion vulnerability in multiple products
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service.
network
low complexity
apache redhat canonical netapp CWE-400
7.5
2018-06-13 CVE-2017-15695 Incorrect Authorization vulnerability in Apache Geode
When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function.
network
low complexity
apache CWE-863
8.8