Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-04 CVE-2017-17837 Cross-site Scripting vulnerability in Apache Deltaspike 1.8.0
The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling.
network
low complexity
apache CWE-79
6.1
2017-12-18 CVE-2017-12630 Cross-site Scripting vulnerability in Apache Drill
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards.
network
low complexity
apache CWE-79
5.4
2017-12-01 CVE-2017-15707 Improper Input Validation vulnerability in multiple products
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
local
low complexity
apache netapp oracle CWE-20
6.2
2017-11-20 CVE-2017-3157 Information Exposure vulnerability in multiple products
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem.
local
low complexity
apache debian redhat CWE-200
5.5
2017-11-15 CVE-2014-0219 Improper Input Validation vulnerability in Apache Karaf
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.
local
low complexity
apache CWE-20
5.5
2017-11-14 CVE-2017-12624 Unspecified vulnerability in Apache CXF
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications.
local
low complexity
apache
5.5
2017-11-01 CVE-2017-12625 Information Exposure vulnerability in Apache Hive
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger.
network
low complexity
apache CWE-200
4.3
2017-10-30 CVE-2012-5636 Cross-site Scripting vulnerability in Apache Wicket
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to <script> tags in a rendered response.
network
low complexity
apache CWE-79
6.1
2017-10-30 CVE-2009-1198 Cross-site Scripting vulnerability in Apache Juddi
Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname parameter to happyjuddi.jsp.
network
low complexity
apache CWE-79
6.1
2017-10-30 CVE-2009-1197 Improper Input Validation vulnerability in Apache Juddi 0.9/2.0
Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.
network
low complexity
apache CWE-20
5.3