Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-23 CVE-2014-0229 Permissions, Privileges, and Access Controls vulnerability in multiple products
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
network
low complexity
cloudera apache CWE-264
6.5
2017-02-02 CVE-2016-1566 Cross-site Scripting vulnerability in Apache Guacamole 0.9.8/0.9.9
Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by multiple users, allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.
network
low complexity
apache CWE-79
5.4
2016-12-15 CVE-2015-3271 Information Exposure vulnerability in Apache Tika 1.9
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
network
low complexity
apache CWE-200
5.3
2016-09-26 CVE-2016-5395 Cross-site Scripting vulnerability in Apache Ranger
Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.
network
low complexity
apache CWE-79
4.8
2016-08-19 CVE-2016-3089 Cross-site Scripting vulnerability in Apache Openmeetings
Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the swf parameter.
network
low complexity
apache CWE-79
6.1
2016-08-05 CVE-2016-0782 Cross-site Scripting vulnerability in Apache Activemq
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
network
low complexity
apache CWE-79
5.4
2016-08-05 CVE-2016-5000 XXE vulnerability in Apache POI
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
local
low complexity
apache CWE-611
5.5
2016-07-28 CVE-2016-5005 Cross-site Scripting vulnerability in Apache Archiva
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via the connector.sourceRepoId parameter to admin/addProxyConnector_commit.action.
network
low complexity
apache CWE-79
4.8
2016-07-06 CVE-2016-1546 Resource Management Errors vulnerability in Apache Http Server 2.4.17/2.4.18
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
network
high complexity
apache CWE-399
5.9
2016-07-04 CVE-2016-4465 Improper Input Validation vulnerability in Apache Struts
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
network
low complexity
apache CWE-20
5.3