Apache
apache
3,377 CVEs • 392 products
Products (392)
Click to collapseToggle
Products (392)
Click to collapse
CVEs (3,377)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javasc...Show more |
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute...Show more |
The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attack...Show more |
Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any f...Show more |
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuratio...Show more |
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manage...Show more |
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch...Show more |
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine,...Show more |
The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the r...Show more |
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the att...Show more |
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is...Show more |
3Apache FedoraprojectOracle19Banking Payments Banking PlatformCommons Compress+16 moreJun 17, 2026 Aug 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker...Show more |
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and...Show more |
2Apache Rust Protobuf Project2Hbase Rust ProtobufJun 17, 2026 Aug 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls. |
3Apache OracleRedhat3Jboss Enterprise Application Platform Santuario Xml Security For JavaWeblogic ServerJun 17, 2026 Aug 23, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a m...Show more |
6Apache DebianFedoraproject+3 more61Agile Plm Agile Product Lifecycle ManagementAgile Product Lifecycle Management Integration Pack+58 moreAug 25, 2026 Aug 20, 2019 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, howev...Show more |
2Apache Debian2Debian Linux Http ServerJun 17, 2026 Aug 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the con...Show more |
11Apache AppleCanonical+8 more18Debian Linux Diskstation ManagerEnterprise Linux+15 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These fra...Show more |
12Apache AppleCanonical+9 more23Clustered Data Ontap Communications Element ManagerDebian Linux+20 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they...Show more |
12Apache AppleCanonical+9 more19Debian Linux Diskstation ManagerEnterprise Linux+16 moreJun 17, 2026 Aug 13, 2019 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman en...Show more |