Apache
apache
3,377 CVEs • 392 products
Products (392)
Click to collapseToggle
Products (392)
Click to collapse
CVEs (3,377)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes...Show more |
3Apache FedoraprojectOracle3Fedora PdfboxRetail Xstore Point Of ServiceNov 21, 2024 Oct 5, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree. |
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0 |
The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of...Show more |
6Apache CanonicalDebian+3 more15Communications Application Session Controller Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Oct 4, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially craf...Show more |
5Apache CanonicalNetapp+2 more9Enterprise Linux Enterprise Manager Ops CenterHospitality Guest Access+6 moreNov 21, 2024 Sep 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2...Show more |
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. |
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value agains...Show more |
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser. |
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat",...Show more |
2Apache Oracle2Business Process Management Suite TikaNov 21, 2024 Sep 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack. |
In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo s...Show more |
In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file...Show more |
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal. |
4Apache CanonicalDebian+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Sep 17, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. |
4Apache CanonicalDebian+1 more4Debian Linux PdfinfoSpamassassin+1 moreNov 21, 2024 Sep 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. |
4Apache CanonicalDebian+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+4 moreNov 21, 2024 Sep 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan...Show more |
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because o...Show more |
2Apache Oracle3Activemq Enterprise RepositoryFlexcube Private BankingNov 21, 2024 Sep 10, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ serv...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Aug 29, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To...Show more |