Apache Software Foundation

352 tracked vulnerabilities.

CVE-2017-9801 HIGH
Apache Commons Email <1.5 - Info Disclosure
Aug 07, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-7659 HIGH
Apache HTTP Server <2.4.24-2.4.25 - Use After Free
Jul 26, 2017
CVSS 7.5
EPSS 0.38
CVE-2017-7688 HIGH
Apache OpenMeetings 1.0.0 - Info Disclosure
Jul 17, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-7685 MEDIUM
Apache OpenMeetings 1.0.0 - Info Disclosure
Jul 17, 2017
CVSS 5.3
EPSS 0.01
CVE-2017-7684 HIGH
Apache OpenMeetings 1.0.0 - Denial of Service via Large File Upload
Jul 17, 2017
CVSS 7.5
EPSS 0.02
CVE-2017-7683 HIGH
Apache OpenMeetings 1.0.0 - Info Disclosure
Jul 17, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-7682 HIGH
Apache OpenMeetings 3.2.0 - Info Disclosure
Jul 17, 2017
CVSS 8.2
EPSS 0.01
CVE-2017-7681 HIGH
Apache OpenMeetings 1.0.0 - SQL Injection
Jul 17, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-7680 HIGH
Apache OpenMeetings 1.0.0 - Overly Permissive crossdomain.xml
Jul 17, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-7673 CRITICAL
Apache OpenMeetings 1.0.0 - Info Disclosure
Jul 17, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-7666 HIGH
Apache OpenMeetings 1.0.0 - Cross-Site Request Forgery
Jul 17, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-7664 CRITICAL
Apache OpenMeetings 3.1.0 - Info Disclosure
Jul 17, 2017
CVSS 10.0
EPSS 0.01
CVE-2017-7663 MEDIUM
Apache OpenMeetings 3.2.0 - Stored Cross-Site Scripting in Global and Room Chat
Jul 17, 2017
CVSS 6.1
EPSS 0.01
CVE-2017-9789 HIGH
Apache httpd 2.4.26 - Memory Corruption
Jul 13, 2017
CVSS 7.5
EPSS 0.06
CVE-2017-9788 CRITICAL
Apache httpd <2.2.34 & 2.4.x <2.4.27 - Info Disclosure
Jul 13, 2017
CVSS 9.1
EPSS 0.49
CVE-2017-9787 HIGH
Apache Struts - Denial of Service via Spring AOP Functionality
Jul 13, 2017
CVSS 7.5
EPSS 0.08
CVE-2017-7672 MEDIUM
Apache Struts 2.5.0-2.5.10.1 - Denial of Service via URLValidator
Jul 13, 2017
CVSS 5.9
EPSS 0.01
CVE-2017-5652 HIGH
Apache Impala 2.7.0-2.8.0 - Cleartext Transmission of Sensitive Information via StatestoreSubscriber Thrift Transport
Jul 10, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-5640 CRITICAL
Apache Impala 2.7.0-2.8.0 - Improper Authentication via Early SASL Handshake Completion
Jul 10, 2017
CVSS 9.8
EPSS 0.01
CVE-2017-7670 HIGH
Apache Traffic Control - Denial of Service via Slowloris Attack
Jul 10, 2017
CVSS 7.5
EPSS 0.02
CVE-2017-9791 CRITICAL KEVNUCLEI
Apache Struts 2.1.x and 2.3.x - Remote Code Execution via ActionMessage Field Value
Jul 10, 2017
CVSS 9.8
EPSS 0.94
CVE-2017-7660 HIGH
Apache Solr 5.3.0-5.5.4 and 6.0-6.5.1 - Improper Authentication via Malicious Node Name
Jul 07, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-7686 HIGH
Apache Ignite <2.0 - Info Disclosure
Jun 28, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-7679 CRITICAL
Apache httpd <2.2.33, <2.4.26 - Buffer Overflow
Jun 20, 2017
CVSS 9.8
EPSS 0.30
CVE-2017-7668 HIGH
Apache HTTP Server 2.2.32-2.4.24 - Out-of-bounds Read via Token List Parsing
Jun 20, 2017
CVSS 7.5
EPSS 0.63