NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
43992 | CVE-2012-2145 | Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections. | 2 | 5 | Medium | 2017-01-19 | 2013-03-21 | View | |
20409 | CVE-2016-4974 | Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function. | 2 | 6 | Medium | 2017-01-19 | 2016-09-01 | View | |
17117 | CVE-2016-0735 | Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy. | 2 | 6.5 | Medium | 2017-01-19 | 2016-04-19 | View | |
87221 | CVE-2016-8746 | Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true. | 2 | 4.3 | Medium | 2017-06-23 | 2017-06-19 | View | |
87222 | CVE-2016-8751 | Apache Ranger before 0.6.is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies. | 2 | 3.5 | Low | 2017-06-23 | 2017-06-19 | View |
Page 1281 of 17672, showing 5 records out of 88360 total, starting on record 6401, ending on 6405