NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
29044 | CVE-2014-0111 | Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings." | 2 | 6.5 | Medium | 2017-01-19 | 2014-05-09 | View | |
31688 | CVE-2014-3503 | Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack. | 2 | 5 | Medium | 2017-01-19 | 2014-07-11 | View | |
30485 | CVE-2014-1972 | Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data. | 2 | 7.8 | High | 2017-01-19 | 2015-08-24 | View | |
25148 | CVE-2015-3271 | Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header. | 2 | 5 | Medium | 2017-01-19 | 2016-12-22 | View | |
48562 | CVE-2009-1275 | Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags. | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-29 | View |
Page 1289 of 17672, showing 5 records out of 88360 total, starting on record 6441, ending on 6445