Apache / CouchDB
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-45725 | Apache CouchDB, IBM Cloudant: Privilege Escalation Using _design Documents | MEDIUM | 5.7 | Dec 13, 2023 |
| CVE-2023-26268 | Apache CouchDB, IBM Cloudant: Information sharing via couchjs processes | MEDIUM | 5.3 | May 2, 2023 |
| CVE-2022-24706 KEV | Remote Code Execution Vulnerability in Packaging | CRITICAL | 9.8 | Apr 26, 2022 |
| CVE-2021-38295 | Privilege escalation vulnerability when using HTML attachments | HIGH | 7.3 | Oct 14, 2021 |
| CVE-2020-1955 | CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_… | CRITICAL | 9.8 | May 20, 2020 |
| CVE-2018-17188 | Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where… | HIGH | 7.2 | Jan 2, 2019 |
| CVE-2018-14889 | CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. | HIGH | 7.8 | Sep 21, 2018 |
| CVE-2018-11769 | CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration… | HIGH | 7.2 | Aug 8, 2018 |
| CVE-2018-8007 | Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration setti… | HIGH | 7.2 | Jul 11, 2018 |
| CVE-2016-8742 | The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions… | HIGH | 7.8 | Feb 12, 2018 |
| CVE-2017-12636 | CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries… | HIGH | 7.2 | Nov 14, 2017 |
| CVE-2017-12635 | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to subm… | CRITICAL | 9.8 | Nov 14, 2017 |
| CVE-2012-5649 | Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adob… | MEDIUM | 6.8 | May 23, 2014 |
| CVE-2014-2668 | Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids. | MEDIUM | 5.0 | Mar 28, 2014 |
| CVE-2012-5650 | Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to… | MEDIUM | 4.3 | Mar 18, 2014 |
| CVE-2012-5641 | Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x befor… | MEDIUM | 5.0 | Mar 18, 2014 |
| CVE-2010-3854 | Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attacker… | MEDIUM | 4.3 | Feb 2, 2011 |
| CVE-2010-2953 | couchdb: start-up script sets insecure LD_LIBRARY_PATH | MEDIUM | 6.9 | Sep 14, 2010 |
| CVE-2010-2234 | Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators f… | MEDIUM | 6.8 | Aug 19, 2010 |
| CVE-2010-0009 | Apache CouchDB v0.10.0 prone to timing attacks vulnerability | MEDIUM | 4.3 | Apr 5, 2010 |
Showing 1 to 20 of 20 CVEs