imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2021-35516
High 7.5

When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Comp…

apache commons_compress · netapp active_iq_unified_manager · netapp oncommand_insight · oracle banking_digital_experience · and 20 more
0.12EPSS
CVE-2020-36230
High 7.5

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.

apache bookkeeper · apple mac_os_x · apple macos · debian debian_linux · and 1 more
0.12EPSS
CVE-2019-17554
Medium 5.5

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger …

apache olingo
0.12EPSS
CVE-2001-0829
Medium 5.1

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

apache tomcat
0.12EPSS
CVE-2015-1832
Critical 9.1

XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via ve…

apache derby
0.12EPSS
CVE-2013-4295
Medium 5.0

The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

apache shindig
0.12EPSS
CVE-2013-2250
High 10.0

Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related …

apache ofbiz
0.12EPSS
CVE-2012-5887
Medium 5.0

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for …

apache tomcat
0.12EPSS
CVE-2009-3301
High 9.3

Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.12EPSS
CVE-2015-0248
Medium 5.0

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revis…

apache subversion · apple xcode · opensuse opensuse · oracle solaris · and 5 more
0.12EPSS
CVE-2018-8037
Medium 5.9

If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO…

apache tomcat · debian debian_linux
0.12EPSS
CVE-2009-1956
Medium 6.4

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

apache apr-util · apache http_server · canonical ubuntu_linux
0.12EPSS
CVE-2019-0222
High 7.5

In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.

apache activemq · debian debian_linux · netapp e-series_santricity_web_services · oracle communications_diameter_signaling_router · and 4 more
0.12EPSS
CVE-2001-1342
Medium 5.0

Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointe…

apache http_server
0.12EPSS
CVE-2012-3546
Medium 4.3

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j…

apache tomcat
0.12EPSS
CVE-2001-0730
Medium 5.0

split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.

apache http_server
0.12EPSS
CVE-2020-13938
Medium 5.5

Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows

apache http_server · mcafee epolicy_orchestrator · netapp cloud_backup
0.12EPSS
CVE-2021-42340
High 7.5

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket co…

apache tomcat · debian debian_linux · netapp hci · netapp management_services_for_element_software · and 14 more
0.12EPSS
CVE-2007-1863
Medium 5.0

cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s…

apache http_server · apple mac_os_x_server
0.12EPSS
CVE-2009-3302
High 9.3

filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary e…

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.12EPSS
CVE-2014-1882
High 7.5

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and directly accesses bridg…

adobe phonegap · apache cordova
0.12EPSS
CVE-2018-8007
High 7.2

Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to…

apache couchdb
0.12EPSS
CVE-2010-2245
High 7.4

XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.

apache wink
0.12EPSS
CVE-2021-35515
High 7.5

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

apache commons_compress · netapp active_iq_unified_manager · netapp oncommand_insight · oracle banking_digital_experience · and 22 more
0.12EPSS
CVE-2016-4003
Medium 6.1

Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters …

apache struts
0.12EPSS