imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2012-1621
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script or HTML via (1) a parameter array in freemarker templates, the (2) contentId or (3…

apache ofbiz
0.10EPSS
CVE-2010-2076
Critical 9.8

Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote at…

apache cxf
0.10EPSS
CVE-2016-1240
High 7.8

The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages…

apache tomcat
0.10EPSS
CVE-2019-0188
High 7.5

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.

apache camel · oracle enterprise_data_quality · oracle enterprise_manager_base_platform · oracle enterprise_repository · and 1 more
0.10EPSS
CVE-2008-1947
Medium 4.3

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

apache tomcat
0.10EPSS
CVE-2014-8108
Medium 5.0

The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual t…

apache subversion · apple xcode · redhat enterprise_linux_desktop · redhat enterprise_linux_hpc_node · and 2 more
0.10EPSS
CVE-2009-3569
High 9.3

Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side stack overflow exploit." NOTE: as of 2009100…

apache openoffice.org
0.10EPSS
CVE-2020-17531
Critical 9.8

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached en…

apache tapestry
0.10EPSS
CVE-2017-9787
High 7.5

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.

apache struts
0.10EPSS
CVE-2002-2272
High 7.8

Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.

apache http_server · apache tomcat
0.10EPSS
CVE-2016-6802
High 7.5

Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

apache shiro
0.10EPSS
CVE-2016-4433
High 7.5

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.

apache struts
0.10EPSS
CVE-2016-4431
High 7.5

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.

apache struts
0.10EPSS
CVE-2010-3453
High 9.3

The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attac…

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.10EPSS
CVE-2015-5351
High 8.8

The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mecha…

apache tomcat · canonical ubuntu_linux · debian debian_linux
0.10EPSS
CVE-2009-2693
Medium 5.8

Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.

apache tomcat
0.10EPSS
CVE-2018-11761
High 7.5

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

apache tika · oracle business_process_management_suite
0.10EPSS
CVE-2019-0201
Medium 5.9

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintex…

apache activemq · apache drill · apache zookeeper · debian debian_linux · and 6 more
0.10EPSS
CVE-2012-3502
Medium 4.3

The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection,…

apache http_server
0.10EPSS
CVE-2014-1972
High 7.8

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.…

apache tapestry
0.10EPSS
CVE-2019-10241
Medium 6.1

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listi…

apache activemq · apache drill · debian debian_linux · eclipse jetty · and 3 more
0.10EPSS
CVE-2012-5568
Medium 5.0

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

apache tomcat · opensuse opensuse
0.10EPSS
CVE-2017-9789
High 7.5

When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.

apache http_server
0.10EPSS
CVE-2001-0042
Medium 5.0

PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.

apache http_server
0.10EPSS
CVE-2015-5214
Medium 6.8

LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.

apache openoffice · canonical ubuntu_linux · debian debian_linux · libreoffice libreoffice
0.10EPSS