imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2021-34798
Alta 7.5

Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.

apache http_server · broadcom brocade_fabric_operating_system_firmware · debian debian_linux · fedoraproject fedora · e altri 14
0.65EPSS
CVE-2020-13934
Alta 7.5

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur …

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp oncommand_system_manager · e altri 10
0.64EPSS
CVE-2021-28125
Media 6.1

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard …

apache superset
0.64EPSS
CVE-2023-34468
Alta 8.8

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates th…

apache nifi
0.64EPSS
CVE-2022-23302
Alta 8.8

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a Topi…

apache log4j · broadcom brocade_sannav · netapp snapmanager · oracle advanced_supply_chain_planning · e altri 22
0.64EPSS
CVE-2023-50968
Alta 7.5

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to up…

apache ofbiz
0.63EPSS
CVE-2021-36160
Alta 7.5

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).

apache http_server · broadcom brocade_fabric_operating_system_firmware · debian debian_linux · fedoraproject fedora · e altri 9
0.63EPSS
CVE-2007-5333
Media 5.0

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs …

apache tomcat
0.63EPSS
CVE-2000-0760
Media 6.4

The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

apache tomcat
0.62EPSS
CVE-2003-0245
Media 5.0

Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XM…

apache http_server
0.62EPSS
CVE-2021-30181
Critica 9.8

Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubb…

apache dubbo
0.61EPSS
CVE-2021-30180
Critica 9.8

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo custome…

apache dubbo
0.60EPSS
CVE-2019-17567
Media 5.3

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass throug…

apache http_server · fedoraproject fedora · oracle enterprise_manager_ops_center · oracle instantis_enterprisetrack · e altri 1
0.60EPSS
CVE-2013-5704
Media 5.0

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security is…

apache http_server · apple mac_os_x · apple mac_os_x_server · canonical ubuntu_linux · e altri 11
0.60EPSS
CVE-2025-31650
Alta 7.5

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfM…

apache tomcat
0.60EPSS
CVE-2011-4317
Media 4.3

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for …

apache http_server
0.60EPSS
CVE-2019-9511
Alta 7.5

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipu…

apache traffic_server · apple swiftnio · canonical ubuntu_linux · debian debian_linux · e altri 16
0.60EPSS
CVE-2024-27136
Media 6.1

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.

apache jspwiki
0.59EPSS
CVE-2019-0190
Alta 7.5

A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.…

apache http_server · oracle enterprise_manager_ops_center · oracle hospitality_guest_access · oracle instantis_enterprisetrack · e altri 1
0.59EPSS
CVE-2007-3386
Media 4.3

Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an h…

apache tomcat
0.59EPSS
CVE-2020-11993
Alta 7.5

Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_…

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 9
0.59EPSS
CVE-2002-0654
Media 5.0

Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when…

apache http_server
0.59EPSS
CVE-2012-1006
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName p…

apache struts
0.58EPSS
CVE-2018-11803
Alta 7.5

Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.

apache subversion · canonical ubuntu_linux
0.58EPSS
CVE-2007-1355
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to injec…

apache tomcat
0.58EPSS