imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2007-6514
Media 4.3

Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the inte…

apache http_server
0.38EPSS
CVE-2004-0488
Alta 7.5

Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.

apache http_server · debian debian_linux · redhat enterprise_linux_server · redhat enterprise_linux_workstation
0.38EPSS
CVE-2019-2684
Media 5.9

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated at…

apache cassandra · apache tomcat · canonical ubuntu_linux · debian debian_linux · e altri 13
0.38EPSS
CVE-2022-22733
Media 6.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere El…

apache shardingsphere_elasticjob-ui
0.38EPSS
CVE-2007-3382
Media 4.3

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to condu…

apache tomcat
0.37EPSS
CVE-2012-0393
Media 6.4

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.

apache struts
0.37EPSS
CVE-2014-0118
Media 4.3

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data …

apache http_server · debian debian_linux · redhat jboss_enterprise_application_platform
0.37EPSS
CVE-2025-68493
Alta 8.1

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

apache struts
0.37EPSS
CVE-2020-11981
Critica 9.8

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.

apache airflow
0.37EPSS
CVE-2019-17564
Critica 9.8

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue aff…

apache dubbo
0.37EPSS
CVE-2008-6504
Media 5.0

ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph N…

apache struts · opensymphony xwork
0.36EPSS
CVE-2008-5518
Alta 9.4

Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group…

apache geronimo
0.36EPSS
CVE-2016-3092
Alta 7.5

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consum…

apache commons_fileupload · apache tomcat · canonical ubuntu_linux · debian debian_linux · e altri 2
0.36EPSS
CVE-2014-0117
Media 4.3

The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.

apache http_server · apple mac_os_x
0.36EPSS
CVE-2024-39573
Alta 7.5

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

apache http_server · netapp ontap
0.35EPSS
CVE-1999-1412
Media 5.0

A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

apache http_server · apple macos
0.35EPSS
CVE-2010-2103
Media 4.3

Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows…

apache axis2
0.35EPSS
CVE-2016-1000031
Critica 9.8

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

apache commons_fileupload
0.35EPSS
CVE-2020-9483
Alta 7.5

**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implemen…

apache skywalking
0.35EPSS
CVE-2000-0913
Media 5.0

mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.

apache http_server
0.35EPSS
CVE-2012-1007
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/pro…

apache struts
0.34EPSS
CVE-2020-1947
Critica 9.8

In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshallin…

apache shardingsphere
0.34EPSS
CVE-2004-0492
Alta 10.0

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large a…

apache http_server · hp virtualvault · hp vvos · hp webproxy · e altri 3
0.34EPSS
CVE-2020-13921
Critica 9.8

**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.

apache skywalking
0.33EPSS
CVE-2011-4367
Media 5.0

Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.reso…

apache myfaces
0.33EPSS