imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2011-1772
Bassa 2.6

Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the acti…

apache struts · opensymphony webwork · opensymphony xwork
0.33EPSS
CVE-2019-0235
Alta 8.8

Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

apache ofbiz
0.33EPSS
CVE-2003-0866
Media 5.0

The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.

apache tomcat
0.33EPSS
CVE-2014-0002
Alta 7.5

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity ref…

apache camel
0.33EPSS
CVE-2013-2160
Media 5.0

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) ne…

apache cxf
0.32EPSS
CVE-2006-0254
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by th…

apache geronimo
0.32EPSS
CVE-2013-2088
Alta 7.1

contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.

apache subversion · collabnet subversion · opensuse opensuse
0.31EPSS
CVE-1999-0678
Media 5.0

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

apache http_server
0.31EPSS
CVE-2003-1172
Media 5.0

Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.

apache cocoon
0.31EPSS
CVE-2012-0021
Bassa 2.6

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (da…

apache http_server
0.31EPSS
CVE-2002-2006
Media 5.0

The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.

apache tomcat
0.31EPSS
CVE-2005-2700
Alta 10.0

ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access…

apache http_server · canonical ubuntu_linux · debian debian_linux
0.31EPSS
CVE-2011-0419
Media 4.3

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6…

apache http_server · apache portable_runtime · apple mac_os_x · debian debian_linux · e altri 6
0.30EPSS
CVE-2009-2625
Media 5.0

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and applica…

apache xerces2_java · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 5
0.30EPSS
CVE-2015-5343
Alta 7.6

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code…

apache subversion · debian debian_linux
0.30EPSS
CVE-2019-10086
Alta 7.3

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default charac…

apache commons_beanutils · apache nifi · debian debian_linux · fedoraproject fedora · e altri 56
0.30EPSS
CVE-2020-11975
Critica 9.8

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

apache unomi
0.30EPSS
CVE-2005-2090
Media 4.3

Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Con…

apache tomcat
0.30EPSS
CVE-2009-0796
Bassa 2.6

Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.

apache mod_perl
0.30EPSS
CVE-1999-0070
Media 5.0

test-cgi program allows an attacker to list files on the server.

apache http_server
0.30EPSS
CVE-2013-1896
Media 4.3

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by t…

apache http_server · canonical ubuntu_linux · opensuse opensuse · redhat enterprise_linux_desktop · e altri 5
0.29EPSS
CVE-2020-9480
Critica 9.8

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application'…

apache spark · oracle business_intelligence
0.29EPSS
CVE-2023-37941
Media 6.6

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is t…

apache superset
0.29EPSS
CVE-2005-1344
Alta 7.5

Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escala…

apache http_server
0.29EPSS
CVE-2011-5057
Media 5.0

Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to …

apache struts
0.29EPSS