imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2012-1592
Alta 8.8

A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.

apache struts
0.29EPSS
CVE-2022-22720
Critica 9.8

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

apache http_server · apple mac_os_x · apple macos · debian debian_linux · e altri 4
0.28EPSS
CVE-2026-49975
Alta 7.5

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

apache http_server · debian debian_linux
0.28EPSS
CVE-2009-3720
Media 5.0

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 se…

apache http_server · libexpat_project libexpat
0.28EPSS
CVE-2019-9517
Alta 7.5

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer …

apache http_server · apache traffic_server · apple swiftnio · canonical ubuntu_linux · e altri 19
0.28EPSS
CVE-2006-5752
Media 4.3

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecif…

apache http_server · canonical ubuntu_linux · fedoraproject fedora · redhat enterprise_linux_desktop · e altri 3
0.28EPSS
CVE-2007-2353
Media 5.0

Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.

apache axis
0.28EPSS
CVE-2002-0936
Media 5.0

The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).

apache tomcat
0.27EPSS
CVE-2002-1567
Media 6.8

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.

apache tomcat
0.27EPSS
CVE-2013-6438
Media 5.0

The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a craft…

apache http_server · canonical ubuntu_linux · oracle http_server
0.27EPSS
CVE-2020-11996
Alta 7.5

A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connec…

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp oncommand_system_manager · e altri 4
0.27EPSS
CVE-2007-4465
Media 6.1

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 c…

apache http_server
0.26EPSS
CVE-1999-0045
Alta 7.5

List of arbitrary files on Web host via nph-test-cgi script.

apache http_server · netscape commerce_server · netscape communications_server · netscape enterprise_server
0.26EPSS
CVE-2014-0098
Media 5.0

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during …

apache http_server · canonical ubuntu_linux · oracle http_server · oracle secure_global_desktop
0.26EPSS
CVE-2024-38473
Alta 8.1

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, wh…

apache http_server · netapp ontap
0.26EPSS
CVE-1999-0236
Alta 7.5

ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.

apache http_server · illinois ncsa_httpd
0.26EPSS
CVE-2018-8033
Alta 7.5

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain …

apache ofbiz
0.26EPSS
CVE-2016-1182
Alta 8.2

ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-…

apache struts
0.26EPSS
CVE-2005-3745
Media 4.3

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an err…

apache struts
0.26EPSS
CVE-2005-4703
Media 5.0

Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nik…

apache tomcat
0.26EPSS
CVE-2000-0759
Media 6.4

Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.

apache tomcat
0.26EPSS
CVE-2019-9518
Alta 7.5

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION a…

apache traffic_server · apple swiftnio · canonical ubuntu_linux · debian debian_linux · e altri 14
0.25EPSS
CVE-2022-32532
Critica 9.8

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

apache shiro
0.25EPSS
CVE-2021-41524
Alta 7.5

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49.…

apache http_server · fedoraproject fedora · netapp cloud_backup · oracle instantis_enterprisetrack
0.25EPSS
CVE-2020-13944
Media 6.1

In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.

apache airflow
0.25EPSS