imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2014-0230
Alta 7.8

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread con…

apache tomcat · oracle virtualization
0.20EPSS
CVE-2017-3167
Critica 9.8

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.

apache http_server · apple mac_os_x · debian debian_linux · netapp clustered_data_ontap · e altri 10
0.20EPSS
CVE-2022-26377
Alta 7.5

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Ser…

apache http_server · fedoraproject fedora · netapp clustered_data_ontap
0.20EPSS
CVE-2010-1623
Media 5.0

Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers …

apache apr-util · apache http_server
0.20EPSS
CVE-2018-1322
Media 4.9

An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.

apache syncope
0.20EPSS
CVE-2018-17189
Media 5.3

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connec…

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 8
0.20EPSS
CVE-2014-0075
Media 5.0

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remote attackers to cause a denial of service (resource consumptio…

apache tomcat
0.20EPSS
CVE-2019-0196
Media 5.3

A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectl…

apache http_server · canonical ubuntu_linux · debian debian_linux
0.20EPSS
CVE-2017-3169
Critica 9.8

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.

apache http_server
0.20EPSS
CVE-1999-0107
Media 5.0

Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.

apache http_server
0.20EPSS
CVE-2007-1358
Bassa 2.6

Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 261…

apache tomcat
0.20EPSS
CVE-2020-13925
Critica 9.8

Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to exec…

apache kylin
0.20EPSS
CVE-2016-4975
Media 6.1

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed i…

apache http_server
0.20EPSS
CVE-2016-2168
Media 6.5

The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in …

apache subversion
0.20EPSS
CVE-2008-0128
Media 5.0

The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for …

apache tomcat
0.20EPSS
CVE-2016-3082
Critica 9.8

XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.

apache struts
0.20EPSS
CVE-2021-33813
Alta 7.5

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

apache solr · apache tika · debian debian_linux · fedoraproject fedora · e altri 2
0.19EPSS
CVE-2017-3164
Alta 7.5

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reach…

apache solr
0.19EPSS
CVE-2018-8013
Critica 9.8

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling ne…

apache batik · canonical ubuntu_linux · debian debian_linux · oracle business_intelligence · e altri 17
0.19EPSS
CVE-2008-0456
Bassa 2.6

CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary…

apache http_server · redhat enterprise_linux_desktop · redhat enterprise_linux_server · redhat enterprise_linux_workstation
0.19EPSS
CVE-2016-6808
Critica 9.8

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

apache tomcat_jk_connector
0.19EPSS
CVE-2017-9800
Critica 9.8

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing…

apache subversion
0.19EPSS
CVE-2021-21295
Media 5.9

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that …

apache kudu · apache zookeeper · debian debian_linux · netapp oncommand_api_services · e altri 4
0.19EPSS
CVE-2015-0228
Media 5.0

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called t…

apache http_server · apple mac_os_x · apple mac_os_x_server · canonical ubuntu_linux · e altri 1
0.19EPSS
CVE-2016-4979
Alta 7.5

The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by …

apache http_server
0.19EPSS