imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2015-3185
Media 4.3

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers…

apache http_server · apple mac_os_x · apple mac_os_x_server · apple xcode · e altri 1
0.19EPSS
CVE-2015-5262
Media 4.3

http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspe…

apache httpclient · canonical ubuntu_linux · fedoraproject fedora
0.19EPSS
CVE-2008-5515
Media 5.0

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass inte…

apache tomcat
0.19EPSS
CVE-2002-1148
Media 5.0

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

apache tomcat
0.19EPSS
CVE-2019-0220
Media 5.3

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while oth…

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 1
0.18EPSS
CVE-2010-0434
Media 4.3

The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might …

apache http_server · debian debian_linux · fedoraproject fedora
0.18EPSS
CVE-2025-61734
Alta 7.5

Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upg…

apache kylin
0.18EPSS
CVE-2015-5345
Media 5.3

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a direct…

apache tomcat · canonical ubuntu_linux · debian debian_linux
0.18EPSS
CVE-2010-5312
Media 6.1

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

apache drill · debian debian_linux · drupal drupal · fedoraproject fedora · e altri 2
0.18EPSS
CVE-2007-1858
Bassa 2.6

The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have oth…

apache tomcat
0.18EPSS
CVE-2021-25122
Alta 7.5

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could …

apache tomcat · debian debian_linux · oracle agile_plm · oracle communications_cloud_native_core_policy · e altri 8
0.18EPSS
CVE-2015-6420
Critica 9.8

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching…

apache commons_collections
0.18EPSS
CVE-2009-0038
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) descripti…

apache geronimo
0.18EPSS
CVE-2017-15710
Alta 7.5

In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header v…

apache http_server · canonical ubuntu_linux · debian debian_linux · netapp clustered_data_ontap · e altri 4
0.18EPSS
CVE-2024-41107
Alta 8.1

The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiates CloudStack SAML single sign-on authentication can bypass SAML authentication …

apache cloudstack
0.18EPSS
CVE-2017-15708
Critica 9.8

In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecti…

apache synapse · oracle financial_services_market_risk_measurement_and_management · oracle peoplesoft_enterprise_peopletools
0.18EPSS
CVE-2018-1321
Alta 7.2

An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including…

apache syncope
0.18EPSS
CVE-2020-25649
Alta 7.5

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

apache iotdb · fasterxml jackson-databind · fedoraproject fedora · netapp oncommand_api_services · e altri 35
0.18EPSS
CVE-2012-4557
Media 5.0

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive…

apache http_server
0.17EPSS
CVE-2012-0881
Alta 7.5

Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.

apache xerces2_java
0.17EPSS
CVE-2003-0083
Media 5.0

Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escap…

apache http_server
0.17EPSS
CVE-2002-1850
Alta 7.5

mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between htt…

apache http_server
0.17EPSS
CVE-2018-1285
Critica 9.8

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

apache log4net · fedoraproject fedora · netapp manageability_software_development_kit · netapp snapcenter · e altri 3
0.17EPSS
CVE-2019-0217
Alta 7.5

In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 10
0.17EPSS
CVE-2016-6814
Critica 9.8

When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an atta…

apache groovy · redhat enterprise_linux_server
0.17EPSS