imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2021-21347
Media 6.1

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · e altri 12
0.14EPSS
CVE-2024-21733
Media 5.3

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade …

apache tomcat
0.14EPSS
CVE-2013-2249
Alta 7.5

mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vecto…

apache http_server
0.14EPSS
CVE-2005-2970
Media 5.0

Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other c…

apache http_server · canonical ubuntu_linux · fedoraproject fedora_core · redhat enterprise_linux_desktop · e altri 2
0.14EPSS
CVE-2009-2699
Alta 7.5

The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attack…

apache http_server · apache portable_runtime
0.14EPSS
CVE-2016-4463
Alta 7.5

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

apache xerces-c\+\+ · debian debian_linux
0.14EPSS
CVE-2012-2138
Media 5.0

The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite …

apache org.apache.sling.servlets.post
0.14EPSS
CVE-2009-2949
Alta 9.3

Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.14EPSS
CVE-2013-4444
Media 6.8

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

apache tomcat
0.14EPSS
CVE-2020-11971
Alta 7.5

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.

apache camel · oracle communications_diameter_intelligence_hub · oracle communications_diameter_signaling_router · oracle enterprise_manager_base_platform · e altri 1
0.14EPSS
CVE-2012-0838
Alta 10.0

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

apache struts
0.14EPSS
CVE-2014-7810
Media 5.0

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypas…

apache tomcat · debian debian_linux
0.14EPSS
CVE-2019-12419
Critica 9.8

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to …

apache cxf · oracle commerce_guided_search · oracle enterprise_manager_base_platform · oracle flexcube_private_banking · e altri 1
0.14EPSS
CVE-2004-0885
Alta 7.5

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

apache http_server
0.14EPSS
CVE-2021-21348
Media 5.3

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · e altri 12
0.14EPSS
CVE-2013-2135
Alta 9.3

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.

apache struts
0.14EPSS
CVE-2015-4551
Media 4.3

LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafte…

apache openoffice · canonical ubuntu_linux · debian debian_linux · libreoffice libreoffice
0.14EPSS
CVE-2014-0107
Alta 7.5

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access exter…

apache xalan-java · oracle webcenter_sites
0.14EPSS
CVE-2009-2412
Alta 10.0

Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vector…

apache apr-util · apache portable_runtime
0.14EPSS
CVE-2012-1149
Alta 7.5

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embed…

apache openoffice.org · debian debian_linux · fedoraproject fedora · libreoffice libreoffice · e altri 6
0.14EPSS
CVE-2012-0037
Media 6.5

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) decl…

apache openoffice · debian debian_linux · fedoraproject fedora · librdf raptor · e altri 9
0.14EPSS
CVE-2020-11987
Alta 8.2

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET…

apache batik · debian debian_linux · fedoraproject fedora · oracle agile_engineering_data_management · e altri 18
0.14EPSS
CVE-2002-0682
Alta 7.5

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

apache tomcat
0.14EPSS
CVE-2014-3581
Media 5.0

The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-T…

apache http_server · canonical ubuntu_linux · oracle enterprise_manager_ops_center · oracle linux · e altri 5
0.14EPSS
CVE-2019-20445
Critica 9.1

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

apache spark · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 3
0.13EPSS