imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2003-0460
Media 5.0

The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.

apache http_server
0.13EPSS
CVE-2009-2950
Alta 9.3

Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a…

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.13EPSS
CVE-2012-2149
Alta 7.5

The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD document that causes a negative array index …

apache openoffice.org · libwpd libwpd · redhat enterprise_linux__optional_productivity_applications · redhat enterprise_linux_desktop
0.13EPSS
CVE-2015-0254
Alta 7.5

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.

apache standard_taglibs · canonical ubuntu_linux
0.13EPSS
CVE-2014-3529
Media 4.3

The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

apache poi
0.13EPSS
CVE-2016-8743
Alta 7.5

Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain…

apache http_server · debian debian_linux · netapp clustered_data_ontap · netapp oncommand_unified_manager · e altri 7
0.13EPSS
CVE-2013-4365
Alta 7.5

Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.

apache mod_fcgid · debian debian_linux · opensuse opensuse · suse cloud · e altri 1
0.13EPSS
CVE-2017-5648
Critica 9.1

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted applic…

apache tomcat
0.13EPSS
CVE-2018-1302
Media 5.9

When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger …

apache http_server · canonical ubuntu_linux · netapp clustered_data_ontap · netapp santricity_cloud_connector · e altri 2
0.13EPSS
CVE-2016-1181
Alta 8.1

ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a relat…

apache struts · oracle banking_platform · oracle portal
0.13EPSS
CVE-2016-0714
Alta 8.8

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and …

apache tomcat · canonical ubuntu_linux · debian debian_linux
0.13EPSS
CVE-2012-2334
Media 6.8

Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length o…

apache openoffice.org · libreoffice libreoffice
0.13EPSS
CVE-2021-36090
Alta 7.5

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Com…

apache commons_compress · netapp active_iq_unified_manager · netapp oncommand_insight · oracle banking_apis · e altri 30
0.13EPSS
CVE-2007-1860
Media 5.0

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving do…

apache tomcat_jk_web_server_connector
0.13EPSS
CVE-2007-3847
Media 5.0

The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-rea…

apache http_server · canonical ubuntu_linux · fedoraproject fedora · fedoraproject fedora_core
0.13EPSS
CVE-2015-5213
Media 6.8

Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overf…

apache openoffice · canonical ubuntu_linux · debian debian_linux · libreoffice libreoffice
0.13EPSS
CVE-2014-3576
Alta 7.5

The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.

apache activemq · oracle business_intelligence_publisher · oracle fusion_middleware
0.13EPSS
CVE-2003-0542
Alta 7.2

Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.…

apache http_server
0.13EPSS
CVE-2008-2364
Media 5.0

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory c…

apache http_server · canonical ubuntu_linux · fedoraproject fedora · redhat enterprise_linux_desktop · e altri 3
0.13EPSS
CVE-2016-2170
Critica 9.8

Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

apache ofbiz
0.13EPSS
CVE-2012-2098
Media 5.0

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeati…

apache commons_compress
0.13EPSS
CVE-2009-3095
Media 5.0

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstra…

apache http_server · apple mac_os_x · debian debian_linux · fedoraproject fedora · e altri 3
0.13EPSS
CVE-2015-5174
Media 4.3

Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash do…

apache tomcat · canonical ubuntu_linux · debian debian_linux
0.13EPSS
CVE-2002-1592
Media 5.0

The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.

apache http_server
0.12EPSS
CVE-2009-1191
Media 5.0

mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.

apache http_server · canonical ubuntu_linux
0.12EPSS