imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2004-0174
Alta 7.5

Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket.…

apache http_server
0.12EPSS
CVE-2013-4352
Media 4.3

The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and daemon crash)…

apache http_server
0.12EPSS
CVE-2003-0789
Alta 10.0

mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.

apache http_server
0.12EPSS
CVE-2013-6408
Media 6.4

The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity refer…

apache solr
0.11EPSS
CVE-2013-6407
Media 6.4

The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

apache solr
0.11EPSS
CVE-2021-26117
Alta 7.5

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to v…

apache activemq · apache artemis · debian debian_linux · netapp oncommand_workflow_automation · e altri 4
0.11EPSS
CVE-2007-2834
Alta 9.3

Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers …

apache openoffice · canonical ubuntu_linux · debian debian_linux · sun staroffice · e altri 1
0.11EPSS
CVE-2016-0763
Media 6.3

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows…

apache tomcat · canonical ubuntu_linux · debian debian_linux
0.11EPSS
CVE-2016-4970
Alta 7.5

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

apache cassandra · netty netty · redhat jboss_data_grid · redhat jboss_middleware_text-only_advisories
0.11EPSS
CVE-2014-1881
Alta 7.5

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and waits a certain amount …

adobe phonegap · apache cordova
0.11EPSS
CVE-2017-5653
Media 5.3

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.

apache cxf
0.11EPSS
CVE-2023-22884
Critica 9.8

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Air…

apache airflow · apache apache-airflow-providers-mysql
0.11EPSS
CVE-2009-0039
Media 6.8

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web admi…

apache geronimo
0.11EPSS
CVE-2014-0032
Media 4.3

The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and…

apache subversion
0.11EPSS
CVE-2019-17195
Critica 9.8

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

apache hadoop · connect2id nimbus_jose\+jwt · oracle communications_cloud_native_core_security_edge_protection_proxy · oracle communications_pricing_design_center · e altri 11
0.11EPSS
CVE-2004-0113
Media 5.0

Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.

apache http_server
0.11EPSS
CVE-2012-3544
Media 5.0

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.

apache tomcat
0.11EPSS
CVE-2005-2728
Media 5.0

The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.

apache http_server
0.11EPSS
CVE-2001-0590
Media 5.0

Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).

apache tomcat
0.11EPSS
CVE-2015-5175
Alta 7.5

Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.

apache cxf_fediz
0.11EPSS
CVE-2019-17566
Alta 7.5

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary …

apache batik · oracle api_gateway · oracle business_intelligence · oracle communications_application_session_controller · e altri 14
0.11EPSS
CVE-2012-0022
Media 5.0

Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and param…

apache tomcat
0.11EPSS
CVE-2019-14439
Alta 7.5

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in t…

apache drill · debian debian_linux · fasterxml jackson-databind · fedoraproject fedora · e altri 14
0.11EPSS
CVE-2003-0993
Alta 7.5

mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.

apache http_server
0.11EPSS
CVE-2018-11780
Critica 9.8

A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

apache spamassassin · canonical ubuntu_linux · debian debian_linux · pdfinfo_project pdfinfo
0.11EPSS