imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2014-3583
Media 5.0

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.

apache http_server · apple mac_os_x · apple os_x_server · canonical ubuntu_linux
0.11EPSS
CVE-2009-2902
Media 4.3

Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.

apache tomcat
0.11EPSS
CVE-2014-3580
Media 5.0

The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

apache subversion · apple xcode · debian debian_linux · redhat enterprise_linux_desktop · e altri 4
0.11EPSS
CVE-2008-3282
Alta 7.8

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitr…

apache openoffice · fedoraproject fedora
0.11EPSS
CVE-2010-3450
Alta 9.3

Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspe…

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.11EPSS
CVE-2018-8038
Alta 7.5

Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.

apache cxf_fediz
0.11EPSS
CVE-2019-0215
Alta 7.5

In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.

apache http_server · fedoraproject fedora
0.11EPSS
CVE-2019-17563
Alta 7.5

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical b…

apache tomcat · canonical ubuntu_linux · debian debian_linux · opensuse leap · e altri 7
0.11EPSS
CVE-2021-35517
Alta 7.5

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Com…

apache commons_compress · netapp active_iq_unified_manager · netapp oncommand_insight · oracle banking_apis · e altri 23
0.11EPSS
CVE-2015-3184
Media 5.0

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.

apache subversion · apple xcode
0.11EPSS
CVE-2016-8749
Critica 9.8

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

apache camel
0.11EPSS
CVE-2015-5346
Alta 8.1

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web…

apache tomcat · canonical ubuntu_linux · debian debian_linux
0.11EPSS
CVE-2025-64408
Media 6.3

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authentic…

apache causeway
0.11EPSS
CVE-2018-8032
Media 6.1

Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

apache axis · debian debian_linux · oracle agile_engineering_data_management · oracle agile_product_lifecycle_management · e altri 34
0.11EPSS
CVE-2010-0395
Alta 9.3

OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory struct…

apache openoffice · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 2
0.11EPSS
CVE-2018-8039
Alta 8.1

It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the Hos…

apache cxf · redhat jboss_enterprise_application_platform
0.10EPSS
CVE-2011-1928
Media 4.3

The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of…

apache apr-util · apache http_server
0.10EPSS
CVE-2016-5018
Critica 9.1

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp oncommand_insight · e altri 11
0.10EPSS
CVE-2016-4465
Media 5.3

The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.

apache struts
0.10EPSS
CVE-2010-3454
Alta 9.3

Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typograph…

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.10EPSS
CVE-2010-3452
Alta 9.3

Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.10EPSS
CVE-2010-3451
Alta 9.3

Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in an RTF document.

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.10EPSS
CVE-2019-0225
Alta 7.5

A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.

apache jspwiki
0.10EPSS
CVE-2021-29425
Media 4.8

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not furthe…

apache commons_io · debian debian_linux · netapp active_iq_unified_manager · oracle access_manager · e altri 56
0.10EPSS
CVE-2011-0013
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name ta…

apache tomcat
0.10EPSS