imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2022-47501
Alta 7.5

Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.

apache ofbiz
0.10EPSS
CVE-2000-1204
Media 5.0

Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.

apache http_server
0.10EPSS
CVE-2017-12626
Alta 7.5

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI b…

apache poi
0.10EPSS
CVE-2017-7675
Alta 7.5

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.

apache tomcat
0.10EPSS
CVE-2025-55754
Critica 9.6

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape …

apache tomcat
0.10EPSS
CVE-2007-1349
Media 5.0

PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.

apache mod_perl · canonical ubuntu_linux · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · e altri 3
0.10EPSS
CVE-2010-4643
Alta 9.3

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Of…

apache openoffice
0.10EPSS
CVE-2010-4253
Alta 9.3

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as d…

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.10EPSS
CVE-2007-0086
Alta 7.8

The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the sev…

apache http_server
0.10EPSS
CVE-2012-6612
Alta 7.5

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML …

apache solr
0.10EPSS
CVE-2009-0033
Media 5.0

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid hea…

apache tomcat
0.10EPSS
CVE-2026-27446
Critica 9.8

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an att…

apache artemis
0.10EPSS
CVE-2014-3600
Critica 9.8

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

apache activemq
0.10EPSS
CVE-2007-6422
Media 4.0

The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.…

apache http_server
0.10EPSS
CVE-2020-11986
Critica 9.8

To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build script to be invoked at load time of the project. Apache NetBeans up to and including 12.0 did not request con…

apache netbeans
0.10EPSS
CVE-2018-1283
Media 5.3

In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable…

apache http_server · canonical ubuntu_linux · debian debian_linux · netapp clustered_data_ontap · e altri 4
0.10EPSS
CVE-2018-1297
Critica 9.8

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

apache jmeter
0.10EPSS
CVE-2014-0033
Media 4.3

org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.

apache tomcat
0.10EPSS
CVE-2021-30640
Media 6.5

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to…

apache tomcat · debian debian_linux · oracle communications_cloud_native_core_policy · oracle communications_diameter_signaling_router · e altri 3
0.10EPSS
CVE-2021-26920
Media 6.5

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th…

apache druid
0.10EPSS
CVE-2016-0779
Critica 9.8

The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.

apache tomee
0.10EPSS
CVE-2014-3575
Media 4.3

The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.

apache openoffice · libreoffice libreoffice · redhat enterprise_linux_desktop · redhat enterprise_linux_server · e altri 1
0.10EPSS
CVE-2018-8041
Media 5.3

Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.

apache camel
0.10EPSS
CVE-2000-0672
Media 5.0

The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.

apache tomcat
0.10EPSS
CVE-2013-1777
Alta 10.0

The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitr…

apache geronimo · ibm websphere_application_server
0.10EPSS