imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2014-0094
Media 5.0

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

apache struts
1.00EPSS
CVE-2021-25646
Alta 8.8

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possibl…

apache druid
0.99EPSS
CVE-2011-3192
Alta 7.8

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited i…

apache http_server · canonical ubuntu_linux · opensuse opensuse · suse linux_enterprise_server · e altri 1
0.99EPSS
CVE-2020-9496
Media 6.1

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

apache ofbiz
0.99EPSS
CVE-2012-0392
Media 6.8

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.

apache struts
0.98EPSS
CVE-2019-5736
Alta 8.6

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of contain…

apache mesos · canonical ubuntu_linux · d2iq dc\/os · d2iq kubernetes_engine · e altri 15
0.98EPSS
CVE-2014-0112
Alta 7.5

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists becau…

apache struts
0.98EPSS
CVE-2021-44832
Media 6.6

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of…

apache log4j · cisco cloudcenter · debian debian_linux · fedoraproject fedora · e altri 18
0.98EPSS
CVE-2021-26295
Critica 9.8

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

apache ofbiz
0.98EPSS
CVE-2020-1943
Media 6.1

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

apache ofbiz
0.97EPSS
CVE-2019-0230
Critica 9.8

Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

apache struts · oracle communications_policy_management · oracle financial_services_data_integration_hub · oracle financial_services_market_risk_measurement_and_management · e altri 1
0.97EPSS
CVE-2021-44790
Critica 9.8

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue aff…

apache http_server · apple mac_os_x · apple macos · debian debian_linux · e altri 10
0.97EPSS
CVE-2006-3747
Alta 7.6

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash…

apache http_server · canonical ubuntu_linux · debian debian_linux
0.96EPSS
CVE-2014-0114
Alta 7.5

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate"…

apache commons_beanutils · apache struts
0.96EPSS
CVE-2023-51467
Critica 9.8

The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

apache ofbiz
0.96EPSS
CVE-2023-25194
Alta 8.8

A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security proto…

apache kafka_connect
0.96EPSS
CVE-2023-49070
Critica 9.8

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

apache ofbiz
0.95EPSS
CVE-2002-0840
Media 6.8

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors…

apache http_server · oracle application_server · oracle database_server · oracle oracle8i · e altri 1
0.95EPSS
CVE-2002-0392
Alta 7.5

Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.

apache http_server · debian debian_linux
0.95EPSS
CVE-2017-9798
Alta 7.5

Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and …

apache http_server · debian debian_linux
0.95EPSS
CVE-2006-3918
Media 4.3

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an e…

apache http_server · canonical ubuntu_linux · debian debian_linux · redhat enterprise_linux_server · e altri 1
0.95EPSS
CVE-2013-2248
Media 5.8

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.

apache struts
0.95EPSS
CVE-2024-31309
Alta 7.5

HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minut…

apache traffic_server · debian debian_linux · fedoraproject fedora
0.95EPSS
CVE-2018-11784
Media 4.3

When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redir…

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp snap_creator_framework · e altri 11
0.94EPSS
CVE-2009-0580
Media 4.3

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to im…

apache tomcat
0.94EPSS