imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2005-1266
Media 5.0

Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.

apache spamassassin
0.08EPSS
CVE-2013-4316
Alta 10.0

Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.

apache struts · oracle flexcube_private_banking · oracle mysql_enterprise_monitor · oracle webcenter_sites
0.08EPSS
CVE-2007-6421
Bassa 3.5

Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.

apache http_server
0.08EPSS
CVE-2024-42323
Alta 8.8

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to vers…

apache hertzbeat
0.08EPSS
CVE-2016-6796
Alta 7.5

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Ser…

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp oncommand_insight · e altri 11
0.08EPSS
CVE-2006-7197
Alta 7.8

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

apache tomcat
0.08EPSS
CVE-2018-21234
Critica 9.8

Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.

apache hive · jodd jodd
0.08EPSS
CVE-2010-2791
Media 5.0

mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response inten…

apache http_server
0.08EPSS
CVE-2016-5002
Alta 7.8

XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.

apache xml-rpc
0.08EPSS
CVE-2017-5650
Alta 7.5

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write m…

apache tomcat
0.08EPSS
CVE-2019-19603
Alta 7.5

SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.

apache guacamole · netapp cloud_backup · netapp ontap_select_deploy_administration_utility · oracle mysql_workbench · e altri 2
0.08EPSS
CVE-2020-11979
Alta 7.5

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said prote…

apache ant · fedoraproject fedora · gradle gradle · oracle agile_engineering_data_management · e altri 33
0.08EPSS
CVE-2015-5347
Media 6.1

Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attackers to in…

apache wicket
0.08EPSS
CVE-2018-11756
Critica 9.8

In PHP Runtime for Apache OpenWhisk, a Docker action inheriting one of the Docker tags openwhisk/action-php-v7.2:1.0.0 or openwhisk/action-php-v7.1:1.0.1 (or earlier) may allow an attacker to replace the user function inside the container if the user code is v…

apache openwhisk
0.08EPSS
CVE-2014-1884
Alta 7.5

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote attackers to bypass intended device-resource restrictions via content that is accessed (1) in an IFRA…

adobe phonegap · apache cordova
0.08EPSS
CVE-2014-0232
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors,…

apache ofbiz
0.08EPSS
CVE-2018-1320
Alta 7.5

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be dis…

apache thrift · debian debian_linux · f5 traffix_signaling_delivery_controller · oracle global_lifecycle_management_opatch · e altri 1
0.08EPSS
CVE-2001-0917
Media 5.0

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

apache tomcat
0.08EPSS
CVE-2017-9804
Alta 7.5

In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing valid…

apache struts
0.08EPSS
CVE-2001-0766
Critica 9.8

Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.

apache http_server
0.08EPSS
CVE-2012-5633
Media 5.8

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

apache cxf
0.08EPSS
CVE-1999-1237
Alta 10.0

Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified meth…

apache http_server
0.08EPSS
CVE-2018-11769
Alta 7.2

CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privile…

apache couchdb
0.08EPSS
CVE-2016-6795
Critica 9.8

In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.

apache struts
0.08EPSS
CVE-2009-2901
Media 4.3

The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements v…

apache tomcat
0.08EPSS