Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Nuttx CRITICAL 9.8
CVE-2025-47869

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc applic…

Fix: 12.9.0+
Fix from $2,300 2025-06-16
Nuttx CRITICAL 9.8
CVE-2025-35003

Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache Nut…

Fix: 12.9.0+
Fix from $2,300 2025-05-26
Plc4x HIGH 8.8
CVE-2021-43083

Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport.…

Fix: 0.9.1+
Fix from $1,950 2021-12-19
Cloudstack CRITICAL 9.8
CVE-2019-17562

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vul…

Fix: 4.13.1.0+
Fix from $2,300 2020-05-14
Hadoop HIGH 7.5
CVE-2018-11768EPSS 7%

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across …

Fix: after 3.1.1
Fix from $1,950 2019-10-04
Mesos HIGH 7.5
CVE-2018-11793

When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 …

Fix: 1.4.3 / 1.5.2+
Fix from $1,950 2019-03-05
HTTP Server MEDIUM 5.9
CVE-2018-1301EPSS 15%

A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is re…

Fix: after 2.4.29
Fix from $1,600 2018-03-26
Traffic Server CRITICAL 9.8
CVE-2015-3249EPSS 5%

The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces…

Mitigation only
Fix from $2,300 2017-10-30
Tomcat HIGH 7.5
CVE-2016-6817EPSS 7%

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger …

Mitigation only
Fix from $1,950 2017-08-10
HTTP Server CRITICAL 9.8
CVE-2017-7679EPSS 39%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Typ…

Fix: 2.2.33 / 2.4.26+
Fix from $2,300 2017-06-20
Tomcat Jk Connector CRITICAL 9.8
CVE-2016-6808EPSS 19%

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

Fix: 1.2.42+
Fix from $2,300 2017-04-12
Zookeeper HIGH 8.1
CVE-2016-5017EPSS 8%

Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers…

Fix: after 3.4.8
Fix from $1,950 2016-09-21
Xerces C\+\+ HIGH 7.5
CVE-2016-4463EPSS 14%

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

Fix: after 3.1.3
Fix from $1,950 2016-07-08
Subversion HIGH 7.6
CVE-2015-5343EPSS 30%

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users t…

Fix: 1.8.15 / 1.9.3+
Fix from $1,950 2016-04-14
Subversion HIGH 8.6
CVE-2015-5259EPSS 57%

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2016-01-08
Traffic Server MEDIUM 5.0
CVE-2014-10022EPSS 6%

Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.

Fix: after 5.1.1
Fix from $1,600 2015-01-13
HTTP Server MEDIUM 5.0
CVE-2014-3583EPSS 11%

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause …

Mitigation only
Fix from $1,600 2014-12-15
Org.apache.sling.servlets.post MEDIUM 5.0
CVE-2013-2254

The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache S…

Patch available
Fix from $1,600 2013-10-17
Xml Security For C\+\+ HIGH 7.5
CVE-2013-2210EPSS 6%

Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 al…

Fix: after 1.7.1
Fix from $1,950 2013-08-20
Xml Security For C\+\+ HIGH 7.5
CVE-2013-2154EPSS 8%

Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka …

Fix: after 1.7.0
Fix from $1,950 2013-08-20
Xml Security For C\+\+ HIGH 7.5
CVE-2013-2156EPSS 8%

Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++…

Fix: after 1.7.0
Fix from $1,950 2013-08-20
Subversion MEDIUM 5.0
CVE-2013-1884EPSS 51%

The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault…

Mitigation only
Fix from $1,600 2013-05-02
Qpid MEDIUM 5.0
CVE-2012-4460

The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial o…

Fix: after 0.20
Fix from $1,600 2013-03-14
Traffic Server MEDIUM 5.0
CVE-2012-0256

Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to ca…

Patch available
Fix from $1,600 2012-03-26
Mod Fcgid MEDIUM 5.0
CVE-2012-1181

fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual h…

Patch available
Fix from $1,600 2012-03-19
Apr Util MEDIUM 5.0
CVE-2010-1623EPSS 20%

Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.…

Fix: 2.0.64 / 2.2.17+
Fix from $1,600 2010-10-04
Tomcat MEDIUM 6.4
CVE-2010-2227EPSS 55%

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows r…

Patch available
Fix from $1,600 2010-07-13
HTTP Server MEDIUM 5.0
CVE-2009-3560EPSS 24%

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to c…

Fix: 2.0.64 / 2.2.17+
Fix from $1,600 2009-12-04
Openoffice.org HIGH 9.3
CVE-2009-3569EPSS 10%

Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a c…

No fix yet
Fix from $1,950 2009-10-06
Mod Jk HIGH 7.5
CVE-2007-6258EPSS 41%

Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via …

Patch available
Fix from $1,950 2008-02-19