Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2025-47869
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc applic…
Nuttx
12.9.0+
CRITICAL 9.8
CVE-2025-35003
Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache Nut…
Nuttx
12.9.0+
HIGH 8.8
CVE-2021-43083
Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport.…
Plc4x
0.9.1+
CRITICAL 9.8
CVE-2019-17562
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vul…
Cloudstack
4.13.1.0+
HIGH 7.5
CVE-2018-11768EPSS 7%
In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across …
Hadoop
after 3.1.1
HIGH 7.5
CVE-2018-11793
When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 …
Mesos
1.4.3 / 1.5.2+
MEDIUM 5.9
CVE-2018-1301EPSS 15%
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is re…
HTTP Server
after 2.4.29
CRITICAL 9.8
CVE-2015-3249EPSS 5%
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces…
Traffic Server
Mitigation only
HIGH 7.5
CVE-2016-6817EPSS 7%
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger …
Tomcat
Mitigation only
CRITICAL 9.8
CVE-2017-7679EPSS 39%
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Typ…
HTTP Server
2.2.33 / 2.4.26+
CRITICAL 9.8
CVE-2016-6808EPSS 19%
Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
Tomcat Jk Connector
1.2.42+
HIGH 8.1
CVE-2016-5017EPSS 8%
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers…
Zookeeper
after 3.4.8
HIGH 7.5
CVE-2016-4463EPSS 14%
Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.
Xerces C\+\+
after 3.1.3
HIGH 7.6
CVE-2015-5343EPSS 30%
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users t…
Subversion
1.8.15 / 1.9.3+
HIGH 8.6
CVE-2015-5259EPSS 57%
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar…
Subversion
Mitigation only
MEDIUM 5.0
CVE-2014-10022EPSS 6%
Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.
Traffic Server
after 5.1.1
MEDIUM 5.0
CVE-2014-3583EPSS 11%
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause …
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2013-2254
The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache S…
Org.apache.sling.servlets.post
Patch available
HIGH 7.5
CVE-2013-2210EPSS 6%
Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 al…
Xml Security For C\+\+
after 1.7.1
HIGH 7.5
CVE-2013-2154EPSS 8%
Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka …
Xml Security For C\+\+
after 1.7.0
HIGH 7.5
CVE-2013-2156EPSS 8%
Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++…
Xml Security For C\+\+
after 1.7.0
MEDIUM 5.0
CVE-2013-1884EPSS 51%
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault…
Subversion
Mitigation only
MEDIUM 5.0
CVE-2012-4460
The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial o…
Qpid
after 0.20
MEDIUM 5.0
CVE-2012-0256
Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to ca…
Traffic Server
Patch available
MEDIUM 5.0
CVE-2012-1181
fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual h…
Mod Fcgid
Patch available
MEDIUM 5.0
CVE-2010-1623EPSS 20%
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.…
Apr Util
2.0.64 / 2.2.17+
MEDIUM 6.4
CVE-2010-2227EPSS 55%
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows r…
Tomcat
Patch available
MEDIUM 5.0
CVE-2009-3560EPSS 24%
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to c…
HTTP Server
2.0.64 / 2.2.17+
HIGH 9.3
CVE-2009-3569EPSS 10%
Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a c…
Openoffice.org
No fix yet
HIGH 7.5
CVE-2007-6258EPSS 41%
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via …
Mod Jk
Patch available