Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Subversion HIGH 7.1
CVE-2013-2088EPSS 31%

contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary …

Fix: after 1.6.21
Fix from $1,950 2013-07-31
Struts MEDIUM 5.8
CVE-2013-2248EPSS 95%

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond…

Mitigation only
Fix from $1,600 2013-07-20
Tomcat MEDIUM 5.0
CVE-2012-3544EPSS 11%

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attac…

Patch available
Fix from $1,600 2013-06-01
Tomcat MEDIUM 5.0
CVE-2012-2733EPSS 9%

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not…

Mitigation only
Fix from $1,600 2012-11-16
Activemq MEDIUM 5.8
CVE-2012-5784EPSS 6%

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service impleme…

Fix: after 5.7.0
Fix from $1,600 2012-11-04
Axis2 MEDIUM 5.8
CVE-2012-5785

Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

Fix: after 1.6.2
Fix from $1,600 2012-11-04
Cxf MEDIUM 5.8
CVE-2012-5786

The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that …

Fix: after 2.6.17
Fix from $1,600 2012-11-04
Struts HIGH 10.0
CVE-2012-0838EPSS 14%

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to m…

Fix: after 2.2.3
Fix from $1,950 2012-03-02
Portable Runtime MEDIUM 5.0
CVE-2012-0840EPSS 43%

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash col…

Fix: after 1.4.5
Fix from $1,600 2012-02-10
Geronimo HIGH 7.8
CVE-2011-5034EPSS 81%

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, wh…

Fix: after 2.2.1
Fix from $1,950 2011-12-30
HTTP Server MEDIUM 5.0
CVE-2011-3368EPSS 91%

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with u…

Patch available
Fix from $1,600 2011-10-05
Tomcat MEDIUM 5.0
CVE-2011-1475EPSS 9%

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses…

Patch available
Fix from $1,600 2011-04-08
Axis2 HIGH 7.5
CVE-2010-1632EPSS 22%

Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through …

Fix: after 1.5.1
Fix from $1,950 2010-06-22
Activemq MEDIUM 5.0
CVE-2010-1587EPSS 78%

The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash …

Patch available
Fix from $1,600 2010-04-28
Tomcat MEDIUM 5.0
CVE-2009-0033EPSS 10%

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, a…

Patch available
Fix from $1,600 2009-06-05
Struts MEDIUM 5.0
CVE-2008-6504EPSS 36%

ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly…

Patch available
Fix from $1,600 2009-03-23
Xerces C\+\+ HIGH 7.8
CVE-2008-4482

The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML sc…

Fix: after 2.8.0
Fix from $1,950 2008-10-08
Mod Perl MEDIUM 5.0
CVE-2007-1349EPSS 10%

PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expressi…

Fix: 1.30+
Fix from $1,600 2007-03-30