Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.1 CVE-2013-2088EPSS 31% contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary … Subversion after 1.6.21 Fix from $1,9502013-07-31 MEDIUM 5.8 CVE-2013-2248EPSS 95% Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond… Struts Mitigation only Fix from $1,6002013-07-20 MEDIUM 5.0 CVE-2012-3544EPSS 11% Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attac… Tomcat Patch available Fix from $1,6002013-06-01 MEDIUM 5.0 CVE-2012-2733EPSS 9% java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not… Tomcat Mitigation only Fix from $1,6002012-11-16 MEDIUM 5.8 CVE-2012-5784EPSS 6% Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service impleme… Activemq after 5.7.0 Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5785 Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam… Axis2 after 1.6.2 Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5786 The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that … Cxf after 2.6.17 Fix from $1,6002012-11-04 HIGH 10.0 CVE-2012-0838EPSS 14% Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to m… Struts after 2.2.3 Fix from $1,9502012-03-02 MEDIUM 5.0 CVE-2012-0840EPSS 43% tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash col… Portable Runtime after 1.4.5 Fix from $1,6002012-02-10 HIGH 7.8 CVE-2011-5034EPSS 81% Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, wh… Geronimo after 2.2.1 Fix from $1,9502011-12-30 MEDIUM 5.0 CVE-2011-3368EPSS 91% The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with u… HTTP Server Patch available Fix from $1,6002011-10-05 MEDIUM 5.0 CVE-2011-1475EPSS 9% The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses… Tomcat Patch available Fix from $1,6002011-04-08 HIGH 7.5 CVE-2010-1632EPSS 22% Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through … Axis2 after 1.5.1 Fix from $1,9502010-06-22 MEDIUM 5.0 CVE-2010-1587EPSS 78% The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash … Activemq Patch available Fix from $1,6002010-04-28 MEDIUM 5.0 CVE-2009-0033EPSS 10% Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, a… Tomcat Patch available Fix from $1,6002009-06-05 MEDIUM 5.0 CVE-2008-6504EPSS 36% ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly… Struts Patch available Fix from $1,6002009-03-23 HIGH 7.8 CVE-2008-4482 The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML sc… Xerces C\+\+ after 2.8.0 Fix from $1,9502008-10-08 MEDIUM 5.0 CVE-2007-1349EPSS 10% PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expressi… Mod Perl 1.30+ Fix from $1,6002007-03-30