Vulnerability index

Browse CVEs

130 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Cloudstack MEDIUM 5.0
CVE-2014-9593

Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

Fix: after 4.3.1
Fix from $1,600 2015-01-15
Shindig MEDIUM 5.0
CVE-2013-4295EPSS 12%

The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an externa…

Patch available
Fix from $1,600 2013-10-24
Tomcat MEDIUM 5.0
CVE-2011-3375EPSS 7%

Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request object…

Mitigation only
Fix from $1,600 2012-01-19
Struts MEDIUM 5.0
CVE-2011-2088EPSS 6%

XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive informati…

Patch available
Fix from $1,600 2011-05-13
HTTP Server MEDIUM 5.0
CVE-2010-2791EPSS 8%

mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon…

Mitigation only
Fix from $1,600 2010-08-05
HTTP Server MEDIUM 5.0
CVE-2010-2068EPSS 16%

mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in cer…

Patch available
Fix from $1,600 2010-06-18
Tomcat MEDIUM 5.0
CVE-2007-5333EPSS 63%

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5…

Fix: after 6.0.14
Fix from $1,600 2008-02-12
Axis MEDIUM 5.0
CVE-2007-2353EPSS 28%

Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path i…

No fix yet
Fix from $1,600 2007-04-30
Tomcat HIGH 7.8
CVE-2005-4836

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot…

No fix yet
Fix from $1,950 2005-12-31
Derby MEDIUM 5.0
CVE-2005-4849

Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b)…

Fix: after 10.1.1.0
Fix from $1,600 2005-12-31