Vulnerability index

Browse CVEs

25 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Xerces2 Java HIGH 7.5
CVE-2012-0881EPSS 17%

Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML servi…

Fix: after 2.11.0
Fix from $1,950 2017-10-30
Xerces C\+\+ HIGH 7.5
CVE-2012-0880

Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes has…

Mitigation only
Fix from $1,950 2017-08-08
Traffic Server HIGH 7.5
CVE-2016-5396

Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.

Patch available
Fix from $1,950 2017-04-17
HTTP Server HIGH 7.5
CVE-2016-8740EPSS 79%

The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-…

Patch available
Fix from $1,950 2016-12-05
Derby CRITICAL 9.1
CVE-2015-1832EPSS 12%

XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows…

Mitigation only
Fix from $2,300 2016-10-03
HTTP Server MEDIUM 5.9
CVE-2016-1546EPSS 15%

The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 con…

Patch available
Fix from $1,600 2016-07-06
Tapestry HIGH 7.8
CVE-2014-1972EPSS 10%

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attac…

Fix: after 5.3.5
Fix from $1,950 2015-08-22
Tomcat HIGH 7.8
CVE-2014-0230EPSS 20%

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishin…

Patch available
Fix from $1,950 2015-06-07
Subversion MEDIUM 5.0
CVE-2015-0248EPSS 12%

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2015-04-08
Subversion HIGH 7.8
CVE-2015-0202EPSS 8%

The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large numbe…

Mitigation only
Fix from $1,950 2015-04-08
Cxf MEDIUM 5.0
CVE-2014-3584EPSS 7%

The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service …

Fix: after 2.6.10
Fix from $1,600 2014-10-30
HTTP Server MEDIUM 5.0
CVE-2014-3523EPSS 16%

Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when …

Patch available
Fix from $1,600 2014-07-20
HTTP Server MEDIUM 5.0
CVE-2014-0231EPSS 44%

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of ser…

Fix: 2.2.29 / 2.4.10+
Fix from $1,600 2014-07-20
Cxf MEDIUM 5.0
CVE-2013-2160EPSS 32%

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of s…

Patch available
Fix from $1,600 2013-08-19
Activemq MEDIUM 5.0
CVE-2012-6551EPSS 8%

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of servic…

Fix: after 5.7.0
Fix from $1,600 2013-04-21
HTTP Server MEDIUM 5.0
CVE-2012-4557EPSS 17%

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-pr…

Patch available
Fix from $1,600 2012-11-30
Qpid MEDIUM 5.0
CVE-2012-2145

Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file…

Fix: after 0.17
Fix from $1,600 2012-09-28
Poi MEDIUM 5.0
CVE-2012-0213EPSS 8%

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial…

Fix: after 3.8
Fix from $1,600 2012-08-07
Tomcat MEDIUM 5.0
CVE-2011-4858EPSS 80%

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to tri…

No fix yet
Fix from $1,600 2012-01-05
Activemq MEDIUM 5.0
CVE-2011-4905EPSS 9%

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending ma…

Fix: after 5.5.1
Fix from $1,600 2012-01-05
HTTP Server MEDIUM 5.0
CVE-2007-6750EPSS 71%

The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by…

Fix: after 2.2.14
Fix from $1,600 2011-12-27
Tomcat MEDIUM 5.0
CVE-2011-0534EPSS 8%

Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector…

Patch available
Fix from $1,600 2011-02-10
Subversion MEDIUM 6.8
CVE-2010-4539EPSS 5%

The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote a…

Fix: after 1.6.14
Fix from $1,600 2011-01-07
HTTP Server HIGH 7.8
CVE-2007-6423

Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to tr…

Mitigation only
Fix from $1,950 2008-01-12
HTTP Server MEDIUM 5.4
CVE-2005-3357EPSS 24%

mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers …

Patch available
Fix from $1,600 2005-12-31