Vulnerability index

Browse CVEs

25 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
HIGH 7.5 CVE-2012-0881EPSS 17% Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML servi… Xerces2 Java after 2.11.0 Fix from $1,9502017-10-30 HIGH 7.5 CVE-2012-0880 Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes has… Xerces C\+\+ Mitigation only Fix from $1,9502017-08-08 HIGH 7.5 CVE-2016-5396 Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack. Traffic Server Patch available Fix from $1,9502017-04-17 HIGH 7.5 CVE-2016-8740EPSS 79% The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-… HTTP Server Patch available Fix from $1,9502016-12-05 CRITICAL 9.1 CVE-2015-1832EPSS 12% XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows… Derby Mitigation only Fix from $2,3002016-10-03 MEDIUM 5.9 CVE-2016-1546EPSS 15% The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 con… HTTP Server Patch available Fix from $1,6002016-07-06 HIGH 7.8 CVE-2014-1972EPSS 10% Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attac… Tapestry after 5.3.5 Fix from $1,9502015-08-22 HIGH 7.8 CVE-2014-0230EPSS 20% Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishin… Tomcat Patch available Fix from $1,9502015-06-07 MEDIUM 5.0 CVE-2015-0248EPSS 12% The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of … Subversion Mitigation only Fix from $1,6002015-04-08 HIGH 7.8 CVE-2015-0202EPSS 8% The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large numbe… Subversion Mitigation only Fix from $1,9502015-04-08 MEDIUM 5.0 CVE-2014-3584EPSS 7% The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service … Cxf after 2.6.10 Fix from $1,6002014-10-30 MEDIUM 5.0 CVE-2014-3523EPSS 16% Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when … HTTP Server Patch available Fix from $1,6002014-07-20 MEDIUM 5.0 CVE-2014-0231EPSS 44% The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of ser… HTTP Server 2.2.29 / 2.4.10+ Fix from $1,6002014-07-20 MEDIUM 5.0 CVE-2013-2160EPSS 32% The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of s… Cxf Patch available Fix from $1,6002013-08-19 MEDIUM 5.0 CVE-2012-6551EPSS 8% The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of servic… Activemq after 5.7.0 Fix from $1,6002013-04-21 MEDIUM 5.0 CVE-2012-4557EPSS 17% The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-pr… HTTP Server Patch available Fix from $1,6002012-11-30 MEDIUM 5.0 CVE-2012-2145 Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file… Qpid after 0.17 Fix from $1,6002012-09-28 MEDIUM 5.0 CVE-2012-0213EPSS 8% The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial… Poi after 3.8 Fix from $1,6002012-08-07 MEDIUM 5.0 CVE-2011-4858EPSS 80% Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to tri… Tomcat No fix yet Fix from $1,6002012-01-05 MEDIUM 5.0 CVE-2011-4905EPSS 9% Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending ma… Activemq after 5.5.1 Fix from $1,6002012-01-05 MEDIUM 5.0 CVE-2007-6750EPSS 71% The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by… HTTP Server after 2.2.14 Fix from $1,6002011-12-27 MEDIUM 5.0 CVE-2011-0534EPSS 8% Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector… Tomcat Patch available Fix from $1,6002011-02-10 MEDIUM 6.8 CVE-2010-4539EPSS 5% The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote a… Subversion after 1.6.14 Fix from $1,6002011-01-07 HIGH 7.8 CVE-2007-6423 Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to tr… HTTP Server Mitigation only Fix from $1,9502008-01-12 MEDIUM 5.4 CVE-2005-3357EPSS 24% mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers … HTTP Server Patch available Fix from $1,6002005-12-31