Vulnerability index

Browse CVEs

43 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Traffic Server HIGH 8.2
CVE-2026-58188

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 …

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58184

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58187

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apac…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58177

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Se…

Fix: 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server HIGH 8.9
CVE-2026-58154

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: fr…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Nimble HIGH 8.8
CVE-2026-45813

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS servic…

Fix: 1.10.0+
Fix from $1,950 2026-07-24
Fory CRITICAL 9.8
CVE-2026-64608

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
HTTP Server CRITICAL 9.8
CVE-2026-28780

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server …

Fix: 2.4.67+
Fix from $2,300 2026-05-05
Hadoop HIGH 7.3
CVE-2025-27821

Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recomme…

Fix: 3.4.2+
Fix from $1,950 2026-01-26
Nuttx CRITICAL 9.8
CVE-2025-47868

Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that…

Fix: 12.9.0+
Fix from $2,300 2025-06-16
Commons Configuration HIGH 7.3
CVE-2024-29131

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are…

Fix: 2.10.1+
Fix from $1,950 2024-03-21
Commons Configuration MEDIUM 5.4
CVE-2024-29133

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are…

Fix: 2.10.1+
Fix from $1,600 2024-03-21
HTTP Server HIGH 7.5
CVE-2006-20001

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header va…

Fix: 2.4.55+
Fix from $1,950 2023-01-17
Commons Bcel CRITICAL 9.8
CVE-2022-42920

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds wri…

Fix: 6.6.0+
Fix from $2,300 2022-11-07
Commons Jxpath MEDIUM 6.5
CVE-2022-40160

** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…

Fix: after 1.3
Fix from $1,600 2022-10-06
Commons Jxpath MEDIUM 6.5
CVE-2022-40159

** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…

Fix: after 1.3
Fix from $1,600 2022-10-06
Hadoop CRITICAL 9.8
CVE-2021-37404

There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in…

Fix: 2.10.2 / 3.2.3+
Fix from $2,300 2022-06-13
HTTP Server CRITICAL 9.8
CVE-2022-23943EPSS 50%

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. …

Fix: 2.4.53+
Fix from $2,300 2022-03-14
HTTP Server CRITICAL 9.8
CVE-2021-44790EPSS 97%

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache http…

Fix: 2.4.52 / 5.20.0+
Fix from $2,300 2021-12-20
HTTP Server CRITICAL 9.8
CVE-2021-39275EPSS 39%

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but t…

Fix: 2.4.49+
Fix from $2,300 2021-09-16
Traffic Server CRITICAL 9.8
CVE-2021-35474

Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.…

Fix: after 9.0.1
Fix from $2,300 2021-06-30
HTTP Server CRITICAL 9.8
CVE-2021-26691EPSS 68%

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

Fix: 18.1.0.1.0+
Fix from $2,300 2021-06-10
HTTP Server HIGH 7.3
CVE-2020-35452EPSS 53%

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of thi…

Fix: after 2.4.46
Fix from $1,950 2021-06-10
Nuttx CRITICAL 9.8
CVE-2020-17529

Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt …

Fix: after 9.1.0
Fix from $2,300 2020-12-09
Nuttx CRITICAL 9.1
CVE-2020-17528

Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt …

Fix: after 9.1.0
Fix from $2,300 2020-12-09
Guacamole MEDIUM 6.7
CVE-2020-9498

Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a m…

Fix: after 1.1.0
Fix from $1,600 2020-07-02
HTTP Server HIGH 7.2
CVE-2019-10097EPSS 53%

In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specia…

Fix: after 17.3
Fix from $1,950 2019-09-26
HTTP Server HIGH 7.5
CVE-2019-10081EPSS 15%

HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing r…

Fix: after 2.4.39
Fix from $1,950 2019-08-15
Ranger HIGH 8.8
CVE-2018-11778

UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1…

Fix: 1.2.0+
Fix from $1,950 2018-10-05
HTTP Server HIGH 7.5
CVE-2017-15710EPSS 18%

In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-La…

No fix yet
Fix from $1,950 2018-03-26