Vulnerability index

Browse CVEs

43 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
HIGH 8.2 CVE-2026-58188 Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 … Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58184 The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58187 The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apac… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2026-58177 The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Se… Traffic Server 10.1.4+ Fix from $2,3002026-07-29 HIGH 8.9 CVE-2026-58154 Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: fr… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 8.8 CVE-2026-45813 Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS servic… Nimble 1.10.0+ Fix from $1,9502026-07-24 CRITICAL 9.8 CVE-2026-64608 Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa… Fory 1.4.0+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-28780 Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server … HTTP Server 2.4.67+ Fix from $2,3002026-05-05 HIGH 7.3 CVE-2025-27821 Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recomme… Hadoop 3.4.2+ Fix from $1,9502026-01-26 CRITICAL 9.8 CVE-2025-47868 Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that… Nuttx 12.9.0+ Fix from $2,3002025-06-16 HIGH 7.3 CVE-2024-29131 Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are… Commons Configuration 2.10.1+ Fix from $1,9502024-03-21 MEDIUM 5.4 CVE-2024-29133 Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are… Commons Configuration 2.10.1+ Fix from $1,6002024-03-21 HIGH 7.5 CVE-2006-20001 A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header va… HTTP Server 2.4.55+ Fix from $1,9502023-01-17 CRITICAL 9.8 CVE-2022-42920 Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds wri… Commons Bcel 6.6.0+ Fix from $2,3002022-11-07 MEDIUM 6.5 CVE-2022-40160 ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to… Commons Jxpath after 1.3 Fix from $1,6002022-10-06 MEDIUM 6.5 CVE-2022-40159 ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to… Commons Jxpath after 1.3 Fix from $1,6002022-10-06 CRITICAL 9.8 CVE-2021-37404 There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in… Hadoop 2.10.2 / 3.2.3+ Fix from $2,3002022-06-13 CRITICAL 9.8 CVE-2022-23943EPSS 50% Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. … HTTP Server 2.4.53+ Fix from $2,3002022-03-14 CRITICAL 9.8 CVE-2021-44790EPSS 97% A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache http… HTTP Server 2.4.52 / 5.20.0+ Fix from $2,3002021-12-20 CRITICAL 9.8 CVE-2021-39275EPSS 39% ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but t… HTTP Server 2.4.49+ Fix from $2,3002021-09-16 CRITICAL 9.8 CVE-2021-35474 Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.… Traffic Server after 9.0.1 Fix from $2,3002021-06-30 CRITICAL 9.8 CVE-2021-26691EPSS 68% In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow HTTP Server 18.1.0.1.0+ Fix from $2,3002021-06-10 HIGH 7.3 CVE-2020-35452EPSS 53% Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of thi… HTTP Server after 2.4.46 Fix from $1,9502021-06-10 CRITICAL 9.8 CVE-2020-17529 Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt … Nuttx after 9.1.0 Fix from $2,3002020-12-09 CRITICAL 9.1 CVE-2020-17528 Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt … Nuttx after 9.1.0 Fix from $2,3002020-12-09 MEDIUM 6.7 CVE-2020-9498 Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a m… Guacamole after 1.1.0 Fix from $1,6002020-07-02 HIGH 7.2 CVE-2019-10097EPSS 53% In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specia… HTTP Server after 17.3 Fix from $1,9502019-09-26 HIGH 7.5 CVE-2019-10081EPSS 15% HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing r… HTTP Server after 2.4.39 Fix from $1,9502019-08-15 HIGH 8.8 CVE-2018-11778 UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1… Ranger 1.2.0+ Fix from $1,9502018-10-05 HIGH 7.5 CVE-2017-15710EPSS 18% In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-La… HTTP Server No fix yet Fix from $1,9502018-03-26