Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Tomcat MEDIUM 5.0
CVE-2011-4858EPSS 80%

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to tri…

No fix yet
Fix from $1,600 2012-01-05
Tomcat HIGH 7.5
CVE-2011-3190EPSS 15%

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other …

No fix yet
Fix from $1,950 2011-08-31
Archiva MEDIUM 6.8
CVE-2011-1026

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij…

No fix yet
Fix from $1,600 2011-06-02
Archiva MEDIUM 6.8
CVE-2010-4408

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password …

Mitigation only
Fix from $1,600 2010-12-06
Tomcat MEDIUM 6.4
CVE-2010-4312

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers …

Mitigation only
Fix from $1,600 2010-11-26
Couchdb MEDIUM 6.9
CVE-2010-2953

Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges…

Mitigation only
Fix from $1,600 2010-09-14
Couchdb MEDIUM 6.8
CVE-2010-2234

Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of admini…

Mitigation only
Fix from $1,600 2010-08-19
Struts MEDIUM 5.0
CVE-2010-1870EPSS 91%

The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly ot…

No fix yet
Fix from $1,600 2010-08-17
HTTP Server MEDIUM 5.0
CVE-2010-2791EPSS 8%

mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon…

Mitigation only
Fix from $1,600 2010-08-05
Openoffice HIGH 9.3
CVE-2010-0136EPSS 8%

OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remo…

Mitigation only
Fix from $1,950 2010-02-16
Openoffice.org HIGH 9.3
CVE-2009-3569EPSS 10%

Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a c…

No fix yet
Fix from $1,950 2009-10-06
Geronimo MEDIUM 6.8
CVE-2009-0039EPSS 11%

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 …

No fix yet
Fix from $1,600 2009-04-17
Tiles MEDIUM 6.8
CVE-2009-1275

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumsta…

Mitigation only
Fix from $1,600 2009-04-09
Struts MEDIUM 5.0
CVE-2008-6505EPSS 73%

Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary fil…

Mitigation only
Fix from $1,600 2009-03-23
Openoffice HIGH 7.8
CVE-2008-3282EPSS 11%

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit…

Mitigation only
Fix from $1,950 2008-08-29
Apache Webserver MEDIUM 6.5
CVE-2008-2717

TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al…

Mitigation only
Fix from $1,600 2008-06-16
Tomcat MEDIUM 5.8
CVE-2008-0002EPSS 5%

Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, whi…

Mitigation only
Fix from $1,600 2008-02-12
HTTP Server HIGH 7.8
CVE-2007-6423

Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to tr…

Mitigation only
Fix from $1,950 2008-01-12
Geronimo HIGH 7.5
CVE-2007-5797

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut…

Mitigation only
Fix from $1,950 2007-11-03
Geronimo MEDIUM 5.0
CVE-2007-5085

Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a…

Mitigation only
Fix from $1,600 2007-09-26
Axis MEDIUM 5.0
CVE-2007-2353EPSS 28%

Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path i…

No fix yet
Fix from $1,600 2007-04-30
HTTP Server MEDIUM 6.2
CVE-2007-1741

Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to g…

Mitigation only
Fix from $1,600 2007-04-13
HTTP Server HIGH 7.8
CVE-2007-0086EPSS 10%

The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ…

Mitigation only
Fix from $1,950 2007-01-05
Ofbiz HIGH 7.5
CVE-2006-6588

The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTyp…

No fix yet
Fix from $1,950 2006-12-15
Ofbiz MEDIUM 6.8
CVE-2006-6587EPSS 8%

Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allow…

No fix yet
Fix from $1,600 2006-12-15
Ofbiz MEDIUM 6.8
CVE-2006-6589

Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows…

No fix yet
Fix from $1,600 2006-12-15
James HIGH 7.8
CVE-2006-2806EPSS 6%

The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption)…

No fix yet
Fix from $1,950 2006-06-05
Tomcat HIGH 7.8
CVE-2005-4836

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot…

No fix yet
Fix from $1,950 2005-12-31
Tomcat MEDIUM 5.0
CVE-2005-4703EPSS 26%

Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DO…

No fix yet
Fix from $1,600 2005-12-31
HTTP Server HIGH 7.5
CVE-2005-1344EPSS 29%

Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normal…

No fix yet
Fix from $1,950 2005-05-02