Vulnerability index

Browse CVEs

393 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HTTP Server MEDIUM 5.0
CVE-2003-0017EPSS 6%

Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal charac…

Mitigation only
Fix from $1,600 2003-02-07
Tomcat MEDIUM 5.0
CVE-2003-0043

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote…

Mitigation only
Fix from $1,600 2003-02-07
Tomcat MEDIUM 5.0
CVE-2003-0045

Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption…

Mitigation only
Fix from $1,600 2003-02-07
Tomcat HIGH 7.5
CVE-2002-1394EPSS 6%

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server …

Mitigation only
Fix from $1,950 2003-01-17
HTTP Server HIGH 7.5
CVE-2002-2029EPSS 25%

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly exe…

No fix yet
Fix from $1,950 2002-12-31
Tomcat MEDIUM 5.0
CVE-2002-2006EPSS 31%

The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sen…

No fix yet
Fix from $1,600 2002-12-31
Tomcat MEDIUM 5.0
CVE-2002-2007EPSS 41%

The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings …

No fix yet
Fix from $1,600 2002-12-31
Tomcat MEDIUM 5.0
CVE-2002-2009EPSS 7%

Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %…

No fix yet
Fix from $1,600 2002-12-31
HTTP Server HIGH 7.5
CVE-2002-0843EPSS 21%

Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web ser…

Mitigation only
Fix from $1,950 2002-10-11
HTTP Server MEDIUM 6.8
CVE-2002-0840EPSS 95%

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off…

Mitigation only
Fix from $1,600 2002-10-11
HTTP Server MEDIUM 5.0
CVE-2002-1156EPSS 15%

Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.

Mitigation only
Fix from $1,600 2002-10-11
Tomcat MEDIUM 5.0
CVE-2002-0936EPSS 27%

The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that…

No fix yet
Fix from $1,600 2002-10-04
HTTP Server MEDIUM 5.0
CVE-2002-0654EPSS 59%

Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .…

Mitigation only
Fix from $1,600 2002-09-05
HTTP Server MEDIUM 5.0
CVE-2002-0240EPSS 8%

PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of …

Mitigation only
Fix from $1,600 2002-05-29
HTTP Server MEDIUM 5.0
CVE-2002-0249EPSS 8%

PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe …

Mitigation only
Fix from $1,600 2002-05-29
HTTP Server MEDIUM 5.0
CVE-2002-1592EPSS 12%

The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include t…

Mitigation only
Fix from $1,600 2002-05-06
Tomcat MEDIUM 5.0
CVE-2001-0917EPSS 8%

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

Mitigation only
Fix from $1,600 2001-11-22
HTTP Server MEDIUM 5.0
CVE-2001-0729EPSS 7%

Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number o…

Mitigation only
Fix from $1,600 2001-10-30
HTTP Server MEDIUM 5.0
CVE-2001-0730EPSS 12%

split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slas…

Mitigation only
Fix from $1,600 2001-10-30
HTTP Server MEDIUM 5.0
CVE-2001-0042EPSS 10%

PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash…

No fix yet
Fix from $1,600 2001-02-16
Tomcat MEDIUM 6.4
CVE-2000-0759EPSS 26%

Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error…

No fix yet
Fix from $1,600 2000-10-20
Tomcat MEDIUM 6.4
CVE-2000-0760EPSS 62%

The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL w…

No fix yet
Fix from $1,600 2000-10-20
HTTP Server MEDIUM 5.0
CVE-2000-1204EPSS 11%

Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for…

No fix yet
Fix from $1,600 2000-10-13
HTTP Server MEDIUM 5.0
CVE-1999-0289

The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.

Mitigation only
Fix from $1,600 1999-12-12
HTTP Server HIGH 10.0
CVE-1999-0926EPSS 9%

Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.

No fix yet
Fix from $1,950 1999-09-03
HTTP Server MEDIUM 5.0
CVE-2000-1206EPSS 5%

Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows r…

Mitigation only
Fix from $1,600 1999-08-20
HTTP Server HIGH 10.0
CVE-1999-1237EPSS 8%

Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attac…

Mitigation only
Fix from $1,950 1999-06-06
HTTP Server MEDIUM 5.0
CVE-1999-1412EPSS 35%

A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a fl…

Mitigation only
Fix from $1,600 1999-06-03
HTTP Server MEDIUM 5.0
CVE-1999-0678EPSS 31%

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the …

Mitigation only
Fix from $1,600 1999-01-17
HTTP Server MEDIUM 5.0
CVE-1999-0107EPSS 20%

Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a la…

Mitigation only
Fix from $1,600 1997-12-30