Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2011-4858EPSS 80% Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to tri… Tomcat No fix yet Fix from $1,6002012-01-05 HIGH 7.5 CVE-2011-3190EPSS 15% Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other … Tomcat No fix yet Fix from $1,9502011-08-31 MEDIUM 6.8 CVE-2011-1026 Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij… Archiva No fix yet Fix from $1,6002011-06-02 MEDIUM 6.8 CVE-2010-4408 Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password … Archiva Mitigation only Fix from $1,6002010-12-06 MEDIUM 6.4 CVE-2010-4312 The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers … Tomcat Mitigation only Fix from $1,6002010-11-26 MEDIUM 6.9 CVE-2010-2953 Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges… Couchdb Mitigation only Fix from $1,6002010-09-14 MEDIUM 6.8 CVE-2010-2234 Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of admini… Couchdb Mitigation only Fix from $1,6002010-08-19 MEDIUM 5.0 CVE-2010-1870EPSS 91% The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly ot… Struts No fix yet Fix from $1,6002010-08-17 MEDIUM 5.0 CVE-2010-2791EPSS 8% mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon… HTTP Server Mitigation only Fix from $1,6002010-08-05 HIGH 9.3 CVE-2010-0136EPSS 8% OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remo… Openoffice Mitigation only Fix from $1,9502010-02-16 HIGH 9.3 CVE-2009-3569EPSS 10% Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a c… Openoffice.org No fix yet Fix from $1,9502009-10-06 MEDIUM 6.8 CVE-2009-0039EPSS 11% Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 … Geronimo No fix yet Fix from $1,6002009-04-17 MEDIUM 6.8 CVE-2009-1275 Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumsta… Tiles Mitigation only Fix from $1,6002009-04-09 MEDIUM 5.0 CVE-2008-6505EPSS 73% Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary fil… Struts Mitigation only Fix from $1,6002009-03-23 HIGH 7.8 CVE-2008-3282EPSS 11% Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit… Openoffice Mitigation only Fix from $1,9502008-08-29 MEDIUM 6.5 CVE-2008-2717 TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al… Apache Webserver Mitigation only Fix from $1,6002008-06-16 MEDIUM 5.8 CVE-2008-0002EPSS 5% Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, whi… Tomcat Mitigation only Fix from $1,6002008-02-12 HIGH 7.8 CVE-2007-6423 Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to tr… HTTP Server Mitigation only Fix from $1,9502008-01-12 HIGH 7.5 CVE-2007-5797 SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut… Geronimo Mitigation only Fix from $1,9502007-11-03 MEDIUM 5.0 CVE-2007-5085 Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a… Geronimo Mitigation only Fix from $1,6002007-09-26 MEDIUM 5.0 CVE-2007-2353EPSS 28% Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path i… Axis No fix yet Fix from $1,6002007-04-30 MEDIUM 6.2 CVE-2007-1741 Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to g… HTTP Server Mitigation only Fix from $1,6002007-04-13 HIGH 7.8 CVE-2007-0086EPSS 10% The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ… HTTP Server Mitigation only Fix from $1,9502007-01-05 HIGH 7.5 CVE-2006-6588 The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTyp… Ofbiz No fix yet Fix from $1,9502006-12-15 MEDIUM 6.8 CVE-2006-6587EPSS 8% Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allow… Ofbiz No fix yet Fix from $1,6002006-12-15 MEDIUM 6.8 CVE-2006-6589 Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows… Ofbiz No fix yet Fix from $1,6002006-12-15 HIGH 7.8 CVE-2006-2806EPSS 6% The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption)… James No fix yet Fix from $1,9502006-06-05 HIGH 7.8 CVE-2005-4836 The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot… Tomcat No fix yet Fix from $1,9502005-12-31 MEDIUM 5.0 CVE-2005-4703EPSS 26% Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DO… Tomcat No fix yet Fix from $1,6002005-12-31 HIGH 7.5 CVE-2005-1344EPSS 29% Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normal… HTTP Server No fix yet Fix from $1,9502005-05-02