Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.0
CVE-2011-4858EPSS 80%
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to tri…
Tomcat
No fix yet
HIGH 7.5
CVE-2011-3190EPSS 15%
Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other …
Tomcat
No fix yet
MEDIUM 6.8
CVE-2011-1026
Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij…
Archiva
No fix yet
MEDIUM 6.8
CVE-2010-4408
Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password …
Archiva
Mitigation only
MEDIUM 6.4
CVE-2010-4312
The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers …
Tomcat
Mitigation only
MEDIUM 6.9
CVE-2010-2953
Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges…
Couchdb
Mitigation only
MEDIUM 6.8
CVE-2010-2234
Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of admini…
Couchdb
Mitigation only
MEDIUM 5.0
CVE-2010-1870EPSS 91%
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly ot…
Struts
No fix yet
MEDIUM 5.0
CVE-2010-2791EPSS 8%
mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon…
HTTP Server
Mitigation only
HIGH 9.3
CVE-2010-0136EPSS 8%
OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remo…
Openoffice
Mitigation only
HIGH 9.3
CVE-2009-3569EPSS 10%
Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a c…
Openoffice.org
No fix yet
MEDIUM 6.8
CVE-2009-0039EPSS 11%
Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 …
Geronimo
No fix yet
MEDIUM 6.8
CVE-2009-1275
Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumsta…
Tiles
Mitigation only
MEDIUM 5.0
CVE-2008-6505EPSS 73%
Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary fil…
Struts
Mitigation only
HIGH 7.8
CVE-2008-3282EPSS 11%
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit…
Openoffice
Mitigation only
MEDIUM 6.5
CVE-2008-2717
TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al…
Apache Webserver
Mitigation only
MEDIUM 5.8
CVE-2008-0002EPSS 5%
Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, whi…
Tomcat
Mitigation only
HIGH 7.8
CVE-2007-6423
Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to tr…
HTTP Server
Mitigation only
HIGH 7.5
CVE-2007-5797
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut…
Geronimo
Mitigation only
MEDIUM 5.0
CVE-2007-5085
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a…
Geronimo
Mitigation only
MEDIUM 5.0
CVE-2007-2353EPSS 28%
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path i…
Axis
No fix yet
MEDIUM 6.2
CVE-2007-1741
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to g…
HTTP Server
Mitigation only
HIGH 7.8
CVE-2007-0086EPSS 10%
The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ…
HTTP Server
Mitigation only
HIGH 7.5
CVE-2006-6588
The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTyp…
Ofbiz
No fix yet
MEDIUM 6.8
CVE-2006-6587EPSS 8%
Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allow…
Ofbiz
No fix yet
MEDIUM 6.8
CVE-2006-6589
Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows…
Ofbiz
No fix yet
HIGH 7.8
CVE-2006-2806EPSS 6%
The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption)…
James
No fix yet
HIGH 7.8
CVE-2005-4836
The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot…
Tomcat
No fix yet
MEDIUM 5.0
CVE-2005-4703EPSS 26%
Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DO…
Tomcat
No fix yet
HIGH 7.5
CVE-2005-1344EPSS 29%
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normal…
HTTP Server
No fix yet