Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2005-0808EPSS 23% Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007. Tomcat Mitigation only Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0108 Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MES… Mod Auth Radius No fix yet Fix from $1,6002005-01-11 MEDIUM 5.0 CVE-2004-0263 PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child proce… HTTP Server Mitigation only Fix from $1,6002004-11-23 MEDIUM 6.8 CVE-2002-1567EPSS 27% Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL wit… Tomcat No fix yet Fix from $1,6002003-10-06 HIGH 7.5 CVE-2003-0016EPSS 17% Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute … HTTP Server Mitigation only Fix from $1,9502003-02-07 MEDIUM 5.0 CVE-2003-0017EPSS 6% Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal charac… HTTP Server Mitigation only Fix from $1,6002003-02-07 MEDIUM 5.0 CVE-2003-0043 Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote… Tomcat Mitigation only Fix from $1,6002003-02-07 MEDIUM 5.0 CVE-2003-0045 Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption… Tomcat Mitigation only Fix from $1,6002003-02-07 HIGH 7.5 CVE-2002-1394EPSS 6% Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server … Tomcat Mitigation only Fix from $1,9502003-01-17 HIGH 7.5 CVE-2002-2029EPSS 25% PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly exe… HTTP Server No fix yet Fix from $1,9502002-12-31 MEDIUM 5.0 CVE-2002-2006EPSS 31% The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sen… Tomcat No fix yet Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2007EPSS 41% The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings … Tomcat No fix yet Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2009EPSS 7% Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %… Tomcat No fix yet Fix from $1,6002002-12-31 HIGH 7.5 CVE-2002-0843EPSS 21% Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web ser… HTTP Server Mitigation only Fix from $1,9502002-10-11 MEDIUM 6.8 CVE-2002-0840EPSS 95% Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off… HTTP Server Mitigation only Fix from $1,6002002-10-11 MEDIUM 5.0 CVE-2002-1156EPSS 15% Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled. HTTP Server Mitigation only Fix from $1,6002002-10-11 MEDIUM 5.0 CVE-2002-0936EPSS 27% The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that… Tomcat No fix yet Fix from $1,6002002-10-04 MEDIUM 5.0 CVE-2002-0654EPSS 59% Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .… HTTP Server Mitigation only Fix from $1,6002002-09-05 MEDIUM 5.0 CVE-2002-0240EPSS 8% PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of … HTTP Server Mitigation only Fix from $1,6002002-05-29 MEDIUM 5.0 CVE-2002-0249EPSS 8% PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe … HTTP Server Mitigation only Fix from $1,6002002-05-29 MEDIUM 5.0 CVE-2002-1592EPSS 12% The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include t… HTTP Server Mitigation only Fix from $1,6002002-05-06 MEDIUM 5.0 CVE-2001-0917EPSS 8% Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension. Tomcat Mitigation only Fix from $1,6002001-11-22 MEDIUM 5.0 CVE-2001-0729EPSS 7% Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number o… HTTP Server Mitigation only Fix from $1,6002001-10-30 MEDIUM 5.0 CVE-2001-0730EPSS 12% split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slas… HTTP Server Mitigation only Fix from $1,6002001-10-30 MEDIUM 5.0 CVE-2001-0042EPSS 10% PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash… HTTP Server No fix yet Fix from $1,6002001-02-16 MEDIUM 6.4 CVE-2000-0759EPSS 26% Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error… Tomcat No fix yet Fix from $1,6002000-10-20 MEDIUM 6.4 CVE-2000-0760EPSS 62% The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL w… Tomcat No fix yet Fix from $1,6002000-10-20 MEDIUM 5.0 CVE-2000-1204EPSS 11% Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for… HTTP Server No fix yet Fix from $1,6002000-10-13 MEDIUM 5.0 CVE-1999-0289 The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL. HTTP Server Mitigation only Fix from $1,6001999-12-12 HIGH 10.0 CVE-1999-0926EPSS 9% Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. HTTP Server No fix yet Fix from $1,9501999-09-03