Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.0
CVE-2005-0808EPSS 23%
Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2005-0108
Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MES…
Mod Auth Radius
No fix yet
MEDIUM 5.0
CVE-2004-0263
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child proce…
HTTP Server
Mitigation only
MEDIUM 6.8
CVE-2002-1567EPSS 27%
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL wit…
Tomcat
No fix yet
HIGH 7.5
CVE-2003-0016EPSS 17%
Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute …
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2003-0017EPSS 6%
Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal charac…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2003-0043
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2003-0045
Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption…
Tomcat
Mitigation only
HIGH 7.5
CVE-2002-1394EPSS 6%
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server …
Tomcat
Mitigation only
HIGH 7.5
CVE-2002-2029EPSS 25%
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly exe…
HTTP Server
No fix yet
MEDIUM 5.0
CVE-2002-2006EPSS 31%
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sen…
Tomcat
No fix yet
MEDIUM 5.0
CVE-2002-2007EPSS 41%
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings …
Tomcat
No fix yet
MEDIUM 5.0
CVE-2002-2009EPSS 7%
Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %…
Tomcat
No fix yet
HIGH 7.5
CVE-2002-0843EPSS 21%
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web ser…
HTTP Server
Mitigation only
MEDIUM 6.8
CVE-2002-0840EPSS 95%
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2002-1156EPSS 15%
Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2002-0936EPSS 27%
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that…
Tomcat
No fix yet
MEDIUM 5.0
CVE-2002-0654EPSS 59%
Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2002-0240EPSS 8%
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of …
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2002-0249EPSS 8%
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe …
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2002-1592EPSS 12%
The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include t…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2001-0917EPSS 8%
Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2001-0729EPSS 7%
Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number o…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2001-0730EPSS 12%
split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slas…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2001-0042EPSS 10%
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash…
HTTP Server
No fix yet
MEDIUM 6.4
CVE-2000-0759EPSS 26%
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error…
Tomcat
No fix yet
MEDIUM 6.4
CVE-2000-0760EPSS 62%
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL w…
Tomcat
No fix yet
MEDIUM 5.0
CVE-2000-1204EPSS 11%
Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for…
HTTP Server
No fix yet
MEDIUM 5.0
CVE-1999-0289
The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
HTTP Server
Mitigation only
HIGH 10.0
CVE-1999-0926EPSS 9%
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
HTTP Server
No fix yet