Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HTTP Server HIGH 7.5
CVE-2013-2249EPSS 14%

mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considerin…

Fix: after 2.4.4
Fix from $1,950 2013-07-23
Archiva CRITICAL 9.8
CVE-2013-2251 KEVEPSS 100%

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi…

Fix: 1.3.8+
Fix from $2,300 2013-07-20
Struts MEDIUM 5.8
CVE-2013-2248EPSS 95%

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond…

Mitigation only
Fix from $1,600 2013-07-20
Struts HIGH 9.3
CVE-2013-2134EPSS 70%

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly …

Fix: 2.3.14.3+
Fix from $1,950 2013-07-16
Struts HIGH 9.3
CVE-2013-2135EPSS 14%

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" an…

Fix: 2.3.14.3+
Fix from $1,950 2013-07-16
Geronimo HIGH 10.0
CVE-2013-1777EPSS 10%

The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and o…

Patch available
Fix from $1,950 2013-07-11
Openjpa HIGH 7.5
CVE-2013-1768EPSS 10%

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace d…

Mitigation only
Fix from $1,950 2013-07-11
Struts HIGH 9.3
CVE-2013-1965EPSS 94%

Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a cr…

Fix: 2.3.14.1+
Fix from $1,950 2013-07-10
Struts HIGH 9.3
CVE-2013-1966EPSS 74%

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …

Fix: 2.3.14.1+
Fix from $1,950 2013-07-10
Struts HIGH 8.1
CVE-2013-2115EPSS 75%

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …

Fix: after 2.3.14.1
Fix from $1,950 2013-07-10
HTTP Server MEDIUM 5.1
CVE-2013-1862EPSS 25%

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable char…

Fix: 2.0.65 / 2.2.25+
Fix from $1,600 2013-06-10
Tomcat MEDIUM 6.8
CVE-2013-2067EPSS 7%

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x befor…

Patch available
Fix from $1,600 2013-06-01
Tomcat MEDIUM 5.0
CVE-2012-3544EPSS 11%

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attac…

Patch available
Fix from $1,600 2013-06-01
Subversion MEDIUM 5.0
CVE-2013-1847EPSS 51%

The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,600 2013-05-02
Subversion MEDIUM 5.0
CVE-2013-1884EPSS 51%

The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault…

Mitigation only
Fix from $1,600 2013-05-02
Activemq MEDIUM 6.4
CVE-2013-3060EPSS 6%

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cau…

Fix: after 5.7.0
Fix from $1,600 2013-04-21
Activemq MEDIUM 5.0
CVE-2012-6551EPSS 8%

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of servic…

Fix: after 5.7.0
Fix from $1,600 2013-04-21
Maven MEDIUM 5.8
CVE-2013-0253

The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof …

Patch available
Fix from $1,600 2013-04-09
Qpid MEDIUM 5.0
CVE-2012-4458EPSS 7%

The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via …

Fix: after 0.20
Fix from $1,600 2013-03-14
Qpid MEDIUM 5.0
CVE-2012-4459EPSS 9%

Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of s…

Fix: after 0.20
Fix from $1,600 2013-03-14
Qpid MEDIUM 5.0
CVE-2012-4460

The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial o…

Fix: after 0.20
Fix from $1,600 2013-03-14
Qpid MEDIUM 6.8
CVE-2012-4446

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking t…

Fix: after 0.20
Fix from $1,600 2013-03-14
Cxf MEDIUM 5.8
CVE-2012-5633EPSS 8%

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Secu…

Fix: after 2.5.7
Fix from $1,600 2013-03-12
Cxf MEDIUM 5.0
CVE-2013-0239

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote att…

Fix: after 2.5.8
Fix from $1,600 2013-03-12
Cxf HIGH 10.0
CVE-2012-2379

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 pol…

Patch available
Fix from $1,950 2013-01-03
HTTP Server MEDIUM 5.0
CVE-2012-4557EPSS 17%

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-pr…

Patch available
Fix from $1,600 2012-11-30
Tomcat MEDIUM 5.0
CVE-2012-5568EPSS 10%

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowlo…

Fix: after 7.0.105
Fix from $1,600 2012-11-30
Tomcat MEDIUM 5.0
CVE-2012-5885EPSS 9%

The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.…

Mitigation only
Fix from $1,600 2012-11-17
Tomcat MEDIUM 5.0
CVE-2012-5886EPSS 9%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio…

Mitigation only
Fix from $1,600 2012-11-17
Tomcat MEDIUM 5.0
CVE-2012-5887EPSS 12%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly…

Fix: 5.5.36 / 6.0.36+
Fix from $1,600 2012-11-17