Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tomcat MEDIUM 5.0
CVE-2011-3375EPSS 7%

Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request object…

Mitigation only
Fix from $1,600 2012-01-19
Tomcat MEDIUM 5.0
CVE-2012-0022EPSS 11%

Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote…

Mitigation only
Fix from $1,600 2012-01-19
Tomcat MEDIUM 5.0
CVE-2011-1184EPSS 9%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the…

Patch available
Fix from $1,600 2012-01-14
Tomcat MEDIUM 5.0
CVE-2011-5062EPSS 8%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qo…

Patch available
Fix from $1,600 2012-01-14
Struts MEDIUM 5.0
CVE-2011-5057EPSS 29%

Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and req…

Fix: 2.3.3+
Fix from $1,600 2012-01-08
Struts CRITICAL 9.8
CVE-2012-0391 KEVEPSS 76%

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling fo…

Fix: 2.2.3.1+
Fix from $2,300 2012-01-08
Struts MEDIUM 6.8
CVE-2012-0392EPSS 98%

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute a…

Fix: 2.3.1+
Fix from $1,600 2012-01-08
Struts MEDIUM 6.8
CVE-2012-0394EPSS 75%

The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary command…

Fix: after 2.3.17
Fix from $1,600 2012-01-08
Struts MEDIUM 6.4
CVE-2012-0393EPSS 37%

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to c…

Fix: 2.3.1.1+
Fix from $1,600 2012-01-08
Tomcat MEDIUM 5.0
CVE-2011-4858EPSS 80%

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to tri…

No fix yet
Fix from $1,600 2012-01-05
Activemq MEDIUM 5.0
CVE-2011-4905EPSS 8%

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending ma…

Fix: after 5.5.1
Fix from $1,600 2012-01-05
Geronimo HIGH 7.8
CVE-2011-5034EPSS 81%

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, wh…

Fix: after 2.2.1
Fix from $1,950 2011-12-30
HTTP Server MEDIUM 5.0
CVE-2007-6750EPSS 71%

The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by…

Fix: after 2.2.14
Fix from $1,600 2011-12-27
HTTP Server MEDIUM 5.0
CVE-2011-3368EPSS 91%

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with u…

Patch available
Fix from $1,600 2011-10-05
Tomcat HIGH 7.5
CVE-2011-3190EPSS 15%

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other …

No fix yet
Fix from $1,950 2011-08-31
HTTP Server HIGH 7.8
CVE-2011-3192EPSS 99%

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of ser…

Fix: 2.0.65 / 2.2.20+
Fix from $1,950 2011-08-29
Tomcat MEDIUM 5.0
CVE-2011-2729EPSS 7%

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33,…

Patch available
Fix from $1,600 2011-08-15
Xml Security For C\+\+ MEDIUM 5.0
CVE-2011-2516EPSS 8%

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, a…

Fix: after 2.4.2
Fix from $1,600 2011-07-11
Subversion MEDIUM 5.0
CVE-2011-1752EPSS 8%

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of se…

Fix: 1.6.17 / 10.7.3+
Fix from $1,600 2011-06-06
Rampart\/c MEDIUM 6.5
CVE-2011-2329

The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration …

Patch available
Fix from $1,600 2011-06-02
Archiva MEDIUM 6.8
CVE-2011-1026

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij…

No fix yet
Fix from $1,600 2011-06-02
Struts MEDIUM 5.0
CVE-2011-2088EPSS 6%

XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive informati…

Patch available
Fix from $1,600 2011-05-13
Tomcat MEDIUM 5.8
CVE-2011-1183EPSS 6%

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended…

Patch available
Fix from $1,600 2011-04-08
Tomcat MEDIUM 5.0
CVE-2011-1475EPSS 9%

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses…

Patch available
Fix from $1,600 2011-04-08
Tomcat MEDIUM 5.8
CVE-2011-1088EPSS 6%

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via…

Patch available
Fix from $1,600 2011-03-14
Tomcat MEDIUM 5.8
CVE-2011-1419EPSS 7%

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers…

Patch available
Fix from $1,600 2011-03-14
Tomcat MEDIUM 5.0
CVE-2011-0534EPSS 8%

Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector…

Patch available
Fix from $1,600 2011-02-10
Openoffice HIGH 9.3
CVE-2010-3450EPSS 11%

Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a…

Fix: 3.3.0+
Fix from $1,950 2011-01-28
Openoffice HIGH 9.3
CVE-2010-3451EPSS 10%

Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…

Fix: 3.3.0+
Fix from $1,950 2011-01-28
Openoffice HIGH 9.3
CVE-2010-3452EPSS 10%

Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…

Fix: 3.3.0+
Fix from $1,950 2011-01-28