Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openoffice HIGH 9.3
CVE-2010-3453EPSS 10%

The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number…

Fix: 3.3.0+
Fix from $1,950 2011-01-28
Openoffice HIGH 9.3
CVE-2010-3454EPSS 10%

Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote atta…

Fix: 3.3.0+
Fix from $1,950 2011-01-28
Openoffice HIGH 9.3
CVE-2010-4253EPSS 10%

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio…

Fix: 3.3.0+
Fix from $1,950 2011-01-28
Openoffice HIGH 9.3
CVE-2010-4643EPSS 10%

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio…

Fix: 3.3.0+
Fix from $1,950 2011-01-28
Openoffice MEDIUM 6.9
CVE-2010-3689

soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privilege…

Fix: 3.3.0+
Fix from $1,600 2011-01-28
Subversion MEDIUM 6.8
CVE-2010-4539EPSS 5%

The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote a…

Fix: after 1.6.14
Fix from $1,600 2011-01-07
Archiva MEDIUM 6.8
CVE-2010-3449

Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through …

Fix: after 1.2.3
Fix from $1,600 2010-12-06
Archiva MEDIUM 6.8
CVE-2010-4408

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password …

Mitigation only
Fix from $1,600 2010-12-06
Tomcat MEDIUM 6.4
CVE-2010-4312

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers …

Mitigation only
Fix from $1,600 2010-11-26
Mod Fcgid HIGH 7.5
CVE-2010-3872

A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgi…

Fix: after 2.3.5
Fix from $1,950 2010-11-22
Shiro MEDIUM 5.0
CVE-2010-3863EPSS 55%

Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows …

Fix: after 1.0.0
Fix from $1,600 2010-11-05
Myfaces MEDIUM 5.0
CVE-2010-2057

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a M…

Patch available
Fix from $1,600 2010-10-20
Axis2 HIGH 10.0
CVE-2010-0219EPSS 90%

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of a…

Patch available
Fix from $1,950 2010-10-18
Qpid MEDIUM 5.0
CVE-2009-5005EPSS 6%

The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows r…

Fix: after 1.2.2
Fix from $1,600 2010-10-18
Subversion MEDIUM 6.0
CVE-2010-3315

authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SV…

Patch available
Fix from $1,600 2010-10-04
Apr Util MEDIUM 5.0
CVE-2010-1623EPSS 20%

Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.…

Fix: 2.0.64 / 2.2.17+
Fix from $1,600 2010-10-04
Couchdb MEDIUM 6.9
CVE-2010-2953

Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges…

Mitigation only
Fix from $1,600 2010-09-14
Couchdb MEDIUM 6.8
CVE-2010-2234

Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of admini…

Mitigation only
Fix from $1,600 2010-08-19
Cxf CRITICAL 9.8
CVE-2010-2076EPSS 10%

Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUD…

Fix: 2.0.13 / 2.1.10+
Fix from $2,300 2010-08-19
Struts MEDIUM 5.0
CVE-2010-1870EPSS 92%

The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly ot…

No fix yet
Fix from $1,600 2010-08-17
HTTP Server MEDIUM 5.0
CVE-2010-2791EPSS 8%

mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon…

Mitigation only
Fix from $1,600 2010-08-05
HTTP Server MEDIUM 5.0
CVE-2010-1452EPSS 22%

The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process …

Fix: 2.0.64 / 2.2.16+
Fix from $1,600 2010-07-28
Tomcat MEDIUM 6.4
CVE-2010-2227EPSS 55%

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows r…

Patch available
Fix from $1,600 2010-07-13
Axis2 HIGH 7.5
CVE-2010-1632EPSS 22%

Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through …

Fix: after 1.5.1
Fix from $1,950 2010-06-22
HTTP Server MEDIUM 5.0
CVE-2010-2068EPSS 16%

mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in cer…

Patch available
Fix from $1,600 2010-06-18
Activemq MEDIUM 5.0
CVE-2010-1587EPSS 78%

The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash …

Patch available
Fix from $1,600 2010-04-28
Apache Http Server MEDIUM 6.8
CVE-2010-1151

Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modif…

Patch available
Fix from $1,600 2010-04-20
Activemq MEDIUM 6.8
CVE-2010-1244

Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the aut…

Fix: after 5.3.0
Fix from $1,600 2010-04-05
HTTP Server HIGH 10.0
CVE-2010-0425EPSS 94%

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when runni…

Fix: 2.0.64 / 2.2.15+
Fix from $1,950 2010-03-05
HTTP Server MEDIUM 5.0
CVE-2010-0408EPSS 21%

The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain …

Patch available
Fix from $1,600 2010-03-05