Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openoffice HIGH 9.3
CVE-2009-2949EPSS 14%

Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to …

Fix: 3.2.0+
Fix from $1,950 2010-02-16
Openoffice HIGH 9.3
CVE-2009-2950EPSS 14%

Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 al…

Fix: 3.2.0+
Fix from $1,950 2010-02-16
Openoffice HIGH 9.3
CVE-2009-3301EPSS 12%

Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application cras…

Fix: 3.2.0+
Fix from $1,950 2010-02-16
Openoffice HIGH 9.3
CVE-2009-3302EPSS 12%

filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execut…

Fix: 3.2.0+
Fix from $1,950 2010-02-16
Openoffice HIGH 9.3
CVE-2010-0136EPSS 8%

OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remo…

Mitigation only
Fix from $1,950 2010-02-16
HTTP Server MEDIUM 6.8
CVE-2010-0010EPSS 43%

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allo…

Fix: after 1.3.41
Fix from $1,600 2010-02-02
Tomcat MEDIUM 5.8
CVE-2009-2693EPSS 10%

Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbit…

Patch available
Fix from $1,600 2010-01-28
HTTP Server MEDIUM 5.0
CVE-2009-3560EPSS 24%

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to c…

Fix: 2.0.64 / 2.2.17+
Fix from $1,600 2009-12-04
Tomcat HIGH 7.5
CVE-2009-3548EPSS 79%

The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for t…

Patch available
Fix from $1,950 2009-11-12
HTTP Server CRITICAL 9.8
CVE-2009-3555EPSS 87%

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache …

Fix: after 3.12.4
Fix from $2,300 2009-11-09
HTTP Server MEDIUM 5.0
CVE-2009-3720EPSS 28%

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context…

Fix: 2.0.64 / 2.2.17+
Fix from $1,600 2009-11-03
HTTP Server HIGH 7.5
CVE-2009-2699EPSS 14%

The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the A…

Fix: 1.3.9 / 2.2.14+
Fix from $1,950 2009-10-13
Openoffice.org HIGH 9.3
CVE-2009-3569EPSS 10%

Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a c…

No fix yet
Fix from $1,950 2009-10-06
HTTP Server MEDIUM 5.0
CVE-2009-3095EPSS 13%

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an F…

Fix: 2.0.64 / 2.2.14+
Fix from $1,600 2009-09-08
Apr Util HIGH 10.0
CVE-2009-2412EPSS 14%

Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow …

Patch available
Fix from $1,950 2009-08-06
HTTP Server HIGH 7.1
CVE-2009-1891EPSS 17%

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is clo…

Fix: 2.0.64 / 2.2.12+
Fix from $1,950 2009-07-10
HTTP Server HIGH 7.1
CVE-2009-1890EPSS 16%

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured…

Fix: 2.2.12+
Fix from $1,950 2009-07-05
Tomcat MEDIUM 5.0
CVE-2008-5515EPSS 19%

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before f…

Patch available
Fix from $1,600 2009-06-16
Apr Util HIGH 7.5
CVE-2009-1955EPSS 53%

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in t…

Fix: 1.3.7 / 2.2.12+
Fix from $1,950 2009-06-08
Apr Util MEDIUM 6.4
CVE-2009-1956EPSS 12%

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensit…

Fix: 2.2.12+
Fix from $1,600 2009-06-08
Tomcat MEDIUM 5.0
CVE-2009-0033EPSS 10%

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, a…

Patch available
Fix from $1,600 2009-06-05
HTTP Server MEDIUM 5.0
CVE-2009-1191EPSS 12%

mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for …

Patch available
Fix from $1,600 2009-04-23
Geronimo HIGH 9.4
CVE-2008-5518EPSS 36%

Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows all…

Patch available
Fix from $1,950 2009-04-17
Geronimo MEDIUM 6.8
CVE-2009-0039EPSS 11%

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 …

No fix yet
Fix from $1,600 2009-04-17
Tiles MEDIUM 6.8
CVE-2009-1275

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumsta…

Mitigation only
Fix from $1,600 2009-04-09
Struts MEDIUM 5.0
CVE-2008-6504EPSS 37%

ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly…

Patch available
Fix from $1,600 2009-03-23
Struts MEDIUM 5.0
CVE-2008-6505EPSS 73%

Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary fil…

Mitigation only
Fix from $1,600 2009-03-23
Xerces C\+\+ HIGH 7.8
CVE-2008-4482

The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML sc…

Fix: after 2.8.0
Fix from $1,950 2008-10-08
Openoffice HIGH 7.8
CVE-2008-3282EPSS 11%

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit…

Mitigation only
Fix from $1,950 2008-08-29
Tomcat MEDIUM 5.0
CVE-2008-2370EPSS 53%

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization bef…

Patch available
Fix from $1,600 2008-08-04