Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Apache Webserver MEDIUM 6.5
CVE-2008-2717

TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al…

Mitigation only
Fix from $1,600 2008-06-16
HTTP Server MEDIUM 5.0
CVE-2008-2364EPSS 13%

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the…

Fix: 2.0.64 / 2.2.9+
Fix from $1,600 2008-06-13
Mod Jk HIGH 7.5
CVE-2007-6258EPSS 41%

Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via …

Patch available
Fix from $1,950 2008-02-19
Tomcat MEDIUM 5.8
CVE-2008-0002EPSS 5%

Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, whi…

Mitigation only
Fix from $1,600 2008-02-12
Tomcat MEDIUM 5.0
CVE-2007-5333EPSS 63%

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5…

Fix: after 6.0.14
Fix from $1,600 2008-02-12
Tomcat MEDIUM 5.0
CVE-2008-0128EPSS 20%

The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONI…

Fix: after 5.5.20
Fix from $1,600 2008-01-23
HTTP Server HIGH 7.8
CVE-2007-6423

Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to tr…

Mitigation only
Fix from $1,950 2008-01-12
Tomcat MEDIUM 6.4
CVE-2007-5342EPSS 5%

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain pe…

Patch available
Fix from $1,600 2007-12-27
Geronimo HIGH 7.5
CVE-2007-5797

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut…

Mitigation only
Fix from $1,950 2007-11-03
Geronimo MEDIUM 5.0
CVE-2007-5085

Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a…

Mitigation only
Fix from $1,600 2007-09-26
Openoffice HIGH 9.3
CVE-2007-2834EPSS 12%

Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attack…

Fix: 2.3.0+
Fix from $1,950 2007-09-18
HTTP Server MEDIUM 6.1
CVE-2007-4465EPSS 26%

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is no…

Fix: 2.0.61 / 2.2.6+
Fix from $1,600 2007-09-14
Geronimo HIGH 10.0
CVE-2007-4548

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote att…

Patch available
Fix from $1,950 2007-08-27
HTTP Server MEDIUM 5.0
CVE-2007-3847EPSS 13%

The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a …

Fix: 2.0.61 / 2.2.6+
Fix from $1,600 2007-08-23
HTTP Server MEDIUM 5.0
CVE-2007-1863EPSS 12%

cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, all…

Fix: 2.0.61 / 2.2.6+
Fix from $1,600 2007-06-27
HTTP Server MEDIUM 5.0
CVE-2007-1862EPSS 6%

The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP …

Patch available
Fix from $1,600 2007-06-04
Tomcat Jk Web Server Connector MEDIUM 5.0
CVE-2007-1860EPSS 13%

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomc…

Fix: after 1.2.22
Fix from $1,600 2007-05-25
Axis MEDIUM 5.0
CVE-2007-2353EPSS 28%

Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path i…

No fix yet
Fix from $1,600 2007-04-30
Tomcat HIGH 7.8
CVE-2006-7197EPSS 8%

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_…

Patch available
Fix from $1,950 2007-04-25
HTTP Server MEDIUM 6.2
CVE-2007-1741

Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to g…

Mitigation only
Fix from $1,600 2007-04-13
Mod Perl MEDIUM 5.0
CVE-2007-1349EPSS 10%

PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expressi…

Fix: 1.30+
Fix from $1,600 2007-03-30
HTTP Server MEDIUM 5.0
CVE-2007-0450EPSS 91%

Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_pro…

Fix: 5.5.22 / 6.0.10+
Fix from $1,600 2007-03-16
Tomcat Jk Web Server Connector HIGH 7.5
CVE-2007-0774EPSS 82%

Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connec…

Patch available
Fix from $1,950 2007-03-04
HTTP Server HIGH 7.8
CVE-2007-0086EPSS 10%

The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ…

Mitigation only
Fix from $1,950 2007-01-05
Ofbiz HIGH 7.5
CVE-2006-6588

The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTyp…

No fix yet
Fix from $1,950 2006-12-15
Ofbiz MEDIUM 6.8
CVE-2006-6587EPSS 8%

Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allow…

No fix yet
Fix from $1,600 2006-12-15
Ofbiz MEDIUM 6.8
CVE-2006-6589

Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows…

No fix yet
Fix from $1,600 2006-12-15
HTTP Server MEDIUM 6.8
CVE-2006-4154EPSS 16%

Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string s…

Patch available
Fix from $1,600 2006-10-16
HTTP Server HIGH 7.6
CVE-2006-3747EPSS 96%

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, …

Fix: 1.3.37 / 2.0.59+
Fix from $1,950 2006-07-28
Tomcat MEDIUM 5.0
CVE-2006-3835EPSS 46%

Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demons…

Patch available
Fix from $1,600 2006-07-25