Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spamassassin MEDIUM 5.1
CVE-2006-2447EPSS 75%

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a craft…

Patch available
Fix from $1,600 2006-06-06
James HIGH 7.8
CVE-2006-2806EPSS 6%

The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption)…

No fix yet
Fix from $1,950 2006-06-05
Struts HIGH 7.5
CVE-2006-1546EPSS 6%

Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html…

Fix: after 1.2.8
Fix from $1,950 2006-03-30
Struts HIGH 7.5
CVE-2006-1547 KEVEPSS 55%

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a mult…

Fix: 1.2.9+
Fix from $1,950 2006-03-30
Log4net MEDIUM 5.0
CVE-2006-0743EPSS 6%

Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corrupti…

Patch available
Fix from $1,600 2006-03-09
Mod Python HIGH 7.2
CVE-2006-1095

Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a …

Patch available
Fix from $1,950 2006-03-09
Libapreq2 MEDIUM 5.0
CVE-2006-0042EPSS 6%

Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remo…

Fix: 2.07+
Fix from $1,600 2006-02-18
Tomcat HIGH 7.8
CVE-2005-4836

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot…

No fix yet
Fix from $1,950 2005-12-31
HTTP Server MEDIUM 5.4
CVE-2005-3357EPSS 24%

mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers …

Patch available
Fix from $1,600 2005-12-31
Tomcat MEDIUM 5.0
CVE-2005-4703EPSS 26%

Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DO…

No fix yet
Fix from $1,600 2005-12-31
Derby MEDIUM 5.0
CVE-2005-4849

Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b)…

Fix: after 10.1.1.0
Fix from $1,600 2005-12-31
Spamassassin MEDIUM 5.0
CVE-2005-3351EPSS 7%

SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus e…

Patch available
Fix from $1,600 2005-11-20
Tomcat MEDIUM 5.0
CVE-2005-3510EPSS 6%

Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to l…

Patch available
Fix from $1,600 2005-11-06
HTTP Server MEDIUM 5.0
CVE-2005-2970EPSS 14%

Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consump…

Fix: 2.0.55+
Fix from $1,600 2005-10-25
HTTP Server HIGH 10.0
CVE-2005-2700EPSS 31%

ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enfor…

Fix: 2.0.55+
Fix from $1,950 2005-09-06
HTTP Server MEDIUM 5.0
CVE-2005-2728EPSS 11%

The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a…

Patch available
Fix from $1,600 2005-08-30
HTTP Server MEDIUM 5.0
CVE-2005-1268EPSS 8%

Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attack…

Fix: after 2.0.54
Fix from $1,600 2005-08-05
Spamassassin MEDIUM 5.0
CVE-2005-1266EPSS 8%

Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a …

Patch available
Fix from $1,600 2005-06-15
Mod Python HIGH 7.5
CVE-2005-0088EPSS 6%

The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.

Fix: after 2.7.8
Fix from $1,950 2005-05-02
HTTP Server HIGH 7.5
CVE-2005-1344EPSS 29%

Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normal…

No fix yet
Fix from $1,950 2005-05-02
Tomcat MEDIUM 5.0
CVE-2005-0808EPSS 23%

Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.

Mitigation only
Fix from $1,600 2005-05-02
HTTP Server HIGH 7.8
CVE-2004-0940

Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrar…

Fix: after 1.3.32
Fix from $1,950 2005-02-09
HTTP Server MEDIUM 5.0
CVE-2004-0942EPSS 55%

Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header…

Fix: after 2.0.52
Fix from $1,600 2005-02-09
Mod Auth Radius MEDIUM 5.0
CVE-2005-0108

Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MES…

No fix yet
Fix from $1,600 2005-01-11
HTTP Server HIGH 7.5
CVE-2004-0811EPSS 7%

Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted re…

Patch available
Fix from $1,950 2004-12-31
HTTP Server HIGH 7.2
CVE-2004-2343

Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as De…

Fix: after 2.0.47
Fix from $1,950 2004-12-31
Xerces C\+\+ MEDIUM 5.0
CVE-2004-1575EPSS 6%

The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML documen…

Patch available
Fix from $1,600 2004-12-31
Mod Python MEDIUM 5.0
CVE-2004-2680

mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filt…

Fix: after 3.1.4
Fix from $1,600 2004-12-31
HTTP Server MEDIUM 5.0
CVE-2004-0263

PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child proce…

Mitigation only
Fix from $1,600 2004-11-23
HTTP Server HIGH 7.5
CVE-2004-0885EPSS 14%

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients…

Patch available
Fix from $1,950 2004-11-03