Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HTTP Server HIGH 7.5
CVE-2003-0016EPSS 18%

Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute …

Mitigation only
Fix from $1,950 2003-02-07
Tomcat MEDIUM 6.8
CVE-2003-0044EPSS 9%

Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow rem…

Patch available
Fix from $1,600 2003-02-07
HTTP Server MEDIUM 5.0
CVE-2003-0017EPSS 6%

Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal charac…

Mitigation only
Fix from $1,600 2003-02-07
Tomcat MEDIUM 5.0
CVE-2003-0042EPSS 46%

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file …

Patch available
Fix from $1,600 2003-02-07
Tomcat MEDIUM 5.0
CVE-2003-0043

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote…

Mitigation only
Fix from $1,600 2003-02-07
Tomcat MEDIUM 5.0
CVE-2003-0045

Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption…

Mitigation only
Fix from $1,600 2003-02-07
Tomcat HIGH 7.5
CVE-2002-1394EPSS 6%

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server …

Mitigation only
Fix from $1,950 2003-01-17
HTTP Server HIGH 7.8
CVE-2002-2272EPSS 10%

Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchroniz…

Patch available
Fix from $1,950 2002-12-31
HTTP Server HIGH 7.5
CVE-2002-1850EPSS 17%

mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by ca…

Patch available
Fix from $1,950 2002-12-31
HTTP Server HIGH 7.5
CVE-2002-2029EPSS 23%

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly exe…

No fix yet
Fix from $1,950 2002-12-31
Tomcat MEDIUM 5.0
CVE-2002-1895

The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of serv…

Patch available
Fix from $1,600 2002-12-31
Tomcat MEDIUM 5.0
CVE-2002-2006EPSS 31%

The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sen…

No fix yet
Fix from $1,600 2002-12-31
Tomcat MEDIUM 5.0
CVE-2002-2007EPSS 41%

The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings …

No fix yet
Fix from $1,600 2002-12-31
Tomcat MEDIUM 5.0
CVE-2002-2008EPSS 7%

Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as l…

Patch available
Fix from $1,600 2002-12-31
Tomcat MEDIUM 5.0
CVE-2002-2009EPSS 7%

Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %…

No fix yet
Fix from $1,600 2002-12-31
HTTP Server MEDIUM 5.0
CVE-2002-2012EPSS 6%

Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP reques…

Patch available
Fix from $1,600 2002-12-31
HTTP Server MEDIUM 5.0
CVE-2002-2103EPSS 6%

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse l…

Patch available
Fix from $1,600 2002-12-31
HTTP Server HIGH 7.5
CVE-2002-0843EPSS 21%

Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web ser…

Mitigation only
Fix from $1,950 2002-10-11
HTTP Server HIGH 7.2
CVE-2002-0839

The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to …

Fix: 1.3.27+
Fix from $1,950 2002-10-11
HTTP Server MEDIUM 6.8
CVE-2002-0840EPSS 95%

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off…

Mitigation only
Fix from $1,600 2002-10-11
Tomcat MEDIUM 5.0
CVE-2002-1148EPSS 19%

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code …

Patch available
Fix from $1,600 2002-10-11
HTTP Server MEDIUM 5.0
CVE-2002-1156EPSS 15%

Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.

Mitigation only
Fix from $1,600 2002-10-11
Tomcat MEDIUM 5.0
CVE-2002-0935EPSS 8%

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a …

Patch available
Fix from $1,600 2002-10-04
Tomcat MEDIUM 5.0
CVE-2002-0936EPSS 27%

The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that…

No fix yet
Fix from $1,600 2002-10-04
HTTP Server MEDIUM 5.0
CVE-2002-1593EPSS 7%

mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null derefe…

Patch available
Fix from $1,600 2002-09-25
HTTP Server MEDIUM 5.0
CVE-2002-0654EPSS 59%

Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .…

Mitigation only
Fix from $1,600 2002-09-05
Tomcat HIGH 7.5
CVE-2002-0493

Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers t…

Fix: after 3.3.2
Fix from $1,950 2002-08-12
HTTP Server HIGH 7.5
CVE-2002-0661EPSS 70%

Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execu…

Patch available
Fix from $1,950 2002-08-12
Tomcat HIGH 7.5
CVE-2002-0682EPSS 14%

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /…

Patch available
Fix from $1,950 2002-07-23
HTTP Server HIGH 7.5
CVE-2002-0392EPSS 95%

Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code vi…

Fix: after 2.0.36
Fix from $1,950 2002-07-03