Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HTTP Server HIGH 7.5
CVE-2002-0257

Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via th…

Patch available
Fix from $1,950 2002-05-29
HTTP Server MEDIUM 5.0
CVE-2002-0240EPSS 8%

PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of …

Mitigation only
Fix from $1,600 2002-05-29
HTTP Server MEDIUM 5.0
CVE-2002-0249EPSS 8%

PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe …

Mitigation only
Fix from $1,600 2002-05-29
Mod Python HIGH 7.5
CVE-2002-0185

mod_python version 2.7.6 and earlier allows a module indirectly imported by a published module to then be accessed via the publisher, which allows re…

Fix: after 2.7.6
Fix from $1,950 2002-05-16
HTTP Server MEDIUM 5.0
CVE-2002-1592EPSS 12%

The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include t…

Mitigation only
Fix from $1,600 2002-05-06
Tomcat MEDIUM 5.0
CVE-2000-1210

Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the…

Fix: after 3.1
Fix from $1,600 2002-03-22
HTTP Server HIGH 7.5
CVE-2002-0061EPSS 50%

Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pip…

Fix: 1.3.24 / 2.0.34+
Fix from $1,950 2002-03-21
Tomcat HIGH 7.5
CVE-2001-1563

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness…

Patch available
Fix from $1,950 2001-12-31
HTTP Server MEDIUM 5.0
CVE-2001-1556

The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allo…

Fix: 1.3.31 / 2.0.49+
Fix from $1,600 2001-12-31
Tomcat MEDIUM 5.1
CVE-2001-0829EPSS 12%

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which caus…

Patch available
Fix from $1,600 2001-12-06
HTTP Server HIGH 7.5
CVE-2001-1449EPSS 8%

The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list t…

Patch available
Fix from $1,950 2001-11-28
Tomcat MEDIUM 5.0
CVE-2001-0917EPSS 8%

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

Mitigation only
Fix from $1,600 2001-11-22
HTTP Server MEDIUM 5.0
CVE-2001-0729EPSS 7%

Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number o…

Mitigation only
Fix from $1,600 2001-10-30
HTTP Server MEDIUM 5.0
CVE-2001-0730EPSS 12%

split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slas…

Mitigation only
Fix from $1,600 2001-10-30
HTTP Server CRITICAL 9.8
CVE-2001-0766EPSS 8%

Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characte…

Patch available
Fix from $2,300 2001-10-18
HTTP Server MEDIUM 5.0
CVE-2001-0731EPSS 57%

Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" que…

Patch available
Fix from $1,600 2001-10-01
HTTP Server MEDIUM 5.0
CVE-2001-1072

Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the …

Patch available
Fix from $1,600 2001-08-31
Tomcat MEDIUM 5.0
CVE-2001-0590EPSS 11%

Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed UR…

Fix: after 3.2.2
Fix from $1,600 2001-08-02
HTTP Server MEDIUM 5.0
CVE-2001-1342EPSS 12%

Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contai…

Patch available
Fix from $1,600 2001-05-12
HTTP Server MEDIUM 5.0
CVE-2001-0925EPSS 75%

The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP req…

Patch available
Fix from $1,600 2001-03-12
HTTP Server MEDIUM 5.0
CVE-2001-0042EPSS 10%

PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash…

No fix yet
Fix from $1,600 2001-02-16
HTTP Server MEDIUM 5.0
CVE-2000-0913EPSS 36%

mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename…

Patch available
Fix from $1,600 2000-12-19
HTTP Server MEDIUM 5.0
CVE-2000-0868EPSS 45%

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ i…

Patch available
Fix from $1,600 2000-11-14
HTTP Server MEDIUM 5.0
CVE-2000-0869EPSS 51%

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROP…

Patch available
Fix from $1,600 2000-11-14
Tomcat MEDIUM 6.4
CVE-2000-0759EPSS 26%

Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error…

No fix yet
Fix from $1,600 2000-10-20
Tomcat MEDIUM 6.4
CVE-2000-0760EPSS 62%

The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL w…

No fix yet
Fix from $1,600 2000-10-20
HTTP Server MEDIUM 5.0
CVE-2000-1204EPSS 11%

Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for…

No fix yet
Fix from $1,600 2000-10-13
Tomcat MEDIUM 5.0
CVE-2000-0672EPSS 10%

The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by …

Patch available
Fix from $1,600 2000-07-20
HTTP Server MEDIUM 5.0
CVE-2000-0505EPSS 47%

The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number o…

Patch available
Fix from $1,600 2000-05-31
HTTP Server HIGH 10.0
CVE-1999-1293

mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump co…

Fix: after 1.2.5
Fix from $1,950 1999-12-31