Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2013-2249EPSS 14% mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considerin… HTTP Server after 2.4.4 Fix from $1,9502013-07-23 CRITICAL 9.8 CVE-2013-2251 KEVEPSS 100% Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi… Archiva 1.3.8+ Fix from $2,3002013-07-20 MEDIUM 5.8 CVE-2013-2248EPSS 95% Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond… Struts Mitigation only Fix from $1,6002013-07-20 HIGH 9.3 CVE-2013-2134EPSS 70% Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly … Struts 2.3.14.3+ Fix from $1,9502013-07-16 HIGH 9.3 CVE-2013-2135EPSS 14% Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" an… Struts 2.3.14.3+ Fix from $1,9502013-07-16 HIGH 10.0 CVE-2013-1777EPSS 10% The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and o… Geronimo Patch available Fix from $1,9502013-07-11 HIGH 7.5 CVE-2013-1768EPSS 10% The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace d… Openjpa Mitigation only Fix from $1,9502013-07-11 HIGH 9.3 CVE-2013-1965EPSS 94% Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a cr… Struts 2.3.14.1+ Fix from $1,9502013-07-10 HIGH 9.3 CVE-2013-1966EPSS 74% Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using … Struts 2.3.14.1+ Fix from $1,9502013-07-10 HIGH 8.1 CVE-2013-2115EPSS 75% Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using … Struts after 2.3.14.1 Fix from $1,9502013-07-10 MEDIUM 5.1 CVE-2013-1862EPSS 25% mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable char… HTTP Server 2.0.65 / 2.2.25+ Fix from $1,6002013-06-10 MEDIUM 6.8 CVE-2013-2067EPSS 7% java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x befor… Tomcat Patch available Fix from $1,6002013-06-01 MEDIUM 5.0 CVE-2012-3544EPSS 11% Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attac… Tomcat Patch available Fix from $1,6002013-06-01 MEDIUM 5.0 CVE-2013-1847EPSS 51% The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of se… Subversion Mitigation only Fix from $1,6002013-05-02 MEDIUM 5.0 CVE-2013-1884EPSS 51% The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault… Subversion Mitigation only Fix from $1,6002013-05-02 MEDIUM 6.4 CVE-2013-3060EPSS 6% The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cau… Activemq after 5.7.0 Fix from $1,6002013-04-21 MEDIUM 5.0 CVE-2012-6551EPSS 8% The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of servic… Activemq after 5.7.0 Fix from $1,6002013-04-21 MEDIUM 5.8 CVE-2013-0253 The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof … Maven Patch available Fix from $1,6002013-04-09 MEDIUM 5.0 CVE-2012-4458EPSS 7% The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via … Qpid after 0.20 Fix from $1,6002013-03-14 MEDIUM 5.0 CVE-2012-4459EPSS 9% Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of s… Qpid after 0.20 Fix from $1,6002013-03-14 MEDIUM 5.0 CVE-2012-4460 The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial o… Qpid after 0.20 Fix from $1,6002013-03-14 MEDIUM 6.8 CVE-2012-4446 The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking t… Qpid after 0.20 Fix from $1,6002013-03-14 MEDIUM 5.8 CVE-2012-5633EPSS 8% The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Secu… Cxf after 2.5.7 Fix from $1,6002013-03-12 MEDIUM 5.0 CVE-2013-0239 Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote att… Cxf after 2.5.8 Fix from $1,6002013-03-12 HIGH 10.0 CVE-2012-2379 Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 pol… Cxf Patch available Fix from $1,9502013-01-03 MEDIUM 5.0 CVE-2012-4557EPSS 17% The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-pr… HTTP Server Patch available Fix from $1,6002012-11-30 MEDIUM 5.0 CVE-2012-5568EPSS 10% Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowlo… Tomcat after 7.0.105 Fix from $1,6002012-11-30 MEDIUM 5.0 CVE-2012-5885EPSS 9% The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.… Tomcat Mitigation only Fix from $1,6002012-11-17 MEDIUM 5.0 CVE-2012-5886EPSS 9% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio… Tomcat Mitigation only Fix from $1,6002012-11-17 MEDIUM 5.0 CVE-2012-5887EPSS 12% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly… Tomcat 5.5.36 / 6.0.36+ Fix from $1,6002012-11-17