Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2011-3375EPSS 7% Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request object… Tomcat Mitigation only Fix from $1,6002012-01-19 MEDIUM 5.0 CVE-2012-0022EPSS 11% Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote… Tomcat Mitigation only Fix from $1,6002012-01-19 MEDIUM 5.0 CVE-2011-1184EPSS 9% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the… Tomcat Patch available Fix from $1,6002012-01-14 MEDIUM 5.0 CVE-2011-5062EPSS 8% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qo… Tomcat Patch available Fix from $1,6002012-01-14 MEDIUM 5.0 CVE-2011-5057EPSS 29% Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and req… Struts 2.3.3+ Fix from $1,6002012-01-08 CRITICAL 9.8 CVE-2012-0391 KEVEPSS 76% The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling fo… Struts 2.2.3.1+ Fix from $2,3002012-01-08 MEDIUM 6.8 CVE-2012-0392EPSS 98% The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute a… Struts 2.3.1+ Fix from $1,6002012-01-08 MEDIUM 6.8 CVE-2012-0394EPSS 75% The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary command… Struts after 2.3.17 Fix from $1,6002012-01-08 MEDIUM 6.4 CVE-2012-0393EPSS 37% The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to c… Struts 2.3.1.1+ Fix from $1,6002012-01-08 MEDIUM 5.0 CVE-2011-4858EPSS 80% Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to tri… Tomcat No fix yet Fix from $1,6002012-01-05 MEDIUM 5.0 CVE-2011-4905EPSS 8% Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending ma… Activemq after 5.5.1 Fix from $1,6002012-01-05 HIGH 7.8 CVE-2011-5034EPSS 81% Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, wh… Geronimo after 2.2.1 Fix from $1,9502011-12-30 MEDIUM 5.0 CVE-2007-6750EPSS 71% The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by… HTTP Server after 2.2.14 Fix from $1,6002011-12-27 MEDIUM 5.0 CVE-2011-3368EPSS 91% The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with u… HTTP Server Patch available Fix from $1,6002011-10-05 HIGH 7.5 CVE-2011-3190EPSS 15% Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other … Tomcat No fix yet Fix from $1,9502011-08-31 HIGH 7.8 CVE-2011-3192EPSS 99% The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of ser… HTTP Server 2.0.65 / 2.2.20+ Fix from $1,9502011-08-29 MEDIUM 5.0 CVE-2011-2729EPSS 7% native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33,… Tomcat Patch available Fix from $1,6002011-08-15 MEDIUM 5.0 CVE-2011-2516EPSS 8% Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, a… Xml Security For C\+\+ after 2.4.2 Fix from $1,6002011-07-11 MEDIUM 5.0 CVE-2011-1752EPSS 8% The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of se… Subversion 1.6.17 / 10.7.3+ Fix from $1,6002011-06-06 MEDIUM 6.5 CVE-2011-2329 The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration … Rampart\/c Patch available Fix from $1,6002011-06-02 MEDIUM 6.8 CVE-2011-1026 Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij… Archiva No fix yet Fix from $1,6002011-06-02 MEDIUM 5.0 CVE-2011-2088EPSS 6% XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive informati… Struts Patch available Fix from $1,6002011-05-13 MEDIUM 5.8 CVE-2011-1183EPSS 6% Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended… Tomcat Patch available Fix from $1,6002011-04-08 MEDIUM 5.0 CVE-2011-1475EPSS 9% The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses… Tomcat Patch available Fix from $1,6002011-04-08 MEDIUM 5.8 CVE-2011-1088EPSS 6% Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via… Tomcat Patch available Fix from $1,6002011-03-14 MEDIUM 5.8 CVE-2011-1419EPSS 7% Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers… Tomcat Patch available Fix from $1,6002011-03-14 MEDIUM 5.0 CVE-2011-0534EPSS 8% Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector… Tomcat Patch available Fix from $1,6002011-02-10 HIGH 9.3 CVE-2010-3450EPSS 11% Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a… Openoffice 3.3.0+ Fix from $1,9502011-01-28 HIGH 9.3 CVE-2010-3451EPSS 10% Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica… Openoffice 3.3.0+ Fix from $1,9502011-01-28 HIGH 9.3 CVE-2010-3452EPSS 10% Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica… Openoffice 3.3.0+ Fix from $1,9502011-01-28