Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2011-3375EPSS 7%
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request object…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2012-0022EPSS 11%
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2011-1184EPSS 9%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the…
Tomcat
Patch available
MEDIUM 5.0
CVE-2011-5062EPSS 8%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qo…
Tomcat
Patch available
MEDIUM 5.0
CVE-2011-5057EPSS 29%
Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and req…
Struts
2.3.3+
CRITICAL 9.8
CVE-2012-0391 KEVEPSS 76%
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling fo…
Struts
2.2.3.1+
MEDIUM 6.8
CVE-2012-0392EPSS 98%
The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute a…
Struts
2.3.1+
MEDIUM 6.8
CVE-2012-0394EPSS 75%
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary command…
Struts
after 2.3.17
MEDIUM 6.4
CVE-2012-0393EPSS 37%
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to c…
Struts
2.3.1.1+
MEDIUM 5.0
CVE-2011-4858EPSS 80%
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to tri…
Tomcat
No fix yet
MEDIUM 5.0
CVE-2011-4905EPSS 8%
Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending ma…
Activemq
after 5.5.1
HIGH 7.8
CVE-2011-5034EPSS 81%
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, wh…
Geronimo
after 2.2.1
MEDIUM 5.0
CVE-2007-6750EPSS 71%
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by…
HTTP Server
after 2.2.14
MEDIUM 5.0
CVE-2011-3368EPSS 91%
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with u…
HTTP Server
Patch available
HIGH 7.5
CVE-2011-3190EPSS 15%
Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other …
Tomcat
No fix yet
HIGH 7.8
CVE-2011-3192EPSS 99%
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of ser…
HTTP Server
2.0.65 / 2.2.20+
MEDIUM 5.0
CVE-2011-2729EPSS 7%
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33,…
Tomcat
Patch available
MEDIUM 5.0
CVE-2011-2516EPSS 8%
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, a…
Xml Security For C\+\+
after 2.4.2
MEDIUM 5.0
CVE-2011-1752EPSS 8%
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of se…
Subversion
1.6.17 / 10.7.3+
MEDIUM 6.5
CVE-2011-2329
The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration …
Rampart\/c
Patch available
MEDIUM 6.8
CVE-2011-1026
Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij…
Archiva
No fix yet
MEDIUM 5.0
CVE-2011-2088EPSS 6%
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive informati…
Struts
Patch available
MEDIUM 5.8
CVE-2011-1183EPSS 6%
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended…
Tomcat
Patch available
MEDIUM 5.0
CVE-2011-1475EPSS 9%
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses…
Tomcat
Patch available
MEDIUM 5.8
CVE-2011-1088EPSS 6%
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via…
Tomcat
Patch available
MEDIUM 5.8
CVE-2011-1419EPSS 7%
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers…
Tomcat
Patch available
MEDIUM 5.0
CVE-2011-0534EPSS 8%
Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector…
Tomcat
Patch available
HIGH 9.3
CVE-2010-3450EPSS 11%
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a…
Openoffice
3.3.0+
HIGH 9.3
CVE-2010-3451EPSS 10%
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…
Openoffice
3.3.0+
HIGH 9.3
CVE-2010-3452EPSS 10%
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…
Openoffice
3.3.0+