Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 9.3
CVE-2010-3453EPSS 10%
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number…
Openoffice
3.3.0+
HIGH 9.3
CVE-2010-3454EPSS 10%
Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote atta…
Openoffice
3.3.0+
HIGH 9.3
CVE-2010-4253EPSS 10%
Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio…
Openoffice
3.3.0+
HIGH 9.3
CVE-2010-4643EPSS 10%
Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio…
Openoffice
3.3.0+
MEDIUM 6.9
CVE-2010-3689
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privilege…
Openoffice
3.3.0+
MEDIUM 6.8
CVE-2010-4539EPSS 5%
The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote a…
Subversion
after 1.6.14
MEDIUM 6.8
CVE-2010-3449
Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through …
Archiva
after 1.2.3
MEDIUM 6.8
CVE-2010-4408
Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password …
Archiva
Mitigation only
MEDIUM 6.4
CVE-2010-4312
The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers …
Tomcat
Mitigation only
HIGH 7.5
CVE-2010-3872
A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgi…
Mod Fcgid
after 2.3.5
MEDIUM 5.0
CVE-2010-3863EPSS 55%
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows …
Shiro
after 1.0.0
MEDIUM 5.0
CVE-2010-2057
shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a M…
Myfaces
Patch available
HIGH 10.0
CVE-2010-0219EPSS 90%
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of a…
Axis2
Patch available
MEDIUM 5.0
CVE-2009-5005EPSS 6%
The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows r…
Qpid
after 1.2.2
MEDIUM 6.0
CVE-2010-3315
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SV…
Subversion
Patch available
MEDIUM 5.0
CVE-2010-1623EPSS 20%
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.…
Apr Util
2.0.64 / 2.2.17+
MEDIUM 6.9
CVE-2010-2953
Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges…
Couchdb
Mitigation only
MEDIUM 6.8
CVE-2010-2234
Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of admini…
Couchdb
Mitigation only
CRITICAL 9.8
CVE-2010-2076EPSS 10%
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUD…
Cxf
2.0.13 / 2.1.10+
MEDIUM 5.0
CVE-2010-1870EPSS 92%
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly ot…
Struts
No fix yet
MEDIUM 5.0
CVE-2010-2791EPSS 8%
mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2010-1452EPSS 22%
The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process …
HTTP Server
2.0.64 / 2.2.16+
MEDIUM 6.4
CVE-2010-2227EPSS 55%
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows r…
Tomcat
Patch available
HIGH 7.5
CVE-2010-1632EPSS 22%
Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through …
Axis2
after 1.5.1
MEDIUM 5.0
CVE-2010-2068EPSS 16%
mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in cer…
HTTP Server
Patch available
MEDIUM 5.0
CVE-2010-1587EPSS 78%
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash …
Activemq
Patch available
MEDIUM 6.8
CVE-2010-1151
Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modif…
Apache Http Server
Patch available
MEDIUM 6.8
CVE-2010-1244
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the aut…
Activemq
after 5.3.0
HIGH 10.0
CVE-2010-0425EPSS 94%
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when runni…
HTTP Server
2.0.64 / 2.2.15+
MEDIUM 5.0
CVE-2010-0408EPSS 21%
The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain …
HTTP Server
Patch available