Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 9.3 CVE-2010-3453EPSS 10% The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number… Openoffice 3.3.0+ Fix from $1,9502011-01-28 HIGH 9.3 CVE-2010-3454EPSS 10% Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote atta… Openoffice 3.3.0+ Fix from $1,9502011-01-28 HIGH 9.3 CVE-2010-4253EPSS 10% Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio… Openoffice 3.3.0+ Fix from $1,9502011-01-28 HIGH 9.3 CVE-2010-4643EPSS 10% Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio… Openoffice 3.3.0+ Fix from $1,9502011-01-28 MEDIUM 6.9 CVE-2010-3689 soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privilege… Openoffice 3.3.0+ Fix from $1,6002011-01-28 MEDIUM 6.8 CVE-2010-4539EPSS 5% The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote a… Subversion after 1.6.14 Fix from $1,6002011-01-07 MEDIUM 6.8 CVE-2010-3449 Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through … Archiva after 1.2.3 Fix from $1,6002010-12-06 MEDIUM 6.8 CVE-2010-4408 Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password … Archiva Mitigation only Fix from $1,6002010-12-06 MEDIUM 6.4 CVE-2010-4312 The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers … Tomcat Mitigation only Fix from $1,6002010-11-26 HIGH 7.5 CVE-2010-3872 A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgi… Mod Fcgid after 2.3.5 Fix from $1,9502010-11-22 MEDIUM 5.0 CVE-2010-3863EPSS 55% Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows … Shiro after 1.0.0 Fix from $1,6002010-11-05 MEDIUM 5.0 CVE-2010-2057 shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a M… Myfaces Patch available Fix from $1,6002010-10-20 HIGH 10.0 CVE-2010-0219EPSS 90% Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of a… Axis2 Patch available Fix from $1,9502010-10-18 MEDIUM 5.0 CVE-2009-5005EPSS 6% The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows r… Qpid after 1.2.2 Fix from $1,6002010-10-18 MEDIUM 6.0 CVE-2010-3315 authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SV… Subversion Patch available Fix from $1,6002010-10-04 MEDIUM 5.0 CVE-2010-1623EPSS 20% Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.… Apr Util 2.0.64 / 2.2.17+ Fix from $1,6002010-10-04 MEDIUM 6.9 CVE-2010-2953 Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges… Couchdb Mitigation only Fix from $1,6002010-09-14 MEDIUM 6.8 CVE-2010-2234 Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of admini… Couchdb Mitigation only Fix from $1,6002010-08-19 CRITICAL 9.8 CVE-2010-2076EPSS 10% Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUD… Cxf 2.0.13 / 2.1.10+ Fix from $2,3002010-08-19 MEDIUM 5.0 CVE-2010-1870EPSS 92% The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly ot… Struts No fix yet Fix from $1,6002010-08-17 MEDIUM 5.0 CVE-2010-2791EPSS 8% mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon… HTTP Server Mitigation only Fix from $1,6002010-08-05 MEDIUM 5.0 CVE-2010-1452EPSS 22% The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process … HTTP Server 2.0.64 / 2.2.16+ Fix from $1,6002010-07-28 MEDIUM 6.4 CVE-2010-2227EPSS 55% Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows r… Tomcat Patch available Fix from $1,6002010-07-13 HIGH 7.5 CVE-2010-1632EPSS 22% Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through … Axis2 after 1.5.1 Fix from $1,9502010-06-22 MEDIUM 5.0 CVE-2010-2068EPSS 16% mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in cer… HTTP Server Patch available Fix from $1,6002010-06-18 MEDIUM 5.0 CVE-2010-1587EPSS 78% The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash … Activemq Patch available Fix from $1,6002010-04-28 MEDIUM 6.8 CVE-2010-1151 Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modif… Apache Http Server Patch available Fix from $1,6002010-04-20 MEDIUM 6.8 CVE-2010-1244 Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the aut… Activemq after 5.3.0 Fix from $1,6002010-04-05 HIGH 10.0 CVE-2010-0425EPSS 94% modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when runni… HTTP Server 2.0.64 / 2.2.15+ Fix from $1,9502010-03-05 MEDIUM 5.0 CVE-2010-0408EPSS 21% The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain … HTTP Server Patch available Fix from $1,6002010-03-05