Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2008-2717
TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al…
Apache Webserver
Mitigation only
MEDIUM 5.0
CVE-2008-2364EPSS 13%
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the…
HTTP Server
2.0.64 / 2.2.9+
HIGH 7.5
CVE-2007-6258EPSS 41%
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via …
Mod Jk
Patch available
MEDIUM 5.8
CVE-2008-0002EPSS 5%
Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, whi…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2007-5333EPSS 63%
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5…
Tomcat
after 6.0.14
MEDIUM 5.0
CVE-2008-0128EPSS 20%
The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONI…
Tomcat
after 5.5.20
HIGH 7.8
CVE-2007-6423
Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to tr…
HTTP Server
Mitigation only
MEDIUM 6.4
CVE-2007-5342EPSS 5%
The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain pe…
Tomcat
Patch available
HIGH 7.5
CVE-2007-5797
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut…
Geronimo
Mitigation only
MEDIUM 5.0
CVE-2007-5085
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a…
Geronimo
Mitigation only
HIGH 9.3
CVE-2007-2834EPSS 12%
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attack…
Openoffice
2.3.0+
MEDIUM 6.1
CVE-2007-4465EPSS 26%
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is no…
HTTP Server
2.0.61 / 2.2.6+
HIGH 10.0
CVE-2007-4548
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote att…
Geronimo
Patch available
MEDIUM 5.0
CVE-2007-3847EPSS 13%
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a …
HTTP Server
2.0.61 / 2.2.6+
MEDIUM 5.0
CVE-2007-1863EPSS 12%
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, all…
HTTP Server
2.0.61 / 2.2.6+
MEDIUM 5.0
CVE-2007-1862EPSS 6%
The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP …
HTTP Server
Patch available
MEDIUM 5.0
CVE-2007-1860EPSS 13%
mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomc…
Tomcat Jk Web Server Connector
after 1.2.22
MEDIUM 5.0
CVE-2007-2353EPSS 28%
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path i…
Axis
No fix yet
HIGH 7.8
CVE-2006-7197EPSS 8%
The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_…
Tomcat
Patch available
MEDIUM 6.2
CVE-2007-1741
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to g…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2007-1349EPSS 10%
PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expressi…
Mod Perl
1.30+
MEDIUM 5.0
CVE-2007-0450EPSS 91%
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_pro…
HTTP Server
5.5.22 / 6.0.10+
HIGH 7.5
CVE-2007-0774EPSS 82%
Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connec…
Tomcat Jk Web Server Connector
Patch available
HIGH 7.8
CVE-2007-0086EPSS 10%
The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ…
HTTP Server
Mitigation only
HIGH 7.5
CVE-2006-6588
The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTyp…
Ofbiz
No fix yet
MEDIUM 6.8
CVE-2006-6587EPSS 8%
Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allow…
Ofbiz
No fix yet
MEDIUM 6.8
CVE-2006-6589
Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows…
Ofbiz
No fix yet
MEDIUM 6.8
CVE-2006-4154EPSS 16%
Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string s…
HTTP Server
Patch available
HIGH 7.6
CVE-2006-3747EPSS 96%
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, …
HTTP Server
1.3.37 / 2.0.59+
MEDIUM 5.0
CVE-2006-3835EPSS 46%
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demons…
Tomcat
Patch available