Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2008-2717 TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al… Apache Webserver Mitigation only Fix from $1,6002008-06-16 MEDIUM 5.0 CVE-2008-2364EPSS 13% The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the… HTTP Server 2.0.64 / 2.2.9+ Fix from $1,6002008-06-13 HIGH 7.5 CVE-2007-6258EPSS 41% Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via … Mod Jk Patch available Fix from $1,9502008-02-19 MEDIUM 5.8 CVE-2008-0002EPSS 5% Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, whi… Tomcat Mitigation only Fix from $1,6002008-02-12 MEDIUM 5.0 CVE-2007-5333EPSS 63% Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5… Tomcat after 6.0.14 Fix from $1,6002008-02-12 MEDIUM 5.0 CVE-2008-0128EPSS 20% The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONI… Tomcat after 5.5.20 Fix from $1,6002008-01-23 HIGH 7.8 CVE-2007-6423 Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to tr… HTTP Server Mitigation only Fix from $1,9502008-01-12 MEDIUM 6.4 CVE-2007-5342EPSS 5% The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain pe… Tomcat Patch available Fix from $1,6002007-12-27 HIGH 7.5 CVE-2007-5797 SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut… Geronimo Mitigation only Fix from $1,9502007-11-03 MEDIUM 5.0 CVE-2007-5085 Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a… Geronimo Mitigation only Fix from $1,6002007-09-26 HIGH 9.3 CVE-2007-2834EPSS 12% Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attack… Openoffice 2.3.0+ Fix from $1,9502007-09-18 MEDIUM 6.1 CVE-2007-4465EPSS 26% Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is no… HTTP Server 2.0.61 / 2.2.6+ Fix from $1,6002007-09-14 HIGH 10.0 CVE-2007-4548 The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote att… Geronimo Patch available Fix from $1,9502007-08-27 MEDIUM 5.0 CVE-2007-3847EPSS 13% The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a … HTTP Server 2.0.61 / 2.2.6+ Fix from $1,6002007-08-23 MEDIUM 5.0 CVE-2007-1863EPSS 12% cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, all… HTTP Server 2.0.61 / 2.2.6+ Fix from $1,6002007-06-27 MEDIUM 5.0 CVE-2007-1862EPSS 6% The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP … HTTP Server Patch available Fix from $1,6002007-06-04 MEDIUM 5.0 CVE-2007-1860EPSS 13% mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomc… Tomcat Jk Web Server Connector after 1.2.22 Fix from $1,6002007-05-25 MEDIUM 5.0 CVE-2007-2353EPSS 28% Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path i… Axis No fix yet Fix from $1,6002007-04-30 HIGH 7.8 CVE-2006-7197EPSS 8% The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_… Tomcat Patch available Fix from $1,9502007-04-25 MEDIUM 6.2 CVE-2007-1741 Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to g… HTTP Server Mitigation only Fix from $1,6002007-04-13 MEDIUM 5.0 CVE-2007-1349EPSS 10% PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expressi… Mod Perl 1.30+ Fix from $1,6002007-03-30 MEDIUM 5.0 CVE-2007-0450EPSS 91% Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_pro… HTTP Server 5.5.22 / 6.0.10+ Fix from $1,6002007-03-16 HIGH 7.5 CVE-2007-0774EPSS 82% Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connec… Tomcat Jk Web Server Connector Patch available Fix from $1,9502007-03-04 HIGH 7.8 CVE-2007-0086EPSS 10% The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ… HTTP Server Mitigation only Fix from $1,9502007-01-05 HIGH 7.5 CVE-2006-6588 The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTyp… Ofbiz No fix yet Fix from $1,9502006-12-15 MEDIUM 6.8 CVE-2006-6587EPSS 8% Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allow… Ofbiz No fix yet Fix from $1,6002006-12-15 MEDIUM 6.8 CVE-2006-6589 Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows… Ofbiz No fix yet Fix from $1,6002006-12-15 MEDIUM 6.8 CVE-2006-4154EPSS 16% Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string s… HTTP Server Patch available Fix from $1,6002006-10-16 HIGH 7.6 CVE-2006-3747EPSS 96% Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, … HTTP Server 1.3.37 / 2.0.59+ Fix from $1,9502006-07-28 MEDIUM 5.0 CVE-2006-3835EPSS 46% Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demons… Tomcat Patch available Fix from $1,6002006-07-25