Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.1 CVE-2006-2447EPSS 75% SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a craft… Spamassassin Patch available Fix from $1,6002006-06-06 HIGH 7.8 CVE-2006-2806EPSS 6% The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption)… James No fix yet Fix from $1,9502006-06-05 HIGH 7.5 CVE-2006-1546EPSS 6% Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html… Struts after 1.2.8 Fix from $1,9502006-03-30 HIGH 7.5 CVE-2006-1547 KEVEPSS 55% ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a mult… Struts 1.2.9+ Fix from $1,9502006-03-30 MEDIUM 5.0 CVE-2006-0743EPSS 6% Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corrupti… Log4net Patch available Fix from $1,6002006-03-09 HIGH 7.2 CVE-2006-1095 Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a … Mod Python Patch available Fix from $1,9502006-03-09 MEDIUM 5.0 CVE-2006-0042EPSS 6% Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remo… Libapreq2 2.07+ Fix from $1,6002006-02-18 HIGH 7.8 CVE-2005-4836 The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot… Tomcat No fix yet Fix from $1,9502005-12-31 MEDIUM 5.4 CVE-2005-3357EPSS 24% mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers … HTTP Server Patch available Fix from $1,6002005-12-31 MEDIUM 5.0 CVE-2005-4703EPSS 26% Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DO… Tomcat No fix yet Fix from $1,6002005-12-31 MEDIUM 5.0 CVE-2005-4849 Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b)… Derby after 10.1.1.0 Fix from $1,6002005-12-31 MEDIUM 5.0 CVE-2005-3351EPSS 7% SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus e… Spamassassin Patch available Fix from $1,6002005-11-20 MEDIUM 5.0 CVE-2005-3510EPSS 6% Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to l… Tomcat Patch available Fix from $1,6002005-11-06 MEDIUM 5.0 CVE-2005-2970EPSS 14% Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consump… HTTP Server 2.0.55+ Fix from $1,6002005-10-25 HIGH 10.0 CVE-2005-2700EPSS 31% ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enfor… HTTP Server 2.0.55+ Fix from $1,9502005-09-06 MEDIUM 5.0 CVE-2005-2728EPSS 11% The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a… HTTP Server Patch available Fix from $1,6002005-08-30 MEDIUM 5.0 CVE-2005-1268EPSS 8% Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attack… HTTP Server after 2.0.54 Fix from $1,6002005-08-05 MEDIUM 5.0 CVE-2005-1266EPSS 8% Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a … Spamassassin Patch available Fix from $1,6002005-06-15 HIGH 7.5 CVE-2005-0088EPSS 6% The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL. Mod Python after 2.7.8 Fix from $1,9502005-05-02 HIGH 7.5 CVE-2005-1344EPSS 29% Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normal… HTTP Server No fix yet Fix from $1,9502005-05-02 MEDIUM 5.0 CVE-2005-0808EPSS 23% Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007. Tomcat Mitigation only Fix from $1,6002005-05-02 HIGH 7.8 CVE-2004-0940 Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrar… HTTP Server after 1.3.32 Fix from $1,9502005-02-09 MEDIUM 5.0 CVE-2004-0942EPSS 55% Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header… HTTP Server after 2.0.52 Fix from $1,6002005-02-09 MEDIUM 5.0 CVE-2005-0108 Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MES… Mod Auth Radius No fix yet Fix from $1,6002005-01-11 HIGH 7.5 CVE-2004-0811EPSS 7% Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted re… HTTP Server Patch available Fix from $1,9502004-12-31 HIGH 7.2 CVE-2004-2343 Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as De… HTTP Server after 2.0.47 Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2004-1575EPSS 6% The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML documen… Xerces C\+\+ Patch available Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2004-2680 mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filt… Mod Python after 3.1.4 Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2004-0263 PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child proce… HTTP Server Mitigation only Fix from $1,6002004-11-23 HIGH 7.5 CVE-2004-0885EPSS 14% The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients… HTTP Server Patch available Fix from $1,9502004-11-03