Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.1
CVE-2006-2447EPSS 75%
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a craft…
Spamassassin
Patch available
HIGH 7.8
CVE-2006-2806EPSS 6%
The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption)…
James
No fix yet
HIGH 7.5
CVE-2006-1546EPSS 6%
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html…
Struts
after 1.2.8
HIGH 7.5
CVE-2006-1547 KEVEPSS 55%
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a mult…
Struts
1.2.9+
MEDIUM 5.0
CVE-2006-0743EPSS 6%
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corrupti…
Log4net
Patch available
HIGH 7.2
CVE-2006-1095
Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a …
Mod Python
Patch available
MEDIUM 5.0
CVE-2006-0042EPSS 6%
Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remo…
Libapreq2
2.07+
HIGH 7.8
CVE-2005-4836
The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot…
Tomcat
No fix yet
MEDIUM 5.4
CVE-2005-3357EPSS 24%
mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers …
HTTP Server
Patch available
MEDIUM 5.0
CVE-2005-4703EPSS 26%
Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DO…
Tomcat
No fix yet
MEDIUM 5.0
CVE-2005-4849
Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b)…
Derby
after 10.1.1.0
MEDIUM 5.0
CVE-2005-3351EPSS 7%
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus e…
Spamassassin
Patch available
MEDIUM 5.0
CVE-2005-3510EPSS 6%
Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to l…
Tomcat
Patch available
MEDIUM 5.0
CVE-2005-2970EPSS 14%
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consump…
HTTP Server
2.0.55+
HIGH 10.0
CVE-2005-2700EPSS 31%
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enfor…
HTTP Server
2.0.55+
MEDIUM 5.0
CVE-2005-2728EPSS 11%
The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a…
HTTP Server
Patch available
MEDIUM 5.0
CVE-2005-1268EPSS 8%
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attack…
HTTP Server
after 2.0.54
MEDIUM 5.0
CVE-2005-1266EPSS 8%
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a …
Spamassassin
Patch available
HIGH 7.5
CVE-2005-0088EPSS 6%
The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.
Mod Python
after 2.7.8
HIGH 7.5
CVE-2005-1344EPSS 29%
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normal…
HTTP Server
No fix yet
MEDIUM 5.0
CVE-2005-0808EPSS 23%
Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
Tomcat
Mitigation only
HIGH 7.8
CVE-2004-0940
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrar…
HTTP Server
after 1.3.32
MEDIUM 5.0
CVE-2004-0942EPSS 55%
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header…
HTTP Server
after 2.0.52
MEDIUM 5.0
CVE-2005-0108
Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MES…
Mod Auth Radius
No fix yet
HIGH 7.5
CVE-2004-0811EPSS 7%
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted re…
HTTP Server
Patch available
HIGH 7.2
CVE-2004-2343
Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as De…
HTTP Server
after 2.0.47
MEDIUM 5.0
CVE-2004-1575EPSS 6%
The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML documen…
Xerces C\+\+
Patch available
MEDIUM 5.0
CVE-2004-2680
mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filt…
Mod Python
after 3.1.4
MEDIUM 5.0
CVE-2004-0263
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child proce…
HTTP Server
Mitigation only
HIGH 7.5
CVE-2004-0885EPSS 14%
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients…
HTTP Server
Patch available