imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2019-6111
Medium 5.9

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only dir…

apache mina_sshd · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · and 15 more
0.58EPSS
CVE-2022-37436
Medium 5.3

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by t…

apache http_server
0.58EPSS
CVE-2017-7668
High 7.5

The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be a…

apache http_server · apple mac_os_x · debian debian_linux · netapp clustered_data_ontap · and 9 more
0.57EPSS
CVE-2020-13943
Medium 4.3

If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent req…

apache tomcat · debian debian_linux · oracle instantis_enterprisetrack · oracle sd-wan_edge
0.57EPSS
CVE-2018-8006
Medium 6.1

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilt…

apache activemq
0.57EPSS
CVE-2015-5259
High 8.6

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds re…

apache subversion
0.57EPSS
CVE-2024-27317
High 8.4

In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a malicious file is uploaded, it could exploit a directory traversal vulnerability.…

apache pulsar
0.57EPSS
CVE-2022-28731
Medium 6.5

A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login pa…

apache jspwiki
0.57EPSS
CVE-2017-9788
Critical 9.1

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no …

apache http_server · apple mac_os_x · debian debian_linux · netapp oncommand_unified_manager · and 11 more
0.57EPSS
CVE-2001-0731
Medium 5.0

Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.

apache http_server
0.57EPSS
CVE-2002-0061
High 7.5

Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell inte…

apache http_server
0.57EPSS
CVE-2020-1927
Medium 6.1

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

apache http_server · broadcom brocade_fabric_operating_system · canonical ubuntu_linux · debian debian_linux · and 10 more
0.57EPSS
CVE-2020-9484
High 7.0

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager…

apache tomcat · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · and 22 more
0.57EPSS
CVE-2016-0784
Medium 6.5

Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.

apache openmeetings
0.56EPSS
CVE-2025-48988
High 7.5

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time th…

apache tomcat
0.56EPSS
CVE-2019-9516
Medium 6.5

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. So…

apache traffic_server · apple swiftnio · canonical ubuntu_linux · debian debian_linux · and 15 more
0.56EPSS
CVE-2013-6397
Medium 4.3

Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. …

apache solr
0.56EPSS
CVE-2018-8011
High 7.5

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).

apache http_server · netapp cloud_backup
0.56EPSS
CVE-2016-5387
High 8.1

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's…

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · and 16 more
0.56EPSS
CVE-2021-29200
Critical 9.8

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

apache ofbiz
0.55EPSS
CVE-2004-0942
Medium 5.0

Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.

apache http_server
0.55EPSS
CVE-2021-44521
Critical 9.1

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. …

apache cassandra
0.55EPSS
CVE-2022-43396
High 8.8

In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.

apache kylin
0.55EPSS
CVE-2008-2168
Medium 4.3

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

apache http_server
0.55EPSS
CVE-2010-3863
Medium 5.0

Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./accoun…

apache shiro · jsecurity jsecurity
0.55EPSS