imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2013-1862
Medium 5.1

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an esca…

apache http_server · canonical ubuntu_linux · opensuse opensuse · oracle http_server · and 6 more
0.25EPSS
CVE-2013-4002
High 7.1

XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60…

apache xerces2_java · canonical ubuntu_linux · ibm host_on-demand · ibm java · and 11 more
0.25EPSS
CVE-2020-17527
High 7.5

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated wit…

apache tomcat · debian debian_linux · netapp element_plug-in · netapp oncommand_system_manager · and 8 more
0.25EPSS
CVE-2002-2029
High 7.5

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

apache http_server
0.25EPSS
CVE-2020-11989
Critical 9.8

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

apache shiro
0.24EPSS
CVE-2025-60021
Critical 9.8

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate t…

apache brpc
0.24EPSS
CVE-2009-3560
Medium 5.0

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a …

apache http_server · libexpat_project libexpat
0.24EPSS
CVE-2005-3357
Medium 5.4

mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL po…

apache http_server
0.24EPSS
CVE-2024-37389
Medium 4.6

Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitra…

apache nifi
0.24EPSS
CVE-2024-52046
Critical 9.8

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses. This vulnerability allows attackers to exploit the deserialization process by se…

apache mina
0.24EPSS
CVE-2019-0189
Critical 9.8

The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "ser…

apache ofbiz
0.24EPSS
CVE-2000-1205
Medium 4.3

Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response …

apache http_server
0.24EPSS
CVE-2005-0808
Medium 5.0

Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.

apache tomcat
0.23EPSS
CVE-2020-17526
High 7.7

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. Thi…

apache airflow
0.23EPSS
CVE-2020-1957
Critical 9.8

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

apache shiro · debian debian_linux
0.23EPSS
CVE-2025-57738
High 7.2

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being p…

apache syncope
0.23EPSS
CVE-2024-24549
High 7.5

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after a…

apache tomcat · debian debian_linux · fedoraproject fedora
0.23EPSS
CVE-2010-0432
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId pa…

apache ofbiz
0.23EPSS
CVE-2012-4558
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attacke…

apache http_server
0.23EPSS
CVE-2012-3499
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod…

apache http_server
0.23EPSS
CVE-2017-15709
Low 3.7

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

apache activemq
0.23EPSS
CVE-2021-24122
Medium 5.9

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root c…

apache tomcat · debian debian_linux · oracle agile_plm
0.23EPSS
CVE-2020-13936
High 8.8

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modi…

apache velocity_engine · apache wss4j · debian debian_linux · oracle banking_deposits_and_lines_of_credit_servicing · and 12 more
0.23EPSS
CVE-2021-26919
High 8.8

Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, which, if le…

apache druid
0.23EPSS
CVE-2012-2687
Low 2.6

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbit…

apache http_server
0.23EPSS