imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2026-45434
Critical 9.8

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

apache ofbiz
0.22EPSS
CVE-2011-3348
Medium 4.3

The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.

apache http_server · redhat jboss_enterprise_web_server
0.22EPSS
CVE-2010-1632
High 7.5

Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, an…

apache axis2
0.22EPSS
CVE-2004-0748
Medium 5.0

mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.

apache http_server
0.22EPSS
CVE-2014-2668
Medium 5.0

Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

apache couchdb
0.22EPSS
CVE-2019-12409
Critical 9.8

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then…

apache solr
0.22EPSS
CVE-2014-8109
Medium 4.3

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attack…

apache http_server · canonical ubuntu_linux · fedoraproject fedora · oracle enterprise_manager_ops_center
0.22EPSS
CVE-2010-1452
Medium 5.0

The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.

apache http_server
0.22EPSS
CVE-2004-0786
Medium 5.0

The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.

apache http_server
0.22EPSS
CVE-2018-8014
Critical 9.8

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have …

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp oncommand_insight · and 4 more
0.22EPSS
CVE-2009-0026
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.

apache jackrabbit
0.22EPSS
CVE-2018-1308
High 7.5

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arb…

apache solr · debian debian_linux
0.21EPSS
CVE-2002-0843
High 7.5

Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.

apache http_server · oracle application_server · oracle database_server · oracle oracle8i
0.21EPSS
CVE-2018-8034
High 7.5

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.

apache tomcat · canonical ubuntu_linux · debian debian_linux · oracle retail_order_broker
0.21EPSS
CVE-2015-0899
High 7.5

The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.

apache struts
0.21EPSS
CVE-2013-0177
Low 3.5

Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script …

apache ofbiz
0.21EPSS
CVE-2021-25641
Critical 9.8

Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by tampering with the byte…

apache dubbo
0.21EPSS
CVE-2014-0227
Medium 6.4

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to c…

apache tomcat
0.21EPSS
CVE-2016-2161
High 7.5

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.

apache http_server
0.21EPSS
CVE-2010-0408
Medium 5.0

The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service …

apache http_server
0.21EPSS
CVE-2017-5641
Critical 9.8

Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undesired side-effects. Ot…

apache flex_blazeds · hp xp_command_view_advanced_edition
0.21EPSS
CVE-2018-17199
High 7.5

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decode…

apache http_server · canonical ubuntu_linux · debian debian_linux · netapp santricity_cloud_connector · and 2 more
0.21EPSS
CVE-2019-0186
Medium 6.1

The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of the chat-room-demo war file

apache pluto
0.21EPSS
CVE-2018-1336
High 7.5

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to …

apache tomcat · canonical ubuntu_linux · debian debian_linux · redhat enterprise_linux_desktop · and 4 more
0.21EPSS
CVE-2005-2088
Medium 4.3

The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding…

apache http_server · debian debian_linux
0.20EPSS