imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2013-1768
High 7.5

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attack…

apache openjpa
0.10EPSS
CVE-2018-1311
High 8.1

The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD proc…

apache xerces-c\+\+ · debian debian_linux · fedoraproject fedora · oracle goldengate · and 6 more
0.10EPSS
CVE-2021-25329
High 7.0

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE…

apache tomcat · debian debian_linux · oracle agile_plm · oracle communications_cloud_native_core_policy · and 8 more
0.09EPSS
CVE-2013-4590
Medium 4.3

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document co…

apache tomcat · debian debian_linux · oracle solaris
0.09EPSS
CVE-2007-3383
Medium 4.3

Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the Fr…

apache tomcat
0.09EPSS
CVE-2022-24070
High 7.5

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive).…

apache subversion · apple macos · debian debian_linux · fedoraproject fedora
0.09EPSS
CVE-2013-4322
Medium 4.3

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which al…

apache tomcat
0.09EPSS
CVE-2019-0228
Critical 9.8

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

apache james · apache pdfbox · fedoraproject fedora · oracle banking_corporate_lending_process_management · and 10 more
0.09EPSS
CVE-1999-0926
High 10.0

Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.

apache http_server
0.09EPSS
CVE-2020-1935
Medium 4.8

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if T…

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp data_availability_services · and 16 more
0.09EPSS
CVE-2012-5783
Medium 5.8

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifi…

apache httpclient · canonical ubuntu_linux
0.09EPSS
CVE-2014-3623
Medium 5.0

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to c…

apache cxf · apache wss4j
0.09EPSS
CVE-2012-4459
Medium 5.0

Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.

apache qpid
0.09EPSS
CVE-2016-6812
Medium 6.1

The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL usi…

apache cxf
0.09EPSS
CVE-2003-0254
Medium 5.0

Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.

apache http_server
0.09EPSS
CVE-2015-3268
Medium 6.1

Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attri…

apache ofbiz
0.09EPSS
CVE-2020-17510
Critical 9.8

Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

apache shiro · debian debian_linux
0.09EPSS
CVE-2019-0205
High 7.5

In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects on…

apache thrift · oracle communications_cloud_native_core_network_slice_selection_function · redhat jboss_enterprise_application_platform
0.09EPSS
CVE-2014-3596
Medium 5.8

The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL …

apache axis
0.09EPSS
CVE-2014-3577
Medium 5.8

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the…

apache httpasyncclient · apache httpclient
0.09EPSS
CVE-2012-4431
Medium 4.3

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

apache tomcat
0.09EPSS
CVE-2003-0044
Medium 6.8

Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.

apache tomcat
0.09EPSS
CVE-2009-0781
Medium 4.3

Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web scrip…

apache tomcat
0.09EPSS
CVE-2007-6420
Medium 4.3

Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.

apache http_server · canonical ubuntu_linux
0.09EPSS
CVE-2003-0253
Medium 5.0

The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.

apache http_server
0.09EPSS