imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2015-5212
Medium 6.8

Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash…

apache openoffice · canonical ubuntu_linux · debian debian_linux · libreoffice libreoffice
0.09EPSS
CVE-2018-17190
Critical 9.8

In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A specially-crafted request to the master can, ho…

apache spark
0.09EPSS
CVE-2017-9793
High 7.5

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.

apache struts
0.09EPSS
CVE-2021-26291
Critical 9.1

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a positi…

apache maven · oracle financial_services_analytical_applications_infrastructure · oracle goldengate_big_data_and_application_adapters · quarkus quarkus
0.09EPSS
CVE-2011-1475
Medium 5.0

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, r…

apache tomcat
0.09EPSS
CVE-2020-13956
Medium 5.3

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

apache httpclient · netapp active_iq_unified_manager · netapp snapcenter · oracle commerce_guided_search · and 13 more
0.09EPSS
CVE-2016-0734
Medium 6.1

The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME el…

apache activemq
0.09EPSS
CVE-2025-27533
High 7.5

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of …

apache activemq
0.09EPSS
CVE-2015-6524
Medium 5.0

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this…

apache activemq · fedoraproject fedora
0.09EPSS
CVE-2009-3094
Low 2.6

The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed rep…

apache http_server · debian debian_linux · fedoraproject fedora
0.09EPSS
CVE-2011-1184
Medium 5.0

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended…

apache tomcat
0.09EPSS
CVE-2017-12621
Critical 9.8

During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser instantiation the parser will attempt to connect to said URL. This…

apache commons_jelly
0.09EPSS
CVE-2009-0023
Medium 4.3

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMa…

apache apr-util · apache http_server
0.09EPSS
CVE-2015-0203
Medium 6.5

The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3) a se…

apache qpid
0.09EPSS
CVE-2013-4330
Medium 6.8

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.

apache camel
0.09EPSS
CVE-2014-0095
Medium 5.0

java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.

apache tomcat
0.08EPSS
CVE-2011-1752
Medium 5.0

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited i…

apache subversion · apple mac_os_x · canonical ubuntu_linux · debian debian_linux · and 1 more
0.08EPSS
CVE-2019-0194
High 7.5

Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.

apache camel
0.08EPSS
CVE-2016-6793
Critical 9.1

The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before…

apache wicket
0.08EPSS
CVE-2022-25762
High 8.6

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it ha…

apache tomcat · oracle agile_plm
0.08EPSS
CVE-2013-2156
High 7.5

Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows remote attackers to cause a denial of service (crash) and possibly ex…

apache xml_security_for_c\+\+
0.08EPSS
CVE-2018-8012
High 7.5

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to th…

apache zookeeper · debian debian_linux · oracle goldengate_stream_analytics
0.08EPSS
CVE-2005-1268
Medium 5.0

Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte…

apache http_server · debian debian_linux · redhat enterprise_linux_desktop · redhat enterprise_linux_server · and 1 more
0.08EPSS
CVE-2016-3093
Medium 5.3

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.

apache struts · ognl_project ognl
0.08EPSS
CVE-2017-12627
Critical 9.8

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

apache xerces-c\+\+
0.08EPSS