imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2016-4469
High 8.8

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add new repository proxy connectors via the token parameter to admin/addP…

apache archiva
0.08EPSS
CVE-2013-4505
Low 2.6

The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a…

apache mod_dontdothat · apache subversion
0.08EPSS
CVE-2019-19924
Medium 5.3

SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling.

apache bookkeeper · netapp cloud_backup · oracle mysql_workbench · siemens sinec_infrastructure_network_services · and 1 more
0.08EPSS
CVE-2005-4838
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotat…

apache tomcat
0.08EPSS
CVE-2002-0935
Medium 5.0

Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.

apache tomcat
0.08EPSS
CVE-2022-29266
High 7.5

In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.

apache apisix
0.08EPSS
CVE-2019-0219
Critical 9.8

A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.

apache cordova_inappbrowser · oracle instantis_enterprisetrack · oracle retail_xstore_point_of_service
0.08EPSS
CVE-2016-3094
Medium 5.9

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught except…

apache qpid_broker-j
0.08EPSS
CVE-2001-1449
High 7.5

The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.

apache http_server · mandrakesoft mandrake_linux · mandrakesoft mandrake_linux_corporate_server · mandrakesoft mandrake_single_network_firewall
0.08EPSS
CVE-2016-5017
High 8.1

Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.

apache zookeeper
0.08EPSS
CVE-2021-29262
High 7.5

When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sen…

apache solr
0.08EPSS
CVE-2002-0240
Medium 5.0

PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.

apache http_server
0.08EPSS
CVE-2012-4501
High 10.0

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.

apache cloudstack · citrix cloudstack
0.08EPSS
CVE-2012-6551
Medium 5.0

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.

apache activemq
0.08EPSS
CVE-2018-17191
Critical 9.8

Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the nashorn script engine the environment of the javascript execution for the Proxy Auto-Configuration leaks privile…

apache netbeans
0.08EPSS
CVE-2017-5651
Critical 9.8

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processo…

apache tomcat
0.08EPSS
CVE-2014-0072
High 7.5

ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9.0 might allow remote attackers to spoof SSL servers by lever…

apache cordova · apache cordova_file_transfer
0.08EPSS
CVE-2018-1318
High 7.5

Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or lat…

apache traffic_server · debian debian_linux
0.08EPSS
CVE-2011-2516
Medium 5.0

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which trigge…

apache xml_security_for_c\+\+ · shibboleth shibboleth-sp
0.08EPSS
CVE-2016-2162
Medium 6.1

Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.

apache struts
0.08EPSS
CVE-2013-2137
Medium 4.3

Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web scr…

apache ofbiz
0.08EPSS
CVE-2020-11974
Critical 9.8

In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.

apache dolphinscheduler
0.08EPSS
CVE-2011-5062
Medium 5.0

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=aut…

apache tomcat
0.08EPSS
CVE-2014-0119
Medium 4.3

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application…

apache tomcat
0.08EPSS
CVE-2015-1774
Medium 6.8

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds wri…

apache openoffice · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · and 4 more
0.08EPSS