imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2011-0715
Medium 4.3

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.

apache subversion
0.06EPSS
CVE-2018-8004
Medium 6.5

There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.…

apache traffic_server · debian debian_linux
0.06EPSS
CVE-2016-8741
High 7.5

The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these Authenticatio…

apache qpid_broker-j
0.06EPSS
CVE-2015-2944
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlRespons…

apache sling_api · apache sling_servlets_post
0.06EPSS
CVE-2024-52316
Critical 9.8

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an …

apache tomcat · debian debian_linux
0.06EPSS
CVE-2023-41835
High 7.5

When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2…

apache struts
0.06EPSS
CVE-2017-3159
Critical 9.8

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.

apache camel
0.06EPSS
CVE-2026-29146
High 7.5

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.…

apache tomcat
0.06EPSS
CVE-2006-2806
High 7.8

The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.

apache james
0.06EPSS
CVE-2019-12406
Medium 6.5

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of me…

apache cxf · oracle commerce_guided_search · oracle flexcube_private_banking · oracle retail_order_broker
0.06EPSS
CVE-2021-38153
Medium 5.9

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or highe…

apache kafka · oracle communications_brm_-_elastic_charging_engine · oracle communications_cloud_native_core_policy · oracle financial_services_analytical_applications_infrastructure · and 4 more
0.06EPSS
CVE-2017-3162
High 7.3

HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0.

apache hadoop
0.06EPSS
CVE-2016-4974
High 7.5

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and ex…

apache amqp_0-x_jms_client · apache jms_client_amqp
0.06EPSS
CVE-2016-0706
Medium 4.3

Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated…

apache tomcat · canonical ubuntu_linux · debian debian_linux
0.06EPSS
CVE-2006-0042
Medium 5.0

Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers to cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic…

apache libapreq2 · debian debian_linux
0.06EPSS
CVE-2006-0743
Medium 5.0

Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.

apache log4net
0.06EPSS
CVE-2003-0017
Medium 5.0

Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.

apache http_server
0.06EPSS
CVE-2021-23926
Critical 9.1

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

apache xmlbeans · debian debian_linux · netapp oncommand_unified_manager_core_package · netapp snap_creator_framework · and 3 more
0.06EPSS
CVE-2017-15702
Critical 9.8

In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port into…

apache qpid_broker-j
0.06EPSS
CVE-2020-1941
Medium 6.1

In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.

apache activemq · oracle communications_diameter_signaling_router · oracle communications_element_manager · oracle communications_session_report_manager · and 3 more
0.06EPSS
CVE-2019-0223
High 7.4

While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* w…

apache qpid · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · redhat enterprise_linux_server · and 6 more
0.06EPSS
CVE-2004-1575
Medium 5.0

The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.

apache xerces-c\+\+
0.06EPSS
CVE-2021-44140
Critical 9.1

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki user…

apache jspwiki
0.06EPSS
CVE-2026-33453
Critical 10.0

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when route…

apache camel
0.06EPSS
CVE-2022-34305
Medium 6.1

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.

apache tomcat
0.06EPSS