imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2014-0231
Media 5.0

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

apache http_server
0.44EPSS
CVE-2010-0010
Media 6.8

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a l…

apache http_server
0.43EPSS
CVE-2020-13954
Media 6.1

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject jav…

apache cxf · netapp snap_creator_framework · netapp vasa_provider_for_clustered_data_ontap · oracle business_intelligence · e altri 2
0.43EPSS
CVE-2012-0840
Media 5.0

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) vi…

apache portable_runtime
0.43EPSS
CVE-2016-2171
Alta 7.5

The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.

apache jetspeed
0.43EPSS
CVE-2022-33980
Critica 9.8

Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configurat…

apache commons_configuration · debian debian_linux · netapp snapcenter
0.43EPSS
CVE-2010-4172
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsLis…

apache tomcat
0.42EPSS
CVE-2022-22721
Critica 9.1

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

apache http_server · apple mac_os_x · apple macos · debian debian_linux · e altri 4
0.42EPSS
CVE-2024-45387
Critica 9.9

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-craf…

apache traffic_control
0.42EPSS
CVE-2024-38476
Critica 9.8

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2…

apache http_server · netapp clustered_data_ontap
0.42EPSS
CVE-2007-6258
Alta 7.5

Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.

apache mod_jk · f5 big-ip
0.41EPSS
CVE-2002-2007
Media 5.0

The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp…

apache tomcat
0.41EPSS
CVE-2025-61622
Critica 9.8

Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untrusted sourc…

apache fory
0.41EPSS
CVE-2025-30065
Critica 9.8

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

apache parquet_java
0.41EPSS
CVE-2015-3253
Critica 9.8

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.

apache groovy · oracle health_sciences_clinical_development_center · oracle retail_order_broker_cloud_service · oracle retail_service_backbone · e altri 2
0.41EPSS
CVE-2020-17525
Alta 7.5

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. …

apache subversion · debian debian_linux
0.40EPSS
CVE-2021-37580
Critica 9.8

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0

apache shenyu
0.40EPSS
CVE-2015-0252
Media 5.0

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.

apache xerces-c\+\+ · debian debian_linux · fedoraproject fedora
0.40EPSS
CVE-2007-5461
Bassa 3.5

Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that sp…

apache tomcat
0.40EPSS
CVE-2016-6816
Alta 7.1

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted …

apache tomcat
0.40EPSS
CVE-2021-39275
Critica 9.8

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

apache http_server · debian debian_linux · fedoraproject fedora · netapp cloud_backup · e altri 7
0.39EPSS
CVE-2006-4110
Media 4.3

Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-i…

apache http_server
0.39EPSS
CVE-2017-7679
Critica 9.8

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.

apache http_server
0.39EPSS
CVE-2008-2939
Media 4.3

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script o…

apache http_server · apple mac_os_x · canonical ubuntu_linux · opensuse opensuse
0.39EPSS
CVE-2015-5254
Critica 9.8

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

apache activemq · fedoraproject fedora · redhat openshift
0.38EPSS