imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2019-12422
Alta 7.5

Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.

apache shiro
0.09EPSS
CVE-2025-54988
Alta 8.4

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitiv…

apache tika
0.09EPSS
CVE-2015-5209
Alta 7.5

Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.

apache struts
0.09EPSS
CVE-2017-7672
Media 5.9

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts versio…

apache struts
0.09EPSS
CVE-2024-56337
Critica 9.8

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CV…

apache tomcat · netapp bootstrap_os
0.09EPSS
CVE-2018-8026
Media 5.5

This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functional…

apache solr · netapp snapcenter · netapp storage_automation_store
0.09EPSS
CVE-2017-15691
Media 6.5

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache uimaDUCC prior to 2.2.2, this vulnerability relates to an XML external entity expansion (XXE) capability of vario…

apache uima-as · apache uimaducc · apache uimafit · apache uimaj
0.09EPSS
CVE-2012-5885
Media 5.0

The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (a…

apache tomcat
0.09EPSS
CVE-2019-17359
Alta 7.5

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

apache tomee · bouncycastle bc-java · netapp active_iq_unified_manager · netapp oncommand_api_services · e altri 17
0.09EPSS
CVE-2011-2767
Critica 9.8

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP re…

apache mod_perl · canonical ubuntu_linux · debian debian_linux · redhat enterprise_linux · e altri 3
0.09EPSS
CVE-2012-5641
Media 5.0

Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot b…

apache couchdb · mochiweb_project mochiweb
0.09EPSS
CVE-2012-3451
Media 4.3

Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.

apache cxf
0.09EPSS
CVE-2019-17569
Media 4.8

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Reques…

apache tomcat · apache tomee · debian debian_linux · netapp data_availability_services · e altri 12
0.09EPSS
CVE-2013-4517
Media 4.3

Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.

apache santuario_xml_security_for_java
0.09EPSS
CVE-2013-1849
Media 4.3

The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.

apache subversion
0.09EPSS
CVE-2014-0099
Media 4.3

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Conten…

apache tomcat
0.09EPSS
CVE-2016-0785
Alta 8.8

Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.

apache struts
0.09EPSS
CVE-2026-43825
Alta 7.3

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introduced in   OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(InputStream) r…

apache opennlp
0.09EPSS
CVE-2012-6637
Alta 7.5

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an in…

adobe phonegap · apache cordova
0.09EPSS
CVE-2012-5886
Media 5.0

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass a…

apache tomcat
0.09EPSS
CVE-2019-10071
Critica 9.8

The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attacker is able to determine the correct sign…

apache tapestry
0.09EPSS
CVE-2011-4905
Media 5.0

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.

apache activemq
0.09EPSS
CVE-2019-0197
Media 4.2

A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to…

apache http_server · canonical ubuntu_linux · fedoraproject fedora · opensuse leap · e altri 7
0.09EPSS
CVE-2012-2733
Media 5.0

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory …

apache tomcat
0.09EPSS
CVE-2018-1327
Alta 7.5

The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handl…

apache struts
0.09EPSS