imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2016-4432
Critica 9.1

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

apache qpid_broker-j
0.08EPSS
CVE-2014-0073
Critica 9.8

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, whic…

apache cordova · apache cordova_in-app-browser
0.08EPSS
CVE-2010-0136
Alta 9.3

OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.

apache openoffice · canonical ubuntu_linux · debian debian_linux
0.08EPSS
CVE-2020-27218
Media 4.8

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker…

apache kafka · apache spark · debian debian_linux · eclipse jetty · e altri 13
0.08EPSS
CVE-2020-9488
Bassa 3.7

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3…

apache log4j · debian debian_linux · oracle communications_application_session_controller · oracle communications_billing_and_revenue_management · e altri 42
0.08EPSS
CVE-2017-12171
Media 6.5

A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HT…

apache http_server · redhat enterprise_linux · redhat enterprise_linux_desktop · redhat enterprise_linux_server · e altri 1
0.08EPSS
CVE-2012-4387
Media 5.0

Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.

apache struts
0.08EPSS
CVE-2016-6797
Alta 7.5

The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web…

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp oncommand_insight · e altri 10
0.08EPSS
CVE-2017-7674
Media 4.3

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in …

apache tomcat
0.08EPSS
CVE-2019-19906
Alta 7.5

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-s…

apache bookkeeper · apple ipados · apple iphone_os · apple mac_os_x · e altri 15
0.08EPSS
CVE-2013-2154
Alta 7.5

Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possib…

apache xml_security_for_c\+\+
0.08EPSS
CVE-2016-6809
Critica 9.8

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.

apache nutch · apache tika
0.08EPSS
CVE-2016-4461
Alta 8.8

Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.

apache struts · netapp oncommand_balance
0.08EPSS
CVE-2020-9495
Media 5.3

Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDA…

apache archiva
0.08EPSS
CVE-2016-0762
Media 5.9

The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible…

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp oncommand_insight · e altri 11
0.08EPSS
CVE-2016-2163
Media 6.1

Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.

apache openmeetings
0.08EPSS
CVE-2015-0202
Alta 7.8

The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.

apache subversion · opensuse opensuse
0.08EPSS
CVE-2016-5019
Critica 9.8

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.

apache myfaces_trinidad
0.08EPSS
CVE-2022-35741
Critica 9.8

Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be ena…

apache cloudstack
0.08EPSS
CVE-2006-6587
Media 6.8

Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.

apache ofbiz
0.08EPSS
CVE-2014-9527
Media 5.0

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

apache poi · fedoraproject fedora
0.08EPSS
CVE-2008-2025
Media 4.3

Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remot…

apache struts
0.08EPSS
CVE-2011-0534
Media 5.0

Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.

apache tomcat
0.08EPSS
CVE-2017-15705
Media 5.3

A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssassin, using …

apache spamassassin · canonical ubuntu_linux · debian debian_linux · redhat enterprise_linux_desktop · e altri 3
0.08EPSS
CVE-2021-44451
Media 6.5

Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.

apache superset
0.08EPSS