58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Apache
3430 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-19924 | MED 5.3 | apache bookkeeper SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling. | 7,9% | — |
| CVE-2016-5017 | HIGH 8.1 | apache zookeeper Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string. | 7,9% | — |
| CVE-2005-4838 | MED 4.3 | apache tomcat Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotat | 7,9% | — |
| CVE-2002-0935 | MED 5.0 | apache tomcat Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang. | 7,9% | — |
| CVE-2019-0219 | CRIT 9.8 | apache cordova_inappbrowser A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI. | 7,8% | — |
| CVE-2016-3094 | MED 5.9 | apache qpid_broker-j PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught except | 7,8% | — |
| CVE-2001-1449 | HIGH 7.5 | apache http_server The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories. | 7,8% | — |
| CVE-2016-2162 | MED 6.1 | apache struts Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display. | 7,8% | — |
| CVE-2012-4501 | HIGH 10.0 | apache cloudstack Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs. | 7,8% | — |
| CVE-2012-6551 | MED 5.0 | apache activemq The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests. | 7,8% | — |
| CVE-2018-17191 | CRIT 9.8 | apache netbeans Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the nashorn script engine the environment of the javascript execution for the Proxy Auto-Configuration leaks privile | 7,8% | — |
| CVE-2017-5651 | CRIT 9.8 | apache tomcat In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processo | 7,8% | — |
| CVE-2014-0072 | HIGH 7.5 | apache cordova ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9.0 might allow remote attackers to spoof SSL servers by lever | 7,7% | — |
| CVE-2018-1318 | HIGH 7.5 | apache traffic_server Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or lat | 7,7% | — |
| CVE-2011-2516 | MED 5.0 | apache xml_security_for_c\+\+ Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which trigge | 7,7% | — |
| CVE-2013-2137 | MED 4.3 | apache ofbiz Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web scr | 7,7% | — |
| CVE-2014-0119 | MED 4.3 | apache tomcat Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application | 7,6% | — |
| CVE-2015-1774 | MED 6.8 | apache openoffice The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds wri | 7,6% | — |
| CVE-2004-0811 | HIGH 7.5 | apache http_server Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration. | 7,6% | — |
| CVE-2004-1082 | HIGH 7.5 | apache http_server mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials. | 7,6% | — |
| CVE-1999-1199 | HIGH 10.0 | apache http_server Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability. | 7,6% | — |
| CVE-2016-6812 | MED 6.1 | apache cxf The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL usi | 7,5% | — |
| CVE-2015-0227 | MED 5.0 | apache wss4j Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks." | 7,5% | — |
| CVE-2018-11796 | HIGH 7.5 | apache tika In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and t | 7,5% | — |
| CVE-2015-5169 | MED 6.1 | apache struts Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20. | 7,5% | — |