imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2004-1082
Alta 7.5

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

apache http_server · apple apache_mod_digest_apple · avaya communication_manager · avaya intuity_audix_lx · e altri 10
0.08EPSS
CVE-1999-1199
Alta 10.0

Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.

apache http_server
0.08EPSS
CVE-2018-8009
Alta 8.8

Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.

apache hadoop
0.08EPSS
CVE-2015-0251
Media 4.0

The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.

apache subversion · apple xcode · opensuse opensuse · oracle solaris · e altri 5
0.08EPSS
CVE-2014-3528
Media 4.0

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.…

apache subversion · apple xcode · canonical ubuntu_linux · opensuse opensuse · e altri 5
0.08EPSS
CVE-2002-0249
Media 5.0

PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.

apache http_server
0.08EPSS
CVE-2015-0227
Media 5.0

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

apache wss4j
0.08EPSS
CVE-2010-4494
Alta 7.5

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.…

apache openoffice · apple iphone_os · apple itunes · apple mac_os_x · e altri 13
0.08EPSS
CVE-2015-0263
Media 5.0

XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.

apache camel
0.08EPSS
CVE-2012-0213
Media 5.0

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Chann…

apache poi
0.08EPSS
CVE-2018-8022
Alta 7.5

A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.2.2 should upgrade to 6.2.3 or later versions.

apache traffic_server
0.07EPSS
CVE-2021-20190
Alta 8.1

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

apache nifi · debian debian_linux · fasterxml jackson-databind · netapp active_iq_unified_manager · e altri 5
0.07EPSS
CVE-2018-11788
Critica 9.8

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigat…

apache karaf
0.07EPSS
CVE-2012-3506
Alta 10.0

Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.

apache ofbiz
0.07EPSS
CVE-2015-5169
Media 6.1

Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.

apache struts
0.07EPSS
CVE-2013-4310
Media 5.8

Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.

apache struts
0.07EPSS
CVE-2012-4534
Bassa 2.6

org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the…

apache tomcat
0.07EPSS
CVE-2019-12401
Alta 7.5

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will exp…

apache solr
0.07EPSS
CVE-2015-1836
Alta 7.3

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a d…

apache hbase · ibm infosphere_biginsights
0.07EPSS
CVE-2014-0034
Media 4.3

The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.

apache cxf · redhat jboss_enterprise_application_platform
0.07EPSS
CVE-2023-29234
Critica 9.8

A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.

apache dubbo
0.07EPSS
CVE-2014-3574
Media 4.3

Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

apache poi
0.07EPSS
CVE-2021-40690
Alta 7.5

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse…

apache cxf · apache santuario_xml_security_for_java · apache tomee · debian debian_linux · e altri 14
0.07EPSS
CVE-2014-0003
Alta 7.5

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

apache camel
0.07EPSS
CVE-2016-8739
Alta 7.5

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.

apache cxf
0.07EPSS