imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2002-2012
Media 5.0

Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.

apache http_server
0.06EPSS
CVE-2024-29868
Critica 9.1

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over th…

apache streampipes
0.06EPSS
CVE-2011-1921
Media 4.3

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the…

apache subversion
0.06EPSS
CVE-2003-0192
Media 6.4

Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause…

apache http_server
0.06EPSS
CVE-2024-30188
Alta 8.1

File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which f…

apache dolphinscheduler
0.06EPSS
CVE-2024-27135
Alta 8.5

Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies…

apache pulsar
0.06EPSS
CVE-2014-3503
Media 5.0

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

apache syncope
0.06EPSS
CVE-2023-41080
Media 6.1

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 thro…

apache tomcat · debian debian_linux
0.06EPSS
CVE-2005-3510
Media 5.0

Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

apache tomcat
0.06EPSS
CVE-2018-17197
Media 6.5

A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.

apache tika
0.06EPSS
CVE-2013-2172
Media 4.3

jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify a…

apache santuario_xml_security_for_java
0.06EPSS
CVE-2009-5005
Media 5.0

The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.

apache qpid · redhat enterprise_mrg
0.06EPSS
CVE-2010-3854
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

apache couchdb
0.06EPSS
CVE-2015-1835
Media 5.3

Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.

apache cordova
0.06EPSS
CVE-2007-1862
Media 5.0

The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitiv…

apache http_server
0.06EPSS
CVE-2013-4558
Bassa 3.5

The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of…

apache mod_dav_svn · apache subversion
0.06EPSS
CVE-2013-1845
Bassa 2.1

The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file or d…

apache subversion · opensuse opensuse
0.06EPSS
CVE-2017-5643
Alta 7.4

Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

apache camel
0.06EPSS
CVE-2002-1394
Alta 7.5

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.

apache tomcat
0.06EPSS
CVE-2023-45648
Media 5.3

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, in…

apache tomcat · debian debian_linux
0.06EPSS
CVE-2012-6153
Media 4.3

http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-mi…

apache commons-httpclient
0.06EPSS
CVE-2012-5639
Media 6.5

LibreOffice and OpenOffice automatically open embedded content

apache openoffice · debian debian_linux · libreoffice libreoffice
0.06EPSS
CVE-2013-2756
Media 5.0

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.

apache cloudstack · citrix cloudplatform
0.06EPSS
CVE-2013-2155
Media 5.8

Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted leng…

apache xml_security_for_c\+\+
0.06EPSS
CVE-2003-0134
Media 5.0

Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.

apache http_server
0.06EPSS