imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-1999-1293
Alta 10.0

mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.

apache http_server
0.04EPSS
CVE-2021-33191
Critica 9.8

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through…

apache nifi_minifi_c\+\+
0.04EPSS
CVE-2018-11797
Media 5.5

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

apache pdfbox · fedoraproject fedora · oracle retail_xstore_point_of_service
0.04EPSS
CVE-2021-35936
Media 5.3

If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server and is listening on a specific port and also binds on 0.0.0.0 by default. This logging server had no authentic…

apache airflow
0.04EPSS
CVE-2018-11778
Alta 8.8

UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0

apache ranger
0.04EPSS
CVE-2016-4464
Critica 9.8

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified ot…

apache cxf_fediz
0.04EPSS
CVE-2018-8029
Alta 8.8

In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.

apache hadoop
0.04EPSS
CVE-2018-8030
Alta 7.5

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to t…

apache qpid_broker-j
0.04EPSS
CVE-2020-1928
Media 5.3

An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.

apache nifi
0.04EPSS
CVE-2013-4156
Media 6.8

Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.

apache openoffice
0.04EPSS
CVE-2013-2189
Media 6.8

Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.

apache openoffice
0.04EPSS
CVE-2022-40189
Critica 9.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG f…

apache airflow · apache apache-airflow-providers-apache-pig
0.04EPSS
CVE-2019-12412
Alta 7.5

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

apache libapreq2
0.04EPSS
CVE-2020-17522
Media 5.8

When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. A…

apache traffic_control
0.04EPSS
CVE-2012-2378
Media 4.3

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) Sign…

apache cxf
0.04EPSS
CVE-2021-26118
Alta 7.5

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to…

apache artemis · netapp oncommand_workflow_automation
0.04EPSS
CVE-2004-0096
Media 5.0

Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.

apache mod_python
0.04EPSS
CVE-2018-8010
Media 5.5

This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also aff…

apache solr
0.04EPSS
CVE-2019-12399
Alta 7.5

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a conn…

apache kafka · oracle banking_corporate_lending_process_management · oracle banking_credit_facilities_process_management · oracle banking_liquidity_management · e altri 9
0.04EPSS
CVE-2023-38709
Alta 7.3

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.

apache http_server · apple macos · broadcom fabric_operating_system · debian debian_linux · e altri 3
0.04EPSS
CVE-2008-4308
Bassa 2.6

The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.

apache tomcat
0.04EPSS
CVE-2020-9494
Alta 7.5

Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.

apache traffic_server · debian debian_linux
0.04EPSS
CVE-2007-6423
Alta 7.8

Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue

apache http_server
0.04EPSS
CVE-2013-2112
Alta 7.8

The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.

apache subversion · canonical ubuntu_linux · collabnet subversion · opensuse opensuse
0.04EPSS
CVE-2004-0263
Media 5.0

PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.

apache http_server · ibm http_server
0.04EPSS