imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2022-46366
Critica 9.8

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache T…

apache tapestry
0.04EPSS
CVE-2020-9486
Alta 7.5

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plainte…

apache nifi
0.04EPSS
CVE-2006-20001
Alta 7.5

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.

apache http_server
0.04EPSS
CVE-2021-27577
Alta 7.5

Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

apache traffic_server · debian debian_linux
0.04EPSS
CVE-2012-0803
Critica 9.8

The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request.

apache cxf
0.04EPSS
CVE-2017-15698
Media 5.9

When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefor…

apache tomcat_native · debian debian_linux
0.04EPSS
CVE-2016-6800
Media 6.1

The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as…

apache ofbiz
0.04EPSS
CVE-2025-48989
Alta 7.5

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older,…

apache tomcat
0.04EPSS
CVE-2017-7665
Media 6.1

In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.

apache nifi
0.04EPSS
CVE-2004-1834
Bassa 2.1

mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.

apache http_server
0.04EPSS
CVE-2014-0228
Bassa 3.5

Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.

apache hive
0.03EPSS
CVE-2014-7809
Media 6.8

Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.

apache struts
0.03EPSS
CVE-2018-11779
Critica 9.8

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.

apache storm
0.03EPSS
CVE-2005-4836
Alta 7.8

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.

apache tomcat
0.03EPSS
CVE-2014-0212
Alta 7.5

qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors

apache qpid-cpp
0.03EPSS
CVE-2023-44313
Alta 7.6

Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include). Users are recommended to u…

apache servicecomb
0.03EPSS
CVE-2019-12405
Critica 9.8

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as t…

apache traffic_control
0.03EPSS
CVE-2021-41616
Critica 9.8

Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was inse…

apache ddlutils
0.03EPSS
CVE-2000-1210
Media 5.0

Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.

apache tomcat
0.03EPSS
CVE-2016-4434
Alta 7.8

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other …

apache tika
0.03EPSS
CVE-2007-6726
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.htm…

apache struts · dojotoolkit dojo
0.03EPSS
CVE-2005-0108
Media 5.0

Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.

apache mod_auth_radius
0.03EPSS
CVE-2021-31811
Media 5.5

In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

apache pdfbox · fedoraproject fedora · oracle banking_corporate_lending_process_management · oracle banking_credit_facilities_process_management · e altri 8
0.03EPSS
CVE-2019-0234
Media 6.1

A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability…

apache roller
0.03EPSS
CVE-2019-0203
Alta 7.5

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.

apache subversion
0.03EPSS