imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2018-1303
Alta 7.5

A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_…

apache http_server · canonical ubuntu_linux · debian debian_linux · netapp clustered_data_ontap · e altri 3
0.70EPSS
CVE-2013-2134
Alta 9.3

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.

apache struts
0.70EPSS
CVE-2022-22719
Alta 7.5

A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.

apache http_server · apple mac_os_x · apple macos · debian debian_linux · e altri 3
0.70EPSS
CVE-2002-0661
Alta 7.5

Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.

apache http_server
0.70EPSS
CVE-2004-0751
Media 5.0

The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).

apache http_server
0.70EPSS
CVE-2024-43441
Critica 9.8

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

apache hugegraph
0.70EPSS
CVE-2024-38472
Alta 7.5

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations that access…

apache http_server · netapp ontap
0.69EPSS
CVE-2019-17571
Critica 9.8

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data…

apache bookkeeper · apache log4j · canonical ubuntu_linux · debian debian_linux · e altri 13
0.69EPSS
CVE-2022-44635
Alta 8.8

Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and pr…

apache fineract
0.69EPSS
CVE-2015-7611
Alta 8.1

Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors.

apache james_server
0.69EPSS
CVE-2023-50290
Media 6.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify which environment variables to hide,…

apache solr
0.68EPSS
CVE-2020-13942
Critica 9.8

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly …

apache unomi
0.68EPSS
CVE-2021-26691
Critica 9.8

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

apache http_server · debian debian_linux · fedoraproject fedora · netapp cloud_backup · e altri 4
0.68EPSS
CVE-2019-0233
Alta 7.5

An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.

apache struts · oracle communications_policy_management · oracle financial_services_data_integration_hub · oracle financial_services_market_risk_measurement_and_management · e altri 1
0.68EPSS
CVE-2025-48976
Alta 7.5

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrad…

apache commons_fileupload
0.67EPSS
CVE-2022-25813
Alta 7.5

In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in th…

apache ofbiz
0.67EPSS
CVE-2022-23305
Critica 9.8

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate …

apache log4j · broadcom brocade_sannav · netapp snapmanager · oracle advanced_supply_chain_planning · e altri 24
0.67EPSS
CVE-2025-55752
Alta 7.5

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query paramete…

apache tomcat
0.67EPSS
CVE-2018-11770
Media 4.2

From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for auth…

apache spark
0.66EPSS
CVE-2021-40865
Critica 9.8

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrad…

apache storm
0.66EPSS
CVE-2025-30676
Media 6.1

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.

apache ofbiz
0.65EPSS
CVE-2021-26690
Alta 7.5

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service

apache http_server · debian debian_linux · fedoraproject fedora · oracle enterprise_manager_ops_center · e altri 2
0.65EPSS
CVE-2025-27817
Alta 7.5

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and "…

apache kafka
0.65EPSS
CVE-2024-54676
Critica 9.8

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads t…

apache openmeetings
0.65EPSS
CVE-2008-0455
Media 4.3

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inje…

apache http_server · redhat enterprise_linux_desktop · redhat enterprise_linux_server · redhat enterprise_linux_workstation · e altri 1
0.65EPSS