Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,106 CVEs tagged to vendor apache557 Critical, 1,108 High, 1,342 Medium, 97 Low, 2 Unrated.

CVE-2012-2098

Published Jun 29, 2012

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote atta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2381

Published Jun 26, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-2380

Published Jun 26, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1149

Published Jun 21, 2012

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of se…

CVSS 7.5 · High

CVE-2012-0037

Published Jun 17, 2012

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remo…

CVSS 6.5 · Medium

CVE-2011-3620

Published May 3, 2012

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0883

Published Apr 18, 2012

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Troj…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0256

Published Mar 26, 2012

Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1089

Published Mar 23, 2012

Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathna…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0047

Published Mar 23, 2012

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1181

Published Mar 19, 2012

fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0838

Published Mar 2, 2012

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, an…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0840

Published Feb 10, 2012

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which all…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1007

Published Feb 7, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-exam…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1006

Published Feb 7, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastNam…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0053

Published Jan 28, 2012

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows…

CVSS 4.3 · Medium

CVE-2012-0021

Published Jan 28, 2012

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0022

Published Jan 19, 2012

Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3375

Published Jan 19, 2012

Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attacke…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5064

Published Jan 14, 2012

DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5063

Published Jan 14, 2012

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,701-2,725 of 3,106 CVEsPage 109 of 125