Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,106 CVEs tagged to vendor apache557 Critical, 1,108 High, 1,342 Medium, 97 Low, 2 Unrated.

CVE-2011-5062

Published Jan 14, 2012

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1184

Published Jan 14, 2012

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures agai…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5057

Published Jan 8, 2012

Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0394

Published Jan 8, 2012

The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NO…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0393

Published Jan 8, 2012

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary f…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0392

Published Jan 8, 2012

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafte…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0391

Published Jan 8, 2012

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of pro…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2011-4858

Published Jan 5, 2012

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictab…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4905

Published Jan 5, 2012

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5034

Published Dec 30, 2011

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6750

Published Dec 27, 2011

The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4317

Published Nov 30, 2011

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3639

Published Nov 30, 2011

The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1…

CVSS 4.3 · Medium

CVE-2011-3376

Published Nov 11, 2011

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4415

Published Nov 8, 2011

The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the si…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3607

Published Nov 8, 2011

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allo…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3368

Published Oct 5, 2011

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2)…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2000-1247

Published Oct 5, 2011

The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwo…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4340

Published Sep 12, 2011

libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3190

Published Aug 31, 2011

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attacker…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2712

Published Aug 29, 2011

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web scri…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2481

Published Aug 15, 2011

Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,726-2,750 of 3,106 CVEsPage 110 of 125