Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,106 CVEs tagged to vendor apache557 Critical, 1,108 High, 1,342 Medium, 97 Low, 2 Unrated.

CVE-2011-2526

Published Jul 14, 2011

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request att…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1498

Published Jul 7, 2011

Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2204

Published Jun 29, 2011

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1921

Published Jun 6, 2011

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2329

Published Jun 2, 2011

The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which all…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1077

Published Jun 2, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1026

Published Jun 2, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of admi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1928

Published May 24, 2011

The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a den…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1582

Published May 20, 2011

Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2087

Published May 13, 2011

Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1475

Published Apr 8, 2011

The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1183

Published Apr 8, 2011

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1419

Published Mar 14, 2011

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access res…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1088

Published Mar 14, 2011

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web applic…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0715

Published Mar 11, 2011

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereferenc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0013

Published Feb 19, 2011

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attacker…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0533

Published Feb 17, 2011

Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.22 allows remote attacke…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,751-2,775 of 3,106 CVEsPage 111 of 125