Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,106 CVEs tagged to vendor apache557 Critical, 1,108 High, 1,342 Medium, 97 Low, 2 Unrated.

CVE-2011-0534

Published Feb 10, 2011

Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3718

Published Feb 10, 2011

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applicatio…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3854

Published Feb 2, 2011

Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4643

Published Jan 28, 2011

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4644

Published Jan 7, 2011

Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4539

Published Jan 7, 2011

The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4408

Published Dec 6, 2010

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a use…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3449

Published Dec 6, 2010

Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1;…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4312

Published Nov 26, 2010

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4172

Published Nov 26, 2010

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3872

Published Nov 22, 2010

A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_h…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4008

Published Nov 17, 2010

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malf…

CVSS 4.3 · Medium

CVE-2010-3863

Published Nov 5, 2010

Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass int…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2057

Published Oct 20, 2010

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MA…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0219

Published Oct 18, 2010

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, wh…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-5006

Published Oct 18, 2010

The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5005

Published Oct 18, 2010

The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a den…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,776-2,800 of 3,106 CVEsPage 112 of 125