Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,203 CVEs tagged to vendor apache575 Critical, 1,159 High, 1,369 Medium, 98 Low, 2 Unrated.

CVE-2001-0917

Published Nov 22, 2001

Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0729

Published Oct 30, 2001

Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0730

Published Oct 30, 2001

split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0766

Published Oct 18, 2001

Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-0731

Published Oct 1, 2001

Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-1072

Published Aug 31, 2001

Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0590

Published Aug 2, 2001

Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end w…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1342

Published May 12, 2001

Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash)…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0925

Published Mar 12, 2001

The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0042

Published Feb 16, 2001

PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0913

Published Dec 19, 2000

mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0868

Published Nov 14, 2000

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0869

Published Nov 14, 2000

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0759

Published Oct 20, 2000

Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the phy…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0760

Published Oct 20, 2000

The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1204

Published Oct 13, 2000

Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin d…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0672

Published Jul 20, 2000

The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administr…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0505

Published May 31, 2000

The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-1205

Published Feb 1, 2000

Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), whi…

CVSS 4.3 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-1293

Published Dec 31, 1999

mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1053

Published Sep 13, 1999

guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.p…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0926

Published Sep 3, 1999

Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-1206

Published Aug 20, 1999

Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve ar…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 3,176-3,200 of 3,203 CVEsPage 128 of 129