Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,270 CVEs tagged to vendor apache587 Critical, 1,193 High, 1,390 Medium, 98 Low, 2 Unrated.

CVE-2009-0033

Published Jun 5, 2009

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to caus…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1195

Published May 28, 2009

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1191

Published Apr 23, 2009

mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0039

Published Apr 17, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hija…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0038

Published Apr 17, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5518

Published Apr 17, 2009

Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1275

Published Apr 9, 2009

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote atta…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6682

Published Apr 9, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5519

Published Apr 9, 2009

The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opport…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6726

Published Apr 9, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0796

Published Apr 7, 2009

Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible,…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-6505

Published Mar 23, 2009

Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6504

Published Mar 23, 2009

ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) refer…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0781

Published Mar 9, 2009

Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0754

Published Mar 3, 2009

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_ove…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4308

Published Feb 26, 2009

The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause To…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0026

Published Jan 21, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) sear…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3271

Published Oct 13, 2008

Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurren…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4482

Published Oct 8, 2008

The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large m…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3282

Published Aug 29, 2008

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote atta…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2938

Published Aug 13, 2008

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote att…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2008-1232

Published Aug 4, 2008

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web scri…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 3,026-3,050 of 3,270 CVEsPage 122 of 131