Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,268 CVEs tagged to vendor apache586 Critical, 1,193 High, 1,389 Medium, 98 Low, 2 Unrated.

CVE-2008-1947

Published Jun 4, 2008

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2168

Published May 13, 2008

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly ha…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6258

Published Feb 19, 2008

Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0732

Published Feb 12, 2008

The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or direct…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5333

Published Feb 12, 2008

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequence…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6286

Published Feb 12, 2008

Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0002

Published Feb 12, 2008

Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attacker…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0128

Published Jan 23, 2008

The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https sessio…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2007-6420

Published Jan 12, 2008

Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecifi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6423

Published Jan 12, 2008

Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6421

Published Jan 8, 2008

Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web sc…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2007-6388

Published Jan 8, 2008

Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2007-6422

Published Jan 8, 2008

The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated use…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2007-5342

Published Dec 27, 2007

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6514

Published Dec 21, 2007

Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6203

Published Dec 3, 2007

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error mess…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5797

Published Nov 3, 2007

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attemp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5731

Published Oct 30, 2007

Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies a…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5461

Published Oct 15, 2007

Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remo…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5085

Published Sep 26, 2007

Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,051-3,075 of 3,268 CVEsPage 123 of 131