Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,205 CVEs tagged to vendor apache575 Critical, 1,159 High, 1,371 Medium, 98 Low, 2 Unrated.

CVE-2005-2728

Published Aug 30, 2005

The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2088

Published Jul 5, 2005

The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall prote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2090

Published Jul 5, 2005

Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS atta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1266

Published Jun 15, 2005

Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header witho…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0088

Published May 2, 2005

The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0808

Published May 2, 2005

Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1344

Published May 2, 2005

Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0508

Published Mar 14, 2005

Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script sec…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0942

Published Feb 9, 2005

Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines wit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0108

Published Jan 11, 2005

Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute l…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0811

Published Dec 31, 2004

Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1387

Published Dec 31, 2004

The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1575

Published Dec 31, 2004

The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2343

Published Dec 31, 2004

Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an Error…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2650

Published Dec 31, 2004

Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, whic…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2680

Published Dec 31, 2004

mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0263

Published Nov 23, 2004

PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0885

Published Nov 3, 2004

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0747

Published Oct 20, 2004

Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0748

Published Oct 20, 2004

mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child proc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,076-3,100 of 3,205 CVEsPage 124 of 129