Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,280 CVEs tagged to vendor apache587 Critical, 1,195 High, 1,398 Medium, 98 Low, 2 Unrated.

CVE-2003-0253

Published Aug 18, 2003

The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2003-0254

Published Aug 18, 2003

Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0189

Published Jun 9, 2003

The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0245

Published Jun 9, 2003

Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (cras…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0132

Published Apr 11, 2003

A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0134

Published Apr 11, 2003

Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device na…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0083

Published Apr 2, 2003

Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0020

Published Mar 18, 2003

Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnera…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0016

Published Feb 7, 2003

Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP req…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0017

Published Feb 7, 2003

Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2003-0042

Published Feb 7, 2003

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0043

Published Feb 7, 2003

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0044

Published Feb 7, 2003

Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0045

Published Feb 7, 2003

Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1394

Published Jan 17, 2003

Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protec…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2002-1658

Published Dec 31, 2002

Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally acce…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1850

Published Dec 31, 2002

mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1895

Published Dec 31, 2002

The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2006

Published Dec 31, 2002

The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2007

Published Dec 31, 2002

The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2008

Published Dec 31, 2002

Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the informati…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2009

Published Dec 31, 2002

Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2012

Published Dec 31, 2002

Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2029

Published Dec 31, 2002

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2103

Published Dec 31, 2002

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,201-3,225 of 3,280 CVEsPage 129 of 132