· 6 years ago · Mar 23, 2020, 03:56 PM
1#################################################################################################################################
2=================================================================================================================================
3Hostname daddyfree.com ISP LLC Smart Ape
4Continent Europe Flag
5RU
6Country Russian Federation Country Code RU
7Region Unknown Local time 23 Mar 2020 16:54 MSK
8City Unknown Postal Code Unknown
9IP Address 188.127.251.161 Latitude 55.739
10 Longitude 3
11=================================================================================================================================
12##################################################################################################################################
13> daddyfree.com
14Server: 10.101.0.243
15Address: 10.101.0.243#53
16
17Non-authoritative answer:
18Name: daddyfree.com
19Address: 188.127.251.161
20>
21#################################################################################################################################
22 Domain Name: DADDYFREE.COM
23 Registry Domain ID: 2505334920_DOMAIN_COM-VRSN
24 Registrar WHOIS Server: whois.porkbun.com
25 Registrar URL: http://porkbun.com
26 Updated Date: 2020-03-20T13:07:13Z
27 Creation Date: 2020-03-20T12:14:29Z
28 Registry Expiry Date: 2021-03-20T12:14:29Z
29 Registrar: Porkbun LLC
30 Registrar IANA ID: 1861
31 Registrar Abuse Contact Email: abuse@porkbun.com
32 Registrar Abuse Contact Phone: 5038508351
33 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
34 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
35 Name Server: NS1.DYNU.COM
36 Name Server: NS2.DYNU.COM
37 Name Server: NS3.DYNU.COM
38 Name Server: NS4.DYNU.COM
39 Name Server: NS5.DYNU.COM
40 Name Server: NS6.DYNU.COM
41 DNSSEC: unsigned
42################################################################################################################################
43Domain Name: DADDYFREE.COM
44Registry Domain ID: 2505334920_DOMAIN_COM-VRSN
45Registrar WHOIS Server: whois.porkbun.com
46Registrar URL: http://www.porkbun.com
47Updated Date: 2020-03-20 12:14:29
48Created Date: 2020-03-20 12:14:29
49Registrar Registration Expiration Date: 2021-03-20 12:14:29
50Registrar: Porkbun LLC
51Registrar IANA ID: 1861
52Registrar Abuse Contact Email: abuse@porkbun.com
53Registrar Abuse Contact Phone: +1.5038508351
54Domain Status: clientDeleteProhibited http://icann.org/epp#clientDeleteProhibited
55Domain Status: clientTransferProhibited http://icann.org/epp#clientTransferProhibited
56Registry Registrant ID:
57Registrant Name: Whois Privacy
58Registrant Organization: Private by Design, LLC
59Registrant Street: 500 Westover Dr #9816
60Registrant City: Sanford
61Registrant State/Province: NC
62Registrant Postal Code: 27330
63Registrant Country: US
64Registrant Phone: +1.9712666028
65Registrant Phone Ext:
66Registrant Fax:
67Registrant Fax Ext:
68Registrant Email: https://porkbun.com/whois/contact/registrant/daddyfree.com
69Registry Admin ID:
70Admin Name: Whois Privacy
71Admin Organization: Private by Design, LLC
72Admin Street: 500 Westover Dr #9816
73Admin City: Sanford
74Admin State/Province: NC
75Admin Postal Code: 27330
76Admin Country: US
77Admin Phone: +1.9712666028
78Admin Phone Ext:
79Admin Fax:
80Admin Fax Ext:
81Admin Email: https://porkbun.com/whois/contact/admin/daddyfree.com
82Registry Tech ID:
83Tech Name: Whois Privacy
84Tech Organization: Private by Design, LLC
85Tech Street: 500 Westover Dr #9816
86Tech City: Sanford
87Tech State/Province: NC
88Tech Postal Code: 27330
89Tech Country: US
90Tech Phone: +1.9712666028
91Tech Phone Ext:
92Tech Fax:
93Tech Fax Ext:
94Tech Email: https://porkbun.com/whois/contact/tech/daddyfree.com
95Name Server: ns1.dynu.com
96Name Server: ns2.dynu.com
97Name Server: ns3.dynu.com
98Name Server: ns4.dynu.com
99Name Server: ns5.dynu.com
100Name Server: ns6.dynu.com
101DNSSEC: unsignedDelegation
102#################################################################################################################################
103[+] Target : daddyfree.com
104
105[+] IP Address : 188.127.251.161
106
107[+] Headers :
108
109[+] Date : Mon, 23 Mar 2020 14:05:04 GMT
110[+] Server : Apache
111[+] Cache-Control : private, no-cache="set-cookie"
112[+] Expires : Mon, 23 Mar 2020 14:05:04 GMT
113[+] Set-Cookie : phpbb3_7rbub_u=1; expires=Tue, 23-Mar-2021 14:05:04 GMT; path=/; domain=daddyfree.com; HttpOnly, phpbb3_7rbub_k=; expires=Tue, 23-Mar-2021 14:05:04 GMT; path=/; domain=daddyfree.com; HttpOnly, phpbb3_7rbub_sid=831ef35ea62edf9cfaaec3b3065068b8; expires=Tue, 23-Mar-2021 14:05:04 GMT; path=/; domain=daddyfree.com; HttpOnly
114[+] Keep-Alive : timeout=5, max=100
115[+] Connection : Keep-Alive
116[+] Transfer-Encoding : chunked
117[+] Content-Type : text/html; charset=UTF-8
118
119[+] SSL Certificate Information :
120
121[+] commonName : daddyfree.com
122[+] countryName : US
123[+] stateOrProvinceName : TX
124[+] localityName : Houston
125[+] organizationName : cPanel, Inc.
126[+] commonName : cPanel, Inc. Certification Authority
127[+] Version : 3
128[+] Serial Number : C59063D118921B05F9CAD793431883C4
129[+] Not Before : Mar 20 00:00:00 2020 GMT
130[+] Not After : Jun 18 23:59:59 2020 GMT
131[+] OCSP : ('http://ocsp.comodoca.com',)
132[+] subject Alt Name : (('DNS', 'daddyfree.com'), ('DNS', 'cpanel.daddyfree.com'), ('DNS', 'cpcalendars.daddyfree.com'), ('DNS', 'cpcontacts.daddyfree.com'), ('DNS', 'mail.daddyfree.com'), ('DNS', 'webdisk.daddyfree.com'), ('DNS', 'webmail.daddyfree.com'), ('DNS', 'www.daddyfree.com'))
133[+] CA Issuers : ('http://crt.comodoca.com/cPanelIncCertificationAuthority.crt',)
134[+] CRL Distribution Points : ('http://crl.comodoca.com/cPanelIncCertificationAuthority.crl',)
135
136[+] Whois Lookup :
137
138[+] NIR : None
139[+] ASN Registry : ripencc
140[+] ASN : 56694
141[+] ASN CIDR : 188.127.248.0/22
142[+] ASN Country Code : RU
143[+] ASN Date : 2009-08-06
144[+] ASN Description : DHUB, RU
145[+] cidr : 188.127.251.0/24
146[+] name : DHUB-CUST
147[+] handle : SDT129-RIPE
148[+] range : 188.127.251.0 - 188.127.251.255
149[+] description : Digital Hub Customers
150[+] country : RU
151[+] state : None
152[+] city : None
153[+] address : Moscow, Proezd Serp i Molot 3 build.2
154[+] postal_code : None
155[+] emails : None
156[+] created : 2016-02-15T09:46:40Z
157[+] updated : 2016-02-15T09:46:40Z
158
159[+] Crawling Target...
160
161[+] Looking for robots.txt........[ Found ]
162[+] Extracting robots Links.......[ 0 ]
163[+] Looking for sitemap.xml.......[ Found ]
164[+] Extracting sitemap Links......[ 0 ]
165[+] Extracting CSS Links..........[ 3 ]
166[+] Extracting Javascript Links...[ 2 ]
167[+] Extracting Internal Links.....[ 0 ]
168[+] Extracting External Links.....[ 1 ]
169[+] Extracting Images.............[ 0 ]
170
171[+] Total Links Extracted : 6
172
173[+] Dumping Links in /opt/FinalRecon/dumps/daddyfree.com.dump
174[+] Completed!
175#################################################################################################################################
176[i] Scanning Site: http://daddyfree.com
177
178
179
180B A S I C I N F O
181====================
182
183
184[+] Site Title: Daddy Free - DaddyFree
185[+] IP address: 188.127.251.161
186[+] Web Server: Apache
187[+] CMS: Could Not Detect
188[+] Cloudflare: Not Detected
189[+] Robots File: Found
190
191-------------[ contents ]----------------
192<!DOCTYPE html>
193<html dir="ltr" lang="en-gb">
194<head>
195<meta charset="utf-8">
196<meta name="viewport" content="width=device-width, initial-scale=1.0">
197<meta name="designer" content="SiteSplat http://themeforest.net/user/themesplat/portfolio?ref=ThemeSplat">
198<meta content="Daddy Free" property="og:site_name">
199<!-- Place favicon.ico and apple-touch-icon.png in the root directory -->
200
201<title>Daddy Free - DaddyFree</title>
202
203
204
205
206W H O I S L O O K U P
207========================
208
209 Domain Name: DADDYFREE.COM
210 Registry Domain ID: 2505334920_DOMAIN_COM-VRSN
211 Registrar WHOIS Server: whois.porkbun.com
212 Registrar URL: http://porkbun.com
213 Updated Date: 2020-03-20T13:07:13Z
214 Creation Date: 2020-03-20T12:14:29Z
215 Registry Expiry Date: 2021-03-20T12:14:29Z
216 Registrar: Porkbun LLC
217 Registrar IANA ID: 1861
218 Registrar Abuse Contact Email: abuse@porkbun.com
219 Registrar Abuse Contact Phone: 5038508351
220 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
221 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
222 Name Server: NS1.DYNU.COM
223 Name Server: NS2.DYNU.COM
224 Name Server: NS3.DYNU.COM
225 Name Server: NS4.DYNU.COM
226 Name Server: NS5.DYNU.COM
227 Name Server: NS6.DYNU.COM
228 DNSSEC: unsigned
229 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
230>>> Last update of whois database: 2020-03-23T14:05:29Z <<<
231
232For more information on Whois status codes, please visit https://icann.org/epp
233
234
235
236The Registry database contains ONLY .COM, .NET, .EDU domains and
237Registrars.
238
239
240
241
242G E O I P L O O K U P
243=========================
244
245[i] IP Address: 188.127.251.161
246[i] Country: Russia
247[i] State:
248[i] City:
249[i] Latitude: 55.7386
250[i] Longitude: 37.6068
251
252
253
254
255H T T P H E A D E R S
256=======================
257
258
259[i] HTTP/1.1 200 OK
260[i] Date: Mon, 23 Mar 2020 14:05:40 GMT
261[i] Server: Apache
262[i] Cache-Control: private, no-cache="set-cookie"
263[i] Expires: Mon, 23 Mar 2020 14:05:40 GMT
264[i] Set-Cookie: phpbb3_7rbub_u=1; expires=Tue, 23-Mar-2021 14:05:40 GMT; path=/; domain=daddyfree.com; HttpOnly
265[i] Set-Cookie: phpbb3_7rbub_k=; expires=Tue, 23-Mar-2021 14:05:40 GMT; path=/; domain=daddyfree.com; HttpOnly
266[i] Set-Cookie: phpbb3_7rbub_sid=c521a1ab4ab1fe639f9f2ee5619149f6; expires=Tue, 23-Mar-2021 14:05:40 GMT; path=/; domain=daddyfree.com; HttpOnly
267[i] Connection: close
268[i] Content-Type: text/html; charset=UTF-8
269
270
271
272
273D N S L O O K U P
274===================
275
276daddyfree.com. 119 IN A 188.127.251.161
277daddyfree.com. 89 IN NS ns2.dynu.com.
278daddyfree.com. 89 IN NS ns4.dynu.com.
279daddyfree.com. 89 IN NS ns3.dynu.com.
280daddyfree.com. 89 IN NS ns6.dynu.com.
281daddyfree.com. 89 IN NS ns5.dynu.com.
282daddyfree.com. 119 IN SOA ns1.dynu.com. administrator.dynu.com. 2 3600 900 604800 300
283daddyfree.com. 89 IN NS ns1.dynu.com.
284
285
286
287
288S U B N E T C A L C U L A T I O N
289====================================
290
291Address = 188.127.251.161
292Network = 188.127.251.161 / 32
293Netmask = 255.255.255.255
294Broadcast = not needed on Point-to-Point links
295Wildcard Mask = 0.0.0.0
296Hosts Bits = 0
297Max. Hosts = 1 (2^0 - 0)
298Host Range = { 188.127.251.161 - 188.127.251.161 }
299
300
301
302N M A P P O R T S C A N
303============================
304
305Starting Nmap 7.70 ( https://nmap.org ) at 2020-03-23 14:05 UTC
306Nmap scan report for daddyfree.com (188.127.251.161)
307Host is up (0.11s latency).
308rDNS record for 188.127.251.161: byronbayoasisresort.com.au
309
310PORT STATE SERVICE
31121/tcp closed ftp
31222/tcp open ssh
31380/tcp open http
314443/tcp open https
315
316Nmap done: 1 IP address (1 host up) scanned in 0.44 seconds
317################################################################################################################################
318[+] Starting At 2020-03-23 10:05:57.502641
319[+] Collecting Information On: http://daddyfree.com/
320[#] Status: 200
321--------------------------------------------------
322[#] Web Server Detected: Apache
323[!] X-Frame-Options Headers not detect! target might be vulnerable Click Jacking
324- Date: Mon, 23 Mar 2020 14:05:48 GMT
325- Server: Apache
326- Cache-Control: private, no-cache="set-cookie"
327- Expires: Mon, 23 Mar 2020 14:05:48 GMT
328- Set-Cookie: phpbb3_7rbub_u=1; expires=Tue, 23-Mar-2021 14:05:48 GMT; path=/; domain=daddyfree.com; HttpOnly, phpbb3_7rbub_k=; expires=Tue, 23-Mar-2021 14:05:48 GMT; path=/; domain=daddyfree.com; HttpOnly, phpbb3_7rbub_sid=83575650c6f8869947f245e1182332a9; expires=Tue, 23-Mar-2021 14:05:48 GMT; path=/; domain=daddyfree.com; HttpOnly
329- Keep-Alive: timeout=5, max=100
330- Connection: Keep-Alive
331- Transfer-Encoding: chunked
332- Content-Type: text/html; charset=UTF-8
333--------------------------------------------------
334[#] Finding Location..!
335[#] status: success
336[#] country: Russia
337[#] countryCode: RU
338[#] region: LEN
339[#] regionName: Leningradskaya Oblast'
340[#] city: Shcheglovo
341[#] zip: 188671
342[#] lat: 60.0913
343[#] lon: 30.7967
344[#] timezone: Europe/Moscow
345[#] isp: LLC Smart Ape
346[#] org:
347[#] as: AS56694 LLC Smart Ape
348[#] query: 188.127.251.161
349--------------------------------------------------
350[x] Didn't Detect WAF Presence on: http://daddyfree.com/
351--------------------------------------------------
352[#] Starting Reverse DNS
353[-] Failed ! Fail
354--------------------------------------------------
355[!] Scanning Open Port
356[#] 22/tcp open ssh
357[#] 25/tcp open smtp
358[#] 53/tcp open domain
359[#] 80/tcp open http
360[#] 110/tcp open pop3
361[#] 143/tcp open imap
362[#] 443/tcp open https
363[#] 465/tcp open smtps
364[#] 587/tcp open submission
365[#] 993/tcp open imaps
366[#] 995/tcp open pop3s
367[#] 3306/tcp open mysql
368--------------------------------------------------
369[+] Getting SSL Info
370{'OCSP': ('http://ocsp.comodoca.com',),
371 'caIssuers': ('http://crt.comodoca.com/cPanelIncCertificationAuthority.crt',),
372 'crlDistributionPoints': ('http://crl.comodoca.com/cPanelIncCertificationAuthority.crl',),
373 'issuer': ((('countryName', 'US'),),
374 (('stateOrProvinceName', 'TX'),),
375 (('localityName', 'Houston'),),
376 (('organizationName', 'cPanel, Inc.'),),
377 (('commonName', 'cPanel, Inc. Certification Authority'),)),
378 'notAfter': 'Jun 18 23:59:59 2020 GMT',
379 'notBefore': 'Mar 20 00:00:00 2020 GMT',
380 'serialNumber': 'C59063D118921B05F9CAD793431883C4',
381 'subject': ((('commonName', 'daddyfree.com'),),),
382 'subjectAltName': (('DNS', 'daddyfree.com'),
383 ('DNS', 'cpanel.daddyfree.com'),
384 ('DNS', 'cpcalendars.daddyfree.com'),
385 ('DNS', 'cpcontacts.daddyfree.com'),
386 ('DNS', 'mail.daddyfree.com'),
387 ('DNS', 'webdisk.daddyfree.com'),
388 ('DNS', 'webmail.daddyfree.com'),
389 ('DNS', 'www.daddyfree.com')),
390 'version': 3}
391-----BEGIN CERTIFICATE-----
392MIIGczCCBVugAwIBAgIRAMWQY9EYkhsF+crXk0MYg8QwDQYJKoZIhvcNAQELBQAw
393cjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlRYMRAwDgYDVQQHEwdIb3VzdG9uMRUw
394EwYDVQQKEwxjUGFuZWwsIEluYy4xLTArBgNVBAMTJGNQYW5lbCwgSW5jLiBDZXJ0
395aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0yMDAzMjAwMDAwMDBaFw0yMDA2MTgyMzU5
396NTlaMBgxFjAUBgNVBAMTDWRhZGR5ZnJlZS5jb20wggEiMA0GCSqGSIb3DQEBAQUA
397A4IBDwAwggEKAoIBAQDqQRzofVVO7FHCDxnIBaofKr4wjNgD3qvq1TMI+NRjiaLU
398z+D/AqabVAWYrLJzMhH75UWgVgaYxPYlGypybOGg0GEEoKWkXn3pEOrvNBo4Fbk9
399Y0nKoKWWpaM5Z6NGFsmwJd52EPYuef8+viKINYcTtz7L/J3ZUg8w/RIJp64xT8c5
4004/s2ilIYh+Jsupp7+W86OpE3vWL0iKnp4YuUbikmVbfypWksKf1BrKUJenIJ9hx1
401QeMxQnskj1d1i39jT/0zJukDQCDp9V+p8nqFvNnnKxNzXg2nAFdX0p17KkhNJ1WW
402znkV7ENxY5A6zVrO6oa7FBZNd1q7W8EnWjzn5IgPAgMBAAGjggNcMIIDWDAfBgNV
403HSMEGDAWgBR+A1plQWunfgrhuJ0I6h2OHWrHZTAdBgNVHQ4EFgQURp2QiNajmlYv
404O7saKv+fwknYfSMwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0l
405BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMEkGA1UdIARCMEAwNAYLKwYBBAGyMQEC
406AjQwJTAjBggrBgEFBQcCARYXaHR0cHM6Ly9zZWN0aWdvLmNvbS9DUFMwCAYGZ4EM
407AQIBMEwGA1UdHwRFMEMwQaA/oD2GO2h0dHA6Ly9jcmwuY29tb2RvY2EuY29tL2NQ
408YW5lbEluY0NlcnRpZmljYXRpb25BdXRob3JpdHkuY3JsMH0GCCsGAQUFBwEBBHEw
409bzBHBggrBgEFBQcwAoY7aHR0cDovL2NydC5jb21vZG9jYS5jb20vY1BhbmVsSW5j
410Q2VydGlmaWNhdGlvbkF1dGhvcml0eS5jcnQwJAYIKwYBBQUHMAGGGGh0dHA6Ly9v
411Y3NwLmNvbW9kb2NhLmNvbTCCAQIGCisGAQQB1nkCBAIEgfMEgfAA7gB1AAe3XBvl
412fWj/8bDGHSMVx7rmV3xXlLdq7rxhOhpp06IcAAABcPf12nYAAAQDAEYwRAIgDReW
413xuM8jwdxOwDB6CVzuCYnDU1Tw6ZM06v7EJD1c14CICIcL9cbsRLhFCBJ3qbaFxV2
414e9Jf68DpEKIMStZePJBqAHUA5xLysDd+GmL7jskMYYTx6ns3y1YdESZb8+DzS/JB
415VG4AAAFw9/XalAAABAMARjBEAiAWKgQ4Om2L873rQ0pqeqMOrJIqx2eoyHVfqBpm
416e0KL7QIgXh6w7beHQrUJ1ix52XlHjkV5QDAYnPhj85y2F5IVTgswgboGA1UdEQSB
417sjCBr4INZGFkZHlmcmVlLmNvbYIUY3BhbmVsLmRhZGR5ZnJlZS5jb22CGWNwY2Fs
418ZW5kYXJzLmRhZGR5ZnJlZS5jb22CGGNwY29udGFjdHMuZGFkZHlmcmVlLmNvbYIS
419bWFpbC5kYWRkeWZyZWUuY29tghV3ZWJkaXNrLmRhZGR5ZnJlZS5jb22CFXdlYm1h
420aWwuZGFkZHlmcmVlLmNvbYIRd3d3LmRhZGR5ZnJlZS5jb20wDQYJKoZIhvcNAQEL
421BQADggEBAH8YbzaTa9MLCx0Sn4siRbd1qfoxOqwavEAkSzU1tn8ci1QjJjS/IqG5
422AtnXYOyzyWSHcMqS2dLIYr4lwOK8jgDNeHRwoRaoM1tjnXc7vjyhVfi28eTTDdZr
423N8sW/KqcdxbPo1r/2SHiiyXYsfoqsvhHWAsdo6MM603ElHA+xyv/Csf+b11Lp57+
424SNzDhvwcmDFBqCFvm/5QDoK7+letNL1DH5drj+MYUKfl2P8hkkyDHpsp6GssSlcQ
425DgZNd1fMiBAOn+cVb7tVlbih+zDgYTDXIXgygRm3jFVLXoxdVNO9IVmoAfAbyJ1z
426mCfnHP2uGr5fWp5Zvnc4NrtAgArGeR0=
427-----END CERTIFICATE-----
428
429--------------------------------------------------
430[+] Collecting Information Disclosure!
431[#] Detecting sitemap.xml file
432[-] sitemap.xml file not Found!?
433[#] Detecting robots.txt file
434[-] robots.txt file not Found!?
435[#] Detecting GNU Mailman
436[!] GNU Mailman App Detected: http://daddyfree.com//mailman/admin
437[!] version: 2.1.29
438--------------------------------------------------
439[+] Crawling Url Parameter On: http://daddyfree.com/
440--------------------------------------------------
441[#] Searching Html Form !
442[+] Html Form Discovered
443[#] action: ./ucp.php?mode=login&sid=83575650c6f8869947f245e1182332a9
444[#] class: None
445[#] id: None
446[#] method: post
447--------------------------------------------------
448[!] Found 30 dom parameter
449[#] http://daddyfree.com//#
450[#] http://daddyfree.com//#
451[#] http://daddyfree.com//./viewtopic.php?f=47&p=3172&sid=83575650c6f8869947f245e1182332a9#p3172
452[#] http://daddyfree.com//./viewtopic.php?f=47&p=3172&sid=83575650c6f8869947f245e1182332a9#p3172
453[#] http://daddyfree.com//./viewtopic.php?f=54&p=3178&sid=83575650c6f8869947f245e1182332a9#p3178
454[#] http://daddyfree.com//./viewtopic.php?f=54&p=3178&sid=83575650c6f8869947f245e1182332a9#p3178
455[#] http://daddyfree.com//./viewtopic.php?f=55&p=3151&sid=83575650c6f8869947f245e1182332a9#p3151
456[#] http://daddyfree.com//./viewtopic.php?f=55&p=3151&sid=83575650c6f8869947f245e1182332a9#p3151
457[#] http://daddyfree.com//./viewtopic.php?f=6&p=3153&sid=83575650c6f8869947f245e1182332a9#p3153
458[#] http://daddyfree.com//./viewtopic.php?f=6&p=3153&sid=83575650c6f8869947f245e1182332a9#p3153
459[#] http://daddyfree.com//./viewtopic.php?f=10&p=3155&sid=83575650c6f8869947f245e1182332a9#p3155
460[#] http://daddyfree.com//./viewtopic.php?f=10&p=3155&sid=83575650c6f8869947f245e1182332a9#p3155
461[#] http://daddyfree.com//./viewtopic.php?f=3&p=3185&sid=83575650c6f8869947f245e1182332a9#p3185
462[#] http://daddyfree.com//./viewtopic.php?f=3&p=3185&sid=83575650c6f8869947f245e1182332a9#p3185
463[#] http://daddyfree.com//./viewtopic.php?f=12&p=3167&sid=83575650c6f8869947f245e1182332a9#p3167
464[#] http://daddyfree.com//./viewtopic.php?f=12&p=3167&sid=83575650c6f8869947f245e1182332a9#p3167
465[#] http://daddyfree.com//./viewtopic.php?f=15&p=3181&sid=83575650c6f8869947f245e1182332a9#p3181
466[#] http://daddyfree.com//./viewtopic.php?f=15&p=3181&sid=83575650c6f8869947f245e1182332a9#p3181
467[#] http://daddyfree.com//./viewtopic.php?f=18&p=3186&sid=83575650c6f8869947f245e1182332a9#p3186
468[#] http://daddyfree.com//./viewtopic.php?f=18&p=3186&sid=83575650c6f8869947f245e1182332a9#p3186
469[#] http://daddyfree.com//./viewtopic.php?f=22&p=3187&sid=83575650c6f8869947f245e1182332a9#p3187
470[#] http://daddyfree.com//./viewtopic.php?f=22&p=3187&sid=83575650c6f8869947f245e1182332a9#p3187
471[#] http://daddyfree.com//./viewtopic.php?f=60&p=3166&sid=83575650c6f8869947f245e1182332a9#p3166
472[#] http://daddyfree.com//./viewtopic.php?f=60&p=3166&sid=83575650c6f8869947f245e1182332a9#p3166
473[#] http://daddyfree.com//./viewtopic.php?f=56&p=3184&sid=83575650c6f8869947f245e1182332a9#p3184
474[#] http://daddyfree.com//./viewtopic.php?f=56&p=3184&sid=83575650c6f8869947f245e1182332a9#p3184
475[#] http://daddyfree.com//./viewtopic.php?f=39&p=3188&sid=83575650c6f8869947f245e1182332a9#p3188
476[#] http://daddyfree.com//./viewtopic.php?f=39&p=3188&sid=83575650c6f8869947f245e1182332a9#p3188
477[#] http://daddyfree.com//./viewtopic.php?f=59&p=3180&sid=83575650c6f8869947f245e1182332a9#p3180
478[#] http://daddyfree.com//./viewtopic.php?f=59&p=3180&sid=83575650c6f8869947f245e1182332a9#p3180
479--------------------------------------------------
480[!] 98 Internal Dynamic Parameter Discovered
481[+] http://daddyfree.com//./styles/FLATBOOTS/theme/stylesheet.css?assets_version=23
482[+] http://daddyfree.com//./ext/dmzx/ultimatepoints/styles/all/theme/ultimatepoints.css?assets_version=23
483[+] http://daddyfree.com//./ext/vse/abbc3/styles/all/theme/abbc3_common.min.css?assets_version=23
484[+] http://daddyfree.com//./index.php?sid=83575650c6f8869947f245e1182332a9
485[+] http://daddyfree.com//./index.php?sid=83575650c6f8869947f245e1182332a9
486[+] http://daddyfree.com///app.php/help/faq?sid=83575650c6f8869947f245e1182332a9
487[+] http://daddyfree.com//./memberlist.php?mode=team&sid=83575650c6f8869947f245e1182332a9
488[+] http://daddyfree.com//./search.php?sid=83575650c6f8869947f245e1182332a9
489[+] http://daddyfree.com//./ucp.php?mode=register&sid=83575650c6f8869947f245e1182332a9
490[+] http://daddyfree.com//./ucp.php?mode=login&sid=83575650c6f8869947f245e1182332a9
491[+] http://daddyfree.com//./index.php?sid=83575650c6f8869947f245e1182332a9
492[+] http://daddyfree.com//./index.php?sid=83575650c6f8869947f245e1182332a9
493[+] http://daddyfree.com//./viewforum.php?f=47&sid=83575650c6f8869947f245e1182332a9
494[+] http://daddyfree.com//./viewtopic.php?f=47&p=3172&sid=83575650c6f8869947f245e1182332a9#p3172
495[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
496[+] http://daddyfree.com//./viewtopic.php?f=47&p=3172&sid=83575650c6f8869947f245e1182332a9#p3172
497[+] http://daddyfree.com//./viewforum.php?f=52&sid=83575650c6f8869947f245e1182332a9
498[+] http://daddyfree.com//./viewforum.php?f=54&sid=83575650c6f8869947f245e1182332a9
499[+] http://daddyfree.com//./viewtopic.php?f=54&p=3178&sid=83575650c6f8869947f245e1182332a9#p3178
500[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
501[+] http://daddyfree.com//./viewtopic.php?f=54&p=3178&sid=83575650c6f8869947f245e1182332a9#p3178
502[+] http://daddyfree.com//./viewforum.php?f=55&sid=83575650c6f8869947f245e1182332a9
503[+] http://daddyfree.com//./viewtopic.php?f=55&p=3151&sid=83575650c6f8869947f245e1182332a9#p3151
504[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
505[+] http://daddyfree.com//./viewtopic.php?f=55&p=3151&sid=83575650c6f8869947f245e1182332a9#p3151
506[+] http://daddyfree.com//./viewforum.php?f=1&sid=83575650c6f8869947f245e1182332a9
507[+] http://daddyfree.com//./viewforum.php?f=5&sid=83575650c6f8869947f245e1182332a9
508[+] http://daddyfree.com//./viewforum.php?f=6&sid=83575650c6f8869947f245e1182332a9
509[+] http://daddyfree.com//./viewforum.php?f=7&sid=83575650c6f8869947f245e1182332a9
510[+] http://daddyfree.com//./viewtopic.php?f=6&p=3153&sid=83575650c6f8869947f245e1182332a9#p3153
511[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
512[+] http://daddyfree.com//./viewtopic.php?f=6&p=3153&sid=83575650c6f8869947f245e1182332a9#p3153
513[+] http://daddyfree.com//./viewforum.php?f=8&sid=83575650c6f8869947f245e1182332a9
514[+] http://daddyfree.com//./viewforum.php?f=9&sid=83575650c6f8869947f245e1182332a9
515[+] http://daddyfree.com//./viewforum.php?f=10&sid=83575650c6f8869947f245e1182332a9
516[+] http://daddyfree.com//./viewtopic.php?f=10&p=3155&sid=83575650c6f8869947f245e1182332a9#p3155
517[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
518[+] http://daddyfree.com//./viewtopic.php?f=10&p=3155&sid=83575650c6f8869947f245e1182332a9#p3155
519[+] http://daddyfree.com//./viewforum.php?f=2&sid=83575650c6f8869947f245e1182332a9
520[+] http://daddyfree.com//./viewforum.php?f=3&sid=83575650c6f8869947f245e1182332a9
521[+] http://daddyfree.com//./viewforum.php?f=4&sid=83575650c6f8869947f245e1182332a9
522[+] http://daddyfree.com//./viewtopic.php?f=3&p=3185&sid=83575650c6f8869947f245e1182332a9#p3185
523[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
524[+] http://daddyfree.com//./viewtopic.php?f=3&p=3185&sid=83575650c6f8869947f245e1182332a9#p3185
525[+] http://daddyfree.com//./viewforum.php?f=11&sid=83575650c6f8869947f245e1182332a9
526[+] http://daddyfree.com//./viewforum.php?f=12&sid=83575650c6f8869947f245e1182332a9
527[+] http://daddyfree.com//./viewforum.php?f=13&sid=83575650c6f8869947f245e1182332a9
528[+] http://daddyfree.com//./viewtopic.php?f=12&p=3167&sid=83575650c6f8869947f245e1182332a9#p3167
529[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
530[+] http://daddyfree.com//./viewtopic.php?f=12&p=3167&sid=83575650c6f8869947f245e1182332a9#p3167
531[+] http://daddyfree.com//./viewforum.php?f=14&sid=83575650c6f8869947f245e1182332a9
532[+] http://daddyfree.com//./viewforum.php?f=15&sid=83575650c6f8869947f245e1182332a9
533[+] http://daddyfree.com//./viewforum.php?f=16&sid=83575650c6f8869947f245e1182332a9
534[+] http://daddyfree.com//./viewtopic.php?f=15&p=3181&sid=83575650c6f8869947f245e1182332a9#p3181
535[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
536[+] http://daddyfree.com//./viewtopic.php?f=15&p=3181&sid=83575650c6f8869947f245e1182332a9#p3181
537[+] http://daddyfree.com//./viewforum.php?f=17&sid=83575650c6f8869947f245e1182332a9
538[+] http://daddyfree.com//./viewforum.php?f=18&sid=83575650c6f8869947f245e1182332a9
539[+] http://daddyfree.com//./viewforum.php?f=20&sid=83575650c6f8869947f245e1182332a9
540[+] http://daddyfree.com//./viewtopic.php?f=18&p=3186&sid=83575650c6f8869947f245e1182332a9#p3186
541[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
542[+] http://daddyfree.com//./viewtopic.php?f=18&p=3186&sid=83575650c6f8869947f245e1182332a9#p3186
543[+] http://daddyfree.com//./viewforum.php?f=21&sid=83575650c6f8869947f245e1182332a9
544[+] http://daddyfree.com//./viewforum.php?f=22&sid=83575650c6f8869947f245e1182332a9
545[+] http://daddyfree.com//./viewforum.php?f=23&sid=83575650c6f8869947f245e1182332a9
546[+] http://daddyfree.com//./viewforum.php?f=24&sid=83575650c6f8869947f245e1182332a9
547[+] http://daddyfree.com//./viewforum.php?f=25&sid=83575650c6f8869947f245e1182332a9
548[+] http://daddyfree.com//./viewforum.php?f=58&sid=83575650c6f8869947f245e1182332a9
549[+] http://daddyfree.com//./viewtopic.php?f=22&p=3187&sid=83575650c6f8869947f245e1182332a9#p3187
550[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
551[+] http://daddyfree.com//./viewtopic.php?f=22&p=3187&sid=83575650c6f8869947f245e1182332a9#p3187
552[+] http://daddyfree.com//./viewforum.php?f=60&sid=83575650c6f8869947f245e1182332a9
553[+] http://daddyfree.com//./viewtopic.php?f=60&p=3166&sid=83575650c6f8869947f245e1182332a9#p3166
554[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
555[+] http://daddyfree.com//./viewtopic.php?f=60&p=3166&sid=83575650c6f8869947f245e1182332a9#p3166
556[+] http://daddyfree.com//./viewforum.php?f=51&sid=83575650c6f8869947f245e1182332a9
557[+] http://daddyfree.com//./viewforum.php?f=56&sid=83575650c6f8869947f245e1182332a9
558[+] http://daddyfree.com//./viewtopic.php?f=56&p=3184&sid=83575650c6f8869947f245e1182332a9#p3184
559[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
560[+] http://daddyfree.com//./viewtopic.php?f=56&p=3184&sid=83575650c6f8869947f245e1182332a9#p3184
561[+] http://daddyfree.com//./viewforum.php?f=37&sid=83575650c6f8869947f245e1182332a9
562[+] http://daddyfree.com//./viewforum.php?f=38&sid=83575650c6f8869947f245e1182332a9
563[+] http://daddyfree.com//./viewforum.php?f=39&sid=83575650c6f8869947f245e1182332a9
564[+] http://daddyfree.com//./viewforum.php?f=40&sid=83575650c6f8869947f245e1182332a9
565[+] http://daddyfree.com//./viewforum.php?f=46&sid=83575650c6f8869947f245e1182332a9
566[+] http://daddyfree.com//./viewforum.php?f=57&sid=83575650c6f8869947f245e1182332a9
567[+] http://daddyfree.com//./viewtopic.php?f=39&p=3188&sid=83575650c6f8869947f245e1182332a9#p3188
568[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
569[+] http://daddyfree.com//./viewtopic.php?f=39&p=3188&sid=83575650c6f8869947f245e1182332a9#p3188
570[+] http://daddyfree.com//./viewforum.php?f=59&sid=83575650c6f8869947f245e1182332a9
571[+] http://daddyfree.com//./viewtopic.php?f=59&p=3180&sid=83575650c6f8869947f245e1182332a9#p3180
572[+] http://daddyfree.com//./memberlist.php?mode=viewprofile&u=2&sid=83575650c6f8869947f245e1182332a9
573[+] http://daddyfree.com//./viewtopic.php?f=59&p=3180&sid=83575650c6f8869947f245e1182332a9#p3180
574[+] http://daddyfree.com//./ucp.php?mode=terms&sid=83575650c6f8869947f245e1182332a9
575[+] http://daddyfree.com//./ucp.php?mode=privacy&sid=83575650c6f8869947f245e1182332a9
576[+] http://daddyfree.com//./ucp.php?mode=register&sid=83575650c6f8869947f245e1182332a9
577[+] http://daddyfree.com//./ucp.php?mode=privacy&sid=83575650c6f8869947f245e1182332a9
578[+] http://daddyfree.com//./ucp.php?mode=terms&sid=83575650c6f8869947f245e1182332a9
579--------------------------------------------------
580[-] No external Dynamic Paramter Found!?
581--------------------------------------------------
582[!] 6 Internal links Discovered
583[+] http://daddyfree.com//javascript:void(0)
584[+] http://daddyfree.com//javascript:void(0)
585[+] http://daddyfree.com///shop/
586[+] http://daddyfree.com///shop/
587[+] http://daddyfree.com//" title=
588[+] http://daddyfree.com//" onclick=
589--------------------------------------------------
590[!] 1 External links Discovered
591[#] http://www.phpbb.com/
592--------------------------------------------------
593[#] Mapping Subdomain..
594[!] Found 1 Subdomain
595- daddyfree.com
596--------------------------------------------------
597[!] Done At 2020-03-23 10:06:16.219296
598################################################################################################################################
599[INFO] ------TARGET info------
600[*] TARGET: http://daddyfree.com/
601[*] TARGET IP: 188.127.251.161
602[INFO] NO load balancer detected for daddyfree.com...
603[*] DNS servers: ns1.dynu.com.
604[*] TARGET server: Apache
605[*] CC: RU
606[*] Country: Russia
607[*] RegionCode: LEN
608[*] RegionName: Leningradskaya Oblast'
609[*] City: Shcheglovo
610[*] ASN: AS56694
611[*] BGP_PREFIX: 188.127.248.0/22
612[*] ISP: DHUB LLC Smart Ape, RU
613[INFO] DNS enumeration:
614[*] ad.daddyfree.com 188.127.251.161
615[*] admin.daddyfree.com 188.127.251.161
616[*] ads.daddyfree.com 188.127.251.161
617[*] alpha.daddyfree.com 188.127.251.161
618[*] api.daddyfree.com 188.127.251.161
619[*] api-online.daddyfree.com 188.127.251.161
620[*] apolo.daddyfree.com 188.127.251.161
621[*] app.daddyfree.com 188.127.251.161
622[*] beta.daddyfree.com 188.127.251.161
623[*] bi.daddyfree.com 188.127.251.161
624[*] blog.daddyfree.com 188.127.251.161
625[*] cdn.daddyfree.com 188.127.251.161
626[*] events.daddyfree.com 188.127.251.161
627[*] ex.daddyfree.com 188.127.251.161
628[*] files.daddyfree.com 188.127.251.161
629[*] ftp.daddyfree.com 188.127.251.161
630[*] gateway.daddyfree.com 188.127.251.161
631[*] go.daddyfree.com 188.127.251.161
632[*] help.daddyfree.com 188.127.251.161
633[*] ib.daddyfree.com 188.127.251.161
634[*] images.daddyfree.com 188.127.251.161
635[*] internetbanking.daddyfree.com 188.127.251.161
636[*] intranet.daddyfree.com 188.127.251.161
637[*] jobs.daddyfree.com 188.127.251.161
638[*] join.daddyfree.com 188.127.251.161
639[*] live.daddyfree.com 188.127.251.161
640[*] login.daddyfree.com 188.127.251.161
641[*] m.daddyfree.com 188.127.251.161
642[*] mail.daddyfree.com 188.127.251.161
643[*] mail2.daddyfree.com 188.127.251.161
644[*] mobile.daddyfree.com 188.127.251.161
645[*] moodle.daddyfree.com 188.127.251.161
646[*] mx.daddyfree.com 188.127.251.161
647[*] mx2.daddyfree.com 188.127.251.161
648[*] mx3.daddyfree.com 188.127.251.161
649[*] my.daddyfree.com 188.127.251.161
650[*] new.daddyfree.com 188.127.251.161
651[*] news.daddyfree.com 188.127.251.161
652[*] ns1.daddyfree.com 188.127.251.161
653[*] ns2.daddyfree.com 188.127.251.161
654[*] ns3.daddyfree.com 188.127.251.161
655[*] oauth.daddyfree.com 188.127.251.161
656[*] old.daddyfree.com 188.127.251.161
657[*] one.daddyfree.com 188.127.251.161
658[*] open.daddyfree.com 188.127.251.161
659[*] out.daddyfree.com 188.127.251.161
660[*] outlook.daddyfree.com 188.127.251.161
661[*] portfolio.daddyfree.com 188.127.251.161
662[*] raw.daddyfree.com 188.127.251.161
663[*] repo.daddyfree.com 188.127.251.161
664[*] router.daddyfree.com 188.127.251.161
665[*] search.daddyfree.com 188.127.251.161
666[*] siem.daddyfree.com 188.127.251.161
667[*] slack.daddyfree.com 188.127.251.161
668[*] slackbot.daddyfree.com 188.127.251.161
669[*] snmp.daddyfree.com 188.127.251.161
670[*] stream.daddyfree.com 188.127.251.161
671[*] support.daddyfree.com 188.127.251.161
672[*] syslog.daddyfree.com 188.127.251.161
673[*] tags.daddyfree.com 188.127.251.161
674[*] test.daddyfree.com 188.127.251.161
675[*] upload.daddyfree.com 188.127.251.161
676[*] video.daddyfree.com 188.127.251.161
677[*] vpn.daddyfree.com 188.127.251.161
678[*] webconf.daddyfree.com 188.127.251.161
679[*] webmail.daddyfree.com 188.127.251.161
680[*] webportal.daddyfree.com 188.127.251.161
681[*] wiki.daddyfree.com 188.127.251.161
682[*] www2.daddyfree.com 188.127.251.161
683[*] www3.daddyfree.com 188.127.251.161
684[*] zendesk.daddyfree.com 188.127.251.161
685[INFO] Possible abuse mails are:
686[*] abuse@daddyfree.com
687[*] abuse@smartape.ru
688[INFO] NO PAC (Proxy Auto Configuration) file FOUND
689[ALERT] robots.txt file FOUND in http://daddyfree.com/robots.txt
690[INFO] Checking for HTTP status codes recursively from http://daddyfree.com/robots.txt
691[INFO] Status code Folders
692[INFO] Starting FUZZing in http://daddyfree.com/FUzZzZzZzZz...
693[INFO] Status code Folders
694[*] 200 http://daddyfree.com/index
695[*] 200 http://daddyfree.com/images
696[*] 200 http://daddyfree.com/download
697[*] 200 http://daddyfree.com/2006
698[*] 200 http://daddyfree.com/news
699[*] 200 http://daddyfree.com/crack
700[*] 200 http://daddyfree.com/serial
701[*] 200 http://daddyfree.com/warez
702[*] 200 http://daddyfree.com/full
703[*] 200 http://daddyfree.com/12
704[ALERT] Look in the source code. It may contain passwords
705[ALERT] Content in http://daddyfree.com/ AND http://www.daddyfree.com/ is different
706[INFO] MD5 for http://daddyfree.com/ is: fbea43149a3bcd41a7c77d927574f0f4
707[INFO] MD5 for http://www.daddyfree.com/ is: e43db3a2e3e3c273f08cb04e4af1b983
708[INFO] http://daddyfree.com/ redirects to http://daddyfree.com/
709[INFO] http://www.daddyfree.com/ redirects to http://www.daddyfree.com/
710[INFO] Links found from http://daddyfree.com/ http://188.127.251.161/:
711[*] http://188.127.251.161/cgi-sys/defaultwebpage.cgi
712[*] http://daddyfree.com/
713[*] http://daddyfree.com/app.php/help/faq?sid=4801673d127d330016d55bd27f58d0d6
714[*] http://daddyfree.com/index.php?sid=4801673d127d330016d55bd27f58d0d6
715[*] http://daddyfree.com/memberlist.php?mode=team&sid=4801673d127d330016d55bd27f58d0d6
716[*] http://daddyfree.com/memberlist.php?mode=viewprofile&u=2&sid=4801673d127d330016d55bd27f58d0d6
717[*] http://daddyfree.com/search.php?sid=4801673d127d330016d55bd27f58d0d6
718[*] http://daddyfree.com/shop/
719[*] http://daddyfree.com/ucp.php?mode=login&sid=4801673d127d330016d55bd27f58d0d6
720[*] http://daddyfree.com/ucp.php?mode=privacy&sid=4801673d127d330016d55bd27f58d0d6
721[*] http://daddyfree.com/ucp.php?mode=register&sid=4801673d127d330016d55bd27f58d0d6
722[*] http://daddyfree.com/ucp.php?mode=terms&sid=4801673d127d330016d55bd27f58d0d6
723[*] http://daddyfree.com/viewforum.php?f=10&sid=4801673d127d330016d55bd27f58d0d6
724[*] http://daddyfree.com/viewforum.php?f=11&sid=4801673d127d330016d55bd27f58d0d6
725[*] http://daddyfree.com/viewforum.php?f=12&sid=4801673d127d330016d55bd27f58d0d6
726[*] http://daddyfree.com/viewforum.php?f=13&sid=4801673d127d330016d55bd27f58d0d6
727[*] http://daddyfree.com/viewforum.php?f=14&sid=4801673d127d330016d55bd27f58d0d6
728[*] http://daddyfree.com/viewforum.php?f=15&sid=4801673d127d330016d55bd27f58d0d6
729[*] http://daddyfree.com/viewforum.php?f=16&sid=4801673d127d330016d55bd27f58d0d6
730[*] http://daddyfree.com/viewforum.php?f=17&sid=4801673d127d330016d55bd27f58d0d6
731[*] http://daddyfree.com/viewforum.php?f=18&sid=4801673d127d330016d55bd27f58d0d6
732[*] http://daddyfree.com/viewforum.php?f=1&sid=4801673d127d330016d55bd27f58d0d6
733[*] http://daddyfree.com/viewforum.php?f=20&sid=4801673d127d330016d55bd27f58d0d6
734[*] http://daddyfree.com/viewforum.php?f=21&sid=4801673d127d330016d55bd27f58d0d6
735[*] http://daddyfree.com/viewforum.php?f=22&sid=4801673d127d330016d55bd27f58d0d6
736[*] http://daddyfree.com/viewforum.php?f=23&sid=4801673d127d330016d55bd27f58d0d6
737[*] http://daddyfree.com/viewforum.php?f=24&sid=4801673d127d330016d55bd27f58d0d6
738[*] http://daddyfree.com/viewforum.php?f=25&sid=4801673d127d330016d55bd27f58d0d6
739[*] http://daddyfree.com/viewforum.php?f=2&sid=4801673d127d330016d55bd27f58d0d6
740[*] http://daddyfree.com/viewforum.php?f=37&sid=4801673d127d330016d55bd27f58d0d6
741[*] http://daddyfree.com/viewforum.php?f=38&sid=4801673d127d330016d55bd27f58d0d6
742[*] http://daddyfree.com/viewforum.php?f=39&sid=4801673d127d330016d55bd27f58d0d6
743[*] http://daddyfree.com/viewforum.php?f=3&sid=4801673d127d330016d55bd27f58d0d6
744[*] http://daddyfree.com/viewforum.php?f=40&sid=4801673d127d330016d55bd27f58d0d6
745[*] http://daddyfree.com/viewforum.php?f=46&sid=4801673d127d330016d55bd27f58d0d6
746[*] http://daddyfree.com/viewforum.php?f=47&sid=4801673d127d330016d55bd27f58d0d6
747[*] http://daddyfree.com/viewforum.php?f=4&sid=4801673d127d330016d55bd27f58d0d6
748[*] http://daddyfree.com/viewforum.php?f=51&sid=4801673d127d330016d55bd27f58d0d6
749[*] http://daddyfree.com/viewforum.php?f=52&sid=4801673d127d330016d55bd27f58d0d6
750[*] http://daddyfree.com/viewforum.php?f=54&sid=4801673d127d330016d55bd27f58d0d6
751[*] http://daddyfree.com/viewforum.php?f=55&sid=4801673d127d330016d55bd27f58d0d6
752[*] http://daddyfree.com/viewforum.php?f=56&sid=4801673d127d330016d55bd27f58d0d6
753[*] http://daddyfree.com/viewforum.php?f=57&sid=4801673d127d330016d55bd27f58d0d6
754[*] http://daddyfree.com/viewforum.php?f=58&sid=4801673d127d330016d55bd27f58d0d6
755[*] http://daddyfree.com/viewforum.php?f=59&sid=4801673d127d330016d55bd27f58d0d6
756[*] http://daddyfree.com/viewforum.php?f=5&sid=4801673d127d330016d55bd27f58d0d6
757[*] http://daddyfree.com/viewforum.php?f=60&sid=4801673d127d330016d55bd27f58d0d6
758[*] http://daddyfree.com/viewforum.php?f=6&sid=4801673d127d330016d55bd27f58d0d6
759[*] http://daddyfree.com/viewforum.php?f=7&sid=4801673d127d330016d55bd27f58d0d6
760[*] http://daddyfree.com/viewforum.php?f=8&sid=4801673d127d330016d55bd27f58d0d6
761[*] http://daddyfree.com/viewforum.php?f=9&sid=4801673d127d330016d55bd27f58d0d6
762[*] http://daddyfree.com/viewtopic.php?f=10&p=3155&sid=4801673d127d330016d55bd27f58d0d6#p3155
763[*] http://daddyfree.com/viewtopic.php?f=12&p=3167&sid=4801673d127d330016d55bd27f58d0d6#p3167
764[*] http://daddyfree.com/viewtopic.php?f=15&p=3181&sid=4801673d127d330016d55bd27f58d0d6#p3181
765[*] http://daddyfree.com/viewtopic.php?f=18&p=3186&sid=4801673d127d330016d55bd27f58d0d6#p3186
766[*] http://daddyfree.com/viewtopic.php?f=22&p=3187&sid=4801673d127d330016d55bd27f58d0d6#p3187
767[*] http://daddyfree.com/viewtopic.php?f=39&p=3188&sid=4801673d127d330016d55bd27f58d0d6#p3188
768[*] http://daddyfree.com/viewtopic.php?f=3&p=3185&sid=4801673d127d330016d55bd27f58d0d6#p3185
769[*] http://daddyfree.com/viewtopic.php?f=47&p=3172&sid=4801673d127d330016d55bd27f58d0d6#p3172
770[*] http://daddyfree.com/viewtopic.php?f=54&p=3178&sid=4801673d127d330016d55bd27f58d0d6#p3178
771[*] http://daddyfree.com/viewtopic.php?f=55&p=3151&sid=4801673d127d330016d55bd27f58d0d6#p3151
772[*] http://daddyfree.com/viewtopic.php?f=56&p=3184&sid=4801673d127d330016d55bd27f58d0d6#p3184
773[*] http://daddyfree.com/viewtopic.php?f=59&p=3180&sid=4801673d127d330016d55bd27f58d0d6#p3180
774[*] http://daddyfree.com/viewtopic.php?f=60&p=3166&sid=4801673d127d330016d55bd27f58d0d6#p3166
775[*] http://daddyfree.com/viewtopic.php?f=6&p=3153&sid=4801673d127d330016d55bd27f58d0d6#p3153
776[*] http://www.phpbb.com/
777cut: intervalle de champ incorrecte
778Saisissez « cut --help » pour plus d'informations.
779[INFO] BING shows 188.127.251.161 is shared with 6 hosts/vhosts
780[INFO] Shodan detected the following opened ports on 188.127.251.161:
781[*] 1
782[*] 110
783[*] 143
784[*] 2077
785[*] 2082
786[*] 2086
787[*] 2087
788[*] 22
789[*] 3306
790[*] 4
791[*] 465
792[*] 53
793[*] 587
794[*] 80
795[*] 993
796[INFO] ------VirusTotal SECTION------
797[INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
798[INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
799[INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
800[INFO] ------Alexa Rank SECTION------
801[INFO] Percent of Visitors Rank in Country:
802[INFO] Percent of Search Traffic:
803[INFO] Percent of Unique Visits:
804[INFO] Total Sites Linking In:
805[INFO] Useful links related to daddyfree.com - 188.127.251.161:
806[*] https://www.virustotal.com/pt/ip-address/188.127.251.161/information/
807[*] https://www.hybrid-analysis.com/search?host=188.127.251.161
808[*] https://www.shodan.io/host/188.127.251.161
809[*] https://www.senderbase.org/lookup/?search_string=188.127.251.161
810[*] https://www.alienvault.com/open-threat-exchange/ip/188.127.251.161
811[*] http://pastebin.com/search?q=188.127.251.161
812[*] http://urlquery.net/search.php?q=188.127.251.161
813[*] http://www.alexa.com/siteinfo/daddyfree.com
814[*] http://www.google.com/safebrowsing/diagnostic?site=daddyfree.com
815[*] https://censys.io/ipv4/188.127.251.161
816[*] https://www.abuseipdb.com/check/188.127.251.161
817[*] https://urlscan.io/search/#188.127.251.161
818[*] https://github.com/search?q=188.127.251.161&type=Code
819[INFO] Useful links related to AS56694 - 188.127.248.0/22:
820[*] http://www.google.com/safebrowsing/diagnostic?site=AS:56694
821[*] https://www.senderbase.org/lookup/?search_string=188.127.248.0/22
822[*] http://bgp.he.net/AS56694
823[*] https://stat.ripe.net/AS56694
824[INFO] Date: 23/03/20 | Time: 10:07:20
825[INFO] Total time: 1 minute(s) and 20 second(s)
826################################################################################################################################
827; <<>> DiG 9.11.16-2-Debian <<>> +trace daddyfree.com any
828;; global options: +cmd
829. 86400 IN NS m.root-servers.net.
830. 86400 IN NS b.root-servers.net.
831. 86400 IN NS c.root-servers.net.
832. 86400 IN NS d.root-servers.net.
833. 86400 IN NS e.root-servers.net.
834. 86400 IN NS f.root-servers.net.
835. 86400 IN NS g.root-servers.net.
836. 86400 IN NS h.root-servers.net.
837. 86400 IN NS i.root-servers.net.
838. 86400 IN NS a.root-servers.net.
839. 86400 IN NS j.root-servers.net.
840. 86400 IN NS k.root-servers.net.
841. 86400 IN NS l.root-servers.net.
842. 86400 IN RRSIG NS 8 0 518400 20200405050000 20200323040000 33853 . wwuqdFAF+Vuy6Pe0jIDdQRKc0Utq3OrIrEjK5g2osDd4XC3EGVt3AW4c NC1293ownQLkdJz9vKc0FdkEZGURxUBqXzIWPjXdTDn0gkxdKKKXnGEa GRzC6WjeugX1shMmQsD+owQv9h23cwoEsyLjUuolcqKAikIZID6NCHrt y4RA5ZH0d8MFdgqXyDrfdh6urxppsEHedmky/W8Q0s4rYPGFlwCg/7Ik 7AsrvlLW9Ubhc6DmneOZwOwJBEqOBZiJSfNw3SBP7iiqoS0opCAHPzfR u3tvjEQSayiu3wsAUpVChSPR7es5FCQhEzf2pwwSftj4kKxnHi767apw 5HiJgQ==
843;; Received 525 bytes from 10.101.0.243#53(10.101.0.243) in 135 ms
844
845com. 172800 IN NS e.gtld-servers.net.
846com. 172800 IN NS a.gtld-servers.net.
847com. 172800 IN NS k.gtld-servers.net.
848com. 172800 IN NS c.gtld-servers.net.
849com. 172800 IN NS m.gtld-servers.net.
850com. 172800 IN NS i.gtld-servers.net.
851com. 172800 IN NS g.gtld-servers.net.
852com. 172800 IN NS j.gtld-servers.net.
853com. 172800 IN NS h.gtld-servers.net.
854com. 172800 IN NS b.gtld-servers.net.
855com. 172800 IN NS l.gtld-servers.net.
856com. 172800 IN NS f.gtld-servers.net.
857com. 172800 IN NS d.gtld-servers.net.
858com. 86400 IN DS 30909 8 2 E2D3C916F6DEEAC73294E8268FB5885044A833FC5459588F4A9184CF C41A5766
859com. 86400 IN RRSIG DS 8 1 86400 20200405050000 20200323040000 33853 . oFB+p7lZfGV2VEKG1v3XJz263Hh9tdv5yWD2uFAo14dfkDpV0/9VFWWu vm77p6LHI8RGXvyU3Gm1yE6SUJohTK6q5BTp2IKIGByIaDXCCsNuKUN9 UM3Wik0xlbt3RPeUmCCq3XDrFDYUkuU6B5fV+PluW9o8jq5v0j1pGdAg 8nnNrZLeOahO+KgRa0LdeJ7b5Le74fQzzGJ1gCLqzRbBTqf/JMz6F1qN fUTB5PQGnsfdU7D5OWMfomq7KhlNgKEqIayMtyFmj4DaWyyqiYXjLcB7 CuuWUoUe4/2Ox27nEwMx/w3W/Nd5B+c14xaE4mmQldQ8ULZhlVFUiTsA XnlZlg==
860;; Received 1201 bytes from 192.112.36.4#53(g.root-servers.net) in 173 ms
861
862daddyfree.com. 172800 IN NS ns1.dynu.com.
863daddyfree.com. 172800 IN NS ns2.dynu.com.
864daddyfree.com. 172800 IN NS ns3.dynu.com.
865daddyfree.com. 172800 IN NS ns4.dynu.com.
866daddyfree.com. 172800 IN NS ns5.dynu.com.
867daddyfree.com. 172800 IN NS ns6.dynu.com.
868CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN NSEC3 1 1 0 - CK0Q1GIN43N1ARRC9OSM6QPQR81H5M9A NS SOA RRSIG DNSKEY NSEC3PARAM
869CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN RRSIG NSEC3 8 2 86400 20200330044934 20200323033934 56311 com. X8d+VA0H6piJtM33QjsmcHGIAHAf/rrZemEJYtpU5wqfKV5DiwJXkm8e D7FaYcauGloPV1usHu/Yk+jp3Fq07Fa7fOPQcPs8UWp+q6YN3nZOItwS JJxyMw1cAQkpEMXYJMPgCShjHyB1osWgyAjFebRSyIMMRnhBqhKz0tAG OrDnY6Wr6/Ajm+IM7ElE8sL0PJhzQ00JPfSLorvSl8scig==
870PDBJKC661F1BJM8M3R457S5A2ADDMSBA.com. 86400 IN NSEC3 1 1 0 - PDBKG33DAGUCKJNDNK8A8G2QG5EC2MLO NS DS RRSIG
871PDBJKC661F1BJM8M3R457S5A2ADDMSBA.com. 86400 IN RRSIG NSEC3 8 2 86400 20200330052444 20200323041444 56311 com. iEZbFJ1+9ejq44lcc1q5AAiYR8ew+a7tf+Iu1fZm8XUALf/6yj4TYBNT wCB41ZwIYNrJbVYFOS3pe2t4jzEE7ddKwVZO/4njwL1DGEmdi3MU97Jz FMcnCRBnHUIQtw8YvPdZyB8MZklRLuU51//pX051PRX4e29fWATCZrjm BaLTX+n5gQhQ+VWdaKM4hLXc9JioV5OAuDIeVVVz72Sjfw==
872;; Received 940 bytes from 192.52.178.30#53(k.gtld-servers.net) in 143 ms
873
874daddyfree.com. 90 IN NS ns6.dynu.com.
875daddyfree.com. 90 IN NS ns2.dynu.com.
876daddyfree.com. 120 IN A 188.127.251.161
877daddyfree.com. 90 IN NS ns3.dynu.com.
878daddyfree.com. 90 IN NS ns5.dynu.com.
879daddyfree.com. 120 IN SOA ns1.dynu.com. administrator.dynu.com. 2 3600 900 604800 300
880daddyfree.com. 90 IN NS ns4.dynu.com.
881daddyfree.com. 90 IN NS ns1.dynu.com.
882;; Received 485 bytes from 2604:6600:2000:39::8888#53(ns3.dynu.com) in 74 ms
883################################################################################################################################
884*] Performing General Enumeration of Domain: daddyfree.com
885[!] Wildcard resolution is enabled on this domain
886[!] It is resolving to 188.127.251.161
887[!] All queries will resolve to this address!!
888[-] DNSSEC is not configured for daddyfree.com
889[*] SOA ns1.dynu.com 207.38.70.2
890[*] NS ns4.dynu.com 45.119.209.45
891[*] NS ns4.dynu.com 2605:aa80:2::8888
892[*] NS ns5.dynu.com 74.121.191.194
893[*] NS ns5.dynu.com 2607:f8f8:630:1058::8888
894[*] NS ns3.dynu.com 104.149.238.82
895[*] NS ns3.dynu.com 2604:6600:2000:39::8888
896[*] NS ns6.dynu.com 69.25.120.150
897[*] NS ns6.dynu.com 2600:c05:3002:1::150
898[*] NS ns1.dynu.com 207.38.70.2
899[*] NS ns1.dynu.com 2602:ff23:0:8888::2
900[*] NS ns2.dynu.com 104.247.193.125
901[*] NS ns2.dynu.com 2607:3f00:11:32::8888
902[-] Could not Resolve MX Records for daddyfree.com
903[*] A daddyfree.com 188.127.251.161
904[*] Enumerating SRV Records
905[-] No SRV Records Found for daddyfree.com
906[+] 0 Records Found
907###############################################################################################################################
908traceroute to daddyfree.com (188.127.251.161), 30 hops max, 60 byte packets
909 1 _gateway (10.203.21.1) 129.472 ms 134.408 ms 134.408 ms
910 2 * * *
911 3 te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49) 135.156 ms 135.140 ms 135.125 ms
912 4 be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249) 134.973 ms 134.972 ms 134.955 ms
913 5 be3741.ccr22.sto03.atlas.cogentco.com (154.54.60.194) 140.246 ms 140.235 ms 140.108 ms
914 6 be3377.ccr21.sto01.atlas.cogentco.com (154.54.36.90) 140.187 ms 135.502 ms be3376.ccr21.sto01.atlas.cogentco.com (130.117.50.226) 139.635 ms
915 7 rascom.demarc.cogentco.com (149.6.168.138) 140.185 ms 139.721 ms 140.061 ms
916 8 * * *
917 9 dhub.inet2.ru (85.112.122.67) 158.189 ms 158.176 ms 158.059 ms
91810 185.130.248.22 (185.130.248.22) 157.395 ms 157.763 ms 153.597 ms
919################################################################################################################################
920Domains still to check: 1
921 Checking if the hostname daddyfree.com. given is in fact a domain...
922
923Analyzing domain: daddyfree.com.
924 Checking NameServers using system default resolver...
925 IP: 207.38.70.2 (United States)
926 HostName: ns1.dynu.com Type: NS
927 HostName: ns1.dynu.com Type: PTR
928 IP: 69.25.120.150 (United States)
929 HostName: ns6.dynu.com Type: NS
930 HostName: ns6.dynu.com Type: PTR
931 IP: 104.247.193.125 (United States)
932 HostName: ns2.dynu.com Type: NS
933 HostName: ns2.dynu.com Type: PTR
934 IP: 104.149.238.82 (United States)
935 HostName: ns3.dynu.com Type: NS
936 HostName: ns3.dynu.com Type: PTR
937 IP: 45.119.209.45 (United States)
938 HostName: ns4.dynu.com Type: NS
939 HostName: ns4.dynu.com Type: PTR
940 IP: 74.121.191.194 (United States)
941 HostName: ns5.dynu.com Type: NS
942 HostName: 1.2.3.4-reverse.wowrack.com Type: PTR
943
944 Checking MailServers using system default resolver...
945 WARNING!! There are no MX records for this domain
946 WARNING!! This domain has wildcards activated for hostnames resolution. We are checking "www" anyway, but perhaps it doesn't exists!
947
948 Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
949 No zone transfer found on nameserver 45.119.209.45
950 No zone transfer found on nameserver 104.247.193.125
951 No zone transfer found on nameserver 207.38.70.2
952 No zone transfer found on nameserver 104.149.238.82
953 No zone transfer found on nameserver 74.121.191.194
954 No zone transfer found on nameserver 69.25.120.150
955
956 Checking SPF record...
957 No SPF record
958
959 Checking 1 most common hostnames using system default resolver...
960 IP: 188.127.251.161 (Russian Federation)
961 HostName: www.daddyfree.com. Type: A
962
963 Checking with nmap the reverse DNS hostnames of every <ip>/24 netblock using system default resolver...
964 Checking netblock 45.119.209.0
965 Checking netblock 104.247.193.0
966 Checking netblock 207.38.70.0
967 Checking netblock 104.149.238.0
968 Checking netblock 74.121.191.0
969 Checking netblock 188.127.251.0
970 Checking netblock 69.25.120.0
971
972 Searching for daddyfree.com. emails in Google
973
974 Checking 7 active hosts using nmap... (nmap -sn -n -v -PP -PM -PS80,25 -PA -PY -PU53,40125 -PE --reason <ip> -oA <output_directory>/nmap/<ip>.sn)
975 Host 45.119.209.45 is up (echo-reply ttl 48)
976 Host 104.247.193.125 is up (echo-reply ttl 45)
977 Host 207.38.70.2 is up (host-prohibited ttl 42)
978 Host 104.149.238.82 is up (host-prohibited ttl 46)
979 Host 74.121.191.194 is up (host-prohibited ttl 43)
980 Host 188.127.251.161 is down
981 Host 69.25.120.150 is up (host-prohibited ttl 45)
982
983 Checking ports on every active host using nmap... (nmap -O --reason --webxml --traceroute -sS -sV -sC -Pn -n -v -F <ip> -oA <output_directory>/nmap/<ip>)
984 Scanning ip 45.119.209.45 (ns4.dynu.com (PTR)):
985 53/tcp open domain? syn-ack ttl 48
986 | fingerprint-strings:
987 | DNSVersionBindReqTCP:
988 | version
989 |_ bind
990 Scanning ip 104.247.193.125 (ns2.dynu.com (PTR)):
991 53/tcp open domain? syn-ack ttl 45
992 | fingerprint-strings:
993 | DNSVersionBindReqTCP:
994 | version
995 |_ bind
996 Scanning ip 207.38.70.2 (ns1.dynu.com (PTR)):
997 53/tcp open domain? syn-ack ttl 42
998 | fingerprint-strings:
999 | DNSVersionBindReqTCP:
1000 | version
1001 |_ bind
1002 Scanning ip 104.149.238.82 (ns3.dynu.com (PTR)):
1003 53/tcp open domain? syn-ack ttl 46
1004 | fingerprint-strings:
1005 | DNSVersionBindReqTCP:
1006 | version
1007 |_ bind
1008 Scanning ip 74.121.191.194 (1.2.3.4-reverse.wowrack.com (PTR)):
1009 53/tcp open domain? syn-ack ttl 43
1010 | fingerprint-strings:
1011 | DNSVersionBindReqTCP:
1012 | version
1013 |_ bind
1014 Scanning ip 69.25.120.150 (ns6.dynu.com (PTR)):
1015 53/tcp open domain? syn-ack ttl 45
1016 | fingerprint-strings:
1017 | DNSVersionBindReqTCP:
1018 | version
1019 |_ bind
1020 WebCrawling domain's web servers... up to 50 max links.
1021--Finished--
1022Summary information for domain daddyfree.com.
1023-----------------------------------------
1024
1025 Domain Ips Information:
1026 IP: 45.119.209.45
1027 HostName: ns4.dynu.com Type: NS
1028 HostName: ns4.dynu.com Type: PTR
1029 Country: United States
1030 Is Active: True (echo-reply ttl 48)
1031 Port: 53/tcp open domain? syn-ack ttl 48
1032 Script Info: | fingerprint-strings:
1033 Script Info: | DNSVersionBindReqTCP:
1034 Script Info: | version
1035 Script Info: |_ bind
1036 IP: 104.247.193.125
1037 HostName: ns2.dynu.com Type: NS
1038 HostName: ns2.dynu.com Type: PTR
1039 Country: United States
1040 Is Active: True (echo-reply ttl 45)
1041 Port: 53/tcp open domain? syn-ack ttl 45
1042 Script Info: | fingerprint-strings:
1043 Script Info: | DNSVersionBindReqTCP:
1044 Script Info: | version
1045 Script Info: |_ bind
1046 IP: 207.38.70.2
1047 HostName: ns1.dynu.com Type: NS
1048 HostName: ns1.dynu.com Type: PTR
1049 Country: United States
1050 Is Active: True (host-prohibited ttl 42)
1051 Port: 53/tcp open domain? syn-ack ttl 42
1052 Script Info: | fingerprint-strings:
1053 Script Info: | DNSVersionBindReqTCP:
1054 Script Info: | version
1055 Script Info: |_ bind
1056 IP: 104.149.238.82
1057 HostName: ns3.dynu.com Type: NS
1058 HostName: ns3.dynu.com Type: PTR
1059 Country: United States
1060 Is Active: True (host-prohibited ttl 46)
1061 Port: 53/tcp open domain? syn-ack ttl 46
1062 Script Info: | fingerprint-strings:
1063 Script Info: | DNSVersionBindReqTCP:
1064 Script Info: | version
1065 Script Info: |_ bind
1066 IP: 74.121.191.194
1067 HostName: ns5.dynu.com Type: NS
1068 HostName: 1.2.3.4-reverse.wowrack.com Type: PTR
1069 Country: United States
1070 Is Active: True (host-prohibited ttl 43)
1071 Port: 53/tcp open domain? syn-ack ttl 43
1072 Script Info: | fingerprint-strings:
1073 Script Info: | DNSVersionBindReqTCP:
1074 Script Info: | version
1075 Script Info: |_ bind
1076 IP: 188.127.251.161
1077 HostName: www.daddyfree.com. Type: A
1078 Country: Russian Federation
1079 Is Active: False
1080 IP: 69.25.120.150
1081 HostName: ns6.dynu.com Type: NS
1082 HostName: ns6.dynu.com Type: PTR
1083 Country: United States
1084 Is Active: True (host-prohibited ttl 45)
1085 Port: 53/tcp open domain? syn-ack ttl 45
1086 Script Info: | fingerprint-strings:
1087 Script Info: | DNSVersionBindReqTCP:
1088 Script Info: | version
1089 Script Info: |_ bind
1090
1091--------------End Summary --------------
1092-----------------------------------------
1093################################################################################################################################
1094----- daddyfree.com -----
1095
1096
1097Host's addresses:
1098__________________
1099
1100daddyfree.com. 120 IN A 188.127.251.161
1101
1102
1103Wildcard detection using: jvwzgmtwyiys
1104_______________________________________
1105
1106jvwzgmtwyiys.daddyfree.com. 119 IN A 188.127.251.161
1107
1108
1109!!!!!!!!!!!!!!!!!!!!!!!!!!!!
1110
1111 Wildcards detected, all subdomains will point to the same IP address
1112 Omitting results containing 188.127.251.161.
1113 Maybe you are using OpenDNS servers.
1114
1115!!!!!!!!!!!!!!!!!!!!!!!!!!!!
1116
1117
1118Name Servers:
1119______________
1120
1121ns6.dynu.com. 3600 IN A 69.25.120.150
1122ns4.dynu.com. 3600 IN A 45.119.209.45
1123ns5.dynu.com. 3600 IN A 74.121.191.194
1124ns1.dynu.com. 86398 IN A 207.38.70.2
1125ns3.dynu.com. 3599 IN A 104.149.238.82
1126ns2.dynu.com. 3600 IN A 104.247.193.125
1127
1128
1129Mail (MX) Servers:
1130___________________
1131
1132
1133Brute forcing with /usr/share/dnsenum/dns.txt:
1134_______________________________________________
1135
1136
1137
1138Launching Whois Queries:
1139_________________________
1140
1141 whois ip result: 188.127.251.0 -> 188.127.251.0/24
1142
1143
1144daddyfree.com_____________
1145
1146 188.127.251.0/24
1147################################################################################################################################
1148dnsenum VERSION:1.2.6
1149
1150----- daddyfree.com -----
1151
1152
1153Host's addresses:
1154__________________
1155
1156daddyfree.com. 29 IN A 188.127.251.161
1157
1158
1159Wildcard detection using: jjcjbffsekpp
1160_______________________________________
1161
1162jjcjbffsekpp.daddyfree.com. 120 IN A 188.127.251.161
1163
1164
1165!!!!!!!!!!!!!!!!!!!!!!!!!!!!
1166
1167 Wildcards detected, all subdomains will point to the same IP address
1168 Omitting results containing 188.127.251.161.
1169 Maybe you are using OpenDNS servers.
1170
1171!!!!!!!!!!!!!!!!!!!!!!!!!!!!
1172
1173
1174Name Servers:
1175______________
1176
1177ns5.dynu.com. 2514 IN A 74.121.191.194
1178ns4.dynu.com. 3600 IN A 45.119.209.45
1179ns6.dynu.com. 3600 IN A 69.25.120.150
1180ns1.dynu.com. 84908 IN A 207.38.70.2
1181ns3.dynu.com. 2107 IN A 104.149.238.82
1182ns2.dynu.com. 2107 IN A 104.247.193.125
1183
1184
1185Mail (MX) Servers:
1186___________________
1187
1188
1189
1190Trying Zone Transfers and getting Bind Versions:
1191_________________________________________________
1192
1193
1194Trying Zone Transfer for daddyfree.com on ns5.dynu.com ...
1195
1196Trying Zone Transfer for daddyfree.com on ns4.dynu.com ...
1197
1198Trying Zone Transfer for daddyfree.com on ns6.dynu.com ...
1199
1200Trying Zone Transfer for daddyfree.com on ns1.dynu.com ...
1201
1202Trying Zone Transfer for daddyfree.com on ns3.dynu.com ...
1203
1204Trying Zone Transfer for daddyfree.com on ns2.dynu.com ...
1205
1206
1207Brute forcing with /usr/share/sniper/wordlists/vhosts.txt:
1208___________________________________________________________
1209
1210
1211
1212daddyfree.com class C netranges:
1213_________________________________
1214
1215 188.127.251.0/24
1216
1217
1218daddyfree.com ip blocks:
1219_________________________
1220
1221 188.127.251.161/32
1222
1223done.
1224################################################################################################################################
1225Virustotal: www.daddyfree.com
1226Virustotal: bbs.daddyfree.com
1227Virustotal: email.daddyfree.com
1228[-] Saving results to file: /usr/share/sniper/loot/workspace/daddyfree.com/domains/domains-daddyfree.com.txt
1229[-] Total Unique Subdomains Found: 9
1230www.daddyfree.com
1231bbs.daddyfree.com
1232cpanel.daddyfree.com
1233cpcalendars.daddyfree.com
1234cpcontacts.daddyfree.com
1235email.daddyfree.com
1236mail.daddyfree.com
1237webdisk.daddyfree.com
1238webmail.daddyfree.com
1239################################################################################################################################
1240cpanel.daddyfree.com 188.127.251.161
1241webmail.daddyfree.com 188.127.251.161
1242cpcontacts.daddyfree.com 188.127.251.161
1243webdisk.daddyfree.com 188.127.251.161
1244mail.daddyfree.com 188.127.251.161
1245################################################################################################################################
1246[*] Processing domain daddyfree.com
1247[*] Using system resolvers ['10.101.0.243', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a', '2001:18c0:ffe0:2::2', '2001:18c0:ffe0:3::2', '2001:18c0:ffe0:1::2']
1248[+] Getting nameservers
1249104.247.193.125 - ns2.dynu.com
125069.25.120.150 - ns6.dynu.com
125174.121.191.194 - ns5.dynu.com
125245.119.209.45 - ns4.dynu.com
1253104.149.238.82 - ns3.dynu.com
1254207.38.70.2 - ns1.dynu.com
1255[-] Zone transfer failed
1256
1257[+] Wildcard domain found - 188.127.251.161
1258[*] Scanning daddyfree.com for A records
1259
1260###############################################################################################################################
1261
1262cpanel.daddyfree.com
1263cpcalendars.daddyfree.com
1264cpcontacts.daddyfree.com
1265daddyfree.com
1266mail.daddyfree.com
1267webdisk.daddyfree.com
1268webmail.daddyfree.com
1269www.daddyfree.com
1270################################################################################################################################
1271min.daddyfree.com
1272www.daddyfree.com
1273bbs.daddyfree.com
1274cpanel.daddyfree.com
1275cpcalendars.daddyfree.com
1276cpcontacts.daddyfree.com
1277email.daddyfree.com
1278mail.daddyfree.com
1279webdisk.daddyfree.com
1280webmail.daddyfree.com
1281daddyfree.com
1282domain
1283################################################################################################################################
1284[+] daddyfree.com has no SPF record!
1285[*] No DMARC record found. Looking for organizational record
1286[+] No organizational DMARC record
1287[+] Spoofing possible for daddyfree.com!
1288################################################################################################################################
1289Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:25 EDT
1290Nmap scan report for daddyfree.com (188.127.251.161)
1291Host is up.
1292rDNS record for 188.127.251.161: byronbayoasisresort.com.au
1293
1294PORT STATE SERVICE
129553/udp open|filtered domain
129667/udp open|filtered dhcps
129768/udp open|filtered dhcpc
129869/udp open|filtered tftp
129988/udp open|filtered kerberos-sec
1300123/udp open|filtered ntp
1301137/udp open|filtered netbios-ns
1302138/udp open|filtered netbios-dgm
1303139/udp open|filtered netbios-ssn
1304161/udp open|filtered snmp
1305162/udp open|filtered snmptrap
1306389/udp open|filtered ldap
1307500/udp open|filtered isakmp
1308520/udp open|filtered route
13092049/udp open|filtered nfs
1310
1311Nmap done: 1 IP address (1 host up) scanned in 5.63 seconds
1312################################################################################################################################
1313Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:11 EDT
1314Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1315Host is up (0.16s latency).
1316Not shown: 441 filtered ports, 23 closed ports
1317Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
1318PORT STATE SERVICE VERSION
131922/tcp open ssh OpenSSH 7.4 (protocol 2.0)
1320| ssh-hostkey:
1321| 2048 8f:c6:dc:66:5f:e7:2c:e0:18:ce:d5:c0:43:73:1f:5b (RSA)
1322| 256 63:c5:8b:2d:2f:84:0d:f4:52:08:32:a8:42:89:cc:42 (ECDSA)
1323|_ 256 47:14:c6:2f:9c:75:ac:93:ae:30:e0:db:51:1e:75:e5 (ED25519)
132425/tcp open smtp?
1325|_smtp-commands: Couldn't establish connection on port 25
132653/tcp open domain PowerDNS Authoritative Server 4.1.10
1327| dns-nsid:
1328| NSID: xbabes.com (7862616265732e636f6d)
1329| id.server: xbabes.com
1330|_ bind.version: PowerDNS Authoritative Server 4.1.10 (built Mar 11 2020 14:41:48 by root@rpmbuild-64-centos-7.dev.cpanel.net)
133180/tcp open http Apache httpd
1332|_http-server-header: Apache
1333|_http-title: Site doesn't have a title (text/html).
1334110/tcp open pop3 Dovecot pop3d
1335|_pop3-capabilities: AUTH-RESP-CODE STLS UIDL RESP-CODES SASL(PLAIN LOGIN) CAPA USER TOP PIPELINING
1336| ssl-cert: Subject: commonName=xbabes.com
1337| Subject Alternative Name: DNS:xbabes.com
1338| Not valid before: 2020-03-22T21:17:40
1339|_Not valid after: 2021-03-22T21:17:40
1340143/tcp open imap Dovecot imapd
1341|_imap-capabilities: OK more IDLE Pre-login LITERAL+ AUTH=LOGINA0001 listed post-login STARTTLS NAMESPACE ID SASL-IR AUTH=PLAIN IMAP4rev1 LOGIN-REFERRALS capabilities have ENABLE
1342| ssl-cert: Subject: commonName=xbabes.com
1343| Subject Alternative Name: DNS:xbabes.com
1344| Not valid before: 2020-03-22T21:17:40
1345|_Not valid after: 2021-03-22T21:17:40
1346443/tcp open ssl/http Apache httpd
1347|_http-server-header: Apache
1348|_http-title: Daddy Free - DaddyFree
1349|_http-trane-info: Problem with XML parsing of /evox/about
1350| ssl-cert: Subject: commonName=daddyfree.com
1351| Subject Alternative Name: DNS:daddyfree.com, DNS:cpanel.daddyfree.com, DNS:cpcalendars.daddyfree.com, DNS:cpcontacts.daddyfree.com, DNS:mail.daddyfree.com, DNS:webdisk.daddyfree.com, DNS:webmail.daddyfree.com, DNS:www.daddyfree.com
1352| Not valid before: 2020-03-20T00:00:00
1353|_Not valid after: 2020-06-18T23:59:59
1354465/tcp open ssl/smtp Exim smtpd 4.93
1355| smtp-commands: xbabes.com Hello byronbayoasisresort.com.au [45.132.192.71], SIZE 52428800, 8BITMIME, PIPELINING, AUTH PLAIN LOGIN, HELP,
1356|_ Commands supported: AUTH HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
1357| ssl-cert: Subject: commonName=xbabes.com
1358| Subject Alternative Name: DNS:xbabes.com
1359| Not valid before: 2020-03-22T21:17:40
1360|_Not valid after: 2021-03-22T21:17:40
1361587/tcp open smtp Exim smtpd 4.93
1362| smtp-commands: xbabes.com Hello byronbayoasisresort.com.au [45.132.192.71], SIZE 52428800, 8BITMIME, PIPELINING, STARTTLS, HELP,
1363|_ Commands supported: AUTH STARTTLS HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
1364| ssl-cert: Subject: commonName=xbabes.com
1365| Subject Alternative Name: DNS:xbabes.com
1366| Not valid before: 2020-03-22T21:17:40
1367|_Not valid after: 2021-03-22T21:17:40
1368993/tcp open imaps?
1369|_imap-capabilities: OK more IDLE Pre-login LITERAL+ AUTH=LOGINA0001 listed post-login NAMESPACE LOGIN-REFERRALS ID AUTH=PLAIN IMAP4rev1 SASL-IR capabilities have ENABLE
1370| ssl-cert: Subject: commonName=xbabes.com
1371| Subject Alternative Name: DNS:xbabes.com
1372| Not valid before: 2020-03-22T21:17:40
1373|_Not valid after: 2021-03-22T21:17:40
1374995/tcp open pop3s?
1375|_pop3-capabilities: SASL(PLAIN LOGIN) CAPA AUTH-RESP-CODE USER PIPELINING UIDL TOP RESP-CODES
1376| ssl-cert: Subject: commonName=xbabes.com
1377| Subject Alternative Name: DNS:xbabes.com
1378| Not valid before: 2020-03-22T21:17:40
1379|_Not valid after: 2021-03-22T21:17:40
13803306/tcp open mysql MySQL (unauthorized)
1381Aggressive OS guesses: Linux 3.10 - 4.11 (94%), HP P2000 G3 NAS device (90%), Linux 3.2 - 4.9 (90%), Linux 3.13 or 4.2 (89%), Linux 3.16 - 4.6 (89%), Linux 4.1 (89%), Linux 4.10 (89%), Linux 4.2 (89%), Linux 4.4 (89%), Asus RT-AC66U WAP (89%)
1382No exact OS matches for host (test conditions non-ideal).
1383Network Distance: 11 hops
1384Service Info: Host: xbabes.com
1385
1386TRACEROUTE (using port 587/tcp)
1387HOP RTT ADDRESS
13881 133.61 ms 10.203.21.1
13892 ...
13903 134.18 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
13914 133.99 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
13925 139.60 ms be3740.ccr21.sto03.atlas.cogentco.com (154.54.60.190)
13936 140.39 ms be3376.ccr21.sto01.atlas.cogentco.com (130.117.50.226)
13947 140.42 ms rascom.demarc.cogentco.com (149.6.168.138)
13958 ...
13969 157.83 ms dhub.inet2.ru (85.112.122.67)
139710 153.31 ms 185.130.248.18
139811 156.69 ms byronbayoasisresort.com.au (188.127.251.161)
1399################################################################################################################################
1400Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:15 EDT
1401Warning: 188.127.251.161 giving up on port because retransmission cap hit (2).
1402Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1403Host is up (0.16s latency).
1404Not shown: 16 filtered ports
1405Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
1406PORT STATE SERVICE VERSION
140753/tcp open domain PowerDNS Authoritative Server 4.1.10
140853/udp open domain PowerDNS Authoritative Server 4.1.10
1409| dns-nsid:
1410| NSID: xbabes.com (7862616265732e636f6d)
1411| id.server: xbabes.com
1412|_ bind.version: PowerDNS Authoritative Server 4.1.10 (built Mar 11 2020 14:41:48 by root@rpmbuild-64-centos-7.dev.cpanel.net)
141368/udp open|filtered dhcpc
141469/udp open|filtered tftp
141588/udp open|filtered kerberos-sec
1416123/udp open|filtered ntp
1417138/udp open|filtered netbios-dgm
1418139/udp open|filtered netbios-ssn
1419161/udp open|filtered snmp
1420162/udp open|filtered snmptrap
1421389/udp open|filtered ldap
1422520/udp open|filtered route
1423Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
1424Aggressive OS guesses: Linux 3.10 - 4.11 (92%), Linux 3.2 - 4.9 (92%), Crestron XPanel control system (90%), Linux 3.18 (89%), Linux 3.16 (89%), ASUS RT-N56U WAP (Linux 3.4) (87%), Linux 3.1 (87%), Linux 3.2 (87%), HP P2000 G3 NAS device (87%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (87%)
1425No exact OS matches for host (test conditions non-ideal).
1426Network Distance: 11 hops
1427
1428TRACEROUTE (using port 53/tcp)
1429HOP RTT ADDRESS
14301 135.00 ms 10.203.21.1
14312 ...
14323 132.10 ms 149.6.188.49
14334 132.07 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
14345 138.06 ms be3740.ccr21.sto03.atlas.cogentco.com (154.54.60.190)
14356 138.13 ms be3376.ccr21.sto01.atlas.cogentco.com (130.117.50.226)
14367 138.12 ms rascom.demarc.cogentco.com (149.6.168.138)
14378 ...
14389 156.33 ms dhub.inet2.ru (85.112.122.67)
143910 156.34 ms 185.130.248.18
144011 154.83 ms byronbayoasisresort.com.au (188.127.251.161)
1441################################################################################################################################
1442# general
1443(gen) banner: SSH-2.0-OpenSSH_7.4
1444(gen) software: OpenSSH 7.4
1445(gen) compatibility: OpenSSH 7.3+ (some functionality from 6.6), Dropbear SSH 2016.73+ (some functionality from 0.52)
1446(gen) compression: enabled (zlib@openssh.com)
1447
1448# key exchange algorithms
1449(kex) curve25519-sha256 -- [warn] unknown algorithm
1450(kex) curve25519-sha256@libssh.org -- [info] available since OpenSSH 6.5, Dropbear SSH 2013.62
1451(kex) ecdh-sha2-nistp256 -- [fail] using weak elliptic curves
1452 `- [info] available since OpenSSH 5.7, Dropbear SSH 2013.62
1453(kex) ecdh-sha2-nistp384 -- [fail] using weak elliptic curves
1454 `- [info] available since OpenSSH 5.7, Dropbear SSH 2013.62
1455(kex) ecdh-sha2-nistp521 -- [fail] using weak elliptic curves
1456 `- [info] available since OpenSSH 5.7, Dropbear SSH 2013.62
1457(kex) diffie-hellman-group-exchange-sha256 -- [warn] using custom size modulus (possibly weak)
1458 `- [info] available since OpenSSH 4.4
1459(kex) diffie-hellman-group16-sha512 -- [info] available since OpenSSH 7.3, Dropbear SSH 2016.73
1460(kex) diffie-hellman-group18-sha512 -- [info] available since OpenSSH 7.3
1461(kex) diffie-hellman-group-exchange-sha1 -- [fail] removed (in server) since OpenSSH 6.7, unsafe algorithm
1462 `- [warn] using weak hashing algorithm
1463 `- [info] available since OpenSSH 2.3.0
1464(kex) diffie-hellman-group14-sha256 -- [info] available since OpenSSH 7.3, Dropbear SSH 2016.73
1465(kex) diffie-hellman-group14-sha1 -- [warn] using weak hashing algorithm
1466 `- [info] available since OpenSSH 3.9, Dropbear SSH 0.53
1467(kex) diffie-hellman-group1-sha1 -- [fail] removed (in server) since OpenSSH 6.7, unsafe algorithm
1468 `- [fail] disabled (in client) since OpenSSH 7.0, logjam attack
1469 `- [warn] using small 1024-bit modulus
1470 `- [warn] using weak hashing algorithm
1471 `- [info] available since OpenSSH 2.3.0, Dropbear SSH 0.28
1472
1473# host-key algorithms
1474(key) ssh-rsa -- [info] available since OpenSSH 2.5.0, Dropbear SSH 0.28
1475(key) rsa-sha2-512 -- [info] available since OpenSSH 7.2
1476(key) rsa-sha2-256 -- [info] available since OpenSSH 7.2
1477(key) ecdsa-sha2-nistp256 -- [fail] using weak elliptic curves
1478 `- [warn] using weak random number generator could reveal the key
1479 `- [info] available since OpenSSH 5.7, Dropbear SSH 2013.62
1480(key) ssh-ed25519 -- [info] available since OpenSSH 6.5
1481
1482# encryption algorithms (ciphers)
1483(enc) chacha20-poly1305@openssh.com -- [info] available since OpenSSH 6.5
1484 `- [info] default cipher since OpenSSH 6.9.
1485(enc) aes128-ctr -- [info] available since OpenSSH 3.7, Dropbear SSH 0.52
1486(enc) aes192-ctr -- [info] available since OpenSSH 3.7
1487(enc) aes256-ctr -- [info] available since OpenSSH 3.7, Dropbear SSH 0.52
1488(enc) aes128-gcm@openssh.com -- [info] available since OpenSSH 6.2
1489(enc) aes256-gcm@openssh.com -- [info] available since OpenSSH 6.2
1490(enc) aes128-cbc -- [fail] removed (in server) since OpenSSH 6.7, unsafe algorithm
1491 `- [warn] using weak cipher mode
1492 `- [info] available since OpenSSH 2.3.0, Dropbear SSH 0.28
1493(enc) aes192-cbc -- [fail] removed (in server) since OpenSSH 6.7, unsafe algorithm
1494 `- [warn] using weak cipher mode
1495 `- [info] available since OpenSSH 2.3.0
1496(enc) aes256-cbc -- [fail] removed (in server) since OpenSSH 6.7, unsafe algorithm
1497 `- [warn] using weak cipher mode
1498 `- [info] available since OpenSSH 2.3.0, Dropbear SSH 0.47
1499(enc) blowfish-cbc -- [fail] removed (in server) since OpenSSH 6.7, unsafe algorithm
1500 `- [fail] disabled since Dropbear SSH 0.53
1501 `- [warn] disabled (in client) since OpenSSH 7.2, legacy algorithm
1502 `- [warn] using weak cipher mode
1503 `- [warn] using small 64-bit block size
1504 `- [info] available since OpenSSH 1.2.2, Dropbear SSH 0.28
1505(enc) cast128-cbc -- [fail] removed (in server) since OpenSSH 6.7, unsafe algorithm
1506 `- [warn] disabled (in client) since OpenSSH 7.2, legacy algorithm
1507 `- [warn] using weak cipher mode
1508 `- [warn] using small 64-bit block size
1509 `- [info] available since OpenSSH 2.1.0
1510(enc) 3des-cbc -- [fail] removed (in server) since OpenSSH 6.7, unsafe algorithm
1511 `- [warn] using weak cipher
1512 `- [warn] using weak cipher mode
1513 `- [warn] using small 64-bit block size
1514 `- [info] available since OpenSSH 1.2.2, Dropbear SSH 0.28
1515
1516# message authentication code algorithms
1517(mac) umac-64-etm@openssh.com -- [warn] using small 64-bit tag size
1518 `- [info] available since OpenSSH 6.2
1519(mac) umac-128-etm@openssh.com -- [info] available since OpenSSH 6.2
1520(mac) hmac-sha2-256-etm@openssh.com -- [info] available since OpenSSH 6.2
1521(mac) hmac-sha2-512-etm@openssh.com -- [info] available since OpenSSH 6.2
1522(mac) hmac-sha1-etm@openssh.com -- [warn] using weak hashing algorithm
1523 `- [info] available since OpenSSH 6.2
1524(mac) umac-64@openssh.com -- [warn] using encrypt-and-MAC mode
1525 `- [warn] using small 64-bit tag size
1526 `- [info] available since OpenSSH 4.7
1527(mac) umac-128@openssh.com -- [warn] using encrypt-and-MAC mode
1528 `- [info] available since OpenSSH 6.2
1529(mac) hmac-sha2-256 -- [warn] using encrypt-and-MAC mode
1530 `- [info] available since OpenSSH 5.9, Dropbear SSH 2013.56
1531(mac) hmac-sha2-512 -- [warn] using encrypt-and-MAC mode
1532 `- [info] available since OpenSSH 5.9, Dropbear SSH 2013.56
1533(mac) hmac-sha1 -- [warn] using encrypt-and-MAC mode
1534 `- [warn] using weak hashing algorithm
1535 `- [info] available since OpenSSH 2.1.0, Dropbear SSH 0.28
1536
1537# algorithm recommendations (for OpenSSH 7.4)
1538(rec) -diffie-hellman-group14-sha1 -- kex algorithm to remove
1539(rec) -ecdh-sha2-nistp256 -- kex algorithm to remove
1540(rec) -diffie-hellman-group-exchange-sha256 -- kex algorithm to remove
1541(rec) -diffie-hellman-group1-sha1 -- kex algorithm to remove
1542(rec) -diffie-hellman-group-exchange-sha1 -- kex algorithm to remove
1543(rec) -ecdh-sha2-nistp521 -- kex algorithm to remove
1544(rec) -ecdh-sha2-nistp384 -- kex algorithm to remove
1545(rec) -ecdsa-sha2-nistp256 -- key algorithm to remove
1546(rec) -blowfish-cbc -- enc algorithm to remove
1547(rec) -3des-cbc -- enc algorithm to remove
1548(rec) -aes256-cbc -- enc algorithm to remove
1549(rec) -cast128-cbc -- enc algorithm to remove
1550(rec) -aes192-cbc -- enc algorithm to remove
1551(rec) -aes128-cbc -- enc algorithm to remove
1552(rec) -hmac-sha2-512 -- mac algorithm to remove
1553(rec) -umac-128@openssh.com -- mac algorithm to remove
1554(rec) -hmac-sha2-256 -- mac algorithm to remove
1555(rec) -umac-64@openssh.com -- mac algorithm to remove
1556(rec) -hmac-sha1 -- mac algorithm to remove
1557(rec) -hmac-sha1-etm@openssh.com -- mac algorithm to remove
1558(rec) -umac-64-etm@openssh.com -- mac algorithm to remove
1559################################################################################################################################
1560Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:16 EDT
1561NSE: [ssh-run] Failed to specify credentials and command to run.
1562NSE: [ssh-brute] Trying username/password pair: root:root
1563NSE: [ssh-brute] Trying username/password pair: admin:admin
1564NSE: [ssh-brute] Trying username/password pair: administrator:administrator
1565NSE: [ssh-brute] Trying username/password pair: webadmin:webadmin
1566NSE: [ssh-brute] Trying username/password pair: sysadmin:sysadmin
1567NSE: [ssh-brute] Trying username/password pair: netadmin:netadmin
1568NSE: [ssh-brute] Trying username/password pair: guest:guest
1569NSE: [ssh-brute] Trying username/password pair: user:user
1570NSE: [ssh-brute] Trying username/password pair: web:web
1571NSE: [ssh-brute] Trying username/password pair: test:test
1572NSE: [ssh-brute] Trying username/password pair: root:
1573NSE: [ssh-brute] Trying username/password pair: admin:
1574NSE: [ssh-brute] Trying username/password pair: administrator:
1575NSE: [ssh-brute] Trying username/password pair: webadmin:
1576NSE: [ssh-brute] Trying username/password pair: sysadmin:
1577NSE: [ssh-brute] Trying username/password pair: netadmin:
1578NSE: [ssh-brute] Trying username/password pair: guest:
1579NSE: [ssh-brute] Trying username/password pair: user:
1580NSE: [ssh-brute] Trying username/password pair: web:
1581NSE: [ssh-brute] Trying username/password pair: test:
1582NSE: [ssh-brute] Trying username/password pair: root:123456
1583NSE: [ssh-brute] Trying username/password pair: admin:123456
1584NSE: [ssh-brute] Trying username/password pair: administrator:123456
1585NSE: [ssh-brute] Trying username/password pair: webadmin:123456
1586NSE: [ssh-brute] Trying username/password pair: sysadmin:123456
1587NSE: [ssh-brute] Trying username/password pair: netadmin:123456
1588NSE: [ssh-brute] Trying username/password pair: guest:123456
1589NSE: [ssh-brute] Trying username/password pair: user:123456
1590NSE: [ssh-brute] Trying username/password pair: web:123456
1591NSE: [ssh-brute] Trying username/password pair: test:123456
1592NSE: [ssh-brute] Trying username/password pair: root:12345
1593NSE: [ssh-brute] Trying username/password pair: admin:12345
1594NSE: [ssh-brute] Trying username/password pair: administrator:12345
1595NSE: [ssh-brute] Trying username/password pair: webadmin:12345
1596NSE: [ssh-brute] Trying username/password pair: sysadmin:12345
1597NSE: [ssh-brute] Trying username/password pair: netadmin:12345
1598NSE: [ssh-brute] Trying username/password pair: guest:12345
1599NSE: [ssh-brute] Trying username/password pair: user:12345
1600NSE: [ssh-brute] Trying username/password pair: web:12345
1601NSE: [ssh-brute] Trying username/password pair: test:12345
1602NSE: [ssh-brute] Trying username/password pair: root:123456789
1603NSE: [ssh-brute] Trying username/password pair: admin:123456789
1604NSE: [ssh-brute] Trying username/password pair: administrator:123456789
1605NSE: [ssh-brute] Trying username/password pair: webadmin:123456789
1606NSE: [ssh-brute] Trying username/password pair: sysadmin:123456789
1607NSE: [ssh-brute] Trying username/password pair: netadmin:123456789
1608NSE: [ssh-brute] Trying username/password pair: guest:123456789
1609NSE: [ssh-brute] Trying username/password pair: user:123456789
1610NSE: [ssh-brute] Trying username/password pair: web:123456789
1611NSE: [ssh-brute] Trying username/password pair: test:123456789
1612Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1613Host is up (0.15s latency).
1614
1615PORT STATE SERVICE VERSION
161622/tcp open ssh OpenSSH 7.4 (protocol 2.0)
1617| ssh-auth-methods:
1618| Supported authentication methods:
1619| publickey
1620| gssapi-keyex
1621| gssapi-with-mic
1622|_ password
1623| ssh-hostkey:
1624| 2048 8f:c6:dc:66:5f:e7:2c:e0:18:ce:d5:c0:43:73:1f:5b (RSA)
1625| 256 63:c5:8b:2d:2f:84:0d:f4:52:08:32:a8:42:89:cc:42 (ECDSA)
1626|_ 256 47:14:c6:2f:9c:75:ac:93:ae:30:e0:db:51:1e:75:e5 (ED25519)
1627| ssh-publickey-acceptance:
1628|_ Accepted Public Keys: No public keys accepted
1629|_ssh-run: Failed to specify credentials and command to run.
1630Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
1631Aggressive OS guesses: Linux 3.10 - 4.11 (92%), Linux 3.2 - 4.9 (92%), Linux 3.18 (90%), Crestron XPanel control system (90%), Linux 3.16 (89%), ASUS RT-N56U WAP (Linux 3.4) (87%), Linux 3.1 (87%), Linux 3.2 (87%), HP P2000 G3 NAS device (87%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (87%)
1632No exact OS matches for host (test conditions non-ideal).
1633Network Distance: 11 hops
1634
1635TRACEROUTE (using port 22/tcp)
1636HOP RTT ADDRESS
16371 136.47 ms 10.203.21.1
16382 ...
16393 137.34 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
16404 136.98 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
16415 142.55 ms be3740.ccr21.sto03.atlas.cogentco.com (154.54.60.190)
16426 143.19 ms be3376.ccr21.sto01.atlas.cogentco.com (130.117.50.226)
16437 136.73 ms rascom.demarc.cogentco.com (149.6.168.138)
16448 ...
16459 155.97 ms dhub.inet2.ru (85.112.122.67)
164610 154.55 ms 185.130.248.18
164711 154.80 ms byronbayoasisresort.com.au (188.127.251.161)
1648################################################################################################################################
1649USER_FILE => /usr/share/brutex/wordlists/simple-users.txt
1650RHOSTS => 188.127.251.161
1651RHOST => 188.127.251.161
1652[*] 188.127.251.161:22 - SSH - Using malformed packet technique
1653[*] 188.127.251.161:22 - SSH - Starting scan
1654[-] 188.127.251.161:22 - SSH - User 'admin' on could not connect
1655[-] 188.127.251.161:22 - SSH - User 'administrator' on could not connect
1656[-] 188.127.251.161:22 - SSH - User 'anonymous' on could not connect
1657[-] 188.127.251.161:22 - SSH - User 'backup' on could not connect
1658[-] 188.127.251.161:22 - SSH - User 'bee' on could not connect
1659[-] 188.127.251.161:22 - SSH - User 'ftp' on could not connect
1660[-] 188.127.251.161:22 - SSH - User 'guest' on could not connect
1661[-] 188.127.251.161:22 - SSH - User 'GUEST' on could not connect
1662[-] 188.127.251.161:22 - SSH - User 'info' on could not connect
1663[-] 188.127.251.161:22 - SSH - User 'mail' on could not connect
1664[-] 188.127.251.161:22 - SSH - User 'mailadmin' on could not connect
1665[-] 188.127.251.161:22 - SSH - User 'msfadmin' on could not connect
1666[-] 188.127.251.161:22 - SSH - User 'mysql' on could not connect
1667[-] 188.127.251.161:22 - SSH - User 'nobody' on could not connect
1668[-] 188.127.251.161:22 - SSH - User 'oracle' on could not connect
1669[-] 188.127.251.161:22 - SSH - User 'owaspbwa' on could not connect
1670[-] 188.127.251.161:22 - SSH - User 'postfix' on could not connect
1671[-] 188.127.251.161:22 - SSH - User 'postgres' on could not connect
1672[-] 188.127.251.161:22 - SSH - User 'private' on could not connect
1673[-] 188.127.251.161:22 - SSH - User 'proftpd' on could not connect
1674[-] 188.127.251.161:22 - SSH - User 'public' on could not connect
1675[-] 188.127.251.161:22 - SSH - User 'root' on could not connect
1676[-] 188.127.251.161:22 - SSH - User 'superadmin' on could not connect
1677[-] 188.127.251.161:22 - SSH - User 'support' on could not connect
1678[-] 188.127.251.161:22 - SSH - User 'sys' on could not connect
1679[-] 188.127.251.161:22 - SSH - User 'system' on could not connect
1680[-] 188.127.251.161:22 - SSH - User 'systemadmin' on could not connect
1681[-] 188.127.251.161:22 - SSH - User 'systemadministrator' on could not connect
1682[-] 188.127.251.161:22 - SSH - User 'test' on could not connect
1683[-] 188.127.251.161:22 - SSH - User 'tomcat' on could not connect
1684[-] 188.127.251.161:22 - SSH - User 'user' on could not connect
1685[-] 188.127.251.161:22 - SSH - User 'webmaster' on could not connect
1686[-] 188.127.251.161:22 - SSH - User 'www-data' on could not connect
1687[-] 188.127.251.161:22 - SSH - User 'Fortimanager_Access' on could not connect
1688[*] Scanned 1 of 1 hosts (100% complete)
1689[*] Auxiliary module execution completed
1690################################################################################################################################
1691Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:47 EDT
1692Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1693Host is up.
1694
1695PORT STATE SERVICE VERSION
169625/tcp filtered smtp
1697Too many fingerprints match this host to give specific OS details
1698
1699TRACEROUTE (using proto 1/icmp)
1700HOP RTT ADDRESS
17011 133.17 ms 10.203.21.1
17022 ...
17033 134.06 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
17044 134.02 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
17055 139.79 ms be3741.ccr22.sto03.atlas.cogentco.com (154.54.60.194)
17066 139.86 ms be3377.ccr21.sto01.atlas.cogentco.com (154.54.36.90)
17077 141.86 ms rascom.demarc.cogentco.com (149.6.168.138)
17088 ...
17099 154.29 ms dhub.inet2.ru (85.112.122.67)
171010 154.31 ms 185.130.248.18
171111 ... 30
1712################################################################################################################################
1713Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:47 EDT
1714Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1715Host is up.
1716
1717PORT STATE SERVICE VERSION
171853/tcp filtered domain
1719Too many fingerprints match this host to give specific OS details
1720
1721Host script results:
1722| dns-blacklist:
1723| SPAM
1724| spam.dnsbl.sorbs.net - SPAM
1725| dnsbl.inps.de - SPAM
1726|_ Spam Received See: http://www.sorbs.net/lookup.shtml?188.127.251.161
1727| dns-brute:
1728| DNS Brute-force hostnames:
1729| stats.com.au - 69.172.201.153
1730| mx.com.au - 91.195.240.126
1731| devel.com.au - 103.20.200.201
1732| admin.com.au - 43.250.140.20
1733| devel.com.au - 2405:3f00:a222:bbbb:bba1:22:ffff:ffff
1734| id.com.au - 52.255.48.85
1735| development.com.au - 192.132.253.223
1736| svn.com.au - 203.30.44.22
1737| administration.com.au - 3.1.172.131
1738| images.com.au - 104.24.116.27
1739| images.com.au - 104.24.117.27
1740| images.com.au - 2606:4700:3030::6818:751b
1741| images.com.au - 2606:4700:3031::6818:741b
1742| ads.com.au - 192.185.21.193
1743| info.com.au - 3.223.194.171
1744| devtest.com.au - 91.195.240.103
1745| mx1.com.au - 203.206.228.243
1746| internal.com.au - 69.172.201.153
1747| test.com.au - 173.254.16.166
1748| mysql.com.au - 27.50.92.50
1749| internet.com.au - 52.65.127.33
1750| direct.com.au - 13.237.69.52
1751| intra.com.au - 54.66.238.177
1752| news.com.au - 104.123.192.150
1753| noc.com.au - 69.172.201.153
1754| intranet.com.au - 202.124.241.203
1755| intranet.com.au - 2403:1400:2:1::107
1756| ns.com.au - 185.53.177.31
1757| ipv6.com.au - 199.59.242.153
1758| lab.com.au - 202.124.241.178
1759| dns.com.au - 203.170.84.122
1760| dns.com.au - 2404:8280:a222:bbbb:bba1:94:ffff:ffff
1761| ns1.com.au - 112.140.176.10
1762| ns1.com.au - 2400:b800::1:0:0:0:6
1763| adserver.com.au - 208.91.197.94
1764| ns2.com.au - 112.140.180.10
1765| ns2.com.au - 2400:b800:1:1::3
1766| dns1.com.au - 122.201.80.136
1767| linux.com.au - 192.55.98.180
1768| local.com.au - 54.153.243.82
1769| local.com.au - 54.206.27.100
1770| dns2.com.au - 122.201.80.136
1771| log.com.au - 69.172.201.153
1772| mail.com.au - 91.195.240.126
1773| download.com.au - 124.150.18.91
1774| alerts.com.au - 54.79.53.166
1775| en.com.au - 162.241.244.100
1776| alpha.com.au - 101.0.114.116
1777| ap.com.au - 69.172.201.153
1778| eshop.com.au - 91.195.240.126
1779| main.com.au - 208.113.196.100
1780| exchange.com.au - 50.87.145.203
1781| apache.com.au - 110.232.141.125
1782| f5.com.au - 35.208.240.66
1783| mgmt.com.au - 101.0.115.166
1784| fileserver.com.au - 184.168.221.63
1785| firewall.com.au - 72.249.49.85
1786| app.com.au - 203.149.77.68
1787| app.com.au - 43.239.97.21
1788| forum.com.au - 198.185.159.144
1789| forum.com.au - 198.185.159.145
1790| forum.com.au - 198.49.23.144
1791| forum.com.au - 198.49.23.145
1792| apps.com.au - 166.62.30.147
1793| mobile.com.au - 103.18.109.184
1794| ftp.com.au - 185.53.177.31
1795| auth.com.au - 103.224.212.243
1796| mobile.com.au - 2407:e700:2:13::105
1797| git.com.au - 203.55.18.48
1798| backup.com.au - 139.99.139.228
1799| beta.com.au - 101.0.102.133
1800| gw.com.au - 203.27.127.154
1801| mta.com.au - 203.41.91.102
1802| cdn.com.au - 202.139.235.196
1803| chat.com.au - 124.150.18.91
1804| citrix.com.au - 50.17.245.212
1805| cms.com.au - 119.9.8.91
1806| corp.com.au - 203.31.199.241
1807| crs.com.au - 103.27.32.36
1808| cvs.com.au - 184.168.131.241
1809| database.com.au - 203.17.73.173
1810| db.com.au - 103.224.182.246
1811| ntp.com.au - 175.107.174.102
1812| ops.com.au - 50.87.144.150
1813| owa.com.au - 103.42.108.46
1814| pbx.com.au - 74.208.131.211
1815| s3.com.au - 104.31.76.214
1816| s3.com.au - 104.31.77.214
1817| s3.com.au - 2606:4700:3030::681f:4cd6
1818| s3.com.au - 2606:4700:3033::681f:4dd6
1819| secure.com.au - 203.32.66.34
1820| sip.com.au - 203.28.142.42
1821| smtp.com.au - 103.224.182.251
1822| sql.com.au - 162.242.150.89
1823| sql.com.au - 176.34.241.253
1824| sql.com.au - 23.253.58.227
1825| squid.com.au - 69.172.201.153
1826| ssh.com.au - 122.201.127.228
1827| ssl.com.au - 165.160.13.20
1828| ssl.com.au - 165.160.15.20
1829| home.com.au - 18.205.97.157
1830| home.com.au - 52.0.199.132
1831| upload.com.au - 198.185.159.144
1832| upload.com.au - 198.185.159.145
1833| upload.com.au - 198.49.23.144
1834| upload.com.au - 198.49.23.145
1835| vnc.com.au - 210.50.6.238
1836| voip.com.au - 35.189.14.57
1837| vpn.com.au - 116.202.209.138
1838| web.com.au - 13.238.152.224
1839| whois.com.au - 122.201.118.68
1840| wiki.com.au - 151.101.0.194
1841| wiki.com.au - 151.101.128.194
1842| wiki.com.au - 151.101.192.194
1843| wiki.com.au - 151.101.64.194
1844| wiki.com.au - 2a04:4e42:200::194
1845| wiki.com.au - 2a04:4e42:400::194
1846| wiki.com.au - 2a04:4e42:600::194
1847| wiki.com.au - 2a04:4e42::194
1848| www.com.au - 58.108.130.49
1849| www2.com.au - 166.62.26.1
1850| xml.com.au - 91.195.240.126
1851|_ dev.com.au - 208.91.197.94
1852
1853TRACEROUTE (using proto 1/icmp)
1854HOP RTT ADDRESS
18551 133.98 ms 10.203.21.1
18562 ...
18573 135.15 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
18584 130.80 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
18595 136.22 ms be3741.ccr22.sto03.atlas.cogentco.com (154.54.60.194)
18606 136.66 ms be3377.ccr21.sto01.atlas.cogentco.com (154.54.36.90)
18617 136.64 ms rascom.demarc.cogentco.com (149.6.168.138)
18628 ...
18639 155.25 ms dhub.inet2.ru (85.112.122.67)
186410 155.07 ms 185.130.248.18
186511 ... 30
1866################################################################################################################################
1867Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:49 EDT
1868Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1869Host is up.
1870
1871PORT STATE SERVICE VERSION
187268/tcp filtered dhcpc
187368/udp open|filtered dhcpc
1874Too many fingerprints match this host to give specific OS details
1875
1876TRACEROUTE (using proto 1/icmp)
1877HOP RTT ADDRESS
18781 132.34 ms 10.203.21.1
18792 ...
18803 133.51 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
18814 132.95 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
18825 138.74 ms be3741.ccr22.sto03.atlas.cogentco.com (154.54.60.194)
18836 138.60 ms be3377.ccr21.sto01.atlas.cogentco.com (154.54.36.90)
18847 138.77 ms rascom.demarc.cogentco.com (149.6.168.138)
18858 ...
18869 158.37 ms dhub.inet2.ru (85.112.122.67)
188710 157.25 ms 185.130.248.18
188811 ... 30
1889################################################################################################################################
1890Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:51 EDT
1891Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1892Host is up.
1893
1894PORT STATE SERVICE VERSION
189569/tcp filtered tftp
189669/udp open|filtered tftp
1897Too many fingerprints match this host to give specific OS details
1898
1899TRACEROUTE (using proto 1/icmp)
1900HOP RTT ADDRESS
19011 133.27 ms 10.203.21.1
19022 ...
19033 134.48 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
19044 130.11 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
19055 135.70 ms be3741.ccr22.sto03.atlas.cogentco.com (154.54.60.194)
19066 136.07 ms be3377.ccr21.sto01.atlas.cogentco.com (154.54.36.90)
19077 135.89 ms rascom.demarc.cogentco.com (149.6.168.138)
19088 ...
19099 154.02 ms dhub.inet2.ru (85.112.122.67)
191010 154.02 ms 185.130.248.18
191111 ... 30
1912################################################################################################################################
1913Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:57 EDT
1914Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1915Host is up.
1916
1917PORT STATE SERVICE VERSION
1918110/tcp filtered pop3
1919Too many fingerprints match this host to give specific OS details
1920
1921TRACEROUTE (using proto 1/icmp)
1922HOP RTT ADDRESS
19231 135.32 ms 10.203.21.1
19242 ...
19253 136.03 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
19264 135.94 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
19275 141.33 ms be3741.ccr22.sto03.atlas.cogentco.com (154.54.60.194)
19286 141.48 ms be3377.ccr21.sto01.atlas.cogentco.com (154.54.36.90)
19297 141.52 ms rascom.demarc.cogentco.com (149.6.168.138)
19308 ...
19319 156.18 ms dhub.inet2.ru (85.112.122.67)
193210 156.48 ms 185.130.248.18
193311 ... 30
1934################################################################################################################################
1935Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:57 EDT
1936Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1937Host is up.
1938
1939PORT STATE SERVICE VERSION
1940123/tcp filtered ntp
1941123/udp open|filtered ntp
1942Too many fingerprints match this host to give specific OS details
1943
1944TRACEROUTE (using proto 1/icmp)
1945HOP RTT ADDRESS
19461 134.23 ms 10.203.21.1
19472 ...
19483 131.49 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
19494 131.45 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
19505 136.87 ms be3741.ccr22.sto03.atlas.cogentco.com (154.54.60.194)
19516 136.84 ms be3377.ccr21.sto01.atlas.cogentco.com (154.54.36.90)
19527 137.26 ms rascom.demarc.cogentco.com (149.6.168.138)
19538 ...
19549 155.27 ms dhub.inet2.ru (85.112.122.67)
195510 155.27 ms 185.130.248.18
195611 ... 30
1957################################################################################################################################
1958Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 11:05 EDT
1959Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1960Host is up.
1961
1962PORT STATE SERVICE VERSION
19633306/tcp filtered mysql
1964Too many fingerprints match this host to give specific OS details
1965
1966TRACEROUTE (using proto 1/icmp)
1967HOP RTT ADDRESS
19681 137.08 ms 10.203.21.1
19692 ...
19703 138.11 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
19714 138.07 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
19725 143.36 ms be3741.ccr22.sto03.atlas.cogentco.com (154.54.60.194)
19736 143.32 ms be3377.ccr21.sto01.atlas.cogentco.com (154.54.36.90)
19747 143.41 ms rascom.demarc.cogentco.com (149.6.168.138)
19758 ...
19769 161.74 ms dhub.inet2.ru (85.112.122.67)
197710 173.60 ms 185.130.248.18
197811 ... 30
1979################################################################################################################################
1980Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 11:21 EDT
1981Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
1982Host is up.
1983
1984PORT STATE SERVICE VERSION
198553/tcp filtered domain
198667/tcp filtered dhcps
198768/tcp filtered dhcpc
198869/tcp filtered tftp
198988/tcp filtered kerberos-sec
1990123/tcp filtered ntp
1991137/tcp filtered netbios-ns
1992138/tcp filtered netbios-dgm
1993139/tcp filtered netbios-ssn
1994161/tcp filtered snmp
1995162/tcp filtered snmptrap
1996389/tcp filtered ldap
1997520/tcp filtered efs
19982049/tcp filtered nfs
199953/udp open|filtered domain
200067/udp open|filtered dhcps
200168/udp open|filtered dhcpc
200269/udp open|filtered tftp
200388/udp open|filtered kerberos-sec
2004123/udp open|filtered ntp
2005137/udp open|filtered netbios-ns
2006138/udp open|filtered netbios-dgm
2007139/udp open|filtered netbios-ssn
2008161/udp open|filtered snmp
2009162/udp open|filtered snmptrap
2010389/udp open|filtered ldap
2011520/udp open|filtered route
20122049/udp open|filtered nfs
2013Too many fingerprints match this host to give specific OS details
2014
2015TRACEROUTE (using proto 1/icmp)
2016HOP RTT ADDRESS
20171 130.89 ms 10.203.21.1
20182 ...
20193 131.54 ms te0-0-2-1.nr11.b069785-0.tll01.atlas.cogentco.com (149.6.188.49)
20204 131.49 ms be2160.rcr51.tll01.atlas.cogentco.com (154.25.10.249)
20215 138.13 ms be3741.ccr22.sto03.atlas.cogentco.com (154.54.60.194)
20226 138.21 ms be3377.ccr21.sto01.atlas.cogentco.com (154.54.36.90)
20237 138.20 ms rascom.demarc.cogentco.com (149.6.168.138)
20248 ...
20259 155.64 ms dhub.inet2.ru (85.112.122.67)
202610 155.22 ms 185.130.248.18
202711 ... 30
2028################################################################################################################################
2029Hosts
2030=====
2031
2032address mac name os_name os_flavor os_sp purpose info comments
2033------- --- ---- ------- --------- ----- ------- ---- --------
20343.83.211.23 ec2-3-83-211-23.compute-1.amazonaws.com embedded device
20353.216.98.236 ec2-3-216-98-236.compute-1.amazonaws.com Linux 3.X server
20365.45.67.166 dns.sflex.net Unknown device
203723.229.234.138 ip-23-229-234-138.ip.secureserver.net Linux 3.X server
203834.224.171.238 ec2-34-224-171-238.compute-1.amazonaws.com Linux server
203934.236.0.217 ec2-34-236-0-217.compute-1.amazonaws.com Linux 3.X server
204034.253.89.155 ec2-34-253-89-155.eu-west-1.compute.amazonaws.com Linux 4.X server
204137.1.207.121 teens-sins.net 2-Series 3.X device
204243.245.223.4 Linux 2.6.X server
204345.60.47.218 Linux 3.X server
204445.88.202.111 Linux 3.X server
204545.239.108.252 whale.ecohosting.cl Linux 3.X server
204652.1.2.24 ec2-52-1-2-24.compute-1.amazonaws.com Linux server
204752.1.174.10 ec2-52-1-174-10.compute-1.amazonaws.com Linux 3.X server
204852.30.54.73 ec2-52-30-54-73.eu-west-1.compute.amazonaws.com Linux 4.X server
204952.52.234.222 ec2-52-52-234-222.us-west-1.compute.amazonaws.com Unknown device
205052.138.144.162 Unknown device
205154.36.158.42 lb.xtgem.com Linux 3.X server
205254.72.57.25 ec2-54-72-57-25.eu-west-1.compute.amazonaws.com Linux 4.X server
205354.85.59.109 ec2-54-85-59-109.compute-1.amazonaws.com Linux 3.X server
205454.194.134.190 ec2-54-194-134-190.eu-west-1.compute.amazonaws.com Linux 4.X server
205564.69.94.253 Unknown device
205667.205.1.246 ps614624.dreamhost.com Android 5.X device
205769.163.233.4 ps54052.dreamhostps.com Linux 14.04 server
205874.117.180.192 embedded device
205982.94.222.131 Unknown device
206082.94.222.134 Unknown device
206182.94.228.245 Linux 2.6.X server
206289.248.172.178 no-reverse-dns-configured.com Linux 3.X server
206392.123.250.35 a92-123-250-35.deploy.static.akamaitechnologies.com embedded device
206492.123.250.65 a92-123-250-65.deploy.static.akamaitechnologies.com Linux 3.X server
206594.102.51.111 Linux 2.6.X server
206694.102.51.112 no-reverse-dns-configured.com Linux 2.6.X server
2067104.244.73.40 Unknown device
2068104.244.76.231 Linux 3.X server
2069104.244.77.188 Linux 3.X server
2070104.244.79.89 Linux 3.X server
2071107.180.28.114 ip-107-180-28-114.ip.secureserver.net Unknown device
2072111.90.145.39 web16.support-emilid.com Linux 2.6.X server
2073143.95.110.248 ip-143-95-110-248.iplocal Linux 3.X server
2074146.83.222.104 callecalle5.uach.cl Unknown device
2075149.126.72.220 149.126.72.220.ip.incapdns.net Linux 3.X server
2076151.106.38.107 ns3152160.ip-151-106-38.eu embedded device
2077158.69.13.254 ip254.ip-158-69-13.net 2-Series 2.6.X device
2078162.244.35.13 xnlog.com FreeBSD 7.X device
2079163.247.48.46 Unknown device
2080163.247.127.20 Unknown device
2081163.247.130.114 embedded device
2082163.247.175.176 Unknown device
2083165.22.143.229 Linux 2.6.X server
2084165.227.99.239 Linux 3.X server
2085169.239.218.20 cp10.domains.co.za Linux 2.6.X server
2086170.239.85.227 gesaguas.cl Unknown device
2087173.214.244.169 173.214.244.169.serverel.net Unknown device
2088174.142.53.51 mail.marineland.ca Linux 3.X server
2089186.64.118.40 mail.blue127.dnsmisitio.net embedded device
2090188.127.251.161 byronbayoasisresort.com.au Linux 3.X server
2091190.98.209.37 static.190.98.209.37.gtdinternet.com Unknown device
2092190.107.177.35 srv25.cpanelhost.cl Linux 2.6.X server
2093190.110.121.175 todofutbol.hn.cl Unknown device
2094190.153.209.187 static.190.153.209.187.gtdinternet.com Unknown device
2095190.153.219.254 mail.evopoli.cl Linux 3.X server
2096192.185.134.58 ns36.accountservergroup.com Linux 3.X server
2097198.49.23.144 Unknown device
2098198.49.23.145 Unknown device
2099198.185.159.144 Unknown device
2100198.185.159.145 Unknown device
2101199.38.245.243 embedded device
2102200.2.249.28 Linux 3.X server
2103200.10.251.82 homer.sii.cl Unknown device
2104200.12.19.101 embedded device
2105200.29.0.33 cp33.puntoweb.cl Unknown device
2106200.54.92.108 Linux 9.0 server
2107200.54.230.247 plesk.tdata.cloud Linux 3.X server
2108200.55.198.228 Linux 2.4.X server
2109200.68.30.227 mail.gorecoquimbo.cl Unknown device
2110200.68.34.99 Unknown device
2111200.73.54.34 mail.maxtel.cl Linux 2.6.X server
2112200.91.40.252 200-91-40-252.avz.cl Unknown device
2113200.91.41.5 cruzblanca.cl Unknown device
2114200.126.100.83 toqui.gorearaucania.cl Unknown device
2115201.159.170.136 soloweb.sinc.cl Unknown device
2116204.93.193.141 suzuka.mochahost.com Unknown device
2117206.48.140.40 Unknown device
2118207.246.147.189 2-Series device
2119207.246.147.190 Linux 4.X server
2120207.246.147.247 Linux 4.X server
2121207.246.147.248 Linux 4.X server
2122211.13.196.135 sv3.isle.ne.jp Linux 2.6.X server
2123212.174.0.150 Windows 2012 server
2124216.172.184.117 Linux 3.X server
2125218.45.5.97 www.town.koya.wakayama.jp Linux 2.6.X server
2126################################################################################################################################
2127Services
2128========
2129
2130host port proto name state info
2131---- ---- ----- ---- ----- ----
21323.83.211.23 53 tcp domain filtered
21333.83.211.23 53 udp domain unknown
21343.83.211.23 67 tcp dhcps filtered
21353.83.211.23 67 udp dhcps unknown
21363.83.211.23 68 tcp dhcpc filtered
21373.83.211.23 68 udp dhcpc unknown
21383.83.211.23 69 tcp tftp filtered
21393.83.211.23 69 udp tftp unknown
21403.83.211.23 80 tcp http open Microsoft IIS httpd 10.0
21413.83.211.23 88 tcp kerberos-sec filtered
21423.83.211.23 88 udp kerberos-sec unknown
21433.83.211.23 123 tcp ntp filtered
21443.83.211.23 123 udp ntp unknown
21453.83.211.23 137 tcp netbios-ns filtered
21463.83.211.23 137 udp netbios-ns unknown
21473.83.211.23 138 tcp netbios-dgm filtered
21483.83.211.23 138 udp netbios-dgm unknown
21493.83.211.23 139 tcp netbios-ssn filtered
21503.83.211.23 139 udp netbios-ssn unknown
21513.83.211.23 161 tcp snmp filtered
21523.83.211.23 161 udp snmp unknown
21533.83.211.23 162 tcp snmptrap filtered
21543.83.211.23 162 udp snmptrap unknown
21553.83.211.23 389 tcp ldap filtered
21563.83.211.23 389 udp ldap unknown
21573.83.211.23 443 tcp ssl/http open Microsoft IIS httpd 10.0
21583.83.211.23 520 tcp efs filtered
21593.83.211.23 520 udp route unknown
21603.83.211.23 2049 tcp nfs filtered
21613.83.211.23 2049 udp nfs unknown
21623.216.98.236 53 tcp domain filtered
21633.216.98.236 53 udp domain unknown
21643.216.98.236 67 tcp dhcps filtered
21653.216.98.236 67 udp dhcps unknown
21663.216.98.236 68 tcp dhcpc filtered
21673.216.98.236 68 udp dhcpc unknown
21683.216.98.236 69 tcp tftp filtered
21693.216.98.236 69 udp tftp unknown
21703.216.98.236 80 tcp http open Microsoft IIS httpd 10.0
21713.216.98.236 88 tcp kerberos-sec filtered
21723.216.98.236 88 udp kerberos-sec unknown
21733.216.98.236 123 tcp ntp filtered
21743.216.98.236 123 udp ntp unknown
21753.216.98.236 137 tcp netbios-ns filtered
21763.216.98.236 137 udp netbios-ns unknown
21773.216.98.236 138 tcp netbios-dgm filtered
21783.216.98.236 138 udp netbios-dgm unknown
21793.216.98.236 139 tcp netbios-ssn filtered
21803.216.98.236 139 udp netbios-ssn unknown
21813.216.98.236 161 tcp snmp filtered
21823.216.98.236 161 udp snmp unknown
21833.216.98.236 162 tcp snmptrap filtered
21843.216.98.236 162 udp snmptrap unknown
21853.216.98.236 389 tcp ldap filtered
21863.216.98.236 389 udp ldap unknown
21873.216.98.236 443 tcp ssl/http open Microsoft IIS httpd 10.0
21883.216.98.236 520 tcp efs filtered
21893.216.98.236 520 udp route unknown
21903.216.98.236 2049 tcp nfs filtered
21913.216.98.236 2049 udp nfs unknown
21925.45.67.166 22 tcp ssh open SSH-2.0-OpenSSH_7.4
21935.45.67.166 53 tcp domain closed
21945.45.67.166 53 udp domain closed
21955.45.67.166 67 tcp dhcps closed
21965.45.67.166 67 udp dhcps closed
21975.45.67.166 68 tcp dhcpc closed
21985.45.67.166 68 udp dhcpc closed
21995.45.67.166 69 tcp tftp closed
22005.45.67.166 69 udp tftp closed
22015.45.67.166 88 tcp kerberos-sec closed
22025.45.67.166 88 udp kerberos-sec unknown
22035.45.67.166 123 tcp ntp closed
22045.45.67.166 123 udp ntp unknown
22055.45.67.166 137 tcp netbios-ns filtered
22065.45.67.166 137 udp netbios-ns unknown
22075.45.67.166 138 tcp netbios-dgm filtered
22085.45.67.166 138 udp netbios-dgm unknown
22095.45.67.166 139 tcp netbios-ssn filtered
22105.45.67.166 139 udp netbios-ssn closed
22115.45.67.166 161 tcp snmp closed
22125.45.67.166 161 udp snmp unknown
22135.45.67.166 162 tcp snmptrap closed
22145.45.67.166 162 udp snmptrap unknown
22155.45.67.166 389 tcp ldap closed
22165.45.67.166 389 udp ldap unknown
22175.45.67.166 520 tcp efs closed
22185.45.67.166 520 udp route closed
22195.45.67.166 2049 tcp nfs closed
22205.45.67.166 2049 udp nfs closed
222123.229.234.138 21 tcp ftp open Pure-FTPd
222223.229.234.138 22 tcp ssh open OpenSSH 5.3 protocol 2.0
222323.229.234.138 25 tcp smtp open
222423.229.234.138 53 udp domain unknown
222523.229.234.138 67 udp dhcps unknown
222623.229.234.138 68 udp dhcpc unknown
222723.229.234.138 69 udp tftp unknown
222823.229.234.138 80 tcp http open Apache httpd PHP 5.6.40
222923.229.234.138 88 udp kerberos-sec unknown
223023.229.234.138 110 tcp pop3 open Dovecot pop3d
223123.229.234.138 123 udp ntp unknown
223223.229.234.138 137 udp netbios-ns unknown
223323.229.234.138 138 udp netbios-dgm unknown
223423.229.234.138 139 udp netbios-ssn unknown
223523.229.234.138 143 tcp imap open Dovecot imapd
223623.229.234.138 161 udp snmp unknown
223723.229.234.138 162 udp snmptrap unknown
223823.229.234.138 389 udp ldap unknown
223923.229.234.138 443 tcp ssl/http open Apache httpd PHP 5.6.40
224023.229.234.138 465 tcp ssl/smtp open Exim smtpd 4.92
224123.229.234.138 520 udp route unknown
224223.229.234.138 587 tcp smtp open Exim smtpd 4.92
224323.229.234.138 993 tcp ssl/imaps open
224423.229.234.138 995 tcp ssl/pop3s open
224523.229.234.138 2049 udp nfs unknown
224623.229.234.138 3306 tcp mysql open MySQL 5.6.44-cll-lve
224734.224.171.238 53 tcp domain filtered
224834.224.171.238 53 udp domain unknown
224934.224.171.238 67 tcp dhcps filtered
225034.224.171.238 67 udp dhcps unknown
225134.224.171.238 68 tcp dhcpc filtered
225234.224.171.238 68 udp dhcpc unknown
225334.224.171.238 69 tcp tftp filtered
225434.224.171.238 69 udp tftp unknown
225534.224.171.238 80 tcp http open Apache httpd 2.4.29 (Ubuntu)
225634.224.171.238 88 tcp kerberos-sec filtered
225734.224.171.238 88 udp kerberos-sec unknown
225834.224.171.238 123 tcp ntp filtered
225934.224.171.238 123 udp ntp unknown
226034.224.171.238 137 tcp netbios-ns filtered
226134.224.171.238 137 udp netbios-ns unknown
226234.224.171.238 138 tcp netbios-dgm filtered
226334.224.171.238 138 udp netbios-dgm unknown
226434.224.171.238 139 tcp netbios-ssn filtered
226534.224.171.238 139 udp netbios-ssn unknown
226634.224.171.238 161 tcp snmp filtered
226734.224.171.238 161 udp snmp unknown
226834.224.171.238 162 tcp snmptrap filtered
226934.224.171.238 162 udp snmptrap unknown
227034.224.171.238 389 tcp ldap filtered
227134.224.171.238 389 udp ldap unknown
227234.224.171.238 443 tcp ssl/http open Apache httpd 2.4.29 (Ubuntu)
227334.224.171.238 520 tcp efs filtered
227434.224.171.238 520 udp route unknown
227534.224.171.238 2049 tcp nfs filtered
227634.224.171.238 2049 udp nfs unknown
227734.236.0.217 53 tcp domain filtered
227834.236.0.217 53 udp domain unknown
227934.236.0.217 67 tcp dhcps filtered
228034.236.0.217 67 udp dhcps unknown
228134.236.0.217 68 tcp dhcpc filtered
228234.236.0.217 68 udp dhcpc unknown
228334.236.0.217 69 tcp tftp filtered
228434.236.0.217 69 udp tftp unknown
228534.236.0.217 80 tcp http open nginx
228634.236.0.217 88 tcp kerberos-sec filtered
228734.236.0.217 88 udp kerberos-sec unknown
228834.236.0.217 123 tcp ntp filtered
228934.236.0.217 123 udp ntp unknown
229034.236.0.217 137 tcp netbios-ns filtered
229134.236.0.217 137 udp netbios-ns unknown
229234.236.0.217 138 tcp netbios-dgm filtered
229334.236.0.217 138 udp netbios-dgm unknown
229434.236.0.217 139 tcp netbios-ssn filtered
229534.236.0.217 139 udp netbios-ssn unknown
229634.236.0.217 161 tcp snmp filtered
229734.236.0.217 161 udp snmp unknown
229834.236.0.217 162 tcp snmptrap filtered
229934.236.0.217 162 udp snmptrap unknown
230034.236.0.217 389 tcp ldap filtered
230134.236.0.217 389 udp ldap unknown
230234.236.0.217 443 tcp ssl/http open nginx
230334.236.0.217 520 tcp efs filtered
230434.236.0.217 520 udp route unknown
230534.236.0.217 2049 tcp nfs filtered
230634.236.0.217 2049 udp nfs unknown
230734.253.89.155 53 tcp domain closed
230834.253.89.155 53 udp domain unknown
230934.253.89.155 67 tcp dhcps closed
231034.253.89.155 67 udp dhcps unknown
231134.253.89.155 68 tcp dhcpc closed
231234.253.89.155 68 udp dhcpc unknown
231334.253.89.155 69 tcp tftp closed
231434.253.89.155 69 udp tftp unknown
231534.253.89.155 80 tcp http open nginx
231634.253.89.155 88 tcp kerberos-sec closed
231734.253.89.155 88 udp kerberos-sec unknown
231834.253.89.155 123 tcp ntp closed
231934.253.89.155 123 udp ntp unknown
232034.253.89.155 137 tcp netbios-ns closed
232134.253.89.155 137 udp netbios-ns unknown
232234.253.89.155 138 tcp netbios-dgm closed
232334.253.89.155 138 udp netbios-dgm unknown
232434.253.89.155 139 tcp netbios-ssn closed
232534.253.89.155 139 udp netbios-ssn unknown
232634.253.89.155 161 tcp snmp closed
232734.253.89.155 161 udp snmp unknown
232834.253.89.155 162 tcp snmptrap closed
232934.253.89.155 162 udp snmptrap unknown
233034.253.89.155 389 tcp ldap closed
233134.253.89.155 389 udp ldap unknown
233234.253.89.155 443 tcp ssl/http open nginx
233334.253.89.155 520 tcp efs closed
233434.253.89.155 520 udp route unknown
233534.253.89.155 2049 tcp nfs closed
233634.253.89.155 2049 udp nfs unknown
233737.1.207.121 53 tcp domain open ISC BIND 9.9.4 RedHat Enterprise Linux 7
233837.1.207.121 53 udp domain open ISC BIND 9.9.4 RedHat Enterprise Linux 7
233937.1.207.121 67 tcp dhcps filtered
234037.1.207.121 67 udp dhcps unknown
234137.1.207.121 68 tcp dhcpc filtered
234237.1.207.121 68 udp dhcpc filtered
234337.1.207.121 69 tcp tftp filtered
234437.1.207.121 69 udp tftp unknown
234537.1.207.121 88 tcp kerberos-sec filtered
234637.1.207.121 88 udp kerberos-sec filtered
234737.1.207.121 123 tcp ntp filtered
234837.1.207.121 123 udp ntp unknown
234937.1.207.121 137 tcp netbios-ns filtered
235037.1.207.121 137 udp netbios-ns unknown
235137.1.207.121 138 tcp netbios-dgm filtered
235237.1.207.121 138 udp netbios-dgm unknown
235337.1.207.121 139 tcp netbios-ssn filtered
235437.1.207.121 139 udp netbios-ssn unknown
235537.1.207.121 161 tcp snmp filtered
235637.1.207.121 161 udp snmp unknown
235737.1.207.121 162 tcp snmptrap filtered
235837.1.207.121 162 udp snmptrap unknown
235937.1.207.121 389 tcp ldap filtered
236037.1.207.121 389 udp ldap unknown
236137.1.207.121 520 tcp efs filtered
236237.1.207.121 520 udp route unknown
236337.1.207.121 2049 tcp nfs filtered
236437.1.207.121 2049 udp nfs filtered
236543.245.223.4 80 tcp http open nginx
236643.245.223.4 443 tcp ssl/http open nginx
236743.245.223.4 32022 tcp ssh open OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 Ubuntu Linux; protocol 2.0
236845.60.47.218 25 tcp http open Incapsula CDN httpd
236945.60.47.218 53 tcp domain open
237045.60.47.218 53 udp domain open
237145.60.47.218 67 udp dhcps unknown
237245.60.47.218 68 udp dhcpc unknown
237345.60.47.218 69 udp tftp unknown
237445.60.47.218 80 tcp http open Incapsula CDN httpd
237545.60.47.218 81 tcp http open Incapsula CDN httpd
237645.60.47.218 85 tcp http open Incapsula CDN httpd
237745.60.47.218 88 tcp http open Incapsula CDN httpd
237845.60.47.218 88 udp kerberos-sec unknown
237945.60.47.218 123 udp ntp unknown
238045.60.47.218 137 udp netbios-ns unknown
238145.60.47.218 138 udp netbios-dgm unknown
238245.60.47.218 139 udp netbios-ssn unknown
238345.60.47.218 161 udp snmp unknown
238445.60.47.218 162 udp snmptrap unknown
238545.60.47.218 389 tcp ssl/http open Incapsula CDN httpd
238645.60.47.218 389 udp ldap unknown
238745.60.47.218 443 tcp ssl/http open Incapsula CDN httpd
238845.60.47.218 444 tcp ssl/http open Incapsula CDN httpd
238945.60.47.218 445 tcp ssl/http open Incapsula CDN httpd
239045.60.47.218 446 tcp http open Incapsula CDN httpd
239145.60.47.218 520 udp route unknown
239245.60.47.218 587 tcp http open Incapsula CDN httpd
239345.60.47.218 631 tcp http open Incapsula CDN httpd
239445.60.47.218 888 tcp http open Incapsula CDN httpd
239545.60.47.218 995 tcp ssl/http open Incapsula CDN httpd
239645.60.47.218 998 tcp ssl/http open Incapsula CDN httpd
239745.60.47.218 999 tcp http open Incapsula CDN httpd
239845.60.47.218 1000 tcp http open Incapsula CDN httpd
239945.60.47.218 1024 tcp http open Incapsula CDN httpd
240045.60.47.218 1103 tcp http open Incapsula CDN httpd
240145.60.47.218 1234 tcp http open Incapsula CDN httpd
240245.60.47.218 1433 tcp http open Incapsula CDN httpd
240345.60.47.218 1494 tcp http open Incapsula CDN httpd
240445.60.47.218 2000 tcp ssl/http open Incapsula CDN httpd
240545.60.47.218 2001 tcp http open Incapsula CDN httpd
240645.60.47.218 2049 tcp http open Incapsula CDN httpd
240745.60.47.218 2049 udp nfs unknown
240845.60.47.218 2067 tcp http open Incapsula CDN httpd
240945.60.47.218 2100 tcp ssl/http open Incapsula CDN httpd
241045.60.47.218 2222 tcp http open Incapsula CDN httpd
241145.60.47.218 2598 tcp http open Incapsula CDN httpd
241245.60.47.218 3000 tcp http open Incapsula CDN httpd
241345.60.47.218 3050 tcp http open Incapsula CDN httpd
241445.60.47.218 3057 tcp http open Incapsula CDN httpd
241545.60.47.218 3299 tcp http open Incapsula CDN httpd
241645.60.47.218 3306 tcp ssl/http open Incapsula CDN httpd
241745.60.47.218 3333 tcp http open Incapsula CDN httpd
241845.60.47.218 3389 tcp ssl/http open Incapsula CDN httpd
241945.60.47.218 3500 tcp http open Incapsula CDN httpd
242045.60.47.218 3790 tcp http open Incapsula CDN httpd
242145.60.47.218 4000 tcp http open Incapsula CDN httpd
242245.60.47.218 4444 tcp ssl/http open Incapsula CDN httpd
242345.60.47.218 4445 tcp ssl/http open Incapsula CDN httpd
242445.60.47.218 4848 tcp http open Incapsula CDN httpd
242545.60.47.218 5000 tcp http open Incapsula CDN httpd
242645.60.47.218 5009 tcp http open Incapsula CDN httpd
242745.60.47.218 5051 tcp ssl/http open Incapsula CDN httpd
242845.60.47.218 5060 tcp ssl/http open Incapsula CDN httpd
242945.60.47.218 5061 tcp ssl/http open Incapsula CDN httpd
243045.60.47.218 5227 tcp ssl/http open Incapsula CDN httpd
243145.60.47.218 5247 tcp ssl/http open Incapsula CDN httpd
243245.60.47.218 5250 tcp ssl/http open Incapsula CDN httpd
243345.60.47.218 5555 tcp http open Incapsula CDN httpd
243445.60.47.218 5900 tcp http open Incapsula CDN httpd
243545.60.47.218 5901 tcp ssl/http open Incapsula CDN httpd
243645.60.47.218 5902 tcp ssl/http open Incapsula CDN httpd
243745.60.47.218 5903 tcp ssl/http open Incapsula CDN httpd
243845.60.47.218 5904 tcp ssl/http open Incapsula CDN httpd
243945.60.47.218 5905 tcp ssl/http open Incapsula CDN httpd
244045.60.47.218 5906 tcp ssl/http open Incapsula CDN httpd
244145.60.47.218 5907 tcp ssl/http open Incapsula CDN httpd
244245.60.47.218 5908 tcp ssl/http open Incapsula CDN httpd
244345.60.47.218 5909 tcp ssl/http open Incapsula CDN httpd
244445.60.47.218 5910 tcp ssl/http open Incapsula CDN httpd
244545.60.47.218 5920 tcp ssl/http open Incapsula CDN httpd
244645.60.47.218 5984 tcp ssl/http open Incapsula CDN httpd
244745.60.47.218 5985 tcp http open Incapsula CDN httpd
244845.60.47.218 5986 tcp ssl/http open Incapsula CDN httpd
244945.60.47.218 5999 tcp ssl/http open Incapsula CDN httpd
245045.60.47.218 6000 tcp http open Incapsula CDN httpd
245145.60.47.218 6060 tcp http open Incapsula CDN httpd
245245.60.47.218 6161 tcp http open Incapsula CDN httpd
245345.60.47.218 6379 tcp http open Incapsula CDN httpd
245445.60.47.218 6661 tcp ssl/http open Incapsula CDN httpd
245545.60.47.218 6789 tcp http open Incapsula CDN httpd
245645.60.47.218 7000 tcp ssl/http open Incapsula CDN httpd
245745.60.47.218 7001 tcp http open Incapsula CDN httpd
245845.60.47.218 7021 tcp http open Incapsula CDN httpd
245945.60.47.218 7071 tcp ssl/http open Incapsula CDN httpd
246045.60.47.218 7080 tcp http open Incapsula CDN httpd
246145.60.47.218 7272 tcp ssl/http open Incapsula CDN httpd
246245.60.47.218 7443 tcp ssl/http open Incapsula CDN httpd
246345.60.47.218 7700 tcp http open Incapsula CDN httpd
246445.60.47.218 7777 tcp http open Incapsula CDN httpd
246545.60.47.218 7778 tcp http open Incapsula CDN httpd
246645.60.47.218 8000 tcp http open Incapsula CDN httpd
246745.60.47.218 8001 tcp http open Incapsula CDN httpd
246845.60.47.218 8008 tcp http open Incapsula CDN httpd
246945.60.47.218 8014 tcp http open Incapsula CDN httpd
247045.60.47.218 8020 tcp http open Incapsula CDN httpd
247145.60.47.218 8023 tcp http open Incapsula CDN httpd
247245.60.47.218 8028 tcp http open Incapsula CDN httpd
247345.60.47.218 8030 tcp http open Incapsula CDN httpd
247445.60.47.218 8050 tcp http open Incapsula CDN httpd
247545.60.47.218 8051 tcp http open Incapsula CDN httpd
247645.60.47.218 8080 tcp http open Incapsula CDN httpd
247745.60.47.218 8081 tcp http open Incapsula CDN httpd
247845.60.47.218 8082 tcp http open Incapsula CDN httpd
247945.60.47.218 8085 tcp http open Incapsula CDN httpd
248045.60.47.218 8086 tcp http open Incapsula CDN httpd
248145.60.47.218 8087 tcp http open Incapsula CDN httpd
248245.60.47.218 8088 tcp http open Incapsula CDN httpd
248345.60.47.218 8090 tcp http open Incapsula CDN httpd
248445.60.47.218 8091 tcp http open Incapsula CDN httpd
248545.60.47.218 8095 tcp http open Incapsula CDN httpd
248645.60.47.218 8101 tcp http open Incapsula CDN httpd
248745.60.47.218 8161 tcp http open Incapsula CDN httpd
248845.60.47.218 8180 tcp http open Incapsula CDN httpd
248945.60.47.218 8222 tcp http open Incapsula CDN httpd
249045.60.47.218 8333 tcp http open Incapsula CDN httpd
249145.60.47.218 8443 tcp ssl/http open Incapsula CDN httpd
249245.60.47.218 8444 tcp http open Incapsula CDN httpd
249345.60.47.218 8445 tcp http open Incapsula CDN httpd
249445.60.47.218 8503 tcp ssl/http open Incapsula CDN httpd
249545.60.47.218 8686 tcp http open Incapsula CDN httpd
249645.60.47.218 8701 tcp ssl/http open Incapsula CDN httpd
249745.60.47.218 8787 tcp http open Incapsula CDN httpd
249845.60.47.218 8800 tcp http open Incapsula CDN httpd
249945.60.47.218 8812 tcp http open Incapsula CDN httpd
250045.60.47.218 8834 tcp http open Incapsula CDN httpd
250145.60.47.218 8880 tcp http open Incapsula CDN httpd
250245.60.47.218 8888 tcp http open Incapsula CDN httpd
250345.60.47.218 8889 tcp http open Incapsula CDN httpd
250445.60.47.218 8890 tcp http open Incapsula CDN httpd
250545.60.47.218 8899 tcp http open Incapsula CDN httpd
250645.60.47.218 8901 tcp http open Incapsula CDN httpd
250745.60.47.218 8902 tcp http open Incapsula CDN httpd
250845.60.47.218 8999 tcp http open Incapsula CDN httpd
250945.60.47.218 9000 tcp http open Incapsula CDN httpd
251045.60.47.218 9001 tcp http open Incapsula CDN httpd
251145.60.47.218 9002 tcp http open Incapsula CDN httpd
251245.60.47.218 9003 tcp http open Incapsula CDN httpd
251345.60.47.218 9004 tcp http open Incapsula CDN httpd
251445.60.47.218 9005 tcp http open Incapsula CDN httpd
251545.60.47.218 9010 tcp http open Incapsula CDN httpd
251645.60.47.218 9050 tcp http open Incapsula CDN httpd
251745.60.47.218 9080 tcp http open Incapsula CDN httpd
251845.60.47.218 9081 tcp ssl/http open Incapsula CDN httpd
251945.60.47.218 9084 tcp http open Incapsula CDN httpd
252045.60.47.218 9090 tcp http open Incapsula CDN httpd
252145.60.47.218 9099 tcp http open Incapsula CDN httpd
252245.60.47.218 9100 tcp jetdirect open
252345.60.47.218 9111 tcp http open Incapsula CDN httpd
252445.60.47.218 9200 tcp http open Incapsula CDN httpd
252545.60.47.218 9300 tcp http open Incapsula CDN httpd
252645.60.47.218 9500 tcp http open Incapsula CDN httpd
252745.60.47.218 9711 tcp ssl/http open Incapsula CDN httpd
252845.60.47.218 9991 tcp http open Incapsula CDN httpd
252945.60.47.218 9999 tcp http open Incapsula CDN httpd
253045.60.47.218 10000 tcp http open Incapsula CDN httpd
253145.60.47.218 10001 tcp http open Incapsula CDN httpd
253245.60.47.218 10008 tcp http open Incapsula CDN httpd
253345.60.47.218 10443 tcp ssl/http open Incapsula CDN httpd
253445.60.47.218 11001 tcp ssl/http open Incapsula CDN httpd
253545.60.47.218 12174 tcp http open Incapsula CDN httpd
253645.60.47.218 12203 tcp http open Incapsula CDN httpd
253745.60.47.218 12221 tcp http open Incapsula CDN httpd
253845.60.47.218 12345 tcp http open Incapsula CDN httpd
253945.60.47.218 12397 tcp http open Incapsula CDN httpd
254045.60.47.218 12401 tcp http open Incapsula CDN httpd
254145.60.47.218 14330 tcp http open Incapsula CDN httpd
254245.60.47.218 16000 tcp http open Incapsula CDN httpd
254345.60.47.218 20000 tcp http open Incapsula CDN httpd
254445.60.47.218 20010 tcp ssl/http open Incapsula CDN httpd
254545.60.47.218 25000 tcp ssl/http open Incapsula CDN httpd
254645.60.47.218 30000 tcp http open Incapsula CDN httpd
254745.60.47.218 44334 tcp ssl/http open Incapsula CDN httpd
254845.60.47.218 50000 tcp http open Incapsula CDN httpd
254945.60.47.218 50001 tcp ssl/http open Incapsula CDN httpd
255045.60.47.218 50050 tcp ssl/http open Incapsula CDN httpd
255145.88.202.111 22 tcp ssh open OpenSSH 7.9p1 Debian 10+deb10u1 protocol 2.0
255245.88.202.111 53 tcp domain open PowerDNS Authoritative Server 4.2.0-rc3
255345.88.202.111 53 udp domain open PowerDNS Authoritative Server 4.2.0-rc3
255445.88.202.111 67 tcp dhcps closed
255545.88.202.111 67 udp dhcps unknown
255645.88.202.111 68 tcp dhcpc closed
255745.88.202.111 68 udp dhcpc unknown
255845.88.202.111 69 tcp tftp closed
255945.88.202.111 69 udp tftp closed
256045.88.202.111 80 tcp http open nginx
256145.88.202.111 88 tcp kerberos-sec closed
256245.88.202.111 88 udp kerberos-sec unknown
256345.88.202.111 123 tcp ntp closed
256445.88.202.111 123 udp ntp closed
256545.88.202.111 137 tcp netbios-ns closed
256645.88.202.111 137 udp netbios-ns filtered
256745.88.202.111 138 tcp netbios-dgm closed
256845.88.202.111 138 udp netbios-dgm filtered
256945.88.202.111 139 tcp netbios-ssn closed
257045.88.202.111 139 udp netbios-ssn closed
257145.88.202.111 161 tcp snmp closed
257245.88.202.111 161 udp snmp closed
257345.88.202.111 162 tcp snmptrap closed
257445.88.202.111 162 udp snmptrap closed
257545.88.202.111 179 tcp bgp filtered
257645.88.202.111 389 tcp ldap closed
257745.88.202.111 389 udp ldap unknown
257845.88.202.111 443 tcp ssl/http open nginx
257945.88.202.111 520 tcp efs closed
258045.88.202.111 520 udp route unknown
258145.88.202.111 2049 tcp nfs closed
258245.88.202.111 2049 udp nfs closed
258345.88.202.111 10050 tcp tcpwrapped open
258445.239.108.252 53 tcp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
258545.239.108.252 53 udp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
258645.239.108.252 67 tcp dhcps filtered
258745.239.108.252 67 udp dhcps unknown
258845.239.108.252 68 tcp dhcpc filtered
258945.239.108.252 68 udp dhcpc unknown
259045.239.108.252 69 tcp tftp filtered
259145.239.108.252 69 udp tftp unknown
259245.239.108.252 88 tcp kerberos-sec filtered
259345.239.108.252 88 udp kerberos-sec unknown
259445.239.108.252 123 tcp ntp filtered
259545.239.108.252 123 udp ntp unknown
259645.239.108.252 137 tcp netbios-ns filtered
259745.239.108.252 137 udp netbios-ns unknown
259845.239.108.252 138 tcp netbios-dgm filtered
259945.239.108.252 138 udp netbios-dgm unknown
260045.239.108.252 139 tcp netbios-ssn filtered
260145.239.108.252 139 udp netbios-ssn unknown
260245.239.108.252 161 tcp snmp filtered
260345.239.108.252 161 udp snmp unknown
260445.239.108.252 162 tcp snmptrap filtered
260545.239.108.252 162 udp snmptrap unknown
260645.239.108.252 389 tcp ldap filtered
260745.239.108.252 389 udp ldap unknown
260845.239.108.252 520 tcp efs filtered
260945.239.108.252 520 udp route unknown
261045.239.108.252 2049 tcp nfs filtered
261145.239.108.252 2049 udp nfs unknown
261252.1.2.24 53 tcp domain filtered
261352.1.2.24 53 udp domain unknown
261452.1.2.24 67 tcp dhcps filtered
261552.1.2.24 67 udp dhcps unknown
261652.1.2.24 68 tcp dhcpc filtered
261752.1.2.24 68 udp dhcpc unknown
261852.1.2.24 69 tcp tftp filtered
261952.1.2.24 69 udp tftp unknown
262052.1.2.24 80 tcp http open Apache httpd 2.4.29 (Ubuntu)
262152.1.2.24 88 tcp kerberos-sec filtered
262252.1.2.24 88 udp kerberos-sec unknown
262352.1.2.24 123 tcp ntp filtered
262452.1.2.24 123 udp ntp unknown
262552.1.2.24 137 tcp netbios-ns filtered
262652.1.2.24 137 udp netbios-ns unknown
262752.1.2.24 138 tcp netbios-dgm filtered
262852.1.2.24 138 udp netbios-dgm unknown
262952.1.2.24 139 tcp netbios-ssn filtered
263052.1.2.24 139 udp netbios-ssn unknown
263152.1.2.24 161 tcp snmp filtered
263252.1.2.24 161 udp snmp unknown
263352.1.2.24 162 tcp snmptrap filtered
263452.1.2.24 162 udp snmptrap unknown
263552.1.2.24 389 tcp ldap filtered
263652.1.2.24 389 udp ldap unknown
263752.1.2.24 443 tcp ssl/http open Apache httpd 2.4.29 (Ubuntu)
263852.1.2.24 520 tcp efs filtered
263952.1.2.24 520 udp route unknown
264052.1.2.24 2049 tcp nfs filtered
264152.1.2.24 2049 udp nfs unknown
264252.1.174.10 53 tcp domain filtered
264352.1.174.10 53 udp domain unknown
264452.1.174.10 67 tcp dhcps filtered
264552.1.174.10 67 udp dhcps unknown
264652.1.174.10 68 tcp dhcpc filtered
264752.1.174.10 68 udp dhcpc unknown
264852.1.174.10 69 tcp tftp filtered
264952.1.174.10 69 udp tftp unknown
265052.1.174.10 80 tcp http open nginx
265152.1.174.10 88 tcp kerberos-sec filtered
265252.1.174.10 88 udp kerberos-sec unknown
265352.1.174.10 123 tcp ntp filtered
265452.1.174.10 123 udp ntp unknown
265552.1.174.10 137 tcp netbios-ns filtered
265652.1.174.10 137 udp netbios-ns unknown
265752.1.174.10 138 tcp netbios-dgm filtered
265852.1.174.10 138 udp netbios-dgm unknown
265952.1.174.10 139 tcp netbios-ssn filtered
266052.1.174.10 139 udp netbios-ssn unknown
266152.1.174.10 161 tcp snmp filtered
266252.1.174.10 161 udp snmp unknown
266352.1.174.10 162 tcp snmptrap filtered
266452.1.174.10 162 udp snmptrap unknown
266552.1.174.10 389 tcp ldap filtered
266652.1.174.10 389 udp ldap unknown
266752.1.174.10 443 tcp ssl/http open nginx
266852.1.174.10 520 tcp efs filtered
266952.1.174.10 520 udp route unknown
267052.1.174.10 2049 tcp nfs filtered
267152.1.174.10 2049 udp nfs unknown
267252.30.54.73 53 tcp domain closed
267352.30.54.73 53 udp domain unknown
267452.30.54.73 67 tcp dhcps closed
267552.30.54.73 67 udp dhcps unknown
267652.30.54.73 68 tcp dhcpc closed
267752.30.54.73 68 udp dhcpc unknown
267852.30.54.73 69 tcp tftp closed
267952.30.54.73 69 udp tftp unknown
268052.30.54.73 80 tcp http open nginx
268152.30.54.73 88 tcp kerberos-sec closed
268252.30.54.73 88 udp kerberos-sec unknown
268352.30.54.73 123 tcp ntp closed
268452.30.54.73 123 udp ntp unknown
268552.30.54.73 137 tcp netbios-ns closed
268652.30.54.73 137 udp netbios-ns unknown
268752.30.54.73 138 tcp netbios-dgm closed
268852.30.54.73 138 udp netbios-dgm unknown
268952.30.54.73 139 tcp netbios-ssn closed
269052.30.54.73 139 udp netbios-ssn unknown
269152.30.54.73 161 tcp snmp closed
269252.30.54.73 161 udp snmp unknown
269352.30.54.73 162 tcp snmptrap closed
269452.30.54.73 162 udp snmptrap unknown
269552.30.54.73 389 tcp ldap closed
269652.30.54.73 389 udp ldap unknown
269752.30.54.73 443 tcp ssl/http open nginx
269852.30.54.73 520 tcp efs closed
269952.30.54.73 520 udp route unknown
270052.30.54.73 2049 tcp nfs closed
270152.30.54.73 2049 udp nfs unknown
270252.52.234.222 53 tcp domain filtered
270352.52.234.222 53 udp domain unknown
270452.52.234.222 67 tcp dhcps filtered
270552.52.234.222 67 udp dhcps unknown
270652.52.234.222 68 tcp dhcpc filtered
270752.52.234.222 68 udp dhcpc unknown
270852.52.234.222 69 tcp tftp filtered
270952.52.234.222 69 udp tftp unknown
271052.52.234.222 88 tcp kerberos-sec filtered
271152.52.234.222 88 udp kerberos-sec unknown
271252.52.234.222 123 tcp ntp filtered
271352.52.234.222 123 udp ntp unknown
271452.52.234.222 137 tcp netbios-ns filtered
271552.52.234.222 137 udp netbios-ns unknown
271652.52.234.222 138 tcp netbios-dgm filtered
271752.52.234.222 138 udp netbios-dgm unknown
271852.52.234.222 139 tcp netbios-ssn filtered
271952.52.234.222 139 udp netbios-ssn unknown
272052.52.234.222 161 tcp snmp filtered
272152.52.234.222 161 udp snmp unknown
272252.52.234.222 162 tcp snmptrap filtered
272352.52.234.222 162 udp snmptrap unknown
272452.52.234.222 389 tcp ldap filtered
272552.52.234.222 389 udp ldap unknown
272652.52.234.222 520 tcp efs filtered
272752.52.234.222 520 udp route unknown
272852.52.234.222 2049 tcp nfs filtered
272952.52.234.222 2049 udp nfs unknown
273052.138.144.162 53 tcp domain filtered
273152.138.144.162 53 udp domain unknown
273252.138.144.162 67 tcp dhcps filtered
273352.138.144.162 67 udp dhcps unknown
273452.138.144.162 68 tcp dhcpc filtered
273552.138.144.162 68 udp dhcpc unknown
273652.138.144.162 69 tcp tftp filtered
273752.138.144.162 69 udp tftp unknown
273852.138.144.162 80 tcp http open Microsoft IIS httpd 7.5
273952.138.144.162 88 tcp kerberos-sec filtered
274052.138.144.162 88 udp kerberos-sec unknown
274152.138.144.162 123 tcp ntp filtered
274252.138.144.162 123 udp ntp unknown
274352.138.144.162 137 tcp netbios-ns filtered
274452.138.144.162 137 udp netbios-ns unknown
274552.138.144.162 138 tcp netbios-dgm filtered
274652.138.144.162 138 udp netbios-dgm unknown
274752.138.144.162 139 tcp netbios-ssn filtered
274852.138.144.162 139 udp netbios-ssn unknown
274952.138.144.162 161 tcp snmp filtered
275052.138.144.162 161 udp snmp unknown
275152.138.144.162 162 tcp snmptrap filtered
275252.138.144.162 162 udp snmptrap unknown
275352.138.144.162 389 tcp ldap filtered
275452.138.144.162 389 udp ldap unknown
275552.138.144.162 443 tcp ssl/http open Microsoft IIS httpd 7.5
275652.138.144.162 520 tcp efs filtered
275752.138.144.162 520 udp route unknown
275852.138.144.162 2049 tcp nfs filtered
275952.138.144.162 2049 udp nfs unknown
276052.138.144.162 3911 tcp http open Microsoft IIS httpd 7.5
276152.138.144.162 3912 tcp ssl/http open Microsoft IIS httpd 7.5
276252.138.144.162 7777 tcp http open Microsoft IIS httpd 7.5
276352.138.144.162 8080 tcp ssl/http open Microsoft IIS httpd 10.0
276452.138.144.162 8089 tcp ssl/http open Microsoft IIS httpd 7.5
276552.138.144.162 8888 tcp http open Microsoft IIS httpd 7.5
276652.138.144.162 9090 tcp http open Microsoft IIS httpd 7.5
276752.138.144.162 9191 tcp http open Microsoft IIS httpd 7.5
276852.138.144.162 9999 tcp http open Microsoft IIS httpd 7.5
276952.138.144.162 65503 tcp http open Microsoft HTTPAPI httpd 2.0 SSDP/UPnP
277052.138.144.162 65504 tcp http open Microsoft HTTPAPI httpd 2.0 SSDP/UPnP
277154.36.158.42 22 tcp ssh open OpenSSH 7.4 protocol 2.0
277254.36.158.42 53 udp domain unknown
277354.36.158.42 67 udp dhcps unknown
277454.36.158.42 68 udp dhcpc unknown
277554.36.158.42 80 tcp http-proxy open HAProxy http proxy 1.3.1 or later
277654.36.158.42 137 udp netbios-ns unknown
277754.36.158.42 139 udp netbios-ssn unknown
277854.36.158.42 443 tcp ssl/http-proxy open HAProxy http proxy 1.3.1 or later
277954.36.158.42 2049 udp nfs unknown
278054.36.158.42 5000 tcp http open Apache httpd
278154.36.158.42 8088 tcp radan-http open
278254.36.158.42 22222 tcp ssh open OpenSSH 7.4 protocol 2.0
278354.72.57.25 53 tcp domain closed
278454.72.57.25 53 udp domain unknown
278554.72.57.25 67 tcp dhcps closed
278654.72.57.25 67 udp dhcps unknown
278754.72.57.25 68 tcp dhcpc closed
278854.72.57.25 68 udp dhcpc unknown
278954.72.57.25 69 tcp tftp closed
279054.72.57.25 69 udp tftp unknown
279154.72.57.25 80 tcp http open nginx
279254.72.57.25 88 tcp kerberos-sec closed
279354.72.57.25 88 udp kerberos-sec unknown
279454.72.57.25 123 tcp ntp closed
279554.72.57.25 123 udp ntp unknown
279654.72.57.25 137 tcp netbios-ns closed
279754.72.57.25 137 udp netbios-ns unknown
279854.72.57.25 138 tcp netbios-dgm closed
279954.72.57.25 138 udp netbios-dgm unknown
280054.72.57.25 139 tcp netbios-ssn closed
280154.72.57.25 139 udp netbios-ssn unknown
280254.72.57.25 161 tcp snmp closed
280354.72.57.25 161 udp snmp unknown
280454.72.57.25 162 tcp snmptrap closed
280554.72.57.25 162 udp snmptrap unknown
280654.72.57.25 389 tcp ldap closed
280754.72.57.25 389 udp ldap unknown
280854.72.57.25 443 tcp ssl/http open nginx
280954.72.57.25 520 tcp efs closed
281054.72.57.25 520 udp route unknown
281154.72.57.25 2049 tcp nfs closed
281254.72.57.25 2049 udp nfs unknown
281354.85.59.109 53 tcp domain filtered
281454.85.59.109 53 udp domain unknown
281554.85.59.109 67 tcp dhcps filtered
281654.85.59.109 67 udp dhcps unknown
281754.85.59.109 68 tcp dhcpc filtered
281854.85.59.109 68 udp dhcpc unknown
281954.85.59.109 69 tcp tftp filtered
282054.85.59.109 69 udp tftp unknown
282154.85.59.109 80 tcp http open nginx
282254.85.59.109 88 tcp kerberos-sec filtered
282354.85.59.109 88 udp kerberos-sec unknown
282454.85.59.109 123 tcp ntp filtered
282554.85.59.109 123 udp ntp unknown
282654.85.59.109 137 tcp netbios-ns filtered
282754.85.59.109 137 udp netbios-ns unknown
282854.85.59.109 138 tcp netbios-dgm filtered
282954.85.59.109 138 udp netbios-dgm unknown
283054.85.59.109 139 tcp netbios-ssn filtered
283154.85.59.109 139 udp netbios-ssn unknown
283254.85.59.109 161 tcp snmp filtered
283354.85.59.109 161 udp snmp unknown
283454.85.59.109 162 tcp snmptrap filtered
283554.85.59.109 162 udp snmptrap unknown
283654.85.59.109 389 tcp ldap filtered
283754.85.59.109 389 udp ldap unknown
283854.85.59.109 443 tcp ssl/http open nginx
283954.85.59.109 520 tcp efs filtered
284054.85.59.109 520 udp route unknown
284154.85.59.109 2049 tcp nfs filtered
284254.85.59.109 2049 udp nfs unknown
284354.194.134.190 53 tcp domain closed
284454.194.134.190 53 udp domain unknown
284554.194.134.190 67 tcp dhcps closed
284654.194.134.190 67 udp dhcps unknown
284754.194.134.190 68 tcp dhcpc closed
284854.194.134.190 68 udp dhcpc unknown
284954.194.134.190 69 tcp tftp closed
285054.194.134.190 69 udp tftp unknown
285154.194.134.190 80 tcp http open nginx
285254.194.134.190 88 tcp kerberos-sec closed
285354.194.134.190 88 udp kerberos-sec unknown
285454.194.134.190 123 tcp ntp closed
285554.194.134.190 123 udp ntp unknown
285654.194.134.190 137 tcp netbios-ns closed
285754.194.134.190 137 udp netbios-ns unknown
285854.194.134.190 138 tcp netbios-dgm closed
285954.194.134.190 138 udp netbios-dgm unknown
286054.194.134.190 139 tcp netbios-ssn closed
286154.194.134.190 139 udp netbios-ssn unknown
286254.194.134.190 161 tcp snmp closed
286354.194.134.190 161 udp snmp unknown
286454.194.134.190 162 tcp snmptrap closed
286554.194.134.190 162 udp snmptrap unknown
286654.194.134.190 389 tcp ldap closed
286754.194.134.190 389 udp ldap unknown
286854.194.134.190 443 tcp ssl/http open nginx
286954.194.134.190 520 tcp efs closed
287054.194.134.190 520 udp route unknown
287154.194.134.190 2049 tcp nfs closed
287254.194.134.190 2049 udp nfs unknown
287364.69.94.253 53 tcp domain filtered
287464.69.94.253 53 udp domain unknown
287564.69.94.253 67 tcp dhcps filtered
287664.69.94.253 67 udp dhcps unknown
287764.69.94.253 68 tcp dhcpc filtered
287864.69.94.253 68 udp dhcpc unknown
287964.69.94.253 69 tcp tftp filtered
288064.69.94.253 69 udp tftp unknown
288164.69.94.253 88 tcp kerberos-sec filtered
288264.69.94.253 88 udp kerberos-sec unknown
288364.69.94.253 123 tcp ntp filtered
288464.69.94.253 123 udp ntp unknown
288564.69.94.253 137 tcp netbios-ns filtered
288664.69.94.253 137 udp netbios-ns unknown
288764.69.94.253 138 tcp netbios-dgm filtered
288864.69.94.253 138 udp netbios-dgm unknown
288964.69.94.253 139 tcp netbios-ssn filtered
289064.69.94.253 139 udp netbios-ssn unknown
289164.69.94.253 161 tcp snmp filtered
289264.69.94.253 161 udp snmp unknown
289364.69.94.253 162 tcp snmptrap filtered
289464.69.94.253 162 udp snmptrap unknown
289564.69.94.253 389 tcp ldap filtered
289664.69.94.253 389 udp ldap unknown
289764.69.94.253 520 tcp efs filtered
289864.69.94.253 520 udp route unknown
289964.69.94.253 2049 tcp nfs filtered
290064.69.94.253 2049 udp nfs unknown
290167.205.1.246 21 tcp ftp open ProFTPD
290267.205.1.246 22 tcp ssh open OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.13 Ubuntu Linux; protocol 2.0
290367.205.1.246 25 tcp smtp open Postfix smtpd
290467.205.1.246 53 tcp domain closed
290567.205.1.246 53 udp domain closed
290667.205.1.246 67 tcp dhcps closed
290767.205.1.246 67 udp dhcps closed
290867.205.1.246 68 tcp dhcpc closed
290967.205.1.246 68 udp dhcpc closed
291067.205.1.246 69 tcp tftp closed
291167.205.1.246 69 udp tftp unknown
291267.205.1.246 80 tcp http open Apache httpd
291367.205.1.246 88 tcp kerberos-sec closed
291467.205.1.246 88 udp kerberos-sec unknown
291567.205.1.246 111 tcp rpcbind filtered
291667.205.1.246 123 tcp ntp closed
291767.205.1.246 123 udp ntp unknown
291867.205.1.246 137 tcp netbios-ns closed
291967.205.1.246 137 udp netbios-ns closed
292067.205.1.246 138 tcp netbios-dgm closed
292167.205.1.246 138 udp netbios-dgm unknown
292267.205.1.246 139 tcp netbios-ssn closed
292367.205.1.246 139 udp netbios-ssn closed
292467.205.1.246 161 tcp snmp closed
292567.205.1.246 161 udp snmp unknown
292667.205.1.246 162 tcp snmptrap closed
292767.205.1.246 162 udp snmptrap unknown
292867.205.1.246 389 tcp ldap closed
292967.205.1.246 389 udp ldap unknown
293067.205.1.246 443 tcp ssl/http open Apache httpd
293167.205.1.246 520 tcp efs closed
293267.205.1.246 520 udp route unknown
293367.205.1.246 587 tcp smtp open Postfix smtpd
293467.205.1.246 1030 tcp iad1 filtered
293567.205.1.246 2049 tcp nfs closed
293667.205.1.246 2049 udp nfs unknown
293767.205.1.246 5666 tcp nrpe filtered
293867.205.1.246 8901 tcp jmb-cds2 filtered
293967.205.1.246 8902 tcp filtered
294069.163.233.4 21 tcp ftp open 220 DreamHost FTP Server\x0d\x0a
294169.163.233.4 22 tcp ssh open SSH-2.0-OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.13
294269.163.233.4 25 tcp open
294369.163.233.4 53 tcp domain closed
294469.163.233.4 53 udp domain unknown
294569.163.233.4 67 tcp dhcps closed
294669.163.233.4 67 udp dhcps closed
294769.163.233.4 68 tcp dhcpc closed
294869.163.233.4 68 udp dhcpc unknown
294969.163.233.4 69 tcp tftp closed
295069.163.233.4 69 udp tftp closed
295169.163.233.4 88 tcp kerberos-sec closed
295269.163.233.4 88 udp kerberos-sec unknown
295369.163.233.4 123 tcp ntp closed
295469.163.233.4 123 udp ntp unknown
295569.163.233.4 137 tcp netbios-ns closed
295669.163.233.4 137 udp netbios-ns closed
295769.163.233.4 138 tcp netbios-dgm closed
295869.163.233.4 138 udp netbios-dgm closed
295969.163.233.4 139 tcp netbios-ssn closed
296069.163.233.4 139 udp netbios-ssn unknown
296169.163.233.4 161 tcp snmp closed
296269.163.233.4 161 udp snmp closed
296369.163.233.4 162 tcp snmptrap closed
296469.163.233.4 162 udp snmptrap closed
296569.163.233.4 389 tcp ldap closed
296669.163.233.4 389 udp ldap unknown
296769.163.233.4 520 tcp efs closed
296869.163.233.4 520 udp route closed
296969.163.233.4 2049 tcp nfs closed
297069.163.233.4 2049 udp nfs unknown
297174.117.180.192 21 tcp ftp filtered 220 Hello.\x0d\x0a
297274.117.180.192 22 tcp ssh filtered
297374.117.180.192 25 tcp smtp filtered
297474.117.180.192 53 tcp domain closed
297574.117.180.192 53 udp domain unknown
297674.117.180.192 67 tcp dhcps closed
297774.117.180.192 67 udp dhcps unknown
297874.117.180.192 68 tcp dhcpc closed
297974.117.180.192 68 udp dhcpc closed
298074.117.180.192 69 tcp tftp closed
298174.117.180.192 69 udp tftp closed
298274.117.180.192 80 tcp http filtered
298374.117.180.192 88 tcp kerberos-sec closed
298474.117.180.192 88 udp kerberos-sec closed
298574.117.180.192 110 tcp pop3 filtered
298674.117.180.192 111 tcp rpcbind filtered
298774.117.180.192 123 tcp ntp closed
298874.117.180.192 123 udp ntp unknown
298974.117.180.192 137 tcp netbios-ns closed
299074.117.180.192 137 udp netbios-ns closed
299174.117.180.192 138 tcp netbios-dgm closed
299274.117.180.192 138 udp netbios-dgm unknown
299374.117.180.192 139 tcp netbios-ssn closed
299474.117.180.192 139 udp netbios-ssn unknown
299574.117.180.192 143 tcp imap filtered
299674.117.180.192 161 tcp snmp closed
299774.117.180.192 161 udp snmp closed
299874.117.180.192 162 tcp snmptrap closed
299974.117.180.192 162 udp snmptrap unknown
300074.117.180.192 323 tcp rpki-rtr filtered
300174.117.180.192 389 tcp ldap closed
300274.117.180.192 389 udp ldap closed
300374.117.180.192 443 tcp https filtered
300474.117.180.192 465 tcp ssl/smtp open Exim smtpd 4.92.3
300574.117.180.192 520 tcp efs closed
300674.117.180.192 520 udp route unknown
300774.117.180.192 587 tcp submission filtered
300874.117.180.192 873 tcp rsync filtered
300974.117.180.192 993 tcp imaps filtered
301074.117.180.192 995 tcp pop3s filtered
301174.117.180.192 2049 tcp nfs closed
301274.117.180.192 2049 udp nfs closed
301374.117.180.192 2525 tcp smtp open Exim smtpd
301474.117.180.192 3306 tcp mysql filtered
301574.117.180.192 4949 tcp tcpwrapped open
301674.117.180.192 5666 tcp tcpwrapped open
301774.117.180.192 6380 tcp filtered
301874.117.180.192 9306 tcp sphinx-search open Sphinx Search daemon 2.1.5-id64-release
301974.117.180.192 11211 tcp memcache filtered
302082.94.222.131 53 udp domain unknown
302182.94.222.131 67 udp dhcps unknown
302282.94.222.131 68 udp dhcpc unknown
302382.94.222.131 69 udp tftp unknown
302482.94.222.131 88 udp kerberos-sec unknown
302582.94.222.131 123 udp ntp unknown
302682.94.222.131 137 udp netbios-ns unknown
302782.94.222.131 138 udp netbios-dgm unknown
302882.94.222.131 139 udp netbios-ssn unknown
302982.94.222.131 161 udp snmp unknown
303082.94.222.131 162 udp snmptrap unknown
303182.94.222.131 389 udp ldap unknown
303282.94.222.131 520 udp route unknown
303382.94.222.131 2049 udp nfs unknown
303482.94.222.134 53 udp domain unknown
303582.94.222.134 67 udp dhcps unknown
303682.94.222.134 68 udp dhcpc unknown
303782.94.222.134 69 udp tftp unknown
303882.94.222.134 88 udp kerberos-sec unknown
303982.94.222.134 123 udp ntp unknown
304082.94.222.134 137 udp netbios-ns unknown
304182.94.222.134 138 udp netbios-dgm unknown
304282.94.222.134 139 udp netbios-ssn unknown
304382.94.222.134 161 udp snmp unknown
304482.94.222.134 162 udp snmptrap unknown
304582.94.222.134 389 udp ldap unknown
304682.94.222.134 520 udp route unknown
304782.94.222.134 2049 udp nfs unknown
304882.94.228.245 53 tcp domain filtered
304982.94.228.245 53 udp domain unknown
305082.94.228.245 67 tcp dhcps filtered
305182.94.228.245 67 udp dhcps unknown
305282.94.228.245 68 tcp dhcpc filtered
305382.94.228.245 68 udp dhcpc unknown
305482.94.228.245 69 tcp tftp filtered
305582.94.228.245 69 udp tftp unknown
305682.94.228.245 80 tcp http open nginx
305782.94.228.245 88 tcp kerberos-sec filtered
305882.94.228.245 88 udp kerberos-sec unknown
305982.94.228.245 122 tcp ssh open OpenSSH 6.0p1 Debian 4+deb7u7 protocol 2.0
306082.94.228.245 123 tcp ntp filtered
306182.94.228.245 123 udp ntp unknown
306282.94.228.245 137 tcp netbios-ns filtered
306382.94.228.245 137 udp netbios-ns unknown
306482.94.228.245 138 tcp netbios-dgm filtered
306582.94.228.245 138 udp netbios-dgm unknown
306682.94.228.245 139 tcp netbios-ssn filtered
306782.94.228.245 139 udp netbios-ssn unknown
306882.94.228.245 161 tcp snmp filtered
306982.94.228.245 161 udp snmp unknown
307082.94.228.245 162 tcp snmptrap filtered
307182.94.228.245 162 udp snmptrap unknown
307282.94.228.245 389 tcp ldap filtered
307382.94.228.245 389 udp ldap unknown
307482.94.228.245 443 tcp ssl/http open nginx
307582.94.228.245 520 tcp efs filtered
307682.94.228.245 520 udp route unknown
307782.94.228.245 2049 tcp nfs filtered
307882.94.228.245 2049 udp nfs unknown
307982.94.228.245 38754 tcp ssh open OpenSSH 6.0p1 Debian 4+deb7u7 protocol 2.0
308089.248.172.178 21 tcp ftp open ProFTPD or KnFTPD
308189.248.172.178 53 tcp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
308289.248.172.178 53 udp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
308389.248.172.178 67 tcp dhcps filtered
308489.248.172.178 67 udp dhcps unknown
308589.248.172.178 68 tcp dhcpc filtered
308689.248.172.178 68 udp dhcpc unknown
308789.248.172.178 69 tcp tftp filtered
308889.248.172.178 69 udp tftp unknown
308989.248.172.178 80 tcp http open nginx 1.16.1
309089.248.172.178 88 tcp kerberos-sec filtered
309189.248.172.178 88 udp kerberos-sec unknown
309289.248.172.178 123 tcp ntp filtered
309389.248.172.178 123 udp ntp unknown
309489.248.172.178 137 tcp netbios-ns filtered
309589.248.172.178 137 udp netbios-ns unknown
309689.248.172.178 138 tcp netbios-dgm filtered
309789.248.172.178 138 udp netbios-dgm unknown
309889.248.172.178 139 tcp netbios-ssn filtered
309989.248.172.178 139 udp netbios-ssn unknown
310089.248.172.178 161 tcp snmp filtered
310189.248.172.178 161 udp snmp unknown
310289.248.172.178 162 tcp snmptrap filtered
310389.248.172.178 162 udp snmptrap unknown
310489.248.172.178 389 tcp ldap filtered
310589.248.172.178 389 udp ldap unknown
310689.248.172.178 520 tcp efs filtered
310789.248.172.178 520 udp route unknown
310889.248.172.178 2049 tcp nfs filtered
310989.248.172.178 2049 udp nfs unknown
311089.248.172.178 10050 tcp tcpwrapped open
311192.123.250.35 53 tcp domain closed
311292.123.250.35 53 udp domain closed
311392.123.250.35 67 tcp dhcps filtered
311492.123.250.35 67 udp dhcps unknown
311592.123.250.35 68 tcp dhcpc filtered
311692.123.250.35 68 udp dhcpc unknown
311792.123.250.35 69 tcp tftp filtered
311892.123.250.35 69 udp tftp unknown
311992.123.250.35 80 tcp http open AkamaiGHost Akamai's HTTP Acceleration/Mirror service
312092.123.250.35 88 tcp kerberos-sec filtered
312192.123.250.35 88 udp kerberos-sec unknown
312292.123.250.35 123 tcp ntp filtered
312392.123.250.35 123 udp ntp unknown
312492.123.250.35 137 tcp netbios-ns filtered
312592.123.250.35 137 udp netbios-ns unknown
312692.123.250.35 138 tcp netbios-dgm filtered
312792.123.250.35 138 udp netbios-dgm unknown
312892.123.250.35 139 tcp netbios-ssn filtered
312992.123.250.35 139 udp netbios-ssn unknown
313092.123.250.35 161 tcp snmp filtered
313192.123.250.35 161 udp snmp unknown
313292.123.250.35 162 tcp snmptrap filtered
313392.123.250.35 162 udp snmptrap unknown
313492.123.250.35 389 tcp ldap filtered
313592.123.250.35 389 udp ldap unknown
313692.123.250.35 443 tcp ssl/https open
313792.123.250.35 520 tcp efs filtered
313892.123.250.35 520 udp route unknown
313992.123.250.35 2049 tcp nfs filtered
314092.123.250.35 2049 udp nfs unknown
314192.123.250.35 8883 tcp secure-mqtt open
314292.123.250.65 53 tcp domain filtered
314392.123.250.65 53 udp domain unknown
314492.123.250.65 67 tcp dhcps filtered
314592.123.250.65 67 udp dhcps unknown
314692.123.250.65 68 tcp dhcpc filtered
314792.123.250.65 68 udp dhcpc unknown
314892.123.250.65 69 tcp tftp filtered
314992.123.250.65 69 udp tftp unknown
315092.123.250.65 80 tcp http open AkamaiGHost Akamai's HTTP Acceleration/Mirror service
315192.123.250.65 88 tcp kerberos-sec filtered
315292.123.250.65 88 udp kerberos-sec unknown
315392.123.250.65 123 tcp ntp filtered
315492.123.250.65 123 udp ntp unknown
315592.123.250.65 137 tcp netbios-ns filtered
315692.123.250.65 137 udp netbios-ns unknown
315792.123.250.65 138 tcp netbios-dgm filtered
315892.123.250.65 138 udp netbios-dgm unknown
315992.123.250.65 139 tcp netbios-ssn filtered
316092.123.250.65 139 udp netbios-ssn unknown
316192.123.250.65 161 tcp snmp filtered
316292.123.250.65 161 udp snmp unknown
316392.123.250.65 162 tcp snmptrap filtered
316492.123.250.65 162 udp snmptrap unknown
316592.123.250.65 389 tcp ldap filtered
316692.123.250.65 389 udp ldap unknown
316792.123.250.65 443 tcp ssl/https open
316892.123.250.65 520 tcp efs filtered
316992.123.250.65 520 udp route unknown
317092.123.250.65 2049 tcp nfs filtered
317192.123.250.65 2049 udp nfs unknown
317292.123.250.65 8883 tcp secure-mqtt open
317394.102.51.111 22 tcp ssh open
317494.102.51.111 25 tcp smtp open Exim smtpd 4.89
317594.102.51.111 53 tcp domain open ISC BIND 9.9.4 RedHat Enterprise Linux 7
317694.102.51.111 53 udp domain open ISC BIND 9.9.4 RedHat Enterprise Linux 7
317794.102.51.111 67 tcp dhcps filtered
317894.102.51.111 67 udp dhcps unknown
317994.102.51.111 68 tcp dhcpc filtered
318094.102.51.111 68 udp dhcpc unknown
318194.102.51.111 69 tcp tftp filtered
318294.102.51.111 69 udp tftp unknown
318394.102.51.111 80 tcp http open nginx
318494.102.51.111 88 tcp kerberos-sec filtered
318594.102.51.111 88 udp kerberos-sec unknown
318694.102.51.111 110 tcp pop3 open Dovecot pop3d
318794.102.51.111 123 tcp ntp filtered
318894.102.51.111 123 udp ntp unknown
318994.102.51.111 137 tcp netbios-ns filtered
319094.102.51.111 137 udp netbios-ns unknown
319194.102.51.111 138 tcp netbios-dgm filtered
319294.102.51.111 138 udp netbios-dgm unknown
319394.102.51.111 139 tcp netbios-ssn filtered
319494.102.51.111 139 udp netbios-ssn unknown
319594.102.51.111 143 tcp imap open Dovecot imapd
319694.102.51.111 161 tcp snmp filtered
319794.102.51.111 161 udp snmp unknown
319894.102.51.111 162 tcp snmptrap filtered
319994.102.51.111 162 udp snmptrap unknown
320094.102.51.111 389 tcp ldap filtered
320194.102.51.111 389 udp ldap unknown
320294.102.51.111 465 tcp ssl/smtp open Exim smtpd 4.89
320394.102.51.111 520 tcp efs filtered
320494.102.51.111 520 udp route unknown
320594.102.51.111 993 tcp ssl/imaps open
320694.102.51.111 995 tcp ssl/pop3s open
320794.102.51.111 2049 tcp nfs filtered
320894.102.51.111 2049 udp nfs unknown
320994.102.51.112 22 tcp ssh open
321094.102.51.112 25 tcp smtp open Exim smtpd 4.89
321194.102.51.112 53 tcp domain open ISC BIND 9.9.4 RedHat Enterprise Linux 7
321294.102.51.112 53 udp domain open ISC BIND 9.9.4 RedHat Enterprise Linux 7
321394.102.51.112 67 tcp dhcps filtered
321494.102.51.112 67 udp dhcps unknown
321594.102.51.112 68 tcp dhcpc filtered
321694.102.51.112 68 udp dhcpc unknown
321794.102.51.112 69 tcp tftp filtered
321894.102.51.112 69 udp tftp unknown
321994.102.51.112 80 tcp http open nginx
322094.102.51.112 88 tcp kerberos-sec filtered
322194.102.51.112 88 udp kerberos-sec unknown
322294.102.51.112 110 tcp pop3 open Dovecot pop3d
322394.102.51.112 123 tcp ntp filtered
322494.102.51.112 123 udp ntp unknown
322594.102.51.112 137 tcp netbios-ns filtered
322694.102.51.112 137 udp netbios-ns unknown
322794.102.51.112 138 tcp netbios-dgm filtered
322894.102.51.112 138 udp netbios-dgm unknown
322994.102.51.112 139 tcp netbios-ssn filtered
323094.102.51.112 139 udp netbios-ssn unknown
323194.102.51.112 143 tcp imap open Dovecot imapd
323294.102.51.112 161 tcp snmp filtered
323394.102.51.112 161 udp snmp unknown
323494.102.51.112 162 tcp snmptrap filtered
323594.102.51.112 162 udp snmptrap unknown
323694.102.51.112 389 tcp ldap filtered
323794.102.51.112 389 udp ldap unknown
323894.102.51.112 465 tcp ssl/smtp open Exim smtpd 4.89
323994.102.51.112 520 tcp efs filtered
324094.102.51.112 520 udp route unknown
324194.102.51.112 993 tcp ssl/imaps open
324294.102.51.112 995 tcp ssl/pop3s open
324394.102.51.112 2049 tcp nfs filtered
324494.102.51.112 2049 udp nfs unknown
3245104.244.73.40 53 udp domain unknown
3246104.244.73.40 67 udp dhcps unknown
3247104.244.73.40 68 udp dhcpc unknown
3248104.244.73.40 69 udp tftp unknown
3249104.244.73.40 88 udp kerberos-sec unknown
3250104.244.73.40 123 udp ntp unknown
3251104.244.73.40 137 udp netbios-ns unknown
3252104.244.73.40 138 udp netbios-dgm unknown
3253104.244.73.40 139 udp netbios-ssn unknown
3254104.244.73.40 161 udp snmp unknown
3255104.244.73.40 162 udp snmptrap unknown
3256104.244.73.40 389 udp ldap unknown
3257104.244.73.40 520 udp route unknown
3258104.244.73.40 2049 udp nfs unknown
3259104.244.76.231 53 tcp domain filtered
3260104.244.76.231 53 udp domain unknown
3261104.244.76.231 67 tcp dhcps filtered
3262104.244.76.231 67 udp dhcps unknown
3263104.244.76.231 68 tcp dhcpc filtered
3264104.244.76.231 68 udp dhcpc unknown
3265104.244.76.231 69 tcp tftp filtered
3266104.244.76.231 69 udp tftp unknown
3267104.244.76.231 80 tcp http open nginx
3268104.244.76.231 88 tcp kerberos-sec filtered
3269104.244.76.231 88 udp kerberos-sec unknown
3270104.244.76.231 123 tcp ntp filtered
3271104.244.76.231 123 udp ntp unknown
3272104.244.76.231 137 tcp netbios-ns filtered
3273104.244.76.231 137 udp netbios-ns unknown
3274104.244.76.231 138 tcp netbios-dgm filtered
3275104.244.76.231 138 udp netbios-dgm unknown
3276104.244.76.231 139 tcp netbios-ssn filtered
3277104.244.76.231 139 udp netbios-ssn unknown
3278104.244.76.231 161 tcp snmp filtered
3279104.244.76.231 161 udp snmp unknown
3280104.244.76.231 162 tcp snmptrap filtered
3281104.244.76.231 162 udp snmptrap unknown
3282104.244.76.231 389 tcp ldap filtered
3283104.244.76.231 389 udp ldap unknown
3284104.244.76.231 443 tcp ssl/http open nginx
3285104.244.76.231 520 tcp efs filtered
3286104.244.76.231 520 udp route unknown
3287104.244.76.231 2049 tcp nfs filtered
3288104.244.76.231 2049 udp nfs unknown
3289104.244.76.231 5040 tcp unknown closed
3290104.244.76.231 16001 tcp ssl/http open MiniServ 1.910 Webmin httpd
3291104.244.76.231 16221 tcp closed
3292104.244.76.231 23022 tcp closed
3293104.244.76.231 32022 tcp ssh open OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 Ubuntu Linux; protocol 2.0
3294104.244.77.188 53 tcp domain filtered
3295104.244.77.188 53 udp domain unknown
3296104.244.77.188 67 tcp dhcps filtered
3297104.244.77.188 67 udp dhcps unknown
3298104.244.77.188 68 tcp dhcpc filtered
3299104.244.77.188 68 udp dhcpc unknown
3300104.244.77.188 69 tcp tftp filtered
3301104.244.77.188 69 udp tftp unknown
3302104.244.77.188 80 tcp http open nginx
3303104.244.77.188 88 tcp kerberos-sec filtered
3304104.244.77.188 88 udp kerberos-sec unknown
3305104.244.77.188 123 tcp ntp filtered
3306104.244.77.188 123 udp ntp unknown
3307104.244.77.188 137 tcp netbios-ns filtered
3308104.244.77.188 137 udp netbios-ns unknown
3309104.244.77.188 138 tcp netbios-dgm filtered
3310104.244.77.188 138 udp netbios-dgm unknown
3311104.244.77.188 139 tcp netbios-ssn filtered
3312104.244.77.188 139 udp netbios-ssn unknown
3313104.244.77.188 161 tcp snmp filtered
3314104.244.77.188 161 udp snmp unknown
3315104.244.77.188 162 tcp snmptrap filtered
3316104.244.77.188 162 udp snmptrap unknown
3317104.244.77.188 389 tcp ldap filtered
3318104.244.77.188 389 udp ldap unknown
3319104.244.77.188 443 tcp ssl/http open nginx
3320104.244.77.188 520 tcp efs filtered
3321104.244.77.188 520 udp route unknown
3322104.244.77.188 2049 tcp nfs filtered
3323104.244.77.188 2049 udp nfs unknown
3324104.244.77.188 5040 tcp unknown closed
3325104.244.77.188 16001 tcp ssl/http open MiniServ 1.910 Webmin httpd
3326104.244.77.188 16221 tcp closed
3327104.244.77.188 23022 tcp closed
3328104.244.77.188 32022 tcp ssh open OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 Ubuntu Linux; protocol 2.0
3329104.244.79.89 53 tcp domain filtered
3330104.244.79.89 53 udp domain unknown
3331104.244.79.89 67 tcp dhcps filtered
3332104.244.79.89 67 udp dhcps unknown
3333104.244.79.89 68 tcp dhcpc filtered
3334104.244.79.89 68 udp dhcpc unknown
3335104.244.79.89 69 tcp tftp filtered
3336104.244.79.89 69 udp tftp unknown
3337104.244.79.89 80 tcp http open nginx
3338104.244.79.89 88 tcp kerberos-sec filtered
3339104.244.79.89 88 udp kerberos-sec unknown
3340104.244.79.89 123 tcp ntp filtered
3341104.244.79.89 123 udp ntp unknown
3342104.244.79.89 137 tcp netbios-ns filtered
3343104.244.79.89 137 udp netbios-ns unknown
3344104.244.79.89 138 tcp netbios-dgm filtered
3345104.244.79.89 138 udp netbios-dgm unknown
3346104.244.79.89 139 tcp netbios-ssn filtered
3347104.244.79.89 139 udp netbios-ssn unknown
3348104.244.79.89 161 tcp snmp filtered
3349104.244.79.89 161 udp snmp unknown
3350104.244.79.89 162 tcp snmptrap filtered
3351104.244.79.89 162 udp snmptrap unknown
3352104.244.79.89 389 tcp ldap filtered
3353104.244.79.89 389 udp ldap unknown
3354104.244.79.89 443 tcp ssl/http open nginx
3355104.244.79.89 520 tcp efs filtered
3356104.244.79.89 520 udp route unknown
3357104.244.79.89 2049 tcp nfs filtered
3358104.244.79.89 2049 udp nfs unknown
3359104.244.79.89 7910 tcp ssl/http open nginx
3360104.244.79.89 7920 tcp unknown closed
3361104.244.79.89 7930 tcp closed
3362104.244.79.89 16001 tcp http open MiniServ 1.930 Webmin httpd
3363104.244.79.89 16010 tcp ssl/http open nginx
3364104.244.79.89 16221 tcp ssh open OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 Ubuntu Linux; protocol 2.0
3365104.244.79.89 32022 tcp ssh open OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 Ubuntu Linux; protocol 2.0
3366107.180.28.114 21 tcp ftp open 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------\x0d\x0a220-You are user number 3 of 500 allowed.\x0d\x0a220-Local time is now 05:54. Server port: 21.\x0d\x0a220-This is a private system - No anonymous login\x0d\x0a220 You will be disconnected after 15 minutes of inactivity.\x0d\x0a
3367107.180.28.114 22 tcp ssh open SSH-2.0-OpenSSH_5.3
3368107.180.28.114 53 tcp domain filtered
3369107.180.28.114 53 udp domain unknown
3370107.180.28.114 67 tcp dhcps filtered
3371107.180.28.114 67 udp dhcps unknown
3372107.180.28.114 68 tcp dhcpc filtered
3373107.180.28.114 68 udp dhcpc unknown
3374107.180.28.114 69 tcp tftp filtered
3375107.180.28.114 69 udp tftp unknown
3376107.180.28.114 88 tcp kerberos-sec filtered
3377107.180.28.114 88 udp kerberos-sec unknown
3378107.180.28.114 123 tcp ntp filtered
3379107.180.28.114 123 udp ntp unknown
3380107.180.28.114 137 tcp netbios-ns filtered
3381107.180.28.114 137 udp netbios-ns unknown
3382107.180.28.114 138 tcp netbios-dgm filtered
3383107.180.28.114 138 udp netbios-dgm unknown
3384107.180.28.114 139 tcp netbios-ssn filtered
3385107.180.28.114 139 udp netbios-ssn unknown
3386107.180.28.114 161 tcp snmp filtered
3387107.180.28.114 161 udp snmp unknown
3388107.180.28.114 162 tcp snmptrap filtered
3389107.180.28.114 162 udp snmptrap unknown
3390107.180.28.114 389 tcp ldap filtered
3391107.180.28.114 389 udp ldap unknown
3392107.180.28.114 520 tcp efs filtered
3393107.180.28.114 520 udp route unknown
3394107.180.28.114 2049 tcp nfs filtered
3395107.180.28.114 2049 udp nfs unknown
3396111.90.145.39 21 tcp ftp open 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------\x0d\x0a220-You are user number 1 of 50 allowed.\x0d\x0a220-Local time is now 15:04. Server port: 21.\x0d\x0a220-This is a private system - No anonymous login\x0d\x0a220-IPv6 connections are also welcome on this server.\x0d\x0a220 You will be disconnected after 15 minutes of inactivity.\x0d\x0a
3397111.90.145.39 53 tcp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
3398111.90.145.39 53 udp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
3399111.90.145.39 67 tcp dhcps closed
3400111.90.145.39 67 udp dhcps closed
3401111.90.145.39 68 tcp dhcpc closed
3402111.90.145.39 68 udp dhcpc unknown
3403111.90.145.39 69 tcp tftp closed
3404111.90.145.39 69 udp tftp unknown
3405111.90.145.39 88 tcp kerberos-sec closed
3406111.90.145.39 88 udp kerberos-sec unknown
3407111.90.145.39 123 tcp ntp closed
3408111.90.145.39 123 udp ntp closed
3409111.90.145.39 137 tcp netbios-ns closed
3410111.90.145.39 137 udp netbios-ns unknown
3411111.90.145.39 138 tcp netbios-dgm closed
3412111.90.145.39 138 udp netbios-dgm unknown
3413111.90.145.39 139 tcp netbios-ssn filtered
3414111.90.145.39 139 udp netbios-ssn closed
3415111.90.145.39 161 tcp snmp closed
3416111.90.145.39 161 udp snmp unknown
3417111.90.145.39 162 tcp snmptrap closed
3418111.90.145.39 162 udp snmptrap closed
3419111.90.145.39 389 tcp ldap closed
3420111.90.145.39 389 udp ldap unknown
3421111.90.145.39 520 tcp efs closed
3422111.90.145.39 520 udp route closed
3423111.90.145.39 2049 tcp nfs closed
3424111.90.145.39 2049 udp nfs closed
3425143.95.110.248 21 tcp ftp open 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------\x0d\x0a220-You are user number 1 of 150 allowed.\x0d\x0a220-Local time is now 05:55. Server port: 21.\x0d\x0a220-IPv6 connections are also welcome on this server.\x0d\x0a220 You will be disconnected after 15 minutes of inactivity.\x0d\x0a
3426143.95.110.248 53 tcp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
3427143.95.110.248 53 udp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
3428143.95.110.248 67 tcp dhcps closed
3429143.95.110.248 67 udp dhcps unknown
3430143.95.110.248 68 tcp dhcpc closed
3431143.95.110.248 68 udp dhcpc unknown
3432143.95.110.248 69 tcp tftp closed
3433143.95.110.248 69 udp tftp unknown
3434143.95.110.248 88 tcp kerberos-sec closed
3435143.95.110.248 88 udp kerberos-sec unknown
3436143.95.110.248 123 tcp ntp closed
3437143.95.110.248 123 udp ntp unknown
3438143.95.110.248 137 tcp netbios-ns closed
3439143.95.110.248 137 udp netbios-ns unknown
3440143.95.110.248 138 tcp netbios-dgm closed
3441143.95.110.248 138 udp netbios-dgm closed
3442143.95.110.248 139 tcp netbios-ssn closed
3443143.95.110.248 139 udp netbios-ssn unknown
3444143.95.110.248 161 tcp snmp closed
3445143.95.110.248 161 udp snmp closed
3446143.95.110.248 162 tcp snmptrap closed
3447143.95.110.248 162 udp snmptrap unknown
3448143.95.110.248 389 tcp ldap closed
3449143.95.110.248 389 udp ldap closed
3450143.95.110.248 520 tcp efs closed
3451143.95.110.248 520 udp route unknown
3452143.95.110.248 2049 tcp nfs closed
3453143.95.110.248 2049 udp nfs unknown
3454146.83.222.104 53 tcp domain filtered
3455146.83.222.104 53 udp domain unknown
3456146.83.222.104 67 tcp dhcps filtered
3457146.83.222.104 67 udp dhcps unknown
3458146.83.222.104 68 tcp dhcpc filtered
3459146.83.222.104 68 udp dhcpc unknown
3460146.83.222.104 69 tcp tftp filtered
3461146.83.222.104 69 udp tftp filtered
3462146.83.222.104 88 tcp kerberos-sec filtered
3463146.83.222.104 88 udp kerberos-sec unknown
3464146.83.222.104 123 tcp ntp filtered
3465146.83.222.104 123 udp ntp unknown
3466146.83.222.104 137 tcp netbios-ns filtered
3467146.83.222.104 137 udp netbios-ns unknown
3468146.83.222.104 138 tcp netbios-dgm filtered
3469146.83.222.104 138 udp netbios-dgm unknown
3470146.83.222.104 139 tcp netbios-ssn filtered
3471146.83.222.104 139 udp netbios-ssn unknown
3472146.83.222.104 161 tcp snmp filtered
3473146.83.222.104 161 udp snmp unknown
3474146.83.222.104 162 tcp snmptrap filtered
3475146.83.222.104 162 udp snmptrap unknown
3476146.83.222.104 389 tcp ldap filtered
3477146.83.222.104 389 udp ldap unknown
3478146.83.222.104 520 tcp efs filtered
3479146.83.222.104 520 udp route unknown
3480146.83.222.104 2049 tcp nfs filtered
3481146.83.222.104 2049 udp nfs unknown
3482149.126.72.220 25 tcp smtp closed
3483149.126.72.220 51 tcp tcpwrapped open
3484149.126.72.220 53 tcp domain open
3485149.126.72.220 53 udp domain open
3486149.126.72.220 65 tcp tcpwrapped open
3487149.126.72.220 66 tcp tcpwrapped open
3488149.126.72.220 67 tcp dhcps filtered
3489149.126.72.220 67 udp dhcps unknown
3490149.126.72.220 68 tcp dhcpc filtered
3491149.126.72.220 68 udp dhcpc unknown
3492149.126.72.220 69 tcp tftp filtered
3493149.126.72.220 69 udp tftp unknown
3494149.126.72.220 80 tcp tcpwrapped open
3495149.126.72.220 81 tcp tcpwrapped open
3496149.126.72.220 82 tcp tcpwrapped open
3497149.126.72.220 83 tcp tcpwrapped open
3498149.126.72.220 84 tcp tcpwrapped open
3499149.126.72.220 85 tcp tcpwrapped open
3500149.126.72.220 86 tcp tcpwrapped open
3501149.126.72.220 88 tcp http open Incapsula CDN httpd
3502149.126.72.220 88 udp kerberos-sec unknown
3503149.126.72.220 89 tcp tcpwrapped open
3504149.126.72.220 90 tcp tcpwrapped open
3505149.126.72.220 91 tcp tcpwrapped open
3506149.126.72.220 92 tcp tcpwrapped open
3507149.126.72.220 98 tcp tcpwrapped open
3508149.126.72.220 99 tcp tcpwrapped open
3509149.126.72.220 123 tcp ntp filtered
3510149.126.72.220 123 udp ntp unknown
3511149.126.72.220 137 tcp netbios-ns filtered
3512149.126.72.220 137 udp netbios-ns filtered
3513149.126.72.220 138 tcp netbios-dgm filtered
3514149.126.72.220 138 udp netbios-dgm filtered
3515149.126.72.220 139 tcp netbios-ssn closed
3516149.126.72.220 139 udp netbios-ssn unknown
3517149.126.72.220 160 tcp sgmp-traps closed
3518149.126.72.220 161 tcp snmp filtered
3519149.126.72.220 161 udp snmp unknown
3520149.126.72.220 162 tcp snmptrap filtered
3521149.126.72.220 162 udp snmptrap unknown
3522149.126.72.220 189 tcp tcpwrapped open
3523149.126.72.220 190 tcp tcpwrapped open
3524149.126.72.220 192 tcp tcpwrapped open
3525149.126.72.220 243 tcp tcpwrapped open
3526149.126.72.220 285 tcp tcpwrapped open
3527149.126.72.220 314 tcp tcpwrapped open
3528149.126.72.220 343 tcp tcpwrapped open
3529149.126.72.220 347 tcp tcpwrapped open
3530149.126.72.220 385 tcp tcpwrapped open
3531149.126.72.220 389 tcp ssl/http open Incapsula CDN httpd
3532149.126.72.220 389 udp ldap unknown
3533149.126.72.220 400 tcp tcpwrapped open
3534149.126.72.220 440 tcp tcpwrapped open
3535149.126.72.220 441 tcp tcpwrapped open
3536149.126.72.220 442 tcp tcpwrapped open
3537149.126.72.220 443 tcp ssl/tcpwrapped open
3538149.126.72.220 444 tcp tcpwrapped open
3539149.126.72.220 445 tcp microsoft-ds closed
3540149.126.72.220 446 tcp tcpwrapped open
3541149.126.72.220 447 tcp tcpwrapped open
3542149.126.72.220 448 tcp tcpwrapped open
3543149.126.72.220 449 tcp tcpwrapped open
3544149.126.72.220 452 tcp tcpwrapped open
3545149.126.72.220 461 tcp tcpwrapped open
3546149.126.72.220 462 tcp tcpwrapped open
3547149.126.72.220 480 tcp tcpwrapped open
3548149.126.72.220 485 tcp tcpwrapped open
3549149.126.72.220 487 tcp tcpwrapped open
3550149.126.72.220 488 tcp tcpwrapped open
3551149.126.72.220 491 tcp tcpwrapped open
3552149.126.72.220 520 tcp efs filtered
3553149.126.72.220 520 udp route unknown
3554149.126.72.220 555 tcp tcpwrapped open
3555149.126.72.220 556 tcp tcpwrapped open
3556149.126.72.220 587 tcp tcpwrapped open
3557149.126.72.220 631 tcp tcpwrapped open
3558149.126.72.220 632 tcp tcpwrapped open
3559149.126.72.220 636 tcp tcpwrapped open
3560149.126.72.220 743 tcp tcpwrapped open
3561149.126.72.220 772 tcp tcpwrapped open
3562149.126.72.220 777 tcp tcpwrapped open
3563149.126.72.220 782 tcp tcpwrapped open
3564149.126.72.220 785 tcp tcpwrapped open
3565149.126.72.220 800 tcp tcpwrapped open
3566149.126.72.220 801 tcp tcpwrapped open
3567149.126.72.220 805 tcp tcpwrapped open
3568149.126.72.220 806 tcp tcpwrapped open
3569149.126.72.220 809 tcp tcpwrapped open
3570149.126.72.220 843 tcp tcpwrapped open
3571149.126.72.220 853 tcp tcpwrapped open
3572149.126.72.220 885 tcp tcpwrapped open
3573149.126.72.220 886 tcp tcpwrapped open
3574149.126.72.220 887 tcp tcpwrapped open
3575149.126.72.220 888 tcp tcpwrapped open
3576149.126.72.220 943 tcp tcpwrapped open
3577149.126.72.220 947 tcp tcpwrapped open
3578149.126.72.220 953 tcp tcpwrapped open
3579149.126.72.220 990 tcp tcpwrapped open
3580149.126.72.220 995 tcp tcpwrapped open
3581149.126.72.220 998 tcp tcpwrapped open
3582149.126.72.220 999 tcp tcpwrapped open
3583149.126.72.220 1000 tcp tcpwrapped open
3584149.126.72.220 1002 tcp tcpwrapped open
3585149.126.72.220 1024 tcp tcpwrapped open
3586149.126.72.220 1025 tcp tcpwrapped open
3587149.126.72.220 1028 tcp tcpwrapped open
3588149.126.72.220 1080 tcp tcpwrapped open
3589149.126.72.220 1103 tcp tcpwrapped open
3590149.126.72.220 1111 tcp tcpwrapped open
3591149.126.72.220 1180 tcp tcpwrapped open
3592149.126.72.220 1181 tcp tcpwrapped open
3593149.126.72.220 1207 tcp tcpwrapped open
3594149.126.72.220 1234 tcp tcpwrapped open
3595149.126.72.220 1250 tcp tcpwrapped open
3596149.126.72.220 1283 tcp tcpwrapped open
3597149.126.72.220 1291 tcp tcpwrapped open
3598149.126.72.220 1292 tcp tcpwrapped open
3599149.126.72.220 1293 tcp tcpwrapped open
3600149.126.72.220 1337 tcp tcpwrapped open
3601149.126.72.220 1344 tcp tcpwrapped open
3602149.126.72.220 1355 tcp tcpwrapped open
3603149.126.72.220 1364 tcp tcpwrapped open
3604149.126.72.220 1366 tcp tcpwrapped open
3605149.126.72.220 1377 tcp tcpwrapped open
3606149.126.72.220 1387 tcp tcpwrapped open
3607149.126.72.220 1388 tcp tcpwrapped open
3608149.126.72.220 1433 tcp tcpwrapped open
3609149.126.72.220 1443 tcp tcpwrapped open
3610149.126.72.220 1447 tcp tcpwrapped open
3611149.126.72.220 1450 tcp tcpwrapped open
3612149.126.72.220 1451 tcp tcpwrapped open
3613149.126.72.220 1452 tcp tcpwrapped open
3614149.126.72.220 1453 tcp tcpwrapped open
3615149.126.72.220 1454 tcp tcpwrapped open
3616149.126.72.220 1455 tcp tcpwrapped open
3617149.126.72.220 1456 tcp tcpwrapped open
3618149.126.72.220 1457 tcp tcpwrapped open
3619149.126.72.220 1458 tcp tcpwrapped open
3620149.126.72.220 1459 tcp tcpwrapped open
3621149.126.72.220 1460 tcp tcpwrapped open
3622149.126.72.220 1494 tcp tcpwrapped open
3623149.126.72.220 1935 tcp tcpwrapped open
3624149.126.72.220 1950 tcp tcpwrapped open
3625149.126.72.220 1951 tcp tcpwrapped open
3626149.126.72.220 1952 tcp tcpwrapped open
3627149.126.72.220 1953 tcp tcpwrapped open
3628149.126.72.220 1954 tcp tcpwrapped open
3629149.126.72.220 1955 tcp tcpwrapped open
3630149.126.72.220 1956 tcp tcpwrapped open
3631149.126.72.220 1957 tcp tcpwrapped open
3632149.126.72.220 1958 tcp tcpwrapped open
3633149.126.72.220 1959 tcp tcpwrapped open
3634149.126.72.220 1960 tcp tcpwrapped open
3635149.126.72.220 1964 tcp tcpwrapped open
3636149.126.72.220 1965 tcp tcpwrapped open
3637149.126.72.220 1966 tcp tcpwrapped open
3638149.126.72.220 1967 tcp tcpwrapped open
3639149.126.72.220 1968 tcp tcpwrapped open
3640149.126.72.220 1969 tcp tcpwrapped open
3641149.126.72.220 1970 tcp tcpwrapped open
3642149.126.72.220 1971 tcp tcpwrapped open
3643149.126.72.220 1972 tcp tcpwrapped open
3644149.126.72.220 1973 tcp tcpwrapped open
3645149.126.72.220 1974 tcp tcpwrapped open
3646149.126.72.220 1975 tcp tcpwrapped open
3647149.126.72.220 1976 tcp tcpwrapped open
3648149.126.72.220 1977 tcp tcpwrapped open
3649149.126.72.220 1978 tcp tcpwrapped open
3650149.126.72.220 1979 tcp tcpwrapped open
3651149.126.72.220 1980 tcp tcpwrapped open
3652149.126.72.220 1981 tcp tcpwrapped open
3653149.126.72.220 1982 tcp tcpwrapped open
3654149.126.72.220 1983 tcp tcpwrapped open
3655149.126.72.220 1984 tcp tcpwrapped open
3656149.126.72.220 1985 tcp tcpwrapped open
3657149.126.72.220 1986 tcp tcpwrapped open
3658149.126.72.220 1987 tcp tcpwrapped open
3659149.126.72.220 1988 tcp tcpwrapped open
3660149.126.72.220 1989 tcp tcpwrapped open
3661149.126.72.220 2000 tcp tcpwrapped open
3662149.126.72.220 2001 tcp tcpwrapped open
3663149.126.72.220 2006 tcp tcpwrapped open
3664149.126.72.220 2012 tcp tcpwrapped open
3665149.126.72.220 2020 tcp tcpwrapped open
3666149.126.72.220 2048 tcp tcpwrapped open
3667149.126.72.220 2049 tcp http open Incapsula CDN httpd
3668149.126.72.220 2049 udp nfs unknown
3669149.126.72.220 2050 tcp tcpwrapped open
3670149.126.72.220 2051 tcp tcpwrapped open
3671149.126.72.220 2052 tcp tcpwrapped open
3672149.126.72.220 2053 tcp tcpwrapped open
3673149.126.72.220 2054 tcp tcpwrapped open
3674149.126.72.220 2055 tcp tcpwrapped open
3675149.126.72.220 2056 tcp tcpwrapped open
3676149.126.72.220 2057 tcp tcpwrapped open
3677149.126.72.220 2058 tcp tcpwrapped open
3678149.126.72.220 2059 tcp tcpwrapped open
3679149.126.72.220 2060 tcp tcpwrapped open
3680149.126.72.220 2061 tcp tcpwrapped open
3681149.126.72.220 2062 tcp tcpwrapped open
3682149.126.72.220 2063 tcp tcpwrapped open
3683149.126.72.220 2064 tcp tcpwrapped open
3684149.126.72.220 2065 tcp tcpwrapped open
3685149.126.72.220 2066 tcp tcpwrapped open
3686149.126.72.220 2067 tcp tcpwrapped open
3687149.126.72.220 2068 tcp tcpwrapped open
3688149.126.72.220 2069 tcp tcpwrapped open
3689149.126.72.220 2070 tcp tcpwrapped open
3690149.126.72.220 2072 tcp tcpwrapped open
3691149.126.72.220 2082 tcp tcpwrapped open
3692149.126.72.220 2083 tcp tcpwrapped open
3693149.126.72.220 2087 tcp tcpwrapped open
3694149.126.72.220 2096 tcp tcpwrapped open
3695149.126.72.220 2100 tcp tcpwrapped open
3696149.126.72.220 2108 tcp tcpwrapped open
3697149.126.72.220 2200 tcp tcpwrapped open
3698149.126.72.220 2209 tcp tcpwrapped open
3699149.126.72.220 2222 tcp tcpwrapped open
3700149.126.72.220 2226 tcp tcpwrapped open
3701149.126.72.220 2248 tcp tcpwrapped open
3702149.126.72.220 2344 tcp tcpwrapped open
3703149.126.72.220 2345 tcp tcpwrapped open
3704149.126.72.220 2353 tcp tcpwrapped open
3705149.126.72.220 2363 tcp tcpwrapped open
3706149.126.72.220 2423 tcp tcpwrapped open
3707149.126.72.220 2433 tcp tcpwrapped open
3708149.126.72.220 2435 tcp tcpwrapped open
3709149.126.72.220 2443 tcp tcpwrapped open
3710149.126.72.220 2453 tcp tcpwrapped open
3711149.126.72.220 2480 tcp tcpwrapped open
3712149.126.72.220 2548 tcp tcpwrapped open
3713149.126.72.220 2549 tcp tcpwrapped open
3714149.126.72.220 2550 tcp tcpwrapped open
3715149.126.72.220 2551 tcp tcpwrapped open
3716149.126.72.220 2552 tcp tcpwrapped open
3717149.126.72.220 2553 tcp tcpwrapped open
3718149.126.72.220 2554 tcp tcpwrapped open
3719149.126.72.220 2555 tcp tcpwrapped open
3720149.126.72.220 2556 tcp tcpwrapped open
3721149.126.72.220 2557 tcp tcpwrapped open
3722149.126.72.220 2558 tcp tcpwrapped open
3723149.126.72.220 2559 tcp tcpwrapped open
3724149.126.72.220 2560 tcp tcpwrapped open
3725149.126.72.220 2561 tcp tcpwrapped open
3726149.126.72.220 2562 tcp tcpwrapped open
3727149.126.72.220 2563 tcp tcpwrapped open
3728149.126.72.220 2566 tcp tcpwrapped open
3729149.126.72.220 2567 tcp tcpwrapped open
3730149.126.72.220 2568 tcp tcpwrapped open
3731149.126.72.220 2569 tcp tcpwrapped open
3732149.126.72.220 2570 tcp tcpwrapped open
3733149.126.72.220 2572 tcp tcpwrapped open
3734149.126.72.220 2598 tcp tcpwrapped open
3735149.126.72.220 2599 tcp tcpwrapped open
3736149.126.72.220 2850 tcp tcpwrapped open
3737149.126.72.220 2985 tcp tcpwrapped open
3738149.126.72.220 2995 tcp tcpwrapped open
3739149.126.72.220 3000 tcp tcpwrapped open
3740149.126.72.220 3001 tcp tcpwrapped open
3741149.126.72.220 3002 tcp tcpwrapped open
3742149.126.72.220 3003 tcp tcpwrapped open
3743149.126.72.220 3004 tcp tcpwrapped open
3744149.126.72.220 3005 tcp tcpwrapped open
3745149.126.72.220 3006 tcp tcpwrapped open
3746149.126.72.220 3007 tcp tcpwrapped open
3747149.126.72.220 3008 tcp tcpwrapped open
3748149.126.72.220 3009 tcp tcpwrapped open
3749149.126.72.220 3010 tcp tcpwrapped open
3750149.126.72.220 3011 tcp tcpwrapped open
3751149.126.72.220 3012 tcp tcpwrapped open
3752149.126.72.220 3013 tcp tcpwrapped open
3753149.126.72.220 3014 tcp tcpwrapped open
3754149.126.72.220 3015 tcp tcpwrapped open
3755149.126.72.220 3016 tcp tcpwrapped open
3756149.126.72.220 3017 tcp tcpwrapped open
3757149.126.72.220 3018 tcp tcpwrapped open
3758149.126.72.220 3019 tcp tcpwrapped open
3759149.126.72.220 3020 tcp tcpwrapped open
3760149.126.72.220 3021 tcp tcpwrapped open
3761149.126.72.220 3022 tcp tcpwrapped open
3762149.126.72.220 3030 tcp tcpwrapped open
3763149.126.72.220 3047 tcp tcpwrapped open
3764149.126.72.220 3048 tcp tcpwrapped open
3765149.126.72.220 3049 tcp tcpwrapped open
3766149.126.72.220 3050 tcp tcpwrapped open
3767149.126.72.220 3051 tcp tcpwrapped open
3768149.126.72.220 3052 tcp tcpwrapped open
3769149.126.72.220 3053 tcp tcpwrapped open
3770149.126.72.220 3054 tcp tcpwrapped open
3771149.126.72.220 3055 tcp tcpwrapped open
3772149.126.72.220 3056 tcp tcpwrapped open
3773149.126.72.220 3057 tcp tcpwrapped open
3774149.126.72.220 3058 tcp tcpwrapped open
3775149.126.72.220 3059 tcp tcpwrapped open
3776149.126.72.220 3060 tcp tcpwrapped open
3777149.126.72.220 3061 tcp tcpwrapped open
3778149.126.72.220 3062 tcp tcpwrapped open
3779149.126.72.220 3063 tcp tcpwrapped open
3780149.126.72.220 3064 tcp tcpwrapped open
3781149.126.72.220 3065 tcp tcpwrapped open
3782149.126.72.220 3066 tcp tcpwrapped open
3783149.126.72.220 3067 tcp tcpwrapped open
3784149.126.72.220 3068 tcp tcpwrapped open
3785149.126.72.220 3069 tcp tcpwrapped open
3786149.126.72.220 3070 tcp tcpwrapped open
3787149.126.72.220 3071 tcp tcpwrapped open
3788149.126.72.220 3072 tcp tcpwrapped open
3789149.126.72.220 3073 tcp tcpwrapped open
3790149.126.72.220 3074 tcp tcpwrapped open
3791149.126.72.220 3075 tcp tcpwrapped open
3792149.126.72.220 3076 tcp tcpwrapped open
3793149.126.72.220 3077 tcp tcpwrapped open
3794149.126.72.220 3078 tcp tcpwrapped open
3795149.126.72.220 3079 tcp tcpwrapped open
3796149.126.72.220 3080 tcp tcpwrapped open
3797149.126.72.220 3081 tcp tcpwrapped open
3798149.126.72.220 3082 tcp tcpwrapped open
3799149.126.72.220 3083 tcp tcpwrapped open
3800149.126.72.220 3084 tcp tcpwrapped open
3801149.126.72.220 3085 tcp tcpwrapped open
3802149.126.72.220 3086 tcp tcpwrapped open
3803149.126.72.220 3087 tcp tcpwrapped open
3804149.126.72.220 3088 tcp tcpwrapped open
3805149.126.72.220 3089 tcp tcpwrapped open
3806149.126.72.220 3090 tcp tcpwrapped open
3807149.126.72.220 3091 tcp tcpwrapped open
3808149.126.72.220 3092 tcp tcpwrapped open
3809149.126.72.220 3093 tcp tcpwrapped open
3810149.126.72.220 3094 tcp tcpwrapped open
3811149.126.72.220 3095 tcp tcpwrapped open
3812149.126.72.220 3096 tcp tcpwrapped open
3813149.126.72.220 3097 tcp tcpwrapped open
3814149.126.72.220 3098 tcp tcpwrapped open
3815149.126.72.220 3099 tcp tcpwrapped open
3816149.126.72.220 3100 tcp tcpwrapped open
3817149.126.72.220 3101 tcp tcpwrapped open
3818149.126.72.220 3102 tcp tcpwrapped open
3819149.126.72.220 3103 tcp tcpwrapped open
3820149.126.72.220 3104 tcp tcpwrapped open
3821149.126.72.220 3105 tcp tcpwrapped open
3822149.126.72.220 3106 tcp tcpwrapped open
3823149.126.72.220 3107 tcp tcpwrapped open
3824149.126.72.220 3108 tcp tcpwrapped open
3825149.126.72.220 3109 tcp tcpwrapped open
3826149.126.72.220 3110 tcp tcpwrapped open
3827149.126.72.220 3111 tcp tcpwrapped open
3828149.126.72.220 3112 tcp tcpwrapped open
3829149.126.72.220 3113 tcp tcpwrapped open
3830149.126.72.220 3114 tcp tcpwrapped open
3831149.126.72.220 3115 tcp tcpwrapped open
3832149.126.72.220 3116 tcp tcpwrapped open
3833149.126.72.220 3117 tcp tcpwrapped open
3834149.126.72.220 3118 tcp tcpwrapped open
3835149.126.72.220 3119 tcp tcpwrapped open
3836149.126.72.220 3120 tcp tcpwrapped open
3837149.126.72.220 3121 tcp tcpwrapped open
3838149.126.72.220 3150 tcp tcpwrapped open
3839149.126.72.220 3155 tcp tcpwrapped open
3840149.126.72.220 3160 tcp tcpwrapped open
3841149.126.72.220 3165 tcp tcpwrapped open
3842149.126.72.220 3270 tcp tcpwrapped open
3843149.126.72.220 3299 tcp tcpwrapped open
3844149.126.72.220 3306 tcp tcpwrapped open
3845149.126.72.220 3333 tcp tcpwrapped open
3846149.126.72.220 3389 tcp tcpwrapped open
3847149.126.72.220 3391 tcp tcpwrapped open
3848149.126.72.220 3400 tcp tcpwrapped open
3849149.126.72.220 3401 tcp tcpwrapped open
3850149.126.72.220 3402 tcp tcpwrapped open
3851149.126.72.220 3403 tcp tcpwrapped open
3852149.126.72.220 3404 tcp tcpwrapped open
3853149.126.72.220 3405 tcp tcpwrapped open
3854149.126.72.220 3406 tcp tcpwrapped open
3855149.126.72.220 3407 tcp tcpwrapped open
3856149.126.72.220 3408 tcp tcpwrapped open
3857149.126.72.220 3409 tcp tcpwrapped open
3858149.126.72.220 3410 tcp tcpwrapped open
3859149.126.72.220 3412 tcp tcpwrapped open
3860149.126.72.220 3443 tcp tcpwrapped open
3861149.126.72.220 3500 tcp tcpwrapped open
3862149.126.72.220 3510 tcp tcpwrapped open
3863149.126.72.220 3521 tcp tcpwrapped open
3864149.126.72.220 3522 tcp tcpwrapped open
3865149.126.72.220 3523 tcp tcpwrapped open
3866149.126.72.220 3524 tcp tcpwrapped open
3867149.126.72.220 3530 tcp tcpwrapped open
3868149.126.72.220 3531 tcp tcpwrapped open
3869149.126.72.220 3540 tcp tcpwrapped open
3870149.126.72.220 3548 tcp tcpwrapped open
3871149.126.72.220 3549 tcp tcpwrapped open
3872149.126.72.220 3550 tcp tcpwrapped open
3873149.126.72.220 3551 tcp tcpwrapped open
3874149.126.72.220 3552 tcp tcpwrapped open
3875149.126.72.220 3553 tcp tcpwrapped open
3876149.126.72.220 3554 tcp tcpwrapped open
3877149.126.72.220 3555 tcp tcpwrapped open
3878149.126.72.220 3556 tcp tcpwrapped open
3879149.126.72.220 3557 tcp tcpwrapped open
3880149.126.72.220 3558 tcp tcpwrapped open
3881149.126.72.220 3559 tcp tcpwrapped open
3882149.126.72.220 3560 tcp tcpwrapped open
3883149.126.72.220 3561 tcp tcpwrapped open
3884149.126.72.220 3562 tcp tcpwrapped open
3885149.126.72.220 3563 tcp tcpwrapped open
3886149.126.72.220 3566 tcp tcpwrapped open
3887149.126.72.220 3567 tcp tcpwrapped open
3888149.126.72.220 3568 tcp tcpwrapped open
3889149.126.72.220 3569 tcp tcpwrapped open
3890149.126.72.220 3570 tcp tcpwrapped open
3891149.126.72.220 3572 tcp tcpwrapped open
3892149.126.72.220 3580 tcp tcpwrapped open
3893149.126.72.220 3590 tcp tcpwrapped open
3894149.126.72.220 3790 tcp tcpwrapped open
3895149.126.72.220 3791 tcp tcpwrapped open
3896149.126.72.220 3792 tcp tcpwrapped open
3897149.126.72.220 3793 tcp tcpwrapped open
3898149.126.72.220 3794 tcp tcpwrapped open
3899149.126.72.220 3838 tcp tcpwrapped open
3900149.126.72.220 3841 tcp tcpwrapped open
3901149.126.72.220 3842 tcp tcpwrapped open
3902149.126.72.220 3950 tcp tcpwrapped open
3903149.126.72.220 3951 tcp tcpwrapped open
3904149.126.72.220 3952 tcp tcpwrapped open
3905149.126.72.220 3953 tcp tcpwrapped open
3906149.126.72.220 3954 tcp adrep open
3907149.126.72.220 4000 tcp tcpwrapped open
3908149.126.72.220 4001 tcp newoak open
3909149.126.72.220 4002 tcp mlchat-proxy open
3910149.126.72.220 4021 tcp nexus-portal open
3911149.126.72.220 4022 tcp dnox open
3912149.126.72.220 4023 tcp esnm-zoning open
3913149.126.72.220 4043 tcp nirp open
3914149.126.72.220 4072 tcp zieto-sock open
3915149.126.72.220 4080 tcp lorica-in open
3916149.126.72.220 4085 tcp ezmessagesrv open
3917149.126.72.220 4120 tcp minirem open
3918149.126.72.220 4147 tcp vrxpservman open
3919149.126.72.220 4148 tcp hhb-handheld open
3920149.126.72.220 4150 tcp poweralert-nsa open
3921149.126.72.220 4155 tcp bzr open
3922149.126.72.220 4160 tcp jini-discovery open
3923149.126.72.220 4165 tcp altcp open
3924149.126.72.220 4172 tcp pcoip open
3925149.126.72.220 4243 tcp vrml-multi-use open
3926149.126.72.220 4244 tcp vrml-multi-use open
3927149.126.72.220 4250 tcp vrml-multi-use open
3928149.126.72.220 4300 tcp corelccam open
3929149.126.72.220 4333 tcp msql open
3930149.126.72.220 4343 tcp unicall open
3931149.126.72.220 4344 tcp vinainstall open
3932149.126.72.220 4400 tcp ds-srv open
3933149.126.72.220 4401 tcp tcpwrapped open
3934149.126.72.220 4402 tcp tcpwrapped open
3935149.126.72.220 4430 tcp tcpwrapped open
3936149.126.72.220 4431 tcp tcpwrapped open
3937149.126.72.220 4432 tcp tcpwrapped open
3938149.126.72.220 4434 tcp tcpwrapped open
3939149.126.72.220 4435 tcp tcpwrapped open
3940149.126.72.220 4436 tcp tcpwrapped open
3941149.126.72.220 4437 tcp tcpwrapped open
3942149.126.72.220 4439 tcp tcpwrapped open
3943149.126.72.220 4440 tcp tcpwrapped open
3944149.126.72.220 4443 tcp tcpwrapped open
3945149.126.72.220 4444 tcp tcpwrapped open
3946149.126.72.220 4445 tcp tcpwrapped open
3947149.126.72.220 4451 tcp tcpwrapped open
3948149.126.72.220 4455 tcp tcpwrapped open
3949149.126.72.220 4457 tcp tcpwrapped open
3950149.126.72.220 4459 tcp tcpwrapped open
3951149.126.72.220 4461 tcp tcpwrapped open
3952149.126.72.220 4463 tcp tcpwrapped open
3953149.126.72.220 4477 tcp tcpwrapped open
3954149.126.72.220 4482 tcp tcpwrapped open
3955149.126.72.220 4500 tcp tcpwrapped open
3956149.126.72.220 4502 tcp tcpwrapped open
3957149.126.72.220 4505 tcp tcpwrapped open
3958149.126.72.220 4572 tcp tcpwrapped open
3959149.126.72.220 4602 tcp tcpwrapped open
3960149.126.72.220 4620 tcp tcpwrapped open
3961149.126.72.220 4643 tcp tcpwrapped open
3962149.126.72.220 4848 tcp tcpwrapped open
3963149.126.72.220 4933 tcp tcpwrapped open
3964149.126.72.220 4993 tcp tcpwrapped open
3965149.126.72.220 5000 tcp tcpwrapped open
3966149.126.72.220 5001 tcp tcpwrapped open
3967149.126.72.220 5002 tcp tcpwrapped open
3968149.126.72.220 5003 tcp tcpwrapped open
3969149.126.72.220 5004 tcp tcpwrapped open
3970149.126.72.220 5005 tcp tcpwrapped open
3971149.126.72.220 5006 tcp tcpwrapped open
3972149.126.72.220 5007 tcp tcpwrapped open
3973149.126.72.220 5008 tcp tcpwrapped open
3974149.126.72.220 5009 tcp tcpwrapped open
3975149.126.72.220 5010 tcp tcpwrapped open
3976149.126.72.220 5011 tcp tcpwrapped open
3977149.126.72.220 5022 tcp tcpwrapped open
3978149.126.72.220 5050 tcp tcpwrapped open
3979149.126.72.220 5053 tcp tcpwrapped open
3980149.126.72.220 5060 tcp tcpwrapped open
3981149.126.72.220 5061 tcp tcpwrapped open
3982149.126.72.220 5080 tcp tcpwrapped open
3983149.126.72.220 5083 tcp tcpwrapped open
3984149.126.72.220 5089 tcp tcpwrapped open
3985149.126.72.220 5090 tcp tcpwrapped open
3986149.126.72.220 5100 tcp tcpwrapped open
3987149.126.72.220 5105 tcp tcpwrapped open
3988149.126.72.220 5119 tcp tcpwrapped open
3989149.126.72.220 5120 tcp tcpwrapped open
3990149.126.72.220 5130 tcp tcpwrapped open
3991149.126.72.220 5140 tcp tcpwrapped open
3992149.126.72.220 5150 tcp tcpwrapped open
3993149.126.72.220 5160 tcp tcpwrapped open
3994149.126.72.220 5180 tcp tcpwrapped open
3995149.126.72.220 5201 tcp tcpwrapped open
3996149.126.72.220 5222 tcp tcpwrapped open
3997149.126.72.220 5223 tcp tcpwrapped open
3998149.126.72.220 5224 tcp tcpwrapped open
3999149.126.72.220 5225 tcp tcpwrapped open
4000149.126.72.220 5226 tcp tcpwrapped open
4001149.126.72.220 5227 tcp tcpwrapped open
4002149.126.72.220 5228 tcp tcpwrapped open
4003149.126.72.220 5229 tcp tcpwrapped open
4004149.126.72.220 5230 tcp tcpwrapped open
4005149.126.72.220 5231 tcp tcpwrapped open
4006149.126.72.220 5232 tcp tcpwrapped open
4007149.126.72.220 5233 tcp tcpwrapped open
4008149.126.72.220 5234 tcp tcpwrapped open
4009149.126.72.220 5235 tcp tcpwrapped open
4010149.126.72.220 5236 tcp tcpwrapped open
4011149.126.72.220 5237 tcp tcpwrapped open
4012149.126.72.220 5238 tcp tcpwrapped open
4013149.126.72.220 5239 tcp tcpwrapped open
4014149.126.72.220 5240 tcp tcpwrapped open
4015149.126.72.220 5241 tcp tcpwrapped open
4016149.126.72.220 5242 tcp tcpwrapped open
4017149.126.72.220 5243 tcp tcpwrapped open
4018149.126.72.220 5244 tcp tcpwrapped open
4019149.126.72.220 5245 tcp tcpwrapped open
4020149.126.72.220 5246 tcp tcpwrapped open
4021149.126.72.220 5247 tcp tcpwrapped open
4022149.126.72.220 5248 tcp tcpwrapped open
4023149.126.72.220 5249 tcp tcpwrapped open
4024149.126.72.220 5250 tcp tcpwrapped open
4025149.126.72.220 5251 tcp tcpwrapped open
4026149.126.72.220 5252 tcp tcpwrapped open
4027149.126.72.220 5253 tcp tcpwrapped open
4028149.126.72.220 5254 tcp tcpwrapped open
4029149.126.72.220 5255 tcp tcpwrapped open
4030149.126.72.220 5256 tcp tcpwrapped open
4031149.126.72.220 5257 tcp tcpwrapped open
4032149.126.72.220 5258 tcp tcpwrapped open
4033149.126.72.220 5259 tcp tcpwrapped open
4034149.126.72.220 5260 tcp tcpwrapped open
4035149.126.72.220 5261 tcp tcpwrapped open
4036149.126.72.220 5262 tcp tcpwrapped open
4037149.126.72.220 5263 tcp tcpwrapped open
4038149.126.72.220 5264 tcp tcpwrapped open
4039149.126.72.220 5265 tcp tcpwrapped open
4040149.126.72.220 5266 tcp tcpwrapped open
4041149.126.72.220 5267 tcp tcpwrapped open
4042149.126.72.220 5268 tcp tcpwrapped open
4043149.126.72.220 5269 tcp tcpwrapped open
4044149.126.72.220 5270 tcp tcpwrapped open
4045149.126.72.220 5271 tcp tcpwrapped open
4046149.126.72.220 5272 tcp tcpwrapped open
4047149.126.72.220 5273 tcp tcpwrapped open
4048149.126.72.220 5274 tcp tcpwrapped open
4049149.126.72.220 5275 tcp tcpwrapped open
4050149.126.72.220 5276 tcp tcpwrapped open
4051149.126.72.220 5277 tcp tcpwrapped open
4052149.126.72.220 5278 tcp tcpwrapped open
4053149.126.72.220 5279 tcp tcpwrapped open
4054149.126.72.220 5280 tcp tcpwrapped open
4055149.126.72.220 5440 tcp tcpwrapped open
4056149.126.72.220 5443 tcp tcpwrapped open
4057149.126.72.220 5456 tcp tcpwrapped open
4058149.126.72.220 5494 tcp tcpwrapped open
4059149.126.72.220 5495 tcp tcpwrapped open
4060149.126.72.220 5500 tcp tcpwrapped open
4061149.126.72.220 5503 tcp tcpwrapped open
4062149.126.72.220 5552 tcp tcpwrapped open
4063149.126.72.220 5555 tcp tcpwrapped open
4064149.126.72.220 5556 tcp tcpwrapped open
4065149.126.72.220 5557 tcp tcpwrapped open
4066149.126.72.220 5567 tcp tcpwrapped open
4067149.126.72.220 5568 tcp tcpwrapped open
4068149.126.72.220 5569 tcp tcpwrapped open
4069149.126.72.220 5590 tcp tcpwrapped open
4070149.126.72.220 5591 tcp tcpwrapped open
4071149.126.72.220 5592 tcp tcpwrapped open
4072149.126.72.220 5593 tcp tcpwrapped open
4073149.126.72.220 5594 tcp tcpwrapped open
4074149.126.72.220 5595 tcp tcpwrapped open
4075149.126.72.220 5596 tcp tcpwrapped open
4076149.126.72.220 5597 tcp tcpwrapped open
4077149.126.72.220 5598 tcp tcpwrapped open
4078149.126.72.220 5599 tcp tcpwrapped open
4079149.126.72.220 5600 tcp tcpwrapped open
4080149.126.72.220 5601 tcp tcpwrapped open
4081149.126.72.220 5602 tcp tcpwrapped open
4082149.126.72.220 5603 tcp tcpwrapped open
4083149.126.72.220 5604 tcp tcpwrapped open
4084149.126.72.220 5605 tcp tcpwrapped open
4085149.126.72.220 5606 tcp tcpwrapped open
4086149.126.72.220 5607 tcp tcpwrapped open
4087149.126.72.220 5608 tcp tcpwrapped open
4088149.126.72.220 5609 tcp tcpwrapped open
4089149.126.72.220 5613 tcp tcpwrapped open
4090149.126.72.220 5614 tcp tcpwrapped open
4091149.126.72.220 5620 tcp tcpwrapped open
4092149.126.72.220 5630 tcp tcpwrapped open
4093149.126.72.220 5640 tcp tcpwrapped open
4094149.126.72.220 5650 tcp tcpwrapped open
4095149.126.72.220 5660 tcp tcpwrapped open
4096149.126.72.220 5671 tcp tcpwrapped open
4097149.126.72.220 5672 tcp tcpwrapped open
4098149.126.72.220 5673 tcp tcpwrapped open
4099149.126.72.220 5680 tcp tcpwrapped open
4100149.126.72.220 5696 tcp tcpwrapped open
4101149.126.72.220 5698 tcp tcpwrapped open
4102149.126.72.220 5701 tcp tcpwrapped open
4103149.126.72.220 5721 tcp tcpwrapped open
4104149.126.72.220 5900 tcp tcpwrapped open
4105149.126.72.220 5901 tcp tcpwrapped open
4106149.126.72.220 5902 tcp tcpwrapped open
4107149.126.72.220 5903 tcp tcpwrapped open
4108149.126.72.220 5904 tcp tcpwrapped open
4109149.126.72.220 5905 tcp tcpwrapped open
4110149.126.72.220 5906 tcp tcpwrapped open
4111149.126.72.220 5907 tcp tcpwrapped open
4112149.126.72.220 5908 tcp tcpwrapped open
4113149.126.72.220 5909 tcp tcpwrapped open
4114149.126.72.220 5910 tcp tcpwrapped open
4115149.126.72.220 5911 tcp tcpwrapped open
4116149.126.72.220 5912 tcp tcpwrapped open
4117149.126.72.220 5913 tcp tcpwrapped open
4118149.126.72.220 5914 tcp tcpwrapped open
4119149.126.72.220 5915 tcp tcpwrapped open
4120149.126.72.220 5916 tcp tcpwrapped open
4121149.126.72.220 5917 tcp tcpwrapped open
4122149.126.72.220 5918 tcp tcpwrapped open
4123149.126.72.220 5919 tcp tcpwrapped open
4124149.126.72.220 5920 tcp tcpwrapped open
4125149.126.72.220 5984 tcp tcpwrapped open
4126149.126.72.220 5985 tcp tcpwrapped open
4127149.126.72.220 5986 tcp tcpwrapped open
4128149.126.72.220 5987 tcp tcpwrapped open
4129149.126.72.220 5988 tcp tcpwrapped open
4130149.126.72.220 5989 tcp tcpwrapped open
4131149.126.72.220 5990 tcp tcpwrapped open
4132149.126.72.220 5991 tcp tcpwrapped open
4133149.126.72.220 5992 tcp tcpwrapped open
4134149.126.72.220 5993 tcp tcpwrapped open
4135149.126.72.220 5994 tcp tcpwrapped open
4136149.126.72.220 5995 tcp tcpwrapped open
4137149.126.72.220 5996 tcp tcpwrapped open
4138149.126.72.220 5997 tcp tcpwrapped open
4139149.126.72.220 5998 tcp tcpwrapped open
4140149.126.72.220 5999 tcp tcpwrapped open
4141149.126.72.220 6000 tcp tcpwrapped open
4142149.126.72.220 6001 tcp tcpwrapped open
4143149.126.72.220 6002 tcp tcpwrapped open
4144149.126.72.220 6003 tcp tcpwrapped open
4145149.126.72.220 6004 tcp tcpwrapped open
4146149.126.72.220 6005 tcp tcpwrapped open
4147149.126.72.220 6006 tcp tcpwrapped open
4148149.126.72.220 6007 tcp tcpwrapped open
4149149.126.72.220 6008 tcp tcpwrapped open
4150149.126.72.220 6009 tcp tcpwrapped open
4151149.126.72.220 6010 tcp tcpwrapped open
4152149.126.72.220 6011 tcp tcpwrapped open
4153149.126.72.220 6021 tcp tcpwrapped open
4154149.126.72.220 6060 tcp tcpwrapped open
4155149.126.72.220 6061 tcp tcpwrapped open
4156149.126.72.220 6081 tcp tcpwrapped open
4157149.126.72.220 6100 tcp tcpwrapped open
4158149.126.72.220 6102 tcp tcpwrapped open
4159149.126.72.220 6134 tcp tcpwrapped open
4160149.126.72.220 6161 tcp tcpwrapped open
4161149.126.72.220 6331 tcp tcpwrapped open
4162149.126.72.220 6348 tcp tcpwrapped open
4163149.126.72.220 6379 tcp tcpwrapped open
4164149.126.72.220 6380 tcp tcpwrapped open
4165149.126.72.220 6433 tcp tcpwrapped open
4166149.126.72.220 6440 tcp tcpwrapped open
4167149.126.72.220 6443 tcp tcpwrapped open
4168149.126.72.220 6488 tcp tcpwrapped open
4169149.126.72.220 6500 tcp tcpwrapped open
4170149.126.72.220 6505 tcp tcpwrapped open
4171149.126.72.220 6510 tcp tcpwrapped open
4172149.126.72.220 6511 tcp tcpwrapped open
4173149.126.72.220 6512 tcp tcpwrapped open
4174149.126.72.220 6514 tcp tcpwrapped open
4175149.126.72.220 6543 tcp tcpwrapped open
4176149.126.72.220 6544 tcp tcpwrapped open
4177149.126.72.220 6560 tcp tcpwrapped open
4178149.126.72.220 6561 tcp tcpwrapped open
4179149.126.72.220 6565 tcp tcpwrapped open
4180149.126.72.220 6580 tcp tcpwrapped open
4181149.126.72.220 6581 tcp tcpwrapped open
4182149.126.72.220 6590 tcp tcpwrapped open
4183149.126.72.220 6601 tcp tcpwrapped open
4184149.126.72.220 6603 tcp tcpwrapped open
4185149.126.72.220 6605 tcp tcpwrapped open
4186149.126.72.220 6661 tcp tcpwrapped open
4187149.126.72.220 6662 tcp tcpwrapped open
4188149.126.72.220 6666 tcp tcpwrapped open
4189149.126.72.220 6686 tcp tcpwrapped open
4190149.126.72.220 6688 tcp tcpwrapped open
4191149.126.72.220 6700 tcp tcpwrapped open
4192149.126.72.220 6755 tcp tcpwrapped open
4193149.126.72.220 6775 tcp tcpwrapped open
4194149.126.72.220 6779 tcp tcpwrapped open
4195149.126.72.220 6789 tcp tcpwrapped open
4196149.126.72.220 6799 tcp tcpwrapped open
4197149.126.72.220 7000 tcp tcpwrapped open
4198149.126.72.220 7001 tcp tcpwrapped open
4199149.126.72.220 7002 tcp tcpwrapped open
4200149.126.72.220 7003 tcp tcpwrapped open
4201149.126.72.220 7004 tcp tcpwrapped open
4202149.126.72.220 7005 tcp tcpwrapped open
4203149.126.72.220 7007 tcp tcpwrapped open
4204149.126.72.220 7010 tcp tcpwrapped open
4205149.126.72.220 7011 tcp tcpwrapped open
4206149.126.72.220 7021 tcp tcpwrapped open
4207149.126.72.220 7070 tcp tcpwrapped open
4208149.126.72.220 7071 tcp tcpwrapped open
4209149.126.72.220 7079 tcp tcpwrapped open
4210149.126.72.220 7080 tcp tcpwrapped open
4211149.126.72.220 7081 tcp tcpwrapped open
4212149.126.72.220 7082 tcp tcpwrapped open
4213149.126.72.220 7083 tcp tcpwrapped open
4214149.126.72.220 7084 tcp tcpwrapped open
4215149.126.72.220 7085 tcp tcpwrapped open
4216149.126.72.220 7086 tcp tcpwrapped open
4217149.126.72.220 7087 tcp tcpwrapped open
4218149.126.72.220 7088 tcp tcpwrapped open
4219149.126.72.220 7090 tcp tcpwrapped open
4220149.126.72.220 7171 tcp tcpwrapped open
4221149.126.72.220 7172 tcp tcpwrapped open
4222149.126.72.220 7272 tcp tcpwrapped open
4223149.126.72.220 7348 tcp tcpwrapped open
4224149.126.72.220 7403 tcp tcpwrapped open
4225149.126.72.220 7433 tcp tcpwrapped open
4226149.126.72.220 7441 tcp tcpwrapped open
4227149.126.72.220 7443 tcp tcpwrapped open
4228149.126.72.220 7444 tcp tcpwrapped open
4229149.126.72.220 7445 tcp tcpwrapped open
4230149.126.72.220 7473 tcp tcpwrapped open
4231149.126.72.220 7500 tcp tcpwrapped open
4232149.126.72.220 7537 tcp tcpwrapped open
4233149.126.72.220 7687 tcp tcpwrapped open
4234149.126.72.220 7700 tcp tcpwrapped open
4235149.126.72.220 7771 tcp tcpwrapped open
4236149.126.72.220 7773 tcp tcpwrapped open
4237149.126.72.220 7774 tcp tcpwrapped open
4238149.126.72.220 7775 tcp tcpwrapped open
4239149.126.72.220 7776 tcp tcpwrapped open
4240149.126.72.220 7777 tcp tcpwrapped open
4241149.126.72.220 7778 tcp tcpwrapped open
4242149.126.72.220 7779 tcp tcpwrapped open
4243149.126.72.220 7788 tcp tcpwrapped open
4244149.126.72.220 7799 tcp tcpwrapped open
4245149.126.72.220 7998 tcp tcpwrapped open
4246149.126.72.220 7999 tcp tcpwrapped open
4247149.126.72.220 8000 tcp tcpwrapped open
4248149.126.72.220 8001 tcp tcpwrapped open
4249149.126.72.220 8002 tcp tcpwrapped open
4250149.126.72.220 8003 tcp tcpwrapped open
4251149.126.72.220 8004 tcp tcpwrapped open
4252149.126.72.220 8005 tcp tcpwrapped open
4253149.126.72.220 8006 tcp tcpwrapped open
4254149.126.72.220 8007 tcp tcpwrapped open
4255149.126.72.220 8008 tcp tcpwrapped open
4256149.126.72.220 8009 tcp tcpwrapped open
4257149.126.72.220 8010 tcp tcpwrapped open
4258149.126.72.220 8011 tcp tcpwrapped open
4259149.126.72.220 8012 tcp tcpwrapped open
4260149.126.72.220 8013 tcp tcpwrapped open
4261149.126.72.220 8014 tcp tcpwrapped open
4262149.126.72.220 8015 tcp tcpwrapped open
4263149.126.72.220 8016 tcp tcpwrapped open
4264149.126.72.220 8017 tcp tcpwrapped open
4265149.126.72.220 8018 tcp tcpwrapped open
4266149.126.72.220 8019 tcp tcpwrapped open
4267149.126.72.220 8020 tcp tcpwrapped open
4268149.126.72.220 8021 tcp tcpwrapped open
4269149.126.72.220 8022 tcp tcpwrapped open
4270149.126.72.220 8023 tcp tcpwrapped open
4271149.126.72.220 8024 tcp tcpwrapped open
4272149.126.72.220 8025 tcp tcpwrapped open
4273149.126.72.220 8026 tcp tcpwrapped open
4274149.126.72.220 8027 tcp tcpwrapped open
4275149.126.72.220 8028 tcp tcpwrapped open
4276149.126.72.220 8029 tcp tcpwrapped open
4277149.126.72.220 8030 tcp tcpwrapped open
4278149.126.72.220 8031 tcp tcpwrapped open
4279149.126.72.220 8032 tcp tcpwrapped open
4280149.126.72.220 8033 tcp tcpwrapped open
4281149.126.72.220 8034 tcp tcpwrapped open
4282149.126.72.220 8035 tcp tcpwrapped open
4283149.126.72.220 8036 tcp tcpwrapped open
4284149.126.72.220 8037 tcp tcpwrapped open
4285149.126.72.220 8038 tcp tcpwrapped open
4286149.126.72.220 8039 tcp tcpwrapped open
4287149.126.72.220 8040 tcp tcpwrapped open
4288149.126.72.220 8041 tcp tcpwrapped open
4289149.126.72.220 8042 tcp tcpwrapped open
4290149.126.72.220 8043 tcp tcpwrapped open
4291149.126.72.220 8044 tcp tcpwrapped open
4292149.126.72.220 8045 tcp tcpwrapped open
4293149.126.72.220 8046 tcp tcpwrapped open
4294149.126.72.220 8047 tcp tcpwrapped open
4295149.126.72.220 8048 tcp tcpwrapped open
4296149.126.72.220 8049 tcp tcpwrapped open
4297149.126.72.220 8050 tcp tcpwrapped open
4298149.126.72.220 8051 tcp tcpwrapped open
4299149.126.72.220 8052 tcp tcpwrapped open
4300149.126.72.220 8053 tcp tcpwrapped open
4301149.126.72.220 8054 tcp tcpwrapped open
4302149.126.72.220 8055 tcp tcpwrapped open
4303149.126.72.220 8056 tcp tcpwrapped open
4304149.126.72.220 8057 tcp tcpwrapped open
4305149.126.72.220 8058 tcp tcpwrapped open
4306149.126.72.220 8060 tcp tcpwrapped open
4307149.126.72.220 8064 tcp tcpwrapped open
4308149.126.72.220 8065 tcp tcpwrapped open
4309149.126.72.220 8069 tcp tcpwrapped open
4310149.126.72.220 8070 tcp tcpwrapped open
4311149.126.72.220 8071 tcp tcpwrapped open
4312149.126.72.220 8072 tcp tcpwrapped open
4313149.126.72.220 8074 tcp tcpwrapped open
4314149.126.72.220 8079 tcp tcpwrapped open
4315149.126.72.220 8080 tcp tcpwrapped open
4316149.126.72.220 8081 tcp tcpwrapped open
4317149.126.72.220 8082 tcp tcpwrapped open
4318149.126.72.220 8083 tcp tcpwrapped open
4319149.126.72.220 8084 tcp tcpwrapped open
4320149.126.72.220 8085 tcp tcpwrapped open
4321149.126.72.220 8086 tcp tcpwrapped open
4322149.126.72.220 8087 tcp tcpwrapped open
4323149.126.72.220 8088 tcp tcpwrapped open
4324149.126.72.220 8089 tcp tcpwrapped open
4325149.126.72.220 8090 tcp tcpwrapped open
4326149.126.72.220 8091 tcp tcpwrapped open
4327149.126.72.220 8092 tcp tcpwrapped open
4328149.126.72.220 8093 tcp tcpwrapped open
4329149.126.72.220 8094 tcp tcpwrapped open
4330149.126.72.220 8095 tcp tcpwrapped open
4331149.126.72.220 8096 tcp tcpwrapped open
4332149.126.72.220 8097 tcp tcpwrapped open
4333149.126.72.220 8098 tcp tcpwrapped open
4334149.126.72.220 8099 tcp tcpwrapped open
4335149.126.72.220 8100 tcp tcpwrapped open
4336149.126.72.220 8101 tcp tcpwrapped open
4337149.126.72.220 8102 tcp tcpwrapped open
4338149.126.72.220 8103 tcp tcpwrapped open
4339149.126.72.220 8104 tcp tcpwrapped open
4340149.126.72.220 8105 tcp tcpwrapped open
4341149.126.72.220 8106 tcp tcpwrapped open
4342149.126.72.220 8107 tcp tcpwrapped open
4343149.126.72.220 8108 tcp tcpwrapped open
4344149.126.72.220 8109 tcp tcpwrapped open
4345149.126.72.220 8110 tcp tcpwrapped open
4346149.126.72.220 8113 tcp tcpwrapped open
4347149.126.72.220 8114 tcp tcpwrapped open
4348149.126.72.220 8115 tcp tcpwrapped open
4349149.126.72.220 8118 tcp tcpwrapped open
4350149.126.72.220 8119 tcp tcpwrapped open
4351149.126.72.220 8120 tcp tcpwrapped open
4352149.126.72.220 8121 tcp tcpwrapped open
4353149.126.72.220 8123 tcp tcpwrapped open
4354149.126.72.220 8125 tcp tcpwrapped open
4355149.126.72.220 8126 tcp tcpwrapped open
4356149.126.72.220 8128 tcp tcpwrapped open
4357149.126.72.220 8129 tcp tcpwrapped open
4358149.126.72.220 8130 tcp tcpwrapped open
4359149.126.72.220 8131 tcp tcpwrapped open
4360149.126.72.220 8132 tcp tcpwrapped open
4361149.126.72.220 8133 tcp tcpwrapped open
4362149.126.72.220 8136 tcp tcpwrapped open
4363149.126.72.220 8140 tcp tcpwrapped open
4364149.126.72.220 8142 tcp tcpwrapped open
4365149.126.72.220 8143 tcp tcpwrapped open
4366149.126.72.220 8144 tcp tcpwrapped open
4367149.126.72.220 8147 tcp tcpwrapped open
4368149.126.72.220 8148 tcp tcpwrapped open
4369149.126.72.220 8149 tcp tcpwrapped open
4370149.126.72.220 8150 tcp tcpwrapped open
4371149.126.72.220 8154 tcp tcpwrapped open
4372149.126.72.220 8156 tcp tcpwrapped open
4373149.126.72.220 8157 tcp tcpwrapped open
4374149.126.72.220 8158 tcp tcpwrapped open
4375149.126.72.220 8160 tcp tcpwrapped open
4376149.126.72.220 8161 tcp tcpwrapped open
4377149.126.72.220 8162 tcp tcpwrapped open
4378149.126.72.220 8163 tcp tcpwrapped open
4379149.126.72.220 8164 tcp tcpwrapped open
4380149.126.72.220 8165 tcp tcpwrapped open
4381149.126.72.220 8166 tcp tcpwrapped open
4382149.126.72.220 8167 tcp tcpwrapped open
4383149.126.72.220 8168 tcp tcpwrapped open
4384149.126.72.220 8169 tcp tcpwrapped open
4385149.126.72.220 8170 tcp tcpwrapped open
4386149.126.72.220 8171 tcp tcpwrapped open
4387149.126.72.220 8172 tcp tcpwrapped open
4388149.126.72.220 8173 tcp tcpwrapped open
4389149.126.72.220 8175 tcp tcpwrapped open
4390149.126.72.220 8176 tcp tcpwrapped open
4391149.126.72.220 8178 tcp tcpwrapped open
4392149.126.72.220 8179 tcp tcpwrapped open
4393149.126.72.220 8180 tcp tcpwrapped open
4394149.126.72.220 8181 tcp tcpwrapped open
4395149.126.72.220 8182 tcp tcpwrapped open
4396149.126.72.220 8183 tcp tcpwrapped open
4397149.126.72.220 8184 tcp tcpwrapped open
4398149.126.72.220 8185 tcp tcpwrapped open
4399149.126.72.220 8186 tcp tcpwrapped open
4400149.126.72.220 8187 tcp tcpwrapped open
4401149.126.72.220 8188 tcp tcpwrapped open
4402149.126.72.220 8189 tcp tcpwrapped open
4403149.126.72.220 8190 tcp tcpwrapped open
4404149.126.72.220 8191 tcp tcpwrapped open
4405149.126.72.220 8192 tcp tcpwrapped open
4406149.126.72.220 8193 tcp tcpwrapped open
4407149.126.72.220 8194 tcp tcpwrapped open
4408149.126.72.220 8195 tcp tcpwrapped open
4409149.126.72.220 8198 tcp tcpwrapped open
4410149.126.72.220 8199 tcp tcpwrapped open
4411149.126.72.220 8200 tcp tcpwrapped open
4412149.126.72.220 8203 tcp tcpwrapped open
4413149.126.72.220 8222 tcp tcpwrapped open
4414149.126.72.220 8230 tcp tcpwrapped open
4415149.126.72.220 8236 tcp tcpwrapped open
4416149.126.72.220 8237 tcp tcpwrapped open
4417149.126.72.220 8238 tcp tcpwrapped open
4418149.126.72.220 8239 tcp tcpwrapped open
4419149.126.72.220 8241 tcp tcpwrapped open
4420149.126.72.220 8243 tcp tcpwrapped open
4421149.126.72.220 8248 tcp tcpwrapped open
4422149.126.72.220 8249 tcp tcpwrapped open
4423149.126.72.220 8250 tcp tcpwrapped open
4424149.126.72.220 8251 tcp tcpwrapped open
4425149.126.72.220 8252 tcp tcpwrapped open
4426149.126.72.220 8280 tcp tcpwrapped open
4427149.126.72.220 8282 tcp tcpwrapped open
4428149.126.72.220 8333 tcp tcpwrapped open
4429149.126.72.220 8340 tcp tcpwrapped open
4430149.126.72.220 8343 tcp tcpwrapped open
4431149.126.72.220 8350 tcp tcpwrapped open
4432149.126.72.220 8381 tcp tcpwrapped open
4433149.126.72.220 8382 tcp tcpwrapped open
4434149.126.72.220 8383 tcp tcpwrapped open
4435149.126.72.220 8384 tcp tcpwrapped open
4436149.126.72.220 8385 tcp tcpwrapped open
4437149.126.72.220 8388 tcp tcpwrapped open
4438149.126.72.220 8393 tcp tcpwrapped open
4439149.126.72.220 8401 tcp tcpwrapped open
4440149.126.72.220 8402 tcp tcpwrapped open
4441149.126.72.220 8403 tcp tcpwrapped open
4442149.126.72.220 8404 tcp tcpwrapped open
4443149.126.72.220 8405 tcp tcpwrapped open
4444149.126.72.220 8406 tcp tcpwrapped open
4445149.126.72.220 8407 tcp tcpwrapped open
4446149.126.72.220 8408 tcp tcpwrapped open
4447149.126.72.220 8409 tcp tcpwrapped open
4448149.126.72.220 8410 tcp tcpwrapped open
4449149.126.72.220 8411 tcp tcpwrapped open
4450149.126.72.220 8412 tcp tcpwrapped open
4451149.126.72.220 8413 tcp tcpwrapped open
4452149.126.72.220 8414 tcp tcpwrapped open
4453149.126.72.220 8415 tcp tcpwrapped open
4454149.126.72.220 8416 tcp tcpwrapped open
4455149.126.72.220 8417 tcp tcpwrapped open
4456149.126.72.220 8418 tcp tcpwrapped open
4457149.126.72.220 8419 tcp tcpwrapped open
4458149.126.72.220 8420 tcp tcpwrapped open
4459149.126.72.220 8421 tcp tcpwrapped open
4460149.126.72.220 8422 tcp tcpwrapped open
4461149.126.72.220 8423 tcp tcpwrapped open
4462149.126.72.220 8424 tcp tcpwrapped open
4463149.126.72.220 8425 tcp tcpwrapped open
4464149.126.72.220 8426 tcp tcpwrapped open
4465149.126.72.220 8427 tcp tcpwrapped open
4466149.126.72.220 8428 tcp tcpwrapped open
4467149.126.72.220 8429 tcp tcpwrapped open
4468149.126.72.220 8430 tcp tcpwrapped open
4469149.126.72.220 8431 tcp tcpwrapped open
4470149.126.72.220 8432 tcp tcpwrapped open
4471149.126.72.220 8433 tcp tcpwrapped open
4472149.126.72.220 8435 tcp tcpwrapped open
4473149.126.72.220 8440 tcp tcpwrapped open
4474149.126.72.220 8441 tcp tcpwrapped open
4475149.126.72.220 8442 tcp tcpwrapped open
4476149.126.72.220 8443 tcp tcpwrapped open
4477149.126.72.220 8444 tcp tcpwrapped open
4478149.126.72.220 8445 tcp tcpwrapped open
4479149.126.72.220 8446 tcp tcpwrapped open
4480149.126.72.220 8447 tcp tcpwrapped open
4481149.126.72.220 8448 tcp tcpwrapped open
4482149.126.72.220 8449 tcp tcpwrapped open
4483149.126.72.220 8450 tcp tcpwrapped open
4484149.126.72.220 8451 tcp tcpwrapped open
4485149.126.72.220 8452 tcp tcpwrapped open
4486149.126.72.220 8453 tcp tcpwrapped open
4487149.126.72.220 8454 tcp tcpwrapped open
4488149.126.72.220 8455 tcp tcpwrapped open
4489149.126.72.220 8456 tcp tcpwrapped open
4490149.126.72.220 8457 tcp tcpwrapped open
4491149.126.72.220 8458 tcp tcpwrapped open
4492149.126.72.220 8459 tcp tcpwrapped open
4493149.126.72.220 8460 tcp tcpwrapped open
4494149.126.72.220 8461 tcp tcpwrapped open
4495149.126.72.220 8462 tcp tcpwrapped open
4496149.126.72.220 8463 tcp tcpwrapped open
4497149.126.72.220 8464 tcp tcpwrapped open
4498149.126.72.220 8465 tcp tcpwrapped open
4499149.126.72.220 8466 tcp tcpwrapped open
4500149.126.72.220 8467 tcp tcpwrapped open
4501149.126.72.220 8470 tcp tcpwrapped open
4502149.126.72.220 8472 tcp tcpwrapped open
4503149.126.72.220 8473 tcp tcpwrapped open
4504149.126.72.220 8475 tcp tcpwrapped open
4505149.126.72.220 8480 tcp tcpwrapped open
4506149.126.72.220 8481 tcp tcpwrapped open
4507149.126.72.220 8482 tcp tcpwrapped open
4508149.126.72.220 8484 tcp tcpwrapped open
4509149.126.72.220 8485 tcp tcpwrapped open
4510149.126.72.220 8488 tcp tcpwrapped open
4511149.126.72.220 8493 tcp tcpwrapped open
4512149.126.72.220 8494 tcp tcpwrapped open
4513149.126.72.220 8500 tcp tcpwrapped open
4514149.126.72.220 8502 tcp tcpwrapped open
4515149.126.72.220 8503 tcp tcpwrapped open
4516149.126.72.220 8504 tcp tcpwrapped open
4517149.126.72.220 8505 tcp tcpwrapped open
4518149.126.72.220 8506 tcp tcpwrapped open
4519149.126.72.220 8510 tcp tcpwrapped open
4520149.126.72.220 8513 tcp tcpwrapped open
4521149.126.72.220 8514 tcp tcpwrapped open
4522149.126.72.220 8515 tcp tcpwrapped open
4523149.126.72.220 8519 tcp tcpwrapped open
4524149.126.72.220 8520 tcp tcpwrapped open
4525149.126.72.220 8521 tcp tcpwrapped open
4526149.126.72.220 8523 tcp tcpwrapped open
4527149.126.72.220 8524 tcp tcpwrapped open
4528149.126.72.220 8525 tcp tcpwrapped open
4529149.126.72.220 8526 tcp tcpwrapped open
4530149.126.72.220 8528 tcp tcpwrapped open
4531149.126.72.220 8529 tcp tcpwrapped open
4532149.126.72.220 8530 tcp tcpwrapped open
4533149.126.72.220 8531 tcp tcpwrapped open
4534149.126.72.220 8532 tcp tcpwrapped open
4535149.126.72.220 8533 tcp tcpwrapped open
4536149.126.72.220 8536 tcp tcpwrapped open
4537149.126.72.220 8540 tcp tcpwrapped open
4538149.126.72.220 8543 tcp tcpwrapped open
4539149.126.72.220 8544 tcp tcpwrapped open
4540149.126.72.220 8548 tcp tcpwrapped open
4541149.126.72.220 8549 tcp tcpwrapped open
4542149.126.72.220 8550 tcp tcpwrapped open
4543149.126.72.220 8551 tcp tcpwrapped open
4544149.126.72.220 8553 tcp tcpwrapped open
4545149.126.72.220 8556 tcp tcpwrapped open
4546149.126.72.220 8557 tcp tcpwrapped open
4547149.126.72.220 8558 tcp tcpwrapped open
4548149.126.72.220 8560 tcp tcpwrapped open
4549149.126.72.220 8561 tcp tcpwrapped open
4550149.126.72.220 8562 tcp tcpwrapped open
4551149.126.72.220 8563 tcp tcpwrapped open
4552149.126.72.220 8564 tcp tcpwrapped open
4553149.126.72.220 8565 tcp tcpwrapped open
4554149.126.72.220 8566 tcp tcpwrapped open
4555149.126.72.220 8567 tcp tcpwrapped open
4556149.126.72.220 8568 tcp tcpwrapped open
4557149.126.72.220 8569 tcp tcpwrapped open
4558149.126.72.220 8570 tcp tcpwrapped open
4559149.126.72.220 8571 tcp tcpwrapped open
4560149.126.72.220 8573 tcp tcpwrapped open
4561149.126.72.220 8574 tcp tcpwrapped open
4562149.126.72.220 8575 tcp tcpwrapped open
4563149.126.72.220 8576 tcp tcpwrapped open
4564149.126.72.220 8577 tcp tcpwrapped open
4565149.126.72.220 8578 tcp tcpwrapped open
4566149.126.72.220 8579 tcp tcpwrapped open
4567149.126.72.220 8580 tcp tcpwrapped open
4568149.126.72.220 8581 tcp tcpwrapped open
4569149.126.72.220 8582 tcp tcpwrapped open
4570149.126.72.220 8583 tcp tcpwrapped open
4571149.126.72.220 8585 tcp tcpwrapped open
4572149.126.72.220 8586 tcp tcpwrapped open
4573149.126.72.220 8588 tcp tcpwrapped open
4574149.126.72.220 8589 tcp tcpwrapped open
4575149.126.72.220 8590 tcp tcpwrapped open
4576149.126.72.220 8591 tcp tcpwrapped open
4577149.126.72.220 8592 tcp tcpwrapped open
4578149.126.72.220 8593 tcp tcpwrapped open
4579149.126.72.220 8594 tcp tcpwrapped open
4580149.126.72.220 8595 tcp tcpwrapped open
4581149.126.72.220 8596 tcp tcpwrapped open
4582149.126.72.220 8597 tcp tcpwrapped open
4583149.126.72.220 8598 tcp tcpwrapped open
4584149.126.72.220 8599 tcp tcpwrapped open
4585149.126.72.220 8600 tcp tcpwrapped open
4586149.126.72.220 8601 tcp tcpwrapped open
4587149.126.72.220 8605 tcp tcpwrapped open
4588149.126.72.220 8606 tcp tcpwrapped open
4589149.126.72.220 8630 tcp tcpwrapped open
4590149.126.72.220 8640 tcp tcpwrapped open
4591149.126.72.220 8641 tcp tcpwrapped open
4592149.126.72.220 8643 tcp tcpwrapped open
4593149.126.72.220 8663 tcp tcpwrapped open
4594149.126.72.220 8666 tcp tcpwrapped open
4595149.126.72.220 8686 tcp tcpwrapped open
4596149.126.72.220 8688 tcp tcpwrapped open
4597149.126.72.220 8700 tcp tcpwrapped open
4598149.126.72.220 8701 tcp tcpwrapped open
4599149.126.72.220 8702 tcp tcpwrapped open
4600149.126.72.220 8703 tcp tcpwrapped open
4601149.126.72.220 8704 tcp tcpwrapped open
4602149.126.72.220 8705 tcp tcpwrapped open
4603149.126.72.220 8706 tcp tcpwrapped open
4604149.126.72.220 8707 tcp tcpwrapped open
4605149.126.72.220 8708 tcp tcpwrapped open
4606149.126.72.220 8709 tcp tcpwrapped open
4607149.126.72.220 8723 tcp tcpwrapped open
4608149.126.72.220 8724 tcp tcpwrapped open
4609149.126.72.220 8731 tcp tcpwrapped open
4610149.126.72.220 8732 tcp tcpwrapped open
4611149.126.72.220 8764 tcp tcpwrapped open
4612149.126.72.220 8765 tcp tcpwrapped open
4613149.126.72.220 8766 tcp tcpwrapped open
4614149.126.72.220 8767 tcp tcpwrapped open
4615149.126.72.220 8771 tcp tcpwrapped open
4616149.126.72.220 8787 tcp tcpwrapped open
4617149.126.72.220 8788 tcp tcpwrapped open
4618149.126.72.220 8789 tcp tcpwrapped open
4619149.126.72.220 8790 tcp tcpwrapped open
4620149.126.72.220 8791 tcp tcpwrapped open
4621149.126.72.220 8800 tcp tcpwrapped open
4622149.126.72.220 8801 tcp tcpwrapped open
4623149.126.72.220 8802 tcp tcpwrapped open
4624149.126.72.220 8803 tcp tcpwrapped open
4625149.126.72.220 8804 tcp tcpwrapped open
4626149.126.72.220 8805 tcp tcpwrapped open
4627149.126.72.220 8806 tcp tcpwrapped open
4628149.126.72.220 8807 tcp tcpwrapped open
4629149.126.72.220 8808 tcp tcpwrapped open
4630149.126.72.220 8809 tcp tcpwrapped open
4631149.126.72.220 8810 tcp tcpwrapped open
4632149.126.72.220 8811 tcp tcpwrapped open
4633149.126.72.220 8812 tcp tcpwrapped open
4634149.126.72.220 8813 tcp tcpwrapped open
4635149.126.72.220 8814 tcp tcpwrapped open
4636149.126.72.220 8815 tcp tcpwrapped open
4637149.126.72.220 8816 tcp tcpwrapped open
4638149.126.72.220 8817 tcp tcpwrapped open
4639149.126.72.220 8818 tcp tcpwrapped open
4640149.126.72.220 8819 tcp tcpwrapped open
4641149.126.72.220 8820 tcp tcpwrapped open
4642149.126.72.220 8821 tcp tcpwrapped open
4643149.126.72.220 8822 tcp tcpwrapped open
4644149.126.72.220 8823 tcp tcpwrapped open
4645149.126.72.220 8824 tcp tcpwrapped open
4646149.126.72.220 8825 tcp tcpwrapped open
4647149.126.72.220 8826 tcp tcpwrapped open
4648149.126.72.220 8827 tcp tcpwrapped open
4649149.126.72.220 8828 tcp tcpwrapped open
4650149.126.72.220 8829 tcp tcpwrapped open
4651149.126.72.220 8830 tcp tcpwrapped open
4652149.126.72.220 8831 tcp tcpwrapped open
4653149.126.72.220 8832 tcp tcpwrapped open
4654149.126.72.220 8833 tcp tcpwrapped open
4655149.126.72.220 8834 tcp tcpwrapped open
4656149.126.72.220 8835 tcp tcpwrapped open
4657149.126.72.220 8836 tcp tcpwrapped open
4658149.126.72.220 8837 tcp tcpwrapped open
4659149.126.72.220 8838 tcp tcpwrapped open
4660149.126.72.220 8839 tcp tcpwrapped open
4661149.126.72.220 8840 tcp tcpwrapped open
4662149.126.72.220 8841 tcp tcpwrapped open
4663149.126.72.220 8842 tcp tcpwrapped open
4664149.126.72.220 8843 tcp tcpwrapped open
4665149.126.72.220 8844 tcp tcpwrapped open
4666149.126.72.220 8845 tcp tcpwrapped open
4667149.126.72.220 8846 tcp tcpwrapped open
4668149.126.72.220 8847 tcp tcpwrapped open
4669149.126.72.220 8848 tcp tcpwrapped open
4670149.126.72.220 8849 tcp tcpwrapped open
4671149.126.72.220 8850 tcp tcpwrapped open
4672149.126.72.220 8851 tcp tcpwrapped open
4673149.126.72.220 8852 tcp tcpwrapped open
4674149.126.72.220 8853 tcp tcpwrapped open
4675149.126.72.220 8854 tcp tcpwrapped open
4676149.126.72.220 8855 tcp tcpwrapped open
4677149.126.72.220 8856 tcp tcpwrapped open
4678149.126.72.220 8857 tcp tcpwrapped open
4679149.126.72.220 8858 tcp tcpwrapped open
4680149.126.72.220 8859 tcp tcpwrapped open
4681149.126.72.220 8860 tcp tcpwrapped open
4682149.126.72.220 8861 tcp tcpwrapped open
4683149.126.72.220 8862 tcp tcpwrapped open
4684149.126.72.220 8863 tcp tcpwrapped open
4685149.126.72.220 8864 tcp tcpwrapped open
4686149.126.72.220 8865 tcp tcpwrapped open
4687149.126.72.220 8866 tcp tcpwrapped open
4688149.126.72.220 8867 tcp tcpwrapped open
4689149.126.72.220 8868 tcp tcpwrapped open
4690149.126.72.220 8869 tcp tcpwrapped open
4691149.126.72.220 8870 tcp tcpwrapped open
4692149.126.72.220 8871 tcp tcpwrapped open
4693149.126.72.220 8872 tcp tcpwrapped open
4694149.126.72.220 8873 tcp tcpwrapped open
4695149.126.72.220 8874 tcp tcpwrapped open
4696149.126.72.220 8875 tcp tcpwrapped open
4697149.126.72.220 8876 tcp tcpwrapped open
4698149.126.72.220 8877 tcp tcpwrapped open
4699149.126.72.220 8878 tcp tcpwrapped open
4700149.126.72.220 8879 tcp tcpwrapped open
4701149.126.72.220 8880 tcp tcpwrapped open
4702149.126.72.220 8881 tcp tcpwrapped open
4703149.126.72.220 8882 tcp tcpwrapped open
4704149.126.72.220 8883 tcp tcpwrapped open
4705149.126.72.220 8884 tcp tcpwrapped open
4706149.126.72.220 8885 tcp tcpwrapped open
4707149.126.72.220 8887 tcp tcpwrapped open
4708149.126.72.220 8888 tcp tcpwrapped open
4709149.126.72.220 8889 tcp tcpwrapped open
4710149.126.72.220 8890 tcp tcpwrapped open
4711149.126.72.220 8891 tcp tcpwrapped open
4712149.126.72.220 8899 tcp tcpwrapped open
4713149.126.72.220 8900 tcp tcpwrapped open
4714149.126.72.220 8901 tcp tcpwrapped open
4715149.126.72.220 8902 tcp tcpwrapped open
4716149.126.72.220 8905 tcp tcpwrapped open
4717149.126.72.220 8906 tcp tcpwrapped open
4718149.126.72.220 8907 tcp tcpwrapped open
4719149.126.72.220 8908 tcp tcpwrapped open
4720149.126.72.220 8910 tcp tcpwrapped open
4721149.126.72.220 8911 tcp tcpwrapped open
4722149.126.72.220 8912 tcp tcpwrapped open
4723149.126.72.220 8913 tcp tcpwrapped open
4724149.126.72.220 8915 tcp tcpwrapped open
4725149.126.72.220 8916 tcp tcpwrapped open
4726149.126.72.220 8935 tcp tcpwrapped open
4727149.126.72.220 8943 tcp tcpwrapped open
4728149.126.72.220 8969 tcp tcpwrapped open
4729149.126.72.220 8988 tcp tcpwrapped open
4730149.126.72.220 8989 tcp tcpwrapped open
4731149.126.72.220 8999 tcp tcpwrapped open
4732149.126.72.220 9000 tcp tcpwrapped open
4733149.126.72.220 9001 tcp tcpwrapped open
4734149.126.72.220 9002 tcp tcpwrapped open
4735149.126.72.220 9003 tcp tcpwrapped open
4736149.126.72.220 9004 tcp tcpwrapped open
4737149.126.72.220 9005 tcp tcpwrapped open
4738149.126.72.220 9006 tcp tcpwrapped open
4739149.126.72.220 9007 tcp tcpwrapped open
4740149.126.72.220 9008 tcp tcpwrapped open
4741149.126.72.220 9009 tcp tcpwrapped open
4742149.126.72.220 9010 tcp tcpwrapped open
4743149.126.72.220 9011 tcp tcpwrapped open
4744149.126.72.220 9012 tcp tcpwrapped open
4745149.126.72.220 9013 tcp tcpwrapped open
4746149.126.72.220 9014 tcp tcpwrapped open
4747149.126.72.220 9015 tcp tcpwrapped open
4748149.126.72.220 9016 tcp tcpwrapped open
4749149.126.72.220 9017 tcp tcpwrapped open
4750149.126.72.220 9018 tcp tcpwrapped open
4751149.126.72.220 9019 tcp tcpwrapped open
4752149.126.72.220 9020 tcp tcpwrapped open
4753149.126.72.220 9021 tcp tcpwrapped open
4754149.126.72.220 9022 tcp tcpwrapped open
4755149.126.72.220 9023 tcp tcpwrapped open
4756149.126.72.220 9024 tcp tcpwrapped open
4757149.126.72.220 9025 tcp tcpwrapped open
4758149.126.72.220 9026 tcp tcpwrapped open
4759149.126.72.220 9027 tcp tcpwrapped open
4760149.126.72.220 9028 tcp tcpwrapped open
4761149.126.72.220 9029 tcp tcpwrapped open
4762149.126.72.220 9030 tcp tcpwrapped open
4763149.126.72.220 9031 tcp tcpwrapped open
4764149.126.72.220 9032 tcp tcpwrapped open
4765149.126.72.220 9033 tcp tcpwrapped open
4766149.126.72.220 9034 tcp tcpwrapped open
4767149.126.72.220 9035 tcp tcpwrapped open
4768149.126.72.220 9036 tcp tcpwrapped open
4769149.126.72.220 9037 tcp tcpwrapped open
4770149.126.72.220 9038 tcp tcpwrapped open
4771149.126.72.220 9039 tcp tcpwrapped open
4772149.126.72.220 9040 tcp tcpwrapped open
4773149.126.72.220 9041 tcp tcpwrapped open
4774149.126.72.220 9042 tcp tcpwrapped open
4775149.126.72.220 9043 tcp tcpwrapped open
4776149.126.72.220 9044 tcp tcpwrapped open
4777149.126.72.220 9045 tcp tcpwrapped open
4778149.126.72.220 9046 tcp tcpwrapped open
4779149.126.72.220 9047 tcp tcpwrapped open
4780149.126.72.220 9048 tcp tcpwrapped open
4781149.126.72.220 9049 tcp tcpwrapped open
4782149.126.72.220 9050 tcp tcpwrapped open
4783149.126.72.220 9051 tcp tcpwrapped open
4784149.126.72.220 9052 tcp tcpwrapped open
4785149.126.72.220 9058 tcp tcpwrapped open
4786149.126.72.220 9060 tcp tcpwrapped open
4787149.126.72.220 9061 tcp tcpwrapped open
4788149.126.72.220 9070 tcp tcpwrapped open
4789149.126.72.220 9080 tcp tcpwrapped open
4790149.126.72.220 9081 tcp tcpwrapped open
4791149.126.72.220 9082 tcp tcpwrapped open
4792149.126.72.220 9084 tcp tcpwrapped open
4793149.126.72.220 9085 tcp tcpwrapped open
4794149.126.72.220 9086 tcp tcpwrapped open
4795149.126.72.220 9088 tcp tcpwrapped open
4796149.126.72.220 9089 tcp tcpwrapped open
4797149.126.72.220 9090 tcp tcpwrapped open
4798149.126.72.220 9091 tcp tcpwrapped open
4799149.126.72.220 9092 tcp tcpwrapped open
4800149.126.72.220 9093 tcp tcpwrapped open
4801149.126.72.220 9094 tcp tcpwrapped open
4802149.126.72.220 9095 tcp tcpwrapped open
4803149.126.72.220 9096 tcp tcpwrapped open
4804149.126.72.220 9097 tcp tcpwrapped open
4805149.126.72.220 9098 tcp tcpwrapped open
4806149.126.72.220 9099 tcp tcpwrapped open
4807149.126.72.220 9100 tcp jetdirect open
4808149.126.72.220 9101 tcp jetdirect open
4809149.126.72.220 9102 tcp jetdirect open
4810149.126.72.220 9103 tcp jetdirect open
4811149.126.72.220 9104 tcp jetdirect open
4812149.126.72.220 9105 tcp jetdirect open
4813149.126.72.220 9106 tcp jetdirect open
4814149.126.72.220 9107 tcp jetdirect open
4815149.126.72.220 9108 tcp tcpwrapped open
4816149.126.72.220 9109 tcp tcpwrapped open
4817149.126.72.220 9110 tcp tcpwrapped open
4818149.126.72.220 9111 tcp tcpwrapped open
4819149.126.72.220 9136 tcp tcpwrapped open
4820149.126.72.220 9143 tcp tcpwrapped open
4821149.126.72.220 9189 tcp tcpwrapped open
4822149.126.72.220 9199 tcp tcpwrapped open
4823149.126.72.220 9200 tcp tcpwrapped open
4824149.126.72.220 9201 tcp tcpwrapped open
4825149.126.72.220 9202 tcp tcpwrapped open
4826149.126.72.220 9203 tcp tcpwrapped open
4827149.126.72.220 9204 tcp tcpwrapped open
4828149.126.72.220 9205 tcp tcpwrapped open
4829149.126.72.220 9206 tcp tcpwrapped open
4830149.126.72.220 9207 tcp tcpwrapped open
4831149.126.72.220 9208 tcp tcpwrapped open
4832149.126.72.220 9209 tcp tcpwrapped open
4833149.126.72.220 9210 tcp tcpwrapped open
4834149.126.72.220 9211 tcp tcpwrapped open
4835149.126.72.220 9212 tcp tcpwrapped open
4836149.126.72.220 9213 tcp tcpwrapped open
4837149.126.72.220 9214 tcp tcpwrapped open
4838149.126.72.220 9215 tcp tcpwrapped open
4839149.126.72.220 9216 tcp tcpwrapped open
4840149.126.72.220 9217 tcp tcpwrapped open
4841149.126.72.220 9218 tcp tcpwrapped open
4842149.126.72.220 9219 tcp tcpwrapped open
4843149.126.72.220 9220 tcp tcpwrapped open
4844149.126.72.220 9221 tcp tcpwrapped open
4845149.126.72.220 9236 tcp tcpwrapped open
4846149.126.72.220 9251 tcp tcpwrapped open
4847149.126.72.220 9289 tcp tcpwrapped open
4848149.126.72.220 9299 tcp tcpwrapped open
4849149.126.72.220 9300 tcp tcpwrapped open
4850149.126.72.220 9301 tcp tcpwrapped open
4851149.126.72.220 9302 tcp tcpwrapped open
4852149.126.72.220 9303 tcp tcpwrapped open
4853149.126.72.220 9304 tcp tcpwrapped open
4854149.126.72.220 9305 tcp tcpwrapped open
4855149.126.72.220 9306 tcp tcpwrapped open
4856149.126.72.220 9307 tcp tcpwrapped open
4857149.126.72.220 9308 tcp tcpwrapped open
4858149.126.72.220 9309 tcp tcpwrapped open
4859149.126.72.220 9310 tcp tcpwrapped open
4860149.126.72.220 9311 tcp tcpwrapped open
4861149.126.72.220 9350 tcp tcpwrapped open
4862149.126.72.220 9383 tcp tcpwrapped open
4863149.126.72.220 9387 tcp tcpwrapped open
4864149.126.72.220 9389 tcp tcpwrapped open
4865149.126.72.220 9433 tcp tcpwrapped open
4866149.126.72.220 9443 tcp tcpwrapped open
4867149.126.72.220 9444 tcp tcpwrapped open
4868149.126.72.220 9446 tcp tcpwrapped open
4869149.126.72.220 9447 tcp tcpwrapped open
4870149.126.72.220 9500 tcp tcpwrapped open
4871149.126.72.220 9510 tcp tcpwrapped open
4872149.126.72.220 9530 tcp tcpwrapped open
4873149.126.72.220 9550 tcp tcpwrapped open
4874149.126.72.220 9600 tcp tcpwrapped open
4875149.126.72.220 9663 tcp tcpwrapped open
4876149.126.72.220 9690 tcp tcpwrapped open
4877149.126.72.220 9704 tcp tcpwrapped open
4878149.126.72.220 9710 tcp tcpwrapped open
4879149.126.72.220 9711 tcp tcpwrapped open
4880149.126.72.220 9765 tcp tcpwrapped open
4881149.126.72.220 9773 tcp tcpwrapped open
4882149.126.72.220 9779 tcp tcpwrapped open
4883149.126.72.220 9800 tcp tcpwrapped open
4884149.126.72.220 9803 tcp tcpwrapped open
4885149.126.72.220 9804 tcp tcpwrapped open
4886149.126.72.220 9950 tcp tcpwrapped open
4887149.126.72.220 9991 tcp tcpwrapped open
4888149.126.72.220 9992 tcp tcpwrapped open
4889149.126.72.220 9993 tcp tcpwrapped open
4890149.126.72.220 9994 tcp tcpwrapped open
4891149.126.72.220 9997 tcp tcpwrapped open
4892149.126.72.220 9998 tcp tcpwrapped open
4893149.126.72.220 9999 tcp tcpwrapped open
4894149.126.72.220 10000 tcp tcpwrapped open
4895149.126.72.220 10001 tcp tcpwrapped open
4896149.126.72.220 10002 tcp tcpwrapped open
4897149.126.72.220 10003 tcp tcpwrapped open
4898149.126.72.220 10004 tcp tcpwrapped open
4899149.126.72.220 10005 tcp tcpwrapped open
4900149.126.72.220 10006 tcp tcpwrapped open
4901149.126.72.220 10007 tcp tcpwrapped open
4902149.126.72.220 10008 tcp tcpwrapped open
4903149.126.72.220 10009 tcp tcpwrapped open
4904149.126.72.220 10010 tcp tcpwrapped open
4905149.126.72.220 10011 tcp tcpwrapped open
4906149.126.72.220 10012 tcp tcpwrapped open
4907149.126.72.220 10013 tcp tcpwrapped open
4908149.126.72.220 10014 tcp tcpwrapped open
4909149.126.72.220 10015 tcp tcpwrapped open
4910149.126.72.220 10016 tcp tcpwrapped open
4911149.126.72.220 10017 tcp tcpwrapped open
4912149.126.72.220 10018 tcp tcpwrapped open
4913149.126.72.220 10019 tcp tcpwrapped open
4914149.126.72.220 10020 tcp tcpwrapped open
4915149.126.72.220 10021 tcp tcpwrapped open
4916149.126.72.220 10022 tcp tcpwrapped open
4917149.126.72.220 10023 tcp tcpwrapped open
4918149.126.72.220 10024 tcp tcpwrapped open
4919149.126.72.220 10025 tcp tcpwrapped open
4920149.126.72.220 10026 tcp tcpwrapped open
4921149.126.72.220 10027 tcp tcpwrapped open
4922149.126.72.220 10028 tcp tcpwrapped open
4923149.126.72.220 10029 tcp tcpwrapped open
4924149.126.72.220 10030 tcp tcpwrapped open
4925149.126.72.220 10031 tcp tcpwrapped open
4926149.126.72.220 10032 tcp tcpwrapped open
4927149.126.72.220 10033 tcp tcpwrapped open
4928149.126.72.220 10034 tcp tcpwrapped open
4929149.126.72.220 10035 tcp tcpwrapped open
4930149.126.72.220 10036 tcp tcpwrapped open
4931149.126.72.220 10037 tcp tcpwrapped open
4932149.126.72.220 10038 tcp tcpwrapped open
4933149.126.72.220 10039 tcp tcpwrapped open
4934149.126.72.220 10040 tcp tcpwrapped open
4935149.126.72.220 10041 tcp tcpwrapped open
4936149.126.72.220 10042 tcp tcpwrapped open
4937149.126.72.220 10043 tcp tcpwrapped open
4938149.126.72.220 10044 tcp tcpwrapped open
4939149.126.72.220 10045 tcp tcpwrapped open
4940149.126.72.220 10046 tcp tcpwrapped open
4941149.126.72.220 10047 tcp tcpwrapped open
4942149.126.72.220 10048 tcp tcpwrapped open
4943149.126.72.220 10049 tcp tcpwrapped open
4944149.126.72.220 10065 tcp tcpwrapped open
4945149.126.72.220 10071 tcp tcpwrapped open
4946149.126.72.220 10075 tcp tcpwrapped open
4947149.126.72.220 10082 tcp tcpwrapped open
4948149.126.72.220 10084 tcp tcpwrapped open
4949149.126.72.220 10100 tcp tcpwrapped open
4950149.126.72.220 10123 tcp tcpwrapped open
4951149.126.72.220 10200 tcp tcpwrapped open
4952149.126.72.220 10443 tcp tcpwrapped open
4953149.126.72.220 10444 tcp tcpwrapped open
4954149.126.72.220 10892 tcp tcpwrapped open
4955149.126.72.220 10894 tcp tcpwrapped open
4956149.126.72.220 11001 tcp tcpwrapped open
4957149.126.72.220 11002 tcp tcpwrapped open
4958149.126.72.220 11007 tcp tcpwrapped open
4959149.126.72.220 11027 tcp tcpwrapped open
4960149.126.72.220 11065 tcp tcpwrapped open
4961149.126.72.220 11075 tcp tcpwrapped open
4962149.126.72.220 11082 tcp tcpwrapped open
4963149.126.72.220 11084 tcp tcpwrapped open
4964149.126.72.220 11110 tcp tcpwrapped open
4965149.126.72.220 11182 tcp tcpwrapped open
4966149.126.72.220 11184 tcp tcpwrapped open
4967149.126.72.220 11443 tcp tcpwrapped open
4968149.126.72.220 12016 tcp tcpwrapped open
4969149.126.72.220 12082 tcp tcpwrapped open
4970149.126.72.220 12084 tcp tcpwrapped open
4971149.126.72.220 12103 tcp tcpwrapped open
4972149.126.72.220 12104 tcp tcpwrapped open
4973149.126.72.220 12105 tcp tcpwrapped open
4974149.126.72.220 12106 tcp tcpwrapped open
4975149.126.72.220 12107 tcp tcpwrapped open
4976149.126.72.220 12108 tcp tcpwrapped open
4977149.126.72.220 12109 tcp tcpwrapped open
4978149.126.72.220 12110 tcp tcpwrapped open
4979149.126.72.220 12111 tcp tcpwrapped open
4980149.126.72.220 12112 tcp tcpwrapped open
4981149.126.72.220 12113 tcp tcpwrapped open
4982149.126.72.220 12114 tcp tcpwrapped open
4983149.126.72.220 12115 tcp tcpwrapped open
4984149.126.72.220 12116 tcp tcpwrapped open
4985149.126.72.220 12117 tcp tcpwrapped open
4986149.126.72.220 12118 tcp tcpwrapped open
4987149.126.72.220 12119 tcp tcpwrapped open
4988149.126.72.220 12120 tcp tcpwrapped open
4989149.126.72.220 12121 tcp tcpwrapped open
4990149.126.72.220 12122 tcp tcpwrapped open
4991149.126.72.220 12123 tcp tcpwrapped open
4992149.126.72.220 12124 tcp tcpwrapped open
4993149.126.72.220 12125 tcp tcpwrapped open
4994149.126.72.220 12126 tcp tcpwrapped open
4995149.126.72.220 12127 tcp tcpwrapped open
4996149.126.72.220 12128 tcp tcpwrapped open
4997149.126.72.220 12129 tcp tcpwrapped open
4998149.126.72.220 12130 tcp tcpwrapped open
4999149.126.72.220 12131 tcp tcpwrapped open
5000149.126.72.220 12132 tcp tcpwrapped open
5001149.126.72.220 12133 tcp tcpwrapped open
5002149.126.72.220 12134 tcp tcpwrapped open
5003149.126.72.220 12135 tcp tcpwrapped open
5004149.126.72.220 12136 tcp tcpwrapped open
5005149.126.72.220 12137 tcp tcpwrapped open
5006149.126.72.220 12138 tcp tcpwrapped open
5007149.126.72.220 12139 tcp tcpwrapped open
5008149.126.72.220 12140 tcp tcpwrapped open
5009149.126.72.220 12141 tcp tcpwrapped open
5010149.126.72.220 12142 tcp tcpwrapped open
5011149.126.72.220 12143 tcp tcpwrapped open
5012149.126.72.220 12144 tcp tcpwrapped open
5013149.126.72.220 12145 tcp tcpwrapped open
5014149.126.72.220 12146 tcp tcpwrapped open
5015149.126.72.220 12147 tcp tcpwrapped open
5016149.126.72.220 12148 tcp tcpwrapped open
5017149.126.72.220 12149 tcp tcpwrapped open
5018149.126.72.220 12150 tcp tcpwrapped open
5019149.126.72.220 12151 tcp tcpwrapped open
5020149.126.72.220 12152 tcp tcpwrapped open
5021149.126.72.220 12153 tcp tcpwrapped open
5022149.126.72.220 12154 tcp tcpwrapped open
5023149.126.72.220 12155 tcp tcpwrapped open
5024149.126.72.220 12156 tcp tcpwrapped open
5025149.126.72.220 12157 tcp tcpwrapped open
5026149.126.72.220 12158 tcp tcpwrapped open
5027149.126.72.220 12159 tcp tcpwrapped open
5028149.126.72.220 12160 tcp tcpwrapped open
5029149.126.72.220 12161 tcp tcpwrapped open
5030149.126.72.220 12162 tcp tcpwrapped open
5031149.126.72.220 12163 tcp tcpwrapped open
5032149.126.72.220 12164 tcp tcpwrapped open
5033149.126.72.220 12165 tcp tcpwrapped open
5034149.126.72.220 12166 tcp tcpwrapped open
5035149.126.72.220 12167 tcp tcpwrapped open
5036149.126.72.220 12168 tcp tcpwrapped open
5037149.126.72.220 12169 tcp tcpwrapped open
5038149.126.72.220 12170 tcp tcpwrapped open
5039149.126.72.220 12171 tcp tcpwrapped open
5040149.126.72.220 12172 tcp tcpwrapped open
5041149.126.72.220 12173 tcp tcpwrapped open
5042149.126.72.220 12174 tcp tcpwrapped open
5043149.126.72.220 12175 tcp tcpwrapped open
5044149.126.72.220 12176 tcp tcpwrapped open
5045149.126.72.220 12177 tcp tcpwrapped open
5046149.126.72.220 12178 tcp tcpwrapped open
5047149.126.72.220 12179 tcp tcpwrapped open
5048149.126.72.220 12180 tcp tcpwrapped open
5049149.126.72.220 12181 tcp tcpwrapped open
5050149.126.72.220 12182 tcp tcpwrapped open
5051149.126.72.220 12183 tcp tcpwrapped open
5052149.126.72.220 12184 tcp tcpwrapped open
5053149.126.72.220 12185 tcp tcpwrapped open
5054149.126.72.220 12186 tcp tcpwrapped open
5055149.126.72.220 12187 tcp tcpwrapped open
5056149.126.72.220 12188 tcp tcpwrapped open
5057149.126.72.220 12189 tcp tcpwrapped open
5058149.126.72.220 12190 tcp tcpwrapped open
5059149.126.72.220 12191 tcp tcpwrapped open
5060149.126.72.220 12192 tcp tcpwrapped open
5061149.126.72.220 12193 tcp tcpwrapped open
5062149.126.72.220 12194 tcp tcpwrapped open
5063149.126.72.220 12195 tcp tcpwrapped open
5064149.126.72.220 12196 tcp tcpwrapped open
5065149.126.72.220 12197 tcp tcpwrapped open
5066149.126.72.220 12198 tcp tcpwrapped open
5067149.126.72.220 12199 tcp tcpwrapped open
5068149.126.72.220 12200 tcp tcpwrapped open
5069149.126.72.220 12201 tcp tcpwrapped open
5070149.126.72.220 12202 tcp tcpwrapped open
5071149.126.72.220 12203 tcp tcpwrapped open
5072149.126.72.220 12204 tcp tcpwrapped open
5073149.126.72.220 12205 tcp tcpwrapped open
5074149.126.72.220 12206 tcp tcpwrapped open
5075149.126.72.220 12207 tcp tcpwrapped open
5076149.126.72.220 12208 tcp tcpwrapped open
5077149.126.72.220 12209 tcp tcpwrapped open
5078149.126.72.220 12210 tcp tcpwrapped open
5079149.126.72.220 12211 tcp tcpwrapped open
5080149.126.72.220 12212 tcp tcpwrapped open
5081149.126.72.220 12213 tcp tcpwrapped open
5082149.126.72.220 12214 tcp tcpwrapped open
5083149.126.72.220 12215 tcp tcpwrapped open
5084149.126.72.220 12216 tcp tcpwrapped open
5085149.126.72.220 12217 tcp tcpwrapped open
5086149.126.72.220 12218 tcp tcpwrapped open
5087149.126.72.220 12219 tcp tcpwrapped open
5088149.126.72.220 12220 tcp tcpwrapped open
5089149.126.72.220 12221 tcp tcpwrapped open
5090149.126.72.220 12222 tcp tcpwrapped open
5091149.126.72.220 12223 tcp tcpwrapped open
5092149.126.72.220 12224 tcp tcpwrapped open
5093149.126.72.220 12225 tcp tcpwrapped open
5094149.126.72.220 12226 tcp tcpwrapped open
5095149.126.72.220 12227 tcp tcpwrapped open
5096149.126.72.220 12228 tcp tcpwrapped open
5097149.126.72.220 12229 tcp tcpwrapped open
5098149.126.72.220 12230 tcp tcpwrapped open
5099149.126.72.220 12231 tcp tcpwrapped open
5100149.126.72.220 12232 tcp tcpwrapped open
5101149.126.72.220 12233 tcp tcpwrapped open
5102149.126.72.220 12234 tcp tcpwrapped open
5103149.126.72.220 12235 tcp tcpwrapped open
5104149.126.72.220 12236 tcp tcpwrapped open
5105149.126.72.220 12237 tcp tcpwrapped open
5106149.126.72.220 12238 tcp tcpwrapped open
5107149.126.72.220 12239 tcp tcpwrapped open
5108149.126.72.220 12240 tcp tcpwrapped open
5109149.126.72.220 12241 tcp tcpwrapped open
5110149.126.72.220 12242 tcp tcpwrapped open
5111149.126.72.220 12243 tcp tcpwrapped open
5112149.126.72.220 12244 tcp tcpwrapped open
5113149.126.72.220 12245 tcp tcpwrapped open
5114149.126.72.220 12246 tcp tcpwrapped open
5115149.126.72.220 12247 tcp tcpwrapped open
5116149.126.72.220 12248 tcp tcpwrapped open
5117149.126.72.220 12249 tcp tcpwrapped open
5118149.126.72.220 12250 tcp tcpwrapped open
5119149.126.72.220 12251 tcp tcpwrapped open
5120149.126.72.220 12252 tcp tcpwrapped open
5121149.126.72.220 12253 tcp tcpwrapped open
5122149.126.72.220 12254 tcp tcpwrapped open
5123149.126.72.220 12255 tcp tcpwrapped open
5124149.126.72.220 12256 tcp tcpwrapped open
5125149.126.72.220 12257 tcp tcpwrapped open
5126149.126.72.220 12258 tcp tcpwrapped open
5127149.126.72.220 12259 tcp tcpwrapped open
5128149.126.72.220 12260 tcp tcpwrapped open
5129149.126.72.220 12261 tcp tcpwrapped open
5130149.126.72.220 12262 tcp tcpwrapped open
5131149.126.72.220 12263 tcp tcpwrapped open
5132149.126.72.220 12264 tcp tcpwrapped open
5133149.126.72.220 12265 tcp tcpwrapped open
5134149.126.72.220 12266 tcp tcpwrapped open
5135149.126.72.220 12267 tcp tcpwrapped open
5136149.126.72.220 12268 tcp tcpwrapped open
5137149.126.72.220 12269 tcp tcpwrapped open
5138149.126.72.220 12270 tcp tcpwrapped open
5139149.126.72.220 12271 tcp tcpwrapped open
5140149.126.72.220 12272 tcp tcpwrapped open
5141149.126.72.220 12273 tcp tcpwrapped open
5142149.126.72.220 12274 tcp tcpwrapped open
5143149.126.72.220 12275 tcp tcpwrapped open
5144149.126.72.220 12276 tcp tcpwrapped open
5145149.126.72.220 12277 tcp tcpwrapped open
5146149.126.72.220 12278 tcp tcpwrapped open
5147149.126.72.220 12279 tcp tcpwrapped open
5148149.126.72.220 12280 tcp tcpwrapped open
5149149.126.72.220 12281 tcp tcpwrapped open
5150149.126.72.220 12282 tcp tcpwrapped open
5151149.126.72.220 12283 tcp tcpwrapped open
5152149.126.72.220 12284 tcp tcpwrapped open
5153149.126.72.220 12285 tcp tcpwrapped open
5154149.126.72.220 12286 tcp tcpwrapped open
5155149.126.72.220 12287 tcp tcpwrapped open
5156149.126.72.220 12288 tcp tcpwrapped open
5157149.126.72.220 12289 tcp tcpwrapped open
5158149.126.72.220 12290 tcp tcpwrapped open
5159149.126.72.220 12291 tcp tcpwrapped open
5160149.126.72.220 12292 tcp tcpwrapped open
5161149.126.72.220 12293 tcp tcpwrapped open
5162149.126.72.220 12294 tcp tcpwrapped open
5163149.126.72.220 12295 tcp tcpwrapped open
5164149.126.72.220 12296 tcp tcpwrapped open
5165149.126.72.220 12297 tcp tcpwrapped open
5166149.126.72.220 12298 tcp tcpwrapped open
5167149.126.72.220 12299 tcp tcpwrapped open
5168149.126.72.220 12300 tcp tcpwrapped open
5169149.126.72.220 12301 tcp tcpwrapped open
5170149.126.72.220 12302 tcp tcpwrapped open
5171149.126.72.220 12303 tcp tcpwrapped open
5172149.126.72.220 12304 tcp tcpwrapped open
5173149.126.72.220 12305 tcp tcpwrapped open
5174149.126.72.220 12306 tcp tcpwrapped open
5175149.126.72.220 12307 tcp tcpwrapped open
5176149.126.72.220 12308 tcp tcpwrapped open
5177149.126.72.220 12309 tcp tcpwrapped open
5178149.126.72.220 12310 tcp tcpwrapped open
5179149.126.72.220 12311 tcp tcpwrapped open
5180149.126.72.220 12312 tcp tcpwrapped open
5181149.126.72.220 12313 tcp tcpwrapped open
5182149.126.72.220 12314 tcp tcpwrapped open
5183149.126.72.220 12315 tcp tcpwrapped open
5184149.126.72.220 12316 tcp tcpwrapped open
5185149.126.72.220 12317 tcp tcpwrapped open
5186149.126.72.220 12318 tcp tcpwrapped open
5187149.126.72.220 12319 tcp tcpwrapped open
5188149.126.72.220 12320 tcp tcpwrapped open
5189149.126.72.220 12321 tcp tcpwrapped open
5190149.126.72.220 12322 tcp tcpwrapped open
5191149.126.72.220 12323 tcp tcpwrapped open
5192149.126.72.220 12324 tcp tcpwrapped open
5193149.126.72.220 12325 tcp tcpwrapped open
5194149.126.72.220 12326 tcp tcpwrapped open
5195149.126.72.220 12327 tcp tcpwrapped open
5196149.126.72.220 12328 tcp tcpwrapped open
5197149.126.72.220 12329 tcp tcpwrapped open
5198149.126.72.220 12330 tcp tcpwrapped open
5199149.126.72.220 12331 tcp tcpwrapped open
5200149.126.72.220 12332 tcp tcpwrapped open
5201149.126.72.220 12333 tcp tcpwrapped open
5202149.126.72.220 12334 tcp tcpwrapped open
5203149.126.72.220 12335 tcp tcpwrapped open
5204149.126.72.220 12336 tcp tcpwrapped open
5205149.126.72.220 12337 tcp tcpwrapped open
5206149.126.72.220 12338 tcp tcpwrapped open
5207149.126.72.220 12339 tcp tcpwrapped open
5208149.126.72.220 12340 tcp tcpwrapped open
5209149.126.72.220 12341 tcp tcpwrapped open
5210149.126.72.220 12342 tcp tcpwrapped open
5211149.126.72.220 12343 tcp tcpwrapped open
5212149.126.72.220 12344 tcp tcpwrapped open
5213149.126.72.220 12345 tcp tcpwrapped open
5214149.126.72.220 12346 tcp tcpwrapped open
5215149.126.72.220 12347 tcp tcpwrapped open
5216149.126.72.220 12348 tcp tcpwrapped open
5217149.126.72.220 12349 tcp tcpwrapped open
5218149.126.72.220 12350 tcp tcpwrapped open
5219149.126.72.220 12351 tcp tcpwrapped open
5220149.126.72.220 12352 tcp tcpwrapped open
5221149.126.72.220 12353 tcp tcpwrapped open
5222149.126.72.220 12354 tcp tcpwrapped open
5223149.126.72.220 12355 tcp tcpwrapped open
5224149.126.72.220 12356 tcp tcpwrapped open
5225149.126.72.220 12357 tcp tcpwrapped open
5226149.126.72.220 12358 tcp tcpwrapped open
5227149.126.72.220 12359 tcp tcpwrapped open
5228149.126.72.220 12360 tcp tcpwrapped open
5229149.126.72.220 12361 tcp tcpwrapped open
5230149.126.72.220 12362 tcp tcpwrapped open
5231149.126.72.220 12363 tcp tcpwrapped open
5232149.126.72.220 12364 tcp tcpwrapped open
5233149.126.72.220 12365 tcp tcpwrapped open
5234149.126.72.220 12366 tcp tcpwrapped open
5235149.126.72.220 12367 tcp tcpwrapped open
5236149.126.72.220 12368 tcp tcpwrapped open
5237149.126.72.220 12369 tcp tcpwrapped open
5238149.126.72.220 12370 tcp tcpwrapped open
5239149.126.72.220 12371 tcp tcpwrapped open
5240149.126.72.220 12372 tcp tcpwrapped open
5241149.126.72.220 12373 tcp tcpwrapped open
5242149.126.72.220 12374 tcp tcpwrapped open
5243149.126.72.220 12375 tcp tcpwrapped open
5244149.126.72.220 12376 tcp tcpwrapped open
5245149.126.72.220 12377 tcp tcpwrapped open
5246149.126.72.220 12378 tcp tcpwrapped open
5247149.126.72.220 12379 tcp tcpwrapped open
5248149.126.72.220 12380 tcp tcpwrapped open
5249149.126.72.220 12381 tcp tcpwrapped open
5250149.126.72.220 12382 tcp tcpwrapped open
5251149.126.72.220 12383 tcp tcpwrapped open
5252149.126.72.220 12384 tcp tcpwrapped open
5253149.126.72.220 12385 tcp tcpwrapped open
5254149.126.72.220 12386 tcp tcpwrapped open
5255149.126.72.220 12387 tcp tcpwrapped open
5256149.126.72.220 12388 tcp tcpwrapped open
5257149.126.72.220 12389 tcp tcpwrapped open
5258149.126.72.220 12390 tcp tcpwrapped open
5259149.126.72.220 12391 tcp tcpwrapped open
5260149.126.72.220 12392 tcp tcpwrapped open
5261149.126.72.220 12393 tcp tcpwrapped open
5262149.126.72.220 12394 tcp tcpwrapped open
5263149.126.72.220 12395 tcp tcpwrapped open
5264149.126.72.220 12396 tcp tcpwrapped open
5265149.126.72.220 12397 tcp tcpwrapped open
5266149.126.72.220 12398 tcp tcpwrapped open
5267149.126.72.220 12399 tcp tcpwrapped open
5268149.126.72.220 12400 tcp tcpwrapped open
5269149.126.72.220 12401 tcp tcpwrapped open
5270149.126.72.220 12402 tcp tcpwrapped open
5271149.126.72.220 12403 tcp tcpwrapped open
5272149.126.72.220 12404 tcp tcpwrapped open
5273149.126.72.220 12405 tcp tcpwrapped open
5274149.126.72.220 12406 tcp tcpwrapped open
5275149.126.72.220 12407 tcp tcpwrapped open
5276149.126.72.220 12408 tcp tcpwrapped open
5277149.126.72.220 12409 tcp tcpwrapped open
5278149.126.72.220 12410 tcp tcpwrapped open
5279149.126.72.220 12411 tcp tcpwrapped open
5280149.126.72.220 12412 tcp tcpwrapped open
5281149.126.72.220 12413 tcp tcpwrapped open
5282149.126.72.220 12414 tcp tcpwrapped open
5283149.126.72.220 12415 tcp tcpwrapped open
5284149.126.72.220 12416 tcp tcpwrapped open
5285149.126.72.220 12417 tcp tcpwrapped open
5286149.126.72.220 12418 tcp tcpwrapped open
5287149.126.72.220 12419 tcp tcpwrapped open
5288149.126.72.220 12420 tcp tcpwrapped open
5289149.126.72.220 12421 tcp tcpwrapped open
5290149.126.72.220 12422 tcp tcpwrapped open
5291149.126.72.220 12423 tcp tcpwrapped open
5292149.126.72.220 12424 tcp tcpwrapped open
5293149.126.72.220 12425 tcp tcpwrapped open
5294149.126.72.220 12426 tcp tcpwrapped open
5295149.126.72.220 12427 tcp tcpwrapped open
5296149.126.72.220 12428 tcp tcpwrapped open
5297149.126.72.220 12429 tcp tcpwrapped open
5298149.126.72.220 12430 tcp tcpwrapped open
5299149.126.72.220 12431 tcp tcpwrapped open
5300149.126.72.220 12432 tcp tcpwrapped open
5301149.126.72.220 12433 tcp tcpwrapped open
5302149.126.72.220 12434 tcp tcpwrapped open
5303149.126.72.220 12435 tcp tcpwrapped open
5304149.126.72.220 12436 tcp tcpwrapped open
5305149.126.72.220 12437 tcp tcpwrapped open
5306149.126.72.220 12438 tcp tcpwrapped open
5307149.126.72.220 12439 tcp tcpwrapped open
5308149.126.72.220 12440 tcp tcpwrapped open
5309149.126.72.220 12441 tcp tcpwrapped open
5310149.126.72.220 12442 tcp tcpwrapped open
5311149.126.72.220 12443 tcp tcpwrapped open
5312149.126.72.220 12444 tcp tcpwrapped open
5313149.126.72.220 12445 tcp tcpwrapped open
5314149.126.72.220 12446 tcp tcpwrapped open
5315149.126.72.220 12447 tcp tcpwrapped open
5316149.126.72.220 12448 tcp tcpwrapped open
5317149.126.72.220 12449 tcp tcpwrapped open
5318149.126.72.220 12450 tcp tcpwrapped open
5319149.126.72.220 12451 tcp tcpwrapped open
5320149.126.72.220 12452 tcp tcpwrapped open
5321149.126.72.220 12453 tcp tcpwrapped open
5322149.126.72.220 12454 tcp tcpwrapped open
5323149.126.72.220 12455 tcp tcpwrapped open
5324149.126.72.220 12456 tcp tcpwrapped open
5325149.126.72.220 12457 tcp tcpwrapped open
5326149.126.72.220 12458 tcp tcpwrapped open
5327149.126.72.220 12459 tcp tcpwrapped open
5328149.126.72.220 12460 tcp tcpwrapped open
5329149.126.72.220 12461 tcp tcpwrapped open
5330149.126.72.220 12462 tcp tcpwrapped open
5331149.126.72.220 12463 tcp tcpwrapped open
5332149.126.72.220 12464 tcp tcpwrapped open
5333149.126.72.220 12465 tcp tcpwrapped open
5334149.126.72.220 12466 tcp tcpwrapped open
5335149.126.72.220 12467 tcp tcpwrapped open
5336149.126.72.220 12468 tcp tcpwrapped open
5337149.126.72.220 12469 tcp tcpwrapped open
5338149.126.72.220 12470 tcp tcpwrapped open
5339149.126.72.220 12471 tcp tcpwrapped open
5340149.126.72.220 12472 tcp tcpwrapped open
5341149.126.72.220 12473 tcp tcpwrapped open
5342149.126.72.220 12474 tcp tcpwrapped open
5343149.126.72.220 12475 tcp tcpwrapped open
5344149.126.72.220 12476 tcp tcpwrapped open
5345149.126.72.220 12477 tcp tcpwrapped open
5346149.126.72.220 12478 tcp tcpwrapped open
5347149.126.72.220 12479 tcp tcpwrapped open
5348149.126.72.220 12480 tcp tcpwrapped open
5349149.126.72.220 12481 tcp tcpwrapped open
5350149.126.72.220 12482 tcp tcpwrapped open
5351149.126.72.220 12483 tcp tcpwrapped open
5352149.126.72.220 12484 tcp tcpwrapped open
5353149.126.72.220 12485 tcp tcpwrapped open
5354149.126.72.220 12486 tcp tcpwrapped open
5355149.126.72.220 12487 tcp tcpwrapped open
5356149.126.72.220 12488 tcp tcpwrapped open
5357149.126.72.220 12489 tcp tcpwrapped open
5358149.126.72.220 12490 tcp tcpwrapped open
5359149.126.72.220 12491 tcp tcpwrapped open
5360149.126.72.220 12492 tcp tcpwrapped open
5361149.126.72.220 12493 tcp tcpwrapped open
5362149.126.72.220 12494 tcp tcpwrapped open
5363149.126.72.220 12495 tcp tcpwrapped open
5364149.126.72.220 12496 tcp tcpwrapped open
5365149.126.72.220 12497 tcp tcpwrapped open
5366149.126.72.220 12498 tcp tcpwrapped open
5367149.126.72.220 12499 tcp tcpwrapped open
5368149.126.72.220 12500 tcp tcpwrapped open
5369149.126.72.220 12501 tcp tcpwrapped open
5370149.126.72.220 12502 tcp tcpwrapped open
5371149.126.72.220 12503 tcp tcpwrapped open
5372149.126.72.220 12504 tcp tcpwrapped open
5373149.126.72.220 12505 tcp tcpwrapped open
5374149.126.72.220 12506 tcp tcpwrapped open
5375149.126.72.220 12507 tcp tcpwrapped open
5376149.126.72.220 12508 tcp tcpwrapped open
5377149.126.72.220 12509 tcp tcpwrapped open
5378149.126.72.220 12510 tcp tcpwrapped open
5379149.126.72.220 12511 tcp tcpwrapped open
5380149.126.72.220 12512 tcp tcpwrapped open
5381149.126.72.220 12513 tcp tcpwrapped open
5382149.126.72.220 12514 tcp tcpwrapped open
5383149.126.72.220 12515 tcp tcpwrapped open
5384149.126.72.220 12516 tcp tcpwrapped open
5385149.126.72.220 12517 tcp tcpwrapped open
5386149.126.72.220 12518 tcp tcpwrapped open
5387149.126.72.220 12519 tcp tcpwrapped open
5388149.126.72.220 12520 tcp tcpwrapped open
5389149.126.72.220 12521 tcp tcpwrapped open
5390149.126.72.220 12522 tcp tcpwrapped open
5391149.126.72.220 12523 tcp tcpwrapped open
5392149.126.72.220 12524 tcp tcpwrapped open
5393149.126.72.220 12525 tcp tcpwrapped open
5394149.126.72.220 12526 tcp tcpwrapped open
5395149.126.72.220 12527 tcp tcpwrapped open
5396149.126.72.220 12528 tcp tcpwrapped open
5397149.126.72.220 12529 tcp tcpwrapped open
5398149.126.72.220 12530 tcp tcpwrapped open
5399149.126.72.220 12531 tcp tcpwrapped open
5400149.126.72.220 12532 tcp tcpwrapped open
5401149.126.72.220 12533 tcp tcpwrapped open
5402149.126.72.220 12534 tcp tcpwrapped open
5403149.126.72.220 12535 tcp tcpwrapped open
5404149.126.72.220 12536 tcp tcpwrapped open
5405149.126.72.220 12537 tcp tcpwrapped open
5406149.126.72.220 12538 tcp tcpwrapped open
5407149.126.72.220 12539 tcp tcpwrapped open
5408149.126.72.220 12540 tcp tcpwrapped open
5409149.126.72.220 12541 tcp tcpwrapped open
5410149.126.72.220 12542 tcp tcpwrapped open
5411149.126.72.220 12543 tcp tcpwrapped open
5412149.126.72.220 12544 tcp tcpwrapped open
5413149.126.72.220 12545 tcp tcpwrapped open
5414149.126.72.220 12546 tcp tcpwrapped open
5415149.126.72.220 12547 tcp tcpwrapped open
5416149.126.72.220 12548 tcp tcpwrapped open
5417149.126.72.220 12549 tcp tcpwrapped open
5418149.126.72.220 12550 tcp tcpwrapped open
5419149.126.72.220 12551 tcp tcpwrapped open
5420149.126.72.220 12552 tcp tcpwrapped open
5421149.126.72.220 12553 tcp tcpwrapped open
5422149.126.72.220 12554 tcp tcpwrapped open
5423149.126.72.220 12555 tcp tcpwrapped open
5424149.126.72.220 12556 tcp tcpwrapped open
5425149.126.72.220 12557 tcp tcpwrapped open
5426149.126.72.220 12558 tcp tcpwrapped open
5427149.126.72.220 12559 tcp tcpwrapped open
5428149.126.72.220 12560 tcp tcpwrapped open
5429149.126.72.220 12561 tcp tcpwrapped open
5430149.126.72.220 12562 tcp tcpwrapped open
5431149.126.72.220 12563 tcp tcpwrapped open
5432149.126.72.220 12564 tcp tcpwrapped open
5433149.126.72.220 12565 tcp tcpwrapped open
5434149.126.72.220 12566 tcp tcpwrapped open
5435149.126.72.220 12567 tcp tcpwrapped open
5436149.126.72.220 12568 tcp tcpwrapped open
5437149.126.72.220 12569 tcp tcpwrapped open
5438149.126.72.220 12570 tcp tcpwrapped open
5439149.126.72.220 12571 tcp tcpwrapped open
5440149.126.72.220 12572 tcp tcpwrapped open
5441149.126.72.220 12573 tcp tcpwrapped open
5442149.126.72.220 12574 tcp tcpwrapped open
5443149.126.72.220 12575 tcp tcpwrapped open
5444149.126.72.220 12576 tcp tcpwrapped open
5445149.126.72.220 12577 tcp tcpwrapped open
5446149.126.72.220 12578 tcp tcpwrapped open
5447149.126.72.220 12579 tcp tcpwrapped open
5448149.126.72.220 12580 tcp tcpwrapped open
5449149.126.72.220 12581 tcp tcpwrapped open
5450149.126.72.220 12582 tcp tcpwrapped open
5451149.126.72.220 12583 tcp tcpwrapped open
5452149.126.72.220 12584 tcp tcpwrapped open
5453149.126.72.220 12585 tcp tcpwrapped open
5454149.126.72.220 12586 tcp tcpwrapped open
5455149.126.72.220 12587 tcp tcpwrapped open
5456149.126.72.220 12588 tcp tcpwrapped open
5457149.126.72.220 12589 tcp tcpwrapped open
5458149.126.72.220 12590 tcp tcpwrapped open
5459149.126.72.220 13082 tcp tcpwrapped open
5460149.126.72.220 13084 tcp tcpwrapped open
5461149.126.72.220 13333 tcp tcpwrapped open
5462149.126.72.220 13443 tcp tcpwrapped open
5463149.126.72.220 14006 tcp tcpwrapped open
5464149.126.72.220 14082 tcp tcpwrapped open
5465149.126.72.220 14084 tcp tcpwrapped open
5466149.126.72.220 14104 tcp tcpwrapped open
5467149.126.72.220 14130 tcp tcpwrapped open
5468149.126.72.220 14182 tcp tcpwrapped open
5469149.126.72.220 14184 tcp tcpwrapped open
5470149.126.72.220 14330 tcp tcpwrapped open
5471149.126.72.220 14443 tcp tcpwrapped open
5472149.126.72.220 14825 tcp tcpwrapped open
5473149.126.72.220 15002 tcp tcpwrapped open
5474149.126.72.220 15006 tcp tcpwrapped open
5475149.126.72.220 15082 tcp tcpwrapped open
5476149.126.72.220 15084 tcp tcpwrapped open
5477149.126.72.220 15151 tcp tcpwrapped open
5478149.126.72.220 15555 tcp tcpwrapped open
5479149.126.72.220 16000 tcp tcpwrapped open
5480149.126.72.220 16001 tcp tcpwrapped open
5481149.126.72.220 16015 tcp tcpwrapped open
5482149.126.72.220 16016 tcp tcpwrapped open
5483149.126.72.220 16017 tcp tcpwrapped open
5484149.126.72.220 16082 tcp tcpwrapped open
5485149.126.72.220 16084 tcp tcpwrapped open
5486149.126.72.220 16311 tcp tcpwrapped open
5487149.126.72.220 16316 tcp tcpwrapped open
5488149.126.72.220 16443 tcp tcpwrapped open
5489149.126.72.220 16800 tcp tcpwrapped open
5490149.126.72.220 16888 tcp tcpwrapped open
5491149.126.72.220 17082 tcp tcpwrapped open
5492149.126.72.220 17084 tcp tcpwrapped open
5493149.126.72.220 17182 tcp tcpwrapped open
5494149.126.72.220 17184 tcp tcpwrapped open
5495149.126.72.220 17770 tcp tcpwrapped open
5496149.126.72.220 17771 tcp tcpwrapped open
5497149.126.72.220 17772 tcp tcpwrapped open
5498149.126.72.220 17773 tcp tcpwrapped open
5499149.126.72.220 17774 tcp tcpwrapped open
5500149.126.72.220 17775 tcp tcpwrapped open
5501149.126.72.220 17776 tcp tcpwrapped open
5502149.126.72.220 17777 tcp tcpwrapped open
5503149.126.72.220 17778 tcp tcpwrapped open
5504149.126.72.220 17779 tcp tcpwrapped open
5505149.126.72.220 17780 tcp tcpwrapped open
5506149.126.72.220 18000 tcp tcpwrapped open
5507149.126.72.220 18001 tcp tcpwrapped open
5508149.126.72.220 18002 tcp tcpwrapped open
5509149.126.72.220 18003 tcp tcpwrapped open
5510149.126.72.220 18004 tcp tcpwrapped open
5511149.126.72.220 18005 tcp tcpwrapped open
5512149.126.72.220 18006 tcp tcpwrapped open
5513149.126.72.220 18007 tcp tcpwrapped open
5514149.126.72.220 18008 tcp tcpwrapped open
5515149.126.72.220 18009 tcp tcpwrapped open
5516149.126.72.220 18010 tcp tcpwrapped open
5517149.126.72.220 18011 tcp tcpwrapped open
5518149.126.72.220 18012 tcp tcpwrapped open
5519149.126.72.220 18013 tcp tcpwrapped open
5520149.126.72.220 18014 tcp tcpwrapped open
5521149.126.72.220 18015 tcp tcpwrapped open
5522149.126.72.220 18016 tcp tcpwrapped open
5523149.126.72.220 18017 tcp tcpwrapped open
5524149.126.72.220 18018 tcp tcpwrapped open
5525149.126.72.220 18019 tcp tcpwrapped open
5526149.126.72.220 18020 tcp tcpwrapped open
5527149.126.72.220 18021 tcp tcpwrapped open
5528149.126.72.220 18022 tcp tcpwrapped open
5529149.126.72.220 18023 tcp tcpwrapped open
5530149.126.72.220 18024 tcp tcpwrapped open
5531149.126.72.220 18025 tcp tcpwrapped open
5532149.126.72.220 18026 tcp tcpwrapped open
5533149.126.72.220 18027 tcp tcpwrapped open
5534149.126.72.220 18028 tcp tcpwrapped open
5535149.126.72.220 18029 tcp tcpwrapped open
5536149.126.72.220 18030 tcp tcpwrapped open
5537149.126.72.220 18031 tcp tcpwrapped open
5538149.126.72.220 18032 tcp tcpwrapped open
5539149.126.72.220 18033 tcp tcpwrapped open
5540149.126.72.220 18034 tcp tcpwrapped open
5541149.126.72.220 18035 tcp tcpwrapped open
5542149.126.72.220 18036 tcp tcpwrapped open
5543149.126.72.220 18037 tcp tcpwrapped open
5544149.126.72.220 18038 tcp tcpwrapped open
5545149.126.72.220 18039 tcp tcpwrapped open
5546149.126.72.220 18040 tcp tcpwrapped open
5547149.126.72.220 18041 tcp tcpwrapped open
5548149.126.72.220 18042 tcp tcpwrapped open
5549149.126.72.220 18043 tcp tcpwrapped open
5550149.126.72.220 18044 tcp tcpwrapped open
5551149.126.72.220 18045 tcp tcpwrapped open
5552149.126.72.220 18046 tcp tcpwrapped open
5553149.126.72.220 18047 tcp tcpwrapped open
5554149.126.72.220 18048 tcp tcpwrapped open
5555149.126.72.220 18049 tcp tcpwrapped open
5556149.126.72.220 18050 tcp tcpwrapped open
5557149.126.72.220 18051 tcp tcpwrapped open
5558149.126.72.220 18052 tcp tcpwrapped open
5559149.126.72.220 18053 tcp tcpwrapped open
5560149.126.72.220 18054 tcp tcpwrapped open
5561149.126.72.220 18055 tcp tcpwrapped open
5562149.126.72.220 18056 tcp tcpwrapped open
5563149.126.72.220 18057 tcp tcpwrapped open
5564149.126.72.220 18058 tcp tcpwrapped open
5565149.126.72.220 18059 tcp tcpwrapped open
5566149.126.72.220 18060 tcp tcpwrapped open
5567149.126.72.220 18061 tcp tcpwrapped open
5568149.126.72.220 18062 tcp tcpwrapped open
5569149.126.72.220 18063 tcp tcpwrapped open
5570149.126.72.220 18064 tcp tcpwrapped open
5571149.126.72.220 18065 tcp tcpwrapped open
5572149.126.72.220 18066 tcp tcpwrapped open
5573149.126.72.220 18067 tcp tcpwrapped open
5574149.126.72.220 18068 tcp tcpwrapped open
5575149.126.72.220 18069 tcp tcpwrapped open
5576149.126.72.220 18070 tcp tcpwrapped open
5577149.126.72.220 18071 tcp tcpwrapped open
5578149.126.72.220 18072 tcp tcpwrapped open
5579149.126.72.220 18073 tcp tcpwrapped open
5580149.126.72.220 18074 tcp tcpwrapped open
5581149.126.72.220 18075 tcp tcpwrapped open
5582149.126.72.220 18076 tcp tcpwrapped open
5583149.126.72.220 18077 tcp tcpwrapped open
5584149.126.72.220 18078 tcp tcpwrapped open
5585149.126.72.220 18079 tcp tcpwrapped open
5586149.126.72.220 18080 tcp tcpwrapped open
5587149.126.72.220 18081 tcp tcpwrapped open
5588149.126.72.220 18082 tcp tcpwrapped open
5589149.126.72.220 18083 tcp tcpwrapped open
5590149.126.72.220 18084 tcp tcpwrapped open
5591149.126.72.220 18085 tcp tcpwrapped open
5592149.126.72.220 18086 tcp tcpwrapped open
5593149.126.72.220 18087 tcp tcpwrapped open
5594149.126.72.220 18088 tcp tcpwrapped open
5595149.126.72.220 18089 tcp tcpwrapped open
5596149.126.72.220 18090 tcp tcpwrapped open
5597149.126.72.220 18091 tcp tcpwrapped open
5598149.126.72.220 18092 tcp tcpwrapped open
5599149.126.72.220 18093 tcp tcpwrapped open
5600149.126.72.220 18094 tcp tcpwrapped open
5601149.126.72.220 18095 tcp tcpwrapped open
5602149.126.72.220 18096 tcp tcpwrapped open
5603149.126.72.220 18097 tcp tcpwrapped open
5604149.126.72.220 18098 tcp tcpwrapped open
5605149.126.72.220 18099 tcp tcpwrapped open
5606149.126.72.220 18100 tcp tcpwrapped open
5607149.126.72.220 18101 tcp tcpwrapped open
5608149.126.72.220 18102 tcp tcpwrapped open
5609149.126.72.220 18103 tcp tcpwrapped open
5610149.126.72.220 18104 tcp tcpwrapped open
5611149.126.72.220 18105 tcp tcpwrapped open
5612149.126.72.220 18106 tcp tcpwrapped open
5613149.126.72.220 18107 tcp tcpwrapped open
5614149.126.72.220 18108 tcp tcpwrapped open
5615149.126.72.220 18109 tcp tcpwrapped open
5616149.126.72.220 18110 tcp tcpwrapped open
5617149.126.72.220 18111 tcp tcpwrapped open
5618149.126.72.220 18112 tcp tcpwrapped open
5619149.126.72.220 18113 tcp tcpwrapped open
5620149.126.72.220 18200 tcp tcpwrapped open
5621149.126.72.220 18239 tcp tcpwrapped open
5622149.126.72.220 18443 tcp tcpwrapped open
5623149.126.72.220 18802 tcp tcpwrapped open
5624149.126.72.220 19013 tcp tcpwrapped open
5625149.126.72.220 19014 tcp tcpwrapped open
5626149.126.72.220 19015 tcp tcpwrapped open
5627149.126.72.220 19016 tcp tcpwrapped open
5628149.126.72.220 19017 tcp tcpwrapped open
5629149.126.72.220 19022 tcp tcpwrapped open
5630149.126.72.220 19080 tcp tcpwrapped open
5631149.126.72.220 19082 tcp tcpwrapped open
5632149.126.72.220 19084 tcp tcpwrapped open
5633149.126.72.220 19443 tcp tcpwrapped open
5634149.126.72.220 20000 tcp tcpwrapped open
5635149.126.72.220 20001 tcp tcpwrapped open
5636149.126.72.220 20010 tcp tcpwrapped open
5637149.126.72.220 20020 tcp tcpwrapped open
5638149.126.72.220 20030 tcp tcpwrapped open
5639149.126.72.220 20040 tcp tcpwrapped open
5640149.126.72.220 20050 tcp tcpwrapped open
5641149.126.72.220 20053 tcp tcpwrapped open
5642149.126.72.220 20060 tcp tcpwrapped open
5643149.126.72.220 20070 tcp tcpwrapped open
5644149.126.72.220 20080 tcp tcpwrapped open
5645149.126.72.220 20082 tcp tcpwrapped open
5646149.126.72.220 20084 tcp tcpwrapped open
5647149.126.72.220 20090 tcp tcpwrapped open
5648149.126.72.220 20100 tcp tcpwrapped open
5649149.126.72.220 20106 tcp tcpwrapped open
5650149.126.72.220 20107 tcp tcpwrapped open
5651149.126.72.220 20110 tcp tcpwrapped open
5652149.126.72.220 20150 tcp tcpwrapped open
5653149.126.72.220 20182 tcp tcpwrapped open
5654149.126.72.220 20184 tcp tcpwrapped open
5655149.126.72.220 20185 tcp tcpwrapped open
5656149.126.72.220 20200 tcp tcpwrapped open
5657149.126.72.220 20208 tcp tcpwrapped open
5658149.126.72.220 20325 tcp tcpwrapped open
5659149.126.72.220 20500 tcp tcpwrapped open
5660149.126.72.220 20512 tcp tcpwrapped open
5661149.126.72.220 20600 tcp tcpwrapped open
5662149.126.72.220 20800 tcp tcpwrapped open
5663149.126.72.220 20892 tcp tcpwrapped open
5664149.126.72.220 20894 tcp tcpwrapped open
5665149.126.72.220 20900 tcp tcpwrapped open
5666149.126.72.220 21081 tcp tcpwrapped open
5667149.126.72.220 21082 tcp tcpwrapped open
5668149.126.72.220 21083 tcp tcpwrapped open
5669149.126.72.220 21084 tcp tcpwrapped open
5670149.126.72.220 21100 tcp tcpwrapped open
5671149.126.72.220 21200 tcp tcpwrapped open
5672149.126.72.220 21300 tcp tcpwrapped open
5673149.126.72.220 21357 tcp tcpwrapped open
5674149.126.72.220 21381 tcp tcpwrapped open
5675149.126.72.220 21400 tcp tcpwrapped open
5676149.126.72.220 21500 tcp tcpwrapped open
5677149.126.72.220 21935 tcp tcpwrapped open
5678149.126.72.220 22082 tcp tcpwrapped open
5679149.126.72.220 22084 tcp tcpwrapped open
5680149.126.72.220 22103 tcp tcpwrapped open
5681149.126.72.220 22107 tcp tcpwrapped open
5682149.126.72.220 22206 tcp tcpwrapped open
5683149.126.72.220 22345 tcp tcpwrapped open
5684149.126.72.220 22403 tcp tcpwrapped open
5685149.126.72.220 22609 tcp tcpwrapped open
5686149.126.72.220 22703 tcp tcpwrapped open
5687149.126.72.220 22705 tcp tcpwrapped open
5688149.126.72.220 23082 tcp tcpwrapped open
5689149.126.72.220 23084 tcp tcpwrapped open
5690149.126.72.220 23182 tcp tcpwrapped open
5691149.126.72.220 23184 tcp tcpwrapped open
5692149.126.72.220 24082 tcp tcpwrapped open
5693149.126.72.220 24084 tcp tcpwrapped open
5694149.126.72.220 24472 tcp tcpwrapped open
5695149.126.72.220 24510 tcp tcpwrapped open
5696149.126.72.220 25000 tcp tcpwrapped open
5697149.126.72.220 25001 tcp tcpwrapped open
5698149.126.72.220 25002 tcp tcpwrapped open
5699149.126.72.220 25003 tcp tcpwrapped open
5700149.126.72.220 25004 tcp tcpwrapped open
5701149.126.72.220 25005 tcp tcpwrapped open
5702149.126.72.220 25006 tcp tcpwrapped open
5703149.126.72.220 25007 tcp tcpwrapped open
5704149.126.72.220 25008 tcp tcpwrapped open
5705149.126.72.220 25009 tcp tcpwrapped open
5706149.126.72.220 25010 tcp tcpwrapped open
5707149.126.72.220 25082 tcp tcpwrapped open
5708149.126.72.220 25084 tcp tcpwrapped open
5709149.126.72.220 25782 tcp tcpwrapped open
5710149.126.72.220 25952 tcp tcpwrapped open
5711149.126.72.220 27571 tcp tcpwrapped open
5712149.126.72.220 28001 tcp tcpwrapped open
5713149.126.72.220 28080 tcp tcpwrapped open
5714149.126.72.220 28818 tcp tcpwrapped open
5715149.126.72.220 29798 tcp tcpwrapped open
5716149.126.72.220 29799 tcp tcpwrapped open
5717149.126.72.220 30000 tcp tcpwrapped open
5718149.126.72.220 30001 tcp tcpwrapped open
5719149.126.72.220 30003 tcp tcpwrapped open
5720149.126.72.220 30005 tcp tcpwrapped open
5721149.126.72.220 30007 tcp tcpwrapped open
5722149.126.72.220 30009 tcp tcpwrapped open
5723149.126.72.220 30011 tcp tcpwrapped open
5724149.126.72.220 30013 tcp tcpwrapped open
5725149.126.72.220 30015 tcp tcpwrapped open
5726149.126.72.220 30017 tcp tcpwrapped open
5727149.126.72.220 30019 tcp tcpwrapped open
5728149.126.72.220 30021 tcp tcpwrapped open
5729149.126.72.220 30050 tcp tcpwrapped open
5730149.126.72.220 30106 tcp tcpwrapped open
5731149.126.72.220 30110 tcp tcpwrapped open
5732149.126.72.220 30111 tcp tcpwrapped open
5733149.126.72.220 30112 tcp tcpwrapped open
5734149.126.72.220 30113 tcp tcpwrapped open
5735149.126.72.220 30120 tcp tcpwrapped open
5736149.126.72.220 30121 tcp tcpwrapped open
5737149.126.72.220 30122 tcp tcpwrapped open
5738149.126.72.220 30123 tcp tcpwrapped open
5739149.126.72.220 30452 tcp tcpwrapped open
5740149.126.72.220 30468 tcp tcpwrapped open
5741149.126.72.220 30473 tcp tcpwrapped open
5742149.126.72.220 30479 tcp tcpwrapped open
5743149.126.72.220 30501 tcp tcpwrapped open
5744149.126.72.220 30700 tcp tcpwrapped open
5745149.126.72.220 30701 tcp tcpwrapped open
5746149.126.72.220 30892 tcp tcpwrapped open
5747149.126.72.220 30894 tcp tcpwrapped open
5748149.126.72.220 31337 tcp tcpwrapped open
5749149.126.72.220 32101 tcp tcpwrapped open
5750149.126.72.220 32102 tcp tcpwrapped open
5751149.126.72.220 32202 tcp tcpwrapped open
5752149.126.72.220 32303 tcp tcpwrapped open
5753149.126.72.220 32443 tcp tcpwrapped open
5754149.126.72.220 32444 tcp tcpwrapped open
5755149.126.72.220 32746 tcp tcpwrapped open
5756149.126.72.220 32800 tcp tcpwrapped open
5757149.126.72.220 34225 tcp tcpwrapped open
5758149.126.72.220 34500 tcp tcpwrapped open
5759149.126.72.220 35522 tcp tcpwrapped open
5760149.126.72.220 35524 tcp tcpwrapped open
5761149.126.72.220 35531 tcp tcpwrapped open
5762149.126.72.220 35554 tcp tcpwrapped open
5763149.126.72.220 35559 tcp tcpwrapped open
5764149.126.72.220 35560 tcp tcpwrapped open
5765149.126.72.220 36982 tcp tcpwrapped open
5766149.126.72.220 36983 tcp tcpwrapped open
5767149.126.72.220 36984 tcp tcpwrapped open
5768149.126.72.220 37080 tcp tcpwrapped open
5769149.126.72.220 38880 tcp tcpwrapped open
5770149.126.72.220 39001 tcp tcpwrapped open
5771149.126.72.220 40070 tcp tcpwrapped open
5772149.126.72.220 40099 tcp tcpwrapped open
5773149.126.72.220 40892 tcp tcpwrapped open
5774149.126.72.220 40894 tcp tcpwrapped open
5775149.126.72.220 42208 tcp tcpwrapped open
5776149.126.72.220 42424 tcp tcpwrapped open
5777149.126.72.220 42901 tcp tcpwrapped open
5778149.126.72.220 43008 tcp tcpwrapped open
5779149.126.72.220 43009 tcp tcpwrapped open
5780149.126.72.220 43200 tcp tcpwrapped open
5781149.126.72.220 44100 tcp tcpwrapped open
5782149.126.72.220 44300 tcp tcpwrapped open
5783149.126.72.220 44301 tcp tcpwrapped open
5784149.126.72.220 44302 tcp tcpwrapped open
5785149.126.72.220 44303 tcp tcpwrapped open
5786149.126.72.220 44304 tcp tcpwrapped open
5787149.126.72.220 44305 tcp tcpwrapped open
5788149.126.72.220 44306 tcp tcpwrapped open
5789149.126.72.220 44307 tcp tcpwrapped open
5790149.126.72.220 44308 tcp tcpwrapped open
5791149.126.72.220 44309 tcp tcpwrapped open
5792149.126.72.220 44310 tcp tcpwrapped open
5793149.126.72.220 44320 tcp tcpwrapped open
5794149.126.72.220 44332 tcp tcpwrapped open
5795149.126.72.220 44333 tcp tcpwrapped open
5796149.126.72.220 44334 tcp tcpwrapped open
5797149.126.72.220 44336 tcp tcpwrapped open
5798149.126.72.220 44337 tcp tcpwrapped open
5799149.126.72.220 44340 tcp tcpwrapped open
5800149.126.72.220 44341 tcp tcpwrapped open
5801149.126.72.220 44345 tcp tcpwrapped open
5802149.126.72.220 44400 tcp tcpwrapped open
5803149.126.72.220 44410 tcp tcpwrapped open
5804149.126.72.220 44420 tcp tcpwrapped open
5805149.126.72.220 45000 tcp tcpwrapped open
5806149.126.72.220 45555 tcp tcpwrapped open
5807149.126.72.220 45666 tcp tcpwrapped open
5808149.126.72.220 45667 tcp tcpwrapped open
5809149.126.72.220 45668 tcp tcpwrapped open
5810149.126.72.220 45677 tcp tcpwrapped open
5811149.126.72.220 45777 tcp tcpwrapped open
5812149.126.72.220 45788 tcp tcpwrapped open
5813149.126.72.220 45821 tcp tcpwrapped open
5814149.126.72.220 45886 tcp tcpwrapped open
5815149.126.72.220 45888 tcp tcpwrapped open
5816149.126.72.220 46000 tcp tcpwrapped open
5817149.126.72.220 46443 tcp tcpwrapped open
5818149.126.72.220 46862 tcp tcpwrapped open
5819149.126.72.220 47000 tcp tcpwrapped open
5820149.126.72.220 47080 tcp tcpwrapped open
5821149.126.72.220 47534 tcp tcpwrapped open
5822149.126.72.220 48888 tcp tcpwrapped open
5823149.126.72.220 48889 tcp tcpwrapped open
5824149.126.72.220 49200 tcp tcpwrapped open
5825149.126.72.220 49210 tcp tcpwrapped open
5826149.126.72.220 49443 tcp tcpwrapped open
5827149.126.72.220 49682 tcp tcpwrapped open
5828149.126.72.220 49684 tcp tcpwrapped open
5829149.126.72.220 49686 tcp tcpwrapped open
5830149.126.72.220 49688 tcp tcpwrapped open
5831149.126.72.220 49690 tcp tcpwrapped open
5832149.126.72.220 49692 tcp tcpwrapped open
5833149.126.72.220 49694 tcp tcpwrapped open
5834149.126.72.220 50000 tcp tcpwrapped open
5835149.126.72.220 50001 tcp tcpwrapped open
5836149.126.72.220 50042 tcp tcpwrapped open
5837149.126.72.220 50050 tcp tcpwrapped open
5838149.126.72.220 50073 tcp tcpwrapped open
5839149.126.72.220 50085 tcp tcpwrapped open
5840149.126.72.220 50101 tcp tcpwrapped open
5841149.126.72.220 50102 tcp tcpwrapped open
5842149.126.72.220 50103 tcp tcpwrapped open
5843149.126.72.220 50104 tcp tcpwrapped open
5844149.126.72.220 50105 tcp tcpwrapped open
5845149.126.72.220 50106 tcp tcpwrapped open
5846149.126.72.220 50107 tcp tcpwrapped open
5847149.126.72.220 50112 tcp tcpwrapped open
5848149.126.72.220 50113 tcp tcpwrapped open
5849149.126.72.220 50122 tcp tcpwrapped open
5850149.126.72.220 50160 tcp tcpwrapped open
5851149.126.72.220 50443 tcp tcpwrapped open
5852149.126.72.220 51002 tcp tcpwrapped open
5853149.126.72.220 51003 tcp tcpwrapped open
5854149.126.72.220 51434 tcp tcpwrapped open
5855149.126.72.220 52010 tcp tcpwrapped open
5856149.126.72.220 52230 tcp tcpwrapped open
5857149.126.72.220 52311 tcp tcpwrapped open
5858149.126.72.220 52536 tcp tcpwrapped open
5859149.126.72.220 53480 tcp tcpwrapped open
5860149.126.72.220 53481 tcp tcpwrapped open
5861149.126.72.220 53482 tcp tcpwrapped open
5862149.126.72.220 53483 tcp tcpwrapped open
5863149.126.72.220 53484 tcp tcpwrapped open
5864149.126.72.220 53485 tcp tcpwrapped open
5865149.126.72.220 53490 tcp tcpwrapped open
5866149.126.72.220 53805 tcp tcpwrapped open
5867149.126.72.220 53806 tcp tcpwrapped open
5868149.126.72.220 54327 tcp tcpwrapped open
5869149.126.72.220 54490 tcp tcpwrapped open
5870149.126.72.220 54545 tcp tcpwrapped open
5871149.126.72.220 55055 tcp tcpwrapped open
5872149.126.72.220 55080 tcp tcpwrapped open
5873149.126.72.220 55081 tcp tcpwrapped open
5874149.126.72.220 55350 tcp tcpwrapped open
5875149.126.72.220 55388 tcp tcpwrapped open
5876149.126.72.220 55470 tcp tcpwrapped open
5877149.126.72.220 55475 tcp tcpwrapped open
5878149.126.72.220 55481 tcp tcpwrapped open
5879149.126.72.220 55490 tcp tcpwrapped open
5880149.126.72.220 57778 tcp tcpwrapped open
5881149.126.72.220 57779 tcp tcpwrapped open
5882149.126.72.220 57780 tcp tcpwrapped open
5883149.126.72.220 57781 tcp tcpwrapped open
5884149.126.72.220 57782 tcp tcpwrapped open
5885149.126.72.220 57783 tcp tcpwrapped open
5886149.126.72.220 57784 tcp tcpwrapped open
5887149.126.72.220 57785 tcp tcpwrapped open
5888149.126.72.220 57786 tcp tcpwrapped open
5889149.126.72.220 57787 tcp tcpwrapped open
5890149.126.72.220 57788 tcp tcpwrapped open
5891149.126.72.220 58443 tcp tcpwrapped open
5892149.126.72.220 58585 tcp tcpwrapped open
5893149.126.72.220 59012 tcp tcpwrapped open
5894149.126.72.220 59443 tcp tcpwrapped open
5895149.126.72.220 60021 tcp tcpwrapped open
5896149.126.72.220 60023 tcp tcpwrapped open
5897149.126.72.220 60443 tcp tcpwrapped open
5898149.126.72.220 62080 tcp tcpwrapped open
5899149.126.72.220 62237 tcp tcpwrapped open
5900149.126.72.220 62443 tcp tcpwrapped open
5901149.126.72.220 62865 tcp tcpwrapped open
5902149.126.72.220 63443 tcp tcpwrapped open
5903149.126.72.220 64477 tcp tcpwrapped open
5904149.126.72.220 64671 tcp tcpwrapped open
5905151.106.38.107 21 tcp ftp open 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------\x0d\x0a220-You are user number 1 of 50 allowed.\x0d\x0a220-Local time is now 12:11. Server port: 21.\x0d\x0a220-This is a private system - No anonymous login\x0d\x0a220-IPv6 connections are also welcome on this server.\x0d\x0a220 You will be disconnected after 15 minutes of inactivity.\x0d\x0a
5906151.106.38.107 53 tcp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
5907151.106.38.107 53 udp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
5908151.106.38.107 67 tcp dhcps filtered
5909151.106.38.107 67 udp dhcps unknown
5910151.106.38.107 68 tcp dhcpc filtered
5911151.106.38.107 68 udp dhcpc unknown
5912151.106.38.107 69 tcp tftp filtered
5913151.106.38.107 69 udp tftp unknown
5914151.106.38.107 88 tcp kerberos-sec filtered
5915151.106.38.107 88 udp kerberos-sec unknown
5916151.106.38.107 123 tcp ntp filtered
5917151.106.38.107 123 udp ntp unknown
5918151.106.38.107 137 tcp netbios-ns filtered
5919151.106.38.107 137 udp netbios-ns unknown
5920151.106.38.107 138 tcp netbios-dgm filtered
5921151.106.38.107 138 udp netbios-dgm unknown
5922151.106.38.107 139 tcp netbios-ssn filtered
5923151.106.38.107 139 udp netbios-ssn unknown
5924151.106.38.107 161 tcp snmp filtered
5925151.106.38.107 161 udp snmp unknown
5926151.106.38.107 162 tcp snmptrap filtered
5927151.106.38.107 162 udp snmptrap unknown
5928151.106.38.107 389 tcp ldap filtered
5929151.106.38.107 389 udp ldap unknown
5930151.106.38.107 520 tcp efs filtered
5931151.106.38.107 520 udp route unknown
5932151.106.38.107 2049 tcp nfs filtered
5933151.106.38.107 2049 udp nfs unknown
5934158.69.13.254 22 tcp ssh open OpenSSH 7.4 protocol 2.0
5935158.69.13.254 25 tcp smtp open Exim smtpd 4.92.3
5936158.69.13.254 53 tcp domain open unknown banner: get lost
5937158.69.13.254 53 udp domain open unknown banner: get lost
5938158.69.13.254 67 tcp dhcps filtered
5939158.69.13.254 67 udp dhcps unknown
5940158.69.13.254 68 tcp dhcpc filtered
5941158.69.13.254 68 udp dhcpc unknown
5942158.69.13.254 69 tcp tftp filtered
5943158.69.13.254 69 udp tftp unknown
5944158.69.13.254 80 tcp http open nginx
5945158.69.13.254 88 tcp kerberos-sec filtered
5946158.69.13.254 88 udp kerberos-sec unknown
5947158.69.13.254 123 tcp ntp filtered
5948158.69.13.254 123 udp ntp unknown
5949158.69.13.254 137 tcp netbios-ns filtered
5950158.69.13.254 137 udp netbios-ns unknown
5951158.69.13.254 138 tcp netbios-dgm filtered
5952158.69.13.254 138 udp netbios-dgm unknown
5953158.69.13.254 139 tcp netbios-ssn filtered
5954158.69.13.254 139 udp netbios-ssn unknown
5955158.69.13.254 161 tcp snmp filtered
5956158.69.13.254 161 udp snmp unknown
5957158.69.13.254 162 tcp snmptrap filtered
5958158.69.13.254 162 udp snmptrap unknown
5959158.69.13.254 389 tcp ldap filtered
5960158.69.13.254 389 udp ldap unknown
5961158.69.13.254 443 tcp ssl/http open nginx
5962158.69.13.254 465 tcp ssl/smtp open Exim smtpd 4.92.3
5963158.69.13.254 520 tcp efs filtered
5964158.69.13.254 520 udp route unknown
5965158.69.13.254 587 tcp smtp open Exim smtpd 4.92.3
5966158.69.13.254 2049 tcp nfs filtered
5967158.69.13.254 2049 udp nfs unknown
5968158.69.13.254 2525 tcp smtp open Exim smtpd 4.92.3
5969158.69.13.254 3306 tcp mysql open MySQL blocked - too many connection errors
5970162.244.35.13 22 tcp ssh open SSH-2.0-OpenSSH_7.2 FreeBSD-20160310
5971162.244.35.13 25 tcp open
5972162.244.35.13 53 tcp domain open ISC BIND 9.10.6
5973162.244.35.13 53 udp domain open ISC BIND 9.10.6
5974162.244.35.13 67 tcp dhcps closed
5975162.244.35.13 67 udp dhcps closed
5976162.244.35.13 68 tcp dhcpc closed
5977162.244.35.13 68 udp dhcpc closed
5978162.244.35.13 69 tcp tftp closed
5979162.244.35.13 69 udp tftp closed
5980162.244.35.13 88 tcp kerberos-sec closed
5981162.244.35.13 88 udp kerberos-sec closed
5982162.244.35.13 123 tcp ntp closed
5983162.244.35.13 123 udp ntp closed
5984162.244.35.13 137 tcp netbios-ns filtered
5985162.244.35.13 137 udp netbios-ns unknown
5986162.244.35.13 138 tcp netbios-dgm filtered
5987162.244.35.13 138 udp netbios-dgm unknown
5988162.244.35.13 139 tcp netbios-ssn filtered
5989162.244.35.13 139 udp netbios-ssn unknown
5990162.244.35.13 161 tcp snmp closed
5991162.244.35.13 161 udp snmp closed
5992162.244.35.13 162 tcp snmptrap closed
5993162.244.35.13 162 udp snmptrap closed
5994162.244.35.13 389 tcp ldap closed
5995162.244.35.13 389 udp ldap closed
5996162.244.35.13 520 tcp efs closed
5997162.244.35.13 520 udp route closed
5998162.244.35.13 2049 tcp nfs closed
5999162.244.35.13 2049 udp nfs closed
6000163.247.48.46 53 tcp domain filtered
6001163.247.48.46 53 udp domain unknown
6002163.247.48.46 67 tcp dhcps filtered
6003163.247.48.46 67 udp dhcps unknown
6004163.247.48.46 68 tcp dhcpc filtered
6005163.247.48.46 68 udp dhcpc unknown
6006163.247.48.46 69 tcp tftp filtered
6007163.247.48.46 69 udp tftp unknown
6008163.247.48.46 88 tcp kerberos-sec filtered
6009163.247.48.46 88 udp kerberos-sec unknown
6010163.247.48.46 123 tcp ntp filtered
6011163.247.48.46 123 udp ntp unknown
6012163.247.48.46 137 tcp netbios-ns filtered
6013163.247.48.46 137 udp netbios-ns unknown
6014163.247.48.46 138 tcp netbios-dgm filtered
6015163.247.48.46 138 udp netbios-dgm unknown
6016163.247.48.46 139 tcp netbios-ssn filtered
6017163.247.48.46 139 udp netbios-ssn unknown
6018163.247.48.46 161 tcp snmp filtered
6019163.247.48.46 161 udp snmp unknown
6020163.247.48.46 162 tcp snmptrap filtered
6021163.247.48.46 162 udp snmptrap unknown
6022163.247.48.46 389 tcp ldap filtered
6023163.247.48.46 389 udp ldap unknown
6024163.247.48.46 520 tcp efs filtered
6025163.247.48.46 520 udp route unknown
6026163.247.48.46 2049 tcp nfs filtered
6027163.247.48.46 2049 udp nfs unknown
6028163.247.127.20 53 tcp domain filtered
6029163.247.127.20 53 udp domain unknown
6030163.247.127.20 67 tcp dhcps filtered
6031163.247.127.20 67 udp dhcps unknown
6032163.247.127.20 68 tcp dhcpc filtered
6033163.247.127.20 68 udp dhcpc unknown
6034163.247.127.20 69 tcp tftp filtered
6035163.247.127.20 69 udp tftp unknown
6036163.247.127.20 88 tcp kerberos-sec filtered
6037163.247.127.20 88 udp kerberos-sec unknown
6038163.247.127.20 123 tcp ntp filtered
6039163.247.127.20 123 udp ntp unknown
6040163.247.127.20 137 tcp netbios-ns filtered
6041163.247.127.20 137 udp netbios-ns unknown
6042163.247.127.20 138 tcp netbios-dgm filtered
6043163.247.127.20 138 udp netbios-dgm unknown
6044163.247.127.20 139 tcp netbios-ssn filtered
6045163.247.127.20 139 udp netbios-ssn unknown
6046163.247.127.20 161 tcp snmp filtered
6047163.247.127.20 161 udp snmp unknown
6048163.247.127.20 162 tcp snmptrap filtered
6049163.247.127.20 162 udp snmptrap unknown
6050163.247.127.20 389 tcp ldap filtered
6051163.247.127.20 389 udp ldap unknown
6052163.247.127.20 520 tcp efs filtered
6053163.247.127.20 520 udp route unknown
6054163.247.127.20 2049 tcp nfs filtered
6055163.247.127.20 2049 udp nfs unknown
6056163.247.130.114 53 tcp domain closed
6057163.247.130.114 53 udp domain unknown
6058163.247.130.114 67 tcp dhcps filtered
6059163.247.130.114 67 udp dhcps unknown
6060163.247.130.114 68 tcp dhcpc filtered
6061163.247.130.114 68 udp dhcpc unknown
6062163.247.130.114 69 tcp tftp filtered
6063163.247.130.114 69 udp tftp closed
6064163.247.130.114 88 tcp kerberos-sec filtered
6065163.247.130.114 88 udp kerberos-sec unknown
6066163.247.130.114 123 tcp ntp filtered
6067163.247.130.114 123 udp ntp unknown
6068163.247.130.114 137 tcp netbios-ns filtered
6069163.247.130.114 137 udp netbios-ns unknown
6070163.247.130.114 138 tcp netbios-dgm filtered
6071163.247.130.114 138 udp netbios-dgm unknown
6072163.247.130.114 139 tcp netbios-ssn filtered
6073163.247.130.114 139 udp netbios-ssn unknown
6074163.247.130.114 161 tcp snmp filtered
6075163.247.130.114 161 udp snmp open net-snmp; net-snmp SNMPv3 server
6076163.247.130.114 162 tcp snmptrap filtered
6077163.247.130.114 162 udp snmptrap unknown
6078163.247.130.114 389 tcp ldap filtered
6079163.247.130.114 389 udp ldap unknown
6080163.247.130.114 520 tcp efs filtered
6081163.247.130.114 520 udp route unknown
6082163.247.130.114 2049 tcp nfs filtered
6083163.247.130.114 2049 udp nfs unknown
6084163.247.175.176 53 tcp tcpwrapped open
6085163.247.175.176 53 udp domain unknown
6086163.247.175.176 67 tcp tcpwrapped open
6087163.247.175.176 67 udp dhcps unknown
6088163.247.175.176 68 tcp tcpwrapped open
6089163.247.175.176 68 udp dhcpc unknown
6090163.247.175.176 69 tcp tcpwrapped open
6091163.247.175.176 69 udp tftp unknown
6092163.247.175.176 88 tcp tcpwrapped open
6093163.247.175.176 88 udp kerberos-sec unknown
6094163.247.175.176 123 tcp tcpwrapped open
6095163.247.175.176 123 udp ntp unknown
6096163.247.175.176 137 tcp tcpwrapped open
6097163.247.175.176 137 udp netbios-ns unknown
6098163.247.175.176 138 tcp tcpwrapped open
6099163.247.175.176 138 udp netbios-dgm unknown
6100163.247.175.176 139 udp netbios-ssn unknown
6101163.247.175.176 161 tcp tcpwrapped open
6102163.247.175.176 161 udp snmp unknown
6103163.247.175.176 162 tcp tcpwrapped open
6104163.247.175.176 162 udp snmptrap unknown
6105163.247.175.176 389 tcp tcpwrapped open
6106163.247.175.176 389 udp ldap unknown
6107163.247.175.176 520 tcp tcpwrapped open
6108163.247.175.176 520 udp route unknown
6109163.247.175.176 2049 tcp tcpwrapped open
6110163.247.175.176 2049 udp nfs unknown
6111165.22.143.229 53 tcp domain closed
6112165.22.143.229 53 udp domain unknown
6113165.22.143.229 67 tcp dhcps closed
6114165.22.143.229 67 udp dhcps unknown
6115165.22.143.229 68 tcp dhcpc closed
6116165.22.143.229 68 udp dhcpc unknown
6117165.22.143.229 69 tcp tftp closed
6118165.22.143.229 69 udp tftp closed
6119165.22.143.229 88 tcp kerberos-sec closed
6120165.22.143.229 88 udp kerberos-sec unknown
6121165.22.143.229 123 tcp ntp closed
6122165.22.143.229 123 udp ntp open NTP v4 secondary server
6123165.22.143.229 137 tcp netbios-ns closed
6124165.22.143.229 137 udp netbios-ns closed
6125165.22.143.229 138 tcp netbios-dgm closed
6126165.22.143.229 138 udp netbios-dgm closed
6127165.22.143.229 139 tcp netbios-ssn closed
6128165.22.143.229 139 udp netbios-ssn unknown
6129165.22.143.229 161 tcp snmp closed
6130165.22.143.229 161 udp snmp closed
6131165.22.143.229 162 tcp snmptrap closed
6132165.22.143.229 162 udp snmptrap unknown
6133165.22.143.229 389 tcp ldap closed
6134165.22.143.229 389 udp ldap closed
6135165.22.143.229 520 tcp efs closed
6136165.22.143.229 520 udp route closed
6137165.22.143.229 2049 tcp nfs closed
6138165.22.143.229 2049 udp nfs closed
6139165.227.99.239 53 tcp domain filtered
6140165.227.99.239 53 udp domain unknown
6141165.227.99.239 67 tcp dhcps filtered
6142165.227.99.239 67 udp dhcps unknown
6143165.227.99.239 68 tcp dhcpc filtered
6144165.227.99.239 68 udp dhcpc unknown
6145165.227.99.239 69 tcp tftp filtered
6146165.227.99.239 69 udp tftp unknown
6147165.227.99.239 80 tcp http open nginx
6148165.227.99.239 88 tcp kerberos-sec filtered
6149165.227.99.239 88 udp kerberos-sec unknown
6150165.227.99.239 123 tcp ntp filtered
6151165.227.99.239 123 udp ntp unknown
6152165.227.99.239 137 tcp netbios-ns filtered
6153165.227.99.239 137 udp netbios-ns unknown
6154165.227.99.239 138 tcp netbios-dgm filtered
6155165.227.99.239 138 udp netbios-dgm unknown
6156165.227.99.239 139 tcp netbios-ssn filtered
6157165.227.99.239 139 udp netbios-ssn unknown
6158165.227.99.239 161 tcp snmp filtered
6159165.227.99.239 161 udp snmp open net-snmp; net-snmp SNMPv3 server
6160165.227.99.239 162 tcp snmptrap filtered
6161165.227.99.239 162 udp snmptrap closed
6162165.227.99.239 389 tcp ldap filtered
6163165.227.99.239 389 udp ldap unknown
6164165.227.99.239 443 tcp ssl/http open nginx
6165165.227.99.239 520 tcp efs filtered
6166165.227.99.239 520 udp route unknown
6167165.227.99.239 2049 tcp nfs filtered
6168165.227.99.239 2049 udp nfs unknown
6169169.239.218.20 25 tcp smtp closed
6170169.239.218.20 53 tcp domain filtered
6171169.239.218.20 53 udp domain unknown
6172169.239.218.20 67 tcp dhcps filtered
6173169.239.218.20 67 udp dhcps unknown
6174169.239.218.20 68 tcp dhcpc filtered
6175169.239.218.20 68 udp dhcpc unknown
6176169.239.218.20 69 tcp tftp filtered
6177169.239.218.20 69 udp tftp unknown
6178169.239.218.20 88 tcp kerberos-sec filtered
6179169.239.218.20 88 udp kerberos-sec unknown
6180169.239.218.20 113 tcp ident closed
6181169.239.218.20 123 tcp ntp filtered
6182169.239.218.20 123 udp ntp unknown
6183169.239.218.20 137 tcp netbios-ns filtered
6184169.239.218.20 137 udp netbios-ns filtered
6185169.239.218.20 138 tcp netbios-dgm filtered
6186169.239.218.20 138 udp netbios-dgm filtered
6187169.239.218.20 139 tcp netbios-ssn closed
6188169.239.218.20 139 udp netbios-ssn unknown
6189169.239.218.20 161 tcp snmp filtered
6190169.239.218.20 161 udp snmp unknown
6191169.239.218.20 162 tcp snmptrap filtered
6192169.239.218.20 162 udp snmptrap unknown
6193169.239.218.20 389 tcp ldap filtered
6194169.239.218.20 389 udp ldap unknown
6195169.239.218.20 445 tcp microsoft-ds closed
6196169.239.218.20 520 tcp efs filtered
6197169.239.218.20 520 udp route unknown
6198169.239.218.20 2049 tcp nfs filtered
6199169.239.218.20 2049 udp nfs unknown
6200169.239.218.20 8008 tcp tcpwrapped open
6201170.239.85.227 53 tcp domain closed
6202170.239.85.227 53 udp domain closed
6203170.239.85.227 67 tcp dhcps closed
6204170.239.85.227 67 udp dhcps unknown
6205170.239.85.227 68 tcp dhcpc closed
6206170.239.85.227 68 udp dhcpc closed
6207170.239.85.227 69 tcp tftp closed
6208170.239.85.227 69 udp tftp closed
6209170.239.85.227 88 tcp kerberos-sec closed
6210170.239.85.227 88 udp kerberos-sec unknown
6211170.239.85.227 123 tcp ntp closed
6212170.239.85.227 123 udp ntp closed
6213170.239.85.227 137 tcp netbios-ns closed
6214170.239.85.227 137 udp netbios-ns closed
6215170.239.85.227 138 tcp netbios-dgm closed
6216170.239.85.227 138 udp netbios-dgm unknown
6217170.239.85.227 139 tcp netbios-ssn closed
6218170.239.85.227 139 udp netbios-ssn closed
6219170.239.85.227 161 tcp snmp closed
6220170.239.85.227 161 udp snmp unknown
6221170.239.85.227 162 tcp snmptrap closed
6222170.239.85.227 162 udp snmptrap unknown
6223170.239.85.227 389 tcp ldap closed
6224170.239.85.227 389 udp ldap unknown
6225170.239.85.227 520 tcp efs closed
6226170.239.85.227 520 udp route unknown
6227170.239.85.227 2049 tcp nfs closed
6228170.239.85.227 2049 udp nfs closed
6229173.214.244.169 53 tcp domain filtered
6230173.214.244.169 53 udp domain unknown
6231173.214.244.169 67 tcp dhcps filtered
6232173.214.244.169 67 udp dhcps unknown
6233173.214.244.169 68 tcp dhcpc filtered
6234173.214.244.169 68 udp dhcpc unknown
6235173.214.244.169 69 tcp tftp filtered
6236173.214.244.169 69 udp tftp unknown
6237173.214.244.169 88 tcp kerberos-sec filtered
6238173.214.244.169 88 udp kerberos-sec unknown
6239173.214.244.169 123 tcp ntp filtered
6240173.214.244.169 123 udp ntp unknown
6241173.214.244.169 137 tcp netbios-ns filtered
6242173.214.244.169 137 udp netbios-ns unknown
6243173.214.244.169 138 tcp netbios-dgm filtered
6244173.214.244.169 138 udp netbios-dgm unknown
6245173.214.244.169 139 tcp netbios-ssn filtered
6246173.214.244.169 139 udp netbios-ssn unknown
6247173.214.244.169 161 tcp snmp filtered
6248173.214.244.169 161 udp snmp unknown
6249173.214.244.169 162 tcp snmptrap filtered
6250173.214.244.169 162 udp snmptrap unknown
6251173.214.244.169 389 tcp ldap filtered
6252173.214.244.169 389 udp ldap unknown
6253173.214.244.169 520 tcp efs filtered
6254173.214.244.169 520 udp route unknown
6255173.214.244.169 2049 tcp nfs filtered
6256173.214.244.169 2049 udp nfs unknown
6257174.142.53.51 21 tcp ftp open 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------\x0d\x0a220-You are user number 1 of 50 allowed.\x0d\x0a220-Local time is now 13:59. Server port: 21.\x0d\x0a220-This is a private system - No anonymous login\x0d\x0a220-IPv6 connections are also welcome on this server.\x0d\x0a220 You will be disconnected after 15 minutes of inactivity.\x0d\x0a
6258174.142.53.51 22 tcp ssh open SSH-2.0-OpenSSH_7.4
6259174.142.53.51 25 tcp smtp closed
6260174.142.53.51 53 tcp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
6261174.142.53.51 53 udp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
6262174.142.53.51 67 tcp dhcps filtered
6263174.142.53.51 67 udp dhcps unknown
6264174.142.53.51 68 tcp dhcpc filtered
6265174.142.53.51 68 udp dhcpc unknown
6266174.142.53.51 69 tcp tftp filtered
6267174.142.53.51 69 udp tftp unknown
6268174.142.53.51 88 tcp kerberos-sec filtered
6269174.142.53.51 88 udp kerberos-sec unknown
6270174.142.53.51 123 tcp ntp filtered
6271174.142.53.51 123 udp ntp unknown
6272174.142.53.51 137 tcp netbios-ns filtered
6273174.142.53.51 137 udp netbios-ns filtered
6274174.142.53.51 138 tcp netbios-dgm filtered
6275174.142.53.51 138 udp netbios-dgm filtered
6276174.142.53.51 139 tcp netbios-ssn closed
6277174.142.53.51 139 udp netbios-ssn unknown
6278174.142.53.51 161 tcp snmp filtered
6279174.142.53.51 161 udp snmp unknown
6280174.142.53.51 162 tcp snmptrap filtered
6281174.142.53.51 162 udp snmptrap unknown
6282174.142.53.51 389 tcp ldap filtered
6283174.142.53.51 389 udp ldap unknown
6284174.142.53.51 445 tcp microsoft-ds closed
6285174.142.53.51 520 tcp efs filtered
6286174.142.53.51 520 udp route unknown
6287174.142.53.51 2049 tcp nfs filtered
6288174.142.53.51 2049 udp nfs unknown
6289186.64.118.40 21 tcp ftp open 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------\x0d\x0a220-You are user number 1 of 100 allowed.\x0d\x0a220-Local time is now 13:39. Server port: 21.\x0d\x0a220-This is a private system - No anonymous login\x0d\x0a220-IPv6 connections are also welcome on this server.\x0d\x0a220 You will be disconnected after 10 minutes of inactivity.\x0d\x0a
6290186.64.118.40 53 tcp domain filtered
6291186.64.118.40 53 udp domain closed
6292186.64.118.40 67 tcp dhcps filtered
6293186.64.118.40 67 udp dhcps unknown
6294186.64.118.40 68 tcp dhcpc filtered
6295186.64.118.40 68 udp dhcpc unknown
6296186.64.118.40 69 tcp tftp filtered
6297186.64.118.40 69 udp tftp unknown
6298186.64.118.40 88 tcp kerberos-sec filtered
6299186.64.118.40 88 udp kerberos-sec unknown
6300186.64.118.40 123 tcp ntp filtered
6301186.64.118.40 123 udp ntp unknown
6302186.64.118.40 137 tcp netbios-ns filtered
6303186.64.118.40 137 udp netbios-ns unknown
6304186.64.118.40 138 tcp netbios-dgm filtered
6305186.64.118.40 138 udp netbios-dgm unknown
6306186.64.118.40 139 tcp netbios-ssn filtered
6307186.64.118.40 139 udp netbios-ssn unknown
6308186.64.118.40 161 tcp snmp filtered
6309186.64.118.40 161 udp snmp unknown
6310186.64.118.40 162 tcp snmptrap filtered
6311186.64.118.40 162 udp snmptrap unknown
6312186.64.118.40 389 tcp ldap filtered
6313186.64.118.40 389 udp ldap unknown
6314186.64.118.40 520 tcp efs filtered
6315186.64.118.40 520 udp route unknown
6316186.64.118.40 2049 tcp nfs closed
6317186.64.118.40 2049 udp nfs unknown
6318188.127.251.161 53 tcp domain filtered PowerDNS Authoritative Server 4.1.10
6319188.127.251.161 53 udp domain unknown PowerDNS Authoritative Server 4.1.10
6320188.127.251.161 67 tcp dhcps filtered
6321188.127.251.161 67 udp dhcps unknown
6322188.127.251.161 68 tcp dhcpc filtered
6323188.127.251.161 68 udp dhcpc unknown
6324188.127.251.161 69 tcp tftp filtered
6325188.127.251.161 69 udp tftp unknown
6326188.127.251.161 88 tcp kerberos-sec filtered
6327188.127.251.161 88 udp kerberos-sec unknown
6328188.127.251.161 123 tcp ntp filtered
6329188.127.251.161 123 udp ntp unknown
6330188.127.251.161 137 tcp netbios-ns filtered
6331188.127.251.161 137 udp netbios-ns unknown
6332188.127.251.161 138 tcp netbios-dgm filtered
6333188.127.251.161 138 udp netbios-dgm unknown
6334188.127.251.161 139 tcp netbios-ssn filtered
6335188.127.251.161 139 udp netbios-ssn unknown
6336188.127.251.161 161 tcp snmp filtered
6337188.127.251.161 161 udp snmp unknown
6338188.127.251.161 162 tcp snmptrap filtered
6339188.127.251.161 162 udp snmptrap unknown
6340188.127.251.161 389 tcp ldap filtered
6341188.127.251.161 389 udp ldap unknown
6342188.127.251.161 520 tcp efs filtered
6343188.127.251.161 520 udp route unknown
6344188.127.251.161 2049 tcp nfs filtered
6345188.127.251.161 2049 udp nfs unknown
6346190.98.209.37 53 tcp domain filtered
6347190.98.209.37 53 udp domain unknown
6348190.98.209.37 67 tcp dhcps filtered
6349190.98.209.37 67 udp dhcps unknown
6350190.98.209.37 68 tcp dhcpc filtered
6351190.98.209.37 68 udp dhcpc unknown
6352190.98.209.37 69 tcp tftp filtered
6353190.98.209.37 69 udp tftp unknown
6354190.98.209.37 88 tcp kerberos-sec filtered
6355190.98.209.37 88 udp kerberos-sec unknown
6356190.98.209.37 123 tcp ntp filtered
6357190.98.209.37 123 udp ntp unknown
6358190.98.209.37 137 tcp netbios-ns filtered
6359190.98.209.37 137 udp netbios-ns unknown
6360190.98.209.37 138 tcp netbios-dgm filtered
6361190.98.209.37 138 udp netbios-dgm unknown
6362190.98.209.37 139 tcp netbios-ssn filtered
6363190.98.209.37 139 udp netbios-ssn unknown
6364190.98.209.37 161 tcp snmp filtered
6365190.98.209.37 161 udp snmp unknown
6366190.98.209.37 162 tcp snmptrap filtered
6367190.98.209.37 162 udp snmptrap unknown
6368190.98.209.37 389 tcp ldap filtered
6369190.98.209.37 389 udp ldap unknown
6370190.98.209.37 520 tcp efs filtered
6371190.98.209.37 520 udp route unknown
6372190.98.209.37 2049 tcp nfs filtered
6373190.98.209.37 2049 udp nfs unknown
6374190.107.177.35 53 tcp domain filtered ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
6375190.107.177.35 53 udp domain unknown ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
6376190.107.177.35 67 tcp dhcps filtered
6377190.107.177.35 67 udp dhcps unknown
6378190.107.177.35 68 tcp dhcpc filtered
6379190.107.177.35 68 udp dhcpc unknown
6380190.107.177.35 69 tcp tftp filtered
6381190.107.177.35 69 udp tftp unknown
6382190.107.177.35 88 tcp kerberos-sec filtered
6383190.107.177.35 88 udp kerberos-sec unknown
6384190.107.177.35 123 tcp ntp filtered
6385190.107.177.35 123 udp ntp unknown
6386190.107.177.35 137 tcp netbios-ns filtered
6387190.107.177.35 137 udp netbios-ns unknown
6388190.107.177.35 138 tcp netbios-dgm filtered
6389190.107.177.35 138 udp netbios-dgm unknown
6390190.107.177.35 139 tcp netbios-ssn filtered
6391190.107.177.35 139 udp netbios-ssn unknown
6392190.107.177.35 161 tcp snmp filtered
6393190.107.177.35 161 udp snmp unknown
6394190.107.177.35 162 tcp snmptrap filtered
6395190.107.177.35 162 udp snmptrap unknown
6396190.107.177.35 389 tcp ldap filtered
6397190.107.177.35 389 udp ldap unknown
6398190.107.177.35 520 tcp efs filtered
6399190.107.177.35 520 udp route unknown
6400190.107.177.35 2049 tcp nfs filtered
6401190.107.177.35 2049 udp nfs unknown
6402190.110.121.175 53 tcp domain filtered
6403190.110.121.175 53 udp domain unknown
6404190.110.121.175 67 tcp dhcps filtered
6405190.110.121.175 67 udp dhcps unknown
6406190.110.121.175 68 tcp dhcpc filtered
6407190.110.121.175 68 udp dhcpc unknown
6408190.110.121.175 69 tcp tftp filtered
6409190.110.121.175 69 udp tftp unknown
6410190.110.121.175 88 tcp kerberos-sec filtered
6411190.110.121.175 88 udp kerberos-sec unknown
6412190.110.121.175 123 tcp ntp filtered
6413190.110.121.175 123 udp ntp unknown
6414190.110.121.175 137 tcp netbios-ns filtered
6415190.110.121.175 137 udp netbios-ns unknown
6416190.110.121.175 138 tcp netbios-dgm filtered
6417190.110.121.175 138 udp netbios-dgm unknown
6418190.110.121.175 139 tcp netbios-ssn filtered
6419190.110.121.175 139 udp netbios-ssn unknown
6420190.110.121.175 161 tcp snmp filtered
6421190.110.121.175 161 udp snmp unknown
6422190.110.121.175 162 tcp snmptrap filtered
6423190.110.121.175 162 udp snmptrap unknown
6424190.110.121.175 389 tcp ldap filtered
6425190.110.121.175 389 udp ldap unknown
6426190.110.121.175 520 tcp efs filtered
6427190.110.121.175 520 udp route unknown
6428190.110.121.175 2049 tcp nfs filtered
6429190.110.121.175 2049 udp nfs unknown
6430190.153.209.187 53 tcp domain filtered
6431190.153.209.187 53 udp domain unknown
6432190.153.209.187 67 tcp dhcps filtered
6433190.153.209.187 67 udp dhcps unknown
6434190.153.209.187 68 tcp dhcpc filtered
6435190.153.209.187 68 udp dhcpc unknown
6436190.153.209.187 69 tcp tftp filtered
6437190.153.209.187 69 udp tftp unknown
6438190.153.209.187 88 tcp kerberos-sec filtered
6439190.153.209.187 88 udp kerberos-sec unknown
6440190.153.209.187 123 tcp ntp filtered
6441190.153.209.187 123 udp ntp unknown
6442190.153.209.187 137 tcp netbios-ns filtered
6443190.153.209.187 137 udp netbios-ns unknown
6444190.153.209.187 138 tcp netbios-dgm filtered
6445190.153.209.187 138 udp netbios-dgm unknown
6446190.153.209.187 139 tcp netbios-ssn filtered
6447190.153.209.187 139 udp netbios-ssn unknown
6448190.153.209.187 161 tcp snmp filtered
6449190.153.209.187 161 udp snmp unknown
6450190.153.209.187 162 tcp snmptrap filtered
6451190.153.209.187 162 udp snmptrap unknown
6452190.153.209.187 389 tcp ldap filtered
6453190.153.209.187 389 udp ldap unknown
6454190.153.209.187 520 tcp efs filtered
6455190.153.209.187 520 udp route unknown
6456190.153.209.187 2049 tcp nfs filtered
6457190.153.209.187 2049 udp nfs unknown
6458190.153.219.254 22 tcp ssh open SSH-2.0-OpenSSH_7.4
6459190.153.219.254 53 tcp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
6460190.153.219.254 53 udp domain open ISC BIND 9.11.4-P2 RedHat Enterprise Linux 7
6461190.153.219.254 67 tcp dhcps filtered
6462190.153.219.254 67 udp dhcps unknown
6463190.153.219.254 68 tcp dhcpc filtered
6464190.153.219.254 68 udp dhcpc unknown
6465190.153.219.254 69 tcp tftp filtered
6466190.153.219.254 69 udp tftp unknown
6467190.153.219.254 88 tcp kerberos-sec filtered
6468190.153.219.254 88 udp kerberos-sec unknown
6469190.153.219.254 123 tcp ntp filtered
6470190.153.219.254 123 udp ntp unknown
6471190.153.219.254 137 tcp netbios-ns filtered
6472190.153.219.254 137 udp netbios-ns unknown
6473190.153.219.254 138 tcp netbios-dgm filtered
6474190.153.219.254 138 udp netbios-dgm unknown
6475190.153.219.254 139 tcp netbios-ssn filtered
6476190.153.219.254 139 udp netbios-ssn unknown
6477190.153.219.254 161 tcp snmp filtered
6478190.153.219.254 161 udp snmp unknown
6479190.153.219.254 162 tcp snmptrap filtered
6480190.153.219.254 162 udp snmptrap unknown
6481190.153.219.254 389 tcp ldap filtered
6482190.153.219.254 389 udp ldap unknown
6483190.153.219.254 520 tcp efs filtered
6484190.153.219.254 520 udp route unknown
6485190.153.219.254 2049 tcp nfs filtered
6486190.153.219.254 2049 udp nfs unknown
6487192.185.134.58 21 tcp ftp open 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------\x0d\x0a220-You are user number 2 of 150 allowed.\x0d\x0a220-Local time is now 22:31. Server port: 21.\x0d\x0a220-IPv6 connections are also welcome on this server.\x0d\x0a220 You will be disconnected after 15 minutes of inactivity.\x0d\x0a
6488192.185.134.58 53 tcp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
6489192.185.134.58 53 udp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
6490192.185.134.58 67 tcp dhcps closed
6491192.185.134.58 67 udp dhcps unknown
6492192.185.134.58 68 tcp dhcpc closed
6493192.185.134.58 68 udp dhcpc unknown
6494192.185.134.58 69 tcp tftp closed
6495192.185.134.58 69 udp tftp closed
6496192.185.134.58 88 tcp kerberos-sec closed
6497192.185.134.58 88 udp kerberos-sec closed
6498192.185.134.58 123 tcp ntp closed
6499192.185.134.58 123 udp ntp unknown
6500192.185.134.58 137 tcp netbios-ns closed
6501192.185.134.58 137 udp netbios-ns closed
6502192.185.134.58 138 tcp netbios-dgm closed
6503192.185.134.58 138 udp netbios-dgm closed
6504192.185.134.58 139 tcp netbios-ssn closed
6505192.185.134.58 139 udp netbios-ssn closed
6506192.185.134.58 161 tcp snmp closed
6507192.185.134.58 161 udp snmp unknown
6508192.185.134.58 162 tcp snmptrap closed
6509192.185.134.58 162 udp snmptrap closed
6510192.185.134.58 389 tcp ldap closed
6511192.185.134.58 389 udp ldap unknown
6512192.185.134.58 520 tcp efs closed
6513192.185.134.58 520 udp route unknown
6514192.185.134.58 2049 tcp nfs closed
6515192.185.134.58 2049 udp nfs unknown
6516198.49.23.144 53 tcp domain filtered
6517198.49.23.144 53 udp domain unknown
6518198.49.23.144 67 tcp dhcps filtered
6519198.49.23.144 67 udp dhcps unknown
6520198.49.23.144 68 tcp dhcpc filtered
6521198.49.23.144 68 udp dhcpc unknown
6522198.49.23.144 69 tcp tftp filtered
6523198.49.23.144 69 udp tftp unknown
6524198.49.23.144 88 tcp kerberos-sec filtered
6525198.49.23.144 88 udp kerberos-sec unknown
6526198.49.23.144 123 tcp ntp filtered
6527198.49.23.144 123 udp ntp unknown
6528198.49.23.144 137 tcp netbios-ns filtered
6529198.49.23.144 137 udp netbios-ns unknown
6530198.49.23.144 138 tcp netbios-dgm filtered
6531198.49.23.144 138 udp netbios-dgm unknown
6532198.49.23.144 139 tcp netbios-ssn filtered
6533198.49.23.144 139 udp netbios-ssn unknown
6534198.49.23.144 161 tcp snmp filtered
6535198.49.23.144 161 udp snmp unknown
6536198.49.23.144 162 tcp snmptrap filtered
6537198.49.23.144 162 udp snmptrap unknown
6538198.49.23.144 389 tcp ldap filtered
6539198.49.23.144 389 udp ldap unknown
6540198.49.23.144 520 tcp efs filtered
6541198.49.23.144 520 udp route unknown
6542198.49.23.144 2049 tcp nfs filtered
6543198.49.23.144 2049 udp nfs unknown
6544198.49.23.145 53 tcp domain filtered
6545198.49.23.145 53 udp domain unknown
6546198.49.23.145 67 tcp dhcps filtered
6547198.49.23.145 67 udp dhcps unknown
6548198.49.23.145 68 tcp dhcpc filtered
6549198.49.23.145 68 udp dhcpc unknown
6550198.49.23.145 69 tcp tftp filtered
6551198.49.23.145 69 udp tftp unknown
6552198.49.23.145 80 tcp rtsp open
6553198.49.23.145 88 tcp kerberos-sec filtered
6554198.49.23.145 88 udp kerberos-sec unknown
6555198.49.23.145 123 tcp ntp filtered
6556198.49.23.145 123 udp ntp unknown
6557198.49.23.145 137 tcp netbios-ns filtered
6558198.49.23.145 137 udp netbios-ns unknown
6559198.49.23.145 138 tcp netbios-dgm filtered
6560198.49.23.145 138 udp netbios-dgm unknown
6561198.49.23.145 139 tcp netbios-ssn filtered
6562198.49.23.145 139 udp netbios-ssn unknown
6563198.49.23.145 161 tcp snmp filtered
6564198.49.23.145 161 udp snmp unknown
6565198.49.23.145 162 tcp snmptrap filtered
6566198.49.23.145 162 udp snmptrap unknown
6567198.49.23.145 389 tcp ldap filtered
6568198.49.23.145 389 udp ldap unknown
6569198.49.23.145 443 tcp ssl/rtsp open
6570198.49.23.145 520 tcp efs filtered
6571198.49.23.145 520 udp route unknown
6572198.49.23.145 2030 tcp device2 closed
6573198.49.23.145 2049 tcp nfs filtered
6574198.49.23.145 2049 udp nfs unknown
6575198.185.159.144 53 tcp domain filtered
6576198.185.159.144 53 udp domain unknown
6577198.185.159.144 67 tcp dhcps filtered
6578198.185.159.144 67 udp dhcps unknown
6579198.185.159.144 68 tcp dhcpc filtered
6580198.185.159.144 68 udp dhcpc unknown
6581198.185.159.144 69 tcp tftp filtered
6582198.185.159.144 69 udp tftp unknown
6583198.185.159.144 80 tcp rtsp open
6584198.185.159.144 88 tcp kerberos-sec filtered
6585198.185.159.144 88 udp kerberos-sec unknown
6586198.185.159.144 123 tcp ntp filtered
6587198.185.159.144 123 udp ntp unknown
6588198.185.159.144 137 tcp netbios-ns filtered
6589198.185.159.144 137 udp netbios-ns unknown
6590198.185.159.144 138 tcp netbios-dgm filtered
6591198.185.159.144 138 udp netbios-dgm unknown
6592198.185.159.144 139 tcp netbios-ssn filtered
6593198.185.159.144 139 udp netbios-ssn unknown
6594198.185.159.144 161 tcp snmp filtered
6595198.185.159.144 161 udp snmp unknown
6596198.185.159.144 162 tcp snmptrap filtered
6597198.185.159.144 162 udp snmptrap unknown
6598198.185.159.144 389 tcp ldap filtered
6599198.185.159.144 389 udp ldap unknown
6600198.185.159.144 443 tcp ssl/rtsp open
6601198.185.159.144 520 tcp efs filtered
6602198.185.159.144 520 udp route unknown
6603198.185.159.144 2030 tcp device2 closed
6604198.185.159.144 2049 tcp nfs filtered
6605198.185.159.144 2049 udp nfs unknown
6606198.185.159.145 53 tcp domain filtered
6607198.185.159.145 53 udp domain unknown
6608198.185.159.145 67 tcp dhcps filtered
6609198.185.159.145 67 udp dhcps unknown
6610198.185.159.145 68 tcp dhcpc filtered
6611198.185.159.145 68 udp dhcpc unknown
6612198.185.159.145 69 tcp tftp filtered
6613198.185.159.145 69 udp tftp unknown
6614198.185.159.145 88 tcp kerberos-sec filtered
6615198.185.159.145 88 udp kerberos-sec unknown
6616198.185.159.145 123 tcp ntp filtered
6617198.185.159.145 123 udp ntp unknown
6618198.185.159.145 137 tcp netbios-ns filtered
6619198.185.159.145 137 udp netbios-ns unknown
6620198.185.159.145 138 tcp netbios-dgm filtered
6621198.185.159.145 138 udp netbios-dgm unknown
6622198.185.159.145 139 tcp netbios-ssn filtered
6623198.185.159.145 139 udp netbios-ssn unknown
6624198.185.159.145 161 tcp snmp filtered
6625198.185.159.145 161 udp snmp unknown
6626198.185.159.145 162 tcp snmptrap filtered
6627198.185.159.145 162 udp snmptrap unknown
6628198.185.159.145 389 tcp ldap filtered
6629198.185.159.145 389 udp ldap unknown
6630198.185.159.145 520 tcp efs filtered
6631198.185.159.145 520 udp route unknown
6632198.185.159.145 2049 tcp nfs filtered
6633198.185.159.145 2049 udp nfs unknown
6634199.38.245.243 21 tcp ftp open Pure-FTPd
6635199.38.245.243 22 tcp ssh open OpenSSH 5.3 protocol 2.0
6636199.38.245.243 25 tcp smtp open Exim smtpd 4.92
6637199.38.245.243 53 tcp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
6638199.38.245.243 53 udp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
6639199.38.245.243 67 tcp dhcps closed
6640199.38.245.243 67 udp dhcps unknown
6641199.38.245.243 68 tcp dhcpc closed
6642199.38.245.243 68 udp dhcpc unknown
6643199.38.245.243 69 tcp tftp closed
6644199.38.245.243 69 udp tftp unknown
6645199.38.245.243 80 tcp ssl/http open Apache/2
6646199.38.245.243 88 tcp kerberos-sec closed
6647199.38.245.243 88 udp kerberos-sec unknown
6648199.38.245.243 110 tcp pop3 open Dovecot DirectAdmin pop3d
6649199.38.245.243 123 tcp ntp closed
6650199.38.245.243 123 udp ntp unknown
6651199.38.245.243 137 tcp netbios-ns closed
6652199.38.245.243 137 udp netbios-ns unknown
6653199.38.245.243 138 tcp netbios-dgm closed
6654199.38.245.243 138 udp netbios-dgm unknown
6655199.38.245.243 139 tcp netbios-ssn closed
6656199.38.245.243 139 udp netbios-ssn unknown
6657199.38.245.243 143 tcp imap open Dovecot imapd
6658199.38.245.243 161 tcp snmp closed
6659199.38.245.243 161 udp snmp unknown
6660199.38.245.243 162 tcp snmptrap closed
6661199.38.245.243 162 udp snmptrap unknown
6662199.38.245.243 389 tcp ldap closed
6663199.38.245.243 389 udp ldap unknown
6664199.38.245.243 443 tcp ssl/ssl open Apache httpd SSL-only mode
6665199.38.245.243 465 tcp ssl/smtp open Exim smtpd 4.92
6666199.38.245.243 520 tcp efs closed
6667199.38.245.243 520 udp route unknown
6668199.38.245.243 587 tcp smtp open Exim smtpd 4.92
6669199.38.245.243 993 tcp ssl/imap open
6670199.38.245.243 995 tcp ssl/pop3 open Dovecot DirectAdmin pop3d
6671199.38.245.243 2049 tcp nfs closed
6672199.38.245.243 2049 udp nfs unknown
6673199.38.245.243 2222 tcp http open DirectAdmin httpd 1.57.1 Registered to Your Domain Goes Here, LLP
6674199.38.245.243 3306 tcp mysql open MySQL unauthorized
6675200.2.249.28 21 tcp ftp open vsftpd 3.0.2
6676200.2.249.28 53 udp domain unknown
6677200.2.249.28 67 udp dhcps unknown
6678200.2.249.28 68 udp dhcpc unknown
6679200.2.249.28 69 udp tftp unknown
6680200.2.249.28 80 tcp http open Oracle Application Server 10g httpd 10.1.3.5.0
6681200.2.249.28 88 udp kerberos-sec unknown
6682200.2.249.28 123 udp ntp unknown
6683200.2.249.28 137 udp netbios-ns unknown
6684200.2.249.28 138 udp netbios-dgm unknown
6685200.2.249.28 139 tcp netbios-ssn open Samba smbd 4.8.3 workgroup: SAMBA
6686200.2.249.28 139 udp netbios-ssn unknown
6687200.2.249.28 161 udp snmp unknown
6688200.2.249.28 162 udp snmptrap unknown
6689200.2.249.28 389 udp ldap unknown
6690200.2.249.28 445 tcp netbios-ssn open Samba smbd 4.8.3 workgroup: SAMBA
6691200.2.249.28 520 udp route unknown
6692200.2.249.28 2049 udp nfs unknown
6693200.10.251.82 53 tcp domain filtered
6694200.10.251.82 53 udp domain unknown
6695200.10.251.82 67 tcp dhcps filtered
6696200.10.251.82 67 udp dhcps unknown
6697200.10.251.82 68 tcp dhcpc filtered
6698200.10.251.82 68 udp dhcpc unknown
6699200.10.251.82 69 tcp tftp filtered
6700200.10.251.82 69 udp tftp unknown
6701200.10.251.82 88 tcp kerberos-sec filtered
6702200.10.251.82 88 udp kerberos-sec unknown
6703200.10.251.82 123 tcp ntp filtered
6704200.10.251.82 123 udp ntp unknown
6705200.10.251.82 137 tcp netbios-ns filtered
6706200.10.251.82 137 udp netbios-ns unknown
6707200.10.251.82 138 tcp netbios-dgm filtered
6708200.10.251.82 138 udp netbios-dgm unknown
6709200.10.251.82 139 tcp netbios-ssn filtered
6710200.10.251.82 139 udp netbios-ssn unknown
6711200.10.251.82 161 tcp snmp filtered
6712200.10.251.82 161 udp snmp unknown
6713200.10.251.82 162 tcp snmptrap filtered
6714200.10.251.82 162 udp snmptrap unknown
6715200.10.251.82 389 tcp ldap filtered
6716200.10.251.82 389 udp ldap unknown
6717200.10.251.82 520 tcp efs filtered
6718200.10.251.82 520 udp route unknown
6719200.10.251.82 2049 tcp nfs filtered
6720200.10.251.82 2049 udp nfs unknown
6721200.12.19.101 21 tcp ftp open 220 Microsoft FTP Service\x0d\x0a
6722200.12.19.101 53 tcp domain filtered
6723200.12.19.101 53 udp domain unknown
6724200.12.19.101 67 tcp dhcps filtered
6725200.12.19.101 67 udp dhcps closed
6726200.12.19.101 68 tcp dhcpc closed
6727200.12.19.101 68 udp dhcpc closed
6728200.12.19.101 69 tcp tftp closed
6729200.12.19.101 69 udp tftp closed
6730200.12.19.101 88 tcp kerberos-sec closed
6731200.12.19.101 88 udp kerberos-sec closed
6732200.12.19.101 123 tcp ntp filtered
6733200.12.19.101 123 udp ntp unknown
6734200.12.19.101 137 tcp netbios-ns closed
6735200.12.19.101 137 udp netbios-ns unknown
6736200.12.19.101 138 tcp netbios-dgm closed
6737200.12.19.101 138 udp netbios-dgm closed
6738200.12.19.101 139 tcp netbios-ssn closed
6739200.12.19.101 139 udp netbios-ssn closed
6740200.12.19.101 161 tcp snmp closed
6741200.12.19.101 161 udp snmp unknown
6742200.12.19.101 162 tcp snmptrap closed
6743200.12.19.101 162 udp snmptrap closed
6744200.12.19.101 389 tcp ldap closed
6745200.12.19.101 389 udp ldap unknown
6746200.12.19.101 520 tcp efs filtered
6747200.12.19.101 520 udp route unknown
6748200.12.19.101 2049 tcp nfs closed
6749200.12.19.101 2049 udp nfs unknown
6750200.29.0.33 53 tcp domain filtered
6751200.29.0.33 53 udp domain unknown
6752200.29.0.33 67 tcp dhcps filtered
6753200.29.0.33 67 udp dhcps unknown
6754200.29.0.33 68 tcp dhcpc filtered
6755200.29.0.33 68 udp dhcpc unknown
6756200.29.0.33 69 tcp tftp filtered
6757200.29.0.33 69 udp tftp unknown
6758200.29.0.33 88 tcp kerberos-sec filtered
6759200.29.0.33 88 udp kerberos-sec unknown
6760200.29.0.33 123 tcp ntp filtered
6761200.29.0.33 123 udp ntp unknown
6762200.29.0.33 137 tcp netbios-ns filtered
6763200.29.0.33 137 udp netbios-ns unknown
6764200.29.0.33 138 tcp netbios-dgm filtered
6765200.29.0.33 138 udp netbios-dgm unknown
6766200.29.0.33 139 tcp netbios-ssn filtered
6767200.29.0.33 139 udp netbios-ssn unknown
6768200.29.0.33 161 tcp snmp filtered
6769200.29.0.33 161 udp snmp unknown
6770200.29.0.33 162 tcp snmptrap filtered
6771200.29.0.33 162 udp snmptrap unknown
6772200.29.0.33 389 tcp ldap filtered
6773200.29.0.33 389 udp ldap unknown
6774200.29.0.33 520 tcp efs filtered
6775200.29.0.33 520 udp route unknown
6776200.29.0.33 2049 tcp nfs filtered
6777200.29.0.33 2049 udp nfs unknown
6778200.54.92.108 21 tcp ftp open 220 (vsFTPd 3.0.3)\x0d\x0a
6779200.54.92.108 22 tcp ssh open SSH-2.0-OpenSSH_7.4p1 Debian-10+deb9u7
6780200.54.92.108 53 tcp domain closed
6781200.54.92.108 53 udp domain unknown
6782200.54.92.108 67 tcp dhcps closed
6783200.54.92.108 67 udp dhcps unknown
6784200.54.92.108 68 tcp dhcpc closed
6785200.54.92.108 68 udp dhcpc unknown
6786200.54.92.108 69 tcp tftp closed
6787200.54.92.108 69 udp tftp unknown
6788200.54.92.108 88 tcp kerberos-sec closed
6789200.54.92.108 88 udp kerberos-sec unknown
6790200.54.92.108 123 tcp ntp closed
6791200.54.92.108 123 udp ntp unknown
6792200.54.92.108 137 tcp netbios-ns closed
6793200.54.92.108 137 udp netbios-ns unknown
6794200.54.92.108 138 tcp netbios-dgm closed
6795200.54.92.108 138 udp netbios-dgm unknown
6796200.54.92.108 139 tcp netbios-ssn closed
6797200.54.92.108 139 udp netbios-ssn unknown
6798200.54.92.108 161 tcp snmp closed
6799200.54.92.108 161 udp snmp unknown
6800200.54.92.108 162 tcp snmptrap closed
6801200.54.92.108 162 udp snmptrap unknown
6802200.54.92.108 389 tcp ldap closed
6803200.54.92.108 389 udp ldap unknown
6804200.54.92.108 520 tcp efs closed
6805200.54.92.108 520 udp route unknown
6806200.54.92.108 2049 tcp nfs closed
6807200.54.92.108 2049 udp nfs unknown
6808200.54.230.247 21 tcp ftp open 220 ProFTPD Server (ProFTPD) [200.54.230.247]\x0d\x0a
6809200.54.230.247 22 tcp ssh open SSH-2.0-OpenSSH_7.4
6810200.54.230.247 53 tcp domain open unknown banner: none
6811200.54.230.247 53 udp domain open unknown banner: none
6812200.54.230.247 67 tcp dhcps filtered
6813200.54.230.247 67 udp dhcps unknown
6814200.54.230.247 68 tcp dhcpc filtered
6815200.54.230.247 68 udp dhcpc unknown
6816200.54.230.247 69 tcp tftp filtered
6817200.54.230.247 69 udp tftp unknown
6818200.54.230.247 88 tcp kerberos-sec filtered
6819200.54.230.247 88 udp kerberos-sec unknown
6820200.54.230.247 123 tcp ntp filtered
6821200.54.230.247 123 udp ntp unknown
6822200.54.230.247 137 tcp netbios-ns filtered
6823200.54.230.247 137 udp netbios-ns unknown
6824200.54.230.247 138 tcp netbios-dgm filtered
6825200.54.230.247 138 udp netbios-dgm unknown
6826200.54.230.247 139 tcp netbios-ssn filtered
6827200.54.230.247 139 udp netbios-ssn filtered
6828200.54.230.247 161 tcp snmp filtered
6829200.54.230.247 161 udp snmp unknown
6830200.54.230.247 162 tcp snmptrap filtered
6831200.54.230.247 162 udp snmptrap unknown
6832200.54.230.247 389 tcp ldap filtered
6833200.54.230.247 389 udp ldap filtered
6834200.54.230.247 520 tcp efs filtered
6835200.54.230.247 520 udp route filtered
6836200.54.230.247 2049 tcp nfs filtered
6837200.54.230.247 2049 udp nfs unknown
6838200.55.198.228 22 tcp ssh open SSH-2.0-OpenSSH_7.4p1 Debian-11.0nosystemd1
6839200.55.198.228 53 tcp domain open
6840200.55.198.228 53 udp domain open
6841200.55.198.228 67 tcp dhcps filtered
6842200.55.198.228 67 udp dhcps unknown
6843200.55.198.228 68 tcp dhcpc filtered
6844200.55.198.228 68 udp dhcpc unknown
6845200.55.198.228 69 tcp tftp filtered
6846200.55.198.228 69 udp tftp unknown
6847200.55.198.228 88 tcp kerberos-sec filtered
6848200.55.198.228 88 udp kerberos-sec unknown
6849200.55.198.228 123 tcp ntp filtered
6850200.55.198.228 123 udp ntp unknown
6851200.55.198.228 137 tcp netbios-ns filtered
6852200.55.198.228 137 udp netbios-ns unknown
6853200.55.198.228 138 tcp netbios-dgm filtered
6854200.55.198.228 138 udp netbios-dgm unknown
6855200.55.198.228 139 tcp netbios-ssn filtered
6856200.55.198.228 139 udp netbios-ssn unknown
6857200.55.198.228 161 tcp snmp filtered
6858200.55.198.228 161 udp snmp unknown
6859200.55.198.228 162 tcp snmptrap filtered
6860200.55.198.228 162 udp snmptrap unknown
6861200.55.198.228 389 tcp ldap filtered
6862200.55.198.228 389 udp ldap unknown
6863200.55.198.228 520 tcp efs filtered
6864200.55.198.228 520 udp route closed
6865200.55.198.228 2049 tcp nfs filtered
6866200.55.198.228 2049 udp nfs unknown
6867200.68.30.227 53 tcp domain closed
6868200.68.30.227 53 udp domain unknown
6869200.68.30.227 67 tcp dhcps closed
6870200.68.30.227 67 udp dhcps filtered
6871200.68.30.227 68 tcp dhcpc closed
6872200.68.30.227 68 udp dhcpc unknown
6873200.68.30.227 69 tcp tftp closed
6874200.68.30.227 69 udp tftp unknown
6875200.68.30.227 88 tcp kerberos-sec closed
6876200.68.30.227 88 udp kerberos-sec unknown
6877200.68.30.227 123 tcp ntp closed
6878200.68.30.227 123 udp ntp filtered
6879200.68.30.227 137 tcp netbios-ns closed
6880200.68.30.227 137 udp netbios-ns filtered
6881200.68.30.227 138 tcp netbios-dgm closed
6882200.68.30.227 138 udp netbios-dgm filtered
6883200.68.30.227 139 tcp netbios-ssn closed
6884200.68.30.227 139 udp netbios-ssn filtered
6885200.68.30.227 161 tcp snmp closed
6886200.68.30.227 161 udp snmp filtered
6887200.68.30.227 162 tcp snmptrap closed
6888200.68.30.227 162 udp snmptrap filtered
6889200.68.30.227 389 tcp ldap closed
6890200.68.30.227 389 udp ldap unknown
6891200.68.30.227 520 tcp efs closed
6892200.68.30.227 520 udp route filtered
6893200.68.30.227 2049 tcp nfs closed
6894200.68.30.227 2049 udp nfs filtered
6895200.68.34.99 53 tcp domain filtered
6896200.68.34.99 53 udp domain unknown
6897200.68.34.99 67 tcp dhcps filtered
6898200.68.34.99 67 udp dhcps unknown
6899200.68.34.99 68 tcp dhcpc filtered
6900200.68.34.99 68 udp dhcpc unknown
6901200.68.34.99 69 tcp tftp filtered
6902200.68.34.99 69 udp tftp unknown
6903200.68.34.99 88 tcp kerberos-sec filtered
6904200.68.34.99 88 udp kerberos-sec unknown
6905200.68.34.99 123 tcp ntp filtered
6906200.68.34.99 123 udp ntp unknown
6907200.68.34.99 137 tcp netbios-ns filtered
6908200.68.34.99 137 udp netbios-ns unknown
6909200.68.34.99 138 tcp netbios-dgm filtered
6910200.68.34.99 138 udp netbios-dgm unknown
6911200.68.34.99 139 tcp netbios-ssn filtered
6912200.68.34.99 139 udp netbios-ssn unknown
6913200.68.34.99 161 tcp snmp filtered
6914200.68.34.99 161 udp snmp unknown
6915200.68.34.99 162 tcp snmptrap filtered
6916200.68.34.99 162 udp snmptrap unknown
6917200.68.34.99 389 tcp ldap filtered
6918200.68.34.99 389 udp ldap unknown
6919200.68.34.99 520 tcp efs filtered
6920200.68.34.99 520 udp route unknown
6921200.68.34.99 2049 tcp nfs filtered
6922200.68.34.99 2049 udp nfs unknown
6923200.73.54.34 53 tcp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
6924200.73.54.34 53 udp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
6925200.73.54.34 67 tcp dhcps filtered
6926200.73.54.34 67 udp dhcps unknown
6927200.73.54.34 68 tcp dhcpc filtered
6928200.73.54.34 68 udp dhcpc unknown
6929200.73.54.34 69 tcp tftp filtered
6930200.73.54.34 69 udp tftp unknown
6931200.73.54.34 88 tcp kerberos-sec filtered
6932200.73.54.34 88 udp kerberos-sec unknown
6933200.73.54.34 123 tcp ntp filtered
6934200.73.54.34 123 udp ntp unknown
6935200.73.54.34 137 tcp netbios-ns filtered
6936200.73.54.34 137 udp netbios-ns unknown
6937200.73.54.34 138 tcp netbios-dgm filtered
6938200.73.54.34 138 udp netbios-dgm unknown
6939200.73.54.34 139 tcp netbios-ssn filtered
6940200.73.54.34 139 udp netbios-ssn unknown
6941200.73.54.34 161 tcp snmp filtered
6942200.73.54.34 161 udp snmp unknown
6943200.73.54.34 162 tcp snmptrap filtered
6944200.73.54.34 162 udp snmptrap unknown
6945200.73.54.34 389 tcp ldap filtered
6946200.73.54.34 389 udp ldap unknown
6947200.73.54.34 520 tcp efs filtered
6948200.73.54.34 520 udp route unknown
6949200.73.54.34 2049 tcp nfs filtered
6950200.73.54.34 2049 udp nfs unknown
6951200.91.40.252 53 tcp domain filtered
6952200.91.40.252 53 udp domain unknown
6953200.91.40.252 67 tcp dhcps filtered
6954200.91.40.252 67 udp dhcps unknown
6955200.91.40.252 68 tcp dhcpc filtered
6956200.91.40.252 68 udp dhcpc unknown
6957200.91.40.252 69 tcp tftp filtered
6958200.91.40.252 69 udp tftp unknown
6959200.91.40.252 88 tcp kerberos-sec filtered
6960200.91.40.252 88 udp kerberos-sec unknown
6961200.91.40.252 123 tcp ntp filtered
6962200.91.40.252 123 udp ntp unknown
6963200.91.40.252 137 tcp netbios-ns filtered
6964200.91.40.252 137 udp netbios-ns unknown
6965200.91.40.252 138 tcp netbios-dgm filtered
6966200.91.40.252 138 udp netbios-dgm unknown
6967200.91.40.252 139 tcp netbios-ssn filtered
6968200.91.40.252 139 udp netbios-ssn unknown
6969200.91.40.252 161 tcp snmp filtered
6970200.91.40.252 161 udp snmp unknown
6971200.91.40.252 162 tcp snmptrap filtered
6972200.91.40.252 162 udp snmptrap unknown
6973200.91.40.252 389 tcp ldap filtered
6974200.91.40.252 389 udp ldap unknown
6975200.91.40.252 520 tcp efs filtered
6976200.91.40.252 520 udp route unknown
6977200.91.40.252 2049 tcp nfs filtered
6978200.91.40.252 2049 udp nfs unknown
6979200.91.41.5 53 tcp domain filtered
6980200.91.41.5 53 udp domain unknown
6981200.91.41.5 67 tcp dhcps filtered
6982200.91.41.5 67 udp dhcps unknown
6983200.91.41.5 68 tcp dhcpc filtered
6984200.91.41.5 68 udp dhcpc unknown
6985200.91.41.5 69 tcp tftp filtered
6986200.91.41.5 69 udp tftp unknown
6987200.91.41.5 88 tcp kerberos-sec filtered
6988200.91.41.5 88 udp kerberos-sec unknown
6989200.91.41.5 123 tcp ntp filtered
6990200.91.41.5 123 udp ntp unknown
6991200.91.41.5 137 tcp netbios-ns filtered
6992200.91.41.5 137 udp netbios-ns unknown
6993200.91.41.5 138 tcp netbios-dgm filtered
6994200.91.41.5 138 udp netbios-dgm unknown
6995200.91.41.5 139 tcp netbios-ssn filtered
6996200.91.41.5 139 udp netbios-ssn unknown
6997200.91.41.5 161 tcp snmp filtered
6998200.91.41.5 161 udp snmp unknown
6999200.91.41.5 162 tcp snmptrap filtered
7000200.91.41.5 162 udp snmptrap unknown
7001200.91.41.5 389 tcp ldap filtered
7002200.91.41.5 389 udp ldap unknown
7003200.91.41.5 520 tcp efs filtered
7004200.91.41.5 520 udp route unknown
7005200.91.41.5 2049 tcp nfs filtered
7006200.91.41.5 2049 udp nfs unknown
7007200.126.100.83 53 tcp domain filtered
7008200.126.100.83 53 udp domain unknown
7009200.126.100.83 67 tcp dhcps filtered
7010200.126.100.83 67 udp dhcps unknown
7011200.126.100.83 68 tcp dhcpc filtered
7012200.126.100.83 68 udp dhcpc unknown
7013200.126.100.83 69 tcp tftp filtered
7014200.126.100.83 69 udp tftp unknown
7015200.126.100.83 88 tcp kerberos-sec filtered
7016200.126.100.83 88 udp kerberos-sec unknown
7017200.126.100.83 123 tcp ntp filtered
7018200.126.100.83 123 udp ntp unknown
7019200.126.100.83 137 tcp netbios-ns filtered
7020200.126.100.83 137 udp netbios-ns unknown
7021200.126.100.83 138 tcp netbios-dgm filtered
7022200.126.100.83 138 udp netbios-dgm unknown
7023200.126.100.83 139 tcp netbios-ssn filtered
7024200.126.100.83 139 udp netbios-ssn unknown
7025200.126.100.83 161 tcp snmp filtered
7026200.126.100.83 161 udp snmp unknown
7027200.126.100.83 162 tcp snmptrap filtered
7028200.126.100.83 162 udp snmptrap unknown
7029200.126.100.83 389 tcp ldap filtered
7030200.126.100.83 389 udp ldap unknown
7031200.126.100.83 520 tcp efs filtered
7032200.126.100.83 520 udp route unknown
7033200.126.100.83 2049 tcp nfs filtered
7034200.126.100.83 2049 udp nfs unknown
7035201.159.170.136 53 tcp domain filtered
7036201.159.170.136 53 udp domain unknown
7037201.159.170.136 67 tcp dhcps filtered
7038201.159.170.136 67 udp dhcps unknown
7039201.159.170.136 68 tcp dhcpc filtered
7040201.159.170.136 68 udp dhcpc unknown
7041201.159.170.136 69 tcp tftp filtered
7042201.159.170.136 69 udp tftp unknown
7043201.159.170.136 88 tcp kerberos-sec filtered
7044201.159.170.136 88 udp kerberos-sec unknown
7045201.159.170.136 123 tcp ntp filtered
7046201.159.170.136 123 udp ntp unknown
7047201.159.170.136 137 tcp netbios-ns filtered
7048201.159.170.136 137 udp netbios-ns unknown
7049201.159.170.136 138 tcp netbios-dgm filtered
7050201.159.170.136 138 udp netbios-dgm unknown
7051201.159.170.136 139 tcp netbios-ssn filtered
7052201.159.170.136 139 udp netbios-ssn unknown
7053201.159.170.136 161 tcp snmp filtered
7054201.159.170.136 161 udp snmp unknown
7055201.159.170.136 162 tcp snmptrap filtered
7056201.159.170.136 162 udp snmptrap unknown
7057201.159.170.136 389 tcp ldap filtered
7058201.159.170.136 389 udp ldap unknown
7059201.159.170.136 520 tcp efs filtered
7060201.159.170.136 520 udp route unknown
7061201.159.170.136 2049 tcp nfs filtered
7062201.159.170.136 2049 udp nfs unknown
7063204.93.193.141 21 tcp ftp open Your connection to this server has been blocked.\x0d\x0a\x0d\x0aYou are most likely being blocked due to use of incorrect user/pass combination. Please, check all of your computers/devices to make sure that they are using the correct login credentials, including your email clients. You may also get blocked due to too many POP3/IMAP logins in 1 minute interval, please adjust your email client settings.\x0d\x0a
7064204.93.193.141 53 tcp domain filtered
7065204.93.193.141 53 udp domain unknown
7066204.93.193.141 67 tcp dhcps filtered
7067204.93.193.141 67 udp dhcps unknown
7068204.93.193.141 68 tcp dhcpc filtered
7069204.93.193.141 68 udp dhcpc unknown
7070204.93.193.141 69 tcp tftp filtered
7071204.93.193.141 69 udp tftp unknown
7072204.93.193.141 88 tcp kerberos-sec filtered
7073204.93.193.141 88 udp kerberos-sec unknown
7074204.93.193.141 123 tcp ntp filtered
7075204.93.193.141 123 udp ntp unknown
7076204.93.193.141 137 tcp netbios-ns filtered
7077204.93.193.141 137 udp netbios-ns unknown
7078204.93.193.141 138 tcp netbios-dgm filtered
7079204.93.193.141 138 udp netbios-dgm unknown
7080204.93.193.141 139 tcp netbios-ssn filtered
7081204.93.193.141 139 udp netbios-ssn unknown
7082204.93.193.141 161 tcp snmp filtered
7083204.93.193.141 161 udp snmp unknown
7084204.93.193.141 162 tcp snmptrap filtered
7085204.93.193.141 162 udp snmptrap unknown
7086204.93.193.141 389 tcp ldap filtered
7087204.93.193.141 389 udp ldap unknown
7088204.93.193.141 520 tcp efs filtered
7089204.93.193.141 520 udp route unknown
7090204.93.193.141 2049 tcp nfs filtered
7091204.93.193.141 2049 udp nfs unknown
7092206.48.140.40 53 tcp domain filtered
7093206.48.140.40 53 udp domain unknown
7094206.48.140.40 67 tcp dhcps filtered
7095206.48.140.40 67 udp dhcps unknown
7096206.48.140.40 68 tcp dhcpc filtered
7097206.48.140.40 68 udp dhcpc unknown
7098206.48.140.40 69 tcp tftp filtered
7099206.48.140.40 69 udp tftp unknown
7100206.48.140.40 88 tcp kerberos-sec filtered
7101206.48.140.40 88 udp kerberos-sec unknown
7102206.48.140.40 123 tcp ntp filtered
7103206.48.140.40 123 udp ntp unknown
7104206.48.140.40 137 tcp netbios-ns filtered
7105206.48.140.40 137 udp netbios-ns unknown
7106206.48.140.40 138 tcp netbios-dgm filtered
7107206.48.140.40 138 udp netbios-dgm unknown
7108206.48.140.40 139 tcp netbios-ssn filtered
7109206.48.140.40 139 udp netbios-ssn unknown
7110206.48.140.40 161 tcp snmp filtered
7111206.48.140.40 161 udp snmp unknown
7112206.48.140.40 162 tcp snmptrap filtered
7113206.48.140.40 162 udp snmptrap unknown
7114206.48.140.40 389 tcp ldap filtered
7115206.48.140.40 389 udp ldap unknown
7116206.48.140.40 520 tcp efs filtered
7117206.48.140.40 520 udp route unknown
7118206.48.140.40 2049 tcp nfs filtered
7119206.48.140.40 2049 udp nfs unknown
7120207.246.147.189 53 tcp domain filtered
7121207.246.147.189 53 udp domain unknown
7122207.246.147.189 67 tcp dhcps filtered
7123207.246.147.189 67 udp dhcps unknown
7124207.246.147.189 68 tcp dhcpc filtered
7125207.246.147.189 68 udp dhcpc unknown
7126207.246.147.189 69 tcp tftp filtered
7127207.246.147.189 69 udp tftp unknown
7128207.246.147.189 80 tcp http open nginx
7129207.246.147.189 88 tcp kerberos-sec filtered
7130207.246.147.189 88 udp kerberos-sec unknown
7131207.246.147.189 123 tcp ntp filtered
7132207.246.147.189 123 udp ntp unknown
7133207.246.147.189 137 tcp netbios-ns filtered
7134207.246.147.189 137 udp netbios-ns unknown
7135207.246.147.189 138 tcp netbios-dgm filtered
7136207.246.147.189 138 udp netbios-dgm unknown
7137207.246.147.189 139 tcp netbios-ssn filtered
7138207.246.147.189 139 udp netbios-ssn unknown
7139207.246.147.189 161 tcp snmp filtered
7140207.246.147.189 161 udp snmp unknown
7141207.246.147.189 162 tcp snmptrap filtered
7142207.246.147.189 162 udp snmptrap unknown
7143207.246.147.189 389 tcp ldap filtered
7144207.246.147.189 389 udp ldap unknown
7145207.246.147.189 443 tcp ssl/http open nginx
7146207.246.147.189 520 tcp efs filtered
7147207.246.147.189 520 udp route unknown
7148207.246.147.189 2049 tcp nfs filtered
7149207.246.147.189 2049 udp nfs unknown
7150207.246.147.190 53 tcp domain filtered
7151207.246.147.190 53 udp domain unknown
7152207.246.147.190 67 tcp dhcps filtered
7153207.246.147.190 67 udp dhcps unknown
7154207.246.147.190 68 tcp dhcpc filtered
7155207.246.147.190 68 udp dhcpc unknown
7156207.246.147.190 69 tcp tftp filtered
7157207.246.147.190 69 udp tftp unknown
7158207.246.147.190 80 tcp http open nginx
7159207.246.147.190 88 tcp kerberos-sec filtered
7160207.246.147.190 88 udp kerberos-sec unknown
7161207.246.147.190 123 tcp ntp filtered
7162207.246.147.190 123 udp ntp unknown
7163207.246.147.190 137 tcp netbios-ns filtered
7164207.246.147.190 137 udp netbios-ns unknown
7165207.246.147.190 138 tcp netbios-dgm filtered
7166207.246.147.190 138 udp netbios-dgm filtered
7167207.246.147.190 139 tcp netbios-ssn filtered
7168207.246.147.190 139 udp netbios-ssn unknown
7169207.246.147.190 161 tcp snmp filtered
7170207.246.147.190 161 udp snmp unknown
7171207.246.147.190 162 tcp snmptrap filtered
7172207.246.147.190 162 udp snmptrap unknown
7173207.246.147.190 389 tcp ldap filtered
7174207.246.147.190 389 udp ldap unknown
7175207.246.147.190 443 tcp ssl/http open nginx
7176207.246.147.190 520 tcp efs filtered
7177207.246.147.190 520 udp route unknown
7178207.246.147.190 2049 tcp nfs filtered
7179207.246.147.190 2049 udp nfs unknown
7180207.246.147.247 53 tcp domain filtered
7181207.246.147.247 53 udp domain filtered
7182207.246.147.247 67 tcp dhcps filtered
7183207.246.147.247 67 udp dhcps unknown
7184207.246.147.247 68 tcp dhcpc filtered
7185207.246.147.247 68 udp dhcpc unknown
7186207.246.147.247 69 tcp tftp filtered
7187207.246.147.247 69 udp tftp unknown
7188207.246.147.247 80 tcp http open nginx
7189207.246.147.247 88 tcp kerberos-sec filtered
7190207.246.147.247 88 udp kerberos-sec unknown
7191207.246.147.247 123 tcp ntp filtered
7192207.246.147.247 123 udp ntp unknown
7193207.246.147.247 137 tcp netbios-ns filtered
7194207.246.147.247 137 udp netbios-ns filtered
7195207.246.147.247 138 tcp netbios-dgm filtered
7196207.246.147.247 138 udp netbios-dgm unknown
7197207.246.147.247 139 tcp netbios-ssn filtered
7198207.246.147.247 139 udp netbios-ssn unknown
7199207.246.147.247 161 tcp snmp filtered
7200207.246.147.247 161 udp snmp unknown
7201207.246.147.247 162 tcp snmptrap filtered
7202207.246.147.247 162 udp snmptrap unknown
7203207.246.147.247 389 tcp ldap filtered
7204207.246.147.247 389 udp ldap unknown
7205207.246.147.247 443 tcp ssl/http open nginx
7206207.246.147.247 520 tcp efs filtered
7207207.246.147.247 520 udp route unknown
7208207.246.147.247 2049 tcp nfs filtered
7209207.246.147.247 2049 udp nfs unknown
7210207.246.147.248 53 tcp domain filtered
7211207.246.147.248 53 udp domain unknown
7212207.246.147.248 67 tcp dhcps filtered
7213207.246.147.248 67 udp dhcps unknown
7214207.246.147.248 68 tcp dhcpc filtered
7215207.246.147.248 68 udp dhcpc unknown
7216207.246.147.248 69 tcp tftp filtered
7217207.246.147.248 69 udp tftp unknown
7218207.246.147.248 80 tcp http open nginx
7219207.246.147.248 88 tcp kerberos-sec filtered
7220207.246.147.248 88 udp kerberos-sec unknown
7221207.246.147.248 123 tcp ntp filtered
7222207.246.147.248 123 udp ntp unknown
7223207.246.147.248 137 tcp netbios-ns filtered
7224207.246.147.248 137 udp netbios-ns unknown
7225207.246.147.248 138 tcp netbios-dgm filtered
7226207.246.147.248 138 udp netbios-dgm unknown
7227207.246.147.248 139 tcp netbios-ssn filtered
7228207.246.147.248 139 udp netbios-ssn unknown
7229207.246.147.248 161 tcp snmp filtered
7230207.246.147.248 161 udp snmp unknown
7231207.246.147.248 162 tcp snmptrap filtered
7232207.246.147.248 162 udp snmptrap unknown
7233207.246.147.248 389 tcp ldap filtered
7234207.246.147.248 389 udp ldap unknown
7235207.246.147.248 443 tcp ssl/http open nginx
7236207.246.147.248 520 tcp efs filtered
7237207.246.147.248 520 udp route unknown
7238207.246.147.248 2049 tcp nfs filtered
7239207.246.147.248 2049 udp nfs unknown
7240211.13.196.135 25 tcp smtp closed
7241211.13.196.135 53 tcp domain filtered
7242211.13.196.135 53 udp domain unknown
7243211.13.196.135 67 tcp dhcps filtered
7244211.13.196.135 67 udp dhcps unknown
7245211.13.196.135 68 tcp dhcpc filtered
7246211.13.196.135 68 udp dhcpc unknown
7247211.13.196.135 69 tcp tftp filtered
7248211.13.196.135 69 udp tftp unknown
7249211.13.196.135 80 tcp http open Apache httpd
7250211.13.196.135 88 tcp kerberos-sec filtered
7251211.13.196.135 88 udp kerberos-sec unknown
7252211.13.196.135 113 tcp ident closed
7253211.13.196.135 123 tcp ntp filtered
7254211.13.196.135 123 udp ntp unknown
7255211.13.196.135 137 tcp netbios-ns filtered
7256211.13.196.135 137 udp netbios-ns filtered
7257211.13.196.135 138 tcp netbios-dgm filtered
7258211.13.196.135 138 udp netbios-dgm filtered
7259211.13.196.135 139 tcp netbios-ssn closed
7260211.13.196.135 139 udp netbios-ssn unknown
7261211.13.196.135 161 tcp snmp filtered
7262211.13.196.135 161 udp snmp unknown
7263211.13.196.135 162 tcp snmptrap filtered
7264211.13.196.135 162 udp snmptrap unknown
7265211.13.196.135 389 tcp ldap filtered
7266211.13.196.135 389 udp ldap unknown
7267211.13.196.135 443 tcp ssl/http open Apache httpd
7268211.13.196.135 445 tcp microsoft-ds closed
7269211.13.196.135 520 tcp efs filtered
7270211.13.196.135 520 udp route unknown
7271211.13.196.135 2049 tcp nfs filtered
7272211.13.196.135 2049 udp nfs unknown
7273212.174.0.150 53 tcp domain filtered
7274212.174.0.150 53 udp domain unknown
7275212.174.0.150 67 tcp dhcps filtered
7276212.174.0.150 67 udp dhcps unknown
7277212.174.0.150 68 tcp dhcpc filtered
7278212.174.0.150 68 udp dhcpc unknown
7279212.174.0.150 69 tcp tftp filtered
7280212.174.0.150 69 udp tftp unknown
7281212.174.0.150 80 tcp http open Microsoft IIS httpd 8.5
7282212.174.0.150 88 tcp kerberos-sec filtered
7283212.174.0.150 88 udp kerberos-sec unknown
7284212.174.0.150 123 tcp ntp filtered
7285212.174.0.150 123 udp ntp unknown
7286212.174.0.150 137 tcp netbios-ns filtered
7287212.174.0.150 137 udp netbios-ns unknown
7288212.174.0.150 138 tcp netbios-dgm filtered
7289212.174.0.150 138 udp netbios-dgm unknown
7290212.174.0.150 139 tcp netbios-ssn filtered
7291212.174.0.150 139 udp netbios-ssn unknown
7292212.174.0.150 161 tcp snmp filtered
7293212.174.0.150 161 udp snmp unknown
7294212.174.0.150 162 tcp snmptrap filtered
7295212.174.0.150 162 udp snmptrap unknown
7296212.174.0.150 389 tcp ldap filtered
7297212.174.0.150 389 udp ldap unknown
7298212.174.0.150 520 tcp efs filtered
7299212.174.0.150 520 udp route unknown
7300212.174.0.150 2049 tcp nfs filtered
7301212.174.0.150 2049 udp nfs unknown
7302216.172.184.117 21 tcp ftp open 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------\x0d\x0a220-You are user number 5 of 150 allowed.\x0d\x0a220-Local time is now 01:41. Server port: 21.\x0d\x0a220-IPv6 connections are also welcome on this server.\x0d\x0a220 You will be disconnected after 15 minutes of inactivity.\x0d\x0a
7303216.172.184.117 53 tcp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
7304216.172.184.117 53 udp domain open ISC BIND 9.8.2rc1 RedHat Enterprise Linux 6
7305216.172.184.117 67 tcp dhcps closed
7306216.172.184.117 67 udp dhcps closed
7307216.172.184.117 68 tcp dhcpc closed
7308216.172.184.117 68 udp dhcpc unknown
7309216.172.184.117 69 tcp tftp closed
7310216.172.184.117 69 udp tftp unknown
7311216.172.184.117 88 tcp kerberos-sec closed
7312216.172.184.117 88 udp kerberos-sec unknown
7313216.172.184.117 123 tcp ntp closed
7314216.172.184.117 123 udp ntp unknown
7315216.172.184.117 137 tcp netbios-ns closed
7316216.172.184.117 137 udp netbios-ns unknown
7317216.172.184.117 138 tcp netbios-dgm closed
7318216.172.184.117 138 udp netbios-dgm closed
7319216.172.184.117 139 tcp netbios-ssn closed
7320216.172.184.117 139 udp netbios-ssn closed
7321216.172.184.117 161 tcp snmp closed
7322216.172.184.117 161 udp snmp unknown
7323216.172.184.117 162 tcp snmptrap closed
7324216.172.184.117 162 udp snmptrap closed
7325216.172.184.117 389 tcp ldap closed
7326216.172.184.117 389 udp ldap closed
7327216.172.184.117 520 tcp efs closed
7328216.172.184.117 520 udp route closed
7329216.172.184.117 2049 tcp nfs closed
7330216.172.184.117 2049 udp nfs unknown
7331218.45.5.97 25 tcp smtp closed
7332218.45.5.97 53 tcp domain filtered
7333218.45.5.97 53 udp domain unknown
7334218.45.5.97 67 tcp dhcps filtered
7335218.45.5.97 67 udp dhcps unknown
7336218.45.5.97 68 tcp dhcpc filtered
7337218.45.5.97 68 udp dhcpc unknown
7338218.45.5.97 69 tcp tftp filtered
7339218.45.5.97 69 udp tftp unknown
7340218.45.5.97 80 tcp http open Apache httpd 2.4.6 (CentOS) OpenSSL/1.0.2k-fips mod_fcgid/2.3.9 PHP/7.2.15
7341218.45.5.97 88 tcp kerberos-sec filtered
7342218.45.5.97 88 udp kerberos-sec unknown
7343218.45.5.97 113 tcp ident closed
7344218.45.5.97 123 tcp ntp filtered
7345218.45.5.97 123 udp ntp unknown
7346218.45.5.97 137 tcp netbios-ns filtered
7347218.45.5.97 137 udp netbios-ns filtered
7348218.45.5.97 138 tcp netbios-dgm filtered
7349218.45.5.97 138 udp netbios-dgm filtered
7350218.45.5.97 139 tcp netbios-ssn closed
7351218.45.5.97 139 udp netbios-ssn unknown
7352218.45.5.97 161 tcp snmp filtered
7353218.45.5.97 161 udp snmp unknown
7354218.45.5.97 162 tcp snmptrap filtered
7355218.45.5.97 162 udp snmptrap unknown
7356218.45.5.97 389 tcp ldap filtered
7357218.45.5.97 389 udp ldap unknown
7358218.45.5.97 443 tcp ssl/http open Apache httpd 2.4.6 (CentOS) OpenSSL/1.0.2k-fips mod_fcgid/2.3.9 PHP/7.2.15
7359218.45.5.97 445 tcp microsoft-ds closed
7360218.45.5.97 520 tcp efs filtered
7361218.45.5.97 520 udp route unknown
7362218.45.5.97 2049 tcp nfs filtered
7363218.45.5.97 2049 udp nfs unknown
7364################################################################################################################################
7365Starting Nmap 7.80 ( https://nmap.org ) at 2020-03-23 10:11 EDT
7366Nmap scan report for byronbayoasisresort.com.au (188.127.251.161)
7367Host is up (0.16s latency).
7368Not shown: 929 filtered ports, 59 closed ports
7369PORT STATE SERVICE VERSION
737022/tcp open ssh OpenSSH 7.4 (protocol 2.0)
7371| vulscan: VulDB - https://vuldb.com:
7372| [130671] gsi-openssh-server 7.9p1 on Fedora /etc/gsissh/sshd_config weak authentication
7373| [130371] OpenSSH 7.9 scp Man-in-the-Middle directory traversal
7374| [130370] OpenSSH 7.9 Man-in-the-Middle spoofing
7375| [130369] OpenSSH 7.9 Encoding progressmeter.c refresh_progress_meter() spoofing
7376| [129007] OpenSSH 7.9 scp Client scp.c Filename privilege escalation
7377| [123343] OpenSSH up to 7.8 GSS2 auth-gss2.c information disclosure
7378| [123011] OpenSSH up to 7.7 auth2-gss.c Request information disclosure
7379| [112267] OpenSSH up to 7.3 sshd kex.c/packet.c NEWKEYS Message denial of service
7380| [108627] OpenSSH up to 7.5 Readonly Mode sftp-server.c process_open unknown vulnerability
7381| [94611] OpenSSH up to 7.3 Access Control privilege escalation
7382| [94610] OpenSSH up to 7.3 Shared Memory Manager privilege escalation
7383| [94608] OpenSSH up to 7.3 Unix-Domain Socket privilege escalation
7384| [94607] OpenSSH up to 7.3 Forwarded Agent Channel privilege escalation
7385| [90671] OpenSSH up to 7.2 auth-passwd.c auth_password denial of service
7386| [90405] OpenSSH up to 7.2p2 sshd information disclosure
7387| [90404] OpenSSH up to 7.2p2 sshd information disclosure
7388| [90403] OpenSSH up to 7.2p2 sshd CPU Exhaustion denial of service
7389| [89622] OpenSSH 7.2p2 Authentication Username information disclosure
7390| [81320] OpenSSH up to 7.2p1 X11 Authentication Credential xauth privilege escalation
7391| [80656] OpenBSD OpenSSH 7.1 X11 Forwarding privilege escalation
7392| [80330] OpenSSH up to 7.1p1 packet.c ssh_packet_read_poll2 memory corruption
7393|
7394| MITRE CVE - https://cve.mitre.org:
7395| [CVE-2010-4755] The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in SSH_FXP_STAT requests to an sftp daemon, a different vulnerability than CVE-2010-2632.
7396| [CVE-1999-0661] A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.
7397|
7398| SecurityFocus - https://www.securityfocus.com/bid/:
7399| [102780] OpenSSH CVE-2016-10708 Multiple Denial of Service Vulnerabilities
7400| [101552] OpenSSH 'sftp-server.c' Remote Security Bypass Vulnerability
7401| [94977] OpenSSH CVE-2016-10011 Local Information Disclosure Vulnerability
7402| [94975] OpenSSH CVE-2016-10012 Security Bypass Vulnerability
7403| [94972] OpenSSH CVE-2016-10010 Privilege Escalation Vulnerability
7404| [94968] OpenSSH CVE-2016-10009 Remote Code Execution Vulnerability
7405| [93776] OpenSSH 'ssh/kex.c' Denial of Service Vulnerability
7406| [92212] OpenSSH CVE-2016-6515 Denial of Service Vulnerability
7407| [92210] OpenSSH CBC Padding Weak Encryption Security Weakness
7408| [92209] OpenSSH MAC Verification Security Bypass Vulnerability
7409| [91812] OpenSSH CVE-2016-6210 User Enumeration Vulnerability
7410| [90440] OpenSSH CVE-2004-1653 Remote Security Vulnerability
7411| [90340] OpenSSH CVE-2004-2760 Remote Security Vulnerability
7412| [89385] OpenSSH CVE-2005-2666 Local Security Vulnerability
7413| [88655] OpenSSH CVE-2001-1382 Remote Security Vulnerability
7414| [88513] OpenSSH CVE-2000-0999 Remote Security Vulnerability
7415| [88367] OpenSSH CVE-1999-1010 Local Security Vulnerability
7416| [87789] OpenSSH CVE-2003-0682 Remote Security Vulnerability
7417| [86187] OpenSSH 'session.c' Local Security Bypass Vulnerability
7418| [86144] OpenSSH CVE-2007-2768 Remote Security Vulnerability
7419| [84427] OpenSSH CVE-2016-1908 Security Bypass Vulnerability
7420| [84314] OpenSSH CVE-2016-3115 Remote Command Injection Vulnerability
7421| [84185] OpenSSH CVE-2006-4925 Denial-Of-Service Vulnerability
7422| [81293] OpenSSH CVE-2016-1907 Denial of Service Vulnerability
7423| [80698] OpenSSH CVE-2016-0778 Heap Based Buffer Overflow Vulnerability
7424| [80695] OpenSSH CVE-2016-0777 Information Disclosure Vulnerability
7425| [76497] OpenSSH CVE-2015-6565 Local Security Bypass Vulnerability
7426| [76317] OpenSSH PAM Support Multiple Remote Code Execution Vulnerabilities
7427| [75990] OpenSSH Login Handling Security Bypass Weakness
7428| [75525] OpenSSH 'x11_open_helper()' Function Security Bypass Vulnerability
7429| [71420] Portable OpenSSH 'gss-serv-krb5.c' Security Bypass Vulnerability
7430| [68757] OpenSSH Multiple Remote Denial of Service Vulnerabilities
7431| [66459] OpenSSH Certificate Validation Security Bypass Vulnerability
7432| [66355] OpenSSH 'child_set_env()' Function Security Bypass Vulnerability
7433| [65674] OpenSSH 'ssh-keysign.c' Local Information Disclosure Vulnerability
7434| [65230] OpenSSH 'schnorr.c' Remote Memory Corruption Vulnerability
7435| [63605] OpenSSH 'sshd' Process Remote Memory Corruption Vulnerability
7436| [61286] OpenSSH Remote Denial of Service Vulnerability
7437| [58894] GSI-OpenSSH PAM_USER Security Bypass Vulnerability
7438| [58162] OpenSSH CVE-2010-5107 Denial of Service Vulnerability
7439| [54114] OpenSSH 'ssh_gssapi_parse_ename()' Function Denial of Service Vulnerability
7440| [51702] Debian openssh-server Forced Command Handling Information Disclosure Vulnerability
7441| [50416] Linux Kernel 'kdump' and 'mkdumprd' OpenSSH Integration Remote Information Disclosure Vulnerability
7442| [49473] OpenSSH Ciphersuite Specification Information Disclosure Weakness
7443| [48507] OpenSSH 'pam_thread()' Remote Buffer Overflow Vulnerability
7444| [47691] Portable OpenSSH 'ssh-keysign' Local Unauthorized Access Vulnerability
7445| [46155] OpenSSH Legacy Certificate Signing Information Disclosure Vulnerability
7446| [45304] OpenSSH J-PAKE Security Bypass Vulnerability
7447| [36552] Red Hat Enterprise Linux OpenSSH 'ChrootDirectory' Option Local Privilege Escalation Vulnerability
7448| [32319] OpenSSH CBC Mode Information Disclosure Vulnerability
7449| [30794] Red Hat OpenSSH Backdoor Vulnerability
7450| [30339] OpenSSH 'X11UseLocalhost' X11 Forwarding Session Hijacking Vulnerability
7451| [30276] Debian OpenSSH SELinux Privilege Escalation Vulnerability
7452| [28531] OpenSSH ForceCommand Command Execution Weakness
7453| [28444] OpenSSH X Connections Session Hijacking Vulnerability
7454| [26097] OpenSSH LINUX_AUDIT_RECORD_EVENT Remote Log Injection Weakness
7455| [25628] OpenSSH X11 Cookie Local Authentication Bypass Vulnerability
7456| [23601] OpenSSH S/Key Remote Information Disclosure Vulnerability
7457| [20956] OpenSSH Privilege Separation Key Signature Weakness
7458| [20418] OpenSSH-Portable Existing Password Remote Information Disclosure Weakness
7459| [20245] OpenSSH-Portable GSSAPI Authentication Abort Information Disclosure Weakness
7460| [20241] Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
7461| [20216] OpenSSH Duplicated Block Remote Denial of Service Vulnerability
7462| [16892] OpenSSH Remote PAM Denial Of Service Vulnerability
7463| [14963] OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
7464| [14729] OpenSSH GSSAPI Credential Disclosure Vulnerability
7465| [14727] OpenSSH DynamicForward Inadvertent GatewayPorts Activation Vulnerability
7466| [11781] OpenSSH-portable PAM Authentication Remote Information Disclosure Vulnerability
7467| [9986] RCP, OpenSSH SCP Client File Corruption Vulnerability
7468| [9040] OpenSSH PAM Conversation Memory Scrubbing Weakness
7469| [8677] Multiple Portable OpenSSH PAM Vulnerabilities
7470| [8628] OpenSSH Buffer Mismanagement Vulnerabilities
7471| [7831] OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
7472| [7482] OpenSSH Remote Root Authentication Timing Side-Channel Weakness
7473| [7467] OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
7474| [7343] OpenSSH Authentication Execution Path Timing Information Leakage Weakness
7475| [6168] OpenSSH Visible Password Vulnerability
7476| [5374] OpenSSH Trojan Horse Vulnerability
7477| [5093] OpenSSH Challenge-Response Buffer Overflow Vulnerabilities
7478| [4560] OpenSSH Kerberos 4 TGT/AFS Token Buffer Overflow Vulnerability
7479| [4241] OpenSSH Channel Code Off-By-One Vulnerability
7480| [3614] OpenSSH UseLogin Environment Variable Passing Vulnerability
7481| [3560] OpenSSH Kerberos Arbitrary Privilege Elevation Vulnerability
7482| [3369] OpenSSH Key Based Source IP Access Control Bypass Vulnerability
7483| [3345] OpenSSH SFTP Command Restriction Bypassing Vulnerability
7484| [2917] OpenSSH PAM Session Evasion Vulnerability
7485| [2825] OpenSSH Client X11 Forwarding Cookie Removal File Symbolic Link Vulnerability
7486| [2356] OpenSSH Private Key Authentication Check Vulnerability
7487| [1949] OpenSSH Client Unauthorized Remote Forwarding Vulnerability
7488| [1334] OpenSSH UseLogin Vulnerability
7489|
7490| IBM X-Force - https://exchange.xforce.ibmcloud.com:
7491| [83258] GSI-OpenSSH auth-pam.c security bypass
7492| [82781] OpenSSH time limit denial of service
7493| [82231] OpenSSH pam_ssh_agent_auth PAM code execution
7494| [74809] OpenSSH ssh_gssapi_parse_ename denial of service
7495| [72756] Debian openssh-server commands information disclosure
7496| [68339] OpenSSH pam_thread buffer overflow
7497| [67264] OpenSSH ssh-keysign unauthorized access
7498| [65910] OpenSSH remote_glob function denial of service
7499| [65163] OpenSSH certificate information disclosure
7500| [64387] OpenSSH J-PAKE security bypass
7501| [63337] Cisco Unified Videoconferencing OpenSSH weak security
7502| [46620] OpenSSH and multiple SSH Tectia products CBC mode information disclosure
7503| [45202] OpenSSH signal handler denial of service
7504| [44747] RHEL OpenSSH backdoor
7505| [44280] OpenSSH PermitRootLogin information disclosure
7506| [44279] OpenSSH sshd weak security
7507| [44037] OpenSSH sshd SELinux role unauthorized access
7508| [43940] OpenSSH X11 forwarding information disclosure
7509| [41549] OpenSSH ForceCommand directive security bypass
7510| [41438] OpenSSH sshd session hijacking
7511| [40897] OpenSSH known_hosts weak security
7512| [40587] OpenSSH username weak security
7513| [37371] OpenSSH username data manipulation
7514| [37118] RHSA update for OpenSSH privilege separation monitor authentication verification weakness not installed
7515| [37112] RHSA update for OpenSSH signal handler race condition not installed
7516| [37107] RHSA update for OpenSSH identical block denial of service not installed
7517| [36637] OpenSSH X11 cookie privilege escalation
7518| [35167] OpenSSH packet.c newkeys[mode] denial of service
7519| [34490] OpenSSH OPIE information disclosure
7520| [33794] OpenSSH ChallengeResponseAuthentication information disclosure
7521| [32975] Apple Mac OS X OpenSSH denial of service
7522| [32387] RHSA-2006:0738 updates for openssh not installed
7523| [32359] RHSA-2006:0697 updates for openssh not installed
7524| [32230] RHSA-2006:0298 updates for openssh not installed
7525| [32132] RHSA-2006:0044 updates for openssh not installed
7526| [30120] OpenSSH privilege separation monitor authentication verification weakness
7527| [29255] OpenSSH GSSAPI user enumeration
7528| [29254] OpenSSH signal handler race condition
7529| [29158] OpenSSH identical block denial of service
7530| [28147] Apple Mac OS X OpenSSH nonexistent user login denial of service
7531| [25116] OpenSSH OpenPAM denial of service
7532| [24305] OpenSSH SCP shell expansion command execution
7533| [22665] RHSA-2005:106 updates for openssh not installed
7534| [22117] OpenSSH GSSAPI allows elevated privileges
7535| [22115] OpenSSH GatewayPorts security bypass
7536| [20930] OpenSSH sshd.c LoginGraceTime denial of service
7537| [19441] Sun Solaris OpenSSH LDAP (1) client authentication denial of service
7538| [17213] OpenSSH allows port bouncing attacks
7539| [16323] OpenSSH scp file overwrite
7540| [13797] OpenSSH PAM information leak
7541| [13271] OpenSSH could allow an attacker to corrupt the PAM conversion stack
7542| [13264] OpenSSH PAM code could allow an attacker to gain access
7543| [13215] OpenSSH buffer management errors could allow an attacker to execute code
7544| [13214] OpenSSH memory vulnerabilities
7545| [13191] OpenSSH large packet buffer overflow
7546| [12196] OpenSSH could allow an attacker to bypass login restrictions
7547| [11970] OpenSSH could allow an attacker to obtain valid administrative account
7548| [11902] OpenSSH PAM support enabled information leak
7549| [9803] OpenSSH "
7550| [9763] OpenSSH downloaded from the OpenBSD FTP site or OpenBSD FTP mirror sites could contain a Trojan Horse
7551| [9307] OpenSSH is running on the system
7552| [9169] OpenSSH "
7553| [8896] OpenSSH Kerberos 4 TGT/AFS buffer overflow
7554| [8697] FreeBSD libutil in OpenSSH fails to drop privileges prior to using the login class capability database
7555| [8383] OpenSSH off-by-one error in channel code
7556| [7647] OpenSSH UseLogin option arbitrary code execution
7557| [7634] OpenSSH using sftp and restricted keypairs could allow an attacker to bypass restrictions
7558| [7598] OpenSSH with Kerberos allows attacker to gain elevated privileges
7559| [7179] OpenSSH source IP access control bypass
7560| [6757] OpenSSH "
7561| [6676] OpenSSH X11 forwarding symlink attack could allow deletion of arbitrary files
7562| [6084] OpenSSH 2.3.1 allows remote users to bypass authentication
7563| [5517] OpenSSH allows unauthorized access to resources
7564| [4646] OpenSSH UseLogin option allows remote users to execute commands as root
7565|
7566| Exploit-DB - https://www.exploit-db.com:
7567| [21579] OpenSSH 3.x Challenge-Response Buffer Overflow Vulnerabilities (2)
7568| [21578] OpenSSH 3.x Challenge-Response Buffer Overflow Vulnerabilities (1)
7569| [21402] OpenSSH 2.x/3.x Kerberos 4 TGT/AFS Token Buffer Overflow Vulnerability
7570| [21314] OpenSSH 2.x/3.0.1/3.0.2 Channel Code Off-By-One Vulnerability
7571| [20253] OpenSSH 1.2 scp File Create/Overwrite Vulnerability
7572| [17462] FreeBSD OpenSSH 3.5p1 - Remote Root Exploit
7573| [14866] Novell Netware 6.5 - OpenSSH Remote Stack Overflow
7574| [6094] Debian OpenSSH Remote SELinux Privilege Elevation Exploit (auth)
7575| [3303] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit
7576| [2444] OpenSSH <= 4.3 p1 (Duplicated Block) Remote Denial of Service Exploit
7577| [1572] Dropbear / OpenSSH Server (MAX_UNAUTH_CLIENTS) Denial of Service
7578| [258] glibc-2.2 and openssh-2.3.0p1 exploits glibc => 2.1.9x
7579| [26] OpenSSH/PAM <= 3.6.1p1 Remote Users Ident (gossh.sh)
7580| [25] OpenSSH/PAM <= 3.6.1p1 Remote Users Discovery Tool
7581|
7582| OpenVAS (Nessus) - http://www.openvas.org:
7583| [902488] OpenSSH 'sshd' GSSAPI Credential Disclosure Vulnerability
7584| [900179] OpenSSH CBC Mode Information Disclosure Vulnerability
7585| [881183] CentOS Update for openssh CESA-2012:0884 centos6
7586| [880802] CentOS Update for openssh CESA-2009:1287 centos5 i386
7587| [880746] CentOS Update for openssh CESA-2009:1470 centos5 i386
7588| [870763] RedHat Update for openssh RHSA-2012:0884-04
7589| [870129] RedHat Update for openssh RHSA-2008:0855-01
7590| [861813] Fedora Update for openssh FEDORA-2010-5429
7591| [861319] Fedora Update for openssh FEDORA-2007-395
7592| [861170] Fedora Update for openssh FEDORA-2007-394
7593| [861012] Fedora Update for openssh FEDORA-2007-715
7594| [840345] Ubuntu Update for openssh vulnerability USN-597-1
7595| [840300] Ubuntu Update for openssh update USN-612-5
7596| [840271] Ubuntu Update for openssh vulnerability USN-612-2
7597| [840268] Ubuntu Update for openssh update USN-612-7
7598| [840259] Ubuntu Update for openssh vulnerabilities USN-649-1
7599| [840214] Ubuntu Update for openssh vulnerability USN-566-1
7600| [831074] Mandriva Update for openssh MDVA-2010:162 (openssh)
7601| [830929] Mandriva Update for openssh MDVA-2010:090 (openssh)
7602| [830807] Mandriva Update for openssh MDVA-2010:026 (openssh)
7603| [830603] Mandriva Update for openssh MDVSA-2008:098 (openssh)
7604| [830523] Mandriva Update for openssh MDVSA-2008:078 (openssh)
7605| [830317] Mandriva Update for openssh-askpass-qt MDKA-2007:127 (openssh-askpass-qt)
7606| [830191] Mandriva Update for openssh MDKSA-2007:236 (openssh)
7607| [802407] OpenSSH 'sshd' Challenge Response Authentication Buffer Overflow Vulnerability
7608| [103503] openssh-server Forced Command Handling Information Disclosure Vulnerability
7609| [103247] OpenSSH Ciphersuite Specification Information Disclosure Weakness
7610| [103064] OpenSSH Legacy Certificate Signing Information Disclosure Vulnerability
7611| [100584] OpenSSH X Connections Session Hijacking Vulnerability
7612| [100153] OpenSSH CBC Mode Information Disclosure Vulnerability
7613| [66170] CentOS Security Advisory CESA-2009:1470 (openssh)
7614| [65987] SLES10: Security update for OpenSSH
7615| [65819] SLES10: Security update for OpenSSH
7616| [65514] SLES9: Security update for OpenSSH
7617| [65513] SLES9: Security update for OpenSSH
7618| [65334] SLES9: Security update for OpenSSH
7619| [65248] SLES9: Security update for OpenSSH
7620| [65218] SLES9: Security update for OpenSSH
7621| [65169] SLES9: Security update for openssh,openssh-askpass
7622| [65126] SLES9: Security update for OpenSSH
7623| [65019] SLES9: Security update for OpenSSH
7624| [65015] SLES9: Security update for OpenSSH
7625| [64931] CentOS Security Advisory CESA-2009:1287 (openssh)
7626| [61639] Debian Security Advisory DSA 1638-1 (openssh)
7627| [61030] Debian Security Advisory DSA 1576-2 (openssh)
7628| [61029] Debian Security Advisory DSA 1576-1 (openssh)
7629| [60840] FreeBSD Security Advisory (FreeBSD-SA-08:05.openssh.asc)
7630| [60803] Gentoo Security Advisory GLSA 200804-03 (openssh)
7631| [60667] Slackware Advisory SSA:2008-095-01 openssh
7632| [59014] Slackware Advisory SSA:2007-255-01 openssh
7633| [58741] Gentoo Security Advisory GLSA 200711-02 (openssh)
7634| [57919] Gentoo Security Advisory GLSA 200611-06 (openssh)
7635| [57895] Gentoo Security Advisory GLSA 200609-17 (openssh)
7636| [57585] Debian Security Advisory DSA 1212-1 (openssh (1:3.8.1p1-8.sarge.6))
7637| [57492] Slackware Advisory SSA:2006-272-02 openssh
7638| [57483] Debian Security Advisory DSA 1189-1 (openssh-krb5)
7639| [57476] FreeBSD Security Advisory (FreeBSD-SA-06:22.openssh.asc)
7640| [57470] FreeBSD Ports: openssh
7641| [56352] FreeBSD Security Advisory (FreeBSD-SA-06:09.openssh.asc)
7642| [56330] Gentoo Security Advisory GLSA 200602-11 (OpenSSH)
7643| [56294] Slackware Advisory SSA:2006-045-06 openssh
7644| [53964] Slackware Advisory SSA:2003-266-01 New OpenSSH packages
7645| [53885] Slackware Advisory SSA:2003-259-01 OpenSSH Security Advisory
7646| [53884] Slackware Advisory SSA:2003-260-01 OpenSSH updated again
7647| [53788] Debian Security Advisory DSA 025-1 (openssh)
7648| [52638] FreeBSD Security Advisory (FreeBSD-SA-03:15.openssh.asc)
7649| [52635] FreeBSD Security Advisory (FreeBSD-SA-03:12.openssh.asc)
7650| [11343] OpenSSH Client Unauthorized Remote Forwarding
7651| [10954] OpenSSH AFS/Kerberos ticket/token passing
7652| [10883] OpenSSH Channel Code Off by 1
7653| [10823] OpenSSH UseLogin Environment Variables
7654|
7655| SecurityTracker - https://www.securitytracker.com:
7656| [1028187] OpenSSH pam_ssh_agent_auth Module on Red Hat Enterprise Linux Lets Remote Users Execute Arbitrary Code
7657| [1026593] OpenSSH Lets Remote Authenticated Users Obtain Potentially Sensitive Information
7658| [1025739] OpenSSH on FreeBSD Has Buffer Overflow in pam_thread() That Lets Remote Users Execute Arbitrary Code
7659| [1025482] OpenSSH ssh-keysign Utility Lets Local Users Gain Elevated Privileges
7660| [1025028] OpenSSH Legacy Certificates May Disclose Stack Contents to Remote Users
7661| [1022967] OpenSSH on Red Hat Enterprise Linux Lets Remote Authenticated Users Gain Elevated Privileges
7662| [1021235] OpenSSH CBC Mode Error Handling May Let Certain Remote Users Obtain Plain Text in Certain Cases
7663| [1020891] OpenSSH on Debian Lets Remote Users Prevent Logins
7664| [1020730] OpenSSH for Red Hat Enterprise Linux Packages May Have Been Compromised
7665| [1020537] OpenSSH on HP-UX Lets Local Users Hijack X11 Sessions
7666| [1019733] OpenSSH Unsafe Default Configuration May Let Local Users Execute Arbitrary Commands
7667| [1019707] OpenSSH Lets Local Users Hijack Forwarded X Sessions in Certain Cases
7668| [1017756] Apple OpenSSH Key Generation Process Lets Remote Users Deny Service
7669| [1017183] OpenSSH Privilege Separation Monitor Validation Error May Cause the Monitor to Fail to Properly Control the Unprivileged Process
7670| [1016940] OpenSSH Race Condition in Signal Handler Lets Remote Users Deny Service and May Potentially Permit Code Execution
7671| [1016939] OpenSSH GSSAPI Authentication Abort Error Lets Remote Users Determine Valid Usernames
7672| [1016931] OpenSSH SSH v1 CRC Attack Detection Implementation Lets Remote Users Deny Service
7673| [1016672] OpenSSH on Mac OS X Lets Remote Users Deny Service
7674| [1015706] OpenSSH Interaction With OpenPAM Lets Remote Users Deny Service
7675| [1015540] OpenSSH scp Double Shell Character Expansion During Local-to-Local Copying May Let Local Users Gain Elevated Privileges in Certain Cases
7676| [1014845] OpenSSH May Unexpectedly Activate GatewayPorts and Also May Disclose GSSAPI Credentials in Certain Cases
7677| [1011193] OpenSSH scp Directory Traversal Flaw Lets Remote SSH Servers Overwrite Files in Certain Cases
7678| [1011143] OpenSSH Default Configuration May Be Unsafe When Used With Anonymous SSH Services
7679| [1007791] Portable OpenSSH PAM free() Bug May Let Remote Users Execute Root Code
7680| [1007716] OpenSSH buffer_append_space() and Other Buffer Management Errors May Let Remote Users Execute Arbitrary Code
7681| [1006926] OpenSSH Host Access Restrictions Can Be Bypassed By Remote Users
7682| [1006688] OpenSSH Timing Flaw With Pluggable Authentication Modules Can Disclose Valid User Account Names to Remote Users
7683| [1004818] OpenSSH's Secure Shell (SSH) Implementation Weakness May Disclose User Passwords to Remote Users During Man-in-the-Middle Attacks
7684| [1004616] OpenSSH Integer Overflow and Buffer Overflow May Allow Remote Users to Gain Root Access to the System
7685| [1004391] OpenSSH 'BSD_AUTH' Access Control Bug May Allow Unauthorized Remote Users to Authenticated to the System
7686| [1004115] OpenSSH Buffer Overflow in Kerberos Ticket and AFS Token Processing Lets Local Users Execute Arbitrary Code With Root Level Permissions
7687| [1003758] OpenSSH Off-by-one 'Channels' Bug May Let Authorized Remote Users Execute Arbitrary Code with Root Privileges
7688| [1002895] OpenSSH UseLogin Environment Variable Bug Lets Local Users Execute Commands and Gain Root Access
7689| [1002748] OpenSSH 3.0 Denial of Service Condition May Allow Remote Users to Crash the sshd Daemon and KerberosV Configuration Error May Allow Remote Users to Partially Authenticate When Authentication Should Not Be Permitted
7690| [1002734] OpenSSH's S/Key Implementation Information Disclosure Flaw Provides Remote Users With Information About Valid User Accounts
7691| [1002455] OpenSSH May Fail to Properly Restrict IP Addresses in Certain Configurations
7692| [1002432] OpenSSH's Sftp-server Subsystem Lets Authorized Remote Users with Restricted Keypairs Obtain Additional Access on the Server
7693| [1001683] OpenSSH Allows Authorized Users to Delete Other User Files Named Cookies
7694|
7695| OSVDB - http://www.osvdb.org:
7696| [92034] GSI-OpenSSH auth-pam.c Memory Management Authentication Bypass
7697| [90474] Red Hat / Fedora PAM Module for OpenSSH Incorrect error() Function Calling Local Privilege Escalation
7698| [90007] OpenSSH logingracetime / maxstartup Threshold Connection Saturation Remote DoS
7699| [81500] OpenSSH gss-serv.c ssh_gssapi_parse_ename Function Field Length Value Parsing Remote DoS
7700| [78706] OpenSSH auth-options.c sshd auth_parse_options Function authorized_keys Command Option Debug Message Information Disclosure
7701| [75753] OpenSSH PAM Module Aborted Conversation Local Information Disclosure
7702| [75249] OpenSSH sftp-glob.c remote_glob Function Glob Expression Parsing Remote DoS
7703| [75248] OpenSSH sftp.c process_put Function Glob Expression Parsing Remote DoS
7704| [72183] Portable OpenSSH ssh-keysign ssh-rand-helper Utility File Descriptor Leak Local Information Disclosure
7705| [70873] OpenSSH Legacy Certificates Stack Memory Disclosure
7706| [69658] OpenSSH J-PAKE Public Parameter Validation Shared Secret Authentication Bypass
7707| [67743] Novell NetWare OpenSSH SSHD.NLM Absolute Path Handling Remote Overflow
7708| [59353] OpenSSH sshd Local TCP Redirection Connection Masking Weakness
7709| [58495] OpenSSH sshd ChrootDirectory Feature SetUID Hard Link Local Privilege Escalation
7710| [56921] OpenSSH Unspecified Remote Compromise
7711| [53021] OpenSSH on ftp.openbsd.org Trojaned Distribution
7712| [50036] OpenSSH CBC Mode Chosen Ciphertext 32-bit Chunk Plaintext Context Disclosure
7713| [49386] OpenSSH sshd TCP Connection State Remote Account Enumeration
7714| [48791] OpenSSH on Debian sshd Crafted Username Arbitrary Remote SELinux Role Access
7715| [47635] OpenSSH Packages on Red Hat Enterprise Linux Compromised Distribution
7716| [47227] OpenSSH X11UseLocalhost X11 Forwarding Port Hijacking
7717| [45873] Cisco WebNS SSHield w/ OpenSSH Crafted Large Packet Remote DoS
7718| [43911] OpenSSH ~/.ssh/rc ForceCommand Bypass Arbitrary Command Execution
7719| [43745] OpenSSH X11 Forwarding Local Session Hijacking
7720| [43371] OpenSSH Trusted X11 Cookie Connection Policy Bypass
7721| [39214] OpenSSH linux_audit_record_event Crafted Username Audit Log Injection
7722| [37315] pam_usb OpenSSH Authentication Unspecified Issue
7723| [34850] OpenSSH on Mac OS X Key Generation Remote Connection DoS
7724| [34601] OPIE w/ OpenSSH Account Enumeration
7725| [34600] OpenSSH S/KEY Authentication Account Enumeration
7726| [32721] OpenSSH Username Password Complexity Account Enumeration
7727| [30232] OpenSSH Privilege Separation Monitor Weakness
7728| [29494] OpenSSH packet.c Invalid Protocol Sequence Remote DoS
7729| [29266] OpenSSH GSSAPI Authentication Abort Username Enumeration
7730| [29264] OpenSSH Signal Handler Pre-authentication Race Condition Code Execution
7731| [29152] OpenSSH Identical Block Packet DoS
7732| [27745] Apple Mac OS X OpenSSH Nonexistent Account Login Enumeration DoS
7733| [23797] OpenSSH with OpenPAM Connection Saturation Forked Process Saturation DoS
7734| [22692] OpenSSH scp Command Line Filename Processing Command Injection
7735| [20216] OpenSSH with KerberosV Remote Authentication Bypass
7736| [19142] OpenSSH Multiple X11 Channel Forwarding Leaks
7737| [19141] OpenSSH GSSAPIAuthentication Credential Escalation
7738| [18236] OpenSSH no pty Command Execution Local PAM Restriction Bypass
7739| [16567] OpenSSH Privilege Separation LoginGraceTime DoS
7740| [16039] Solaris 108994 Series Patch OpenSSH LDAP Client Authentication DoS
7741| [9562] OpenSSH Default Configuration Anon SSH Service Port Bounce Weakness
7742| [9550] OpenSSH scp Traversal Arbitrary File Overwrite
7743| [6601] OpenSSH *realloc() Unspecified Memory Errors
7744| [6245] OpenSSH SKEY/BSD_AUTH Challenge-Response Remote Overflow
7745| [6073] OpenSSH on FreeBSD libutil Arbitrary File Read
7746| [6072] OpenSSH PAM Conversation Function Stack Modification
7747| [6071] OpenSSH SSHv1 PAM Challenge-Response Authentication Privilege Escalation
7748| [5536] OpenSSH sftp-server Restricted Keypair Restriction Bypass
7749| [5408] OpenSSH echo simulation Information Disclosure
7750| [5113] OpenSSH NIS YP Netgroups Authentication Bypass
7751| [4536] OpenSSH Portable AIX linker Privilege Escalation
7752| [3938] OpenSSL and OpenSSH /dev/random Check Failure
7753| [3456] OpenSSH buffer_append_space() Heap Corruption
7754| [2557] OpenSSH Multiple Buffer Management Multiple Overflows
7755| [2140] OpenSSH w/ PAM Username Validity Timing Attack
7756| [2112] OpenSSH Reverse DNS Lookup Bypass
7757| [2109] OpenSSH sshd Root Login Timing Side-Channel Weakness
7758| [1853] OpenSSH Symbolic Link 'cookies' File Removal
7759| [839] OpenSSH PAMAuthenticationViaKbdInt Challenge-Response Remote Overflow
7760| [781] OpenSSH Kerberos TGT/AFS Token Passing Remote Overflow
7761| [730] OpenSSH Channel Code Off by One Remote Privilege Escalation
7762| [688] OpenSSH UseLogin Environment Variable Local Command Execution
7763| [642] OpenSSH Multiple Key Type ACL Bypass
7764| [504] OpenSSH SSHv2 Public Key Authentication Bypass
7765| [341] OpenSSH UseLogin Local Privilege Escalation
7766|_
776725/tcp open smtp?
776853/tcp open domain PowerDNS Authoritative Server 4.1.10
7769| vulscan: VulDB - https://vuldb.com:
7770| [127296] PowerDNS Authoritative Server/Recursor up to 4.1.4 Cache Packet denial of service
7771| [133822] Kofax Front Office Server 4.1.1.11.0.5212 Administration Console upload Parameter XML External Entity
7772| [133821] Kofax Front Office Server 4.1.1.11.0.5212 Administration Console cross site scripting
7773| [133820] Kofax Front Office Server 4.1.1.11.0.5212 Administration Console Cleartext information disclosure
7774| [62114] Litespeedtech LiteSpeed Web Server 4.1.11 cross site scripting
7775| [50454] Symantec SecurityExpressions Audit and Compliance Server up to 4.1.1 Error Message cross site scripting
7776| [50453] Symantec SecurityExpressions Audit and Compliance Server up to 4.1.1 Error Message cross site scripting
7777| [40426] Seattle Lab Software SLNet RF Telnet Server up to 4.1.1.3758 slnet.exe denial of service
7778|
7779| MITRE CVE - https://cve.mitre.org:
7780| [CVE-2002-1148] The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
7781| [CVE-2013-3970] Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.
7782| [CVE-2012-4871] Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script or HTML via the gtitle parameter.
7783| [CVE-2012-4729] Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.
7784| [CVE-2011-5239] CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
7785| [CVE-2011-4535] Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file.
7786| [CVE-2011-1498] Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
7787| [CVE-2010-2156] ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.
7788| [CVE-2009-3030] Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue."
7789| [CVE-2009-3029] Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote authenticated users to inject arbitrary web script or HTML via "external client input" that triggers crafted error messages.
7790| [CVE-2008-3286] SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to the server before user session initialization, which triggers a NULL pointer dereference
7791| [CVE-2008-0441] IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log
7792| [CVE-2008-0152] SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unspecified telnet options, which triggers a NULL pointer dereference. NOTE: the crash is not user-assisted when the server is running in debug mode.
7793| [CVE-2007-2865] Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter.
7794| [CVE-2006-2587] Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 and earlier, (3) Battlefield 1942 1.158 and earlier, (4) Battlefield 2 1.184 and earlier, (5) Battlefield Vietnam 1.150 and earlier, (6) Call of Duty 1.173 and earlier, (7) Call of Duty 2 1.108 and earlier, (8) DOOM 3 1.159 and earlier, (9) Enemy Territory 1.167 and earlier, (10) Far Cry 1.150 and earlier, (11) F.E.A.R. 1.093 and earlier, (12) Joint Operations 1.187 and earlier, (13) Quake III Arena 1.150 and earlier, (14) Quake 4 1.181 and earlier, (15) Rainbow Six 3: Raven Shield 1.169 and earlier, (16) Rainbow Six 4: Lockdown 1.093 and earlier, (17) Return to Castle Wolfenstein 1.175 and earlier, and (18) Soldier of Fortune II 1.183 and earlier allows remote attackers to cause a denial of service (application crash) via a long webkey parameter.
7795| [CVE-2006-2369] RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.
7796| [CVE-2003-1414] Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename paramter.
7797| [CVE-2003-1413] parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.
7798| [CVE-2003-0055] Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.
7799| [CVE-2003-0054] Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.
7800| [CVE-2003-0053] Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.
7801| [CVE-2003-0052] parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.
7802| [CVE-2003-0051] parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.
7803| [CVE-2003-0050] parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.
7804| [CVE-2002-0600] Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request.
7805|
7806| SecurityFocus - https://www.securityfocus.com/bid/:
7807| [101982] PowerDNS Authoritative Server Module Multiple Security Vulnerabilities
7808| [89554] Webserver 4 Everyone CVE-2002-1504 Directory Traversal Vulnerability
7809| [82743] Internet Transaction Server 4620.2.0.323011 CVE-2003-1036 Remote Security Vulnerability
7810| [82686] Internet Transaction Server 4620.2.0.323011 CVE-2003-1037 Remote Security Vulnerability
7811| [82454] WordPress Prior to 4.4.2 Server Side Request Forgery Security Bypass Vulnerability
7812| [77836] Internet Transaction Server 4620.2.0.323011 CVE-2003-1038 Information Disclosure Vulnerability
7813| [53472] eLearning Server 4G Remote File Include and SQL Injection Vulnerabilities
7814| [51355] PowerDNS Authoritative Server Remote Denial of Service Vulnerability
7815| [50355] Wing FTP Server Versions Prior to 4.0.1 Information Disclosure Vulnerability
7816| [36739] Overland Storage Snap Server 410 'less' Command Local Privilege Escalation Vulnerability
7817| [36244] Sun Java System ASP Server 4.0.3 Multiple Unspecified Remote Vulnerabilities
7818| [34031] Sun Solaris NFS Version 4 Server Kernel Module Local Denial Of Service Vulnerability
7819| [30152] Empire Server Prior to 4.3.15 Multiple Unspecified Vulnerabilities
7820| [28148] Neptune Web Server 404 Error Page Cross Site Scripting Vulnerability
7821| [26663] Apache HTTP Server 413 Error HTTP Request Method Cross-Site Scripting Weakness
7822| [21560] OpenLDAP Server Kerveros 4 Bind Request Buffer Overflow Vulnerability
7823| [15495] SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released - Multiple Vulnerabilities Fixed
7824| [12937] FastStone 4in1 Browser Web Server Remote Directory Traversal Vulnerability
7825| [9196] Mambo Open Source 4.0.14 Server SQL Injection Vulnerability
7826| [8647] Multiple Mambo Open Source 4.0.14 Server Vulnerabilities
7827| [7541] Microsoft SQL Server JET Database Engine 4.0 Buffer Overrun Vulnerability
7828| [7479] MDG Web Server 4D HTTP Command Buffer Overflow Vulnerability
7829| [6034] Radiobird Software WebServer 4 All Host Field Header Buffer Overflow Vulnerability
7830| [5968] RadioBird Software WebServer 4 All Directory Traversal Vulnerability
7831| [5967] RadioBird Software WebServer 4 All Buffer Overflow Vulnerability
7832| [5803] MDG Web Server 4D Insecure Credential Storage Vulnerability
7833| [3874] MDG Computer Services Web Server 4D/eCommerce DoS Vulnerability
7834| [1924] Windows NT 4.0 Terminal Server RegAPI.DLL Buffer Overflow
7835| [1811] Microsoft Site Server 2.0 with IIS 4.0 Malicious File Upload Vulnerability
7836| [1778] Evolvable Shambala Server 4.5 DoS Vulnerability
7837| [1771] Evolvable Shambala Server 4.5 Plaintext Password Vulnerability
7838| [1582] OS/2 4.5 FTP Server Login DoS Vulnerability
7839| [1314] Allaire ColdFusion Server 4.5.1 Administrator Login Password DoS Vulnerability
7840| [1287] Sambar Server 4.3 Buffer Overflow Vulnerability
7841| [1001] InterAccess TelnetD Server 4.0 Terminal Configuration Vulnerability
7842| [995] InterAccess TelnetD Server 4.0 Buffer Overflow Vulnerability
7843| [601] Lotus Notes Domino Server 4.6 NLDAP DoS Vulnerability
7844| [61774] ISC BIND 9 SRTT Algorithm Authoritative Server Selection Security Vulnerability
7845| [59348] PowerDNS Recursive Server CVE-2012-1193 Multiple Security Bypass Vulnerabilities
7846|
7847| IBM X-Force - https://exchange.xforce.ibmcloud.com:
7848| [13657] Apache HTTP Server 401 error page not CGI script
7849| [4293] iPlanet Web Server 4.1 GET denial of service
7850|
7851| Exploit-DB - https://www.exploit-db.com:
7852| [22968] Valve Software Half-Life Server <= 1.1.1.0 , 3.1.1.1c1 and 4.1.1.1a Multiplayer Request Buffer Overflow
7853| [29439] iPlanet Web Server 4.1 Search Module Cross-Site Scripting Vulnerability
7854| [28666] Call of Duty Server 4.1.x Callvote Map Command Remote Buffer Overflow Vulnerability
7855| [26401] TRENDnet TE100-P1U Print Server Firmware 4.11 Authentication Bypass Vulnerability
7856| [26376] Xerver 4.17 Server URI Null Character XSS
7857| [23410] IBM Directory Server 4.1 Web Administration Interface Cross-Site Scripting Vulnerability
7858| [22629] Apple QuickTime/Darwin Streaming Server 4.1.3 QTSSReflector Module Integer Overflow Vulnerability
7859| [22472] Vignette StoryServer 4.1 Sensitive Stack Memory Information Disclosure Vulnerability
7860| [22312] Apple QuickTime/Darwin Streaming Server 4.1.x parse_xml.cgi File Disclosure Vulnerability
7861| [22230] Netscape Enterprise Server 4.1 HTTP Method Name Buffer Overflow Vulnerability
7862| [21603] iPlanet Web Server 4.1 Search Component File Disclosure Vulnerability
7863| [20570] Sambar Server 4.1 beta Admin Access Vulnerability
7864| [20325] Netscape Directory Server 4.12 Directory Server Directory Traversal Vulnerability
7865| [19112] BSDI BSD/OS <= 2.1,Caldera OpenLinux Standard 1.0,Data General DG/UX <= 5.4 4.11,IBM AIX <= 4.3,ISC BIND <= 8.1.1,NetBSD <= 1.3.1,RedHat Linux <= 5.0,SCO Open Desktop 3.0/Server 5.0,Unixware 2.1/7.0,SGI IRIX <= 6.3,Solaris <= 2.5.1 BIND buffer overflow(2)
7866| [19111] BSDI BSD/OS <= 2.1,Caldera OpenLinux Standard 1.0,Data General DG/UX <= 5.4 4.11,IBM AIX <= 4.3,ISC BIND <= 8.1.1,NetBSD <= 1.3.1,RedHat Linux <= 5.0,SCO Open Desktop 3.0/Server 5.0,Unixware 2.1/7.0,SGI IRIX <= 6.3,Solaris <= 2.5.1 BIND buffer overflow(1)
7867| [1739] Darwin Streaming Server <= 4.1.2 (parse_xml.cgi) Code Execution Exploit
7868| [1327] FTGate4 Groupware Mail Server 4.1 (imapd) Remote Buffer Overflow PoC
7869| [116] NIPrint LPD-LPR Print Server <= 4.10 Remote Exploit
7870|
7871| OpenVAS (Nessus) - http://www.openvas.org:
7872| [103488] eLearning Server 4G Remote File Include and SQL Injection Vulnerabilities
7873| [103383] PowerDNS Authoritative Server Remote Denial of Service Vulnerability
7874| [11441] Mambo Site Server 4.0.10 XSS
7875| [11151] Webserver 4D Cleartext Passwords
7876|
7877| SecurityTracker - https://www.securitytracker.com:
7878| [1026729] PowerDNS Authoritative Server Packet Loop Lets Remote Users Deny Service
7879| [1006687] Web Server 4D Buffer Overflow in Processing Long URLs Allows Remote Users to Execute Arbitrary Code
7880| [1005470] WebServer 4 Everyone Bounds Checking Error Lets Remote Users Crash the Server With a Long Host Field
7881| [1005417] Web Server 4 Everyone Can Be Crashed By Remote Users Sending Long HTTP GET Requests
7882| [1005286] Web Server 4D May Disclose Passwords to Local Users
7883| [1005194] Web Server 4 Everyone Input Validation Flaw Discloses Files to Remote Users
7884| [1003756] Microsoft Internet Information Server 4.0 .HTR Web Application Lets Users Change Their Passwords When the NT Security Policy is Configured to Prohibit Password Changing
7885| [1003224] Microsoft Internet Information Server (IIS) Version 4 Lets Local Users Modify the Log File Undetected
7886| [1003220] Web Server 4D/eCommerce Discloses Files Located Anywhere on the Server to Remote Users
7887| [1003219] Web Server 4D/eCommerce Can Be Crashed By Remote Users Sending a Few Long URL GET Requests
7888|
7889| OSVDB - http://www.osvdb.org:
7890| [78556] Apache HTTP Server Status Code 400 Default Error Response httpOnly Cookie Disclosure
7891| [68626] OpenConnect AnyConnect SSL VPN Server 404 HTTP Status Code Remote DoS
7892| [59540] RadioBird WebServer 4 Everyone Long Host Header HTTP GET Request Remote DoS
7893| [59528] Simple Web Server (SWS) 404 Error Message File Descriptor Closure Weakness Remote DoS
7894| [59158] TwonkyMedia Server 404 Error Page XSS
7895| [55331] MDG Web Server 4D GET Request Remote Overflow DoS
7896| [47587] PowerDNS Authoritative Server Malformed Query Cache Poisoning Weakness
7897| [45420] Apache HTTP Server 403 Error Page UTF-7 Encoded XSS
7898| [42796] Neptune Web Server 404 Error Page XSS
7899| [24469] Cherokee Web Server Error 400 XSS
7900| [15118] FastStone 4in1 Browser Web Server Traversal Arbitrary File Access
7901| [14511] WebServer 4 Everyone HTTP GET Request Remote Overflow
7902| [14252] Web Server 4D/eCommerce Traversal Arbitrary File Access
7903| [10888] QNX 405 Voyager Web Server .photon Directory Information Disclosure
7904| [8946] RadioBird WebServer 4 Everyone Encoded Double Dot Traversal Arbitrary File Access
7905| [8934] WebServer 4 Everyone Double Dot Traversal Arbitrary File Access
7906| [5371] MDG Computer Services Web Server 4D (WS4D) Cleartext Password Storage
7907| [5370] MDG Computer Services Web Server 4D (WS4D)/eCommerce HTTP Request Overflow DoS
7908| [4880] MIT Kerberos 4 Key Server Session Key Masquerade
7909| [2732] Fastream NETFile FTP/WebServer 404 Error Page XSS
7910| [72539] ISC BIND Authoritative Server Crafted IXFR / DDNS Query Update Deadlock DoS
7911| [43906] PowerDNS Unspecified MiTM Master/Server DoS
7912|_
791380/tcp open http Apache httpd
7914|_http-server-header: Apache
7915| vulscan: VulDB - https://vuldb.com:
7916| [141649] Apache OFBiz up to 16.11.05 Form Widget Freemarker Markup Code Execution
7917| [141648] Apache OFBiz up to 16.11.05 Application Stored cross site scripting
7918| [140386] Apache Commons Beanutils 1.9.2 BeanIntrospector unknown vulnerability
7919| [139708] Apache Ranger up to 1.2.0 Policy Import cross site scripting
7920| [139540] cPanel up to 60.0.24 Apache HTTP Server Key information disclosure
7921| [139386] Apache Tike up to 1.21 RecursiveParserWrapper Stack-based memory corruption
7922| [139385] Apache Tika 1.19/1.20/1.21 SAXParsers Hang denial of service
7923| [139384] Apache Tika up to 1.21 RecursiveParserWrapper ZIP File denial of service
7924| [139261] Apache Solr 8.2.0 DataImportHandler Parameter unknown vulnerability
7925| [139259] cPanel up to 68.0.26 WHM Apache Includes Editor information disclosure
7926| [139256] cPanel up to 68.0.26 WHM Apache Configuration Include Editor cross site scripting
7927| [139239] cPanel up to 70.0.22 Apache HTTP Server Log information disclosure
7928| [139141] Apache ActiveMQ Client up to 5.15.4 ActiveMQConnection.java ActiveMQConnection denial of service
7929| [139130] cPanel up to 73.x Apache HTTP Server Injection privilege escalation
7930| [138914] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 VM sql injection
7931| [138913] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Block Argument privilege escalation
7932| [138912] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Cookie sql injection
7933| [138816] Apache Storm up to 1.2.2 Logviewer Daemon Log information disclosure
7934| [138815] Apache Storm up to 1.2.2 UI Daemon Deserialization privilege escalation
7935| [138164] Oracle 2.7.0.1 Apache Log4j unknown vulnerability
7936| [138155] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Tomcat unknown vulnerability
7937| [138151] Oracle Transportation Management 6.3.7 Apache Tomcat unknown vulnerability
7938| [138149] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Commons FileUpload unknown vulnerability
7939| [138131] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Tomcat unknown vulnerability
7940| [138129] Oracle Retail Xstore Point of Service 7.0/7.1 Apache HTTP Server denial of service
7941| [138123] Oracle Retail Order Management System 5.0 Apache Struts 1 unknown vulnerability
7942| [138122] Oracle Retail Order Broker 5.2/15.0 Apache Tomcat unknown vulnerability
7943| [138121] Oracle Retail Order Broker 5.2/15.0 Apache CXF unknown vulnerability
7944| [138112] Oracle Retail Integration Bus 15.0/16.0 Apache Commons FileUpload unknown vulnerability
7945| [138111] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Commons FileUpload unknown vulnerability
7946| [138103] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56/8.57 Apache WSS4J information disclosure
7947| [138053] Oracle JD Edwards EnterpriseOne Tools 9.2 Apache Log4j unknown vulnerability
7948| [138036] Oracle Insurance Rules Palette 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
7949| [138035] Oracle Insurance Policy Administration J2EE 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
7950| [138034] Oracle Insurance Calculation Engine 9.7/10.0/10.1/10.2 Apache Commons FileUpload unknown vulnerability
7951| [138028] Oracle Identity Manager 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
7952| [138020] Oracle BI Publisher 11.1.1.9.0 Apache Tomcat unknown vulnerability
7953| [138019] Oracle BI Publisher (formerly XML Publisher) 11.1.1.9.0 Apache Tomcat unknown vulnerability
7954| [138017] Oracle Outside In Technology 8.5.4 Apache Commons FileUpload unknown vulnerability
7955| [138013] Oracle Outside In Technology 8.5.4 Apache Tomcat unknown vulnerability
7956| [138012] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
7957| [138009] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
7958| [138008] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Struts 1 denial of service
7959| [138007] Oracle WebCenter Sites 12.2.1.3.0 Apache Tomcat denial of service
7960| [138006] Oracle Enterprise Repository 12.1.3.0.0 Apache CXF denial of service
7961| [138000] Oracle WebCenter Sites 12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
7962| [137999] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
7963| [137995] Oracle Hospitality Simphony 18.2.1 Apache WSS4J information disclosure
7964| [137987] Oracle FLEXCUBE Universal Banking up to 12.0.3/12.4.0/14.2.0 Apache Log4j unknown vulnerability
7965| [137981] Oracle Insurance IFRS 17 Analyzer 8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
7966| [137980] Oracle Insurance Data Foundation 8.0.4/8.0.5/8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
7967| [137979] Oracle 8.0.8 Apache Commons FileUpload unknown vulnerability
7968| [137973] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Batik unknown vulnerability
7969| [137970] Oracle Financial Services Profitability Management 8.0.4/8.0.5/8.0.6/8.0.7 Apache ActiveMQ unknown vulnerability
7970| [137967] Oracle up to 8.0.7 Apache httpd unknown vulnerability
7971| [137966] Oracle 8.0.7/8.0.8 Apache Groovy unknown vulnerability
7972| [137965] Oracle Financial Services Liquidity Risk Management 8.0.1/8.0.2/8.0.4/8.0.5/8.0.6 Apache Commons FileUpload unknown vulnerability
7973| [137964] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Log4j unknown vulnerability
7974| [137933] Oracle Banking Platform up to 2.7.1 Apache Tika unknown vulnerability
7975| [137926] Oracle Enterprise Manager for Fusion Middleware 13.2/13.3 Apache Commons FileUpload information disclosure
7976| [137924] Oracle Enterprise Manager Base Platform 12.1.0.5.0/13.2.0.0.0/13.3.0.0.0 Apache Commons FileUpload unknown vulnerability
7977| [137914] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
7978| [137913] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
7979| [137911] Oracle E-Business Suite up to 12.2.8 Apache HTTP Server unknown vulnerability
7980| [137910] Oracle E-Business Suite up to 12.2.8 Apache CXF information disclosure
7981| [137909] Oracle E-Business Suite up to 12.2.8 Apache Commons FileUpload unknown vulnerability
7982| [137905] Oracle Primavera Gateway 15.2/16.2/17.12/18.8 Apache Tika denial of service
7983| [137901] Oracle Primavera Unifier up to 18.8 Apache HTTP Server unknown vulnerability
7984| [137895] Oracle Instant Messaging Server 10.0.1.2.0 Apache Tika information disclosure
7985| [137894] Oracle EAGLE (Software) 46.5/46.6/46.7 Apache Tomcat information disclosure
7986| [137892] Oracle Online Mediation Controller 6.1 Apache Batik denial of service
7987| [137891] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Tomcat unknown vulnerability
7988| [137885] Oracle Diameter Signaling Router (DSR) 8.0/8.1/8.2 Apache cxf unknown vulnerability
7989| [137882] Oracle Unified 8.0.0.2.0 Apache Commons FileUpload unknown vulnerability
7990| [137881] Oracle Online Mediation Controller 6.1 Apache Commons FileUpload unknown vulnerability
7991| [137880] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Log4j unknown vulnerability
7992| [137879] Oracle Convergence 3.0.2 Apache Commons FileUpload unknown vulnerability
7993| [137876] Oracle Application Session Controller 3.7.1/3.8.0 Apache Commons FileUpload unknown vulnerability
7994| [137829] Apache Roller 5.2.3 Math Comment Authenticator Reflected cross site scripting
7995| [137736] Apache Kafka 0.11.0.0/2.1.0 ACL Validation Request privilege escalation
7996| [136858] MakerBot Replicator 5G Printer Apache HTTP Server information disclosure
7997| [136849] Analogic Poste.io 2.1.6 on Apache RoundCube logs/ information disclosure
7998| [136822] Apache Tomcat up to 8.5.40/9.0.19 Incomplete Fix CVE-2019-0199 Resource Exhaustion denial of service
7999| [136808] Apache Geode up to 1.8.0 Secure Mode privilege escalation
8000| [136646] Apache Allura up to 1.10.x Dropdown Selector Stored cross site scripting
8001| [136374] Apache HTTP Server up to 2.4.38 Slash Regular Expression unknown vulnerability
8002| [136373] Apache HTTP Server 2.4.34/2.4.35/2.4.36/2.4.37/2.4.38 HTTP2 Request Crash denial of service
8003| [136372] Apache HTTP Server up to 2.4.38 HTTP2 Request unknown vulnerability
8004| [136370] Apache Fineract up to 1.2.x sql injection
8005| [136369] Apache Fineract up to 1.2.x sql injection
8006| [135731] Apache Hadoop up to 2.8.4/2.9.1/3.1.0 yarn privilege escalation
8007| [135664] Apache Tomcat up to 7.0.93/8.5.39/9.0.0.17 SSI printenv Command cross site scripting
8008| [135663] Apache Camel up to 2.23.x JSON-lib Library XML Data XML External Entity
8009| [135661] Apache Roller up to 5.2.1/5.2.0 XML-RPC Interface XML File Server-Side Request Forgery
8010| [135402] Apache Zookeeper up to 3.4.13/3.5.0-alpha to 3.5.4-beta getACL() information disclosure
8011| [135270] Apache JSPWiki up to 2.11.0.M3 Plugin Link cross site scripting
8012| [135269] Apache JSPWiki up to 2.11.0.M3 InterWiki Link cross site scripting
8013| [135268] Apache JSPWiki up to 2.11.0.M3 Attachment cross site scripting
8014| [134527] Apache Karaf up to 4.2.4 Config Service directory traversal
8015| [134416] Apache Sanselan 0.97-incubator Loop denial of service
8016| [134415] Apache Sanselan 0.97-incubator Hang denial of service
8017| [134291] Apache Axis up to 1.7.8 Server-Side Request Forgery
8018| [134290] Apache UIMA DUCC up to 2.2.2 cross site scripting
8019| [134248] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
8020| [134247] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
8021| [134246] Apache Camel up to 2.19/2.21.3/2.22.2/2.23.0 directory traversal
8022| [134138] Apache Pluto 3.0.0/3.0.1 Chat Room Demo Portlet cross site scripting
8023| [133992] Apache Qpid Proton up to 0.27.0 Certificate Validation Man-in-the-Middle weak authentication
8024| [133977] Apache Zeppelin up to 0.7.x Stored cross site scripting
8025| [133976] Apache Zeppelin up to 0.7.x Cron Scheduler privilege escalation
8026| [133975] Apache Zeppelin up to 0.7.2 Session Fixation weak authentication
8027| [133444] Apache PDFbox 2.0.14 XML Parser XML External Entity
8028| [133573] Oracle FLEXCUBE Private Banking 2.0.0.0/2.2.0.1/12.0.1.0/12.0.3.0/12.1.0.0 Apache ActiveMQ unknown vulnerability
8029| [133407] Apache Tomcat up to 7.0.93/8.5.39/9.0.17 on Windows JRE Command Line Argument Code Execution
8030| [133315] Apache Airflow up to 1.10.2 HTTP Endpoint cross site request forgery
8031| [133314] Apache Airflow up to 1.10.2 Metadata Database cross site scripting
8032| [133290] Apache Tomcat up to 8.5.37/9.0.14 HTTP2 Stream Execution denial of service
8033| [133112] Apache HTTP Server up to 2.4.38 mod_auth_digest race condition privilege escalation
8034| [133111] Apache HTTP Server 2.4.37/2.4.38 mod_ssl Bypass privilege escalation
8035| [133092] Airsonic 10.2.1 org.apache.commons.lang.RandomStringUtils RecoverController.java java.util.Random weak authentication
8036| [132568] Apache JSPWiki up to 2.11.0.M2 URL User information disclosure
8037| [132567] Apache JSPWiki up to 2.11.0.M2 URL cross site scripting
8038| [132566] Apache ActiveMQ up to 5.15.8 MQTT Frame Memory denial of service
8039| [132565] Apache HBase up to 2.1.3 REST Server Request privilege escalation
8040| [132183] Apache Mesos up to pre-1.4.x Docker Image Code Execution
8041| [131988] Apache Karaf up to 4.2.2 kar Deployer directory traversal
8042| [131859] Apache Hadoop up to 2.9.1 privilege escalation
8043| [131479] Apache Solr up to 7.6 HTTP GET Request Server-Side Request Forgery
8044| [131446] Apache Solr up to 5.0.5/6.6.5 Config API HTTP POST Request Code Execution
8045| [131385] Apache Qpid Broker-J up to 6.x/7.0.6/7.1.0 AMQP Command Crash denial of service
8046| [131315] Apache Mesos up to pre-1.4.x Mesos Masters Rendering JSON Payload Recursion denial of service
8047| [131236] Apache Airflow up to 1.10.1 Metadata Database cross site scripting
8048| [130755] Apache JSPWiki up to 2.10.5 URL cross site scripting
8049| [130629] Apache Guacamole Cookie Flag weak encryption
8050| [130628] Apache Hadoop up to 3.0.0 HDFS information disclosure
8051| [130529] Apache Subversion 1.10.0/1.10.1/1.10.2/1.10.3/1.11.0 mod_dav_svn Directory Crash denial of service
8052| [130353] Apache Open Office up to 4.1.5 Document Loader String memory corruption
8053| [130341] Apache HTTP Server 2.4.37 mod_ssl Loop denial of service
8054| [130330] Apache HTTP Server up to 2.4.37 mod_session Expired privilege escalation
8055| [130329] Apache HTTP Server 2.4.37 mod_http2 Slowloris denial of service
8056| [130212] Apache Airflow up to 1.10.0 LDAP Auth Backend Certificate weak authentication
8057| [130123] Apache Airflow up to 1.8.2 information disclosure
8058| [130122] Apache Airflow up to 1.8.2 command injection cross site request forgery
8059| [130121] Apache Airflow up to 1.8.2 Webserver Object Code Execution
8060| [129717] Oracle Secure Global Desktop 5.4 Apache HTTP Server denial of service
8061| [129688] Oracle Tape Library ACSLS 8.4 Apache Log4j unknown vulnerability
8062| [129673] Oracle Retail Returns Management 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
8063| [129672] Oracle Retail Central Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
8064| [129671] Oracle Retail Back Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
8065| [129574] Oracle Outside In Technology 8.5.3/8.5.4 Apache Tomcat denial of service
8066| [129573] Oracle WebLogic Server 10.3.6.0 Apache HTTP Server denial of service
8067| [129563] Oracle Enterprise Repository 12.1.3.0.0 Apache Log4j unknown vulnerability
8068| [129555] Oracle Outside In Technology 8.5.3 Apache Batik denial of service
8069| [129551] Oracle Outside In Technology 8.5.3/8.5.4 Apache Commons FileUpload denial of service
8070| [129542] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
8071| [129538] Oracle SOA Suite 12.1.3.0.0/12.2.1.3.0 Apache Batik unknown vulnerability
8072| [129519] Oracle Enterprise Manager Ops Center 12.2.2/12.3.3 Apache ActiveMQ unknown vulnerability
8073| [129508] Oracle Applications Manager up to 12.2.8 Apache Derby unknown vulnerability
8074| [129507] Oracle Mobile Field Service up to 12.2.8 Apache Log4j unknown vulnerability
8075| [129505] Oracle Email Center up to 12.2.8 Apache Log4j unknown vulnerability
8076| [129504] Oracle CRM Technical Foundation up to 12.2.8 Apache Commons FileUpload unknown vulnerability
8077| [129499] Oracle Partner Management up to 12.2.8 Apache Log4j unknown vulnerability
8078| [129498] Oracle Marketing up to 12.2.8 Apache Commons FileUpload unknown vulnerability
8079| [129480] Oracle Communications WebRTC Session Controller up to 7.1 Apache Batik unknown vulnerability
8080| [129479] Oracle Communications Diameter Signaling Router up to 8.2 Apache Batik unknown vulnerability
8081| [129474] Oracle Communications Diameter Signaling Router up to 8.2 Apache HTTP Server information disclosure
8082| [129472] Oracle Communications WebRTC Session Controller up to 7.1 Apache Struts 1 unknown vulnerability
8083| [129470] Oracle Communications Converged Application Server up to 7.0.0.0 Apache Struts 1 unknown vulnerability
8084| [129463] Oracle Communications WebRTC Session Controller up to 7.1 Apache Log4j unknown vulnerability
8085| [129461] Oracle Communications Services Gatekeeper up to 6.1.0.3.x Apache Commons Collections Fileupload unknown vulnerability
8086| [129460] Oracle Communications Service Broker 6.0 Apache Log4j unknown vulnerability
8087| [129459] Oracle Communications Policy Management up to 12.4 Apache Struts 2 unknown vulnerability
8088| [129458] Oracle Communications Online Mediation Controller 6.1 Apache Log4j unknown vulnerability
8089| [129457] Oracle Communications Diameter Signaling Router up to 8.2 Apache Commons Fileupload unknown vulnerability
8090| [129456] Oracle Communications Converged Application Server 6.1 Apache Log4j unknown vulnerability
8091| [128714] Apache Thrift Java Client Library up to 0.11.0 SASL Negotiation org.apache.thrift.transport.TSaslTransport unknown vulnerability
8092| [128713] Apache Thrift Node.js Static Web Server up to 0.11.0 directory traversal
8093| [128709] Apache Karaf up to 4.1.6/4.2.1 Features Deployer XMLInputFactory XML External Entity
8094| [128575] Apache NetBeans 9.0 Proxy Auto-Config Code Execution
8095| [128369] Apache Tika 1.8-1.19.1 SQLite3Parser Loop sql injection
8096| [128111] Apache NiFi 1.8.0 Template Upload Man-in-the-Middle cross site request forgery
8097| [128110] Apache NiFi 1.8.0 Cluster Request privilege escalation
8098| [128109] Apache NiFi 1.8.0 Error Page message-page.jsp Request Header cross site scripting
8099| [128108] Apache NiFi up to 1.7.x X-Frame-Options Header privilege escalation
8100| [128102] Apache Oozie up to 5.0.0 Workflow XML Impersonation spoofing
8101| [127994] WordPress up to 5.0.0 on Apache httpd MIME Restriction cross site scripting
8102| [127981] Apache OFBiz 16.11.01/16.11.02/16.11.03/16.11.04 HTTP Engine httpService GET Request privilege escalation
8103| [127161] Apache Hadoop 2.7.4/2.7.5/2.7.6 Incomplete Fix CVE-2016-6811 privilege escalation
8104| [127040] Loadbalancer.org Enterprise VA MAX up to 8.3.2 Apache HTTP Server Log cross site scripting
8105| [127007] Apache Spark Request Code Execution
8106| [126791] Apache Hadoop up to 0.23.11/2.7.6/2.8.4/2.9.1/3.0.2 ZIP File unknown vulnerability
8107| [126767] Apache Qpid Proton-J Transport 0.3 Certificate Verification Man-in-the-Middle weak authentication
8108| [126896] Apache Commons FileUpload 1.3.3 on LDAP Manager DiskFileItem File privilege escalation
8109| [126574] Apache Hive up to 2.3.3/3.1.0 Query privilege escalation
8110| [126573] Apache Hive up to 2.3.3/3.1.0 HiveServer2 privilege escalation
8111| [126564] Apache Superset up to 0.22 Pickle Library load Code Execution
8112| [126488] Apache Syncope up to 2.0.10/2.1.1 BPMN Definition xxe privilege escalation
8113| [126487] Apache Syncope up to 2.0.10/2.1.1 cross site scripting
8114| [126346] Apache Tomcat Path privilege escalation
8115| [125922] Apache Impala up to 3.0.0 ALTER privilege escalation
8116| [125921] Apache Impala up to 3.0.0 Queue Injection privilege escalation
8117| [125647] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Install (Apache Tomcat) information disclosure
8118| [125617] Oracle Retail Returns Management 14.1 Apache Batik unknown vulnerability
8119| [125616] Oracle Retail Point-of-Service 13.4/14.0/14.1 Apache Batik unknown vulnerability
8120| [125614] Oracle Retail Central Office 14.1 Apache Batik unknown vulnerability
8121| [125613] Oracle Retail Back Office 13.3/13.4/14/14.1 Apache Batik unknown vulnerability
8122| [125599] Oracle Retail Open Commerce Platform 5.3.0/6.0.0/6.0.1 Apache Log4j unknown vulnerability
8123| [125569] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56 Apache HTTP Server information disclosure
8124| [125494] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat information disclosure
8125| [125447] Oracle Business Intelligence Enterprise Edition 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Batik unknown vulnerability
8126| [125428] Oracle Identity Management Suite 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
8127| [125427] Oracle Identity Analytics 11.1.1.5.8 Apache Log4j unknown vulnerability
8128| [125424] Oracle API Gateway 11.1.2.4.0 Apache Log4j unknown vulnerability
8129| [125423] Oracle BI Publisher 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Log4j unknown vulnerability
8130| [125383] Oracle up to 10.2.0 Apache Trinidad unknown vulnerability
8131| [125379] Oracle up to 10.1.x Apache Struts 1 cross site scripting
8132| [125377] Oracle up to 10.2.0 Apache Commons Collections unknown vulnerability
8133| [125376] Oracle Communications Application Session Controller up to 3.7.0 Apache Commons Collections unknown vulnerability
8134| [125375] Oracle Communications User Data Repository up to 12.1.x Apache Xerces memory corruption
8135| [125248] Apache ActiveMQ up to 5.15.5 Web-based Administration Console queue.jsp Parameter cross site scripting
8136| [125133] Apache Tika up to 1.19 XML Parser reset() denial of service
8137| [124877] Apache PDFbox up to 2.0.11 PDF File denial of service
8138| [124876] Apache Ranger up to 1.1.x UnixAuthenticationService Stack-based memory corruption
8139| [124791] Apache Tomcat up to 7.0.90/8.5.33/9.0.11 URL Open Redirect
8140| [124787] Apache Pony Mail 0.7/0.8/0.9 Statistics Generator Timestamp Data information disclosure
8141| [124447] Apache HTTP Server up to 2.4.34 SETTINGS Frame denial of service
8142| [124346] Apache Mesos pre-1.4.2/1.5.0/1.5.1/1.6.0 on Executor HTTP API String Comparison validation JSON Web Token information disclosure
8143| [124286] Apache Tika up to 1.18 IptcAnpaParser Loop denial of service
8144| [124242] Apache Tika up to 0.18 C:/evil.bat" Directory unknown vulnerability
8145| [124241] Apache Tika up to 0.18 XML Parser Entity Expansion denial of service
8146| [124191] Apache Karaf up to 3.0.8/4.0.8/4.1.0 WebConsole .../gogo/ weak authentication
8147| [124190] Apache Karaf up to 4.1.x sshd privilege escalation
8148| [124152] Apache Camel Mail up to 2.22.0 Path directory traversal
8149| [124143] Apache SpamAssassin up to 3.4.1 PDFInfo Plugin Code Execution
8150| [124134] Apache SpamAssassin up to 3.4.1 Scan Engine HTML::Parser Email denial of service
8151| [124095] PHP up to 5.6.37/7.0.31/7.1.21/7.2.9 Apache2 sapi_apache2.c php_handler cross site scripting
8152| [124024] Apache Mesos 1.4.x/1.5.0 libprocess JSON Payload denial of service
8153| [123814] Apache ActiveMQ Client up to 5.15.5 TLS Hostname Verification Man-in-the-Middle weak authentication
8154| [123393] Apache Traffic Server up to 6.2.2/7.1.3 ESI Plugin Config privilege escalation
8155| [123392] Apache Traffic Server 6.2.2 TLS Handshake Segmentation Fault denial of service
8156| [123391] Apache Traffic Server up to 6.2.2/7.1.3 Range Request Performance denial of service
8157| [123390] Apache Traffic Server up to 6.2.2/7.1.3 Request HTTP Smuggling privilege escalation
8158| [123369] Apache Traffic Server up to 6.2.2/7.1.3 ACL remap.config Request denial of service
8159| [123197] Apache Sentry up to 2.0.0 privilege escalation
8160| [123145] Apache Struts up to 2.3.34/2.5.16 Namespace Code Execution
8161| [123144] Apache Cayenne up to 4.1.M1 CayenneModeler XML File File Transfer privilege escalation
8162| [122981] Apache Commons Compress 1.7 ZipArchiveInputStream ZIP Archive denial of service
8163| [122889] Apache HTTP Server up to 2.2.31/2.4.23 mod_userdir HTTP Response Splitting privilege escalation
8164| [122800] Apache Spark 1.3.0 REST API weak authentication
8165| [122642] Apache Airflow up to 1.8.x 404 Page Reflected cross site scripting
8166| [122568] Apache Tomcat up to 8.5.31/9.0.9 Connection Reuse weak authentication
8167| [122567] Apache Axis 1.0./1.1/1.2/1.3/1.4 cross site scripting
8168| [122556] Apache Tomcat up to 7.0.86/8.0.51/8.5.30/9.0.7 UTF-8 Decoder Loop denial of service
8169| [122531] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.9 WebSocket Client unknown vulnerability
8170| [122456] Apache Camel up to 2.20.3/2.21.0 XSD Validator XML External Entity
8171| [122455] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Revoked Certificate weak authentication
8172| [122454] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Responder Revoked Certificate weak authentication
8173| [122214] Apache Kafka up to 0.9.0.1/0.10.2.1/0.11.0.2/1.0.0 Broker Request Data Loss denial of service
8174| [122202] Apache Kafka up to 0.10.2.1/0.11.0.1 SASL Impersonation spoofing
8175| [122101] Docker Skeleton Runtime for Apache OpenWhisk Docker Action dockerskeleton:1.3.0 privilege escalation
8176| [122100] PHP Runtime for Apache OpenWhisk Docker Action action-php-v7.2:1.0.0 privilege escalation
8177| [122012] Apache Ignite up to 2.5 Serialization privilege escalation
8178| [121911] Apache Ambari up to 2.5.x/2.6.2 Log Message Credentials information disclosure
8179| [121910] Apache HTTP Server 2.4.33 mod_md HTTP Requests denial of service
8180| [121854] Oracle Tape Library ACSLS up to ACSLS 8.4.0-2 Apache Commons Collections unknown vulnerability
8181| [121752] Oracle Insurance Policy Administration 10.0/10.1/10.2/11.0 Apache Log4j unknown vulnerability
8182| [121370] Apache Spark up to 2.1.2/2.2.1/2.3.0 URL cross site scripting
8183| [121354] Apache CouchDB HTTP API Code Execution
8184| [121144] Apache LDAP API up to 1.0.1 SSL Filter information disclosure
8185| [121143] Apache Storm up to 0.10.2/1.0.6/1.1.2/1.2.1 Cluster privilege escalation
8186| [120436] Apache CXF Fediz up to 1.4.3 Application Plugin unknown vulnerability
8187| [120310] Apache PDFbox up to 1.8.14/2.0.10 AFMParser Loop denial of service
8188| [120168] Apache CXF weak authentication
8189| [120080] Apache Cassandra up to 3.11.1 JMX/RMI Interface RMI Request privilege escalation
8190| [120043] Apache HBase up to 1.2.6.0/1.3.2.0/1.4.4/2.0.0 Thrift 1 API Server weak authentication
8191| [119723] Apache Qpid Broker-J 7.0.0/7.0.1/7.0.2/7.0.3/7.0.4 AMQP Messages Crash denial of service
8192| [122569] Apache HTTP Server up to 2.4.33 HTTP2 Request denial of service
8193| [119486] Apache Geode up to 1.4.0 Security Manager Code Execution
8194| [119306] Apache MXNet Network Interface privilege escalation
8195| [118999] Apache Storm up to 1.0.6/1.1.2/1.2.1 Archive directory traversal
8196| [118996] Apache Storm up to 1.0.6/1.1.2/1.2.1 Daemon spoofing
8197| [118644] Apple macOS up to 10.13.5 apache_mod_php unknown vulnerability
8198| [118200] Apache Batik up to 1.9 Deserialization unknown vulnerability
8199| [118143] Apache NiFi activemq-client Library Deserialization denial of service
8200| [118142] Apache NiFi 1.6.0 SplitXML xxe privilege escalation
8201| [118051] Apache Zookeeper up to 3.4.9/3.5.3-beta weak authentication
8202| [117997] Apache ORC up to 1.4.3 ORC File Recursion denial of service
8203| [117825] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.8 CORS Filter privilege escalation
8204| [117405] Apache Derby up to 10.14.1.0 Network Server Network Packet privilege escalation
8205| [117347] Apache Ambari up to 2.6.1 HTTP Request directory traversal
8206| [117265] LibreOffice/Apache Office Writer SMB Connection XML Document information disclosure
8207| [117143] Apache uimaj/uima-as/uimaFIT/uimaDUCC XML XXE information disclosure
8208| [117117] Apache Tika up to 1.17 ChmParser Loop denial of service
8209| [117116] Apache Tika up to 1.17 BPGParser Loop denial of service
8210| [117115] Apache Tika up to 1.17 tika-server command injection
8211| [116929] Apache Fineract getReportType Parameter privilege escalation
8212| [116928] Apache Fineract REST Endpoint Parameter privilege escalation
8213| [116927] Apache Fineract MakercheckersApiResource Parameter sql injection
8214| [116926] Apache Fineract REST Parameter privilege escalation
8215| [116574] Apache wicket-jquery-ui up to 6.29.0/7.10.1/8.0.0-M9.1 WYSIWYG Editor privilege escalation
8216| [116622] Oracle Enterprise Manager for MySQL Database 12.1.0.4 EM Plugin: General (Apache Tomcat) unknown vulnerability
8217| [115931] Apache Solr up to 6.6.2/7.2.1 XML Data Parameter XML External Entity
8218| [115883] Apache Hive up to 2.3.2 privilege escalation
8219| [115882] Apache Hive up to 2.3.2 xpath_short information disclosure
8220| [115881] Apache DriverHive JDBC Driver up to 2.3.2 Escape Argument Bypass privilege escalation
8221| [115518] Apache Ignite 2.3 Deserialization privilege escalation
8222| [115260] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache cross site scripting
8223| [115259] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache Cookie Stack-based memory corruption
8224| [115500] CA Workload Control Center up to r11.4 SP5 Apache MyFaces Component Code Execution
8225| [115121] Apache Struts REST Plugin up to 2.5.15 Xstream XML Data denial of service
8226| [115061] Apache HTTP Server up to 2.4.29 HTTP Digest Authentication Challenge HTTP Requests Replay privilege escalation
8227| [115060] Apache HTTP Server up to 2.4.29 mod_cache_socache Request Header Crash denial of service
8228| [115059] Apache HTTP Server up to 2.4.29 HTTP2 NULL Pointer Dereference denial of service
8229| [115058] Apache HTTP Server up to 2.4.29 HTTP Header Crash denial of service
8230| [115057] Apache HTTP Server up to 2.4.29 mod_session Variable Name Cache privilege escalation
8231| [115039] Apache HTTP Server up to 2.4.29 FilesMatch File Upload privilege escalation
8232| [115038] Apache HTTP Server up to 2.0.65/2.2.34/2.4.29 mod_authnz_ldap Crash denial of service
8233| [114817] Apache Syncope up to 1.2.10/2.0.7 Search Parameter information disclosure
8234| [114816] Apache Syncope up to 1.2.10/2.0.7 XSLT Code Execution
8235| [114717] Apache Commons 1.11/1.12/1.13/1.14/1.15 ZIP Archive ZipFile/ZipArchiveInputStream denial of service
8236| [114661] Apache Allura up to 1.8.0 HTTP Response Splitting privilege escalation
8237| [114400] Apache Tomcat JK ISAPI Connector up to 1.2.42 IIS/ISAPI privilege escalation
8238| [114258] Apache HTTP Server up to 2.4.22 mod_cluster Segmentation Fault denial of service
8239| [114086] Apache ODE 1.3.3 ODE Process Deployment Web Service directory traversal
8240| [113955] Apache Xerces-C up to 3.2.0 XML Parser NULL Pointer Dereference denial of service
8241| [113945] Apache Tomcat up to 7.0.84/8.0.49/8.5.27/9.0.4 URL Pattern Empty String privilege escalation
8242| [113944] Apache OpenMeetings up to 3.x/4.0.1 CRUD Operation denial of service
8243| [113905] Apache Traffic Server up to 5.2.x/5.3.2/6.2.0/7.0.0 TLS Handshake Core Dump denial of service
8244| [113904] Apache Traffic Server up to 6.2.0 Host Header privilege escalation
8245| [113895] Apache Geode up to 1.3.x Code Execution
8246| [113894] Apache Geode up to 1.3.x TcpServer Code Execution
8247| [113888] Apache James Hupa WebMail 0.0.2 cross site scripting
8248| [113813] Apache Geode Cluster up to 1.3.x Secure Mode privilege escalation
8249| [113747] Apache Tomcat Servlets privilege escalation
8250| [113647] Apache Qpid up to 0.30 qpidd Broker AMQP Message Crash denial of service
8251| [113645] Apache VCL up to 2.1/2.2.1/2.3.1 Web GUI/XMLRPC API privilege escalation
8252| [113560] Apache jUDDI Console 3.0.0 Log Entries spoofing
8253| [113571] Apache Oozie up to 4.3.0/5.0.0-beta1 XML Data XML File privilege escalation
8254| [113569] Apache Karaf up to 4.0.7 LDAPLoginModule LDAP injection denial of service
8255| [113273] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
8256| [113198] Apache Qpid Dispatch Router 0.7.0/0.8.0 AMQP denial of service
8257| [113186] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
8258| [113145] Apache Thrift up to 0.9.3 Go Client Library privilege escalation
8259| [113106] Apache jUDDI up to 3.3.3 XML Data WADL2Java/WSDL2Java XML Document privilege escalation
8260| [113105] Apache Qpid Broker-J 7.0.0 AMQP Crash denial of service
8261| [112885] Apache Allura up to 1.8.0 File information disclosure
8262| [112856] Apache CloudStack up to 4.8.1.0/4.9.0.0 API weak authentication
8263| [112855] Apache CloudStack 4.1.0/4.1.1 API information disclosure
8264| [112678] Apache Tomcat up to 7.0.82/8.0.47/8.5.23/9.0.1 Bug Fix 61201 privilege escalation
8265| [112677] Apache Tomcat Native Connector up to 1.1.34/1.2.14 OCSP Checker Client weak authentication
8266| [112625] Apache POI up to 3.16 Loop denial of service
8267| [112448] Apache NiFi up to 1.3.x Deserialization privilege escalation
8268| [112396] Apache Hadoop 2.7.3/2.7.4 YARN NodeManager Credentials information disclosure
8269| [112339] Apache NiFi 1.5.0 Header privilege escalation
8270| [112330] Apache NiFi 1.5.0 Header HTTP Request privilege escalation
8271| [112314] NetGain Enterprise Manager 7.2.730 Build 1034 org.apache.jsp.u.jsp.tools.exec_jsp Servlet Parameter privilege escalation
8272| [112253] Apache Hadoop up to 0.23.x/2.7.4/2.8.2 MapReduce Job History Server Configuration File privilege escalation
8273| [112171] Oracle Secure Global Desktop 5.3 Apache Log4j privilege escalation
8274| [112164] Oracle Agile PLM 9.3.5/9.3.6 Apache Tomcat unknown vulnerability
8275| [112161] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Tomcat privilege escalation
8276| [112158] Oracle Autovue for Agile Product Lifecycle Management 21.0.0/21.0.1 Apache Log4j privilege escalation
8277| [112156] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Log4j privilege escalation
8278| [112155] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Apache Log4j privilege escalation
8279| [112137] Oracle MICROS Relate CRM Software 10.8.x/11.4.x/15.0.x, Apache Tomcat unknown vulnerability
8280| [112136] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat privilege escalation
8281| [112133] Oracle Retail Workforce Management 1.60.7/1.64.0 Apache Log4j privilege escalation
8282| [112129] Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 Apache Log4j privilege escalation
8283| [112114] Oracle 9.1 Apache Log4j privilege escalation
8284| [112113] Oracle 9.1 Apache Log4j privilege escalation
8285| [112045] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat privilege escalation
8286| [112038] Oracle Health Sciences Empirica Inspections 1.0.1.1 Apache Tomcat information disclosure
8287| [112019] Oracle Endeca Information Discovery Integrator 3.1.0/3.2.0 Apache Tomcat privilege escalation
8288| [112017] Oracle WebCenter Portal 11.1.1.9.0/12.2.1.2.0/12.2.1.3.0 Apache Struts 1 cross site scripting
8289| [112011] Oracle Identity Manager 11.1.2.3.0 Apache Commons Collections privilege escalation
8290| [111950] Oracle Database 12.2.0.1 Apache Tomcat information disclosure
8291| [111703] Apache Sling XSS Protection API 1.0.4 URL Encoding cross site scripting
8292| [111556] Apache Geode up to 1.2.x Secure Mode Parameter OQL privilege escalation
8293| [111555] Apache Geode up to 1.2.x Secure Mode OQL privilege escalation
8294| [111540] Apache Geode up to 1.2.x Secure Mode information disclosure
8295| [111519] Apache Sling JCR ContentLoader 2.1.4 xmlreader directory traversal
8296| [111338] Apache DeltaSpike-JSF 1.8.0 cross site scripting
8297| [111330] Apache OFBiz 16.11.01/16.11.02/16.11.03 BIRT Plugin cross site scripting
8298| [110789] Apache Sling up to 1.4.0 Authentication Service Credentials information disclosure
8299| [110785] Apache Drill up to 1.11.0 Query Page unknown vulnerability
8300| [110701] Apache Fineract Query Parameter sql injection
8301| [110484] Apache Synapse up to 3.0.0 Apache Commons Collections Serialized Object Code Injection privilege escalation
8302| [110426] Adobe Experience Manager 6.0/6.1/6.2/6.3 Apache Sling Servlets Post cross site scripting
8303| [110141] Apache Struts up to 2.5.14 REST Plugin denial of service
8304| [110140] Apache Qpid Broker-J up to 0.32 privilege escalation
8305| [110139] Apache Qpid Broker-J up to 6.1.4 AMQP Frame denial of service
8306| [110106] Apache CXF Fediz Spring cross site request forgery
8307| [109766] Apache OpenOffice up to 4.1.3 DOC File Parser WW8Fonts memory corruption
8308| [109750] Apache OpenOffice up to 4.1.3 DOC File Parser ImportOldFormatStyles memory corruption
8309| [109749] Apache OpenOffice up to 4.1.3 PPT File Parser PPTStyleSheet memory corruption
8310| [109606] October CMS Build 412 Apache Configuration File Upload privilege escalation
8311| [109419] Apache Camel up to 2.19.3/2.20.0 camel-castor Java Object Deserialization privilege escalation
8312| [109418] Apache Camel up to 2.19.3/2.20.0 camel-hessian Java Object Deserialization privilege escalation
8313| [109400] Apache CouchDB up to 1.6.x/2.1.0 Database Server Shell privilege escalation
8314| [109399] Apache CouchDB up to 1.6.x/2.1.0 JSON Parser Shell privilege escalation
8315| [109398] Apache CXF 3.1.14/3.2.1 JAX-WS/JAX-RS Attachment denial of service
8316| [108872] Apache Hive up to 2.1.1/2.2.0/2.3.0 Policy Enforcement privilege escalation
8317| [108939] Apple macOS up to 10.13.1 apache unknown vulnerability
8318| [108938] Apple macOS up to 10.13.1 apache denial of service
8319| [108937] Apple macOS up to 10.13.1 apache unknown vulnerability
8320| [108936] Apple macOS up to 10.13.1 apache unknown vulnerability
8321| [108935] Apple macOS up to 10.13.1 apache denial of service
8322| [108934] Apple macOS up to 10.13.1 apache unknown vulnerability
8323| [108933] Apple macOS up to 10.13.1 apache unknown vulnerability
8324| [108932] Apple macOS up to 10.13.1 apache unknown vulnerability
8325| [108931] Apple macOS up to 10.13.1 apache denial of service
8326| [108930] Apple macOS up to 10.13.1 apache unknown vulnerability
8327| [108929] Apple macOS up to 10.13.1 apache denial of service
8328| [108928] Apple macOS up to 10.13.1 apache unknown vulnerability
8329| [108797] Apache Struts up to 2.3.19 TextParseUtiltranslateVariables OGNL Expression privilege escalation
8330| [108795] Apache Traffic Server up to 5.3.0 HTTP2 set_dynamic_table_size memory corruption
8331| [108794] Apache WSS4J up to 1.6.16/2.0.1 Incomplete Fix Leak information disclosure
8332| [108793] Apache Qpid up to 0.30 qpidd Crash denial of service
8333| [108792] Apache Traffic Server up to 5.1.0 Access Restriction privilege escalation
8334| [108791] Apache Wicket up to 1.5.11/6.16.x/7.0.0-M2 Session information disclosure
8335| [108790] Apache Storm 0.9.0.1 Log Viewer directory traversal
8336| [108789] Apache Cordova In-App-Browser Standalone Plugin up to 0.3.1 on iOS CDVInAppBrowser privilege escalation
8337| [108788] Apache Cordova File-Transfer Standalone Plugin up to 0.4.1 on iOS ios/CDVFileTransfer.m spoofing
8338| [108787] Apache HttpClient up to 4.3.0 HttpClientBuilder.java unknown vulnerability
8339| [108786] Apache Wicket up to 1.4.21/1.5.9/6.3.x script Tag cross site scripting
8340| [108783] Apache Hadoop up to 0.23.3/1.0.3/2.0.1 Kerberos Security Feature Key weak encryption
8341| [108782] Apache Xerces2 XML Service denial of service
8342| [108781] Apache jUDDI up to 1.x happyjuddi.jsp Parameter cross site scripting
8343| [108780] Apache jUDDI up to 1.x Log File uddiget.jsp spoofing
8344| [108709] Apache Cordova Android up to 3.7.1/4.0.1 intent URL privilege escalation
8345| [108708] Apache ActiveMQ up to 5.10.0 XML Data XML External Entity
8346| [108707] Apache ActiveMQ up to 1.7.0 XML Data XML External Entity
8347| [108629] Apache OFBiz up to 10.04.01 privilege escalation
8348| [108543] Apache Derby 10.1.2.1/10.2.2.0/10.3.1.4/10.4.1.3 Export File privilege escalation
8349| [108312] Apache HTTP Server on RHEL IP Address Filter privilege escalation
8350| [108297] Apache NiFi up to 0.7.1/1.1.1 Proxy Chain Username Deserialization privilege escalation
8351| [108296] Apache NiFi up to 0.7.1/1.1.1 Cluster Request privilege escalation
8352| [108250] Oracle Secure Global Desktop 5.3 Apache HTTP Server memory corruption
8353| [108245] Oracle Transportation Management up to 6.3.7 Apache Tomcat unknown vulnerability
8354| [108244] Oracle Transportation Management 6.4.1/6.4.2 Apache Commons FileUpload denial of service
8355| [108243] Oracle Agile Engineering Data Management 6.1.3/6.2.0 Apache Commons Collections memory corruption
8356| [108222] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Batik denial of service
8357| [108219] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat unknown vulnerability
8358| [108217] Oracle Retail Store Inventory Management 13.2.9/14.0.4/14.1.3/15.0.1/16.0.1 Apache Groovy unknown vulnerability
8359| [108216] Oracle Retail Convenience and Fuel POS Software 2.1.132 Apache Groovy unknown vulnerability
8360| [108169] Oracle MySQL Enterprise Monitor up to 3.2.8.2223/3.3.4.3247/3.4.2.4181 Apache Tomcat unknown vulnerability
8361| [108113] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Batik denial of service
8362| [108107] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat unknown vulnerability
8363| [108102] Oracle Healthcare Master Person Index 4.x Apache Groovy unknown vulnerability
8364| [108085] Oracle Identity Manager 11.1.2.3.0 Apache Struts 1 memory corruption
8365| [108083] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
8366| [108080] Oracle GlassFish Server 3.1.2 Apache Commons FileUpload denial of service
8367| [108066] Oracle Management Pack for GoldenGate 11.2.1.0.12 Apache Tomcat memory corruption
8368| [108062] Oracle BI Publisher 11.1.1.7.0/12.2.1.1.0/12.2.1.2.0 Apache ActiveMQ memory corruption
8369| [108060] Oracle Enterprise Manager Ops Center 12.2.2/12.3.2 Apache Groovy unknown vulnerability
8370| [108033] Oracle Primavera Unifier 9.13/9.14/10.x/15.x/16.x, Apache Groovy unknown vulnerability
8371| [108013] Oracle Communications WebRTC Session Controller 7.0/7.1/7.2 Apache Groovy unknown vulnerability
8372| [108011] Oracle Communications Services Gatekeeper 5.1/6.0 Apache Trinidad unknown vulnerability
8373| [107904] Apache Struts up to 2.3.28 Double OGNL Evaluation privilege escalation
8374| [107860] Apache Solr up to 7.0 Apache Lucene RunExecutableListener XML External Entity
8375| [107834] Apache Ranger up to 0.6.1 Change Password privilege escalation
8376| [107639] Apache NiFi 1.4.0 XML External Entity
8377| [107606] Apache ZooKeper up to 3.4.9/3.5.2 Command CPU Exhaustion denial of service
8378| [107597] Apache Roller up to 5.0.2 XML-RPC Protocol Support XML External Entity
8379| [107429] Apache Impala up to 2.9.x Kudu Table privilege escalation
8380| [107411] Apache Tomcat up to 7.0.81/8.0.46/8.5.22/9.0.0 JSP File File Upload privilege escalation
8381| [107385] Apache Geode up to 1.2.0 Secure Mode privilege escalation
8382| [107339] Apache OpenNLP up to 1.5.3/1.6.0/1.7.2/1.8.1 XML Data XML External Entity
8383| [107333] Apache Wicket up to 8.0.0-M1 CSRF Prevention HTTP Header privilege escalation
8384| [107323] Apache Wicket 1.5.10/6.13.0 Class Request information disclosure
8385| [107310] Apache Geode up to 1.2.0 Command Line Utility Query privilege escalation
8386| [107276] ArcSight ESM/ArcSight ESM Express up to 6.9.1c Patch 3/6.11.0 Apache Tomcat Version information disclosure
8387| [107266] Apache Tika up to 1.12 XML Parser XML External Entity
8388| [107262] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
8389| [107258] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
8390| [107197] Apache Xerces Jelly Parser XML File XML External Entity
8391| [107193] ZTE NR8950 Apache Commons Collections RMI Request Deserialization privilege escalation
8392| [107084] Apache Struts up to 2.3.19 cross site scripting
8393| [106877] Apache Struts up to 2.0.33/2.5.10 Freemarker Tag privilege escalation
8394| [106875] Apache Struts up to 2.5.5 URL Validator denial of service
8395| [106874] Apache Struts up to 2.3.30 Convention Plugin directory traversal
8396| [106847] Apache Tomcat up to 7.0.80 VirtualDirContext Source information disclosure
8397| [106846] Apache Tomcat up to 7.0.79 on Windows HTTP PUT Method Parameter File Upload privilege escalation
8398| [106777] Apache HTTP Server up to 2.2.34/2.4.27 Limit Directive ap_limit_section HTTP Request information disclosure
8399| [106739] puppetlabs-apache up to 1.11.0/2.0.x weak authentication
8400| [106720] Apache Wicket up to 1.5.12/6.18.x/7.0.0-M4 CryptoMapper privilege escalation
8401| [106586] Apache Brooklyn up to 0.9.x REST Server cross site scripting
8402| [106562] Apache Spark up to 2.1.1 Launcher API Deserialization privilege escalation
8403| [106559] Apache Brooklyn up to 0.9.x SnakeYAML YAML Data Java privilege escalation
8404| [106558] Apache Brooklyn up to 0.9.x REST Server cross site request forgery
8405| [106556] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
8406| [106555] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
8407| [106171] Apache Directory LDAP API up to 1.0.0-M30 Timing unknown vulnerability
8408| [106167] Apache Struts up to 2.5.12 REST Plugin XML Data privilege escalation
8409| [106166] Apache Struts up to 2.3.33/2.5.12 REST Plugin denial of service
8410| [106165] Apache Struts up to 2.3.33/2.5.12 URLValidator Regex CPU Exhaustion denial of service
8411| [106115] Apache Hadoop up to 2.6.4/2.7.2 YARN NodeManager Password information disclosure
8412| [106012] Apache Solr up to 5.5.3/6.4.0 Replication directory traversal
8413| [105980] Apache Engine 16.11.01 Parameter Reflected unknown vulnerability
8414| [105962] Apache Atlas 0.6.0/0.7.0 Frame cross site scripting
8415| [105961] Apache Atlas 0.6.0/0.7.0 Stack Trace information disclosure
8416| [105960] Apache Atlas 0.6.0/0.7.0 Search Reflected cross site scripting
8417| [105959] Apache Atlas 0.6.0/0.7.0 edit Tag DOM cross site scripting
8418| [105958] Apache Atlas 0.6.0/0.7.0 edit Tag Stored cross site scripting
8419| [105957] Apache Atlas 0.6.0/0.7.0 Cookie privilege escalation
8420| [105905] Apache Atlas 0.6.0/0.7.0/0.7.1 /js privilege escalation
8421| [105878] Apache Struts up to 2.3.24.0 privilege escalation
8422| [105682] Apache2Triad 1.5.4 phpsftpd/users.php Parameter cross site scripting
8423| [105681] Apache2Triad 1.5.4 phpsftpd/users.php Request cross site request forgery
8424| [105680] Apache2Triad 1.5.4 Parameter Session Fixation weak authentication
8425| [105643] Apache Pony Mail up to 0.8b weak authentication
8426| [105288] Apache Sling up to 2.3.21 Sling.evalString() String cross site scripting
8427| [105219] Apache Tomcat up to 8.5.15/9.0.0.M21 HTTP2 Bypass directory traversal
8428| [105218] Apache Tomcat up to 7.0.78/8.0.44/8.5.15/9.0.0.M21 CORS Filter Cache Poisoning privilege escalation
8429| [105215] Apache CXF up to 3.0.12/3.1.9 OAuth2 Hawk/JOSE MAC Validation Timing unknown vulnerability
8430| [105206] Apache CXF up to 3.0.11/3.1.8 JAX-RS Module XML External Entity
8431| [105205] Apache CXF up to 3.0.11/3.1.8 HTTP Transport Module Parameter cross site scripting
8432| [105202] Apache Storm 1.0.0/1.0.1/1.0.2/1.0.3/1.1.0 Worker privilege escalation
8433| [104987] Apache Xerces-C++ XML Service CPU Exhaustion denial of service
8434| [104986] Apache CXF 2.4.5/2.5.1 WS-SP UsernameToken Policy SOAP Request weak authentication
8435| [104985] Apache MyFaces Core up to 2.1.4 EL Expression Parameter Injection information disclosure
8436| [104983] Apache Wink up to 1.1.1 XML Document xxe privilege escalation
8437| [104981] Apache Commons Email 1.0/1.1/1.2/1.3/1.4 Subject Linebreak SMTP privilege escalation
8438| [104591] MEDHOST Document Management System Apache Solr Default Credentials weak authentication
8439| [104062] Oracle MySQL Enterprise Monitor up to 3.3.3.1199 Apache Tomcat unknown vulnerability
8440| [104061] Oracle MySQL Enterprise Monitor up to 3.2.7.1204/3.3.3.1199 Apache Tomcat unknown vulnerability
8441| [104060] Oracle MySQL Enterprise Monitor up to 3.1.5.7958/3.2.5.1141/3.3.2.1162 Apache Struts 2 unknown vulnerability
8442| [103995] Oracle 8.3/8.4/15.1/15.2 Apache Trinidad unknown vulnerability
8443| [103993] Oracle Policy Automation up to 12.2.3 Apache Commons FileUplaod denial of service
8444| [103916] Oracle Banking Platform 2.3/2.4/2.4.1/2.5 Apache Commons FileUpload denial of service
8445| [103906] Oracle Communications BRM 11.2.0.0.0 Apache Commons Collections privilege escalation
8446| [103904] Oracle Communications BRM 11.2.0.0.0/11.3.0.0.0 Apache Groovy memory corruption
8447| [103866] Oracle Transportation Management 6.1/6.2 Apache Webserver unknown vulnerability
8448| [103816] Oracle BI Publisher 11.1.1.9.0/12.2.1.1.0/12.2.1.2.0 Apache Commons Fileupload denial of service
8449| [103797] Oracle Tuxedo System and Applications Monitor Apache Commons Collections privilege escalation
8450| [103792] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Commons Fileupload privilege escalation
8451| [103791] Oracle Endeca Server 7.6.0.0/7.6.1.0 Apache Commons Collections privilege escalation
8452| [103788] Oracle Enterprise Repository 11.1.1.7.0/12.1.3.0.0 Apache ActiveMQ memory corruption
8453| [103787] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Groovy memory corruption
8454| [103763] Apache Sling up to 1.0.11 XSS Protection API XSS.getValidXML() Application XML External Entity
8455| [103762] Apache Sling up to 1.0.12 XSS Protection API XSSAPI.encodeForJSString() Script Tag cross site scripting
8456| [103693] Apache OpenMeetings 1.0.0 HTTP Method privilege escalation
8457| [103692] Apache OpenMeetings 1.0.0 Tomcat Error information disclosure
8458| [103691] Apache OpenMeetings 3.2.0 Parameter privilege escalation
8459| [103690] Apache OpenMeetings 1.0.0 sql injection
8460| [103689] Apache OpenMeetings 1.0.0 crossdomain.xml privilege escalation
8461| [103688] Apache OpenMeetings 1.0.0 weak encryption
8462| [103687] Apache OpenMeetings 1.0.0 cross site request forgery
8463| [103556] Apache Roller 5.1.0/5.1.1 Weblog Page Template VTL privilege escalation
8464| [103554] Apache OpenMeetings 1.0.0 Password Update unknown vulnerability
8465| [103553] Apache OpenMeetings 1.0.0 File Upload privilege escalation
8466| [103552] Apache OpenMeetings 3.2.0 Chat cross site scripting
8467| [103551] Apache OpenMeetings 3.1.0 XML unknown vulnerability
8468| [103521] Apache HTTP Server 2.4.26 HTTP2 Free memory corruption
8469| [103520] Apache HTTP Server up to 2.2.33/2.4.26 mod_auth_digest Authorization Header memory corruption
8470| [103519] Apache Struts up to 2.5.11/2.3.32 Spring AOP denial of service
8471| [103518] Apache Struts up to 2.5.11 URLValidator directory traversal
8472| [103492] Apache Spark up to 2.1.x Web UI Reflected cross site scripting
8473| [103401] Apache Struts 2.3.x Struts 1 Plugin ActionMessage privilege escalation
8474| [103399] Apache Traffic Control Traffic Router TCP Connection Slowloris denial of service
8475| [103387] Apache Impala up to 2.8.0 StatestoreSubscriber weak encryption
8476| [103386] Apache Impala up to 2.7.x/2.8.0 Kerberos weak authentication
8477| [103352] Apache Solr Node weak authentication
8478| [102897] Apache Ignite up to 2.0 Update Notifier information disclosure
8479| [102878] Code42 CrashPlan 5.4.x RMI Server org.apache.commons.ssl.rmi.DateRMI privilege escalation
8480| [102698] Apache HTTP Server up to 2.2.32/2.4.25 mod_mime Content-Type memory corruption
8481| [102697] Apache HTTP Server 2.2.24/2.2.32 HTTP Strict Parsing ap_find_token Request Header memory corruption
8482| [102690] Apache HTTP Server up to 2.2.32/2.4.25 mod_ssl ap_hook_process_connection() denial of service
8483| [102689] Apache HTTP Server up to 2.2.32/2.4.25 ap_get_basic_auth_pw weak authentication
8484| [102622] Apache Thrift up to 0.9.2 Client Libraries skip denial of service
8485| [102538] Apache Ranger up to 0.7.0 Authorizer unknown vulnerability
8486| [102537] Apache Ranger up to 0.7.0 Wildcard Character unknown vulnerability
8487| [102536] Apache Ranger up to 0.6 Stored cross site scripting
8488| [102535] Apache Ranger up to 0.6.2 Policy Engine unknown vulnerability
8489| [102255] Apache NiFi up to 0.7.3/1.2.x Response Header privilege escalation
8490| [102254] Apache NiFi up to 0.7.3/1.2.x UI cross site scripting
8491| [102070] Apache CXF Fediz up to 1.1.2/1.2.0 Application Plugin denial of service
8492| [102020] Apache Tomcat up to 9.0.0.M1 Java Servlet HTTP Method unknown vulnerability
8493| [101858] Apache Hive up to 1.2.1/2.0.0 Client weak authentication
8494| [101802] Apache KNOX up to 0.11.0 WebHDFS privilege escalation
8495| [101928] HPE Aruba ClearPass Apache Tomcat information disclosure
8496| [101524] Apache Archiva up to 1.x/2.2.1 REST Endpoint cross site request forgery
8497| [101513] Apache jUDDI 3.1./3.1.2/3.1.3/3.1.4 Logout Open Redirect
8498| [101430] Apache CXF Fediz up to 1.3.1 OIDC Service cross site request forgery
8499| [101429] Apache CXF Fediz up to 1.2.3/1.3.1 Plugins cross site request forgery
8500| [100619] Apache Hadoop up to 2.6.x HDFS Servlet unknown vulnerability
8501| [100618] Apache Hadoop up to 2.7.0 HDFS Web UI cross site scripting
8502| [100621] Adobe ColdFusion 10/11/2016 Apache BlazeDS Library Deserialization privilege escalation
8503| [100205] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Apache Commons FileUpload denial of service
8504| [100191] Oracle Secure Global Desktop 4.71/5.2/5.3 Web Server (Apache HTTP Server) information disclosure
8505| [100162] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Commons Collections privilege escalation
8506| [100160] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Trinidad unknown vulnerability
8507| [99969] Oracle WebCenter Sites 11.1.1.8.0 Apache Tomcat memory corruption
8508| [99937] Apache Batik up to 1.8 privilege escalation
8509| [99936] Apache FOP up to 2.1 privilege escalation
8510| [99935] Apache CXF up to 3.0.12/3.1.10 STSClient Cache information disclosure
8511| [99934] Apache CXF up to 3.0.12/3.1.10 JAX-RS XML Security Streaming Client spoofing
8512| [99930] Apache Traffic Server up to 6.2.0 denial of service
8513| [99929] Apache Log4j up to 2.8.1 Socket Server Deserialization privilege escalation
8514| [99925] Apache Traffic Server 6.0.0/6.1.0/6.2.0 HPACK Bomb denial of service
8515| [99738] Ping Identity OpenID Connect Authentication Module up to 2.13 on Apache Mod_auth_openidc.c spoofing
8516| [117569] Apache Hadoop up to 2.7.3 privilege escalation
8517| [99591] Apache TomEE up to 1.7.3/7.0.0-M2 EjbObjectInputStream Serialized Object privilege escalation
8518| [99370] Apache Ignite up to 1.8 update-notifier Document XML External Entity
8519| [99299] Apache Geode up to 1.1.0 Pulse OQL Query privilege escalation
8520| [99572] Apache Tomcat up to 7.0.75/8.0.41/8.5.11/9.0.0.M17 Application Listener privilege escalation
8521| [99570] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP Connector Cache information disclosure
8522| [99569] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP/2 GOAWAY Frame Resource Exhaustion denial of service
8523| [99568] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 Pipelined Request information disclosure
8524| [99048] Apache Ambari up to 2.3.x REST API Shell Metacharacter privilege escalation
8525| [99014] Apache Camel Jackson/JacksonXML privilege escalation
8526| [98610] Apple macOS up to 10.12.3 apache_mod_php memory corruption
8527| [98609] Apple macOS up to 10.12.3 apache_mod_php denial of service
8528| [98608] Apple macOS up to 10.12.3 apache_mod_php memory corruption
8529| [98607] Apple macOS up to 10.12.3 apache_mod_php denial of service
8530| [98606] Apple macOS up to 10.12.3 apache_mod_php denial of service
8531| [98605] Apple macOS up to 10.12.3 Apache denial of service
8532| [98604] Apple macOS up to 10.12.3 Apache denial of service
8533| [98603] Apple macOS up to 10.12.3 Apache denial of service
8534| [98602] Apple macOS up to 10.12.3 Apache denial of service
8535| [98601] Apple macOS up to 10.12.3 Apache denial of service
8536| [98517] Apache POI up to 3.14 OOXML File XXE denial of service
8537| [98405] Apache Hadoop up to 0.23.10 privilege escalation
8538| [98199] Apache Camel Validation XML External Entity
8539| [97892] Apache Tomcat up to 9.0.0.M15 Reverse-Proxy Http11InputBuffer.java information disclosure
8540| [97617] Apache Camel camel-snakeyaml Deserialization privilege escalation
8541| [97602] Apache Camel camel-jackson/camel-jacksonxml CamelJacksonUnmarshalType privilege escalation
8542| [97732] Apache Struts up to 2.3.31/2.5.10 Jakarta Multipart Parser Content-Type privilege escalation
8543| [97466] mod_auth_openidc up to 2.1.5 on Apache weak authentication
8544| [97455] mod_auth_openidc up to 2.1.4 on Apache weak authentication
8545| [97081] Apache Tomcat HTTPS Request denial of service
8546| [97162] EMC OpenText Documentum D2 BeanShell/Apache Commons privilege escalation
8547| [96949] Hanwha Techwin Smart Security Manager up to 1.5 Redis/Apache Felix Gogo privilege escalation
8548| [96314] Apache Cordova up to 6.1.1 on Android weak authentication
8549| [95945] Apple macOS up to 10.12.2 apache_mod_php denial of service
8550| [95944] Apple macOS up to 10.12.2 apache_mod_php denial of service
8551| [95943] Apple macOS up to 10.12.2 apache_mod_php memory corruption
8552| [95666] Oracle FLEXCUBE Direct Banking 12.0.0/12.0.1/12.0.2/12.0.3 Apache Commons Collections privilege escalation
8553| [95455] Apache NiFi up to 1.0.0/1.1.0 Connection Details Dialogue cross site scripting
8554| [95311] Apache Storm UI Daemon privilege escalation
8555| [95291] ZoneMinder 1.30.0 Apache httpd privilege escalation
8556| [94800] Apache Wicket up to 1.5.16/6.24.x Deserialize DiskFileItem denial of service
8557| [94705] Apache Qpid Broker for Java up to 6.1.0 SCRAM-SHA-1/SCRAM-SHA-256 User information disclosure
8558| [94627] Apache HTTP Server up to 2.4.24 mod_auth_digest Crash denial of service
8559| [94626] Apache HTTP Server up to 2.4.24 mod_session_crypto Padding weak encryption
8560| [94625] Apache HTTP Server up to 2.4.24 Response Split privilege escalation
8561| [94540] Apache Tika 1.9 tika-server File information disclosure
8562| [94600] Apache ActiveMQ up to 5.14.1 Administration Console cross site scripting
8563| [94348] Apple macOS up to 10.12.1 apache_mod_php denial of service
8564| [94347] Apple macOS up to 10.12.1 apache_mod_php denial of service
8565| [94346] Apple macOS up to 10.12.1 apache_mod_php denial of service
8566| [94345] Apple macOS up to 10.12.1 apache_mod_php denial of service
8567| [94344] Apple macOS up to 10.12.1 apache_mod_php denial of service
8568| [94343] Apple macOS up to 10.12.1 apache_mod_php memory corruption
8569| [94342] Apple macOS up to 10.12.1 apache_mod_php memory corruption
8570| [94128] Apache Tomcat up to 9.0.0.M13 Error information disclosure
8571| [93958] Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c denial of service
8572| [93874] Apache Subversion up to 1.8.16/1.9.4 mod_dontdothat XXE denial of service
8573| [93855] Apache Hadoop up to 2.6.4/2.7.2 HDFS Service privilege escalation
8574| [93609] Apache OpenMeetings 3.1.0 RMI Registry privilege escalation
8575| [93555] Apache Tika 1.6-1.13 jmatio MATLAB File privilege escalation
8576| [93799] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
8577| [93798] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
8578| [93797] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 HTTP Split privilege escalation
8579| [93796] Apache Tomcat up to 8.5.6/9.0.0.M11 HTTP/2 Header Parser denial of service
8580| [93532] Apache Commons Collections Library Java privilege escalation
8581| [93210] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 ResourceLinkFactory privilege escalation
8582| [93209] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Realm Authentication User information disclosure
8583| [93208] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 System Property Replacement information disclosure
8584| [93207] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Utility Method privilege escalation
8585| [93206] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Configuration privilege escalation
8586| [93098] Apache Commons FileUpload privilege escalation
8587| [92987] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Commons Collection memory corruption
8588| [92986] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Tomcat memory corruption
8589| [92982] Oracle Insurance IStream 4.3.2 Apache Commons Collections memory corruption
8590| [92981] Oracle Financial Services Lending and Leasing 14.1.0/14.2.0 Apache Commons Collections memory corruption
8591| [92979] Oracle up to 8.0.3 Apache Commons Collections memory corruption
8592| [92977] Oracle FLEXCUBE Universal Banking up to 12.2.0 Apache Commons Collections memory corruption
8593| [92976] Oracle FLEXCUBE Universal Banking 12.87.1/12.87.2 Apache Commons Collections memory corruption
8594| [92975] Oracle FLEXCUBE Private Banking up to 12.1.0 Apache Commons Collections memory corruption
8595| [92974] Oracle FLEXCUBE Investor Servicing 12.0.1 Apache Commons Collections memory corruption
8596| [92973] Oracle 12.0.0/12.1.0 Apache Commons Collections memory corruption
8597| [92972] Oracle FLEXCUBE Core Banking 11.5.0.0.0/11.6.0.0.0 Apache Commons Collections memory corruption
8598| [92962] Oracle Agile PLM 9.3.4/9.3.5 Apache Commons Collections memory corruption
8599| [92909] Oracle Agile PLM 9.3.4/9.3.5 Apache Tomcat unknown vulnerability
8600| [92786] Oracle Banking Digital Experience 15.1 Apache Commons Collections information disclosure
8601| [92549] Apache Tomcat on Red Hat privilege escalation
8602| [92509] Apache Tomcat JK ISAPI Connector up to 1.2.41 jk_uri_worker_map.c memory corruption
8603| [92314] Apache MyFaces Trinidad up to 1.0.13/1.2.15/2.0.1/2.1.1 CoreResponseStateManager memory corruption
8604| [92313] Apache Struts2 up to 2.3.28/2.5.0 Action Name Cleanup cross site request forgery
8605| [92299] Apache Derby up to 10.12.1.0 SqlXmlUtil XML External Entity
8606| [92217] Apache ActiveMQ Artemis up to 1.3.x Broker/REST GetObject privilege escalation
8607| [92174] Apache Ranger up to 0.6.0 Policy cross site scripting
8608| [91831] Apache Jackrabbit up to 2.13.2 HTTP Header cross site request forgery
8609| [91825] Apache Zookeeper up to 3.4.8/3.5.2 C CLI Shell memory corruption
8610| [91818] Apache CXF Fediz up to 1.2.2/1.3.0 Application Plugin privilege escalation
8611| [92056] Apple macOS up to 10.11 apache_mod_php memory corruption
8612| [92055] Apple macOS up to 10.11 apache_mod_php memory corruption
8613| [92054] Apple macOS up to 10.11 apache_mod_php denial of service
8614| [92053] Apple macOS up to 10.11 apache_mod_php denial of service
8615| [92052] Apple macOS up to 10.11 apache_mod_php denial of service
8616| [92051] Apple macOS up to 10.11 apache_mod_php memory corruption
8617| [92050] Apple macOS up to 10.11 apache_mod_php denial of service
8618| [92049] Apple macOS up to 10.11 apache_mod_php memory corruption
8619| [92048] Apple macOS up to 10.11 apache_mod_php denial of service
8620| [92047] Apple macOS up to 10.11 apache_mod_php memory corruption
8621| [92046] Apple macOS up to 10.11 apache_mod_php memory corruption
8622| [92045] Apple macOS up to 10.11 apache_mod_php memory corruption
8623| [92044] Apple macOS up to 10.11 apache_mod_php memory corruption
8624| [92043] Apple macOS up to 10.11 apache_mod_php denial of service
8625| [92042] Apple macOS up to 10.11 apache_mod_php memory corruption
8626| [92041] Apple macOS up to 10.11 apache_mod_php memory corruption
8627| [92040] Apple macOS up to 10.11 Apache Proxy privilege escalation
8628| [91785] Apache Shiro up to 1.3.1 Servlet Filter privilege escalation
8629| [90879] Apache OpenMeetings up to 3.1.1 SWF Panel cross site scripting
8630| [90878] Apache Sentry up to 1.6.x Blacklist Filter reflect/reflect2/java_method privilege escalation
8631| [90610] Apache POI up to 3.13 XLSX2CSV Example OpenXML Document XML External Entity
8632| [90584] Apache ActiveMQ up to 5.11.3/5.12.2/5.13/1 Administration Web Console privilege escalation
8633| [90385] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site scripting
8634| [90384] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site request forgery
8635| [90383] Apache OpenOffice up to 4.1.2 Impress File memory corruption
8636| [89670] Apache Tomcat up to 8.5.4 CGI Servlet Environment Variable Open Redirect
8637| [89669] Apache HTTP Server up to 2.4.23 RFC 3875 Namespace Conflict Environment Variable Open Redirect
8638| [89726] Apple Mac OS X up to 10.11.5 apache_mod_php memory corruption
8639| [89484] Apache Qpid up to 0.13.0 on Windows Proton Library Certificate weak authentication
8640| [89473] HPE iMC PLAT/EAD/APM/iMC NTA/iMC BIMS/iMC UAM_TAM up to 7.2 Apache Commons Collections Library Command privilege escalation
8641| [90263] Apache Archiva Header denial of service
8642| [90262] Apache Archiva Deserialize privilege escalation
8643| [90261] Apache Archiva XML DTD Connection privilege escalation
8644| [88827] Apache Xerces-C++ up to 3.1.3 DTD Stack-Based memory corruption
8645| [88747] Apache HTTP Server 2.4.17/2.4.18 mod_http2 denial of service
8646| [88608] Apache Struts up to 2.3.28.1/2.5.0 URLValidator Null Value denial of service
8647| [88607] Apache Struts up to 2.3.28.1 REST Plugin Expression privilege escalation
8648| [88606] Apache Struts up to 2.3.28.1 Restriction privilege escalation
8649| [88605] Apache Struts up to 2.3.28.1 Restriction privilege escalation
8650| [88604] Apache Struts up to 2.3.28.1 Token Validator cross site request forgery
8651| [88603] Apache Commons FileUpload up to 1.3.1 MultipartStream denial of service
8652| [88602] Apache Struts up to 1.3.10 ActionServlet.java cross site scripting
8653| [88601] Apache Struts up to 1.3.10 Multithreading ActionServlet.java memory corruption
8654| [88600] Apache Struts up to 1.3.10 MultiPageValidator privilege escalation
8655| [89005] Apache Qpid AMQP JMS Client getObject privilege escalation
8656| [87888] Apache Ranger up to 0.5.2 Policy Admin Tool eventTime sql injection
8657| [87835] Apache CloudStack up to 4.5.2.0/4.6.2.0/4.7.1.0/4.8.0.0 SAML-based Authentication privilege escalation
8658| [87806] HPE Discovery and Dependency Mapping Inventory up to 9.32 update 3 Apache Commons Collections Library privilege escalation
8659| [87805] HPE Universal CMDB up to 10.21 Apache Commons Collections Library privilege escalation
8660| [87768] Apache Shiro up to 1.2.4 Cipher Key privilege escalation
8661| [87765] Apache James Server 2.3.2 Command privilege escalation
8662| [88667] Apache HTTP Server up to 2.4.20 mod_http2 Certificate weak authentication
8663| [87718] Apache Struts up to 2.3.24.1 OGNL Caching denial of service
8664| [87717] Apache Struts up to 2.3.28 REST Plugin privilege escalation
8665| [87706] Apache Qpid Java up to 6.0.2 AMQP privilege escalation
8666| [87703] Apache Qbid Java up to 6.0.2 PlainSaslServer.java denial of service
8667| [87702] Apache ActiveMQ up to 5.13.x Fileserver Web Application Upload privilege escalation
8668| [87700] Apache PDFbox up to 1.8.11/2.0.0 XML Parser PDF Document XML External Entity
8669| [87679] HP Release Control 9.13/9.20/9.21 Apache Commons Collections Library Java Object privilege escalation
8670| [87540] Apache Ambari up to 2.2.0 File Browser View information disclosure
8671| [87433] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
8672| [87432] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
8673| [87431] Apple Mac OS X up to 10.11.4 apache_mod_php Format String
8674| [87430] Apple Mac OS X up to 10.11.4 apache_mod_php denial of service
8675| [87429] Apple Mac OS X up to 10.11.4 apache_mod_php information disclosure
8676| [87428] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
8677| [87427] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
8678| [87389] Apache Xerces C++ up to 3.1.3 XML Document DTDScanner.cpp memory corruption
8679| [87172] Adobe ColdFusion 11 Update 7/2016/up to 10 Update 18 Apache Commons Collections Library privilege escalation
8680| [87121] Apache Cordova iOS up to 3.x Plugin privilege escalation
8681| [87120] Apache Cordova iOS up to 3.x URL Whitelist privilege escalation
8682| [83806] HPE Network Node Manager i up to 10.01 Apache Commons Collections Library privilege escalation
8683| [83077] Apache Subversion up to 1.8.15/1.9.3 mod_authz_svn mod_authz_svn.c denial of service
8684| [83076] Apache Subversion up to 1.8.15/1.9.3 svnserve svnserve/cyrus_auth.c privilege escalation
8685| [82790] Apache Struts 2.0.0/2.3.24/2.3.28 Dynamic Method privilege escalation
8686| [82789] Apache Struts 2.0.0/2.3.24/2.3.28 XSLTResult privilege escalation
8687| [82725] HPE P9000 Command View up to 7.x/8.4.0 Apache Commons Collections Library privilege escalation
8688| [82444] Apache Camel up to 2.14.x/2.15.4/2.16.0 HTTP Request privilege escalation
8689| [82389] Apache Subversion up to 1.7.x/1.8.14/1.9.2 mod_dav_svn util.c memory corruption
8690| [82280] Apache Struts up to 1.7 JRE URLDecoder cross site scripting
8691| [82260] Apache OFBiz up to 12.04.05/13.07.02 Java Object privilege escalation
8692| [82259] Apache Qpid Proton up to 0.12.0 proton.reactor.Connector weak encryption
8693| [82250] Apache Ranger up to 0.5.0 Admin UI weak authentication
8694| [82214] Apache Wicket up to 1.5.14/6.21.x/7.1.x Input Element cross site scripting
8695| [82213] Apache Wicket up to 1.5.14/6.21.x/7.1.x ModalWindow Title getWindowOpenJavaScript cross site scripting
8696| [82212] Apache Ranger up to 0.5.0 Policy Admin Tool privilege escalation
8697| [82211] Apache OFBiz up to 12.04.06/13.07.02 ModelFormField.java DisplayEntityField.getDescription cross site scripting
8698| [82082] Apache JetSpeed up to 2.3.0 User Manager Service privilege escalation
8699| [82081] Apache OpenMeetings up to 3.1.0 SOAP API information disclosure
8700| [82080] Apache OpenMeetings up to 3.1.0 Event cross site scripting
8701| [82078] Apache OpenMeetings up to 3.1.0 Import/Export System Backup ZIP Archive directory traversal
8702| [82077] Apache OpenMeetings up to 3.1.0 Password Reset sendHashByUser privilege escalation
8703| [82076] Apache Ranger up to 0.5.1 privilege escalation
8704| [82075] Apache JetSpeed up to 2.3.0 Portal cross site scripting
8705| [82074] Apache JetSpeed up to 2.3.0 cross site scripting
8706| [82073] Apache JetSpeed up to 2.3.0 User Manager Service sql injection
8707| [82072] Apache JetSpeed up to 2.3.0 Portal Site Manager ZIP Archive directory traversal
8708| [82058] Apache LDAP Studio/Directory Studio up to 2.0.0-M9 CSV Export privilege escalation
8709| [82053] Apache Ranger up to 0.4.x Policy Admin Tool privilege escalation
8710| [82052] Apache Ranger up to 0.4.x Policy Admin Tool HTTP Request cross site scripting
8711| [81696] Apache ActiveMQ up to 5.13.1 HTTP Header privilege escalation
8712| [81695] Apache Xerces-C up to 3.1.2 internal/XMLReader.cpp memory corruption
8713| [81622] HPE Asset Manager 9.40/9.41/9.50 Apache Commons Collections Library Java Object privilege escalation
8714| [81406] HPE Service Manager up to 9.35 P3/9.41 P1 Apache Commons Collections Library Command privilege escalation
8715| [81405] HPE Operations Orchestration up to 10.50 Apache Commons Collections Library Command privilege escalation
8716| [81427] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
8717| [81426] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
8718| [81372] Apache Struts up to 2.3.24.1 I18NInterceptor cross site scripting
8719| [81371] Apache Struts up to 2.3.24.1 Double OGNL Evaluation privilege escalation
8720| [81370] Apache Struts up to 2.3.24.1 Java URLDecoder cross site scripting
8721| [81084] Apache Tomcat 6.0/7.0/8.0/9.0 ServletContext directory traversal
8722| [81083] Apache Tomcat 7.0/8.0/9.0 Index Page cross site request forgery
8723| [81082] Apache Tomcat 7.0/8.0/9.0 ResourceLinkFactory.setGlobalContext privilege escalation
8724| [81081] Apache Tomcat 6.0/7.0/8.0/9.0 Error information disclosure
8725| [81080] Apache Tomcat 6.0/7.0/8.0/9.0 Session Persistence privilege escalation
8726| [81079] Apache Tomcat 6.0/7.0/8.0/9.0 StatusManagerServlet information disclosure
8727| [81078] Apache Tomcat 7.0/8.0/9.0 Session privilege escalation
8728| [80970] Apache Solr up to 5.3.0 Admin UI plugins.js cross site scripting
8729| [80969] Apache Solr up to 5.2 Schema schema-browser.js cross site scripting
8730| [80968] Apache Solr up to 5.0 analysis.js cross site scripting
8731| [80940] HP Continuous Delivery Automation 1.30 Apache Commons Collections Library privilege escalation
8732| [80823] Apache CloudStack up to 4.5.1 KVM Virtual Machine Migration privilege escalation
8733| [80822] Apache CloudStack up to 4.5.1 API Call information disclosure
8734| [80778] Apache Camel up to 2.15.4/2.16.0 camel-xstream privilege escalation
8735| [80750] HPE Operations Manager 8.x/9.0 on Windows Apache Commons Collections Library privilege escalation
8736| [80724] Apache Hive up to 1.2.1 Authorization Framework privilege escalation
8737| [80577] Oracle Secure Global Desktop 4.63/4.71/5.2 Apache HTTP Server denial of service
8738| [80165] Intel McAfee ePolicy Orchestrator up to 4.6.9/5.0.3/5.3.1 Apache Commons Collections Library privilege escalation
8739| [80116] Apache Subversion up to 1.9.2 svn Protocol libsvn_ra_svn/marshal.c read_string memory corruption
8740| [80115] Apache ActiveMQ up to 5.12.x Broker Service privilege escalation
8741| [80036] IBM Cognos Business Intelligence Apache Commons Collections Library InvokerTransformer privilege escalation
8742| [79873] VMware vCenter Operations/vRealize Orchestrator Apache Commons Collections Library Serialized Java Object privilege escalation
8743| [79840] Apache Cordova File Transfer Plugin up to 1.2.x on Android unknown vulnerability
8744| [79839] Apache TomEE Serialized Java Stream EjbObjectInputStream privilege escalation
8745| [79791] Cisco Products Apache Commons Collections Library privilege escalation
8746| [79539] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
8747| [79538] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
8748| [79294] Apache Cordova-Android up to 3.6 BridgeSecret Random Generator weak encryption
8749| [79291] Apache Cordova-Android up to 4.0 Javascript Whitelist privilege escalation
8750| [79244] Apache CXF up to 2.7.17/3.0.7/3.1.2 SAML Web SSO Module SAML Response weak authentication
8751| [79243] Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0 WLS Security com.bea.core.apache.commons.collections.jar privilege escalation
8752| [78989] Apache Ambari up to 2.1.1 Open Redirect
8753| [78988] Apache Ambari up to 2.0.1/2.1.0 Password privilege escalation
8754| [78987] Apache Ambari up to 2.0.x cross site scripting
8755| [78986] Apache Ambari up to 2.0.x Proxy Endpoint api/v1/proxy privilege escalation
8756| [78780] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
8757| [78779] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
8758| [78778] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
8759| [78777] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
8760| [78776] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
8761| [78775] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
8762| [78774] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
8763| [78297] Apache Commons Components HttpClient up to 4.3.5 HTTPS Timeout denial of service
8764| [77406] Apache Flex BlazeDS AMF Message XML External Entity
8765| [77429] Apache ActiveMQ up to 5.10.0 LDAPLoginModule privilege escalation
8766| [77399] Apache ActiveMQ up to 5.10.0 LDAPLoginModule weak authentication
8767| [77375] Apache Tapestry up to 5.3.5 Client-Side Object Storage privilege escalation
8768| [77331] Apache ActiveMQ up to 5.11.1 on Windows Fileserver Upload/Download directory traversal
8769| [77299] Apache Solr Real-Time Module up to 7.x-1.1 Index Content information disclosure
8770| [77247] Apache ActiveMQ up to 5.10 TransportConnection.java processControlCommand denial of service
8771| [77083] Apache Groovy up to 2.4.3 MethodClosure.java MethodClosure memory corruption
8772| [76953] Apache Subversion 1.7.0/1.8.0/1.8.10 svn_repos_trace_node_locations information disclosure
8773| [76952] Apache Subversion 1.7.0/1.8.0/1.8.10 mod_authz_svn anonymous/authenticated information disclosure
8774| [76567] Apache Struts 2.3.20 unknown vulnerability
8775| [76733] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 ap_some_auth_required unknown vulnerability
8776| [76732] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 Request apr_brigade_flatten privilege escalation
8777| [76731] Apache HTTP Server 2.4.12 ErrorDocument 400 Crash denial of service
8778| [75690] Apache Camel up to 2.13.3/2.14.1 XPathBuilder.java XML External Entity
8779| [75689] Apache Camel up to 2.13.3/2.14.1 XML Converter Setup XmlConverter.java SAXSource privilege escalation
8780| [75668] Apache Sling API/Sling Servlets Post up to 2.2.1 HtmlResponse cross site scripting
8781| [75601] Apache Jackrabbit up to 2.10.0 WebDAV Request XML External Entity
8782| [75420] Apache Tomcat up to 6.0.43/7.0.58/8.0.16 Security Manager privilege escalation
8783| [75145] Apache OpenOffice up to 4.1.1 HWP Filter Crash denial of service
8784| [75032] Apache Tomcat Connectors up to 1.2.40 mod_jk privilege escalation
8785| [75135] PHP 5.4/5.5 HTTP Request sapi_apache2.c apache2handler privilege escalation
8786| [74793] Apache Tomcat File Upload denial of service
8787| [74708] Apple MacOS X up to 10.10.2 Apache denial of service
8788| [74707] Apple MacOS X up to 10.10.2 Apache denial of service
8789| [74706] Apple MacOS X up to 10.10.2 Apache memory corruption
8790| [74705] Apple MacOS X up to 10.10.2 Apache denial of service
8791| [74704] Apple MacOS X up to 10.10.2 Apache denial of service
8792| [74703] Apple MacOS X up to 10.10.2 Apache denial of service
8793| [74702] Apple MacOS X up to 10.10.2 Apache denial of service
8794| [74701] Apple MacOS X up to 10.10.2 Apache cross site request forgery
8795| [74700] Apple MacOS X up to 10.10.2 Apache unknown vulnerability
8796| [74661] Apache Flex up to 4.14.0 asdoc index.html cross site scripting
8797| [74609] Apache Cassandra up to 1.2.19/2.0.13/2.1.3 JMX/RMI Interface privilege escalation
8798| [74469] Apache Xerces-C up to 7.0 internal/XMLReader.cpp denial of service
8799| [74468] Apache Batik up to 1.6 denial of service
8800| [74414] Apache Mod-gnutls up to 0.5.1 Authentication spoofing
8801| [74371] Apache Standard Taglibs up to 1.2.0 memory corruption
8802| [74367] Apache HTTP Server up to 2.4.12 mod_lua lua_request.c wsupgrade denial of service
8803| [74174] Apache WSS4J up to 2.0.0 privilege escalation
8804| [74172] Apache ActiveMQ up to 5.5.0 Administration Console cross site scripting
8805| [69092] Apache Tomcat up to 6.0.42/7.0.54/8.0.8 HTTP Request Smuggling privilege escalation
8806| [73831] Apache Qpid up to 0.30 Access Restriction unknown vulnerability
8807| [73731] Apache XML Security unknown vulnerability
8808| [68660] Oracle BI Publisher 10.1.3.4.2/11.1.1.7 Apache Tomcat cross site scripting
8809| [73659] Apache CloudStack up to 4.3.0 Stack-Based unknown vulnerability
8810| [73593] Apache Traffic Server up to 5.1.0 denial of service
8811| [73511] Apache POI up to 3.10 Deadlock denial of service
8812| [73510] Apache Solr up to 4.3.0 cross site scripting
8813| [68447] Apache Subversion up to 1.7.18/1.8.10 mod_dav_svn Crash denial of service
8814| [68446] Apache Subversion up to 1.7.18/1.8.10 REPORT Request Crash denial of service
8815| [73173] Apache CloudStack Stack-Based unknown vulnerability
8816| [68357] Apache Struts up to 2.3.16.3 Random Number Generator cross site request forgery
8817| [73106] Apache Hadoop up to 2.4.0 Symlink privilege escalation
8818| [68575] Apache HTTP Server up to 2.4.10 LuaAuthzProvider mod_lua.c privilege escalation
8819| [72890] Apache Qpid 0.30 unknown vulnerability
8820| [72887] Apache Hive 0.13.0 File Permission privilege escalation
8821| [72878] Apache Cordova 3.5.0 cross site request forgery
8822| [72877] Apache Cordova 3.5.0 cross site request forgery
8823| [72876] Apache Cordova 3.5.0 cross site request forgery
8824| [68435] Apache HTTP Server 2.4.10 mod_proxy_fcgi.c handle_headers denial of service
8825| [68065] Apache CXF up to 3.0.1 JAX-RS SAML denial of service
8826| [68064] Apache CXF up to 3.0.0 SAML Token denial of service
8827| [67913] Oracle Retail Markdown Optimization 12.0/13.0/13.1/13.2/13.4 Apache commons-beanutils-1.8.0.jar memory corruption
8828| [67912] Oracle Retail Invoice Matching up to 14.0 Apache commons-beanutils-1.8.0.jar memory corruption
8829| [67911] Oracle Retail Clearance Optimization Engine 13.3/13.4/14.0 Apache commons-beanutils-1.8.0.jar memory corruption
8830| [67910] Oracle Retail Allocation up to 13.2 Apache commons-beanutils-1.8.0.jar memory corruption
8831| [71835] Apache Shiro 1.0.0/1.1.0/1.2.0/1.2.1/1.2.2 unknown vulnerability
8832| [71633] Apachefriends XAMPP 1.8.1 cross site scripting
8833| [71629] Apache Axis2/C spoofing
8834| [67633] Apple Mac OS X up to 10.9.4 apache_mod_php ext/standard/dns.c dns_get_record memory corruption
8835| [67631] Apple Mac OS X up to 10.9.4 apache_mod_php Symlink memory corruption
8836| [67630] Apple Mac OS X up to 10.9.4 apache_mod_php cdf_read_property_info denial of service
8837| [67629] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_count_chain denial of service
8838| [67628] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_check_stream_offset denial of service
8839| [67627] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c mconvert memory corruption
8840| [67626] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c denial of service
8841| [67625] Apple Mac OS X up to 10.9.4 apache_mod_php Crash denial of service
8842| [67624] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_property_info denial of service
8843| [67623] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_unpack_summary_info denial of service
8844| [67622] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_short_sector denial of service
8845| [67620] Apple Mac OS X up to 10.9.4 apache_mod_php magic/Magdir/commands denial of service
8846| [67790] Apache HTTP Server mod_cache NULL Pointer Dereference denial of service
8847| [67522] Apache Tomcat up to 7.0.39 JSP Upload privilege escalation
8848| [70809] Apache POI up to 3.11 Crash denial of service
8849| [70808] Apache POI up to 3.10 unknown vulnerability
8850| [70806] Apache Commons-httpclient 4.2/4.2.1/4.2.2 spoofing
8851| [70749] Apache Axis up to 1.4 getCN spoofing
8852| [70701] Apache Traffic Server up to 3.3.5 denial of service
8853| [70700] Apache OFBiz up to 12.04.03 cross site scripting
8854| [67402] Apache OpenOffice 4.0.0/4.0.1/4.1.0 Calc privilege escalation
8855| [67401] Apache OpenOffice up to 4.1.0 OLE Object information disclosure
8856| [70661] Apache Subversion up to 1.6.17 denial of service
8857| [70660] Apache Subversion up to 1.6.17 spoofing
8858| [70659] Apache Subversion up to 1.6.17 spoofing
8859| [67183] Apache HTTP Server up to 2.4.9 mod_proxy denial of service
8860| [67180] Apache HTTP Server up to 2.4.9 WinNT MPM Memory Leak denial of service
8861| [67185] Apache HTTP Server up to 2.4.9 mod_status Heap-Based memory corruption
8862| [67184] Apache HTTP Server 2.4.5/2.4.6 mod_cache NULL Pointer Dereference denial of service
8863| [67182] Apache HTTP Server up to 2.4.9 mod_deflate Memory Consumption denial of service
8864| [67181] Apache HTTP Server up to 2.4.9 mod_cgid denial of service
8865| [70338] Apache Syncope up to 1.1.7 unknown vulnerability
8866| [70295] Apache CXF up to 2.7.9 Cleartext information disclosure
8867| [70106] Apache Open For Business Project up to 10.04.0 getServerError cross site scripting
8868| [70105] Apache MyFaces up to 2.1.5 JavaServer Faces directory traversal
8869| [69846] Apache HBase up to 0.94.8 information disclosure
8870| [69783] Apache CouchDB up to 1.2.0 memory corruption
8871| [13383] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 XML Parser privilege escalation
8872| [13300] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi setuid privilege escalation
8873| [13299] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi Content-Type Header information disclosure
8874| [13164] Apache CXF up to 2.6.13/2.7.10 SOAP OutgoingChainInterceptor.java Invalid Content denial of service
8875| [13163] Apache CXF up to 2.6.13/2.7.10 SOAP HTML Content denial of service
8876| [13158] Apache Struts up to 2.3.16.2 ParametersInterceptor getClass privilege escalation
8877| [69515] Apache Struts up to 2.3.15.0 CookieInterceptor memory corruption
8878| [13086] Apache Struts up to 1.3.10 Class Loader privilege escalation
8879| [13067] Apache Struts up to 2.3.16.1 Class Loader privilege escalation
8880| [69431] Apache Archiva up to 1.3.6 cross site scripting
8881| [69385] Apache Syncope up to 1.1.6 unknown vulnerability
8882| [69338] Apache Xalan-Java up to 2.7.1 system-property unknown vulnerability
8883| [12742] Trustwave ModSecurity up to 2.7.5 Chunk Extension apache2/modsecurity.c modsecurity_tx_init privilege escalation
8884| [12741] Trustwave ModSecurity up to 2.7.6 Chunked HTTP Transfer apache2/modsecurity.c modsecurity_tx_init Trailing Header privilege escalation
8885| [13387] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Content-Length Header privilege escalation
8886| [13386] Apache Tomcat Security Manager up to 6.0.39/7.0.53/8.0.5 XSLT privilege escalation
8887| [13385] Apache Tomcat 8.0.0/8.0.1/8.0.3 AJP Request Zero Length denial of service
8888| [13384] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Chunked HTTP Request denial of service
8889| [12748] Apache CouchDB 1.5.0 UUIDS /_uuids denial of service
8890| [66739] Apache Camel up to 2.12.2 unknown vulnerability
8891| [66738] Apache Camel up to 2.12.2 unknown vulnerability
8892| [12667] Apache HTTP Server 2.4.7 mod_log_config.c log_cookie denial of service
8893| [66695] Apache CouchDB up to 1.2.0 cross site scripting
8894| [66694] Apache CouchDB up to 1.2.0 Partition partition2 directory traversal
8895| [66689] Apache HTTP Server up to 2.0.33 mod_dav dav_xml_get_cdata denial of service
8896| [12518] Apache Tomcat up to 6.0.38/7.0.49/8.0.0-RC9 HTTP Header denial of service
8897| [66498] Apache expressions up to 3.3.0 Whitelist unknown vulnerability
8898| [12781] Apache Struts up to 2.3.8 ParametersInterceptor getClass denial of service
8899| [12439] Apache Tomcat 6.0.33 XML XXE information disclosure
8900| [12438] Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37 coyoteadapter.java disableURLRewriting privilege escalation
8901| [66356] Apache Wicket up to 6.8.0 information disclosure
8902| [12209] Apache Tomcat 7.0.0/7.0.50/8.0.0-RC1/8.0.1 Content-Type Header for Multi-Part Request Infinite Loop denial of service
8903| [66322] Apache ActiveMQ up to 5.8.0 cross site scripting
8904| [12291] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
8905| [66255] Apache Open For Business Project up to 10.04.3 cross site scripting
8906| [66200] Apache Hadoop up to 2.0.5 Security Feature information disclosure
8907| [66072] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
8908| [66068] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
8909| [11928] Oracle Secure Global Desktop up to 4.71 Apache Tomcat unknown vulnerability
8910| [11924] Oracle Secure Global Desktop up to 4.63 Apache Tomcat denial of service
8911| [11922] Oracle Secure Global Desktop up to 4.63 Apache Tomcat unknown vulnerability
8912| [66049] Apache XML Security for Java up to 1.4.6 Memory Consumption denial of service
8913| [12199] Apache Subversion up to 1.8.5 mod_dav_svn/repos.c get_resource denial of service
8914| [65946] askapache Firefox Adsense up to 3.0 askapache-firefox-adsense.php cross site request forgery
8915| [65668] Apache Solr 4.0.0 Updater denial of service
8916| [65665] Apache Solr up to 4.3.0 denial of service
8917| [65664] Apache Solr 3.6.0/3.6.1/3.6.2/4.0.0 Updater denial of service
8918| [65663] Apache Solr up to 4.5.1 ResourceLoader directory traversal
8919| [65658] Apache roller 4.0/4.0.1/5.0/5.0.1 unknown vulnerability
8920| [65657] Apache Roller 4.0/4.0.1/5.0/5.0.1 cross site scripting
8921| [11325] Apache Subversion 1.7.13 mod_dontdothat Bypass denial of service
8922| [11324] Apache Subversion up to 1.8.4 mod_dav_svn denial of service
8923| [11098] Apache Tomcat 5.5.25 HTTP Request cross site request forgery
8924| [65410] Apache Struts 2.3.15.3 cross site scripting
8925| [65386] Apache Solr up to 2.2.1 on TYPO3 cross site scripting
8926| [65385] Apache Solr up to 2.2.1 on TYPO3 unknown vulnerability
8927| [11044] Apache Struts 2.3.15.3 showConfig.action cross site scripting
8928| [11043] Apache Struts 2.3.15.3 actionNames.action cross site scripting
8929| [11018] cPanel WHM up to 11.40.0.11 Apache mod_userdir Tweak Interface privilege escalation
8930| [65342] Apache Sling 1.0.2/1.0.4/1.0.6/1.1.0/1.1.2 Auth Core cross site scripting
8931| [65340] Apache Shindig 2.5.0 information disclosure
8932| [65316] Apache Mod Fcgid up to 2.3.7 mod_fcgid fcgid_bucket.c fcgid_header_bucket_read memory corruption
8933| [65313] Apache Sling 2.2.0/2.3.0 AbstractCreateOperation.java deepGetOrCreateNode denial of service
8934| [10826] Apache Struts 2 File privilege escalation
8935| [65204] Apache Camel up to 2.10.1 unknown vulnerability
8936| [10460] Apache Struts 2.0.0/2.3.15.1 Action Mapping Mechanism Bypass privilege escalation
8937| [10459] Apache Struts 2.0.0/2.3.15 Dynamic Method Invocation unknown vulnerability
8938| [10160] Apache Subversion 1.8.0/1.8.1/1.8.2 svnwcsub.py handle_options race condition
8939| [10159] Apache Subversion up to 1.8.2 svnserve write_pid_file race condition
8940| [10158] Apache Subversion 1.8.0/1.8.1/1.8.2 daemonize.py daemon::daemonize race condition
8941| [10157] Apache Subversion up to 1.8.1 FSFS Repository Symlink privilege escalation
8942| [64808] Fail2ban up to 0.8.9 apache-auth.conf denial of service
8943| [64760] Best Practical RT up to 4.0.12 Apache::Session::File information disclosure
8944| [64722] Apache XML Security for C++ Heap-based memory corruption
8945| [64719] Apache XML Security for C++ Heap-based memory corruption
8946| [64718] Apache XML Security for C++ verify denial of service
8947| [64717] Apache XML Security for C++ getURIBaseTXFM memory corruption
8948| [64716] Apache XML Security for C++ spoofing
8949| [64701] Apache CXF up to 2.7.3 XML Parser Memory Consumption denial of service
8950| [64700] Apache CloudStack up to 4.1.0 Stack-Based cross site scripting
8951| [64667] Apache Open For Business Project up to 10.04.04 unknown vulnerability
8952| [64666] Apache Open For Business Project up to 10.04.04 cross site scripting
8953| [9891] Apache HTTP Server 2.2.22 suEXEC Feature .htaccess information disclosure
8954| [64509] Apache ActiveMQ up to 5.8.0 scheduled.jsp cross site scripting
8955| [9826] Apache Subversion up to 1.8.0 mod_dav_svn denial of service
8956| [9683] Apache HTTP Server 2.4.5 mod_session_dbd denial of service
8957| [64485] Apache Struts up to 2.2.3.0 privilege escalation
8958| [9568] Apache Struts up to 2.3.15 DefaultActionMapper cross site request forgery
8959| [9567] Apache Struts up to 2.3.15 DefaultActionMapper memory corruption
8960| [64467] Apache Geronimo 3.0 memory corruption
8961| [64466] Apache OpenJPA up to 2.2.1 Serialization memory corruption
8962| [64457] Apache Struts up to 2.2.3.0 cross site scripting
8963| [64326] Alejandro Garza Apachesolr Autocomplete up to 7.x-1.1 cross site scripting
8964| [9184] Apache Qpid up to 0.20 SSL misconfiguration
8965| [8935] Apache Subversion up to 1.7.9 FSFS Format Repository denial of service
8966| [8934] Apache Subversion up to 1.7.9 Svnserve Server denial of service
8967| [8933] Apache Subversion up to 1.6.21 check-mime-type.pl svnlook memory corruption
8968| [8932] Apache Subversion up to 1.6.21 svn-keyword-check.pl svnlook changed memory corruption
8969| [9022] Apache Struts up to 2.3.14.2 OGNL Expression memory corruption
8970| [8873] Apache Struts 2.3.14 privilege escalation
8971| [8872] Apache Struts 2.3.14 privilege escalation
8972| [8746] Apache HTTP Server Log File Terminal Escape Sequence Filtering mod_rewrite.c do_rewritelog privilege escalation
8973| [8666] Apache Tomcat up to 7.0.32 AsyncListener information disclosure
8974| [8665] Apache Tomcat up to 7.0.29 Chunked Transfer Encoding Extension Size denial of service
8975| [8664] Apache Tomcat up to 7.0.32 FORM Authentication weak authentication
8976| [64075] Apache Subversion up to 1.7.7 mod_dav_svn Crash denial of service
8977| [64074] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
8978| [64073] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
8979| [64072] Apache Subversion up to 1.7.7 mod_dav_svn NULL Pointer Dereference denial of service
8980| [64071] Apache Subversion up to 1.7.8 mod_dav_svn Memory Consumption denial of service
8981| [8768] Apache Struts up to 2.3.14 on Mac EL and OGNL Interpreter memory corruption
8982| [64006] Apache ActiveMQ up to 5.7.0 denial of service
8983| [64005] Apache ActiveMQ up to 5.7.0 Default Configuration denial of service
8984| [64004] Apache ActiveMQ up to 5.7.0 PortfolioPublishServlet.java cross site scripting
8985| [8427] Apache Tomcat Session Transaction weak authentication
8986| [63960] Apache Maven 3.0.4 Default Configuration spoofing
8987| [63751] Apache qpid up to 0.20 qpid::framing::Buffer denial of service
8988| [63750] Apache qpid up to 0.20 checkAvailable denial of service
8989| [63749] Apache Qpid up to 0.20 Memory Consumption denial of service
8990| [63748] Apache Qpid up to 0.20 Default Configuration denial of service
8991| [63747] Apache Rave up to 0.20 User Account information disclosure
8992| [7889] Apache Subversion up to 1.6.17 mod_dav_svn/svn_fs_file_length() denial of service
8993| [63646] Apache HTTP Server up to 2.2.23/2.4.3 mod_proxy_balancer.c balancer_handler cross site scripting
8994| [7688] Apache CXF up to 2.7.1 WSS4JInterceptor Bypass weak authentication
8995| [7687] Apache CXF up to 2.7.2 Token weak authentication
8996| [63334] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
8997| [63299] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
8998| [7202] Apache HTTP Server 2.4.2 on Oracle Solaris ld_library_path cross site scripting
8999| [7075] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector NioEndpoint.java denial of service
9000| [7074] Apache Tomcat up to 6.0.35/7.0.29 FORM Authentication RealmBase.java weak authentication
9001| [7073] Apache Tomcat up to 6.0.35/7.0.31 CSRF Prevention Filter cross site request forgery
9002| [63090] Apache Tomcat up to 4.1.24 denial of service
9003| [63089] Apache HTTP Server up to 2.2.13 mod_proxy_ajp denial of service
9004| [62933] Apache Tomcat up to 5.5.0 Access Restriction unknown vulnerability
9005| [62929] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector Memory Consumption denial of service
9006| [62833] Apache CXF -/2.6.0 spoofing
9007| [62832] Apache Axis2 up to 1.6.2 spoofing
9008| [62831] Apache Axis up to 1.4 Java Message Service spoofing
9009| [62830] Apache Commons-httpclient 3.0 Payments spoofing
9010| [62826] Apache Libcloud up to 0.11.0 spoofing
9011| [62757] Apache Open For Business Project up to 10.04.0 unknown vulnerability
9012| [8830] Red Hat JBoss Enterprise Application Platform 6.0.1 org.apache.catalina.connector.Response.encodeURL information disclosure
9013| [62661] Apache Axis2 unknown vulnerability
9014| [62658] Apache Axis2 unknown vulnerability
9015| [62467] Apache Qpid up to 0.17 denial of service
9016| [62417] Apache CXF 2.4.7/2.4.8/2.5.3/2.5.4/2.6.1 spoofing
9017| [6301] Apache HTTP Server mod_pagespeed cross site scripting
9018| [6300] Apache HTTP Server mod_pagespeed Hostname information disclosure
9019| [6123] Apache Wicket up to 1.5.7 Ajax Link cross site scripting
9020| [62035] Apache Struts up to 2.3.4 denial of service
9021| [61916] Apache QPID 0.5/0.6/0.14/0.16 unknown vulnerability
9022| [6998] Apache Tomcat 5.5.35/6.0.35/7.0.28 DIGEST Authentication Session State Caching privilege escalation
9023| [6997] Apache Tomcat 5.5.35/6.0.35/7.0.28 HTTP Digest Authentication Implementation privilege escalation
9024| [6092] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_ajp.c information disclosure
9025| [6090] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_http.c information disclosure
9026| [61507] Apache POI up to 3.8 UnhandledDataStructure denial of service
9027| [6070] Apache Struts up to 2.3.4 Token Name Configuration Parameter privilege escalation
9028| [6069] Apache Struts up to 2.3.4 Request Parameter OGNL Expression denial of service
9029| [5764] Oracle Solaris 10 Apache HTTP Server information disclosure
9030| [5700] Oracle Secure Backup 10.3.0.3/10.4.0.1 Apache denial of service
9031| [61255] Apache Hadoop 2.0.0 Kerberos unknown vulnerability
9032| [61229] Apache Sling up to 2.1.1 denial of service
9033| [61152] Apache Commons-compress 1.0/1.1/1.2/1.3/1.4 denial of service
9034| [61094] Apache Roller up to 5.0 cross site scripting
9035| [61093] Apache Roller up to 5.0 cross site request forgery
9036| [61005] Apache OpenOffice 3.3/3.4 unknown vulnerability
9037| [9673] Apache HTTP Server up to 2.4.4 mod_dav mod_dav.c Request denial of service
9038| [5436] Apache OpenOffice 3.3/3.4 WPXContentListener.cpp _closeTableRow File memory corruption
9039| [5435] Apache OpenOffice 3.3/3.4 vclmi.dll File memory corruption
9040| [60730] PHP 5.4.0/5.4.1/5.4.2 apache_request_headers memory corruption
9041| [60708] Apache Qpid 0.12 unknown vulnerability
9042| [5032] Apache Hadoop up to 0.20.205.0/1.0.1/0.23.1 Kerberos/MapReduce Security Feature privilege escalation
9043| [4949] Apache Struts File Upload XSLTResult.java XSLT File privilege escalation
9044| [4955] Apache Traffic Server 3.0.3/3.1.2 HTTP Header Parser memory corruption
9045| [4882] Apache Wicket up to 1.5.4 directory traversal
9046| [4881] Apache Wicket up to 1.4.19 cross site scripting
9047| [4884] Apache HTTP Server up to 2.3.6 mod_fcgid fcgid_spawn_ctl.c FcgidMaxProcessesPerClass HTTP Requests denial of service
9048| [60352] Apache Struts up to 2.2.3 memory corruption
9049| [60153] Apache Portable Runtime up to 1.4.3 denial of service
9050| [4598] Apache Struts 1.3.10 upload-submit.do cross site scripting
9051| [4597] Apache Struts 1.3.10 processSimple.do cross site scripting
9052| [4596] Apache Struts 2.0.14/2.2.3 struts2-rest-showcase/orders cross site scripting
9053| [4595] Apache Struts 2.0.14/2.2.3 struts2-showcase/person/editPerson.action cross site scripting
9054| [4583] Apache HTTP Server up to 2.2.21 Threaded MPM denial of service
9055| [4582] Apache HTTP Server up to 2.2.21 protocol.c information disclosure
9056| [4571] Apache Struts up to 2.3.1.2 privilege escalation
9057| [4557] Apache Tomcat up to 7.0.21 Caching/Recycling information disclosure
9058| [59934] Apache Tomcat up to 6.0.9 DigestAuthenticator.java unknown vulnerability
9059| [59933] Apache Tomcat up to 6.0.9 Access Restriction unknown vulnerability
9060| [59932] Apache Tomcat up to 6.0.9 unknown vulnerability
9061| [59931] Apache Tomcat up to 6.0.9 Access Restriction information disclosure
9062| [59902] Apache Struts up to 2.2.3 Interfaces unknown vulnerability
9063| [4528] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
9064| [4527] Apache Struts up to 2.2.3 ExceptionDelegator cross site scripting
9065| [59888] Apache Tomcat up to 6.0.6 denial of service
9066| [59886] Apache ActiveMQ up to 5.5.1 Crash denial of service
9067| [4513] Apache Struts up to 2.3.1 ParameterInterceptor directory traversal
9068| [4512] Apache Struts up to 2.2.3 CookieInterceptor privilege escalation
9069| [59850] Apache Geronimo up to 2.2.1 denial of service
9070| [59825] Apache HTTP Server up to 2.1.7 mod_reqtimeout denial of service
9071| [59556] Apache HTTP Server up to 2.0.53 mod_proxy information disclosure
9072| [58467] Apache libcloud 0.2.0/0.3.0/0.3.1/0.4.0 Access Restriction spoofing
9073| [58413] Apache Tomcat up to 6.0.10 spoofing
9074| [58381] Apache Wicket up to 1.4.17 cross site scripting
9075| [58296] Apache Tomcat up to 7.0.19 unknown vulnerability
9076| [57888] Apache HttpClient 4.0/4.0.1/4.1 Authorization information disclosure
9077| [57587] Apache Subversion up to 1.6.16 mod_dav_svn information disclosure
9078| [57585] Apache Subversion up to 1.6.16 mod_dav_svn Memory Consumption denial of service
9079| [57584] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
9080| [57577] Apache Rampart-C 1.3.0 Access Restriction rampart_timestamp_token_validate privilege escalation
9081| [57568] Apache Archiva up to 1.3.4 cross site scripting
9082| [57567] Apache Archiva up to 1.3.4 cross site request forgery
9083| [57481] Apache Tomcat 7.0.12/7.0.13 Access Restriction unknown vulnerability
9084| [4355] Apache HTTP Server APR apr_fnmatch denial of service
9085| [57435] Apache Struts up to 2.2.1.1 FileHandler.java cross site scripting
9086| [57425] Apache Struts up to 2.2.1.1 cross site scripting
9087| [4352] Apache HTTP Server 2.2.x APR apr_fnmatch denial of service
9088| [57025] Apache Tomcat up to 7.0.11 information disclosure
9089| [57024] Apache Tomcat 7.0.11 Access Restriction information disclosure
9090| [56774] IBM WebSphere Application Server up to 7.0.0.14 org.apache.jasper.runtime.JspWriterImpl.response denial of service
9091| [56824] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
9092| [56832] Apache Tomcat up to 7.0.10 Access Restriction information disclosure
9093| [56830] Apache Tomcat up to 7.0.9 Access Restriction privilege escalation
9094| [12440] Apache Tomcat 6.0.33 Malicious Request cross site scripting
9095| [56512] Apache Continuum up to 1.4.0 cross site scripting
9096| [4285] Apache Tomcat 5.x JVM getLocale denial of service
9097| [4284] Apache Tomcat 5.x HTML Manager Infinite Loop cross site scripting
9098| [4283] Apache Tomcat 5.x ServletContect privilege escalation
9099| [56441] Apache Tomcat up to 7.0.6 denial of service
9100| [56300] Apache CouchDB up to 1.0.1 Web Administration Interface cross site scripting
9101| [55967] Apache Subversion up to 1.6.4 rev_hunt.c denial of service
9102| [55966] Apache Subversion up to 1.6.4 mod_dav_svn repos.c walk denial of service
9103| [55095] Apache Axis2 up to 1.6 Default Password memory corruption
9104| [55631] Apache Archiva up to 1.3.1 User Account cross site request forgery
9105| [55556] Apache Tomcat up to 6.0.29 Default Configuration information disclosure
9106| [55553] Apache Tomcat up to 7.0.4 sessionsList.jsp cross site scripting
9107| [55162] Apache MyFaces up to 2.0.0 Authentication Code unknown vulnerability
9108| [54881] Apache Subversion up to 1.6.12 mod_dav_svn authz.c privilege escalation
9109| [54879] Apache APR-util up to 0.9.14 mod_reqtimeout apr_brigade_split_line denial of service
9110| [54693] Apache Traffic Server DNS Cache unknown vulnerability
9111| [54416] Apache CouchDB up to 0.11.0 cross site request forgery
9112| [54394] Apache CXF up to 2.2.8 Memory Consumption denial of service
9113| [54261] Apache Tomcat jsp/cal/cal2.jsp cross site scripting
9114| [54166] Apache HTTP Server up to 2.2.12 mod_cache Crash denial of service
9115| [54385] Apache Struts up to 2.1.8.1 ParameterInterceptor unknown vulnerability
9116| [54012] Apache Tomcat up to 6.0.10 denial of service
9117| [53763] Apache Axis2 1.3/1.4/1.4.1/1.5/1.5.1 Memory Consumption denial of service
9118| [53368] Apache MyFaces 1.1.7/1.2.8 cross site scripting
9119| [53397] Apache axis2 1.4.1/1.5.1 Administration Console cross site scripting
9120| [52894] Apache Tomcat up to 6.0.7 information disclosure
9121| [52960] Apache ActiveMQ up to 5.4-snapshot information disclosure
9122| [52843] Apache HTTP Server mod_auth_shadow unknown vulnerability
9123| [52786] Apache Open For Business Project up to 09.04 cross site scripting
9124| [52587] Apache ActiveMQ up to 5.3.0 cross site request forgery
9125| [52586] Apache ActiveMQ up to 5.3.0 cross site scripting
9126| [52584] Apache CouchDB up to 0.10.1 information disclosure
9127| [51757] Apache HTTP Server 2.0.44 cross site scripting
9128| [51756] Apache HTTP Server 2.0.44 spoofing
9129| [51717] Apache HTTP Server up to 1.3.3 mod_proxy ap_proxy_send_fb memory corruption
9130| [51690] Apache Tomcat up to 6.0 directory traversal
9131| [51689] Apache Tomcat up to 6.0 information disclosure
9132| [51688] Apache Tomcat up to 6.0 directory traversal
9133| [50886] HP Operations Manager 8.10 on Windows File Upload org.apache.catalina.manager.HTMLManagerServlet memory corruption
9134| [50802] Apache Tomcat up to 3.3 Default Password weak authentication
9135| [50626] Apache Solr 1.0.0 cross site scripting
9136| [49857] Apache HTTP Server mod_proxy_ftp cross site scripting
9137| [49856] Apache HTTP Server 2.2.13 mod_proxy_ftp ap_proxy_ftp_handler denial of service
9138| [49348] Apache Xerces-C++ 2.7.0 Stack-Based denial of service
9139| [86789] Apache Portable Runtime memory/unix/apr_pools.c unknown vulnerability
9140| [49283] Apache APR-util up to 1.3.8 apr-util misc/apr_rmm.c apr_rmm_realloc memory corruption
9141| [48952] Apache HTTP Server up to 1.3.6 mod_deflate denial of service
9142| [48626] Apache Tomcat up to 4.1.23 Access Restriction directory traversal
9143| [48431] Apache Tomcat up to 4.1.23 j_security_check cross site scripting
9144| [48430] Apache Tomcat up to 4.1.23 mod_jk denial of service
9145| [47801] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site request forgery
9146| [47800] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site scripting
9147| [47799] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console directory traversal
9148| [47648] Apache Tiles 2.1.0/2.1.1 cross site scripting
9149| [47640] Apache Struts 2.0.6/2.0.8/2.0.9/2.0.11/2.1 cross site scripting
9150| [47638] Apache Tomcat up to 4.1.23 mod_jk information disclosure
9151| [47636] Apache Struts 2.0.9 xip_client.html cross site scripting
9152| [47593] Apache Mod Perl 1 perl-status Apache::Status cross site scripting
9153| [47637] Apache Struts 1.0.2/1.1/1.2.4/1.2.7/1.2.8 cross site scripting
9154| [47239] Apache Struts up to 2.1.2 Beta struts directory traversal
9155| [47214] Apachefriends xampp 1.6.8 spoofing
9156| [47213] Apachefriends xampp 1.6.8 htaccess cross site request forgery
9157| [47162] Apachefriends XAMPP 1.4.4 weak authentication
9158| [47065] Apache Tomcat 4.1.23 cross site scripting
9159| [46834] Apache Tomcat up to 5.5.20 cross site scripting
9160| [46004] Apache Jackrabbit 1.4/1.5.0 search.jsp cross site scripting
9161| [49205] Apache Roller 2.3/3.0/3.1/4.0 Search cross site scripting
9162| [86625] Apache Struts directory traversal
9163| [44461] Apache Tomcat up to 5.5.0 information disclosure
9164| [44389] Apache Xerces-C++ XML Parser Memory Consumption denial of service
9165| [44352] Apache Friends XAMPP 1.6.8 adodb.php cross site scripting
9166| [43663] Apache Tomcat up to 6.0.16 directory traversal
9167| [43612] Apache Friends XAMPP 1.6.7 iart.php cross site scripting
9168| [43556] Apache HTTP Server up to 2.1.8 mod_proxy_ftp proxy_ftp.c cross site scripting
9169| [43516] Apache Tomcat up to 4.1.20 directory traversal
9170| [43509] Apache Tomcat up to 6.0.13 cross site scripting
9171| [42637] Apache Tomcat up to 6.0.16 cross site scripting
9172| [42325] Apache HTTP Server up to 2.1.8 Error Page cross site scripting
9173| [41838] Apache-SSL 1.3.34 1.57 expandcert privilege escalation
9174| [41091] Apache Software Foundation Mod Jk up to 2.0.1 mod_jk2 Stack-based memory corruption
9175| [40924] Apache Tomcat up to 6.0.15 information disclosure
9176| [40923] Apache Tomcat up to 6.0.15 unknown vulnerability
9177| [40922] Apache Tomcat up to 6.0 information disclosure
9178| [40710] Apache HTTP Server up to 2.0.61 mod_negotiation cross site scripting
9179| [40709] Apache HTTP Server up to 2.0.53 mod_negotiation cross site scripting
9180| [40656] Apache Tomcat 5.5.20 information disclosure
9181| [40503] Apache HTTP Server mod_proxy_ftp cross site scripting
9182| [40502] Apache HTTP Server up to 2.2.5 mod_proxy_balancer memory corruption
9183| [40501] Apache HTTP Server 2.2.6 mod_proxy_balancer cross site request forgery
9184| [40398] Apache HTTP Server up to 2.2 mod_proxy_balancer cross site scripting
9185| [40397] Apache HTTP Server up to 2.2 mod_proxy_balancer balancer_handler denial of service
9186| [40234] Apache Tomcat up to 6.0.15 directory traversal
9187| [40221] Apache HTTP Server 2.2.6 information disclosure
9188| [40027] David Castro Apache Authcas 0.4 sql injection
9189| [3495] Apache OpenOffice up to 2.3 Database Document Processor unknown vulnerability
9190| [3489] Apache HTTP Server 2.x HTTP Header cross site scripting
9191| [3414] Apache Tomcat WebDAV Stored privilege escalation
9192| [39489] Apache Jakarta Slide up to 2.1 directory traversal
9193| [39540] Apache Geronimo 2.0/2.0.1/2.0.2/2.1 unknown vulnerability
9194| [3310] Apache OpenOffice 1.1.3/2.0.4/2.2.1 TIFF Image Parser Heap-based memory corruption
9195| [38768] Apache HTTP Server up to 2.1.7 mod_autoindex.c cross site scripting
9196| [38952] Apache Geronimo 2.0.1/2.1 unknown vulnerability
9197| [38658] Apache Tomcat 4.1.31 cal2.jsp cross site request forgery
9198| [38524] Apache Geronimo 2.0 unknown vulnerability
9199| [3256] Apache Tomcat up to 6.0.13 cross site scripting
9200| [38331] Apache Tomcat 4.1.24 information disclosure
9201| [38330] Apache Tomcat 4.1.24 information disclosure
9202| [38185] Apache Tomcat 3.3/3.3.1/3.3.1a/3.3.2 Error Message CookieExample cross site scripting
9203| [37967] Apache Tomcat up to 4.1.36 Error Message sendmail.jsp cross site scripting
9204| [37647] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 Authorization unknown vulnerability
9205| [37646] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 unknown vulnerability
9206| [3141] Apache Tomcat up to 4.1.31 Accept-Language Header cross site scripting
9207| [3133] Apache Tomcat up to 6.0 HTTP cross site scripting
9208| [37292] Apache Tomcat up to 5.5.1 cross site scripting
9209| [3130] Apache OpenOffice 2.2.1 RTF Document Heap-based memory corruption
9210| [36981] Apache Tomcat JK Web Server Connector up to 1.2.22 mod_jk directory traversal
9211| [36892] Apache Tomcat up to 4.0.0 hello.jsp cross site scripting
9212| [37320] Apache MyFaces Tomahawk up to 1.1.4 cross site scripting
9213| [36697] Apache Tomcat up to 5.5.17 implicit-objects.jsp cross site scripting
9214| [36491] Apache Axis 1.0 Installation javaioFileNotFoundException information disclosure
9215| [36400] Apache Tomcat 5.5.15 mod_jk cross site scripting
9216| [36698] Apache Tomcat up to 4.0.0 cal2.jsp cross site scripting
9217| [36224] XAMPP Apache Distribution up to 1.6.0a adodb.php connect memory corruption
9218| [36225] XAMPP Apache Distribution 1.6.0a sql injection
9219| [2997] Apache httpd/Tomcat 5.5/6.0 directory traversal
9220| [35896] Apache Apache Test up to 1.29 mod_perl denial of service
9221| [35653] Avaya S8300 Cm 3.1.2 Apache Tomcat unknown vulnerability
9222| [35402] Apache Tomcat JK Web Server Connector 1.2.19 mod_jk.so map_uri_to_worker memory corruption
9223| [35067] Apache Stats up to 0.0.2 extract unknown vulnerability
9224| [35025] Apache Stats up to 0.0.3 extract unknown vulnerability
9225| [34252] Apache HTTP Server denial of service
9226| [2795] Apache OpenOffice 2.0.4 WMF/EMF File Heap-based memory corruption
9227| [33877] Apache Opentaps 0.9.3 cross site scripting
9228| [33876] Apache Open For Business Project unknown vulnerability
9229| [33875] Apache Open For Business Project cross site scripting
9230| [2703] Apache Jakarta Tomcat up to 5.x der_get_oid memory corruption
9231| [2611] Apache HTTP Server up to 1.0.1 set_var Format String
9232|
9233| MITRE CVE - https://cve.mitre.org:
9234| [CVE-2013-4156] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.
9235| [CVE-2013-4131] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
9236| [CVE-2013-3239] phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.
9237| [CVE-2013-3060] The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
9238| [CVE-2013-2765] The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
9239| [CVE-2013-2251] Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
9240| [CVE-2013-2249] mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
9241| [CVE-2013-2248] Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
9242| [CVE-2013-2189] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.
9243| [CVE-2013-2135] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
9244| [CVE-2013-2134] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
9245| [CVE-2013-2115] Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
9246| [CVE-2013-2071] java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
9247| [CVE-2013-2067] java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
9248| [CVE-2013-1966] Apache Struts 2 before 2.3.14.1 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
9249| [CVE-2013-1965] Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.1, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
9250| [CVE-2013-1896] mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
9251| [CVE-2013-1884] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
9252| [CVE-2013-1879] Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."
9253| [CVE-2013-1862] mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
9254| [CVE-2013-1849] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
9255| [CVE-2013-1847] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
9256| [CVE-2013-1846] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL.
9257| [CVE-2013-1845] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file or directory.
9258| [CVE-2013-1814] The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
9259| [CVE-2013-1777] The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not property implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
9260| [CVE-2013-1768] The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
9261| [CVE-2013-1088] Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
9262| [CVE-2013-1048] The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
9263| [CVE-2013-0966] The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
9264| [CVE-2013-0942] Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
9265| [CVE-2013-0941] EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
9266| [CVE-2013-0253] The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
9267| [CVE-2013-0248] The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
9268| [CVE-2013-0239] Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
9269| [CVE-2012-6573] Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.
9270| [CVE-2012-6551] The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
9271| [CVE-2012-6092] Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
9272| [CVE-2012-5887] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.
9273| [CVE-2012-5886] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
9274| [CVE-2012-5885] The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
9275| [CVE-2012-5786] The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF, possibly 2.6.0, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
9276| [CVE-2012-5785] Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
9277| [CVE-2012-5784] Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
9278| [CVE-2012-5783] Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
9279| [CVE-2012-5633] The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
9280| [CVE-2012-5616] Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.
9281| [CVE-2012-5568] Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
9282| [CVE-2012-5351] Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
9283| [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
9284| [CVE-2012-4557] The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
9285| [CVE-2012-4556] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query.
9286| [CVE-2012-4555] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors.
9287| [CVE-2012-4534] org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
9288| [CVE-2012-4528] The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
9289| [CVE-2012-4501] Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
9290| [CVE-2012-4460] The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an out-of-bounds read, but it might not trigger a crash.
9291| [CVE-2012-4459] Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.
9292| [CVE-2012-4458] The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the client-properties map in a connection.start-ok message.
9293| [CVE-2012-4446] The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
9294| [CVE-2012-4431] org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
9295| [CVE-2012-4418] Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
9296| [CVE-2012-4387] Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
9297| [CVE-2012-4386] The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
9298| [CVE-2012-4360] Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
9299| [CVE-2012-4063] The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via unspecified vectors.
9300| [CVE-2012-4001] The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.
9301| [CVE-2012-3908] Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
9302| [CVE-2012-3546] org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
9303| [CVE-2012-3544] Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
9304| [CVE-2012-3526] The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.
9305| [CVE-2012-3513] munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
9306| [CVE-2012-3506] Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
9307| [CVE-2012-3502] The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
9308| [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
9309| [CVE-2012-3467] Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
9310| [CVE-2012-3451] Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
9311| [CVE-2012-3446] Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
9312| [CVE-2012-3376] DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
9313| [CVE-2012-3373] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
9314| [CVE-2012-3126] Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Products Suite 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Apache Tomcat Agent.
9315| [CVE-2012-3123] Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.
9316| [CVE-2012-2760] mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
9317| [CVE-2012-2733] java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
9318| [CVE-2012-2687] Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
9319| [CVE-2012-2381] Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
9320| [CVE-2012-2380] Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.
9321| [CVE-2012-2379] Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
9322| [CVE-2012-2378] Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
9323| [CVE-2012-2329] Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.
9324| [CVE-2012-2145] Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.
9325| [CVE-2012-2138] The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.
9326| [CVE-2012-2098] Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
9327| [CVE-2012-1574] The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
9328| [CVE-2012-1181] fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.
9329| [CVE-2012-1089] Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
9330| [CVE-2012-1007] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.
9331| [CVE-2012-1006] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
9332| [CVE-2012-0883] envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
9333| [CVE-2012-0840] tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
9334| [CVE-2012-0838] Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
9335| [CVE-2012-0788] The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.
9336| [CVE-2012-0394] ** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
9337| [CVE-2012-0393] The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
9338| [CVE-2012-0392] The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
9339| [CVE-2012-0391] The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
9340| [CVE-2012-0256] Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
9341| [CVE-2012-0216] The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
9342| [CVE-2012-0213] The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
9343| [CVE-2012-0053] protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
9344| [CVE-2012-0047] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
9345| [CVE-2012-0031] scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
9346| [CVE-2012-0022] Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
9347| [CVE-2012-0021] The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
9348| [CVE-2011-5064] DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
9349| [CVE-2011-5063] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
9350| [CVE-2011-5062] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
9351| [CVE-2011-5057] Apache Struts 2.3.1.1 and earlier provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
9352| [CVE-2011-5034] Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
9353| [CVE-2011-4905] Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
9354| [CVE-2011-4858] Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
9355| [CVE-2011-4668] IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
9356| [CVE-2011-4449] actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.
9357| [CVE-2011-4415] The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
9358| [CVE-2011-4317] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
9359| [CVE-2011-3639] The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
9360| [CVE-2011-3620] Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
9361| [CVE-2011-3607] Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.
9362| [CVE-2011-3376] org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
9363| [CVE-2011-3375] Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
9364| [CVE-2011-3368] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
9365| [CVE-2011-3348] The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
9366| [CVE-2011-3192] The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
9367| [CVE-2011-3190] Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
9368| [CVE-2011-2729] native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
9369| [CVE-2011-2712] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
9370| [CVE-2011-2688] SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
9371| [CVE-2011-2526] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.
9372| [CVE-2011-2516] Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
9373| [CVE-2011-2481] Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
9374| [CVE-2011-2329] The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730.
9375| [CVE-2011-2204] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.
9376| [CVE-2011-2088] XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
9377| [CVE-2011-2087] Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
9378| [CVE-2011-1928] The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.
9379| [CVE-2011-1921] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
9380| [CVE-2011-1783] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
9381| [CVE-2011-1772] Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
9382| [CVE-2011-1752] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
9383| [CVE-2011-1610] Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
9384| [CVE-2011-1582] Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
9385| [CVE-2011-1571] Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
9386| [CVE-2011-1570] Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
9387| [CVE-2011-1503] The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.
9388| [CVE-2011-1502] Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
9389| [CVE-2011-1498] Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
9390| [CVE-2011-1475] The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
9391| [CVE-2011-1419] Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
9392| [CVE-2011-1318] Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
9393| [CVE-2011-1184] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
9394| [CVE-2011-1183] Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
9395| [CVE-2011-1176] The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
9396| [CVE-2011-1088] Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
9397| [CVE-2011-1077] Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
9398| [CVE-2011-1026] Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of administrators.
9399| [CVE-2011-0715] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
9400| [CVE-2011-0534] Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
9401| [CVE-2011-0533] Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta
9402| [CVE-2011-0419] Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
9403| [CVE-2011-0013] Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
9404| [CVE-2010-4644] Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
9405| [CVE-2010-4539] The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.
9406| [CVE-2010-4476] The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
9407| [CVE-2010-4455] Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.2 and 11.1.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Apache Plugin.
9408| [CVE-2010-4408] Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.
9409| [CVE-2010-4312] The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
9410| [CVE-2010-4172] Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
9411| [CVE-2010-3872] The fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.6 for the Apache HTTP Server does not use bytewise pointer arithmetic in certain circumstances, which has unspecified impact and attack vectors related to "untrusted FastCGI applications" and a "stack buffer overwrite."
9412| [CVE-2010-3863] Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
9413| [CVE-2010-3854] Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
9414| [CVE-2010-3718] Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
9415| [CVE-2010-3449] Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1
9416| [CVE-2010-3315] authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
9417| [CVE-2010-3083] sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.
9418| [CVE-2010-2952] Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.
9419| [CVE-2010-2791] mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
9420| [CVE-2010-2375] Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
9421| [CVE-2010-2234] Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.
9422| [CVE-2010-2227] Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
9423| [CVE-2010-2103] Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.
9424| [CVE-2010-2086] Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
9425| [CVE-2010-2076] Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
9426| [CVE-2010-2068] mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.
9427| [CVE-2010-2057] shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.
9428| [CVE-2010-1632] Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.
9429| [CVE-2010-1623] Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
9430| [CVE-2010-1587] The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
9431| [CVE-2010-1452] The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
9432| [CVE-2010-1325] Cross-site request forgery (CSRF) vulnerability in the apache2-slms package in SUSE Lifecycle Management Server (SLMS) 1.0 on SUSE Linux Enterprise (SLE) 11 allows remote attackers to hijack the authentication of unspecified victims via vectors related to improper parameter quoting. NOTE: some sources report that this is a vulnerability in a product named "Apache SLMS," but that is incorrect.
9433| [CVE-2010-1244] Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
9434| [CVE-2010-1157] Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.
9435| [CVE-2010-1151] Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.
9436| [CVE-2010-0684] Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
9437| [CVE-2010-0434] The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
9438| [CVE-2010-0432] Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewprofile (aka partymgr/control/login), (3) the start parameter to myportal/control/showPortalPage, (4) an invalid URI beginning with /facility/control/ReceiveReturn (aka /crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the contentId parameter (aka the entityName variable) to ecommerce/control/ViewBlogArticle, (6) the entityName parameter to webtools/control/FindGeneric, or the (7) subject or (8) content parameter to an unspecified component under ecommerce/control/contactus.
9439| [CVE-2010-0425] modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
9440| [CVE-2010-0408] The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
9441| [CVE-2010-0390] Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.
9442| [CVE-2010-0219] Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
9443| [CVE-2010-0010] Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
9444| [CVE-2010-0009] Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.
9445| [CVE-2009-5120] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a Project Woodstock service on this port.
9446| [CVE-2009-5119] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted session data.
9447| [CVE-2009-5006] The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.
9448| [CVE-2009-5005] The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.
9449| [CVE-2009-4355] Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
9450| [CVE-2009-4269] The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
9451| [CVE-2009-3923] The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
9452| [CVE-2009-3890] Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.
9453| [CVE-2009-3843] HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
9454| [CVE-2009-3821] Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
9455| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
9456| [CVE-2009-3548] The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
9457| [CVE-2009-3250] The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.
9458| [CVE-2009-3095] The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
9459| [CVE-2009-3094] The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
9460| [CVE-2009-2902] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
9461| [CVE-2009-2901] The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
9462| [CVE-2009-2823] The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.
9463| [CVE-2009-2699] The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
9464| [CVE-2009-2696] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.
9465| [CVE-2009-2693] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
9466| [CVE-2009-2625] XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
9467| [CVE-2009-2412] Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR
9468| [CVE-2009-2299] The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.
9469| [CVE-2009-1956] Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
9470| [CVE-2009-1955] The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
9471| [CVE-2009-1903] The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
9472| [CVE-2009-1891] The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
9473| [CVE-2009-1890] The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
9474| [CVE-2009-1885] Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.
9475| [CVE-2009-1462] The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.
9476| [CVE-2009-1275] Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
9477| [CVE-2009-1195] The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
9478| [CVE-2009-1191] mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
9479| [CVE-2009-1012] Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.
9480| [CVE-2009-0918] Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.
9481| [CVE-2009-0796] Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.
9482| [CVE-2009-0783] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
9483| [CVE-2009-0781] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
9484| [CVE-2009-0754] PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.
9485| [CVE-2009-0580] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.
9486| [CVE-2009-0486] Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
9487| [CVE-2009-0039] Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.
9488| [CVE-2009-0038] Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring
9489| [CVE-2009-0033] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.
9490| [CVE-2009-0026] Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
9491| [CVE-2009-0023] The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
9492| [CVE-2008-6879] Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
9493| [CVE-2008-6755] ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.
9494| [CVE-2008-6722] Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.
9495| [CVE-2008-6682] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
9496| [CVE-2008-6505] Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.
9497| [CVE-2008-6504] ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.
9498| [CVE-2008-5696] Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
9499| [CVE-2008-5676] Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."
9500| [CVE-2008-5519] The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.
9501| [CVE-2008-5518] Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet)
9502| [CVE-2008-5515] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.
9503| [CVE-2008-5457] Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
9504| [CVE-2008-4308] The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
9505| [CVE-2008-4008] Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.
9506| [CVE-2008-3666] Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured
9507| [CVE-2008-3271] Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
9508| [CVE-2008-3257] Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
9509| [CVE-2008-2939] Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
9510| [CVE-2008-2938] Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
9511| [CVE-2008-2742] Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.
9512| [CVE-2008-2717] TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
9513| [CVE-2008-2579] Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.
9514| [CVE-2008-2384] SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
9515| [CVE-2008-2370] Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
9516| [CVE-2008-2364] The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
9517| [CVE-2008-2168] Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
9518| [CVE-2008-2025] Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
9519| [CVE-2008-1947] Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
9520| [CVE-2008-1734] Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.
9521| [CVE-2008-1678] Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
9522| [CVE-2008-1232] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.
9523| [CVE-2008-0869] Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.
9524| [CVE-2008-0732] The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.
9525| [CVE-2008-0555] The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.
9526| [CVE-2008-0457] Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
9527| [CVE-2008-0456] CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
9528| [CVE-2008-0455] Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
9529| [CVE-2008-0128] The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
9530| [CVE-2008-0005] mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
9531| [CVE-2008-0002] Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
9532| [CVE-2007-6750] The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
9533| [CVE-2007-6726] Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
9534| [CVE-2007-6514] Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
9535| [CVE-2007-6423] ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
9536| [CVE-2007-6422] The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
9537| [CVE-2007-6421] Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
9538| [CVE-2007-6420] Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
9539| [CVE-2007-6388] Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
9540| [CVE-2007-6361] Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
9541| [CVE-2007-6342] SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.
9542| [CVE-2007-6286] Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
9543| [CVE-2007-6258] Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.
9544| [CVE-2007-6231] Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_includepath parameter to (1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php, or (5) libchart-1.1/libchart.php in include/. NOTE: access to include/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
9545| [CVE-2007-6203] Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
9546| [CVE-2007-5797] SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
9547| [CVE-2007-5731] Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.
9548| [CVE-2007-5461] Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
9549| [CVE-2007-5342] The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
9550| [CVE-2007-5333] Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
9551| [CVE-2007-5156] Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
9552| [CVE-2007-5085] Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
9553| [CVE-2007-5000] Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
9554| [CVE-2007-4724] Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.
9555| [CVE-2007-4723] Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
9556| [CVE-2007-4641] Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.
9557| [CVE-2007-4556] Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.
9558| [CVE-2007-4548] The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
9559| [CVE-2007-4465] Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
9560| [CVE-2007-3847] The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
9561| [CVE-2007-3571] The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.
9562| [CVE-2007-3386] Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
9563| [CVE-2007-3385] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
9564| [CVE-2007-3384] Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.
9565| [CVE-2007-3383] Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.
9566| [CVE-2007-3382] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
9567| [CVE-2007-3304] Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
9568| [CVE-2007-3303] Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
9569| [CVE-2007-3101] Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.
9570| [CVE-2007-2450] Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.
9571| [CVE-2007-2449] Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the '
9572| [CVE-2007-2353] Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
9573| [CVE-2007-2025] Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.
9574| [CVE-2007-1863] cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
9575| [CVE-2007-1862] The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
9576| [CVE-2007-1860] mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.
9577| [CVE-2007-1858] The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
9578| [CVE-2007-1842] Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.
9579| [CVE-2007-1801] Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.
9580| [CVE-2007-1743] suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
9581| [CVE-2007-1742] suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
9582| [CVE-2007-1741] Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
9583| [CVE-2007-1720] Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.
9584| [CVE-2007-1636] Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.
9585| [CVE-2007-1633] Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.
9586| [CVE-2007-1577] Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
9587| [CVE-2007-1539] Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.
9588| [CVE-2007-1524] Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.
9589| [CVE-2007-1491] Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.
9590| [CVE-2007-1358] Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
9591| [CVE-2007-1349] PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
9592| [CVE-2007-0975] Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.
9593| [CVE-2007-0930] Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.
9594| [CVE-2007-0792] The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
9595| [CVE-2007-0774] Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
9596| [CVE-2007-0637] Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.
9597| [CVE-2007-0451] Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
9598| [CVE-2007-0450] Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
9599| [CVE-2007-0419] The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).
9600| [CVE-2007-0173] Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
9601| [CVE-2007-0098] Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
9602| [CVE-2007-0086] ** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.
9603| [CVE-2006-7217] Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.
9604| [CVE-2006-7216] Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.
9605| [CVE-2006-7197] The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.
9606| [CVE-2006-7196] Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
9607| [CVE-2006-7195] Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
9608| [CVE-2006-7098] The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
9609| [CVE-2006-6869] Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
9610| [CVE-2006-6675] Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecifeid parameters in Welcome web-app.
9611| [CVE-2006-6613] Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive information via a .. (dot dot) in the pa_lang[include_file] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
9612| [CVE-2006-6589] Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.
9613| [CVE-2006-6588] The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
9614| [CVE-2006-6587] Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.
9615| [CVE-2006-6445] Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
9616| [CVE-2006-6071] TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.
9617| [CVE-2006-6047] Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
9618| [CVE-2006-5894] Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
9619| [CVE-2006-5752] Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
9620| [CVE-2006-5733] Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
9621| [CVE-2006-5263] Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apache HTTP Server log file that apparently contains PHP code.
9622| [CVE-2006-4994] Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted "Program Files" pathname.
9623| [CVE-2006-4636] Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.
9624| [CVE-2006-4625] PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
9625| [CVE-2006-4558] DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
9626| [CVE-2006-4191] Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
9627| [CVE-2006-4154] Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
9628| [CVE-2006-4110] Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
9629| [CVE-2006-4004] Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
9630| [CVE-2006-3918] http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
9631| [CVE-2006-3835] Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (
9632| [CVE-2006-3747] Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
9633| [CVE-2006-3362] Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
9634| [CVE-2006-3102] Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of time under the webroot in the temp/articles directory.
9635| [CVE-2006-3070] write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.
9636| [CVE-2006-2831] Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
9637| [CVE-2006-2806] The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.
9638| [CVE-2006-2743] Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
9639| [CVE-2006-2514] Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
9640| [CVE-2006-2330] PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
9641| [CVE-2006-1777] Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache error_log file, which is then included by doc/index.php.
9642| [CVE-2006-1564] Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.
9643| [CVE-2006-1548] Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
9644| [CVE-2006-1547] ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
9645| [CVE-2006-1546] Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
9646| [CVE-2006-1393] Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
9647| [CVE-2006-1346] Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.
9648| [CVE-2006-1292] Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
9649| [CVE-2006-1243] Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
9650| [CVE-2006-1095] Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
9651| [CVE-2006-1079] htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
9652| [CVE-2006-1078] Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
9653| [CVE-2006-0743] Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
9654| [CVE-2006-0254] Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.
9655| [CVE-2006-0150] Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
9656| [CVE-2006-0144] The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.
9657| [CVE-2006-0042] Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.
9658| [CVE-2005-4857] eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a "memory addressing error".
9659| [CVE-2005-4849] Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information.
9660| [CVE-2005-4836] The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
9661| [CVE-2005-4814] Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.
9662| [CVE-2005-4703] Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
9663| [CVE-2005-3745] Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
9664| [CVE-2005-3630] Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.
9665| [CVE-2005-3510] Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
9666| [CVE-2005-3392] Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.
9667| [CVE-2005-3357] mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
9668| [CVE-2005-3352] Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
9669| [CVE-2005-3319] The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.
9670| [CVE-2005-3164] The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
9671| [CVE-2005-2970] Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
9672| [CVE-2005-2963] The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.
9673| [CVE-2005-2728] The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
9674| [CVE-2005-2660] apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.
9675| [CVE-2005-2088] The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
9676| [CVE-2005-1754] ** DISPUTED ** JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
9677| [CVE-2005-1753] ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
9678| [CVE-2005-1344] Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
9679| [CVE-2005-1268] Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
9680| [CVE-2005-1266] Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
9681| [CVE-2005-0808] Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
9682| [CVE-2005-0182] The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.
9683| [CVE-2005-0108] Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.
9684| [CVE-2004-2734] webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
9685| [CVE-2004-2680] mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
9686| [CVE-2004-2650] Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
9687| [CVE-2004-2343] ** DISPUTED ** Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument.
9688| [CVE-2004-2336] Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.
9689| [CVE-2004-2115] Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.
9690| [CVE-2004-1834] mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
9691| [CVE-2004-1765] Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.
9692| [CVE-2004-1545] UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
9693| [CVE-2004-1438] The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
9694| [CVE-2004-1405] MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
9695| [CVE-2004-1404] Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
9696| [CVE-2004-1387] The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
9697| [CVE-2004-1084] Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
9698| [CVE-2004-1083] Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
9699| [CVE-2004-1082] mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
9700| [CVE-2004-0942] Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
9701| [CVE-2004-0940] Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
9702| [CVE-2004-0885] The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
9703| [CVE-2004-0811] Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
9704| [CVE-2004-0809] The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
9705| [CVE-2004-0786] The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
9706| [CVE-2004-0751] The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
9707| [CVE-2004-0748] mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
9708| [CVE-2004-0747] Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
9709| [CVE-2004-0700] Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
9710| [CVE-2004-0646] Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
9711| [CVE-2004-0529] The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.
9712| [CVE-2004-0493] The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
9713| [CVE-2004-0492] Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
9714| [CVE-2004-0490] cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.
9715| [CVE-2004-0488] Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
9716| [CVE-2004-0263] PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
9717| [CVE-2004-0174] Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
9718| [CVE-2004-0173] Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
9719| [CVE-2004-0113] Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
9720| [CVE-2004-0009] Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.
9721| [CVE-2003-1581] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
9722| [CVE-2003-1580] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
9723| [CVE-2003-1573] The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."
9724| [CVE-2003-1521] Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
9725| [CVE-2003-1516] The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
9726| [CVE-2003-1502] mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.
9727| [CVE-2003-1418] Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child proccess IDs (PID).
9728| [CVE-2003-1307] ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."
9729| [CVE-2003-1172] Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
9730| [CVE-2003-1171] Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.
9731| [CVE-2003-1138] The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
9732| [CVE-2003-1054] mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.
9733| [CVE-2003-0993] mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
9734| [CVE-2003-0987] mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
9735| [CVE-2003-0866] The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
9736| [CVE-2003-0844] mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.
9737| [CVE-2003-0843] Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.
9738| [CVE-2003-0789] mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
9739| [CVE-2003-0771] Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.
9740| [CVE-2003-0658] Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
9741| [CVE-2003-0542] Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
9742| [CVE-2003-0460] The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
9743| [CVE-2003-0254] Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
9744| [CVE-2003-0253] The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
9745| [CVE-2003-0249] ** DISPUTED ** PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."
9746| [CVE-2003-0245] Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
9747| [CVE-2003-0192] Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
9748| [CVE-2003-0189] The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
9749| [CVE-2003-0134] Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.
9750| [CVE-2003-0132] A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.
9751| [CVE-2003-0083] Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
9752| [CVE-2003-0020] Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
9753| [CVE-2003-0017] Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.
9754| [CVE-2003-0016] Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
9755| [CVE-2002-2310] ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
9756| [CVE-2002-2309] php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
9757| [CVE-2002-2272] Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
9758| [CVE-2002-2103] Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
9759| [CVE-2002-2029] PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
9760| [CVE-2002-2012] Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
9761| [CVE-2002-2009] Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
9762| [CVE-2002-2008] Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.
9763| [CVE-2002-2007] The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
9764| [CVE-2002-2006] The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
9765| [CVE-2002-1895] The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
9766| [CVE-2002-1850] mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
9767| [CVE-2002-1793] HTTP Server mod_ssl module running on HP-UX 11.04 with Virtualvault OS (VVOS) 4.5 through 4.6 closes the connection when the Apache server times out during an SSL request, which may allow attackers to cause a denial of service.
9768| [CVE-2002-1658] Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
9769| [CVE-2002-1635] The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin.
9770| [CVE-2002-1593] mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.
9771| [CVE-2002-1592] The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.
9772| [CVE-2002-1567] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
9773| [CVE-2002-1394] Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
9774| [CVE-2002-1233] A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
9775| [CVE-2002-1157] Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
9776| [CVE-2002-1156] Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
9777| [CVE-2002-1148] The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
9778| [CVE-2002-0935] Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
9779| [CVE-2002-0843] Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
9780| [CVE-2002-0840] Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
9781| [CVE-2002-0839] The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
9782| [CVE-2002-0682] Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
9783| [CVE-2002-0661] Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
9784| [CVE-2002-0658] OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.
9785| [CVE-2002-0654] Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
9786| [CVE-2002-0653] Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
9787| [CVE-2002-0513] The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.
9788| [CVE-2002-0493] Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
9789| [CVE-2002-0392] Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
9790| [CVE-2002-0259] InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.
9791| [CVE-2002-0249] PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
9792| [CVE-2002-0240] PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
9793| [CVE-2002-0082] The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
9794| [CVE-2002-0061] Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
9795| [CVE-2001-1556] The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
9796| [CVE-2001-1534] mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
9797| [CVE-2001-1510] Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.
9798| [CVE-2001-1449] The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
9799| [CVE-2001-1385] The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
9800| [CVE-2001-1342] Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
9801| [CVE-2001-1217] Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
9802| [CVE-2001-1216] Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
9803| [CVE-2001-1072] Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
9804| [CVE-2001-1013] Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
9805| [CVE-2001-0925] The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
9806| [CVE-2001-0829] A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
9807| [CVE-2001-0766] Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
9808| [CVE-2001-0731] Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
9809| [CVE-2001-0730] split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
9810| [CVE-2001-0729] Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
9811| [CVE-2001-0590] Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
9812| [CVE-2001-0131] htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
9813| [CVE-2001-0108] PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
9814| [CVE-2001-0042] PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
9815| [CVE-2000-1247] The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
9816| [CVE-2000-1210] Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
9817| [CVE-2000-1206] Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
9818| [CVE-2000-1205] Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.
9819| [CVE-2000-1204] Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
9820| [CVE-2000-1168] IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
9821| [CVE-2000-1016] The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
9822| [CVE-2000-0913] mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
9823| [CVE-2000-0883] The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.
9824| [CVE-2000-0869] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method.
9825| [CVE-2000-0868] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
9826| [CVE-2000-0791] Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.
9827| [CVE-2000-0760] The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
9828| [CVE-2000-0759] Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
9829| [CVE-2000-0628] The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.
9830| [CVE-2000-0505] The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
9831| [CVE-1999-1412] A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
9832| [CVE-1999-1293] mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
9833| [CVE-1999-1237] Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
9834| [CVE-1999-1199] Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
9835| [CVE-1999-1053] guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
9836| [CVE-1999-0926] Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
9837| [CVE-1999-0678] A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
9838| [CVE-1999-0448] IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
9839| [CVE-1999-0289] The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
9840| [CVE-1999-0236] ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
9841| [CVE-1999-0107] Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
9842| [CVE-1999-0071] Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
9843|
9844| SecurityFocus - https://www.securityfocus.com/bid/:
9845| [104554] Apache HBase CVE-2018-8025 Security Bypass Vulnerability
9846| [104465] Apache Geode CVE-2017-15695 Remote Code Execution Vulnerability
9847| [104418] Apache Storm CVE-2018-8008 Arbitrary File Write Vulnerability
9848| [104399] Apache Storm CVE-2018-1332 User Impersonation Vulnerability
9849| [104348] Apache UIMA CVE-2017-15691 XML External Entity Injection Vulnerability
9850| [104313] Apache NiFi XML External Entity Injection and Denial of Service Vulnerability
9851| [104259] Apache Geode CVE-2017-12622 Authorization Bypass Vulnerability
9852| [104257] Apache Sling XSS Protection API CVE-2017-15717 Cross Site Scripting Vulnerability
9853| [104253] Apache ZooKeeper CVE-2018-8012 Security Bypass Vulnerability
9854| [104252] Apache Batik CVE-2018-8013 Information Disclosure Vulnerability
9855| [104239] Apache Solr CVE-2018-8010 XML External Entity Multiple Information Disclosure Vulnerabilities
9856| [104215] Apache ORC CVE-2018-8015 Denial of Service Vulnerability
9857| [104203] Apache Tomcat CVE-2018-8014 Security Bypass Vulnerability
9858| [104161] Apache Ambari CVE-2018-8003 Directory Traversal Vulnerability
9859| [104140] Apache Derby CVE-2018-1313 Security Bypass Vulnerability
9860| [104135] Apache Tika CVE-2018-1338 Denial of Service Vulnerability
9861| [104008] Apache Fineract CVE-2018-1291 SQL Injection Vulnerability
9862| [104007] Apache Fineract CVE-2018-1292 SQL Injection Vulnerability
9863| [104005] Apache Fineract CVE-2018-1289 SQL Injection Vulnerability
9864| [104001] Apache Tika CVE-2018-1335 Remote Command Injection Vulnerability
9865| [103975] Apache Fineract CVE-2018-1290 SQL Injection Vulnerability
9866| [103974] Apache Solr CVE-2018-1308 XML External Entity Injection Vulnerability
9867| [103772] Apache Traffic Server CVE-2017-7671 Denial of Service Vulnerability
9868| [103770] Apache Traffic Server CVE-2017-5660 Security Bypass Vulnerability
9869| [103751] Apache Hive CVE-2018-1282 SQL Injection Vulnerability
9870| [103750] Apache Hive CVE-2018-1284 Security Bypass Vulnerability
9871| [103692] Apache Ignite CVE-2018-1295 Arbitrary Code Execution Vulnerability
9872| [103528] Apache HTTP Server CVE-2018-1302 Denial of Service Vulnerability
9873| [103525] Apache HTTP Server CVE-2017-15715 Remote Security Bypass Vulnerability
9874| [103524] Apache HTTP Server CVE-2018-1312 Remote Security Bypass Vulnerability
9875| [103522] Apache HTTP Server CVE-2018-1303 Denial of Service Vulnerability
9876| [103520] Apache HTTP Server CVE-2018-1283 Remote Security Vulnerability
9877| [103516] Apache Struts CVE-2018-1327 Denial of Service Vulnerability
9878| [103515] Apache HTTP Server CVE-2018-1301 Denial of Service Vulnerability
9879| [103512] Apache HTTP Server CVE-2017-15710 Denial of Service Vulnerability
9880| [103508] Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
9881| [103507] Apache Syncope CVE-2018-1322 Multiple Information Disclosure Vulnerabilities
9882| [103490] Apache Commons Compress CVE-2018-1324 Multiple Denial Of Service Vulnerabilities
9883| [103434] APACHE Allura CVE-2018-1319 HTTP Response Splitting Vulnerability
9884| [103389] Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
9885| [103222] Apache CloudStack CVE-2013-4317 Information Disclosure Vulnerability
9886| [103219] Apache Xerces-C CVE-2017-12627 Null Pointer Dereference Denial of Service Vulnerability
9887| [103206] Apache Geode CVE-2017-15693 Remote Code Execution Vulnerability
9888| [103205] Apache Geode CVE-2017-15692 Remote Code Execution Vulnerability
9889| [103170] Apache Tomcat CVE-2018-1304 Security Bypass Vulnerability
9890| [103144] Apache Tomcat CVE-2018-1305 Security Bypass Vulnerability
9891| [103102] Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
9892| [103098] Apache Karaf CVE-2016-8750 LDAP Injection Vulnerability
9893| [103069] Apache Tomcat CVE-2017-15706 Remote Security Weakness
9894| [103068] Apache JMeter CVE-2018-1287 Security Bypass Vulnerability
9895| [103067] Apache Qpid Dispatch Router 'router_core/connections.c' Denial of Service Vulnerability
9896| [103036] Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
9897| [103025] Apache Thrift CVE-2016-5397 Remote Command Injection Vulnerability
9898| [102879] Apache POI CVE-2017-12626 Multiple Denial of Service Vulnerabilities
9899| [102842] Apache NiFi CVE-2017-12632 Host Header Injection Vulnerability
9900| [102815] Apache NiFi CVE-2017-15697 Multiple Cross Site Scripting Vulnerabilities
9901| [102488] Apache Geode CVE-2017-9795 Remote Code Execution Vulnerability
9902| [102229] Apache Sling CVE-2017-15700 Information Disclosure Vulnerability
9903| [102226] Apache Drill CVE-2017-12630 Cross Site Scripting Vulnerability
9904| [102154] Multiple Apache Products CVE-2017-15708 Remote Code Execution Vulnerability
9905| [102127] Apache CXF Fediz CVE-2017-12631 Multiple Cross Site Request Forgery Vulnerabilities
9906| [102041] Apache Qpid Broker-J CVE-2017-15701 Denial of Service Vulnerability
9907| [102040] Apache Qpid Broker CVE-2017-15702 Security Weakness
9908| [102021] Apache Struts CVE-2017-15707 Denial of Service Vulnerability
9909| [101980] EMC RSA Authentication Agent for Web: Apache Web Server Authentication Bypass Vulnerability
9910| [101876] Apache Camel CVE-2017-12634 Deserialization Remote Code Execution Vulnerability
9911| [101874] Apache Camel CVE-2017-12633 Deserialization Remote Code Execution Vulnerability
9912| [101872] Apache Karaf CVE-2014-0219 Local Denial of Service Vulnerability
9913| [101868] Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
9914| [101859] Apache CXF CVE-2017-12624 Denial of Service Vulnerability
9915| [101844] Apache Sling Servlets Post CVE-2017-11296 Cross Site Scripting Vulnerability
9916| [101686] Apache Hive CVE-2017-12625 Information Disclosure Vulnerability
9917| [101644] Apache Wicket CVE-2012-5636 Cross Site Scripting Vulnerability
9918| [101631] Apache Traffic Server CVE-2015-3249 Multiple Remote Code Execution Vulnerabilities
9919| [101630] Apache Traffic Server CVE-2014-3624 Access Bypass Vulnerability
9920| [101625] Apache jUDDI CVE-2009-1197 Security Bypass Vulnerability
9921| [101623] Apache jUDDI CVE-2009-1198 Cross Site Scripting Vulnerability
9922| [101620] Apache Subversion 'libsvn_fs_fs/fs_fs.c' Denial of Service Vulnerability
9923| [101585] Apache OpenOffice Multiple Remote Code Execution Vulnerabilities
9924| [101577] Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
9925| [101575] Apache Wicket CVE-2014-0043 Information Disclosure Vulnerability
9926| [101570] Apache Geode CVE-2017-9797 Information Disclosure Vulnerability
9927| [101562] Apache Derby CVE-2010-2232 Arbitrary File Overwrite Vulnerability
9928| [101560] Apache Portable Runtime Utility CVE-2017-12613 Multiple Information Disclosure Vulnerabilities
9929| [101558] Apache Portable Runtime Utility Local Out-of-Bounds Read Denial of Service Vulnerability
9930| [101532] Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
9931| [101516] Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
9932| [101261] Apache Solr/Lucene CVE-2017-12629 Information Disclosure and Remote Code Execution Vulnerabilities
9933| [101230] Apache Roller CVE-2014-0030 XML External Entity Injection Vulnerability
9934| [101173] Apache IMPALA CVE-2017-9792 Information Disclosure Vulnerability
9935| [101052] Apache Commons Jelly CVE-2017-12621 Security Bypass Vulnerability
9936| [101027] Apache Mesos CVE-2017-7687 Denial of Service Vulnerability
9937| [101023] Apache Mesos CVE-2017-9790 Denial of Service Vulnerability
9938| [100954] Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
9939| [100946] Apache Wicket CVE-2014-7808 Cross Site Request Forgery Vulnerability
9940| [100901] Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability
9941| [100897] Apache Tomcat CVE-2017-12616 Information Disclosure Vulnerability
9942| [100880] Apache Directory LDAP API CVE-2015-3250 Unspecified Information Disclosure Vulnerability
9943| [100872] Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
9944| [100870] Apache Solr CVE-2017-9803 Remote Privilege Escalation Vulnerability
9945| [100859] puppetlabs-apache CVE-2017-2299 Information Disclosure Vulnerability
9946| [100829] Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
9947| [100823] Apache Spark CVE-2017-12612 Deserialization Remote Code Execution Vulnerability
9948| [100612] Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
9949| [100611] Apache Struts CVE-2017-9793 Denial of Service Vulnerability
9950| [100609] Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
9951| [100587] Apache Atlas CVE-2017-3155 Cross Frame Scripting Vulnerability
9952| [100581] Apache Atlas CVE-2017-3154 Information Disclosure Vulnerability
9953| [100578] Apache Atlas CVE-2017-3153 Cross Site Scripting Vulnerability
9954| [100577] Apache Atlas CVE-2017-3152 Cross Site Scripting Vulnerability
9955| [100547] Apache Atlas CVE-2017-3151 HTML Injection Vulnerability
9956| [100536] Apache Atlas CVE-2017-3150 Cross Site Scripting Vulnerability
9957| [100449] Apache Pony Mail CVE-2016-4460 Authentication Bypass Vulnerability
9958| [100447] Apache2Triad Multiple Security Vulnerabilities
9959| [100284] Apache Sling Servlets Post CVE-2017-9802 Cross Site Scripting Vulnerability
9960| [100280] Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
9961| [100259] Apache Subversion CVE-2017-9800 Remote Command Execution Vulnerability
9962| [100256] Apache Tomcat CVE-2017-7675 Directory Traversal Vulnerability
9963| [100235] Apache Storm CVE-2017-9799 Remote Code Execution Vulnerability
9964| [100082] Apache Commons Email CVE-2017-9801 SMTP Header Injection Vulnerability
9965| [99873] Apache Sling XSS Protection API CVE-2016-6798 XML External Entity Injection Vulnerability
9966| [99870] Apache Sling API CVE-2016-5394 Cross Site Scripting Vulnerability
9967| [99603] Apache Spark CVE-2017-7678 Cross Site Scripting Vulnerability
9968| [99592] Apache OpenMeetings CVE-2017-7685 Security Bypass Vulnerability
9969| [99587] Apache OpenMeetings CVE-2017-7673 Security Bypass Vulnerability
9970| [99586] Apache OpenMeetings CVE-2017-7688 Security Bypass Vulnerability
9971| [99584] Apache OpenMeetings CVE-2017-7684 Denial of Service Vulnerability
9972| [99577] Apache OpenMeetings CVE-2017-7663 Cross Site Scripting Vulnerability
9973| [99576] Apache OpenMeetings CVE-2017-7664 XML External Entity Injection Vulnerability
9974| [99569] Apache HTTP Server CVE-2017-9788 Memory Corruption Vulnerability
9975| [99568] Apache HTTP Server CVE-2017-9789 Denial of Service Vulnerability
9976| [99563] Apache Struts CVE-2017-7672 Denial of Service Vulnerability
9977| [99562] Apache Struts Spring AOP Functionality Denial of Service Vulnerability
9978| [99509] Apache Impala CVE-2017-5652 Information Disclosure Vulnerability
9979| [99508] Apache IMPALA CVE-2017-5640 Authentication Bypass Vulnerability
9980| [99486] Apache Traffic Control CVE-2017-7670 Denial of Service Vulnerability
9981| [99485] Apache Solr CVE-2017-7660 Security Bypass Vulnerability
9982| [99484] Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
9983| [99292] Apache Ignite CVE-2017-7686 Information Disclosure Vulnerability
9984| [99170] Apache HTTP Server CVE-2017-7679 Buffer Overflow Vulnerability
9985| [99137] Apache HTTP Server CVE-2017-7668 Denial of Service Vulnerability
9986| [99135] Apache HTTP Server CVE-2017-3167 Authentication Bypass Vulnerability
9987| [99134] Apache HTTP Server CVE-2017-3169 Denial of Service Vulnerability
9988| [99132] Apache HTTP Server CVE-2017-7659 Denial of Service Vulnerability
9989| [99112] Apache Thrift CVE-2015-3254 Denial of Service Vulnerability
9990| [99067] Apache Ranger CVE-2016-8751 HTML Injection Vulnerability
9991| [99018] Apache NiFi CVE-2017-7667 Cross Frame Scripting Vulnerability
9992| [99009] Apache NiFi CVE-2017-7665 Cross Site Scripting Vulnerability
9993| [98961] Apache Ranger CVE-2017-7677 Security Bypass Vulnerability
9994| [98958] Apache Ranger CVE-2017-7676 Security Bypass Vulnerability
9995| [98888] Apache Tomcat CVE-2017-5664 Security Bypass Vulnerability
9996| [98814] Apache Zookeeper CVE-2017-5637 Denial of Service Vulnerability
9997| [98795] Apache Hadoop CVE-2017-7669 Remote Privilege Escalation Vulnerability
9998| [98739] Apache Knox CVE-2017-5646 User Impersonation Vulnerability
9999| [98669] Apache Hive CVE-2016-3083 Security Bypass Vulnerability
10000| [98646] Apache Atlas CVE-2016-8752 Information Disclosure Vulnerability
10001| [98570] Apache Archiva CVE-2017-5657 Multiple Cross-Site Request Forgery Vulnerabilities
10002| [98489] Apache CXF Fediz CVE-2017-7661 Multiple Cross Site Request Forgery Vulnerabilities
10003| [98485] Apache CXF Fediz CVE-2017-7662 Cross Site Request Forgery Vulnerability
10004| [98466] Apache Ambari CVE-2017-5655 Insecure Temporary File Handling Vulnerability
10005| [98365] Apache Cordova For Android CVE-2016-6799 Information Disclosure Vulnerability
10006| [98025] Apache Hadoop CVE-2017-3161 Cross Site Scripting Vulnerability
10007| [98017] Apache Hadoop CVE-2017-3162 Input Validation Vulnerability
10008| [97971] Apache CXF CVE-2017-5656 Information Disclosure Vulnerability
10009| [97968] Apache CXF CVE-2017-5653 Spoofing Vulnerability
10010| [97967] Apache ActiveMQ CVE-2015-7559 Denial of Service Vulnerability
10011| [97949] Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
10012| [97948] Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
10013| [97947] Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
10014| [97945] Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
10015| [97702] Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
10016| [97582] Apache CXF CVE-2016-6812 Cross Site Scripting Vulnerability
10017| [97579] Apache CXF JAX-RS CVE-2016-8739 XML External Entity Injection Vulnerability
10018| [97544] Apache Tomcat CVE-2017-5651 Information Disclosure Vulnerability
10019| [97531] Apache Tomcat CVE-2017-5650 Denial of Service Vulnerability
10020| [97530] Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
10021| [97509] Apache Ignite CVE-2016-6805 Information Disclosure and XML External Entity Injection Vulnerabilities
10022| [97383] Apache Flex BlazeDS CVE-2017-5641 Remote Code Execution Vulnerability
10023| [97378] Apache Geode CVE-2017-5649 Information Disclosure Vulnerability
10024| [97229] Apache Ambari CVE-2016-4976 Local Information Disclosure Vulnerability
10025| [97226] Apache Camel CVE-2017-5643 Server Side Request Forgery Security Bypass Vulnerability
10026| [97184] Apache Ambari CVE-2016-6807 Remote Command Execution Vulnerability
10027| [97179] Apache Camel CVE-2016-8749 Java Deserialization Multiple Remote Code Execution Vulnerabilities
10028| [96983] Apache POI CVE-2017-5644 Denial Of Service Vulnerability
10029| [96895] Apache Tomcat CVE-2016-8747 Information Disclosure Vulnerability
10030| [96731] Apache NiFi CVE-2017-5636 Remote Code Injection Vulnerability
10031| [96730] Apache NiFi CVE-2017-5635 Security Bypass Vulnerability
10032| [96729] Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
10033| [96540] IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
10034| [96398] Apache CXF CVE-2017-3156 Information Disclosure Vulnerability
10035| [96321] Apache Camel CVE-2017-3159 Remote Code Execution Vulnerability
10036| [96293] Apache Tomcat 'http11/AbstractInputBuffer.java' Denial of Service Vulnerability
10037| [96228] Apache Brooklyn Cross Site Request Forgery and Multiple Cross Site Scripting Vulnerabilities
10038| [95998] Apache Ranger CVE-2016-8746 Security Bypass Vulnerability
10039| [95929] Apache Groovy CVE-2016-6497 Information Disclosure Vulnerability
10040| [95838] Apache Cordova For Android CVE-2017-3160 Man in the Middle Security Bypass Vulnerability
10041| [95675] Apache Struts Remote Code Execution Vulnerability
10042| [95621] Apache NiFi CVE-2106-8748 Cross Site Scripting Vulnerability
10043| [95429] Apache Groovy CVE-2016-6814 Remote Code Execution Vulnerability
10044| [95335] Apache Hadoop CVE-2016-3086 Information Disclosure Vulnerability
10045| [95168] Apache Wicket CVE-2016-6793 Denial of Service Vulnerability
10046| [95136] Apache Qpid Broker for Java CVE-2016-8741 Remote Information Disclosure Vulnerability
10047| [95078] Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
10048| [95077] Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
10049| [95076] Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
10050| [95020] Apache Tika CVE-2015-3271 Remote Information Disclosure Vulnerability
10051| [94950] Apache Hadoop CVE-2016-5001 Local Information Disclosure Vulnerability
10052| [94882] Apache ActiveMQ CVE-2016-6810 HTML Injection Vulnerability
10053| [94828] Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
10054| [94766] Apache CouchDB CVE-2016-8742 Local Privilege Escalation Vulnerability
10055| [94657] Apache Struts CVE-2016-8738 Denial of Service Vulnerability
10056| [94650] Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
10057| [94588] Apache Subversion CVE-2016-8734 XML External Entity Denial of Service Vulnerability
10058| [94513] Apache Karaf CVE-2016-8648 Remote Code Execution Vulnerability
10059| [94463] Apache Tomcat CVE-2016-8735 Remote Code Execution Vulnerability
10060| [94462] Apache Tomcat CVE-2016-6817 Denial of Service Vulnerability
10061| [94461] Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
10062| [94418] Apache OpenOffice CVE-2016-6803 Local Privilege Escalation Vulnerability
10063| [94247] Apache Tika CVE-2016-6809 Remote Code Execution Vulnerability
10064| [94221] Apache Ranger CVE-2016-6815 Local Privilege Escalation Vulnerability
10065| [94145] Apache OpenMeetings CVE-2016-8736 Remote Code Execution Vulnerability
10066| [93945] Apache CloudStack CVE-2016-6813 Authorization Bypass Vulnerability
10067| [93944] Apache Tomcat Security Manager CVE-2016-6796 Security Bypass Vulnerability
10068| [93943] Apache Tomcat CVE-2016-6794 Security Bypass Vulnerability
10069| [93942] Apache Tomcat Security Manager CVE-2016-5018 Security Bypass Vulnerability
10070| [93940] Apache Tomcat CVE-2016-6797 Security Bypass Vulnerability
10071| [93939] Apache Tomcat CVE-2016-0762 Information Disclosure Vulnerability
10072| [93774] Apache OpenOffice CVE-2016-6804 DLL Loading Remote Code Execution Vulnerability
10073| [93773] Apache Struts CVE-2016-6795 Directory Traversal Vulnerability
10074| [93478] Apache Tomcat CVE-2016-6325 Local Privilege Escalation Vulnerability
10075| [93472] Apache Tomcat CVE-2016-5425 Insecure File Permissions Vulnerability
10076| [93429] Apache Tomcat JK Connector CVE-2016-6808 Remote Buffer Overflow Vulnerability
10077| [93263] Apache Tomcat CVE-2016-1240 Local Privilege Escalation Vulnerability
10078| [93236] Apache MyFaces Trinidad CVE-2016-5019 Remote Code Execution Vulnerability
10079| [93142] Apache ActiveMQ Artemis CVE-2016-4978 Remote Code Execution Vulnerability
10080| [93132] Apache Derby CVE-2015-1832 XML External Entity Information Disclosure Vulnerability
10081| [93044] Apache Zookeeper CVE-2016-5017 Buffer Overflow Vulnerability
10082| [92966] Apache Jackrabbit CVE-2016-6801 Cross-Site Request Forgery Vulnerability
10083| [92947] Apache Shiro CVE-2016-6802 Remote Security Bypass Vulnerability
10084| [92905] Apache CXF Fediz CVE-2016-4464 Security Bypass Vulnerability
10085| [92577] Apache Ranger CVE-2016-5395 HTML Injection Vulnerability
10086| [92331] Apache HTTP Server CVE-2016-1546 Remote Denial of Service Vulnerability
10087| [92328] Apache Hive CVE-2016-0760 Multiple Remote Code Execution Vulnerabilities
10088| [92320] Apache APR-util and httpd CVE-2016-6312 Denial of Service Vulnerability
10089| [92100] Apache POI CVE-2016-5000 XML External Entity Injection Vulnerability
10090| [92079] Apache OpenOffice CVE-2016-1513 Remote Code Execution Vulnerability
10091| [91818] Apache Tomcat CVE-2016-5388 Security Bypass Vulnerability
10092| [91816] Apache HTTP Server CVE-2016-5387 Security Bypass Vulnerability
10093| [91788] Apache Qpid Proton CVE-2016-4467 Certificate Verification Security Bypass Vulnerability
10094| [91738] Apache XML-RPC CVE-2016-5003 Remote Code Execution Vulnerability
10095| [91736] Apache XML-RPC Multiple Security Vulnerabilities
10096| [91707] Apache Archiva CVE-2016-5005 HTML Injection Vulnerability
10097| [91703] Apache Archiva CVE-2016-4469 Multiple Cross-Site Request Forgery Vulnerabilities
10098| [91566] Apache HTTP Server CVE-2016-4979 Authentication Bypass Vulnerability
10099| [91537] Apache QPID CVE-2016-4974 Deserialization Security Bypass Vulnerability
10100| [91501] Apache Xerces-C CVE-2016-4463 Stack Buffer Overflow Vulnerability
10101| [91453] Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
10102| [91284] Apache Struts CVE-2016-4431 Security Bypass Vulnerability
10103| [91282] Apache Struts CVE-2016-4433 Security Bypass Vulnerability
10104| [91281] Apache Struts CVE-2016-4430 Cross-Site Request Forgery Vulnerability
10105| [91280] Apache Struts CVE-2016-4436 Security Bypass Vulnerability
10106| [91278] Apache Struts CVE-2016-4465 Denial of Service Vulnerability
10107| [91277] Apache Struts Incomplete Fix Remote Code Execution Vulnerability
10108| [91275] Apache Struts CVE-2016-4438 Remote Code Execution Vulnerability
10109| [91217] Apache Continuum 'saveInstallation.action' Command Execution Vulnerability
10110| [91141] Apache CloudStack CVE-2016-3085 Authentication Bypass Vulnerability
10111| [91068] Apache Struts CVE-2016-1181 Remote Code Execution Vulnerability
10112| [91067] Apache Struts CVE-2016-1182 Security Bypass Vulnerability
10113| [91024] Apache Shiro CVE-2016-4437 Information Disclosure Vulnerability
10114| [90988] Apache Ranger CVE-2016-2174 SQL Injection Vulnerability
10115| [90961] Apache Struts CVE-2016-3093 Denial of Service Vulnerability
10116| [90960] Apache Struts CVE-2016-3087 Remote Code Execution Vulnerability
10117| [90921] Apache Qpid CVE-2016-4432 Authentication Bypass Vulnerability
10118| [90920] Apache Qpid CVE-2016-3094 Denial of Service Vulnerability
10119| [90902] Apache PDFBox CVE-2016-2175 XML External Entity Injection Vulnerability
10120| [90897] Apache Tika CVE-2016-4434 XML External Entity Injection Vulnerability
10121| [90827] Apache ActiveMQ CVE-2016-3088 Multiple Arbitrary File Upload Vulnerabilities
10122| [90755] Apache Ambari CVE-2016-0707 Multiple Local Information Disclosure Vulnerabilities
10123| [90482] Apache CVE-2004-1387 Local Security Vulnerability
10124| [89762] Apache CVE-2001-1556 Remote Security Vulnerability
10125| [89417] Apache Subversion CVE-2016-2167 Authentication Bypass Vulnerability
10126| [89326] RETIRED: Apache Subversion CVE-2016-2167 Security Bypass Vulnerability
10127| [89320] Apache Subversion CVE-2016-2168 Remote Denial of Service Vulnerability
10128| [88826] Apache Struts CVE-2016-3082 Remote Code Execution Vulnerability
10129| [88797] Apache Cordova For iOS CVE-2015-5208 Arbitrary Code Execution Vulnerability
10130| [88764] Apache Cordova iOS CVE-2015-5207 Multiple Security Bypass Vulnerabilities
10131| [88701] Apache CVE-2001-1449 Remote Security Vulnerability
10132| [88635] Apache CVE-2000-1204 Remote Security Vulnerability
10133| [88590] Apache WWW server CVE-1999-1199 Denial-Of-Service Vulnerability
10134| [88496] Apache CVE-2000-1206 Remote Security Vulnerability
10135| [87828] Apache CVE-1999-1237 Remote Security Vulnerability
10136| [87784] Apache CVE-1999-1293 Denial-Of-Service Vulnerability
10137| [87327] Apache Struts CVE-2016-3081 Remote Code Execution Vulnerability
10138| [86622] Apache Stats CVE-2007-0975 Remote Security Vulnerability
10139| [86399] Apache CVE-2007-1743 Local Security Vulnerability
10140| [86397] Apache CVE-2007-1742 Local Security Vulnerability
10141| [86311] Apache Struts CVE-2016-4003 Cross Site Scripting Vulnerability
10142| [86174] Apache Wicket CVE-2015-5347 Cross Site Scripting Vulnerability
10143| [85971] Apache OFBiz CVE-2016-2170 Java Deserialization Remote Code Execution Vulnerability
10144| [85967] Apache OFBiz CVE-2015-3268 HTML Injection Vulnerability
10145| [85759] Apache Jetspeed CVE-2016-2171 Unauthorized Access Vulnerability
10146| [85758] Apache Jetspeed CVE-2016-0712 Cross Site Scripting Vulnerability
10147| [85756] Apache Jetspeed CVE-2016-0710 Multiple SQL Injection Vulnerabilities
10148| [85755] Apache Jetspeed CVE-2016-0711 Mulitple HTML Injection Vulnerabilities
10149| [85754] Apache Jetspeed CVE-2016-0709 Directory Traversal Vulnerability
10150| [85730] Apache Subversion CVE-2015-5343 Integer Overflow Vulnerability
10151| [85691] Apache Ranger CVE-2016-0735 Security Bypass Vulnerability
10152| [85578] Apache ActiveMQ CVE-2010-1244 Cross-Site Request Forgery Vulnerability
10153| [85554] Apache OpenMeetings CVE-2016-2164 Multiple Information Disclosure Vulnerabilities
10154| [85553] Apache OpenMeetings CVE-2016-0783 Information Disclosure Vulnerability
10155| [85552] Apache OpenMeetings CVE-2016-2163 HTML Injection Vulnerability
10156| [85550] Apache OpenMeetings CVE-2016-0784 Directory Traversal Vulnerability
10157| [85386] Apache Hadoop CVE-2015-7430 Local Privilege Escalation Vulnerability
10158| [85377] Apache Qpid Proton Python API CVE-2016-2166 Man in the Middle Security Bypass Vulnerability
10159| [85205] Apache Solr CVE-2015-8796 Cross Site Scripting Vulnerability
10160| [85203] Apache Solr CVE-2015-8795 Mulitple HTML Injection Vulnerabilities
10161| [85163] Apache Geronimo CVE-2008-0732 Local Security Vulnerability
10162| [85131] Apache Struts 'TextParseUtil.translateVariables()' Method Remote Code Execution Vulnerability
10163| [85070] Apache Struts CVE-2016-2162 Cross Site Scripting Vulnerability
10164| [85066] Apache Struts CVE-2016-0785 Remote Code Execution Vulnerability
10165| [84422] Apache TomEE CVE-2016-0779 Unspecified Security Vulnerability
10166| [84321] Apache ActiveMQ CVE-2016-0734 Clickjacking Vulnerability
10167| [84316] Apache ActiveMQ CVE-2016-0782 Multiple Cross Site Scripting Vulnerabilities
10168| [83910] Apache Wicket CVE-2015-7520 Cross Site Scripting Vulnerability
10169| [83423] Apache Xerces-C CVE-2016-0729 Buffer Overflow Vulnerability
10170| [83330] Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability
10171| [83329] Apache Tomcat CVE-2015-5174 Directory Traversal Vulnerability
10172| [83328] Apache Tomcat CVE-2015-5345 Directory Traversal Vulnerability
10173| [83327] Apache Tomcat Security Manager CVE-2016-0714 Remote Code Execution Vulnerability
10174| [83326] Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
10175| [83324] Apache Tomcat Security Manager CVE-2016-0706 Information Disclosure Vulnerability
10176| [83323] Apache Tomcat CVE-2015-5346 Session Fixation Vulnerability
10177| [83259] Apache Hadoop CVE-2015-1776 Information Disclosure Vulnerability
10178| [83243] Apache Solr CVE-2015-8797 Cross Site Scripting Vulnerability
10179| [83119] Apache Sling CVE-2016-0956 Information Disclosure Vulnerability
10180| [83002] Apache CVE-2000-1205 Cross-Site Scripting Vulnerability
10181| [82871] Apache Ranger Authentication Bypass and Security Bypass Vulnerabilities
10182| [82800] Apache CloudStack CVE-2015-3251 Information Disclosure Vulnerability
10183| [82798] Apache CloudStack CVE-2015-3252 Authentication Bypass Vulnerability
10184| [82732] Apache Gallery CVE-2003-0771 Local Security Vulnerability
10185| [82676] Apache CVE-2003-1581 Cross-Site Scripting Vulnerability
10186| [82550] Apache Struts CVE-2015-5209 Security Bypass Vulnerability
10187| [82300] Apache Subversion CVE-2015-5259 Integer Overflow Vulnerability
10188| [82260] Apache Camel CVE-2015-5344 Remote Code Execution Vulnerability
10189| [82234] Apache Hive CVE-2015-7521 Security Bypass Vulnerability
10190| [82082] Apache CVE-1999-0289 Remote Security Vulnerability
10191| [81821] Apache Distribution for Solaris CVE-2007-2080 SQL-Injection Vulnerability
10192| [80696] Apache Camel CVE-2015-5348 Information Disclosure Vulnerability
10193| [80525] Apache CVE-2003-1580 Remote Security Vulnerability
10194| [80354] Drupal Apache Solr Search Module Access Bypass Vulnerability
10195| [80193] Apache CVE-1999-0107 Denial-Of-Service Vulnerability
10196| [79812] Apache Directory Studio CVE-2015-5349 Command Injection Vulnerability
10197| [79744] Apache HBase CVE-2015-1836 Unauthorized Access Vulnerability
10198| [79204] Apache TomEE 'EjbObjectInputStream' Remote Code Execution Vulnerability
10199| [77679] Apache Cordova For Android CVE-2015-8320 Weak Randomization Security Bypass Vulnerability
10200| [77677] Apache Cordova For Android CVE-2015-5256 Security Bypass Vulnerability
10201| [77591] Apache CXF SAML SSO Processing CVE-2015-5253 Security Bypass Vulnerability
10202| [77521] Apache Commons Collections 'InvokerTransformer.java' Remote Code Execution Vulnerability
10203| [77110] Apache HttpComponents HttpClient CVE-2015-5262 Denial of Service Vulnerability
10204| [77086] Apache Ambari CVE-2015-1775 Server Side Request Forgery Security Bypass Vulnerability
10205| [77085] Apache Ambari CVE-2015-3270 Remote Privilege Escalation Vulnerability
10206| [77082] Apache Ambari 'targetURI' Parameter Open Redirection Vulnerability
10207| [77059] Apache Ambari CVE-2015-3186 Cross Site Scripting Vulnerability
10208| [76933] Apache James Server Unspecified Command Execution Vulnerability
10209| [76832] Apache cordova-plugin-file-transfer CVE-2015-5204 HTTP Header Injection Vulnerability
10210| [76625] Apache Struts CVE-2015-5169 Cross Site Scripting Vulnerability
10211| [76624] Apache Struts CVE-2015-2992 Cross Site Scripting Vulnerability
10212| [76522] Apache Tapestry CVE-2014-1972 Security Bypass Vulnerability
10213| [76486] Apache CXF Fediz CVE-2015-5175 Denial of Service Vulnerability
10214| [76452] Apache ActiveMQ CVE-2015-1830 Directory Traversal Vulnerability
10215| [76446] Apache Subversion 'libsvn_fs_fs/tree.c' Denial of Service Vulnerability
10216| [76274] Apache Subversion CVE-2015-3184 Information Disclosure Vulnerability
10217| [76273] Apache Subversion CVE-2015-3187 Information Disclosure Vulnerability
10218| [76272] Apache ActiveMQ CVE-2014-3576 Denial of Service Vulnerability
10219| [76221] Apache Ranger CVE-2015-0266 Access Bypass Vulnerability
10220| [76208] Apache Ranger CVE-2015-0265 JavaScript Code Injection Vulnerability
10221| [76025] Apache ActiveMQ Artemis CVE-2015-3208 XML External Entity Information Disclosure Vulnerability
10222| [75965] Apache HTTP Server CVE-2015-3185 Security Bypass Vulnerability
10223| [75964] Apache HTTP Server CVE-2015-0253 Remote Denial of Service Vulnerability
10224| [75963] Apache HTTP Server CVE-2015-3183 Security Vulnerability
10225| [75940] Apache Struts CVE-2015-1831 Security Bypass Vulnerability
10226| [75919] Apache Groovy CVE-2015-3253 Remote Code Execution Vulnerability
10227| [75338] Apache Storm CVE-2015-3188 Remote Code Execution Vulnerability
10228| [75275] Drupal Apache Solr Real-Time Module Access Bypass Vulnerability
10229| [74866] Apache Cordova For Android CVE-2015-1835 Security Bypass Vulnerability
10230| [74839] Apache Sling API and Sling Servlets CVE-2015-2944 Cross Site Scripting Vulnerability
10231| [74761] Apache Jackrabbit CVE-2015-1833 XML External Entity Information Disclosure Vulnerability
10232| [74686] Apache Ambari '/var/lib/ambari-server/ambari-env.sh' Local Privilege Escalation Vulnerability
10233| [74665] Apache Tomcat CVE-2014-7810 Security Bypass Vulnerability
10234| [74475] Apache Tomcat CVE-2014-0230 Denial of Service Vulnerability
10235| [74423] Apache Struts CVE-2015-0899 Security Bypass Vulnerability
10236| [74338] Apache OpenOffice HWP Filter Memory Corruption Vulnerability
10237| [74265] Apache Tomcat 'mod_jk' CVE-2014-8111 Information Disclosure Vulnerability
10238| [74260] Apache Subversion CVE-2015-0248 Multiple Denial of Service Vulnerabilities
10239| [74259] Apache Subversion 'deadprops.c' Security Bypass Vulnerability
10240| [74204] PHP 'sapi/apache2handler/sapi_apache2.c' Remote Code Execution Vulnerability
10241| [74158] Apache HTTP Server 'protocol.c' Remote Denial of Service Vulnerability
10242| [73954] Apache Flex 'asdoc/templates/index.html' Cross Site Scripting Vulnerability
10243| [73851] Apache2 CVE-2012-0216 Cross-Site Scripting Vulnerability
10244| [73478] Apache Cassandra CVE-2015-0225 Remote Code Execution Vulnerability
10245| [73041] Apache HTTP Server 'mod_lua' Module Denial of Service Vulnerability
10246| [73040] Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
10247| [72809] Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
10248| [72717] Apache Tomcat CVE-2014-0227 Chunk Request Remote Denial Of Service Vulnerability
10249| [72557] Apache WSS4J CVE-2015-0227 Security Bypass Vulnerability
10250| [72553] Apache WSS4J CVE-2015-0226 Information Disclosure Vulnerability
10251| [72513] Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
10252| [72511] Apache ActiveMQ CVE-2014-8110 Multiple Cross Site Scripting Vulnerabilities
10253| [72510] Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
10254| [72508] Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
10255| [72319] Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
10256| [72317] Apache Qpid CVE-2015-0224 Incomplete Fix Multiple Denial of Service Vulnerabilities
10257| [72115] Apache Santuario 'XML Signature Verification' Security Bypass Vulnerability
10258| [72053] Apache HTTP Server 'mod_remoteip.c' IP Address Spoofing Vulnerability
10259| [72030] Apache Qpid CVE-2015-0203 Multiple Denial of Service Vulnerabilities
10260| [71879] Apache Traffic Server 'HttpTransact.cc' Denial of Service Vulnerability
10261| [71726] Apache Subversion CVE-2014-3580 Remote Denial of Service Vulnerability
10262| [71725] Apache Subversion CVE-2014-8108 Remote Denial of Service Vulnerability
10263| [71657] Apache HTTP Server 'mod_proxy_fcgi' Module Denial of Service Vulnerability
10264| [71656] Apache HTTP Server 'mod_cache' Module Denial of Service Vulnerability
10265| [71548] Apache Struts CVE-2014-7809 Security Bypass Vulnerability
10266| [71466] Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
10267| [71353] Apache HTTP Server 'LuaAuthzProvider' Authorization Bypass Vulnerability
10268| [71004] Apache Qpid CVE-2014-3629 XML External Entity Injection Vulnerability
10269| [70970] Apache Traffic Server Cross Site Scripting Vulnerability
10270| [70738] Apache CXF CVE-2014-3584 Denial of Service Vulnerability
10271| [70736] Apache CXF SAML SubjectConfirmation Security Bypass Vulnerability
10272| [69728] Apache Tomcat CVE-2013-4444 Arbitrary File Upload Vulnerability
10273| [69648] Apache POI CVE-2014-3574 Denial Of Service Vulnerability
10274| [69647] Apache POI OpenXML parser CVE-2014-3529 XML External Entity Information Disclosure Vulnerability
10275| [69351] Apache OpenOffice Calc CVE-2014-3524 Command Injection Vulnerability
10276| [69295] Apache Axis Incomplete Fix CVE-2014-3596 SSL Certificate Validation Security Bypass Vulnerability
10277| [69286] Apache OFBiz CVE-2014-0232 Multiple Cross Site Scripting Vulnerabilities
10278| [69258] Apache HttpComponents Incomplete Fix CVE-2014-3577 SSL Validation Security Bypass Vulnerability
10279| [69257] Apache HttpComponents Incomplete Fix SSL Certificate Validation Security Bypass Vulnerability
10280| [69248] Apache HTTP Server CVE-2013-4352 Remote Denial of Service Vulnerability
10281| [69237] Apache Subversion CVE-2014-3522 SSL Certificate Validation Information Disclosure Vulnerability
10282| [69173] Apache Traffic Server CVE-2014-3525 Unspecified Security Vulnerability
10283| [69046] Apache Cordova For Android CVE-2014-3502 Information Disclosure Vulnerability
10284| [69041] Apache Cordova For Android CVE-2014-3501 Security Bypass Vulnerability
10285| [69038] Apache Cordova For Android CVE-2014-3500 Security Bypass Vulnerability
10286| [68995] Apache Subversion CVE-2014-3528 Insecure Authentication Weakness
10287| [68966] Apache Subversion 'irkerbridge.py' Local Privilege Escalation Vulnerability
10288| [68965] Apache Subversion 'svnwcsub.py' Local Privilege Escalation Vulnerability
10289| [68863] Apache HTTP Server 'mod_cache' Module Remote Denial of Service Vulnerability
10290| [68747] Apache HTTP Server CVE-2014-3523 Remote Denial of Service Vulnerability
10291| [68745] Apache HTTP Server CVE-2014-0118 Remote Denial of Service Vulnerability
10292| [68742] Apache HTTP Server CVE-2014-0231 Remote Denial of Service Vulnerability
10293| [68740] Apache HTTP Server CVE-2014-0117 Remote Denial of Service Vulnerability
10294| [68678] Apache HTTP Server 'mod_status' CVE-2014-0226 Remote Code Execution Vulnerability
10295| [68445] Apache CXF UsernameToken Information Disclosure Vulnerability
10296| [68441] Apache CXF SAML Tokens Validation Security Bypass Vulnerability
10297| [68431] Apache Syncope CVE-2014-3503 Insecure Password Generation Weakness
10298| [68229] Apache Harmony PRNG Entropy Weakness
10299| [68111] Apache 'mod_wsgi' Module Privilege Escalation Vulnerability
10300| [68072] Apache Tomcat CVE-2014-0186 Remote Denial of Service Vulnerability
10301| [68039] Apache Hive CVE-2014-0228 Security Bypass Vulnerability
10302| [67673] Apache Tomcat CVE-2014-0095 AJP Request Remote Denial Of Service Vulnerability
10303| [67671] Apache Tomcat CVE-2014-0075 Chunk Request Remote Denial Of Service Vulnerability
10304| [67669] Apache Tomcat CVE-2014-0119 XML External Entity Information Disclosure Vulnerability
10305| [67668] Apache Tomcat CVE-2014-0099 Request Processing Information Disclosure Vulnerability
10306| [67667] Apache Tomcat CVE-2014-0096 XML External Entity Information Disclosure Vulnerability
10307| [67534] Apache 'mod_wsgi' Module CVE-2014-0242 Information Disclosure Vulnerability
10308| [67532] Apache 'mod_wsgi' Module Local Privilege Escalation Vulnerability
10309| [67530] Apache Solr Search Template Cross Site Scripting Vulnerability
10310| [67236] Apache CXF CVE-2014-0109 Remote Denial of Service Vulnerability
10311| [67232] Apache CXF CVE-2014-0110 Denial of Service Vulnerability
10312| [67121] Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
10313| [67081] Apache Struts 'getClass()' Method Security Bypass Vulnerability
10314| [67064] Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
10315| [67013] Apache Zookeeper CVE-2014-0085 Local Information Disclosure Vulnerability
10316| [66998] Apache Archiva CVE-2013-2187 Unspecified Cross Site Scripting Vulnerability
10317| [66991] Apache Archiva CVE-2013-2187 HTML Injection Vulnerability
10318| [66927] Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
10319| [66474] Apache CouchDB Universally Unique IDentifier (UUID) Remote Denial of Service Vulnerability
10320| [66397] Apache Xalan-Java Library CVE-2014-0107 Security Bypass Vulnerability
10321| [66303] Apache HTTP Server Multiple Denial of Service Vulnerabilities
10322| [66041] RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
10323| [65999] Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability
10324| [65967] Apache Cordova File-Transfer Unspecified Security Vulnerability
10325| [65959] Apache Cordova InAppBrowser Remote Privilege Escalation Vulnerability
10326| [65935] Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
10327| [65902] Apache Camel CVE-2014-0003 Remote Code Execution Vulnerability
10328| [65901] Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
10329| [65773] Apache Tomcat CVE-2013-4286 Security Bypass Vulnerability
10330| [65769] Apache Tomcat CVE-2014-0033 Session Fixation Vulnerability
10331| [65768] Apache Tomcat CVE-2013-4590 XML External Entity Information Disclosure Vulnerability
10332| [65767] Apache Tomcat CVE-2013-4322 Incomplete Fix Denial of Service Vulnerability
10333| [65615] Apache ActiveMQ 'refresh' Parameter Cross Site Scripting Vulnerability
10334| [65434] Apache Subversion 'mod_dav_svn' Module SVNListParentPath Denial of Service Vulnerability
10335| [65431] Apache Wicket CVE-2013-2055 Information Disclosure Vulnerability
10336| [65400] Apache Commons FileUpload CVE-2014-0050 Denial Of Service Vulnerability
10337| [64782] Apache CloudStack Virtual Router Component Security Bypass Vulnerability
10338| [64780] Apache CloudStack Unauthorized Access Vulnerability
10339| [64617] Apache Libcloud Digital Ocean API Local Information Disclosure Vulnerability
10340| [64437] Apache Santuario XML Security For JAVA XML Signature Denial of Service Vulnerability
10341| [64427] Apache Solr Multiple XML External Entity Injection Vulnerabilities
10342| [64009] Apache Solr CVE-2013-6408 XML External Entity Injection Vulnerability
10343| [64008] Apache Solr CVE-2013-6407 XML External Entity Injection Vulnerability
10344| [63981] Apache Subversion 'mod_dav_svn' Module Denial of Service Vulnerability
10345| [63966] Apache Subversion CVE-2013-4505 Security Bypass Vulnerability
10346| [63963] Apache Roller CVE-2013-4171 Cross Site Scripting Vulnerability
10347| [63935] Apache Solr 'SolrResourceLoader' Directory Traversal Vulnerability
10348| [63928] Apache Roller CVE-2013-4212 OGNL Expression Injection Remote Code Execution Vulnerability
10349| [63515] Apache Tomcat Manager Component CVE-2013-6357 Cross Site Request Forgery Vulnerability
10350| [63403] Apache Struts Multiple Cross Site Scripting Vulnerabilities
10351| [63400] Apache 'mod_pagespeed' Module Unspecified Cross Site Scripting Vulnerability
10352| [63260] Apache Shindig CVE-2013-4295 XML External Entity Information Disclosure Vulnerability
10353| [63241] Apache Sling 'AbstractAuthenticationFormServlet' Open Redirection Vulnerability
10354| [63174] Apache Commons FileUpload 'DiskFileItem' Class Null Byte Arbitrary File Write Vulnerability
10355| [62939] Apache 'mod_fcgid' Module CVE-2013-4365 Heap Buffer Overflow Vulnerability
10356| [62903] Apache Sling 'deepGetOrCreateNode()' Function Denial Of Service Vulnerability
10357| [62706] Apache Camel CVE-2013-4330 Information Disclosure Vulnerability
10358| [62677] Apache 'mod_accounting' Module CVE-2013-5697 SQL Injection Vulnerability
10359| [62674] TYPO3 Apache Solr Unspecified Cross Site Scripting and PHP Code Execution Vulnerabilities
10360| [62587] Apache Struts CVE-2013-4316 Remote Code Execution Vulnerability
10361| [62584] Apache Struts CVE-2013-4310 Security Bypass Vulnerability
10362| [62266] Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
10363| [61984] Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
10364| [61981] Apache HBase RPC Authentication Man In The Middle Security Bypass Vulnerability
10365| [61638] Apache CloudStack CVE-2013-2136 Multiple Cross Site Scripting Vulnerabilities
10366| [61454] Apache Subversion CVE-2013-4131 Denial Of Service Vulnerability
10367| [61379] Apache HTTP Server CVE-2013-2249 Unspecified Remote Security Vulnerability
10368| [61370] Apache OFBiz CVE-2013-2317 'View Log' Cross Site Scripting Vulnerability
10369| [61369] Apache OFBiz Nested Expression Remote Code Execution Vulnerability
10370| [61196] Apache Struts CVE-2013-2248 Multiple Open Redirection Vulnerabilities
10371| [61189] Apache Struts CVE-2013-2251 Multiple Remote Command Execution Vulnerabilities
10372| [61129] Apache HTTP Server CVE-2013-1896 Remote Denial of Service Vulnerability
10373| [61030] Apache CXF CVE-2013-2160 Multiple Remote Denial of Service Vulnerabilities
10374| [60875] Apache Geronimo RMI Classloader Security Bypass Vulnerability
10375| [60846] Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
10376| [60817] Apache Santuario XML Security for C++ CVE-2013-2210 Heap Buffer Overflow Vulnerability
10377| [60800] Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
10378| [60599] Apache Santuario XML Security for C++ CVE-2013-2156 Remote Heap Buffer Overflow Vulnerability
10379| [60595] Apache Santuario XML Security for C++ XML Signature CVE-2013-2155 Denial of Service Vulnerability
10380| [60594] Apache Santuario XML Security for C++ CVE-2013-2154 Stack Buffer Overflow Vulnerability
10381| [60592] Apache Santuario XML Security for C++ XML Signature CVE-2013-2153 Security Bypass Vulnerability
10382| [60534] Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
10383| [60346] Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
10384| [60345] Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
10385| [60267] Apache Subversion CVE-2013-1968 Remote Denial of Service Vulnerability
10386| [60265] Apache Subversion CVE-2013-2088 Command Injection Vulnerability
10387| [60264] Apache Subversion CVE-2013-2112 Remote Denial of Service Vulnerability
10388| [60187] Apache Tomcat DIGEST Authentication CVE-2013-2051 Incomplete Fix Security Weakness
10389| [60186] Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
10390| [60167] Apache Struts 'includeParams' CVE-2013-2115 Incomplete Fix Security Bypass Vulnerability
10391| [60166] Apache Struts 'includeParams' CVE-2013-1966 Security Bypass Vulnerability
10392| [60082] Apache Struts 'ParameterInterceptor' Class OGNL CVE-2013-1965 Security Bypass Vulnerability
10393| [59826] Apache HTTP Server Terminal Escape Sequence in Logs Command Injection Vulnerability
10394| [59799] Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
10395| [59798] Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
10396| [59797] Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
10397| [59670] Apache VCL Multiple Input Validation Vulnerabilities
10398| [59464] Apache CloudStack CVE-2013-2758 Hash Information Disclosure Vulnerability
10399| [59463] Apache CloudStack CVE-2013-2756 Authentication Bypass Vulnerability
10400| [59402] Apache ActiveMQ CVE-2013-3060 Information Disclosure and Denial of Service Vulnerability
10401| [59401] Apache ActiveMQ CVE-2012-6551 Denial of Service Vulnerability
10402| [59400] Apache ActiveMQ CVE-2012-6092 Multiple Cross Site Scripting Vulnerabilities
10403| [58898] Apache Subversion CVE-2013-1884 Remote Denial of Service Vulnerability
10404| [58897] Apache Subversion 'mod_dav_svn/lock.c' Remote Denial of Service Vulnerability
10405| [58895] Apache Subversion 'mod_dav_svn' Remote Denial of Service Vulnerability
10406| [58455] Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
10407| [58379] Apache Qpid CVE-2012-4446 Authentication Bypass Vulnerability
10408| [58378] Apache Qpid CVE-2012-4460 Denial of Service Vulnerability
10409| [58376] Apache Qpid CVE-2012-4458 Denial of Service Vulnerability
10410| [58337] Apache Qpid CVE-2012-4459 Denial of Service Vulnerability
10411| [58326] Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
10412| [58325] Debian Apache HTTP Server CVE-2013-1048 Symlink Attack Local Privilege Escalation Vulnerability
10413| [58323] Apache Subversion 'svn_fs_file_length()' Remote Denial of Service Vulnerability
10414| [58165] Apache HTTP Server Multiple Cross Site Scripting Vulnerabilities
10415| [58136] Apache Maven CVE-2013-0253 SSL Certificate Validation Security Bypass Vulnerability
10416| [58124] Apache Tomcat 'log/logdir' Directory Insecure File Permissions Vulnerability
10417| [58073] Apache Commons HttpClient CVE-2012-5783 SSL Certificate Validation Security Bypass Vulnerability
10418| [57876] Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
10419| [57874] Apache CXF CVE-2012-5633 Security Bypass Vulnerability
10420| [57463] Apache OFBiz CVE-2013-0177 Multiple Cross Site Scripting Vulnerabilities
10421| [57425] Apache CXF CVE-2012-5786 SSL Certificate Validation Security Bypass Vulnerability
10422| [57321] Apache CouchDB CVE-2012-5650 Cross Site Scripting Vulnerability
10423| [57314] Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
10424| [57267] Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
10425| [57259] Apache CloudStack CVE-2012-5616 Local Information Disclosure Vulnerability
10426| [56814] Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
10427| [56813] Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
10428| [56812] Apache Tomcat CVE-2012-3546 Security Bypass Vulnerability
10429| [56753] Apache Apache HTTP Server 'mod_proxy_ajp Module Denial Of Service Vulnerability
10430| [56686] Apache Tomcat CVE-2012-5568 Denial of Service Vulnerability
10431| [56408] Apache Axis and Axis2/Java SSL Certificate Validation Security Bypass Vulnerability
10432| [56403] Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
10433| [56402] Apache Tomcat CVE-2012-2733 Denial of Service Vulnerability
10434| [56171] Apache OFBiz CVE-2012-3506 Unspecified Security Vulnerability
10435| [55876] Apache CloudStack CVE-2012-4501 Security Bypass Vulnerability
10436| [55628] Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
10437| [55608] Apache Qpid (qpidd) Denial of Service Vulnerability
10438| [55536] Apache 'mod_pagespeed' Module Cross Site Scripting and Security Bypass Vulnerabilities
10439| [55508] Apache Axis2 XML Signature Wrapping Security Vulnerability
10440| [55445] Apache Wicket CVE-2012-3373 Cross Site Scripting Vulnerability
10441| [55346] Apache Struts Cross Site Request Forgery and Denial of Service Vulnerabilities
10442| [55290] Drupal Apache Solr Autocomplete Module Cross Site Scripting Vulnerability
10443| [55165] Apache Struts2 Skill Name Remote Code Execution Vulnerability
10444| [55154] Apache 'mod-rpaf' Module Denial of Service Vulnerability
10445| [55131] Apache HTTP Server HTML-Injection And Information Disclosure Vulnerabilities
10446| [54954] Apache QPID NullAuthenticator Authentication Bypass Vulnerability
10447| [54798] Apache Libcloud Man In The Middle Vulnerability
10448| [54358] Apache Hadoop CVE-2012-3376 Information Disclosure Vulnerability
10449| [54341] Apache Sling CVE-2012-2138 Denial Of Service Vulnerability
10450| [54268] Apache Hadoop Symlink Attack Local Privilege Escalation Vulnerability
10451| [54189] Apache Roller Cross Site Request Forgery Vulnerability
10452| [54187] Apache Roller CVE-2012-2381 Cross Site Scripting Vulnerability
10453| [53880] Apache CXF Child Policies Security Bypass Vulnerability
10454| [53877] Apache CXF Elements Validation Security Bypass Vulnerability
10455| [53676] Apache Commons Compress and Apache Ant CVE-2012-2098 Denial Of Service Vulnerability
10456| [53487] Apache POI CVE-2012-0213 Denial Of Service Vulnerability
10457| [53455] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability
10458| [53305] Apache Qpid CVE-2011-3620 Unauthorized Access Security Bypass Vulnerability
10459| [53046] Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
10460| [53025] Apache OFBiz Unspecified Remote Code Execution Vulnerability
10461| [53023] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
10462| [52939] Apache Hadoop CVE-2012-1574 Unspecified User Impersonation Vulnerability
10463| [52702] Apache Struts2 'XSLTResult.java' Remote Arbitrary File Upload Vulnerability
10464| [52696] Apache Traffic Server HTTP Host Header Handling Heap Based Buffer Overflow Vulnerability
10465| [52680] Apache Wicket 'pageMapName' Parameter Cross Site Scripting Vulnerability
10466| [52679] Apache Wicket Hidden Files Information Disclosure Vulnerability
10467| [52565] Apache 'mod_fcgid' Module Denial Of Service Vulnerability
10468| [52146] TYPO3 Apache Solr Extension Unspecified Cross Site Scripting Vulnerability
10469| [51939] Apache MyFaces 'ln' Parameter Information Disclosure Vulnerability
10470| [51917] Apache APR Hash Collision Denial Of Service Vulnerability
10471| [51902] Apache Struts Multiple HTML Injection Vulnerabilities
10472| [51900] Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
10473| [51886] Apache CXF UsernameToken Policy Validation Security Bypass Vulnerability
10474| [51869] Apache HTTP Server CVE-2011-3639 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
10475| [51706] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
10476| [51705] Apache HTTP Server CVE-2012-0021 mod_log_config Denial Of Service Vulnerability
10477| [51628] Apache Struts 'ParameterInterceptor' Class OGNL (CVE-2011-3923) Security Bypass Vulnerability
10478| [51447] Apache Tomcat Parameter Handling Denial of Service Vulnerability
10479| [51442] Apache Tomcat Request Object Security Bypass Vulnerability
10480| [51407] Apache HTTP Server Scoreboard Local Security Bypass Vulnerability
10481| [51257] Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
10482| [51238] Apache Geronimo Hash Collision Denial Of Service Vulnerability
10483| [51200] Apache Tomcat Hash Collision Denial Of Service Vulnerability
10484| [50940] Apache Struts Session Tampering Security Bypass Vulnerability
10485| [50912] RETIRED: Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
10486| [50904] Apache ActiveMQ Failover Mechanism Remote Denial Of Service Vulnerability
10487| [50848] Apache MyFaces EL Expression Evaluation Security Bypass Vulnerability
10488| [50802] Apache HTTP Server 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
10489| [50639] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
10490| [50603] Apache Tomcat Manager Application Security Bypass Vulnerability
10491| [50494] Apache HTTP Server 'ap_pregsub()' Function Local Privilege Escalation Vulnerability
10492| [49957] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
10493| [49762] Apache Tomcat HTTP DIGEST Authentication Multiple Security Weaknesses
10494| [49728] Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
10495| [49616] Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
10496| [49470] Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
10497| [49353] Apache Tomcat AJP Protocol Security Bypass Vulnerability
10498| [49303] Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability
10499| [49290] Apache Wicket Cross Site Scripting Vulnerability
10500| [49147] Apache Tomcat CVE-2011-2481 Information Disclosure Vulnerability
10501| [49143] Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
10502| [48667] Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability
10503| [48653] Apache 'mod_authnz_external' Module SQL Injection Vulnerability
10504| [48611] Apache XML Security for C++ Signature Key Parsing Denial of Service Vulnerability
10505| [48456] Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability
10506| [48015] Apache Archiva Multiple Cross Site Request Forgery Vulnerabilities
10507| [48011] Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
10508| [47929] Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
10509| [47890] Apache Struts 'javatemplates' Plugin Multiple Cross Site Scripting Vulnerabilities
10510| [47886] Apache Tomcat SecurityConstraints Security Bypass Vulnerability
10511| [47820] Apache APR 'apr_fnmatch()' Denial of Service Vulnerability
10512| [47784] Apache Struts XWork 's:submit' HTML Tag Cross Site Scripting Vulnerability
10513| [47199] Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
10514| [47196] Apache Tomcat Login Constraints Security Bypass Vulnerability
10515| [46974] Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
10516| [46953] Apache MPM-ITK Module Security Weakness
10517| [46734] Subversion 'mod_dav_svn' Apache Server NULL Pointer Dereference Denial Of Service Vulnerability
10518| [46685] Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
10519| [46311] Apache Continuum and Archiva Cross Site Scripting Vulnerability
10520| [46177] Apache Tomcat SecurityManager Security Bypass Vulnerability
10521| [46174] Apache Tomcat HTML Manager Interface HTML Injection Vulnerability
10522| [46166] Apache Tomcat JVM Denial of Service Vulnerability
10523| [46164] Apache Tomcat NIO Connector Denial of Service Vulnerability
10524| [46066] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
10525| [45655] Apache Subversion Server Component Multiple Remote Denial Of Service Vulnerabilities
10526| [45123] Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Vulnerability
10527| [45095] Apache Archiva Cross Site Request Forgery Vulnerability
10528| [45015] Apache Tomcat 'sort' and 'orderBy' Parameters Cross Site Scripting Vulnerabilities
10529| [44900] Apache 'mod_fcgid' Module Unspecified Stack Buffer Overflow Vulnerability
10530| [44616] Apache Shiro Directory Traversal Vulnerability
10531| [44355] Apache MyFaces Encrypted View State Oracle Padding Security Vulnerability
10532| [44068] Apache::AuthenHook Local Information Disclosure Vulnerability
10533| [43862] Apache QPID SSL Connection Denial of Service Vulnerability
10534| [43673] Apache APR-util 'apr_brigade_split_line()' Denial of Service Vulnerability
10535| [43637] Apache XML-RPC SAX Parser Information Disclosure Vulnerability
10536| [43111] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
10537| [42637] Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
10538| [42501] Apache CouchDB Cross Site Request Forgery Vulnerability
10539| [42492] Apache CXF XML DTD Processing Security Vulnerability
10540| [42121] Apache SLMS Insufficient Quoting Cross Site Request Forgery Vulnerability
10541| [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
10542| [41963] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
10543| [41544] Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities
10544| [41076] Apache Axis2 '/axis2/axis2-admin' Session Fixation Vulnerability
10545| [40976] Apache Axis2 Document Type Declaration Processing Security Vulnerability
10546| [40827] Apache 'mod_proxy_http' Timeout Handling Information Disclosure Vulnerability
10547| [40343] Apache Axis2 'xsd' Parameter Directory Traversal Vulnerability
10548| [40327] Apache Axis2 'engagingglobally' Cross-Site Scripting Vulnerability
10549| [39771] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
10550| [39636] Apache ActiveMQ Source Code Information Disclosure Vulnerability
10551| [39635] Apache Tomcat Authentication Header Realm Name Information Disclosure Vulnerability
10552| [39538] Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
10553| [39489] Apache OFBiz Multiple Cross Site Scripting and HTML Injection Vulnerabilities
10554| [39119] Apache ActiveMQ 'createDestination.action' HTML Injection Vulnerability
10555| [38580] Apache Subrequest Handling Information Disclosure Vulnerability
10556| [38494] Apache 'mod_isapi' Memory Corruption Vulnerability
10557| [38491] Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
10558| [37966] Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability
10559| [37945] Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability
10560| [37944] Apache Tomcat WAR File Directory Traversal Vulnerability
10561| [37942] Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability
10562| [37149] Apache Tomcat 404 Error Page Cross Site Scripting Vulnerability
10563| [37027] RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
10564| [36990] Apache HTTP TRACE Cross Site Scripting Vulnerability
10565| [36954] Apache Tomcat Windows Installer Insecure Password Vulnerability
10566| [36889] TYPO3 Apache Solr Search Extension Unspecified Cross Site Scripting Vulnerability
10567| [36596] Apache HTTP Server Solaris Event Port Pollset Support Remote Denial Of Service Vulnerability
10568| [36260] Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
10569| [36254] Apache mod_proxy_ftp Remote Command Injection Vulnerability
10570| [35949] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
10571| [35840] Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
10572| [35623] Apache 'mod_deflate' Remote Denial Of Service Vulnerability
10573| [35565] Apache 'mod_proxy' Remote Denial Of Service Vulnerability
10574| [35416] Apache Tomcat XML Parser Information Disclosure Vulnerability
10575| [35263] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
10576| [35253] Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
10577| [35251] Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
10578| [35221] Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
10579| [35196] Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness
10580| [35193] Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability
10581| [35115] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
10582| [34686] Apache Struts Multiple Cross Site Scripting Vulnerabilities
10583| [34663] Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
10584| [34657] Apache Tiles Cross Site Scripting And Information Disclosure Vulnerabilities
10585| [34562] Apache Geronimo Application Server Multiple Remote Vulnerabilities
10586| [34552] Apache ActiveMQ Web Console Multiple Unspecified HTML Injection Vulnerabilities
10587| [34412] Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability
10588| [34399] Apache Struts Unspecified Cross Site Scripting Vulnerability
10589| [34383] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
10590| [33913] Apache Tomcat POST Data Information Disclosure Vulnerability
10591| [33360] Apache Jackrabbit 'q' Parameter Multiple Cross Site Scripting Vulnerabilities
10592| [33110] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
10593| [32657] Novell NetWare ApacheAdmin Security Bypass Vulnerability
10594| [31805] Apache HTTP Server OS Fingerprinting Unspecified Security Vulnerability
10595| [31761] Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
10596| [31698] Apache Tomcat 'RemoteFilterValve' Security Bypass Vulnerability
10597| [31165] Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
10598| [30560] Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability
10599| [30496] Apache Tomcat 'HttpServletResponse.sendError()' Cross Site Scripting Vulnerability
10600| [30494] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
10601| [29653] Apache 'mod_proxy_http' Interim Response Denial of Service Vulnerability
10602| [29502] Apache Tomcat Host Manager Cross Site Scripting Vulnerability
10603| [28576] Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
10604| [28484] Apache Tomcat Requests Containing MS-DOS Device Names Information Disclosure Vulnerability
10605| [28483] Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
10606| [28482] Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
10607| [28481] Apache Tomcat Cross-Site Scripting Vulnerability
10608| [28477] Apache Tomcat AJP Connector Information Disclosure Vulnerability
10609| [27752] Apache mod_jk2 Host Header Multiple Stack Based Buffer Overflow Vulnerabilities
10610| [27706] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
10611| [27703] Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
10612| [27409] Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
10613| [27365] Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
10614| [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
10615| [27236] Apache 'mod_proxy_balancer' Multiple Vulnerabilities
10616| [27234] Apache 'mod_proxy_ftp' Undefined Charset UTF-7 Cross-Site Scripting Vulnerability
10617| [27006] Apache Tomcat JULI Logging Component Default Security Policy Vulnerability
10618| [26939] Apache HTTP Server Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
10619| [26838] Apache mod_imagemap and mod_imap Cross-Site Scripting Vulnerability
10620| [26762] Apache::AuthCAS Cookie SQL Injection Vulnerability
10621| [26663] Apache HTTP Server 413 Error HTTP Request Method Cross-Site Scripting Weakness
10622| [26287] Apache Geronimo SQLLoginModule Authentication Bypass Vulnerability
10623| [26070] Apache Tomcat WebDav Remote Information Disclosure Vulnerability
10624| [25804] Apache Geronimo Management EJB Security Bypass Vulnerability
10625| [25653] Apache Mod_AutoIndex.C Undefined Charset Cross-Site Scripting Vulnerability
10626| [25531] Apache Tomcat Cal2.JSP Cross-Site Scripting Vulnerability
10627| [25489] Apache HTTP Server Mod_Proxy Denial of Service Vulnerability
10628| [25316] Apache Tomcat Multiple Remote Information Disclosure Vulnerabilities
10629| [25314] Apache Tomcat Host Manager Servlet Cross Site Scripting Vulnerability
10630| [25174] Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
10631| [24999] Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
10632| [24759] MySQLDumper Apache Access Control Authentication Bypass Vulnerability
10633| [24649] Apache HTTP Server Mod_Cache Denial of Service Vulnerability
10634| [24645] Apache HTTP Server Mod_Status Cross-Site Scripting Vulnerability
10635| [24553] Apache Mod_Mem_Cache Information Disclosure Vulnerability
10636| [24524] Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
10637| [24480] Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
10638| [24476] Apache Tomcat JSP Example Web Applications Cross Site Scripting Vulnerability
10639| [24475] Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
10640| [24215] Apache HTTP Server Worker Process Multiple Denial of Service Vulnerabilities
10641| [24147] Apache Tomcat JK Connector Double Encoding Security Bypass Vulnerability
10642| [24058] Apache Tomcat Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
10643| [23687] Apache AXIS Non-Existent WSDL Path Information Disclosure Vulnerability
10644| [23438] Apache HTTPD suEXEC Local Multiple Privilege Escalation Weaknesses
10645| [22960] Apache HTTP Server Tomcat Directory Traversal Vulnerability
10646| [22849] Apache mod_python Output Filter Mode Information Disclosure Vulnerability
10647| [22791] Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability
10648| [22732] Debian Apache Root Shell Local Privilege Escalation Vulnerabilities
10649| [22388] Apache Stats Extract Function Multiple Input Validation Vulnerabilities
10650| [21865] Apache And Microsoft IIS Range Denial of Service Vulnerability
10651| [21214] Apache Mod_Auth_Kerb Off-By-One Denial of Service Vulnerability
10652| [20527] Apache Mod_TCL Remote Format String Vulnerability
10653| [19661] Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
10654| [19447] Apache CGI Script Source Code Information Disclosure Vulnerability
10655| [19204] Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
10656| [19106] Apache Tomcat Information Disclosure Vulnerability
10657| [18138] Apache James SMTP Denial Of Service Vulnerability
10658| [17342] Apache Struts Multiple Remote Vulnerabilities
10659| [17095] Apache Log4Net Denial Of Service Vulnerability
10660| [16916] Apache mod_python FileSession Code Execution Vulnerability
10661| [16710] Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
10662| [16260] Apache Geronimo Multiple Input Validation Vulnerabilities
10663| [16153] Apache mod_auth_pgsql Multiple Format String Vulnerabilities
10664| [16152] Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
10665| [15834] Apache 'mod_imap' Referer Cross-Site Scripting Vulnerability
10666| [15765] Apache James Spooler Memory Leak Denial Of Service Vulnerability
10667| [15762] Apache MPM Worker.C Denial Of Service Vulnerability
10668| [15512] Apache Struts Error Response Cross-Site Scripting Vulnerability
10669| [15413] PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
10670| [15325] Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
10671| [15224] Apache Mod_Auth_Shadow Authentication Bypass Vulnerability
10672| [15177] PHP Apache 2 Local Denial of Service Vulnerability
10673| [14982] ApacheTop Insecure Temporary File Creation Vulnerability
10674| [14721] Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
10675| [14660] Apache CGI Byterange Request Denial of Service Vulnerability
10676| [14366] Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
10677| [14106] Apache HTTP Request Smuggling Vulnerability
10678| [13778] Apache HTPasswd Password Command Line Argument Buffer Overflow Vulnerability
10679| [13777] Apache HTPasswd User Command Line Argument Buffer Overflow Vulnerability
10680| [13756] Apache Tomcat Java Security Manager Bypass Vulnerability
10681| [13537] Apache HTDigest Realm Command Line Argument Buffer Overflow Vulnerability
10682| [12877] Apache mod_ssl ssl_io_filter_cleanup Remote Denial Of Service Vulnerability
10683| [12795] Apache Tomcat Remote Malformed Request Denial Of Service Vulnerability
10684| [12619] Apache Software Foundation Batik Squiggle Browser Access Validation Vulnerability
10685| [12519] Apache mod_python Module Publisher Handler Information Disclosure Vulnerability
10686| [12308] Apache Utilities Insecure Temporary File Creation Vulnerability
10687| [12217] Apache mod_auth_radius Malformed RADIUS Server Reply Integer Overflow Vulnerability
10688| [12181] Mod_DOSEvasive Apache Module Local Insecure Temporary File Creation Vulnerability
10689| [11803] Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
10690| [11471] Apache mod_include Local Buffer Overflow Vulnerability
10691| [11360] Apache mod_ssl SSLCipherSuite Restriction Bypass Vulnerability
10692| [11239] Apache Satisfy Directive Access Control Bypass Vulnerability
10693| [11187] Apache Web Server Remote IPv6 Buffer Overflow Vulnerability
10694| [11185] Apache Mod_DAV LOCK Denial Of Service Vulnerability
10695| [11182] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
10696| [11154] Apache mod_ssl Remote Denial of Service Vulnerability
10697| [11094] Apache mod_ssl Denial Of Service Vulnerability
10698| [10789] Apache mod_userdir Module Information Disclosure Vulnerability
10699| [10736] Apache 'mod_ssl' Log Function Format String Vulnerability
10700| [10619] Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
10701| [10508] Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow Vulnerability
10702| [10478] ClueCentral Apache Suexec Patch Security Weakness
10703| [10355] Apache 'mod_ssl' 'ssl_util_uuencode_binary()' Stack Buffer Overflow Vulnerability
10704| [10212] Apache mod_auth Malformed Password Potential Memory Corruption Vulnerability
10705| [9933] Apache mod_disk_cache Module Client Authentication Credential Storage Weakness
10706| [9930] Apache Error and Access Logs Escape Sequence Injection Vulnerability
10707| [9921] Apache Connection Blocking Denial Of Service Vulnerability
10708| [9885] Apache Mod_Security Module SecFilterScanPost Off-By-One Buffer Overflow Vulnerability
10709| [9874] Apache HTAccess LIMIT Directive Bypass Configuration Error Weakness
10710| [9829] Apache Mod_Access Access Control Rule Bypass Vulnerability
10711| [9826] Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
10712| [9733] Apache Cygwin Directory Traversal Vulnerability
10713| [9599] Apache mod_php Global Variables Information Disclosure Weakness
10714| [9590] Apache-SSL Client Certificate Forging Vulnerability
10715| [9571] Apache mod_digest Client-Supplied Nonce Verification Vulnerability
10716| [9471] Apache mod_perl Module File Descriptor Leakage Vulnerability
10717| [9404] Mod-Auth-Shadow Apache Module Expired User Credential Weakness
10718| [9302] Apache mod_php Module File Descriptor Leakage Vulnerability
10719| [9129] Apache mod_python Module Malformed Query Denial of Service Vulnerability
10720| [8926] Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
10721| [8919] Apache Mod_Security Module Heap Corruption Vulnerability
10722| [8911] Apache Web Server Multiple Module Local Buffer Overflow Vulnerability
10723| [8898] Red Hat Apache Directory Index Default Configuration Error
10724| [8883] Apache Cocoon Directory Traversal Vulnerability
10725| [8824] Apache Tomcat Non-HTTP Request Denial Of Service Vulnerability
10726| [8822] Apache Mod_Throttle Module Local Shared Memory Corruption Vulnerability
10727| [8725] Apache2 MOD_CGI STDERR Denial Of Service Vulnerability
10728| [8707] Apache htpasswd Password Entropy Weakness
10729| [8561] Apache::Gallery Insecure Local File Storage Privilege Escalation Vulnerability
10730| [8287] Mod_Mylo Apache Module REQSTR Buffer Overflow Vulnerability
10731| [8226] Apache HTTP Server Multiple Vulnerabilities
10732| [8138] Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
10733| [8137] Apache Web Server Prefork MPM Denial Of Service Vulnerability
10734| [8136] Macromedia Apache Web Server Encoded Space Source Disclosure Vulnerability
10735| [8135] Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
10736| [8134] Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness
10737| [7768] Apache Tomcat Insecure Directory Permissions Vulnerability
10738| [7725] Apache Basic Authentication Module Valid User Login Denial Of Service Vulnerability
10739| [7723] Apache APR_PSPrintf Memory Corruption Vulnerability
10740| [7448] Apache Mod_Auth_Any Remote Command Execution Vulnerability
10741| [7375] Apache Mod_Access_Referer NULL Pointer Dereference Denial of Service Vulnerability
10742| [7332] Apache Web Server OS2 Filestat Denial Of Service Vulnerability
10743| [7255] Apache Web Server File Descriptor Leakage Vulnerability
10744| [7254] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
10745| [6943] Apache Web Server MIME Boundary Information Disclosure Vulnerability
10746| [6939] Apache Web Server ETag Header Information Disclosure Weakness
10747| [6722] Apache Tomcat Web.XML File Contents Disclosure Vulnerability
10748| [6721] Apache Tomcat Null Byte Directory/File Disclosure Vulnerability
10749| [6720] Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
10750| [6662] Apache Web Server MS-DOS Device Name Denial Of Service Vulnerability
10751| [6661] Apache Web Server Default Script Mapping Bypass Vulnerability
10752| [6660] Apache Web Server Illegal Character HTTP Request File Disclosure Vulnerability
10753| [6659] Apache Web Server MS-DOS Device Name Arbitrary Code Execution Vulnerability
10754| [6562] Apache Tomcat Invoker Servlet File Disclosure Vulnerability
10755| [6320] Apache/Tomcat Mod_JK Chunked Encoding Denial Of Service Vulnerability
10756| [6117] Apache mod_php File Descriptor Leakage Vulnerability
10757| [6065] Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
10758| [5996] Apache AB.C Web Benchmarking Buffer Overflow Vulnerability
10759| [5995] Apache AB.C Web Benchmarking Read_Connection() Buffer Overflow Vulnerability
10760| [5993] Multiple Apache HTDigest Buffer Overflow Vulnerabilities
10761| [5992] Apache HTDigest Insecure Temporary File Vulnerability
10762| [5991] Apache HTDigest Arbitrary Command Execution Vulnerability
10763| [5990] Apache HTPasswd Insecure Temporary File Vulnerability
10764| [5981] Multiple Apache HTDigest and HTPassWD Component Vulnerabilites
10765| [5884] Apache Web Server Scoreboard Memory Segment Overwriting SIGUSR1 Sending Vulnerability
10766| [5847] Apache Server Side Include Cross Site Scripting Vulnerability
10767| [5838] Apache Tomcat 3.2 Directory Disclosure Vulnerability
10768| [5816] Apache 2 mod_dav Denial Of Service Vulnerability
10769| [5791] HP VirtualVault Apache mod_ssl Denial Of Service Vulnerability
10770| [5787] Apache Oversized STDERR Buffer Denial Of Service Vulnerability
10771| [5786] Apache Tomcat DefaultServlet File Disclosure Vulnerability
10772| [5542] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
10773| [5486] Apache 2.0 CGI Path Disclosure Vulnerability
10774| [5485] Apache 2.0 Path Disclosure Vulnerability
10775| [5434] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
10776| [5256] Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
10777| [5194] Apache Tomcat DOS Device Name Cross Site Scripting Vulnerability
10778| [5193] Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
10779| [5067] Apache Tomcat Null Character Malformed Request Denial Of Service Vulnerability
10780| [5054] Apache Tomcat Web Root Path Disclosure Vulnerability
10781| [5033] Apache Chunked-Encoding Memory Corruption Vulnerability
10782| [4995] Apache Tomcat JSP Engine Denial of Service Vulnerability
10783| [4878] Apache Tomcat RealPath.JSP Malformed Request Information Disclosure Vulnerability
10784| [4877] Apache Tomcat Example Files Web Root Path Disclosure Vulnerability
10785| [4876] Apache Tomcat Source.JSP Malformed Request Information Disclosure Vulnerability
10786| [4575] Apache Tomcat Servlet Path Disclosure Vulnerability
10787| [4557] Apache Tomcat System Path Information Disclosure Vulnerability
10788| [4437] Apache Error Message Cross-Site Scripting Vulnerability
10789| [4431] Apache PrintEnv/Test_CGI Script Injection Vulnerability
10790| [4358] Apache Double-Reverse Lookup Log Entry Spoofing Vulnerability
10791| [4335] Apache Win32 Batch File Remote Command Execution Vulnerability
10792| [4292] Oracle 9iAS Apache PL/SQL Module Web Administration Access Vulnerability
10793| [4189] Apache mod_ssl/Apache-SSL Buffer Overflow Vulnerability
10794| [4057] Apache 2 for Windows OPTIONS request Path Disclosure Vulnerability
10795| [4056] Apache 2 for Windows php.exe Path Disclosure Vulnerability
10796| [4037] Oracle 9iAS Apache PL/SQL Module Denial of Service Vulnerability
10797| [4032] Oracle 9iAS Apache PL/SQL Module Multiple Buffer Overflows Vulnerability
10798| [3796] Apache HTTP Request Unexpected Behavior Vulnerability
10799| [3790] Apache Non-Existent Log Directory Denial Of Service Vulnerability
10800| [3786] Apache Win32 PHP.EXE Remote File Disclosure Vulnerability
10801| [3727] Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
10802| [3726] Oracle 9I Application Server PL/SQL Apache Module Buffer Overflow Vulnerability
10803| [3596] Apache Split-Logfile File Append Vulnerability
10804| [3521] Apache mod_usertrack Predictable ID Generation Vulnerability
10805| [3335] Red Hat Linux Apache Remote Username Enumeration Vulnerability
10806| [3316] MacOS X Client Apache Directory Contents Disclosure Vulnerability
10807| [3256] Apache mod_auth_oracle Remote SQL Query Manipulation Vulnerability
10808| [3255] Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
10809| [3254] Apache AuthPG Remote SQL Query Manipulation Vulnerability
10810| [3253] Apache mod_auth_pgsql_sys Remote SQL Query Manipulation Vulnerability
10811| [3251] Apache mod_auth_pgsql Remote SQL Query Manipulation Vulnerability
10812| [3176] Apache Mod ReWrite Rules Bypassing Image Linking Vulnerability
10813| [3169] Apache Server Address Disclosure Vulnerability
10814| [3009] Apache Possible Directory Index Disclosure Vulnerability
10815| [2982] Apache Tomcat Cross-Site Scripting Vulnerability
10816| [2852] MacOS X Client Apache File Protection Bypass Vulnerability
10817| [2740] Apache Web Server HTTP Request Denial of Service Vulnerability
10818| [2518] Apache Tomcat 3.0 Directory Traversal Vulnerability
10819| [2503] Apache Artificially Long Slash Path Directory Listing Vulnerability
10820| [2300] NCSA/Apache httpd ScriptAlias Source Retrieval Vulnerability
10821| [2216] Apache Web Server DoS Vulnerability
10822| [2182] Apache /tmp File Race Vulnerability
10823| [2171] Oracle Apache+WebDB Documented Backdoor Vulnerability
10824| [2060] Apache Web Server with Php 3 File Disclosure Vulnerability
10825| [1821] Apache mod_cookies Buffer Overflow Vulnerability
10826| [1728] Apache Rewrite Module Arbitrary File Disclosure Vulnerability
10827| [1658] SuSE Apache CGI Source Code Viewing Vulnerability
10828| [1656] SuSE Apache WebDAV Directory Listings Vulnerability
10829| [1575] Trustix Apache-SSL RPM Permissions Vulnerability
10830| [1548] Apache Jakarta-Tomcat /admin Context Vulnerability
10831| [1532] Apache Tomcat Snoop Servlet Information Disclosure Vulnerability
10832| [1531] Apache Tomcat 3.1 Path Revealing Vulnerability
10833| [1457] Apache::ASP source.asp Example Script Vulnerability
10834| [1284] Apache HTTP Server (win32) Root Directory Access Vulnerability
10835| [1083] Cobalt Raq Apache .htaccess Disclosure Vulnerability
10836|
10837| IBM X-Force - https://exchange.xforce.ibmcloud.com:
10838| [86258] Apache CloudStack text fields cross-site scripting
10839| [85983] Apache Subversion mod_dav_svn module denial of service
10840| [85875] Apache OFBiz UEL code execution
10841| [85874] Apache OFBiz Webtools View Log screen cross-site scripting
10842| [85871] Apache HTTP Server mod_session_dbd unspecified
10843| [85756] Apache Struts OGNL expression command execution
10844| [85755] Apache Struts DefaultActionMapper class open redirect
10845| [85586] Apache ActiveMQ CVE-2013-1879 cross-site scripting
10846| [85574] Apache HTTP Server mod_dav denial of service
10847| [85573] Apache Struts Showcase App OGNL code execution
10848| [85496] Apache CXF denial of service
10849| [85423] Apache Geronimo RMI classloader code execution
10850| [85326] Apache Santuario XML Security for C++ buffer overflow
10851| [85323] Apache Santuario XML Security for Java spoofing
10852| [85319] Apache Qpid Python client SSL spoofing
10853| [85019] Apache Santuario XML Security for C++ CVE-2013-2156 buffer overflow
10854| [85018] Apache Santuario XML Security for C++ CVE-2013-2155 denial of service
10855| [85017] Apache Santuario XML Security for C++ CVE-2013-2154 buffer overflow
10856| [85016] Apache Santuario XML Security for C++ CVE-2013-2153 spoofing
10857| [84952] Apache Tomcat CVE-2012-3544 denial of service
10858| [84763] Apache Struts CVE-2013-2135 security bypass
10859| [84762] Apache Struts CVE-2013-2134 security bypass
10860| [84719] Apache Subversion CVE-2013-2088 command execution
10861| [84718] Apache Subversion CVE-2013-2112 denial of service
10862| [84717] Apache Subversion CVE-2013-1968 denial of service
10863| [84577] Apache Tomcat security bypass
10864| [84576] Apache Tomcat symlink
10865| [84543] Apache Struts CVE-2013-2115 security bypass
10866| [84542] Apache Struts CVE-2013-1966 security bypass
10867| [84154] Apache Tomcat session hijacking
10868| [84144] Apache Tomcat denial of service
10869| [84143] Apache Tomcat information disclosure
10870| [84111] Apache HTTP Server command execution
10871| [84043] Apache Virtual Computing Lab cross-site scripting
10872| [84042] Apache Virtual Computing Lab cross-site scripting
10873| [83782] Apache CloudStack information disclosure
10874| [83781] Apache CloudStack security bypass
10875| [83720] Apache ActiveMQ cross-site scripting
10876| [83719] Apache ActiveMQ denial of service
10877| [83718] Apache ActiveMQ denial of service
10878| [83263] Apache Subversion denial of service
10879| [83262] Apache Subversion denial of service
10880| [83261] Apache Subversion denial of service
10881| [83259] Apache Subversion denial of service
10882| [83035] Apache mod_ruid2 security bypass
10883| [82852] Apache Qpid federation_tag security bypass
10884| [82851] Apache Qpid qpid::framing::Buffer denial of service
10885| [82758] Apache Rave User RPC API information disclosure
10886| [82663] Apache Subversion svn_fs_file_length() denial of service
10887| [82642] Apache Qpid qpid::framing::Buffer::checkAvailable() denial of service
10888| [82641] Apache Qpid AMQP denial of service
10889| [82626] Apache HTTP Server on Debian GNU/Linux Debian apache2ctl symlink
10890| [82618] Apache Commons FileUpload symlink
10891| [82360] Apache HTTP Server manager interface cross-site scripting
10892| [82359] Apache HTTP Server hostnames cross-site scripting
10893| [82338] Apache Tomcat log/logdir information disclosure
10894| [82328] Apache Maven and Apache Maven Wagon SSL spoofing
10895| [82268] Apache OpenJPA deserialization command execution
10896| [81981] Apache CXF UsernameTokens security bypass
10897| [81980] Apache CXF WS-Security security bypass
10898| [81398] Apache OFBiz cross-site scripting
10899| [81240] Apache CouchDB directory traversal
10900| [81226] Apache CouchDB JSONP code execution
10901| [81225] Apache CouchDB Futon user interface cross-site scripting
10902| [81211] Apache Axis2/C SSL spoofing
10903| [81167] Apache CloudStack DeployVM information disclosure
10904| [81166] Apache CloudStack AddHost API information disclosure
10905| [81165] Apache CloudStack createSSHKeyPair API information disclosure
10906| [80518] Apache Tomcat cross-site request forgery security bypass
10907| [80517] Apache Tomcat FormAuthenticator security bypass
10908| [80516] Apache Tomcat NIO denial of service
10909| [80408] Apache Tomcat replay-countermeasure security bypass
10910| [80407] Apache Tomcat HTTP Digest Access Authentication security bypass
10911| [80317] Apache Tomcat slowloris denial of service
10912| [79984] Apache Commons HttpClient SSL spoofing
10913| [79983] Apache CXF SSL spoofing
10914| [79830] Apache Axis2/Java SSL spoofing
10915| [79829] Apache Axis SSL spoofing
10916| [79809] Apache Tomcat DIGEST security bypass
10917| [79806] Apache Tomcat parseHeaders() denial of service
10918| [79540] Apache OFBiz unspecified
10919| [79487] Apache Axis2 SAML security bypass
10920| [79212] Apache Cloudstack code execution
10921| [78734] Apache CXF SOAP Action security bypass
10922| [78730] Apache Qpid broker denial of service
10923| [78617] Eucalyptus Apache Santuario (XML Security for Java) denial of service
10924| [78563] Apache mod_pagespeed module unspecified cross-site scripting
10925| [78562] Apache mod_pagespeed module security bypass
10926| [78454] Apache Axis2 security bypass
10927| [78452] Websense Web Security and Web Filter Apache Tomcat information disclosure
10928| [78451] Websense Web Security and Web Filter Apache Tomcat cross-site scripting
10929| [78321] Apache Wicket unspecified cross-site scripting
10930| [78183] Apache Struts parameters denial of service
10931| [78182] Apache Struts cross-site request forgery
10932| [78153] Apache Solr Autocomplete module for Drupal autocomplete results cross-site scripting
10933| [77987] mod_rpaf module for Apache denial of service
10934| [77958] Apache Struts skill name code execution
10935| [77914] Apache HTTP Server mod_negotiation module cross-site scripting
10936| [77913] Apache HTTP Server mod_proxy_ajp information disclosure
10937| [77568] Apache Qpid broker security bypass
10938| [77421] Apache Libcloud spoofing
10939| [77059] Oracle Solaris Cluster Apache Tomcat Agent unspecified
10940| [77046] Oracle Solaris Apache HTTP Server information disclosure
10941| [76837] Apache Hadoop information disclosure
10942| [76802] Apache Sling CopyFrom denial of service
10943| [76692] Apache Hadoop symlink
10944| [76535] Apache Roller console cross-site request forgery
10945| [76534] Apache Roller weblog cross-site scripting
10946| [76152] Apache CXF elements security bypass
10947| [76151] Apache CXF child policies security bypass
10948| [75983] MapServer for Windows Apache file include
10949| [75857] Apache Commons Compress and Apache Ant bzip2 denial of service
10950| [75558] Apache POI denial of service
10951| [75545] PHP apache_request_headers() buffer overflow
10952| [75302] Apache Qpid SASL security bypass
10953| [75211] Debian GNU/Linux apache 2 cross-site scripting
10954| [74901] Apache HTTP Server LD_LIBRARY_PATH privilege escalation
10955| [74871] Apache OFBiz FlexibleStringExpander code execution
10956| [74870] Apache OFBiz multiple cross-site scripting
10957| [74750] Apache Hadoop unspecified spoofing
10958| [74319] Apache Struts XSLTResult.java file upload
10959| [74313] Apache Traffic Server header buffer overflow
10960| [74276] Apache Wicket directory traversal
10961| [74273] Apache Wicket unspecified cross-site scripting
10962| [74181] Apache HTTP Server mod_fcgid module denial of service
10963| [73690] Apache Struts OGNL code execution
10964| [73432] Apache Solr extension for TYPO3 unspecified cross-site scripting
10965| [73100] Apache MyFaces in directory traversal
10966| [73096] Apache APR hash denial of service
10967| [73052] Apache Struts name cross-site scripting
10968| [73030] Apache CXF UsernameToken security bypass
10969| [72888] Apache Struts lastName cross-site scripting
10970| [72758] Apache HTTP Server httpOnly information disclosure
10971| [72757] Apache HTTP Server MPM denial of service
10972| [72585] Apache Struts ParameterInterceptor security bypass
10973| [72438] Apache Tomcat Digest security bypass
10974| [72437] Apache Tomcat Digest security bypass
10975| [72436] Apache Tomcat DIGEST security bypass
10976| [72425] Apache Tomcat parameter denial of service
10977| [72422] Apache Tomcat request object information disclosure
10978| [72377] Apache HTTP Server scoreboard security bypass
10979| [72345] Apache HTTP Server HTTP request denial of service
10980| [72229] Apache Struts ExceptionDelegator command execution
10981| [72089] Apache Struts ParameterInterceptor directory traversal
10982| [72088] Apache Struts CookieInterceptor command execution
10983| [72047] Apache Geronimo hash denial of service
10984| [72016] Apache Tomcat hash denial of service
10985| [71711] Apache Struts OGNL expression code execution
10986| [71654] Apache Struts interfaces security bypass
10987| [71620] Apache ActiveMQ failover denial of service
10988| [71617] Apache HTTP Server mod_proxy module information disclosure
10989| [71508] Apache MyFaces EL security bypass
10990| [71445] Apache HTTP Server mod_proxy security bypass
10991| [71203] Apache Tomcat servlets privilege escalation
10992| [71181] Apache HTTP Server ap_pregsub() denial of service
10993| [71093] Apache HTTP Server ap_pregsub() buffer overflow
10994| [70336] Apache HTTP Server mod_proxy information disclosure
10995| [69804] Apache HTTP Server mod_proxy_ajp denial of service
10996| [69472] Apache Tomcat AJP security bypass
10997| [69396] Apache HTTP Server ByteRange filter denial of service
10998| [69394] Apache Wicket multi window support cross-site scripting
10999| [69176] Apache Tomcat XML information disclosure
11000| [69161] Apache Tomcat jsvc information disclosure
11001| [68799] mod_authnz_external module for Apache mysql-auth.pl SQL injection
11002| [68541] Apache Tomcat sendfile information disclosure
11003| [68420] Apache XML Security denial of service
11004| [68238] Apache Tomcat JMX information disclosure
11005| [67860] Apache Rampart/C rampart_timestamp_token_validate security bypass
11006| [67804] Apache Subversion control rules information disclosure
11007| [67803] Apache Subversion control rules denial of service
11008| [67802] Apache Subversion baselined denial of service
11009| [67672] Apache Archiva multiple cross-site scripting
11010| [67671] Apache Archiva multiple cross-site request forgery
11011| [67564] Apache APR apr_fnmatch() denial of service
11012| [67532] IBM WebSphere Application Server org.apache.jasper.runtime.JspWriterImpl.response denial of service
11013| [67515] Apache Tomcat annotations security bypass
11014| [67480] Apache Struts s:submit information disclosure
11015| [67414] Apache APR apr_fnmatch() denial of service
11016| [67356] Apache Struts javatemplates cross-site scripting
11017| [67354] Apache Struts Xwork cross-site scripting
11018| [66676] Apache Tomcat HTTP BIO information disclosure
11019| [66675] Apache Tomcat web.xml security bypass
11020| [66640] Apache HttpComponents HttpClient Proxy-Authorization information disclosure
11021| [66241] Apache HttpComponents information disclosure
11022| [66154] Apache Tomcat ServletSecurity security bypass
11023| [65971] Apache Tomcat ServletSecurity security bypass
11024| [65876] Apache Subversion mod_dav_svn denial of service
11025| [65343] Apache Continuum unspecified cross-site scripting
11026| [65162] Apache Tomcat NIO connector denial of service
11027| [65161] Apache Tomcat javax.servlet.ServletRequest.getLocale() denial of service
11028| [65160] Apache Tomcat HTML Manager interface cross-site scripting
11029| [65159] Apache Tomcat ServletContect security bypass
11030| [65050] Apache CouchDB web-based administration UI cross-site scripting
11031| [64773] Oracle HTTP Server Apache Plugin unauthorized access
11032| [64473] Apache Subversion blame -g denial of service
11033| [64472] Apache Subversion walk() denial of service
11034| [64407] Apache Axis2 CVE-2010-0219 code execution
11035| [63926] Apache Archiva password privilege escalation
11036| [63785] Apache CouchDB LD_LIBRARY_PATH privilege escalation
11037| [63493] Apache Archiva credentials cross-site request forgery
11038| [63477] Apache Tomcat HttpOnly session hijacking
11039| [63422] Apache Tomcat sessionsList.jsp cross-site scripting
11040| [63303] Apache mod_fcgid module fcgid_header_bucket_read() buffer overflow
11041| [62959] Apache Shiro filters security bypass
11042| [62790] Apache Perl cgi module denial of service
11043| [62576] Apache Qpid exchange denial of service
11044| [62575] Apache Qpid AMQP denial of service
11045| [62354] Apache Qpid SSL denial of service
11046| [62235] Apache APR-util apr_brigade_split_line() denial of service
11047| [62181] Apache XML-RPC SAX Parser information disclosure
11048| [61721] Apache Traffic Server cache poisoning
11049| [61202] Apache Derby BUILTIN authentication functionality information disclosure
11050| [61186] Apache CouchDB Futon cross-site request forgery
11051| [61169] Apache CXF DTD denial of service
11052| [61070] Apache Jackrabbit search.jsp SQL injection
11053| [61006] Apache SLMS Quoting cross-site request forgery
11054| [60962] Apache Tomcat time cross-site scripting
11055| [60883] Apache mod_proxy_http information disclosure
11056| [60671] Apache HTTP Server mod_cache and mod_dav denial of service
11057| [60264] Apache Tomcat Transfer-Encoding denial of service
11058| [59746] Apache Axis2 axis2/axis2-admin page session hijacking
11059| [59588] Apache Axis2/Java XML DTD (Document Type Declaration) data denial of service
11060| [59413] Apache mod_proxy_http timeout information disclosure
11061| [59058] Apache MyFaces unencrypted view state cross-site scripting
11062| [58827] Apache Axis2 xsd file include
11063| [58790] Apache Axis2 modules cross-site scripting
11064| [58299] Apache ActiveMQ queueBrowse cross-site scripting
11065| [58169] Apache Tomcat Web Application Manager / Host Manager cross-site request forgery
11066| [58056] Apache ActiveMQ .jsp source code disclosure
11067| [58055] Apache Tomcat realm name information disclosure
11068| [58046] Apache HTTP Server mod_auth_shadow security bypass
11069| [57841] Apache Open For Business Project (OFBiz) subject cross-site scripting
11070| [57840] Apache Open For Business Project (OFBiz) multiple parameters cross-site scripting
11071| [57429] Apache CouchDB algorithms information disclosure
11072| [57398] Apache ActiveMQ Web console cross-site request forgery
11073| [57397] Apache ActiveMQ createDestination.action cross-site scripting
11074| [56653] Apache HTTP Server DNS spoofing
11075| [56652] Apache HTTP Server DNS cross-site scripting
11076| [56625] Apache HTTP Server request header information disclosure
11077| [56624] Apache HTTP Server mod_isapi orphaned callback pointer code execution
11078| [56623] Apache HTTP Server mod_proxy_ajp denial of service
11079| [55941] mod_proxy module for Apache ap_proxy_send_fb() buffer overflow
11080| [55857] Apache Tomcat WAR files directory traversal
11081| [55856] Apache Tomcat autoDeploy attribute security bypass
11082| [55855] Apache Tomcat WAR directory traversal
11083| [55210] Intuit component for Joomla! Apache information disclosure
11084| [54533] Apache Tomcat 404 error page cross-site scripting
11085| [54182] Apache Tomcat admin default password
11086| [53878] Apache Solr Search (solr) extension for TYPO3 unspecified cross-site scripting
11087| [53666] Apache HTTP Server Solaris pollset support denial of service
11088| [53650] Apache HTTP Server HTTP basic-auth module security bypass
11089| [53124] mod_proxy_ftp module for Apache HTTP header security bypass
11090| [53041] mod_proxy_ftp module for Apache denial of service
11091| [52540] Apache Portable Runtime and Apache Portable Utility library multiple buffer overflow
11092| [51953] Apache Tomcat Path Disclosure
11093| [51952] Apache Tomcat Path Traversal
11094| [51951] Apache stronghold-status Information Disclosure
11095| [51950] Apache stronghold-info Information Disclosure
11096| [51949] Apache PHP Source Code Disclosure
11097| [51948] Apache Multiviews Attack
11098| [51946] Apache JServ Environment Status Information Disclosure
11099| [51945] Apache error_log Information Disclosure
11100| [51944] Apache Default Installation Page Pattern Found
11101| [51943] Apache AXIS XML Parser echoheaders.jws Sample Web Service Denial of Service
11102| [51942] Apache AXIS XML External Entity File Retrieval
11103| [51941] Apache AXIS Sample Servlet Information Leak
11104| [51940] Apache access_log Information Disclosure
11105| [51626] Apache mod_deflate denial of service
11106| [51532] mod_proxy module for the Apache HTTP Server stream_reqbody_cl denial of service
11107| [51365] Apache Tomcat RequestDispatcher security bypass
11108| [51273] Apache HTTP Server Incomplete Request denial of service
11109| [51195] Apache Tomcat XML information disclosure
11110| [50994] Apache APR-util xml/apr_xml.c denial of service
11111| [50993] Apache APR-util apr_brigade_vprintf denial of service
11112| [50964] Apache APR-util apr_strmatch_precompile() denial of service
11113| [50930] Apache Tomcat j_security_check information disclosure
11114| [50928] Apache Tomcat AJP denial of service
11115| [50884] Apache HTTP Server XML ENTITY denial of service
11116| [50808] Apache HTTP Server AllowOverride privilege escalation
11117| [50108] Apache Struts s:a tag and s:url tag cross-site scripting
11118| [50059] Apache mod_proxy_ajp information disclosure
11119| [49951] Apache Tiles Expression Language (EL) expressions cross-site scripting
11120| [49925] Apache Geronimo Web Administrative Console cross-site request forgery
11121| [49924] Apache Geronimo console/portal/Server/Monitoring cross-site scripting
11122| [49921] Apache ActiveMQ Web interface cross-site scripting
11123| [49898] Apache Geronimo Services/Repository directory traversal
11124| [49725] Apache Tomcat mod_jk module information disclosure
11125| [49715] Apache mod_perl Apache::Status and Apache2::Status modules cross-site scripting
11126| [49712] Apache Struts unspecified cross-site scripting
11127| [49213] Apache Tomcat cal2.jsp cross-site scripting
11128| [48934] Apache Tomcat POST doRead method information disclosure
11129| [48211] Apache Tomcat header HTTP request smuggling
11130| [48163] libapache2-mod-auth-mysql module for Debian multibyte encoding SQL injection
11131| [48110] Apache Jackrabbit search.jsp and swr.jsp cross-site scripting
11132| [47709] Apache Roller "
11133| [47104] Novell Netware ApacheAdmin console security bypass
11134| [47086] Apache HTTP Server OS fingerprinting unspecified
11135| [46329] Apache Struts FilterDispatcher and DefaultStaticContentLoader class directory traversal
11136| [45791] Apache Tomcat RemoteFilterValve security bypass
11137| [44435] Oracle WebLogic Apache Connector buffer overflow
11138| [44411] Apache Tomcat allowLinking UTF-8 directory traversal
11139| [44223] Apache HTTP Server mod_proxy_ftp cross-site scripting
11140| [44156] Apache Tomcat RequestDispatcher directory traversal
11141| [44155] Apache Tomcat HttpServletResponse.sendError() cross-site scripting
11142| [43885] Oracle WebLogic Server Apache Connector buffer overflow
11143| [42987] Apache HTTP Server mod_proxy module denial of service
11144| [42915] Apache Tomcat JSP files path disclosure
11145| [42914] Apache Tomcat MS-DOS path disclosure
11146| [42892] Apache Tomcat unspecified unauthorized access
11147| [42816] Apache Tomcat Host Manager cross-site scripting
11148| [42303] Apache 403 error cross-site scripting
11149| [41618] Apache-SSL ExpandCert() authentication bypass
11150| [40761] Apache Derby RDBNAM parameter and DatabaseMetaData.getURL information disclosure
11151| [40736] Apache Tomcat HTTP/1.1 connector information disclosure
11152| [40614] Apache mod_jk2 HTTP Host header buffer overflow
11153| [40562] Apache Geronimo init information disclosure
11154| [40478] Novell Web Manager webadmin-apache.conf security bypass
11155| [40411] Apache Tomcat exception handling information disclosure
11156| [40409] Apache Tomcat native (APR based) connector weak security
11157| [40403] Apache Tomcat quotes and %5C cookie information disclosure
11158| [40388] Sun Java Plug-In org.apache.crimson.tree.XmlDocument security bypass
11159| [39893] Apache HTTP Server mod_negotiation HTTP response splitting
11160| [39867] Apache HTTP Server mod_negotiation cross-site scripting
11161| [39804] Apache Tomcat SingleSignOn information disclosure
11162| [39615] Apache HTTP Server mod_proxy_ftp.c UTF-7 cross-site scripting
11163| [39612] Apache HTTP Server mod_proxy_balancer buffer overflow
11164| [39608] Apache HTTP Server balancer manager cross-site request forgery
11165| [39476] Apache mod_proxy_balancer balancer_handler function denial of service
11166| [39474] Apache HTTP Server mod_proxy_balancer cross-site scripting
11167| [39472] Apache HTTP Server mod_status cross-site scripting
11168| [39201] Apache Tomcat JULI logging weak security
11169| [39158] Apache HTTP Server Windows SMB shares information disclosure
11170| [39001] Apache HTTP Server mod_imap and mod_imagemap module cross-site scripting
11171| [38951] Apache::AuthCAS Perl module cookie SQL injection
11172| [38800] Apache HTTP Server 413 error page cross-site scripting
11173| [38211] Apache Geronimo SQLLoginModule authentication bypass
11174| [37243] Apache Tomcat WebDAV directory traversal
11175| [37178] RHSA update for Apache HTTP Server mod_status module cross-site scripting not installed
11176| [37177] RHSA update for Apache HTTP Server Apache child process denial of service not installed
11177| [37119] RHSA update for Apache mod_auth_kerb off-by-one buffer overflow not installed
11178| [37100] RHSA update for Apache and IBM HTTP Server Expect header cross-site scripting not installed
11179| [36782] Apache Geronimo MEJB unauthorized access
11180| [36586] Apache HTTP Server UTF-7 cross-site scripting
11181| [36468] Apache Geronimo LoginModule security bypass
11182| [36467] Apache Tomcat functions.jsp cross-site scripting
11183| [36402] Apache Tomcat calendar cross-site request forgery
11184| [36354] Apache HTTP Server mod_proxy module denial of service
11185| [36352] Apache HTTP Server ap_proxy_date_canon() denial of service
11186| [36336] Apache Derby lock table privilege escalation
11187| [36335] Apache Derby schema privilege escalation
11188| [36006] Apache Tomcat "
11189| [36001] Apache Tomcat Host Manager Servlet alias cross-site scripting
11190| [35999] Apache Tomcat \"
11191| [35795] Apache Tomcat CookieExample cross-site scripting
11192| [35536] Apache Tomcat SendMailServlet example cross-site scripting
11193| [35384] Apache HTTP Server mod_cache module denial of service
11194| [35097] Apache HTTP Server mod_status module cross-site scripting
11195| [35095] Apache HTTP Server Prefork MPM module denial of service
11196| [34984] Apache HTTP Server recall_headers information disclosure
11197| [34966] Apache HTTP Server MPM content spoofing
11198| [34965] Apache HTTP Server MPM information disclosure
11199| [34963] Apache HTTP Server MPM multiple denial of service
11200| [34872] Apache MyFaces Tomahawk autoscroll parameter cross-site scripting
11201| [34869] Apache Tomcat JSP example Web application cross-site scripting
11202| [34868] Apache Tomcat Manager and Host Manager cross-site scripting
11203| [34496] Apache Tomcat JK Connector security bypass
11204| [34377] Apache Tomcat hello.jsp cross-site scripting
11205| [34212] Apache Tomcat SSL configuration security bypass
11206| [34210] Apache Tomcat Accept-Language cross-site scripting
11207| [34209] Apache Tomcat calendar application cross-site scripting
11208| [34207] Apache Tomcat implicit-objects.jsp cross-site scripting
11209| [34167] Apache Axis WSDL file path disclosure
11210| [34068] Apache Tomcat AJP connector information disclosure
11211| [33584] Apache HTTP Server suEXEC privilege escalation
11212| [32988] Apache Tomcat proxy module directory traversal
11213| [32794] Apache Tomcat JK Web Server Connector map_uri_to_worker() buffer overflow
11214| [32708] Debian Apache tty privilege escalation
11215| [32441] ApacheStats extract() PHP call unspecified
11216| [32128] Apache Tomcat default account
11217| [31680] Apache Tomcat RequestParamExample cross-site scripting
11218| [31649] Apache Tomcat Sample Servlet TroubleShooter detected
11219| [31557] BEA WebLogic Server and WebLogic Express Apache proxy plug-in denial of service
11220| [31236] Apache HTTP Server htpasswd.c strcpy buffer overflow
11221| [30456] Apache mod_auth_kerb off-by-one buffer overflow
11222| [29550] Apache mod_tcl set_var() format string
11223| [28620] Apache and IBM HTTP Server Expect header cross-site scripting
11224| [28357] Apache HTTP Server mod_alias script source information disclosure
11225| [28063] Apache mod_rewrite off-by-one buffer overflow
11226| [27902] Apache Tomcat URL information disclosure
11227| [26786] Apache James SMTP server denial of service
11228| [25680] libapache2 /tmp/svn file upload
11229| [25614] Apache Struts lookupMap cross-site scripting
11230| [25613] Apache Struts ActionForm denial of service
11231| [25612] Apache Struts isCancelled() security bypass
11232| [24965] Apache mod_python FileSession command execution
11233| [24716] Apache James spooler memory leak denial of service
11234| [24159] Apache Geronimo Web-Access-Log Viewer cross-site scripting
11235| [24158] Apache Geronimo jsp-examples cross-site scripting
11236| [24030] Apache auth_ldap module multiple format strings
11237| [24008] Apache mod_ssl custom error message denial of service
11238| [24003] Apache mod_auth_pgsql module multiple syslog format strings
11239| [23612] Apache mod_imap referer field cross-site scripting
11240| [23173] Apache Struts error message cross-site scripting
11241| [22942] Apache Tomcat directory listing denial of service
11242| [22858] Apache Multi-Processing Module code allows denial of service
11243| [22602] RHSA-2005:582 updates for Apache httpd not installed
11244| [22520] Apache mod-auth-shadow "
11245| [22466] ApacheTop symlink
11246| [22109] Apache HTTP Server ssl_engine_kernel client certificate validation
11247| [22006] Apache HTTP Server byte-range filter denial of service
11248| [21567] Apache mod_ssl off-by-one buffer overflow
11249| [21195] Apache HTTP Server header HTTP request smuggling
11250| [20383] Apache HTTP Server htdigest buffer overflow
11251| [19681] Apache Tomcat AJP12 request denial of service
11252| [18993] Apache HTTP server check_forensic symlink attack
11253| [18790] Apache Tomcat Manager cross-site scripting
11254| [18349] Apache HTTP server Apple HFS+ filesystem obtain information
11255| [18348] Apache HTTP server Apple HFS+ filesystem .DS_Store and .ht file disclosure
11256| [18347] Apache HTTP server Apple Mac OS X Server mod_digest_apple module could allow an attacker to replay responses
11257| [17961] Apache Web server ServerTokens has not been set
11258| [17930] Apache HTTP Server HTTP GET request denial of service
11259| [17785] Apache mod_include module buffer overflow
11260| [17671] Apache HTTP Server SSLCipherSuite bypass restrictions
11261| [17473] Apache HTTP Server Satisfy directive allows access to resources
11262| [17413] Apache htpasswd buffer overflow
11263| [17384] Apache HTTP Server environment variable configuration file buffer overflow
11264| [17382] Apache HTTP Server IPv6 apr_util denial of service
11265| [17366] Apache HTTP Server mod_dav module LOCK denial of service
11266| [17273] Apache HTTP Server speculative mode denial of service
11267| [17200] Apache HTTP Server mod_ssl denial of service
11268| [16890] Apache HTTP Server server-info request has been detected
11269| [16889] Apache HTTP Server server-status request has been detected
11270| [16705] Apache mod_ssl format string attack
11271| [16524] Apache HTTP Server ap_get_mime_headers_core denial of service
11272| [16387] Apache HTTP Server mod_proxy Content-Length buffer overflow
11273| [16230] Apache HTTP Server PHP denial of service
11274| [16214] Apache mod_ssl ssl_util_uuencode_binary buffer overflow
11275| [15958] Apache HTTP Server authentication modules memory corruption
11276| [15547] Apache HTTP Server mod_disk_cache local information disclosure
11277| [15540] Apache HTTP Server socket starvation denial of service
11278| [15467] Novell GroupWise WebAccess using Apache Web server allows viewing of files on the server
11279| [15422] Apache HTTP Server mod_access information disclosure
11280| [15419] Apache HTTP Server mod_ssl plain HTTP request denial of service
11281| [15293] Apache for Cygwin "
11282| [15065] Apache-SSL has a default password
11283| [15041] Apache HTTP Server mod_digest module could allow an attacker to replay responses
11284| [15015] Apache httpd server httpd.conf could allow a local user to bypass restrictions
11285| [14751] Apache Mod_python output filter information disclosure
11286| [14125] Apache HTTP Server mod_userdir module information disclosure
11287| [14075] Apache HTTP Server mod_php file descriptor leak
11288| [13703] Apache HTTP Server account
11289| [13689] Apache HTTP Server configuration allows symlinks
11290| [13688] Apache HTTP Server configuration allows SSI
11291| [13687] Apache HTTP Server Server: header value
11292| [13685] Apache HTTP Server ServerTokens value
11293| [13684] Apache HTTP Server ServerSignature value
11294| [13672] Apache HTTP Server config allows directory autoindexing
11295| [13671] Apache HTTP Server default content
11296| [13670] Apache HTTP Server config file directive references outside content root
11297| [13668] Apache HTTP Server httpd not running in chroot environment
11298| [13666] Apache HTTP Server CGI directory contains possible command interpreter or compiler
11299| [13664] Apache HTTP Server config file contains ScriptAlias entry
11300| [13663] Apache HTTP Server CGI support modules loaded
11301| [13661] Apache HTTP Server config file contains AddHandler entry
11302| [13660] Apache HTTP Server 500 error page not CGI script
11303| [13659] Apache HTTP Server 413 error page not CGI script
11304| [13658] Apache HTTP Server 403 error page not CGI script
11305| [13657] Apache HTTP Server 401 error page not CGI script
11306| [13552] Apache HTTP Server mod_cgid module information disclosure
11307| [13550] Apache GET request directory traversal
11308| [13516] Apache Cocoon XMLForm and JXForm could allow execution of code
11309| [13499] Apache Cocoon directory traversal allows downloading of boot.ini file
11310| [13429] Apache Tomcat non-HTTP request denial of service
11311| [13400] Apache HTTP server mod_alias and mod_rewrite buffer overflow
11312| [13295] Apache weak password encryption
11313| [13254] Apache Tomcat .jsp cross-site scripting
11314| [13125] Apache::Gallery Inline::C could allow arbitrary code execution
11315| [13086] Apache Jakarta Tomcat mod_jk format string allows remote access
11316| [12681] Apache HTTP Server mod_proxy could allow mail relaying
11317| [12662] Apache HTTP Server rotatelogs denial of service
11318| [12554] Apache Tomcat stores password in plain text
11319| [12553] Apache HTTP Server redirects and subrequests denial of service
11320| [12552] Apache HTTP Server FTP proxy server denial of service
11321| [12551] Apache HTTP Server prefork MPM denial of service
11322| [12550] Apache HTTP Server weaker than expected encryption
11323| [12549] Apache HTTP Server type-map file denial of service
11324| [12206] Apache Tomcat /opt/tomcat directory insecure permissions
11325| [12102] Apache Jakarta Tomcat MS-DOS device name request denial of service
11326| [12091] Apache HTTP Server apr_password_validate denial of service
11327| [12090] Apache HTTP Server apr_psprintf code execution
11328| [11804] Apache HTTP Server mod_access_referer denial of service
11329| [11750] Apache HTTP Server could leak sensitive file descriptors
11330| [11730] Apache HTTP Server error log and access log terminal escape sequence injection
11331| [11703] Apache long slash path allows directory listing
11332| [11695] Apache HTTP Server LF (Line Feed) denial of service
11333| [11694] Apache HTTP Server filestat.c denial of service
11334| [11438] Apache HTTP Server MIME message boundaries information disclosure
11335| [11412] Apache HTTP Server error log terminal escape sequence injection
11336| [11196] Apache Tomcat examples and ROOT Web applications cross-site scripting
11337| [11195] Apache Tomcat web.xml could be used to read files
11338| [11194] Apache Tomcat URL appended with a null character could list directories
11339| [11139] Apache HTTP Server mass virtual hosting with mod_rewrite or mod_vhost_alias could allow an attacker to obtain files
11340| [11126] Apache HTTP Server illegal character file disclosure
11341| [11125] Apache HTTP Server DOS device name HTTP POST code execution
11342| [11124] Apache HTTP Server DOS device name denial of service
11343| [11088] Apache HTTP Server mod_vhost_alias CGI source disclosure
11344| [10938] Apache HTTP Server printenv test CGI cross-site scripting
11345| [10771] Apache Tomcat mod_jk module multiple HTTP GET request buffer overflow
11346| [10575] Apache mod_php module could allow an attacker to take over the httpd process
11347| [10499] Apache HTTP Server WebDAV HTTP POST view source
11348| [10457] Apache HTTP Server mod_ssl "
11349| [10415] Apache HTTP Server htdigest insecure system() call could allow command execution
11350| [10414] Apache HTTP Server htdigest multiple buffer overflows
11351| [10413] Apache HTTP Server htdigest temporary file race condition
11352| [10412] Apache HTTP Server htpasswd temporary file race condition
11353| [10376] Apache Tomcat invoker servlet used in conjunction with the default servlet reveals source code
11354| [10348] Apache Tomcat HTTP GET request DOS device reference could cause a denial of service
11355| [10281] Apache HTTP Server ab.c ApacheBench long response buffer overflow
11356| [10280] Apache HTTP Server shared memory scorecard overwrite
11357| [10263] Apache Tomcat mod_jk or mod_jserv connector directory disclosure
11358| [10241] Apache HTTP Server Host: header cross-site scripting
11359| [10230] Slapper worm variants A, B, and C target OpenSSL/Apache systems
11360| [10208] Apache HTTP Server mod_dav denial of service
11361| [10206] HP VVOS Apache mod_ssl denial of service
11362| [10200] Apache HTTP Server stderr denial of service
11363| [10175] Apache Tomcat org.apache.catalina.servlets.DefaultServlet reveals source code
11364| [10169] Slapper worm variant (Slapper.C) targets OpenSSL/Apache systems
11365| [10154] Slapper worm variant (Slapper.B) targets OpenSSL/Apache systems
11366| [10098] Slapper worm targets OpenSSL/Apache systems
11367| [9876] Apache HTTP Server cgi/cgid request could disclose the path to a requested script
11368| [9875] Apache HTTP Server .var file request could disclose installation path
11369| [9863] Apache Tomcat web.xml file could allow a remote attacker to bypass restrictions
11370| [9808] Apache HTTP Server non-Unix version URL encoded directory traversal
11371| [9623] Apache HTTP Server ap_log_rerror() path disclosure
11372| [9520] Apache Tomcat /servlet/ mapping cross-site scripting
11373| [9415] Apache HTTP Server mod_ssl .htaccess off-by-one buffer overflow
11374| [9396] Apache Tomcat null character to threads denial of service
11375| [9394] Apache Tomcat HTTP request for LPT9 reveals Web root path
11376| [9249] Apache HTTP Server chunked encoding heap buffer overflow
11377| [9208] Apache Tomcat sample file requests could reveal directory listing and path to Web root directory
11378| [8932] Apache Tomcat example class information disclosure
11379| [8633] Apache HTTP Server with mod_rewrite could allow an attacker to bypass directives
11380| [8629] Apache HTTP Server double-reverse DNS lookup spoofing
11381| [8589] Apache HTTP Server for Windows DOS batch file remote command execution
11382| [8457] Oracle9i Application Server Apache PL/SQL HTTP Location header buffer overflow
11383| [8455] Oracle9i Application Server default installation could allow an attacker to access certain Apache Services
11384| [8400] Apache HTTP Server mod_frontpage buffer overflows
11385| [8326] Apache HTTP Server multiple MIME headers (sioux) denial of service
11386| [8308] Apache "
11387| [8275] Apache HTTP Server with Multiviews enabled could disclose directory contents
11388| [8119] Apache and PHP OPTIONS request reveals "
11389| [8054] Apache is running on the system
11390| [8029] Mandrake Linux default Apache configuration could allow an attacker to browse files and directories
11391| [8027] Mandrake Linux default Apache configuration has remote management interface enabled
11392| [8026] Mandrake Linux Apache sample programs could disclose sensitive information about the server
11393| [7836] Apache HTTP Server log directory denial of service
11394| [7815] Apache for Windows "
11395| [7810] Apache HTTP request could result in unexpected behavior
11396| [7599] Apache Tomcat reveals installation path
11397| [7494] Apache "
11398| [7419] Apache Web Server could allow remote attackers to overwrite .log files
11399| [7363] Apache Web Server hidden HTTP requests
11400| [7249] Apache mod_proxy denial of service
11401| [7129] Linux with Apache Web server could allow an attacker to determine if a specified username exists
11402| [7103] Apple Mac OS X used with Apache Web server could disclose directory contents
11403| [7059] Apache "
11404| [7057] Apache "
11405| [7056] Apache "
11406| [7055] Apache "
11407| [7054] Apache "
11408| [6997] Apache Jakarta Tomcat error message may reveal information
11409| [6971] Apache Jakarta Tomcat may reveal JSP source code with missing HTTP protocol specification
11410| [6970] Apache crafted HTTP request could reveal the internal IP address
11411| [6921] Apache long slash path allows directory listing
11412| [6687] Apple Mac OS X used with Apache Web server could allow arbitrary file disclosure
11413| [6527] Apache Web Server for Windows and OS2 denial of service
11414| [6316] Apache Jakarta Tomcat may reveal JSP source code
11415| [6305] Apache Jakarta Tomcat directory traversal
11416| [5926] Linux Apache symbolic link
11417| [5659] Apache Web server discloses files when used with php script
11418| [5310] Apache mod_rewrite allows attacker to view arbitrary files
11419| [5204] Apache WebDAV directory listings
11420| [5197] Apache Web server reveals CGI script source code
11421| [5160] Apache Jakarta Tomcat default installation
11422| [5099] Trustix Secure Linux installs Apache with world writable access
11423| [4968] Apache Jakarta Tomcat snoop servlet gives out information which could be used in attack
11424| [4967] Apache Jakarta Tomcat 404 error reveals the pathname of the requested file
11425| [4931] Apache source.asp example file allows users to write to files
11426| [4575] IBM HTTP Server running Apache allows users to directory listing and file retrieval
11427| [4205] Apache Jakarta Tomcat delivers file contents
11428| [2084] Apache on Debian by default serves the /usr/doc directory
11429| [1630] MessageMedia UnityMail and Apache Web server MIME header flood denial of service
11430| [697] Apache HTTP server beck exploit
11431| [331] Apache cookies buffer overflow
11432|
11433| Exploit-DB - https://www.exploit-db.com:
11434| [31130] Apache Tomcat <= 6.0.15 Cookie Quote Handling Remote Information Disclosure Vulnerability
11435| [31052] Apache <= 2.2.6 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
11436| [30901] Apache HTTP Server 2.2.6 Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
11437| [30835] Apache HTTP Server <= 2.2.4 413 Error HTTP Request Method Cross-Site Scripting Weakness
11438| [30563] Apache Tomcat <= 5.5.15 Cal2.JSP Cross-Site Scripting Vulnerability
11439| [30496] Apache Tomcat <= 6.0.13 Cookie Handling Quote Delimiter Session ID Disclosure
11440| [30495] Apache Tomcat <= 6.0.13 Host Manager Servlet Cross Site Scripting Vulnerability
11441| [30191] Apache MyFaces Tomahawk JSF Framework 1.1.5 Autoscroll Parameter Cross Site Scripting Vulnerability
11442| [30189] Apache Tomcat <= 6.0.13 JSP Example Web Applications Cross Site Scripting Vulnerability
11443| [30052] Apache Tomcat 6.0.10 Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
11444| [29930] Apache AXIS 1.0 Non-Existent WSDL Path Information Disclosure Vulnerability
11445| [29859] Apache Roller OGNL Injection
11446| [29739] Apache HTTP Server Tomcat 5.x/6.0.x Directory Traversal Vulnerability
11447| [29435] Apache Tomcat 5.5.25 - CSRF Vulnerabilities
11448| [29316] Apache + PHP 5.x - Remote Code Execution (Multithreaded Scanner) (2)
11449| [29290] Apache / PHP 5.x Remote Code Execution Exploit
11450| [28713] Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object RCE
11451| [28424] Apache 2.x HTTP Server Arbitrary HTTP Request Headers Security Weakness
11452| [28365] Apache 2.2.2 CGI Script Source Code Information Disclosure Vulnerability
11453| [28254] Apache Tomcat 5 Information Disclosure Vulnerability
11454| [27915] Apache James 2.2 SMTP Denial of Service Vulnerability
11455| [27397] Apache suEXEC Privilege Elevation / Information Disclosure
11456| [27135] Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
11457| [27096] Apache Geronimo 1.0 Error Page XSS
11458| [27095] Apache Tomcat / Geronimo 1.0 Sample Script cal2.jsp time Parameter XSS
11459| [26710] Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4 - Denial of Service
11460| [26542] Apache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability
11461| [25986] Plesk Apache Zeroday Remote Exploit
11462| [25980] Apache Struts includeParams Remote Code Execution
11463| [25625] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (2)
11464| [25624] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (1)
11465| [24874] Apache Struts ParametersInterceptor Remote Code Execution
11466| [24744] Apache Rave 0.11 - 0.20 - User Information Disclosure
11467| [24694] Apache 1.3.x mod_include Local Buffer Overflow Vulnerability
11468| [24590] Apache 2.0.x mod_ssl Remote Denial of Service Vulnerability
11469| [23751] Apache Cygwin 1.3.x/2.0.x Directory Traversal Vulnerability
11470| [23581] Apache 2.0.4x mod_perl Module File Descriptor Leakage Vulnerability
11471| [23482] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (2)
11472| [23481] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (1)
11473| [23296] Red Hat Apache 2.0.40 Directory Index Default Configuration Error
11474| [23282] apache cocoon 2.14/2.2 - Directory Traversal vulnerability
11475| [23245] Apache Tomcat 4.0.x Non-HTTP Request Denial of Service Vulnerability
11476| [23119] Apache::Gallery 0.4/0.5/0.6 Insecure Local File Storage Privilege Escalation Vulnerability
11477| [22505] Apache Mod_Access_Referer 1.0.2 NULL Pointer Dereference Denial of Service Vulnerability
11478| [22205] Apache Tomcat 3.x Null Byte Directory/File Disclosure Vulnerability
11479| [22191] Apache Web Server 2.0.x MS-DOS Device Name Denial of Service Vulnerability
11480| [22068] Apache 1.3.x,Tomcat 4.0.x/4.1.x Mod_JK Chunked Encoding Denial of Service Vulnerability
11481| [21885] Apache 1.3/2.0.x Server Side Include Cross Site Scripting Vulnerability
11482| [21882] Apache Tomcat 3.2 Directory Disclosure Vulnerability
11483| [21854] Apache 2.0.39/40 Oversized STDERR Buffer Denial of Service Vulnerability
11484| [21853] Apache Tomcat 3/4 DefaultServlet File Disclosure Vulnerability
11485| [21734] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
11486| [21719] Apache 2.0 Path Disclosure Vulnerability
11487| [21697] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
11488| [21605] Apache Tomcat 4.0.3 DoS Device Name Cross Site Scripting Vulnerability
11489| [21604] Apache Tomcat 4.0.3 Servlet Mapping Cross Site Scripting Vulnerability
11490| [21560] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (2)
11491| [21559] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (1)
11492| [21534] Apache Tomcat 3/4 JSP Engine Denial of Service Vulnerability
11493| [21492] Apache Tomcat 3.2.3/3.2.4 RealPath.JSP Malformed Request Information Disclosure
11494| [21491] Apache Tomcat 3.2.3/3.2.4 Example Files Web Root Path Disclosure
11495| [21490] Apache Tomcat 3.2.3/3.2.4 Source.JSP Malformed Request Information Disclosure
11496| [21412] Apache Tomcat 4.0/4.1 Servlet Path Disclosure Vulnerability
11497| [21350] Apache Win32 1.3.x/2.0.x Batch File Remote Command Execution Vulnerability
11498| [21204] Apache 1.3.20 Win32 PHP.EXE Remote File Disclosure Vulnerability
11499| [21112] Red Hat Linux 7.0 Apache Remote Username Enumeration Vulnerability
11500| [21067] Apache 1.0/1.2/1.3 Server Address Disclosure Vulnerability
11501| [21002] Apache 1.3 Possible Directory Index Disclosure Vulnerability
11502| [20911] Apache 1.3.14 Mac File Protection Bypass Vulnerability
11503| [20716] apache tomcat 3.0 - Directory Traversal vulnerability
11504| [20695] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (4)
11505| [20694] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (3)
11506| [20693] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (2)
11507| [20692] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (1)
11508| [20595] NCSA 1.3/1.4.x/1.5,Apache httpd 0.8.11/0.8.14 ScriptAlias Source Retrieval Vulnerability
11509| [20558] Apache 1.2 Web Server DoS Vulnerability
11510| [20466] Apache 1.3 Web Server with Php 3 File Disclosure Vulnerability
11511| [20435] Apache 0.8.x/1.0.x,NCSA httpd 1.x test-cgi Directory Listing Vulnerability
11512| [20272] Apache 1.2.5/1.3.1,UnityMail 2.0 MIME Header DoS Vulnerability
11513| [20210] Apache 1.3.12 WebDAV Directory Listings Vulnerability
11514| [20131] Apache Tomcat 3.1 Path Revealing Vulnerability
11515| [19975] Apache 1.3.6/1.3.9/1.3.11/1.3.12/1.3.20 Root Directory Access Vulnerability
11516| [19828] Cobalt RaQ 2.0/3.0 Apache .htaccess Disclosure Vulnerability
11517| [19536] Apache <= 1.1,NCSA httpd <= 1.5.2,Netscape Server 1.12/1.1/2.0 a nph-test-cgi Vulnerability
11518| [19231] PHP apache_request_headers Function Buffer Overflow
11519| [18984] Apache Struts <= 2.2.1.1 - Remote Command Execution
11520| [18897] Oracle Weblogic Apache Connector POST Request Buffer Overflow
11521| [18619] Apache Tomcat Remote Exploit (PUT Request) and Account Scanner
11522| [18452] Apache Struts Multiple Persistent Cross-Site Scripting Vulnerabilities
11523| [18442] Apache httpOnly Cookie Disclosure
11524| [18329] Apache Struts2 <= 2.3.1 - Multiple Vulnerabilities
11525| [18221] Apache HTTP Server Denial of Service
11526| [17969] Apache mod_proxy Reverse Proxy Exposure Vulnerability PoC
11527| [17696] Apache httpd Remote Denial of Service (memory exhaustion)
11528| [17691] Apache Struts < 2.2.0 - Remote Command Execution
11529| [16798] Apache mod_jk 1.2.20 Buffer Overflow
11530| [16782] Apache Win32 Chunked Encoding
11531| [16752] Apache module mod_rewrite LDAP protocol Buffer Overflow
11532| [16317] Apache Tomcat Manager Application Deployer Authenticated Code Execution
11533| [15710] Apache Archiva 1.0 - 1.3.1 CSRF Vulnerability
11534| [15319] Apache 2.2 (Windows) Local Denial of Service
11535| [14617] Apache JackRabbit 2.0.0 webapp XPath Injection
11536| [14489] Apache Tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
11537| [12721] Apache Axis2 1.4.1 - Local File Inclusion Vulnerability
11538| [12689] Authenticated Cross-Site Scripting Vulnerability (XSS) within Apache Axis2 administration console
11539| [12343] Apache Tomcat 5.5.0 to 5.5.29 & 6.0.0 to 6.0.26 - Information Disclosure Vulnerability
11540| [12330] Apache OFBiz - Multiple XSS
11541| [12264] Apache OFBiz - FULLADMIN Creator PoC Payload
11542| [12263] Apache OFBiz - SQL Remote Execution PoC Payload
11543| [11662] Apache Spamassassin Milter Plugin Remote Root Command Execution
11544| [11650] Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit
11545| [10811] Joomla.Tutorials GHDB: Apache directory listing Download Vulnerability
11546| [10292] Apache Tomcat 3.2.1 - 404 Error Page Cross Site Scripting Vulnerability
11547| [9995] Apache Tomcat Form Authentication Username Enumeration Weakness
11548| [9994] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
11549| [9993] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
11550| [8842] Apache mod_dav / svn Remote Denial of Service Exploit
11551| [8458] Apache Geronimo <= 2.1.3 - Multiple Directory Traversal Vulnerabilities
11552| [7264] Apache Tomcat runtime.getRuntime().exec() Privilege Escalation (win)
11553| [6229] apache tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
11554| [6100] Apache mod_jk 1.2.19 Remote Buffer Overflow Exploit (win32)
11555| [6089] Bea Weblogic Apache Connector Code Exec / Denial of Service Exploit
11556| [5386] Apache Tomcat Connector jk2-2.0.2 (mod_jk2) Remote Overflow Exploit
11557| [5330] Apache 2.0 mod_jk2 2.0.2 - Remote Buffer Overflow Exploit (win32)
11558| [4552] Apache Tomcat (webdav) Remote File Disclosure Exploit (ssl support)
11559| [4530] Apache Tomcat (webdav) Remote File Disclosure Exploit
11560| [4162] Apache Tomcat Connector (mod_jk) Remote Exploit (exec-shield)
11561| [4093] Apache mod_jk 1.2.19/1.2.20 Remote Buffer Overflow Exploit
11562| [3996] Apache 2.0.58 mod_rewrite Remote Overflow Exploit (win2k3)
11563| [3680] Apache Mod_Rewrite Off-by-one Remote Overflow Exploit (win32)
11564| [3384] Ubuntu/Debian Apache 1.3.33/1.3.34 (CGI TTY) Local Root Exploit
11565| [2237] Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
11566| [2061] Apache Tomcat < 5.5.17 Remote Directory Listing Vulnerability
11567| [1056] Apache <= 2.0.49 Arbitrary Long HTTP Headers Denial of Service
11568| [855] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit
11569| [764] Apache OpenSSL - Remote Exploit (Multiple Targets) (OpenFuckV2.c)
11570| [587] Apache <= 1.3.31 mod_include Local Buffer Overflow Exploit
11571| [466] htpasswd Apache 1.3.31 - Local Exploit
11572| [371] Apache HTTPd Arbitrary Long HTTP Headers DoS (c version)
11573| [360] Apache HTTPd Arbitrary Long HTTP Headers DoS
11574| [132] Apache 1.3.x - 2.0.48 - mod_userdir Remote Users Disclosure Exploit
11575| [126] Apache mod_gzip (with debug_mode) <= 1.2.26.1a Remote Exploit
11576| [67] Apache 1.3.x mod_mylo Remote Code Execution Exploit
11577| [38] Apache <= 2.0.45 APR Remote Exploit -Apache-Knacker.pl
11578| [34] Webfroot Shoutbox < 2.32 (Apache) Remote Exploit
11579| [11] Apache <= 2.0.44 Linux Remote Denial of Service Exploit
11580| [9] Apache HTTP Server 2.x Memory Leak Exploit
11581|
11582| OpenVAS (Nessus) - http://www.openvas.org:
11583| [902924] Apache Struts2 Showcase Skill Name Remote Code Execution Vulnerability
11584| [902837] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability (Windows)
11585| [902830] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
11586| [902664] Apache Traffic Server HTTP Host Header Denial of Service Vulnerability
11587| [901203] Apache httpd Web Server Range Header Denial of Service Vulnerability
11588| [901110] Apache ActiveMQ Source Code Information Disclosure Vulnerability
11589| [901105] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
11590| [900842] Apache 'mod_proxy_ftp' Module Command Injection Vulnerability (Linux)
11591| [900841] Apache 'mod_proxy_ftp' Module Denial Of Service Vulnerability (Linux)
11592| [900573] Apache APR-Utils XML Parser Denial of Service Vulnerability
11593| [900572] Apache APR-Utils Multiple Denial of Service Vulnerabilities
11594| [900571] Apache APR-Utils Version Detection
11595| [900499] Apache mod_proxy_ajp Information Disclosure Vulnerability
11596| [900496] Apache Tiles Multiple XSS Vulnerability
11597| [900493] Apache Tiles Version Detection
11598| [900107] Apache mod_proxy_ftp Wildcard Characters XSS Vulnerability
11599| [900021] Apache Tomcat Cross-Site Scripting and Security Bypass Vulnerabilities
11600| [880086] CentOS Update for apache CESA-2008:0004-01 centos2 i386
11601| [870175] RedHat Update for apache RHSA-2008:0004-01
11602| [864591] Fedora Update for apache-poi FEDORA-2012-10835
11603| [864383] Fedora Update for apache-commons-compress FEDORA-2012-8428
11604| [864280] Fedora Update for apache-commons-compress FEDORA-2012-8465
11605| [864250] Fedora Update for apache-poi FEDORA-2012-7683
11606| [864249] Fedora Update for apache-poi FEDORA-2012-7686
11607| [863993] Fedora Update for apache-commons-daemon FEDORA-2011-10880
11608| [863466] Fedora Update for apache-commons-daemon FEDORA-2011-10936
11609| [855821] Solaris Update for Apache 1.3 122912-19
11610| [855812] Solaris Update for Apache 1.3 122911-19
11611| [855737] Solaris Update for Apache 1.3 122911-17
11612| [855731] Solaris Update for Apache 1.3 122912-17
11613| [855695] Solaris Update for Apache 1.3 122911-16
11614| [855645] Solaris Update for Apache 1.3 122912-16
11615| [855587] Solaris Update for kernel update and Apache 108529-29
11616| [855566] Solaris Update for Apache 116973-07
11617| [855531] Solaris Update for Apache 116974-07
11618| [855524] Solaris Update for Apache 2 120544-14
11619| [855494] Solaris Update for Apache 1.3 122911-15
11620| [855478] Solaris Update for Apache Security 114145-11
11621| [855472] Solaris Update for Apache Security 113146-12
11622| [855179] Solaris Update for Apache 1.3 122912-15
11623| [855147] Solaris Update for kernel update and Apache 108528-29
11624| [855077] Solaris Update for Apache 2 120543-14
11625| [850196] SuSE Update for apache2 openSUSE-SU-2012:0314-1 (apache2)
11626| [850088] SuSE Update for apache2 SUSE-SA:2007:061
11627| [850009] SuSE Update for apache2,apache SUSE-SA:2008:021
11628| [841209] Ubuntu Update for apache2 USN-1627-1
11629| [840900] Ubuntu Update for apache2 USN-1368-1
11630| [840798] Ubuntu Update for apache2 USN-1259-1
11631| [840734] Ubuntu Update for apache2 USN-1199-1
11632| [840542] Ubuntu Update for apache2 vulnerabilities USN-1021-1
11633| [840504] Ubuntu Update for apache2 vulnerability USN-990-2
11634| [840399] Ubuntu Update for apache2 vulnerabilities USN-908-1
11635| [840304] Ubuntu Update for apache2 vulnerabilities USN-575-1
11636| [840118] Ubuntu Update for libapache2-mod-perl2 vulnerability USN-488-1
11637| [840092] Ubuntu Update for apache2 vulnerabilities USN-499-1
11638| [840039] Ubuntu Update for libapache2-mod-python vulnerability USN-430-1
11639| [835253] HP-UX Update for Apache Web Server HPSBUX02645
11640| [835247] HP-UX Update for Apache-based Web Server HPSBUX02612
11641| [835243] HP-UX Update for Apache Running Tomcat Servlet Engine HPSBUX02579
11642| [835236] HP-UX Update for Apache with PHP HPSBUX02543
11643| [835233] HP-UX Update for Apache-based Web Server HPSBUX02531
11644| [835224] HP-UX Update for Apache-based Web Server HPSBUX02465
11645| [835200] HP-UX Update for Apache Web Server Suite HPSBUX02431
11646| [835190] HP-UX Update for Apache Web Server Suite HPSBUX02401
11647| [835188] HP-UX Update for Apache HPSBUX02308
11648| [835181] HP-UX Update for Apache With PHP HPSBUX02332
11649| [835180] HP-UX Update for Apache with PHP HPSBUX02342
11650| [835172] HP-UX Update for Apache HPSBUX02365
11651| [835168] HP-UX Update for Apache HPSBUX02313
11652| [835148] HP-UX Update for Apache HPSBUX01064
11653| [835139] HP-UX Update for Apache with PHP HPSBUX01090
11654| [835131] HP-UX Update for Apache HPSBUX00256
11655| [835119] HP-UX Update for Apache Remote Execution of Arbitrary Code HPSBUX02186
11656| [835104] HP-UX Update for Apache HPSBUX00224
11657| [835103] HP-UX Update for Apache mod_cgid HPSBUX00301
11658| [835101] HP-UX Update for Apache HPSBUX01232
11659| [835080] HP-UX Update for Apache HPSBUX02273
11660| [835078] HP-UX Update for ApacheStrong HPSBUX00255
11661| [835044] HP-UX Update for Apache HPSBUX01019
11662| [835040] HP-UX Update for Apache PHP HPSBUX00207
11663| [835025] HP-UX Update for Apache HPSBUX00197
11664| [835023] HP-UX Update for Apache HPSBUX01022
11665| [835022] HP-UX Update for Apache HPSBUX02292
11666| [835005] HP-UX Update for Apache HPSBUX02262
11667| [831759] Mandriva Update for apache-mod_security MDVSA-2012:182 (apache-mod_security)
11668| [831737] Mandriva Update for apache MDVSA-2012:154-1 (apache)
11669| [831534] Mandriva Update for apache MDVSA-2012:012 (apache)
11670| [831523] Mandriva Update for apache MDVSA-2012:003 (apache)
11671| [831491] Mandriva Update for apache MDVSA-2011:168 (apache)
11672| [831460] Mandriva Update for apache MDVSA-2011:144 (apache)
11673| [831449] Mandriva Update for apache MDVSA-2011:130 (apache)
11674| [831357] Mandriva Update for apache MDVSA-2011:057 (apache)
11675| [831132] Mandriva Update for apache MDVSA-2010:153 (apache)
11676| [831131] Mandriva Update for apache MDVSA-2010:152 (apache)
11677| [830989] Mandriva Update for apache-mod_auth_shadow MDVSA-2010:081 (apache-mod_auth_shadow)
11678| [830931] Mandriva Update for apache MDVSA-2010:057 (apache)
11679| [830926] Mandriva Update for apache MDVSA-2010:053 (apache)
11680| [830918] Mandriva Update for apache-mod_security MDVSA-2010:050 (apache-mod_security)
11681| [830799] Mandriva Update for apache-conf MDVSA-2009:300-2 (apache-conf)
11682| [830797] Mandriva Update for apache-conf MDVSA-2009:300-1 (apache-conf)
11683| [830791] Mandriva Update for apache-conf MDVA-2010:011 (apache-conf)
11684| [830652] Mandriva Update for apache MDVSA-2008:195 (apache)
11685| [830621] Mandriva Update for apache-conf MDVA-2008:129 (apache-conf)
11686| [830581] Mandriva Update for apache MDVSA-2008:016 (apache)
11687| [830294] Mandriva Update for apache MDKSA-2007:140 (apache)
11688| [830196] Mandriva Update for apache MDKSA-2007:235 (apache)
11689| [830112] Mandriva Update for apache MDKSA-2007:127 (apache)
11690| [830109] Mandriva Update for apache-mod_perl MDKSA-2007:083 (apache-mod_perl)
11691| [802425] Apache Struts2 Showcase Arbitrary Java Method Execution vulnerability
11692| [802423] Apache Struts CookBook/Examples Multiple Cross-Site Scripting Vulnerabilities
11693| [802422] Apache Struts Showcase Multiple Persistence Cross-Site Scripting Vulnerabilities
11694| [802415] Apache Tomcat Multiple Security Bypass Vulnerabilities (Win)
11695| [802385] Apache Tomcat Request Object Security Bypass Vulnerability (Win)
11696| [802384] Apache Tomcat Parameter Handling Denial of Service Vulnerability (Win)
11697| [802378] Apache Tomcat Hash Collision Denial Of Service Vulnerability
11698| [801942] Apache Archiva Multiple Vulnerabilities
11699| [801940] Apache Struts2 'XWork' Information Disclosure Vulnerability
11700| [801663] Apache Struts2/XWork Remote Command Execution Vulnerability
11701| [801521] Apache APR-util 'buckets/apr_brigade.c' Denial Of Service Vulnerability
11702| [801284] Apache Derby Information Disclosure Vulnerability
11703| [801203] Apache ActiveMQ Persistent Cross-Site Scripting Vulnerability
11704| [800837] Apache 'mod_deflate' Denial Of Service Vulnerability - July09
11705| [800827] Apache 'mod_proxy_http.c' Denial Of Service Vulnerability
11706| [800680] Apache APR Version Detection
11707| [800679] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
11708| [800678] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
11709| [800677] Apache Roller Version Detection
11710| [800279] Apache mod_jk Module Version Detection
11711| [800278] Apache Struts Cross Site Scripting Vulnerability
11712| [800277] Apache Tomcat mod_jk Information Disclosure Vulnerability
11713| [800276] Apache Struts Version Detection
11714| [800271] Apache Struts Directory Traversal Vulnerability
11715| [800024] Apache Tomcat RemoteFilterValve Security Bypass Vulnerability
11716| [103333] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
11717| [103293] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
11718| [103122] Apache Web Server ETag Header Information Disclosure Weakness
11719| [103074] Apache Continuum Cross Site Scripting Vulnerability
11720| [103073] Apache Continuum Detection
11721| [103053] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
11722| [101023] Apache Open For Business Weak Password security check
11723| [101020] Apache Open For Business HTML injection vulnerability
11724| [101019] Apache Open For Business service detection
11725| [100924] Apache Archiva Cross Site Request Forgery Vulnerability
11726| [100923] Apache Archiva Detection
11727| [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
11728| [100814] Apache Axis2 Document Type Declaration Processing Security Vulnerability
11729| [100813] Apache Axis2 Detection
11730| [100797] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
11731| [100795] Apache Derby Detection
11732| [100762] Apache CouchDB Cross Site Request Forgery Vulnerability
11733| [100725] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
11734| [100613] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
11735| [100514] Apache Multiple Security Vulnerabilities
11736| [100211] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
11737| [100172] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
11738| [100171] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
11739| [100130] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
11740| [72626] Debian Security Advisory DSA 2579-1 (apache2)
11741| [72612] FreeBSD Ports: apache22
11742| [71551] Gentoo Security Advisory GLSA 201206-25 (apache)
11743| [71550] Gentoo Security Advisory GLSA 201206-24 (apache tomcat)
11744| [71512] FreeBSD Ports: apache
11745| [71485] Debian Security Advisory DSA 2506-1 (libapache-mod-security)
11746| [71256] Debian Security Advisory DSA 2452-1 (apache2)
11747| [71238] Debian Security Advisory DSA 2436-1 (libapache2-mod-fcgid)
11748| [70737] FreeBSD Ports: apache
11749| [70724] Debian Security Advisory DSA 2405-1 (apache2)
11750| [70600] FreeBSD Ports: apache
11751| [70253] FreeBSD Ports: apache, apache-event, apache-itk, apache-peruser, apache-worker
11752| [70235] Debian Security Advisory DSA 2298-2 (apache2)
11753| [70233] Debian Security Advisory DSA 2298-1 (apache2)
11754| [69988] Debian Security Advisory DSA 2279-1 (libapache2-mod-authnz-external)
11755| [69338] Debian Security Advisory DSA 2202-1 (apache2)
11756| [67868] FreeBSD Ports: apache
11757| [66816] FreeBSD Ports: apache
11758| [66553] Mandriva Security Advisory MDVSA-2009:189-1 (apache-mod_auth_mysql)
11759| [66414] Mandriva Security Advisory MDVSA-2009:323 (apache)
11760| [66106] SuSE Security Advisory SUSE-SA:2009:050 (apache2,libapr1)
11761| [66081] SLES11: Security update for Apache 2
11762| [66074] SLES10: Security update for Apache 2
11763| [66070] SLES9: Security update for Apache 2
11764| [65998] SLES10: Security update for apache2-mod_python
11765| [65893] SLES10: Security update for Apache 2
11766| [65888] SLES10: Security update for Apache 2
11767| [65575] SLES9: Security update for apache2,apache2-prefork,apache2-worker
11768| [65510] SLES9: Security update for Apache 2
11769| [65472] SLES9: Security update for Apache
11770| [65467] SLES9: Security update for Apache
11771| [65450] SLES9: Security update for apache2
11772| [65390] SLES9: Security update for Apache2
11773| [65363] SLES9: Security update for Apache2
11774| [65309] SLES9: Security update for Apache and mod_ssl
11775| [65296] SLES9: Security update for webdav apache module
11776| [65283] SLES9: Security update for Apache2
11777| [65249] SLES9: Security update for Apache 2
11778| [65230] SLES9: Security update for Apache 2
11779| [65228] SLES9: Security update for Apache 2
11780| [65212] SLES9: Security update for apache2-mod_python
11781| [65209] SLES9: Security update for apache2-worker
11782| [65207] SLES9: Security update for Apache 2
11783| [65168] SLES9: Security update for apache2-mod_python
11784| [65142] SLES9: Security update for Apache2
11785| [65136] SLES9: Security update for Apache 2
11786| [65132] SLES9: Security update for apache
11787| [65131] SLES9: Security update for Apache 2 oes/CORE
11788| [65113] SLES9: Security update for apache2
11789| [65072] SLES9: Security update for apache and mod_ssl
11790| [65017] SLES9: Security update for Apache 2
11791| [64950] Mandrake Security Advisory MDVSA-2009:240 (apache)
11792| [64783] FreeBSD Ports: apache
11793| [64774] Ubuntu USN-802-2 (apache2)
11794| [64653] Ubuntu USN-813-2 (apache2)
11795| [64559] Debian Security Advisory DSA 1834-2 (apache2)
11796| [64532] Mandrake Security Advisory MDVSA-2009:189 (apache-mod_auth_mysql)
11797| [64527] Mandrake Security Advisory MDVSA-2009:184 (apache-mod_security)
11798| [64526] Mandrake Security Advisory MDVSA-2009:183 (apache-mod_security)
11799| [64500] Mandrake Security Advisory MDVSA-2009:168 (apache)
11800| [64443] Ubuntu USN-802-1 (apache2)
11801| [64426] Gentoo Security Advisory GLSA 200907-04 (apache)
11802| [64423] Debian Security Advisory DSA 1834-1 (apache2)
11803| [64391] Mandrake Security Advisory MDVSA-2009:149 (apache)
11804| [64377] Mandrake Security Advisory MDVSA-2009:124-1 (apache)
11805| [64251] Debian Security Advisory DSA 1816-1 (apache2)
11806| [64201] Ubuntu USN-787-1 (apache2)
11807| [64140] Mandrake Security Advisory MDVSA-2009:124 (apache)
11808| [64136] Mandrake Security Advisory MDVSA-2009:102 (apache)
11809| [63565] FreeBSD Ports: apache
11810| [63562] Ubuntu USN-731-1 (apache2)
11811| [61381] Gentoo Security Advisory GLSA 200807-06 (apache)
11812| [61185] FreeBSD Ports: apache
11813| [60582] Gentoo Security Advisory GLSA 200803-19 (apache)
11814| [60387] Slackware Advisory SSA:2008-045-02 apache
11815| [58826] FreeBSD Ports: apache-tomcat
11816| [58825] FreeBSD Ports: apache-tomcat
11817| [58804] FreeBSD Ports: apache
11818| [58745] Gentoo Security Advisory GLSA 200711-06 (apache)
11819| [58360] Debian Security Advisory DSA 1312-1 (libapache-mod-jk)
11820| [57851] Gentoo Security Advisory GLSA 200608-01 (apache)
11821| [57788] Debian Security Advisory DSA 1247-1 (libapache-mod-auth-kerb)
11822| [57335] Debian Security Advisory DSA 1167-1 (apache)
11823| [57201] Debian Security Advisory DSA 1131-1 (apache)
11824| [57200] Debian Security Advisory DSA 1132-1 (apache2)
11825| [57168] Slackware Advisory SSA:2006-209-01 Apache httpd
11826| [57145] FreeBSD Ports: apache
11827| [56731] Slackware Advisory SSA:2006-129-01 Apache httpd
11828| [56729] Slackware Advisory SSA:2006-130-01 Apache httpd redux
11829| [56246] Gentoo Security Advisory GLSA 200602-03 (Apache)
11830| [56212] Debian Security Advisory DSA 952-1 (libapache-auth-ldap)
11831| [56115] Debian Security Advisory DSA 935-1 (libapache2-mod-auth-pgsql)
11832| [56067] FreeBSD Ports: apache
11833| [55803] Slackware Advisory SSA:2005-310-04 apache
11834| [55519] Debian Security Advisory DSA 839-1 (apachetop)
11835| [55392] Gentoo Security Advisory GLSA 200509-12 (Apache)
11836| [55355] FreeBSD Ports: apache
11837| [55284] Debian Security Advisory DSA 807-1 (libapache-mod-ssl)
11838| [55261] Debian Security Advisory DSA 805-1 (apache2)
11839| [55259] Debian Security Advisory DSA 803-1 (apache)
11840| [55129] Gentoo Security Advisory GLSA 200508-15 (apache)
11841| [54739] Gentoo Security Advisory GLSA 200411-18 (apache)
11842| [54724] Gentoo Security Advisory GLSA 200411-03 (apache)
11843| [54712] Gentoo Security Advisory GLSA 200410-21 (apache)
11844| [54689] Gentoo Security Advisory GLSA 200409-33 (net=www/apache)
11845| [54677] Gentoo Security Advisory GLSA 200409-21 (apache)
11846| [54610] Gentoo Security Advisory GLSA 200407-03 (Apache)
11847| [54601] Gentoo Security Advisory GLSA 200406-16 (Apache)
11848| [54590] Gentoo Security Advisory GLSA 200406-05 (Apache)
11849| [54582] Gentoo Security Advisory GLSA 200405-22 (Apache)
11850| [54529] Gentoo Security Advisory GLSA 200403-04 (Apache)
11851| [54499] Gentoo Security Advisory GLSA 200310-04 (Apache)
11852| [54498] Gentoo Security Advisory GLSA 200310-03 (Apache)
11853| [54439] FreeBSD Ports: apache
11854| [53931] Slackware Advisory SSA:2004-133-01 apache
11855| [53903] Slackware Advisory SSA:2004-299-01 apache, mod_ssl, php
11856| [53902] Slackware Advisory SSA:2004-305-01 apache+mod_ssl
11857| [53878] Slackware Advisory SSA:2003-308-01 apache security update
11858| [53851] Debian Security Advisory DSA 135-1 (libapache-mod-ssl)
11859| [53849] Debian Security Advisory DSA 132-1 (apache-ssl)
11860| [53848] Debian Security Advisory DSA 131-1 (apache)
11861| [53784] Debian Security Advisory DSA 021-1 (apache)
11862| [53738] Debian Security Advisory DSA 195-1 (apache-perl)
11863| [53737] Debian Security Advisory DSA 188-1 (apache-ssl)
11864| [53735] Debian Security Advisory DSA 187-1 (apache)
11865| [53703] Debian Security Advisory DSA 532-1 (libapache-mod-ssl)
11866| [53577] Debian Security Advisory DSA 120-1 (libapache-mod-ssl, apache-ssl)
11867| [53568] Debian Security Advisory DSA 067-1 (apache,apache-ssl)
11868| [53519] Debian Security Advisory DSA 689-1 (libapache-mod-python)
11869| [53433] Debian Security Advisory DSA 181-1 (libapache-mod-ssl)
11870| [53282] Debian Security Advisory DSA 594-1 (apache)
11871| [53248] Debian Security Advisory DSA 558-1 (libapache-mod-dav)
11872| [53224] Debian Security Advisory DSA 532-2 (libapache-mod-ssl)
11873| [53215] Debian Security Advisory DSA 525-1 (apache)
11874| [53151] Debian Security Advisory DSA 452-1 (libapache-mod-python)
11875| [52529] FreeBSD Ports: apache+ssl
11876| [52501] FreeBSD Ports: apache
11877| [52461] FreeBSD Ports: apache
11878| [52390] FreeBSD Ports: apache
11879| [52389] FreeBSD Ports: apache
11880| [52388] FreeBSD Ports: apache
11881| [52383] FreeBSD Ports: apache
11882| [52339] FreeBSD Ports: apache+mod_ssl
11883| [52331] FreeBSD Ports: apache
11884| [52329] FreeBSD Ports: ru-apache+mod_ssl
11885| [52314] FreeBSD Ports: apache
11886| [52310] FreeBSD Ports: apache
11887| [15588] Detect Apache HTTPS
11888| [15555] Apache mod_proxy content-length buffer overflow
11889| [15554] Apache mod_include priviledge escalation
11890| [14771] Apache <= 1.3.33 htpasswd local overflow
11891| [14177] Apache mod_access rule bypass
11892| [13644] Apache mod_rootme Backdoor
11893| [12293] Apache Input Header Folding and mod_ssl ssl_io_filter_cleanup DoS Vulnerabilities
11894| [12280] Apache Connection Blocking Denial of Service
11895| [12239] Apache Error Log Escape Sequence Injection
11896| [12123] Apache Tomcat source.jsp malformed request information disclosure
11897| [12085] Apache Tomcat servlet/JSP container default files
11898| [11438] Apache Tomcat Directory Listing and File disclosure
11899| [11204] Apache Tomcat Default Accounts
11900| [11092] Apache 2.0.39 Win32 directory traversal
11901| [11046] Apache Tomcat TroubleShooter Servlet Installed
11902| [11042] Apache Tomcat DOS Device Name XSS
11903| [11041] Apache Tomcat /servlet Cross Site Scripting
11904| [10938] Apache Remote Command Execution via .bat files
11905| [10839] PHP.EXE / Apache Win32 Arbitrary File Reading Vulnerability
11906| [10773] MacOS X Finder reveals contents of Apache Web files
11907| [10766] Apache UserDir Sensitive Information Disclosure
11908| [10756] MacOS X Finder reveals contents of Apache Web directories
11909| [10752] Apache Auth Module SQL Insertion Attack
11910| [10704] Apache Directory Listing
11911| [10678] Apache /server-info accessible
11912| [10677] Apache /server-status accessible
11913| [10440] Check for Apache Multiple / vulnerability
11914|
11915| SecurityTracker - https://www.securitytracker.com:
11916| [1028865] Apache Struts Bugs Permit Remote Code Execution and URL Redirection Attacks
11917| [1028864] Apache Struts Wildcard Matching and Expression Evaluation Bugs Let Remote Users Execute Arbitrary Code
11918| [1028824] Apache mod_dav_svn URI Processing Flaw Lets Remote Users Deny Service
11919| [1028823] Apache Unspecified Flaw in mod_session_dbd Has Unspecified Impact
11920| [1028724] (HP Issues Fix for HP-UX) Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
11921| [1028722] (Red Hat Issues Fix for JBoss) Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
11922| [1028693] (Red Hat Issues Fix) Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
11923| [1028622] Apache Struts 'includeParams' Bugs Permit Remote Command Execution and Cross-Site Scripting Attacks
11924| [1028621] Apache Subversion Bugs Let Remote Authenticated Users Execute Arbitrary Commands and Deny Service
11925| [1028540] Apache mod_rewrite Input Validation Flaw Lets Remote Users Execute Arbitrary Commands
11926| [1028534] Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
11927| [1028533] Apache Tomcat Lack of Chunked Transfer Encoding Extension Size Limit Lets Remote Users Deny Service
11928| [1028532] Apache Tomcat AsyncListeners Bug May Disclose Information from One Request to Another User
11929| [1028515] Apache VCL Input Validation Flaw Lets Remote Authenticated Users Gain Elevated Privileges
11930| [1028457] Apache ActiveMQ Bugs Let Remote Users Conduct Cross-Site Scripting Attacks, Deny Service, and Obtain Potentially Sensitive Information
11931| [1028287] Apache CXF WSS4JInInterceptor Grants Service Access to Remote Users
11932| [1028286] Apache CXF WS-Security UsernameToken Processing Flaw Lets Remote Users Bypass Authentication
11933| [1028252] Apache Commons FileUpload Unsafe Temporary File Lets Local Users Gain Elevated Privileges
11934| [1028207] Apache Input Validation Bugs Permit Cross-Site Scripting Attacks
11935| [1027836] Apache Tomcat Connection Processing Bug Lets Remote Users Deny Service
11936| [1027834] Apache Tomcat Bug Lets Remote Users Bypass Cross-Site Request Forgery Prevention Filter
11937| [1027833] Apache Tomcat Bug Lets Remote Users Bypass Security Constraints
11938| [1027729] Apache Tomcat Header Processing Bug Lets Remote Users Deny Service
11939| [1027728] Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
11940| [1027554] Apache CXF Lets Remote Authenticated Users Execute Unauthorized SOAP Actions
11941| [1027508] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
11942| [1027421] Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
11943| [1027096] Apache Commons Compress BZip2CompressorOutputStream() Sorting Algorithm Lets Remote or Local Users Deny Service
11944| [1026932] Apache LD_LIBRARY_PATH Processing Lets Local Users Gain Elevated Privileges
11945| [1026928] Apache OFBiz Unspecified Flaw Lets Remote Users Execute Arbitrary Code
11946| [1026927] Apache OFBiz Input Validation Flaws Permit Cross-Site Scripting Attacks
11947| [1026847] Apache Traffic Server Host Header Processing Flaw Lets Remote Users Deny Service
11948| [1026846] Apache Wicket Discloses Hidden Application Files to Remote Users
11949| [1026839] Apache Wicket Input Validation Flaw in 'wicket:pageMapName' Parameter Permits Cross-Site Scripting Attacks
11950| [1026616] Apache Bugs Let Remote Users Deny Service and Obtain Cookie Data
11951| [1026575] Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
11952| [1026484] Apache Struts Bug Lets Remote Users Overwrite Files and Execute Arbitrary Code
11953| [1026477] Apache Tomcat Hash Table Collision Bug Lets Remote Users Deny Service
11954| [1026402] Apache Struts Conversion Error Lets Remote Users Inject Arbitrary Commands
11955| [1026353] Apache mod_proxy/mod_rewrite Bug Lets Remote Users Access Internal Servers
11956| [1026295] Apache Tomcat Lets Untrusted Web Applications Gain Elevated Privileges
11957| [1026267] Apache .htaccess File Integer Overflow Lets Local Users Execute Arbitrary Code
11958| [1026144] Apache mod_proxy Pattern Matching Bug Lets Remote Users Access Internal Servers
11959| [1026095] Apache Tomcat HTTP DIGEST Authentication Weaknesses Let Remote Users Conduct Bypass Attacks
11960| [1026054] Apache mod_proxy_ajp HTTP Processing Error Lets Remote Users Deny Service
11961| [1025993] Apache Tomcat AJP Protocol Processing Bug Lets Remote Users Bypass Authentication or Obtain Information
11962| [1025976] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
11963| [1025960] Apache httpd Byterange Filter Processing Error Lets Remote Users Deny Service
11964| [1025925] Apache Tomcat Commons Daemon jsvc Lets Local Users Gain Elevated Privileges
11965| [1025924] Apache Tomcat XML Validation Flaw Lets Applications Obtain Potentially Sensitive Information
11966| [1025788] Apache Tomcat Lets Malicious Applications Obtain Information and Deny Service
11967| [1025755] Apache Santuario Buffer Overflow Lets Remote Users Deny Service
11968| [1025712] Apache Tomcat Discloses Passwords to Local Users in Certain Cases
11969| [1025577] Apache Archiva Input Validation Hole Permits Cross-Site Scripting Attacks
11970| [1025576] Apache Archiva Request Validation Flaw Permits Cross-Site Request Forgery Attacks
11971| [1025527] Apache APR Library apr_fnmatch() Flaw Lets Remote Users Execute Arbitrary Code
11972| [1025303] Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
11973| [1025215] Apache Tomcat May Ignore @ServletSecurity Annotation Protections
11974| [1025066] Apache Continuum Input Validation Flaw Permits Cross-Site Request Forgery Attacks
11975| [1025065] Apache Continuum Input Validation Hole Permits Cross-Site Scripting Attacks
11976| [1025027] Apache Tomcat maxHttpHeaderSize Parsing Error Lets Remote Users Deny Service
11977| [1025026] Apache Tomcat Manager Input Validation Hole Permits Cross-Site Scripting Attacks
11978| [1025025] Apache Tomcat Security Manager Lets Local Users Bypass File Permissions
11979| [1024764] Apache Tomcat Manager Input Validation Hole in 'sessionList.jsp' Permits Cross-Site Scripting Attacks
11980| [1024417] Apache Traffic Server Insufficient Randomization Lets Remote Users Poison the DNS Cache
11981| [1024332] Apache mod_cache and mod_dav Request Processing Flaw Lets Remote Users Deny Service
11982| [1024180] Apache Tomcat 'Transfer-Encoding' Header Processing Flaw Lets Remote Users Deny Service and Obtain Potentially Sensitive Information
11983| [1024096] Apache mod_proxy_http May Return Results for a Different Request
11984| [1023942] Apache mod_proxy_ajp Error Condition Lets Remote Users Deny Service
11985| [1023941] Apache ap_read_request() Memory Error May Let Remote Users Access Potentially Sensitive Information
11986| [1023778] Apache ActiveMQ Input Validation Flaw Permits Cross-Site Scripting Attacks
11987| [1023701] Apache mod_isapi Error Processing Flaw May Let Remote Users Deny Service
11988| [1023533] Apache mod_proxy Integer Overflow May Let Remote Users Execute Arbitrary Code
11989| [1022988] Apache Solaris Support Code Bug Lets Remote Users Deny Service
11990| [1022529] Apache mod_deflate Connection State Bug Lets Remote Users Deny Service
11991| [1022509] Apache mod_proxy stream_reqbody_cl() Infinite Loop Lets Remote Users Deny Service
11992| [1022296] Apache IncludesNoExec Options Restrictions Can Be Bypass By Local Users
11993| [1022264] Apache mod_proxy_ajp Bug May Disclose Another User's Response Data
11994| [1022001] Apache Tomcat mod_jk May Disclose Responses to the Wrong User
11995| [1021988] mod_perl Input Validation Flaw in Apache::Status and Apache2::Status Permits Cross-Site Scripting Attacks
11996| [1021350] NetWare Bug Lets Remote Users Access the ApacheAdmin Console
11997| [1020635] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
11998| [1020520] Oracle WebLogic Apache Connector Lets Remote Users Execute Arbitrary Code
11999| [1020267] Apache mod_proxy Interim Response Process Bug Lets Remote Users Deny Service
12000| [1019784] Apache-SSL Certificate Processing Bug May Let Remote Users View Portions of Kernel Memory
12001| [1019256] Apache mod_negotiation Input Validation Hole Permits Cross-Site Scripting Attacks
12002| [1019194] Apache Input Validation Hole in Mod_AutoIndex When the Character Set is Undefined May Permit Cross-Site Scripting Attacks
12003| [1019185] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
12004| [1019154] Apache Input Validation Hole in mod_status Permits Cross-Site Scripting Attacks
12005| [1019093] Apache Input Validation Hole in mod_imap Permits Cross-Site Scripting Attacks
12006| [1019030] Apache Input Validation Hole in Default HTTP 413 Error Page Permits Cross-Site Scripting Attacks
12007| [1018633] Apache mod_proxy Bug Lets Remote Users Deny Service
12008| [1018304] Apache HTTPD scoreboard Protection Flaw Lets Local Users Terminate Arbitrary Processes
12009| [1018303] Apache HTTPD mod_cache May Let Remote Users Deny Service
12010| [1018302] Apache mod_status Input Validation Hole Permits Cross-Site Scripting Attacks
12011| [1018269] Apache Tomcat Input Validation Hole in Processing Accept-Language Header Permits Cross-Site Scripting Attacks
12012| [1017904] Apache suEXEC Bugs May Let Local Users Gain Elevated Privileges
12013| [1017719] Apache Tomcat JK Web Server Connector Buffer Overflow in map_uri_to_worker() Lets Remote Users Execute Arbitrary Code
12014| [1017062] Apache mod_tcl Format String Bug in set_var() Function May Let Remote Users Execute Arbitrary Code
12015| [1016601] Apache mod_rewrite Off-by-one Error Lets Remote Users Execute Arbitrary Code
12016| [1016576] Apache Tomcat Discloses Directory Listings to Remote Users
12017| [1015447] Apache mod_ssl Null Pointer Dereference May Let Remote Users Deny Service
12018| [1015344] Apache mod_imap Input Validation Flaw in Referer Field Lets Remote Users Conduct Cross-Site Scripting Attacks
12019| [1015093] Apache Memory Leak in MPM 'worker.c' Code May Let Remote Users Deny Service
12020| [1014996] ApacheTop Unsafe Temporary File May Let Local Users Gain Elevated Privileges
12021| [1014833] Apache ssl_hook_Access() Function May Fail to Verify Client Certificates
12022| [1014826] Apache Memory Leak in 'byterange filter' Lets Remote Users Deny Service
12023| [1014575] Apache mod_ssl Off-by-one Buffer Overflow in Processing CRLs May Let Remote Users Deny Service
12024| [1014323] Apache Chunked Transfer-Encoding and Content-Length Processing Lets Remote Users Smuggle HTTP Requests
12025| [1013156] Apache mod_python Publisher Handler Discloses Information to Remote Users
12026| [1012829] Apache mod_auth_radius radcpy() Integer Overflow Lets Remote Users Deny Service in Certain Cases
12027| [1012416] Apache on Apple OS X Lets Remote Users Bypass Apache File Handlers and Directly Access Files
12028| [1012415] Apache on Apple HFS+ Filesystems May Disclose '.DS_Store' Files to Remote Users
12029| [1012414] Apache mod_digest_apple Lets Remote Users Replay Authentication Credentials
12030| [1012083] Apache Web Server Error in Processing Requests With Many Space Characters Lets Remote Users Deny Service
12031| [1011783] Apache mod_include Buffer Overflow Lets Local Users Execute Arbitrary Code
12032| [1011557] Apache mod_ssl SSLCipherSuite Directive Can By Bypassed in Certain Cases
12033| [1011385] Apache Satsify Directive Error May Let Remote Users Access Restricted Resources
12034| [1011340] Apache SSL Connection Abort State Error Lets Remote Users Deny Service
12035| [1011303] Apache ap_resolve_env() Buffer Overflow in Reading Configuration Files May Let Local Users Gain Elevated Privileges
12036| [1011299] Apache IPv6 Address Parsing Flaw May Let Remote Users Deny Service
12037| [1011248] Apache mod_dav LOCK Method Error May Let Remote Users Deny Service
12038| [1011213] Apache mod_ssl Can Be Crashed By Remote Users When Reverse Proxying SSL Connections
12039| [1010674] Apache Can Be Crashed By PHP Code Invoking Nested Remote Sockets
12040| [1010599] Apache httpd Header Line Memory Allocation Lets Remote Users Crash the Server
12041| [1010462] Apache mod_proxy Buffer Overflow May Let Remote Users Execute Arbitrary Code
12042| [1010322] Apache mod_ssl Stack Overflow in ssl_util_uuencode_binary() May Let Remote Users Execute Arbitrary Code
12043| [1010270] cPanel Apache mod_phpsuexec Options Let Local Users Gain Elevated Privileges
12044| [1009934] Apache Web Server Has Buffer Overflow in ebcdic2ascii() on Older Processor Architectures
12045| [1009516] Apache mod_survey HTML Report Format Lets Remote Users Conduct Cross-Site Scripting Attacks
12046| [1009509] Apache mod_disk_cache Stores Authentication Credentials on Disk
12047| [1009495] Apache Web Server Socket Starvation Flaw May Let Remote Users Deny Service
12048| [1009417] GroupWise WebAccess With Apache on NetWare Has Configuration Flaw That May Grant Web Access to Remote Users
12049| [1009338] Apache mod_access Parsing Flaw May Fail to Enforce Allow/Deny Rules
12050| [1009337] Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon
12051| [1009182] Apache for Cygwin '..%5C' Input Validation Flaw Discloses Files to Remote Users
12052| [1008973] PHP May Apply Incorrect php_admin_* Settings To Requests for Apache Virtual Hosts
12053| [1008967] Apache-SSL 'SSLFakeBasicAuth' Lets Remote Users Forge Client Certificates to Be Authenticated
12054| [1008920] Apache mod_digest May Validate Replayed Client Responses
12055| [1008828] Apache mod_python String Processing Bug Still Lets Remote Users Crash the Web Server
12056| [1008822] Apache mod_perl File Descriptor Leak May Let Local Users Hijack the http and https Services
12057| [1008675] mod_auth_shadow Apache Module Authenticates Expired Passwords
12058| [1008559] Apache mod_php File Descriptor Leak May Let Local Users Hijack the https Service
12059| [1008335] Apache mod_python String Processing Bug Lets Remote Users Crash the Web Server
12060| [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
12061| [1008030] Apache mod_rewrite Contains a Buffer Overflow
12062| [1008029] Apache mod_alias Contains a Buffer Overflow
12063| [1008028] Apache mod_cgid May Disclose CGI Output to Another Client
12064| [1007995] Apache Cocoon Forms May Let Remote Users Execute Arbitrary Java Code on the System
12065| [1007993] Apache Cocoon 'view-source' Sample Script Discloses Files to Remote Users
12066| [1007823] Apache Web Server mod_cgi Error May Let Malicious CGI Scripts Crash the Web Service
12067| [1007664] Apache::Gallery Unsafe Temporary Files May Let Local Users Gain Apache Web Server Privileges
12068| [1007557] Apache Web Server Does Not Filter Terminal Escape Sequences From Log Files
12069| [1007230] Apache HTTP Server 'rotatelogs' Bug on Win32 and OS/2 May Cause the Logging to Stop
12070| [1007146] Apache HTTP Server FTP Proxy Bug May Cause Denial of Service Conditions
12071| [1007145] Apache 'accept()' Errors May Cause Denial of Service Conditions
12072| [1007144] Apache Web Server 'type-map' File Error Permits Local Denial of Service Attacks
12073| [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
12074| [1006864] Apache Web Server Can Be Crashed By Remote Users Via mod_dav Flaws and Also Via Basic Authentication
12075| [1006709] Apache mod_survey Input Validation Flaw Lets Remote Users Fill Up Disk Space
12076| [1006614] Apache mod_ntlm Buffer Overflow and Format String Flaw Let Remote Users Execute Arbitary Code
12077| [1006591] Apache mod_access_referer Module Null Pointer Dereference May Faciliate Denial of Service Attacks
12078| [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
12079| [1006021] Apache Tomcat Server URL Parsing Error May Disclose Otherwise Inaccessible Web Directory Listings and Files to Remote Users
12080| [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
12081| [1005962] Apache Web Server Path Parsing Flaw May Allow Remote Users to Execute Code in Certain Configurations
12082| [1005848] Apache 'printenv' Script Input Validation Bugs in Older Versions May Let Remote Users Conduct Cross-Site Scripting Attacks
12083| [1005765] Apache mod_jk Module Processing Bug When Used With Tomcat May Disclose Information to Remote Users or Crash
12084| [1005548] Apache mod_php Module May Allow Local Users to Gain Control of the Web Port
12085| [1005499] Apache Web Server (2.0.42) May Disclose CGI Source Code to Remote Users When Used With WebDAV
12086| [1005410] Apache Tomcat Java Servlet Engine Can Be Crashed Via Multiple Requests for DOS Device Names
12087| [1005351] Apache Web Server (1.3.x) Shared Memory Scoreboard Bug Lets Certain Local Users Issue Signals With Root Privileges
12088| [1005331] Apache Web Server (2.x) SSI Server Signature Filtering Hole Lets Remote Users Conduct Cross-Site Scripting Attacks
12089| [1005290] Apache Tomcat Java Server Default Servlet Returns JSP Source Code to Remote Users
12090| [1005285] Apache Web Server 'mod_dav' Has Null Pointer Bug That May Allow Remote Users to Cause Denial of Service Conditions
12091| [1005010] Apache Web Server (2.0) Has Unspecified Flaw That Allows Remote Users to Obtain Sensitive Data and Cause Denial of Service Conditions
12092| [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
12093| [1004745] Apache Tomcat Java Server Allows Cross-Site Scripting Attacks
12094| [1004636] Apache mod_ssl 'Off-by-One' Bug May Let Local Users Crash the Web Server or Possibly Execute Arbitrary Code
12095| [1004602] Apache Tomcat Java Server for Windows Can Be Crashed By Remote Users Sending Malicious Requests to Hang All Available Working Threads
12096| [1004586] Apache Tomcat Java Server May Disclose the Installation Path to Remote Users
12097| [1004555] Apache Web Server Chunked Encoding Flaw May Let Remote Users Execute Arbitrary Code on the Server
12098| [1004209] Apache 'mod_python' Python Language Interpreter Bug in Publisher Handler May Allow Remote Users to Modify Files on the System
12099| [1003874] Apache Web Server for Windows Has Batch File Processing Hole That Lets Remote Users Execute Commands on the System
12100| [1003767] 'mod_frontpage' Module for Apache Web Server Has Buffer Overlow in 'fpexec.c' That Allows Remote Users to Execute Arbitrary Code on the System with Root Privileges
12101| [1003723] Apache-SSL for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
12102| [1003664] 'mod_ssl' Security Package for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
12103| [1003602] GNUJSP Java Server Pages Implementation Discloses Web Files and Source Code to Remote Users and Bypasses Apache Access Control Restrictions
12104| [1003465] PHP for Apache Web Server May Disclose Installation Path Information to Remote Users Making 'OPTIONS' Requests
12105| [1003451] Oracle Application Server PL/SQL Module for Apache Has Buffer Overflows That Allow Remote Users to Execute Arbitrary Code and Gain Access to the Server
12106| [1003131] Apache Web Server in Virtual Hosting Mode Can Be Crashed By a Local User Removing a Log Directory
12107| [1003104] PHP.EXE Windows CGI for Apache Web Server May Let Remote Users View Files on the Server Due to Configuration Error
12108| [1003008] Apache 'mod_bf' Module Lets Remote Users Execute Arbitrary Code
12109| [1002629] Apache suEXEC Wrapper Fails to Observe Minimum Group ID Security Settings in Certain Situations
12110| [1002542] Apache Web Server Virtual Hosting Split-Logfile Function Lets Remote Users Write Log Entries to Arbitrary Files on the System
12111| [1002400] Apache mod_gzip Module Has Buffer Overflow That Can Be Exploited By Local Users to Gain Elevated Privileges
12112| [1002303] Several 3rd Party Apache Authentication Modules Allow Remote Users to Execute Arbitrary Code to Gain Access to the System or Execute Stored Procedures to Obtain Arbitrary Database Information
12113| [1002188] Apache Web Server Discloses Internal IP Addresses to Remote Users in Certain Configurations
12114| [1001989] Apache Web Server May Disclose Directory Contents Even If an Index.html File is Present in the Directory
12115| [1001719] Apache Web Server on Mac OS X Client Fails to Enforce File and Directory Access Protections, Giving Remote Users Access to Restricted Pages
12116| [1001572] Apache Web Server on Microsoft Windows Platforms Allows Remote Users to Crash the Web Server
12117| [1001304] Apache Web Server for Windows Lets Remote Users Crash the Web Server Application
12118| [1001083] Apache Web Server May Display Directory Index Listings Even if Directory Listings Are Disabled
12119|
12120| OSVDB - http://www.osvdb.org:
12121| [96078] Apache CloudStack Infrastructure Menu Setup Network Multiple Field XSS
12122| [96077] Apache CloudStack Global Settings Multiple Field XSS
12123| [96076] Apache CloudStack Instances Menu Display Name Field XSS
12124| [96075] Apache CloudStack Instances Menu Add Instances Network Name Field XSS
12125| [96074] Apache CloudStack Instances Menu Add Instances Review Step Multiple Field XSS
12126| [96031] Apache HTTP Server suEXEC Symlink Arbitrary File Access
12127| [95888] Apache Archiva Single / Double Quote Character Handling XSS Weakness
12128| [95885] Apache Subversion mod_dav_svn Module Crafted HTTP Request Handling Remote DoS
12129| [95706] Apache OpenOffice.org (OOo) OOXML Document File XML Element Handling Memory Corruption
12130| [95704] Apache OpenOffice.org (OOo) DOC File PLCF Data Handling Memory Corruption
12131| [95603] Apache Continuum web/util/GenerateRecipentNotifier.java recipient Parameter XSS
12132| [95602] Apache Continuum web/action/notifier/JabberProjectNotifierEditAction-jabberProjectNotifierSave-validation.xml Multiple Parameter XSS
12133| [95601] Apache Continuum web/action/notifier/JabberGroupNotifierEditAction-jabberProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
12134| [95600] Apache Continuum web/action/ScheduleAction-saveSchedule-validation.xml Multiple Parameter XSS
12135| [95599] Apache Continuumweb/action/BuildDefinitionAction-saveBuildDefinition-validation.xml Multiple Parameter XSS
12136| [95598] Apache Continuum web/action/AddProjectAction-addProject-validation.xml Multiple Parameter XSS
12137| [95597] Apache Continuum web/action/ProjectEditAction-projectSave-validation.xml Multiple Parameter XSS
12138| [95596] Apache Continuum web/action/notifier/IrcGroupNotifierEditAction-ircProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
12139| [95595] Apache Continuum web/action/notifier/IrcProjectNotifierEditAction-ircProjectNotifierSave-validation.xml Multiple Parameter XSS
12140| [95594] Apache Continuum web/action/ProjectGroupAction.java Multiple Parameter XSS
12141| [95593] Apache Continuum web/action/AddProjectGroupAction.java Multiple Parameter XSS
12142| [95592] Apache Continuum web/action/AddProjectAction.java Multiple Parameter XSS
12143| [95523] Apache OFBiz Webtools Application View Log Screen Unspecified XSS
12144| [95522] Apache OFBiz Nested Expression Evaluation Arbitrary UEL Function Execution
12145| [95521] Apache HTTP Server mod_session_dbd Session Saving Unspecified Issue
12146| [95498] Apache HTTP Server mod_dav.c Crafted MERGE Request Remote DoS
12147| [95406] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Arbitrary Site Redirect
12148| [95405] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Remote Code Execution
12149| [95011] Apache CXF XML Parser SOAP Message Handling CPU Resource Exhaustion Remote DoS
12150| [94705] Apache Geronimo RMI Classloader Exposure Serialized Object Handling Remote Code Execution
12151| [94651] Apache Santuario (XML Security for C++) XML Signature CanonicalizationMethod Parameter Spoofing Weakness
12152| [94636] Apache Continuum workingCopy.action userDirectory Traversal Arbitrary File Access
12153| [94635] Apache Maven SCM SvnCommandlineUtils Process Listing Local Password Disclosure
12154| [94632] Apache Maven Wagon SSH (wagon-ssh) Host Verification Failure MitM Weakness
12155| [94625] Apache Santuario (XML Security for C++) XML Signature Reference Crafted XPointer Expression Handling Heap Buffer Overflow
12156| [94618] Apache Archiva /archiva/security/useredit.action username Parameter XSS
12157| [94617] Apache Archiva /archiva/security/roleedit.action name Parameter XSS
12158| [94616] Apache Archiva /archiva/security/userlist!show.action roleName Parameter XSS
12159| [94615] Apache Archiva /archiva/deleteArtifact!doDelete.action groupId Parameter XSS
12160| [94614] Apache Archiva /archiva/admin/addLegacyArtifactPath!commit.action legacyArtifactPath.path Parameter XSS
12161| [94613] Apache Archiva /archiva/admin/addRepository.action Multiple Parameter XSS
12162| [94612] Apache Archiva /archiva/admin/editAppearance.action Multiple Parameter XSS
12163| [94611] Apache Archiva /archiva/admin/addLegacyArtifactPath.action Multiple Parameter XSS
12164| [94610] Apache Archiva /archiva/admin/addNetworkProxy.action Multiple Parameter XSS
12165| [94403] Apache Santuario (XML Security for C++) InclusiveNamespace PrefixList Processing Heap Overflow
12166| [94402] Apache Santuario (XML Security for C++) HMAC-based XML Signature Processing DoS
12167| [94401] Apache Santuario (XML Security for C++) XPointer Evaluation Stack Overflow
12168| [94400] Apache Santuario (XML Security for C++) HMAC-Based XML Signature Reference Element Validation Spoofing Weakness
12169| [94279] Apache Qpid CA Certificate Validation Bypass
12170| [94275] Apache Solr JettySolrRunner.java Can Not Find Error Message XSS
12171| [94233] Apache OpenJPA Object Deserialization Arbitrary Executable Creation
12172| [94042] Apache Axis JAX-WS Java Unspecified Exposure
12173| [93969] Apache Struts OGNL Expression Handling Double Evaluation Error Remote Command Execution
12174| [93796] Apache Subversion Filename Handling FSFS Repository Corruption Remote DoS
12175| [93795] Apache Subversion svnserve Server Aborted Connection Message Handling Remote DoS
12176| [93794] Apache Subversion contrib/hook-scripts/check-mime-type.pl svnlook Hyphenated argv Argument Handling Remote DoS
12177| [93793] Apache Subversion contrib/hook-scripts/svn-keyword-check.pl Filename Handling Remote Command Execution
12178| [93646] Apache Struts Crafted Parameter Arbitrary OGNL Code Execution
12179| [93645] Apache Struts URL / Anchor Tag includeParams Attribute Remote Command Execution
12180| [93636] Apache Pig Multiple Physical Operator Memory Exhaustion Remote Remote DoS
12181| [93635] Apache Wink DTD (Document Type Definition) Expansion Data Parsing Information Disclosure
12182| [93605] RT Apache::Session::File Session Replay Reuse Information Disclosure
12183| [93599] Apache Derby SYSCS_UTIL.SYSCS_SET_DATABASE_PROPERTY Boot Password Manipulation Re-encryption Failure Password Corruption
12184| [93555] Apache Commons Codec Invalid Base32 String Information Tunneling Weakness
12185| [93554] Apache HBase bulkLoadHFiles() Method ACL Bypass
12186| [93543] JBoss Enterprise Application Platform org.apache.catalina.connector.Response.encodeURL() Method MitM jsessionid Disclosure
12187| [93542] Apache ManifoldCF (Connectors Framework) org.apache.manifoldcf.crawler.ExportConfiguration Class Configuration Export Password Disclosure
12188| [93541] Apache Solr json.wrf Callback XSS
12189| [93524] Apache Hadoop GetSecurityDescriptorControl() Function Absolute Security Descriptor Handling NULL Descriptor Weakness
12190| [93521] Apache jUDDI Security API Token Session Persistence Weakness
12191| [93520] Apache CloudStack Default SSL Key Weakness
12192| [93519] Apache Shindig /ifr Cross-site Arbitrary Gadget Invocation
12193| [93518] Apache Solr /admin/analysis.jsp name Parameter XSS
12194| [93517] Apache CloudStack setup-cloud-management /etc/sudoers Modification Local Privilege Escalation
12195| [93516] Apache CXF UsernameTokenInterceptor Nonce Caching Replay Weakness
12196| [93515] Apache HBase table.jsp name Parameter XSS
12197| [93514] Apache CloudStack Management Server Unauthenticated Remote JMX Connection Default Setting Weakness
12198| [93463] Apache Struts EL / OGNL Interpretation Unspecified Remote Code Execution
12199| [93462] Apache CXF WS-SecurityPolicy AlgorithmSuite Arbitrary Ciphertext Decryption Weakness
12200| [93401] Apache Hadoop core-site.xml Permission Weakness Local Alfredo Secret Disclosure
12201| [93400] Apache Hadoop Map/Reduce Job Log Directory Symlink Arbitrary File Mode Manipulation
12202| [93397] Apache Wicket Referrer HTTP Header Session ID Disclosure
12203| [93366] Apache HTTP Server modules/mappers/mod_rewrite.c do_rewritelog() Function Log File Terminal Escape Sequence Filtering Remote Command Execution
12204| [93254] Apache Tomcat AsyncListener Method Cross-session Information Disclosure
12205| [93253] Apache Tomcat Chunked Transfer Encoding Data Saturation Remote DoS
12206| [93252] Apache Tomcat FORM Authenticator Session Fixation
12207| [93172] Apache Camel camel/endpoints/ Endpoint XSS
12208| [93171] Apache Sling HtmlResponse Error Message XSS
12209| [93170] Apache Directory DelegatingAuthenticator MitM Spoofing Weakness
12210| [93169] Apache Wave AuthenticationServlet.java Session Fixation Weakness
12211| [93168] Apache Click ErrorReport.java id Parameter XSS
12212| [93167] Apache ActiveMQ JMSXUserId Spoofing Weakness
12213| [93166] Apache CXF Crafted Message Element Count Handling System Resource Exhaustion Remote DoS
12214| [93165] Apache CXF Crafted Message Element Level Handling System Resource Exhaustion Remote DoS
12215| [93164] Apache Harmony DatagramSocket Class connect Method CheckAccept() IP Blacklist Bypass
12216| [93163] Apache Hadoop Map/Reduce Daemon Symlink Arbitrary File Overwrite
12217| [93162] Apache VelocityStruts struts/ErrorsTool.getMsgs Error Message XSS
12218| [93161] Apache CouchDB Rewriter VM Atom Table Memory Exhaustion Remote DoS
12219| [93158] Apache Wicket BookmarkablePageLink Feature XSS CSRF
12220| [93157] Apache Struts UrlHelper.java s:url includeParams Functionality XSS
12221| [93156] Apache Tapestry Calendar Component datefield.js datefield Parameter XSS
12222| [93155] Apache Struts fielderror.ftl fielderror Parameter Error Message XSS
12223| [93154] Apache JSPWiki Edit.jsp createPages WikiPermission Bypass
12224| [93153] Apache PDFBox PDFXrefStreamParser Missing Element Handling PDF Parsing DoS
12225| [93152] Apache Hadoop HttpServer.java Multiple Function XSS
12226| [93151] Apache Shiro Search Filter userName Parameter LDAP Code Injection Weakness
12227| [93150] Apache Harmony java.net.SocketPermission Class boolean equals Function checkConnect() Weakness Host Name Retrieval
12228| [93149] Apache Harmony java.security.Provider Class void load Function checkSecurityAccess() Weakness
12229| [93148] Apache Harmony java.security.ProtectionDomain Class java.lang.String.toString() Function checkPermission() Weakness
12230| [93147] Apache Harmony java.net.URLConnection openConnection Function checkConnect Weakness Proxy Connection Permission Bypass
12231| [93146] Apache Harmony java.net.ServerSocket Class void implAccept Function checkAccept() Weakness SerSocket Subclass Creation
12232| [93145] Apache Qpid JMS Client Detached Session Frame Handling NULL Pointer Dereference Remote DoS
12233| [93144] Apache Solr Admin Command Execution CSRF
12234| [93009] Apache VCL XMLRPC API Unspecified Function Remote Privilege Escalation
12235| [93008] Apache VCL Web GUI Unspecified Remote Privilege Escalation
12236| [92997] Apache Commons Codec org.apache.commons.codec.net.URLCodec Fields Missing 'final' Thread-safety Unspecified Issue
12237| [92976] Apache ActiveMQ scheduled.jsp crontab Command XSS
12238| [92947] Apache Commons Codec org.apache.commons.codec.language.Soundex.US_ENGLISH_MAPPING Missing MS_PKGPROTECT Field Manipulation Unspecified Issue
12239| [92749] Apache CloudStack Predictable Hash Virtual Machine Console Console Access URL Generation
12240| [92748] Apache CloudStack VM Console Access Restriction Bypass
12241| [92709] Apache ActiveMQ Web Console Unauthenticated Remote Access
12242| [92708] Apache ActiveMQ Sample Web Application Broker Resource Consumption Remote DoS
12243| [92707] Apache ActiveMQ webapp/websocket/chat.js Subscribe Message XSS
12244| [92706] Apache ActiveMQ Debug Log Rendering XSS
12245| [92705] Apache ActiveMQ PortfolioPublishServlet.java refresh Parameter XSS
12246| [92270] Apache Tomcat Unspecified CSRF
12247| [92094] Apache Subversion mod_dav_svn Module Nonexistent URL Lock Request Handling NULL Pointer Dereference Remote DoS
12248| [92093] Apache Subversion mod_dav_svn Module Activity URL PROPFIND Request Handling NULL Pointer Dereference Remote DoS
12249| [92092] Apache Subversion mod_dav_svn Module Log REPORT Request Handling NULL Pointer Dereference Remote DoS
12250| [92091] Apache Subversion mod_dav_svn Module Node Property Handling Resource Exhaustion Remote DoS
12251| [92090] Apache Subversion mod_dav_svn Module Activity URL Lock Request Handling NULL Pointer Dereference Remote DoS
12252| [91774] Apache Commons Codec Unspecified Non-private Field Manipulation Weakness
12253| [91628] mod_ruid2 for Apache HTTP Server fchdir() Inherited File Descriptor chroot Restriction Bypass
12254| [91328] Apache Wicket $up$ Traversal Arbitrary File Access
12255| [91295] Apple Mac OS X Apache Unicode Character URI Handling Authentication Bypass
12256| [91235] Apache Rave /app/api/rpc/users/get User Object Hashed Password Remote Disclosure
12257| [91185] Munin Default Apache Configuration Permission Weakness Remote Information Disclosure
12258| [91173] Apache Wicket WebApplicationPath Constructor Bypass /WEB-INF/ Directory File Access
12259| [91172] Apache Wicket PackageResourceGuard File Extension Filter Bypass
12260| [91025] Apache Qpid qpid::framing::Buffer Class Multiple Method Out-of-bounds Access Remote DoS
12261| [91024] Apache Qpid federation_tag Attribute Handling Federated Interbroker Link Access Restriction Bypass
12262| [91023] Apache Qpid AMQP Type Decoder Exposure Array Size Value Handling Memory Consumption Remote DoS
12263| [91022] Apache Qpid qpid/cpp/include/qpid/framing/Buffer.h qpid::framing::Buffer::checkAvailable() Function Integer Overflow
12264| [90986] Apache Jena ARQ INSERT DATA Request Handling Overflow
12265| [90907] Apache Subversion mod_dav_svn / libsvn_fs svn_fs_file_length() Function MKACTIVITY / PROPFIND Option Request Handling Remote DoS
12266| [90906] Apache Commons FileUpload /tmp Storage Symlink Arbitrary File Overwrite
12267| [90864] Apache Batik 1xx Redirect Script Origin Restriction Bypass
12268| [90858] Apache Ant Malformed TAR File Handling Infinite Loop DoS
12269| [90852] Apache HTTP Server for Debian apachectl /var/lock Permission Weakness Symlink Directory Permission Manipulation
12270| [90804] Apache Commons CLI Path Subversion Local Privilege Escalation
12271| [90802] Apache Avro Recursive Schema Handling Infinite Recursion DoS
12272| [90592] Apache Batik ApplicationSecurityEnforcer.java Multiple Method Security Restriction Bypass
12273| [90591] Apache Batik XML External Entity (XXE) Data Parsing Arbitrary File Disclosure
12274| [90565] Apache Tomcat Log Directory Permission Weakness Local Information Disclosure
12275| [90564] Apache Maven / Maven Wagon SSL Certificate Validation MitM Spoofing Weakness
12276| [90557] Apache HTTP Server mod_proxy_balancer balancer-manager Interface Multiple Parameter XSS
12277| [90556] Apache HTTP Server Multiple Module Multiple Parameter XSS
12278| [90276] Apache Axis2 axis2.xml Plaintext Password Local Disclosure
12279| [90249] Apache Axiom ClassLoader XMLInputFactory / XMLOutputFactory Construction Unspecified Issue
12280| [90235] Apache Commons HttpClient Certificate Wildcard Matching Weakness
12281| [90079] Apache CXF WSS4JInInterceptor URIMappingInterceptor WS-Security SOAP Service Access Restriction Bypass
12282| [90078] Apache CXF WS-SecurityPolicy Enabled Plaintext UsernameTokens Handling Authentication Bypass
12283| [89453] Apache Open For Business Project (OFBiz) Screenlet.title Widget Attribute XSS
12284| [89452] Apache Open For Business Project (OFBiz) Image.alt Widget Attribute XSS
12285| [89294] Apache CouchDB Futon UI Browser-based Test Suite Query Parameter XSS
12286| [89293] Apache CouchDB Unspecified Traversal Arbitrary File Access
12287| [89275] Apache HTTP Server mod_proxy_ajp Module Expensive Request Parsing Remote DoS
12288| [89267] Apache CouchDB JSONP Callback Handling Unspecified XSS
12289| [89146] Apache CloudStack Master Server log4j.conf SSH Private Key / Plaintext Password Disclosure
12290| [88603] Apache OpenOffice.org (OOo) Unspecified Information Disclosure
12291| [88602] Apache OpenOffice.org (OOo) Unspecified Manifest-processing Issue
12292| [88601] Apache OpenOffice.org (OOo) Unspecified PowerPoint File Handling Issue
12293| [88285] Apache Tomcat Partial HTTP Request Saturation Remote DoS
12294| [88095] Apache Tomcat NIO Connector Terminated Connection Infinte Loop DoS
12295| [88094] Apache Tomcat FORM Authentication Crafted j_security_check Request Security Constraint Bypass
12296| [88093] Apache Tomcat Null Session Requst CSRF Prevention Filter Bypass
12297| [88043] IBM Tivoli Netcool/Reporter Apache CGI Unspecified Remote Command Execution
12298| [87580] Apache Tomcat DIGEST Authentication Session State Caching Authentication Bypass Weakness
12299| [87579] Apache Tomcat DIGEST Authentication Stale Nonce Verification Authentication Bypass Weakness
12300| [87477] Apache Tomcat Project Woodstock Service Error Page UTF-7 XSS Weakness
12301| [87227] Apache Tomcat InternalNioInputBuffer.java parseHeaders() Function Request Header Size Parsing Remote DoS
12302| [87223] Apache Tomcat DIGEST Authentication replay-countermeasure Functionality cnonce / cn Verification Authentication Bypass Weakness
12303| [87160] Apache Commons HttpClient X.509 Certificate Domain Name Matching MiTM Weakness
12304| [87159] Apache CXF X.509 Certificate Domain Name Matching MiTM Weakness
12305| [87150] Apache Axis / Axis2 X.509 Certificate Domain Name Matching MiTM Weakness
12306| [86902] Apache HTTP Server 3xx Redirect Internal IP Address Remote Disclosure
12307| [86901] Apache Tomcat Error Message Path Disclosure
12308| [86684] Apache CloudStack Unauthorized Arbitrary API Call Invocation
12309| [86556] Apache Open For Business Project (OFBiz) Unspecified Issue
12310| [86503] Visual Tools VS home/apache/DiskManager/cron/init_diskmgr Local Command Execution
12311| [86401] Apache ActiveMQ ResourceHandler Traversal Arbitrary File Access
12312| [86225] Apache Axis2 XML Signature Wrapping (XSW) Authentication Bypass
12313| [86206] Apache Axis2 Crafted SAML Assertion Signature Exclusion Attack Authentication Bypass
12314| [85722] Apache CXF SOAP Request Parsing Access Restriction Bypass
12315| [85704] Apache Qpid Incoming Client Connection Saturation Remote DoS
12316| [85474] Eucalyptus Apache Santuario (XML Security for Java) Library XML Signature Transform Handling DoS
12317| [85430] Apache mod_pagespeed Module Unspecified XSS
12318| [85429] Apache mod_pagespeed Module Hostname Verification Cross-host Resource Disclosure
12319| [85249] Apache Wicket Unspecified XSS
12320| [85236] Apache Hadoop conf/hadoop-env.sh Temporary File Symlink Arbitrary File Manipulation
12321| [85090] Apache HTTP Server mod_proxy_ajp.c mod_proxy_ajp Module Proxy Functionality Cross-client Information Disclosure
12322| [85089] Apache HTTP Server mod_proxy_http.c mod_proxy_http Module Cross-client Information Disclosure
12323| [85062] Apache Solr Autocomplete Module for Drupal Autocomplete Results XSS
12324| [85010] Apache Struts Token Handling Mechanism Token Name Configuration Parameter CSRF Weakness
12325| [85009] Apache Struts Request Parameter OGNL Expression Parsing Remote DoS
12326| [84911] libapache2-mod-rpaf X-Forward-For HTTP Header Parsing Remote DoS
12327| [84823] Apache HTTP Server Multiple Module Back End Server Error Handling HTTP Request Parsing Remote Information Disclosure
12328| [84818] Apache HTTP Server mod_negotiation Module mod_negotiation.c make_variant_list Function XSS
12329| [84562] Apache Qpid Broker Authentication Mechanism AMQP Client Shadow Connection NullAuthenticator Request Parsing Authentication Bypass
12330| [84458] Apache Libcloud SSL Certificate Validation MitM Spoofing Weakness
12331| [84279] PHP on Apache php_default_post_reader POST Request Handling Overflow DoS
12332| [84278] PHP w/ Apache PDO::ATTR_DEFAULT_FETCH_MODE / PDO::FETCH_CLASS DoS
12333| [84231] Apache Hadoop DataNodes Client BlockTokens Arbitrary Block Access
12334| [83943] Oracle Solaris Cluster Apache Tomcat Agent Subcomponent Unspecified Local Privilege Escalation
12335| [83939] Oracle Solaris Apache HTTP Server Subcomponent Unspecified Remote Information Disclosure
12336| [83685] svnauthcheck Apache HTTP Configuration File Permission Revocation Weakness
12337| [83682] Apache Sling POST Servlet @CopyFrom Operation HTTP Request Parsing Infinite Loop Remote DoS
12338| [83339] Apache Roller Blogger Roll Unspecified XSS
12339| [83270] Apache Roller Unspecified Admin Action CSRF
12340| [82782] Apache CXF WS-SecurityPolicy 1.1 SupportingToken Policy Bypass
12341| [82781] Apache CXF WS-SecurityPolicy Supporting Token Children Specification Token Signing Verification Weakness
12342| [82611] cPanel Apache Piped Log Configuration Log Message Formatting Traversal Arbitrary File Creation
12343| [82436] MapServer for Windows Bundled Apache / PHP Configuration Local File Inclusion
12344| [82215] PHP sapi/cgi/cgi_main.c apache_request_headers Function HTTP Header Handling Remote Overflow
12345| [82161] Apache Commons Compress bzip2 File Compression BZip2CompressorOutputStream Class File Handling Remote DoS
12346| [81965] Apache Batik Squiggle SVG Browser JAR File Arbitrary Code Execution
12347| [81790] Apache POI src/org/apache/poi/hwpf/model/UnhandledDataStructure.java UnhandledDataStructure() constructor Length Attribute CDF / CFBF File Handling Remote DoS
12348| [81660] Apache Qpid Credential Checking Cluster Authentication Bypass
12349| [81511] Apache for Debian /usr/share/doc HTTP Request Parsing Local Script Execution
12350| [81359] Apache HTTP Server LD_LIBRARY_PATH Variable Local Privilege Escalation
12351| [81349] Apache Open For Business Project (OFBiz) Webslinger Component Unspecified XSS
12352| [81348] Apache Open For Business Project (OFBiz) Content IDs / Map-Keys Unspecified XSS
12353| [81347] Apache Open For Business Project (OFBiz) Parameter Arrays Unspecified XSS
12354| [81346] Apache Open For Business Project (OFBiz) checkoutProcess.js getServerError() Function Unspecified XSS
12355| [81196] Apache Open For Business Project (OFBiz) FlexibleStringExpander Nested Script String Parsing Remote Code Execution
12356| [80981] Apache Hadoop Kerberos/MapReduce Security Feature User Impersonation Weakness
12357| [80571] Apache Traffic Server Host HTTP Header Parsing Remote Overflow
12358| [80547] Apache Struts XSLTResult.java File Upload Arbitrary Command Execution
12359| [80360] AskApache Password Protector Plugin for WordPress Error Page $_SERVER Superglobal XSS
12360| [80349] Apache HTTP Server mod_fcgid Module fcgid_spawn_ctl.c FcgidMaxProcessesPerClass Virtual Host Directive HTTP Request Parsing Remote DoS
12361| [80301] Apache Wicket /resources/ Absolute Path Arbitrary File Access
12362| [80300] Apache Wicket wicket:pageMapName Parameter XSS
12363| [79478] Apache Solr Extension for TYPO3 Unspecified XSS
12364| [79002] Apache MyFaces javax.faces.resource In Parameter Traversal Arbitrary File Access
12365| [78994] Apache Struts struts-examples/upload/upload-submit.do name Parameter XSS
12366| [78993] Apache Struts struts-cookbook/processDyna.do message Parameter XSS
12367| [78992] Apache Struts struts-cookbook/processSimple.do message Parameter XSS
12368| [78991] Apache Struts struts2-rest-showcase/orders clientName Parameter XSS
12369| [78990] Apache Struts struts2-showcase/person/editPerson.action Multiple Parameter XSS
12370| [78932] Apache APR Hash Collision Form Parameter Parsing Remote DoS
12371| [78903] Apache CXF SOAP Request Parsing WS-Security UsernameToken Policy Bypass
12372| [78600] Apache Tomcat HTTP DIGEST Authentication DigestAuthenticator.java Catalina Weakness Security Bypass
12373| [78599] Apache Tomcat HTTP DIGEST Authentication Realm Value Parsing Security Bypass
12374| [78598] Apache Tomcat HTTP DIGEST Authentication qop Value Parsing Security Bypass
12375| [78573] Apache Tomcat Parameter Saturation CPU Consumption Remote DoS
12376| [78556] Apache HTTP Server Status Code 400 Default Error Response httpOnly Cookie Disclosure
12377| [78555] Apache HTTP Server Threaded MPM %{cookiename}C Log Format String Cookie Handling Remote DoS
12378| [78501] Apache Struts ParameterInterceptor Class OGNL Expression Parsing Remote Command Execution
12379| [78331] Apache Tomcat Request Object Recycling Information Disclosure
12380| [78293] Apache HTTP Server Scoreboard Invalid Free Operation Local Security Bypass
12381| [78277] Apache Struts ExceptionDelegator Component Parameter Parsing Remote Code Execution
12382| [78276] Apache Struts DebuggingInterceptor Component Developer Mode Unspecified Remote Command Execution
12383| [78113] Apache Tomcat Hash Collision Form Parameter Parsing Remote DoS
12384| [78112] Apache Geronimo Hash Collision Form Parameter Parsing Remote DoS
12385| [78109] Apache Struts ParameterInterceptor Traversal Arbitrary File Overwrite
12386| [78108] Apache Struts CookieInterceptor Cookie Name Handling Remote Command Execution
12387| [77593] Apache Struts Conversion Error OGNL Expression Injection
12388| [77496] Apache ActiveMQ Failover Mechanism Openwire Request Parsing Remote DoS
12389| [77444] Apache HTTP Server mod_proxy Mdule Web Request HTTP/0.9 Protocol URL Parsing Proxy Remote Security Bypass
12390| [77374] Apache MyFaces Java Bean includeViewParameters Parsing EL Expression Security Weakness
12391| [77310] Apache HTTP Server mod_proxy Reverse Proxy Mode Security Bypass Weakness (2011-4317)
12392| [77234] Apache HTTP Server on cygwin Encoded Traversal Arbitrary File Access
12393| [77012] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Memory Consumption DoS
12394| [76944] Apache Tomcat Manager Application Servlets Access Restriction Bypass
12395| [76744] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Overflow
12396| [76189] Apache Tomcat HTTP DIGEST Authentication Weakness
12397| [76079] Apache HTTP Server mod_proxy Mdule Web Request URL Parsing Proxy Remote Security Bypass (2011-3368)
12398| [76072] Apache JServ jserv.conf jserv-status Handler jserv/ URI Request Parsing Local Information Disclosure
12399| [75807] Apache HTTP Server Incomplete Header Connection Saturation Remote DoS
12400| [75647] Apache HTTP Server mod_proxy_ajp Module mod_proxy_balancer HTTP Request Remote DoS
12401| [75376] Apache Libcloud SSL Certificate Validation MitM Server Spoofing Weakness
12402| [74853] Domain Technologie Control /etc/apache2/apache2.conf File Permissions Weakness dtcdaemons User Password Disclosure
12403| [74818] Apache Tomcat AJP Message Injection Authentication Bypass
12404| [74725] Apache Wicket Multi Window Support Unspecified XSS
12405| [74721] Apache HTTP Server ByteRange Filter Memory Exhaustion Remote DoS
12406| [74541] Apache Commons Daemon Jsvc Permissions Weakness Arbitrary File Access
12407| [74535] Apache Tomcat XML Parser Cross-application Multiple File Manipulation
12408| [74447] Apache Struts XWork Nonexistent Method s:submit Element Internal Java Class Remote Path Disclosure
12409| [74262] Apache HTTP Server Multi-Processing Module itk.c Configuration Merger mpm-itk root UID / GID Remote Privilege Escalation
12410| [74120] Apache HTTP Server mod_authnz_external mysql/mysql-auth.pl user Field SQL Injection
12411| [73920] Oracle Secure Backup /apache/htdocts/php/common.php username Parameter Remote Code Execution
12412| [73798] Apache Tomcat sendfile Request Start / Endpoint Parsing Local DoS
12413| [73797] Apache Tomcat sendfile Request Attribute Validation Weakness Local Access Restriction Bypass
12414| [73776] Apache Tomcat HTTP BIO Connector HTTP Pipelining Cross-user Remote Response Access
12415| [73644] Apache XML Security Signature Key Parsing Overflow DoS
12416| [73600] Apache Struts javatemplates Plugin Component Handlers .action URI Multiple Parameter XSS
12417| [73462] Apache Rampart/C util/rampart_timestamp_token.c rampart_timestamp_token_validate Function Expired Token Remote Access Restriction Bypass
12418| [73429] Apache Tomcat JMX MemoryUserDatabase Local Password Disclosure
12419| [73384] Apache HTTP Server mod_rewrite PCRE Resource Exhaustion DoS
12420| [73383] Apache HTTP Server Portable Runtime (APR) Library apr_fnmatch() Infinite Loop Remote DoS
12421| [73378] IBM WebSphere Application Server (WAS) JavaServer Pages org.apache.jasper.runtime.JspWriterImpl.response JSP Page Application Restart Remote DoS
12422| [73247] Apache Subversion mod_dav_svn File Permission Weakness Information Disclosure
12423| [73246] Apache Subversion mod_dav_svn Path-based Access Control Rule Handling Remote DoS
12424| [73245] Apache Subversion mod_dav_svn Baselined Resource Request Handling Remote DoS
12425| [73154] Apache Archiva Multiple Unspecified CSRF
12426| [73153] Apache Archiva /archiva/admin/deleteNetworkProxy!confirm.action proxyid Parameter XSS
12427| [72407] Apache Tomcat @ServletSecurity Initial Load Annotation Security Constraint Bypass Information Disclosure
12428| [72238] Apache Struts Action / Method Names <
12429| [71647] Apache HttpComponents HttpClient Proxy-Authorization Credentials Remote Disclosure
12430| [71558] Apache Tomcat SecurityManager ServletContext Attribute Traversal Arbitrary File Manipulation
12431| [71557] Apache Tomcat HTML Manager Multiple XSS
12432| [71075] Apache Archiva User Management Page XSS
12433| [71027] Apache Tomcat @ServletSecurity Annotation Security Constraint Bypass Information Disclosure
12434| [70925] Apache Continuum Project Pages Unspecified XSS (2011-0533)
12435| [70924] Apache Continuum Multiple Admin Function CSRF
12436| [70809] Apache Tomcat NIO HTTP Connector Request Line Processing DoS
12437| [70734] Apache CouchDB Request / Cookie Handling Unspecified XSS
12438| [70585] Oracle Fusion Middleware Oracle HTTP Server Apache Plugin Unspecified Remote Issue
12439| [70333] Apache Subversion rev_hunt.c blame Command Multiple Memory Leak Remote DoS
12440| [70332] Apache Subversion Apache HTTP Server mod_dav_svn repos.c walk FunctionSVNParentPath Collection Remote DoS
12441| [69659] Apache Archiva Admin Authentication Weakness Privilege Escalation
12442| [69520] Apache Archiva Administrator Credential Manipulation CSRF
12443| [69512] Apache Tomcat Set-Cookie Header HTTPOnly Flag Session Hijacking Weakness
12444| [69456] Apache Tomcat Manager manager/html/sessions Multiple Parameter XSS
12445| [69275] Apache mod_fcgid Module fcgid_bucket.c fcgid_header_bucket_read() Function Remote Overflow
12446| [69067] Apache Shiro URI Path Security Traversal Information Disclosure
12447| [68815] Apache MyFaces shared/util/StateUtils.java View State MAC Weakness Cryptographic Padding Remote View State Modification
12448| [68670] Apache Qpid C++ Broker Component broker/SessionAdapter.cpp SessionAdapter::ExchangeHandlerImpl::checkAlternate Function Exchange Alternate Remote DoS
12449| [68669] Apache Qpid cluster/Cluster.cpp Cluster::deliveredEvent Function Invalid AMQP Data Remote DoS
12450| [68662] Apache Axis2 dswsbobje.war Module Admin Account Default Password
12451| [68531] Apache Qpid qpidd sys/ssl/SslSocket.cpp Incomplete SSL Handshake Remote DoS
12452| [68327] Apache APR-util buckets/apr_brigade.c apr_brigade_split_line() Function Memory Consumption DoS
12453| [68314] Apache XML-RPC SAX Parser External Entity Information Disclosure
12454| [67964] Apache Traffic Server Transaction ID / Source Port Randomization Weakness DNS Cache Poisoning
12455| [67846] SUSE Lifecycle Management Server on SUSE Linux Enterprise apache2-slms Parameter Quoting CSRF
12456| [67294] Apache CXF XML SOAP Message Crafted Document Type Declaration Remote DoS
12457| [67240] Apache CouchDB Installation Page Direct Request Arbitrary JavaScript Code Execution CSRF
12458| [67205] Apache Derby BUILTIN Authentication Password Hash Generation Algorithm SHA-1 Transformation Password Substitution
12459| [66745] Apache HTTP Server Multiple Modules Pathless Request Remote DoS
12460| [66319] Apache Tomcat Crafted Transfer-Encoding Header Handling Buffer Recycling Remote DoS
12461| [66280] Apache Struts XWork ParameterInterceptor Server-Side Object Remote Code Execution
12462| [66226] Apache Axis2 Admin Interface Cookie Session Fixation
12463| [65697] Apache Axis2 / Java SOAP Message DTD Rejection Weakness Arbitrary File Access
12464| [65654] Apache HTTP Server mod_proxy_http mod_proxy_http.c Timeout Detection Weakness HTTP Request Response Disclosure
12465| [65429] Apache MyFaces Unencrypted ViewState Serialized View Object Manipulation Arbitrary Expression Language (EL) Statement Execution
12466| [65054] Apache ActiveMQ Jetty Error Handler XSS
12467| [64844] Apache Axis2/Java axis2/axis2-admin/engagingglobally modules Parameter XSS
12468| [64522] Apache Open For Business Project (OFBiz) ecommerce/control/contactus Multiple Parameter XSS
12469| [64521] Apache Open For Business Project (OFBiz) Web Tools Section entityName Parameter XSS
12470| [64520] Apache Open For Business Project (OFBiz) ecommerce/control/ViewBlogArticle contentId Parameter XSS
12471| [64519] Apache Open For Business Project (OFBiz) Control Servlet URI XSS
12472| [64518] Apache Open For Business Project (OFBiz) Show Portal Page Section start Parameter XSS
12473| [64517] Apache Open For Business Project (OFBiz) View Profile Section partyId Parameter XSS
12474| [64516] Apache Open For Business Project (OFBiz) Export Product Listing Section productStoreId Parameter XSS
12475| [64307] Apache Tomcat Web Application Manager/Host Manager CSRF
12476| [64056] mod_auth_shadow for Apache HTTP Server wait() Function Authentication Bypass
12477| [64023] Apache Tomcat WWW-Authenticate Header Local Host Information Disclosure
12478| [64020] Apache ActiveMQ Jetty ResourceHandler Crafted Request JSP File Source Disclosure
12479| [63895] Apache HTTP Server mod_headers Unspecified Issue
12480| [63368] Apache ActiveMQ createDestination.action JMSDestination Parameter CSRF
12481| [63367] Apache ActiveMQ createDestination.action JMSDestination Parameter XSS
12482| [63350] Apache CouchDB Hash Verification Algorithm Predictable Execution Time Weakness
12483| [63140] Apache Thrift Service Malformed Data Remote DoS
12484| [62676] Apache HTTP Server mod_proxy_ajp Module Crafted Request Remote DoS
12485| [62675] Apache HTTP Server Multi-Processing Module (MPM) Subrequest Header Handling Cross-thread Information Disclosure
12486| [62674] Apache HTTP Server mod_isapi Module Unloading Crafted Request Remote DoS
12487| [62231] Apache HTTP Server Logging Format Weakness Crafted DNS Response IP Address Spoofing
12488| [62230] Apache HTTP Server Crafted DNS Response Inverse Lookup Log Corruption XSS
12489| [62054] Apache Tomcat WAR Filename Traversal Work-directory File Deletion
12490| [62053] Apache Tomcat Autodeployment Process appBase File HTTP Request Authentication Bypass
12491| [62052] Apache Tomcat WAR File Traversal Arbitrary File Overwrite
12492| [62009] Apache HTTP Server src/modules/proxy/proxy_util.c mod_proxy ap_proxy_send_fb() Function Overflow
12493| [61379] Apache River Outrigger Entry Storage Saturation Memory Exhaustion DoS
12494| [61378] Apache Hadoop Map/Reduce JobTracker Memory Consumption DoS
12495| [61377] Apache Commons Modeler Multiple Mutable Static Fields Weakness
12496| [61376] Apache Rampart wsse:security Tag Signature Value Checking Weakness
12497| [60687] Apache C++ Standard Library (STDCXX) strxfrm() Function Overflow
12498| [60680] Apache Hadoop JobHistory Job Name Manipulation Weakness
12499| [60679] Apache ODE DeploymentWebService OMElement zipPart CRLF Injection
12500| [60678] Apache Roller Comment Email Notification Manipulation DoS
12501| [60677] Apache CouchDB Unspecified Document Handling Remote DoS
12502| [60428] Sun Java Plug-in org.apache.crimson.tree.XmlDocument Class reateXmlDocument Method Floppy Drive Access Bypass
12503| [60413] mod_throttle for Apache Shared Memory File Manipulation Local Privilege Escalation
12504| [60412] Sun Java Plug-in org.apache.xalan.processor.XSLProcessorVersion Class Unsigned Applet Variable Sharing Privilege Escalation
12505| [60396] Apache HTTP Server on OpenBSD Multipart MIME Boundary Remote Information Disclosure
12506| [60395] Apache HTTP Server on OpenBSD ETag HTTP Header Remote Information Disclosure
12507| [60232] PHP on Apache php.exe Direct Request Remote DoS
12508| [60176] Apache Tomcat Windows Installer Admin Default Password
12509| [60016] Apache HTTP Server on HP Secure OS for Linux HTTP Request Handling Unspecified Issue
12510| [59979] Apache HTTP Server on Apple Mac OS X HTTP TRACE Method Unspecified Client XSS
12511| [59969] Apache HTTP Server mod_ssl SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection
12512| [59944] Apache Hadoop jobhistory.jsp XSS
12513| [59374] Apache Solr Search Extension for TYPO3 Unspecified XSS
12514| [59022] Apache Shindig ConcatProxyServlet HTTP Header Response Splitting
12515| [59021] Apache Cocoon X-Cocoon-Version Header Remote Information Disclosure
12516| [59020] Apache Tapestry HTTPS Session Cookie Secure Flag Weakness
12517| [59019] Apache mod_python Cookie Salting Weakness
12518| [59018] Apache Harmony Error Message Handling Overflow
12519| [59013] Apache Derby SYSCS_EXPORT_TABLE Arbitrary File Overwrite
12520| [59012] Apache Derby Driver Auto-loading Non-deterministic Startup Weakness
12521| [59011] Apache JSPWiki Page Attachment Change Note Function XSS
12522| [59010] Apache Solr get-file.jsp XSS
12523| [59009] Apache Solr action.jsp XSS
12524| [59008] Apache Solr analysis.jsp XSS
12525| [59007] Apache Solr schema.jsp Multiple Parameter XSS
12526| [59006] Apache Beehive select / checkbox Tag XSS
12527| [59005] Apache Beehive jpfScopeID Global Parameter XSS
12528| [59004] Apache Beehive Error Message XSS
12529| [59003] Apache HttpClient POST Request Handling Memory Consumption DoS
12530| [59002] Apache Jetspeed default-page.psml URI XSS
12531| [59001] Apache Axis2 xsd Parameter Traversal Arbitrary File Disclosure
12532| [59000] Apache CXF Unsigned Message Policy Bypass
12533| [58999] Apache WSS4J CallbackHandler Plaintext Password Validation Weakness
12534| [58998] Apache OpenJPA persistence.xml Cleartext Password Local Disclosure
12535| [58997] Apache OpenEJB openejb.xml Cleartext Password Local Disclosure
12536| [58996] Apache Hadoop Map/Reduce LinuxTaskController File Group Ownership Weakness
12537| [58995] Apache Hadoop Map/Reduce Task Ownership Weakness
12538| [58994] Apache Hadoop Map/Reduce DistributedCache Localized File Permission Weakness
12539| [58993] Apache Hadoop browseBlock.jsp XSS
12540| [58991] Apache Hadoop browseDirectory.jsp XSS
12541| [58990] Apache Hadoop Map/Reduce HTTP TaskTrackers User Data Remote Disclosure
12542| [58989] Apache Hadoop Sqoop Process Listing Local Cleartext Password Disclosure
12543| [58988] Apache Hadoop Chukwa HICC Portal Unspecified XSS
12544| [58987] Apache Hadoop Map/Reduce TaskTracker User File Permission Weakness
12545| [58986] Apache Qpid Encrypted Message Handling Remote Overflow DoS
12546| [58985] Apache Qpid Process Listing Local Cleartext Password Disclosure
12547| [58984] Apache Jackrabbit Content Repository (JCR) Default Account Privilege Access Weakness
12548| [58983] Apache Jackrabbit Content Repository (JCR) NamespaceRegistry API Registration Method Race Condition
12549| [58982] Apache Synapse Proxy Service Security Policy Mismatch Weakness
12550| [58981] Apache Geronimo TomcatGeronimoRealm Security Context Persistence Weakness
12551| [58980] Apache Geronimo LDAP Realm Configuration Restart Reversion Weakness
12552| [58979] Apache MyFaces Tomahawk ExtensionsPhaseListener HTML Injection Information Disclosure
12553| [58978] Apache MyFaces Trinidad LocaleInfoScriptlet XSS
12554| [58977] Apache Open For Business Project (OFBiz) Multiple Default Accounts
12555| [58976] Apache Open For Business Project (OFBiz) URI passThru Parameter XSS
12556| [58975] Apache Open For Business Project (OFBiz) PARTYMGR_CREATE/UPDATE Permission Arbitrary User Password Modification
12557| [58974] Apache Sling /apps Script User Session Management Access Weakness
12558| [58973] Apache Tuscany Crafted SOAP Request Access Restriction Bypass
12559| [58931] Apache Geronimo Cookie Parameters Validation Weakness
12560| [58930] Apache Xalan-C++ XPath Handling Remote DoS
12561| [58879] Apache Portable Runtime (APR-util) poll/unix/port.c Event Port Backend Pollset Feature Remote DoS
12562| [58837] Apache Commons Net FTPSClient CipherSuites / Protocols Mutable Object Unspecified Data Security Issue
12563| [58813] Apache MyFaces Trinidad tr:table / HTML Comment Handling DoS
12564| [58812] Apache Open For Business Project (OFBiz) JSESSIONID Session Hijacking Weakness
12565| [58811] Apache Open For Business Project (OFBiz) /catalog/control/EditProductConfigItem configItemId Parameter XSS
12566| [58810] Apache Open For Business Project (OFBiz) /catalog/control/EditProdCatalo prodCatalogId Parameter XSS
12567| [58809] Apache Open For Business Project (OFBiz) /partymgr/control/viewprofile partyId Parameter XSS
12568| [58808] Apache Open For Business Project (OFBiz) /catalog/control/createProduct internalName Parameter XSS
12569| [58807] Apache Open For Business Project (OFBiz) Multiple Unspecified CSRF
12570| [58806] Apache FtpServer MINA Logging Filter Cleartext Credential Local Disclosure
12571| [58805] Apache Derby Unauthenticated Database / Admin Access
12572| [58804] Apache Wicket Header Contribution Unspecified Issue
12573| [58803] Apache Wicket Session Fixation
12574| [58802] Apache Directory Server (ApacheDS) userPassword Attribute Search Password Disclosure
12575| [58801] Apache ActiveMQ Stomp Client Credential Validation Bypass
12576| [58800] Apache Tapestry (context)/servicestatus Internal Service Information Disclosure
12577| [58799] Apache Tapestry Logging Cleartext Password Disclosure
12578| [58798] Apache Jetspeed pipeline Parameter pipeline-map Policy Bypass
12579| [58797] Apache Jetspeed Password Policy Multiple Weaknesses
12580| [58796] Apache Jetspeed Unsalted Password Storage Weakness
12581| [58795] Apache Rampart Crafted SOAP Header Authentication Bypass
12582| [58794] Apache Roller Admin Protocol (RAP) Malformed Header Authentication Bypass
12583| [58793] Apache Hadoop Map/Reduce mapred.system.dir Permission Weakness Job Manipulation
12584| [58792] Apache Shindig gadgets.rpc iframe RPC Call Validation Weakness
12585| [58791] Apache Synapse synapse.properties Cleartext Credential Local Disclosure
12586| [58790] Apache WSS4J SOAP Message UsernameToken Remote Password Disclosure
12587| [58789] Apache WSS4J SOAP Header Malformed UsernameToken Authentication Bypass
12588| [58776] Apache JSPWiki PreviewContent.jsp Edited Text XSS
12589| [58775] Apache JSPWiki preview.jsp action Parameter XSS
12590| [58774] Apache JSPWiki Edit.jsp Multiple Parameter XSS
12591| [58773] Apache JSPWiki Accept-Language Header Multiple Script language Parameter XSS
12592| [58772] Apache JSPWiki EditorManager.java editor Parameter XSS
12593| [58771] Apache JSPWiki GroupContent.jsp Multiple Parameter XSS
12594| [58770] Apache JSPWiki Group.jsp group Parameter XSS
12595| [58769] Apache JSPWiki Database Connection Termination DoS Weakness
12596| [58768] Apache JSPWiki Attachment Servlet nextpage Parameter Arbitrary Site Redirect
12597| [58766] Apache JSPWiki /admin/SecurityConfig.jsp Direct Request Information Disclosure
12598| [58765] Apache JSPWiki Spam Filter UniqueID RNG Weakness
12599| [58764] Apache JSPWiki Edit.jsp Multiple Parameter XSS
12600| [58763] Apache JSPWiki Include Tag Multiple Script XSS
12601| [58762] Apache JSPWiki Multiple .java Tags pageContext Parameter XSS
12602| [58761] Apache JSPWiki Wiki.jsp skin Parameter XSS
12603| [58760] Apache Commons VFS Exception Error Message Cleartext Credential Disclosure
12604| [58759] Apache Jackrabbit Content Repository (JCR) UUID System.currentTimeMillis() RNG Weakness
12605| [58758] Apache River GrantPermission Policy Manipulation Privilege Escalation
12606| [58757] Apache WS-Commons Java2 StaXUtils Multiple Unspecified Minor Issues
12607| [58756] Apache WSS4J WSHandler Client Certificate Signature Validation Weakness
12608| [58755] Apache Harmony DRLVM Non-public Class Member Access
12609| [58754] Apache Harmony File.createTempFile() Temporary File Creation Prediction Weakness
12610| [58751] Apache Geronimo GeronimoIdentityResolver Subject Handling Multiple Issues
12611| [58750] Apache MyFaces Trinidad Generated HTML Information Disclosure
12612| [58749] Apache MyFaces Trinidad Database Access Error Message Information Disclosure
12613| [58748] Apache MyFaces Trinidad Image Resource Loader Traversal Arbitrary Image Access
12614| [58747] Apache MyFaces Trinidad Error Message User Entered Data Disclosure Weakness
12615| [58746] Apache Axis2 JAX-WS Java2 WSDL4J Unspecified Issue
12616| [58744] Apache Wicket Crafted File Upload Disk Space Exhaustion DoS
12617| [58743] Apache Wicket wicket.util.crypt.SunJceCrypt Encryption Reversion Weakness
12618| [58742] Apache Rampart PolicyBasedValiadtor HttpsToken Endpoint Connection Weakness
12619| [58741] Apache Rampart WSSecSignature / WSSecEncryptedKey KeyIdentifierType Validation Weakness
12620| [58740] Apache Rampart TransportBinding Message Payload Cleartext Disclosure
12621| [58739] Apache Open For Business Project (OFBiz) Unsalted Password Storage Weakness
12622| [58738] Apache Open For Business Project (OFBiz) orderId Parameter Arbitrary Order Access
12623| [58737] Apache mod_python w/ mod_python.publisher index.py Underscore Prefixed Variable Disclosure
12624| [58735] Apache Open For Business Project (OFBiz) /ecommerce/control/keywordsearch SEARCH_STRING Parameter XSS
12625| [58734] Apache Torque Log File Cleartext Credential Local Disclosure
12626| [58733] Apache Axis2 doGet Implementation Authentication Bypass Service State Manipulation
12627| [58732] Apache MyFaces UIInput.validate() Null Value Validation Bypass Weakness
12628| [58731] Apache MyFaces /faces/* Prefix Mapping Authentication Bypass
12629| [58725] Apache Tapestry Basic String ACL Bypass Weakness
12630| [58724] Apache Roller Logout Functionality Failure Session Persistence
12631| [58723] Apache Roller User Profile / Admin Page Cleartext Password Disclosure
12632| [58722] Apache Derby Connection URL Encryption Method Reversion Weakness
12633| [58721] Apache Geronimo on Tomcat Security-constraint Resource ACL Bypass
12634| [58720] Apache Geronimo Explicit Servlet Mapping Access Bypass Weakness
12635| [58719] Apache Geronimo Keystore Unprivileged Service Disable DoS
12636| [58718] Apache Geronimo Deployment Plans Remote Password Disclosure
12637| [58717] Apache Jetspeed Portlet Application Edit Access Restriction Bypass
12638| [58716] Apache Jetspeed PSML Management Cached Constraint Authentication Weakness
12639| [58707] Apache WSS4J Crafted PasswordDigest Request Authentication Bypass
12640| [58706] Apache HttpClient Pre-emptive Authorization Remote Credential Disclosure
12641| [58705] Apache Directory Server (ApacheDS) User Passwords Cleartext Disclosure
12642| [58704] Apache Directory Server (ApacheDS) Non-existent User LDAP Bind Remote DoS
12643| [58703] Apache Geronimo Debug Console Unauthenticated Remote Information Disclosure
12644| [58702] Apache Directory Server (ApacheDS) Persistent LDAP Anonymous Bind Weakness
12645| [58701] Apache Jetspeed User Admin Portlet Unpassworded Account Creation Weakness
12646| [58700] Apache MyFaces /faces/* Path Handling Remote Overflow DoS
12647| [58699] Apache MyFaces Disable Property Client Side Manipulation Privilege Escalation
12648| [58698] Apache Roller Remember Me Functionality Cleartext Password Disclosure
12649| [58697] Apache XalanJ2 org.apache.xalan.xsltc.runtime.CallFunction Class Unspecified Issue
12650| [58696] Apache Tapestry Encoded Traversal Arbitrary File Access
12651| [58695] Apache Jetspeed Unauthenticated PSML Tags / Admin Folder Access
12652| [58694] Apache Geronimo Deploy Tool Process List Local Credential Disclosure
12653| [58693] Apache Derby service.properties File Encryption Key Information Disclosure
12654| [58692] Apache Geronimo Default Security Realm Login Brute Force Weakness
12655| [58689] Apache Roller Retrieve Last 5 Post Feature Unauthorized Blog Post Manipulation
12656| [58688] Apache Xalan-Java (XalanJ2) Static Variables Multiple Unspecified Issues
12657| [58687] Apache Axis Invalid wsdl Request XSS
12658| [58686] Apache Cocoon Temporary File Creation Unspecified Race Condition
12659| [58685] Apache Velocity Template Designer Privileged Code Execution
12660| [58684] Apache Jetspeed controls.Customize Action Security Check Bypass
12661| [58675] Apache Open For Business Project (OFBiz) eCommerce/ordermgr Multiple Field XSS
12662| [58674] Apache Open For Business Project (OFBiz) ecommerce/control/login Multiple Field XSS
12663| [58673] Apache Open For Business Project (OFBiz) ecommerce/control/viewprofile Multiple Field XSS
12664| [58672] Apache Open For Business Project (OFBiz) POS Input Panel Cleartext Password Disclosure
12665| [58671] Apache Axis2 JMS Signed Message Crafted WS-Security Header Security Bypass
12666| [58670] Apache Jetspeed JetspeedTool.getPortletFromRegistry Portlet Security Validation Failure
12667| [58669] Apache Jetspeed LDAP Cleartext Passwords Disclosure
12668| [58668] Apache Axis External Entity (XXE) Data Parsing Privilege Escalation
12669| [58667] Apache Roller Database Cleartext Passwords Disclosure
12670| [58666] Apache Xerces-C++ UTF-8 Transcoder Overlong Code Handling Unspecified Issue
12671| [58665] Apache Jetspeed Turbine: Cross-user Privileged Action Execution
12672| [58664] Apache Jetspeed EditAccount.vm Password Modification Weakness
12673| [58663] Apache Jetspeed Role Parameter Arbitrary Portlet Disclosure
12674| [58662] Apache Axis JWS Page Generated .class File Direct Request Information Disclosure
12675| [58661] Apache Jetspeed user-form.vm Password Reset Cleartext Disclosure
12676| [58660] Apache WSS4J checkReceiverResults Function Crafted SOAP Request Authentication Bypass
12677| [58658] Apache Rampart Crafted SOAP Request Security Verification Bypass
12678| [57882] Apache HTTP Server mod_proxy_ftp Authorization HTTP Header Arbitrary FTP Command Injection
12679| [57851] Apache HTTP Server mod_proxy_ftp EPSV Command NULL Dereference Remote DoS
12680| [56984] Apache Xerces2 Java Malformed XML Input DoS
12681| [56903] Apache ODE (Orchestration Director Engine) Process Deployment Web Service Traversal Arbitrary File Manipulation
12682| [56859] Apache Xerces-C++ Multiple Sub-project XML Nested DTD Structures Parsing Recursion Error DoS
12683| [56766] Apache Portable Runtime (APR-util) memory/unix/apr_pools.c Relocatable Memory Block Aligning Overflow
12684| [56765] Apache Portable Runtime (APR-util) misc/apr_rmm.c Multiple Function Overflows
12685| [56517] Apache HTTP Server File Descriptor Leak Arbitrary Local File Append
12686| [56443] PTK Unspecified Apache Sub-process Arbitrary Command Execution
12687| [56414] Apache Tiles Duplicate Expression Language (EL) Expression Evaluation XSS
12688| [55814] mod_NTLM for Apache HTTP Server ap_log_rerror() Function Remote Format String
12689| [55813] mod_NTLM for Apache HTTP Server log() Function Remote Overflow
12690| [55782] Apache HTTP Server mod_deflate Module Aborted Connection DoS
12691| [55553] Apache HTTP Server mod_proxy Module mod_proxy_http.c stream_reqbody_cl Function CPU Consumption DoS
12692| [55059] Apache APR-util strmatch/apr_strmatch.c apr_strmatch_precompile Function Crafted Input Remote DoS
12693| [55058] Apache APR-util apr_brigade_vprintf Function Crafted Input Off-by-one Remote DoS
12694| [55057] Apache APR-util xml/apr_xml.c apr_xml_* Interface Expat XML Parser Crafted XML Document Remote DoS
12695| [55056] Apache Tomcat Cross-application TLD File Manipulation
12696| [55055] Apache Tomcat Illegal URL Encoded Password Request Username Enumeration
12697| [55054] Apache Tomcat Java AJP Connector mod_jk Load Balancing Worker Malformed Header Remote DoS
12698| [55053] Apache Tomcat Crafted Request Security Restraint Bypass Arbitrary Content Access
12699| [54733] Apache HTTP Server AllowOverride Directive .htaccess Options Bypass
12700| [54713] razorCMS Security Manager apache User Account Unspecified File Permission Weakness Issue
12701| [54589] Apache Jserv Nonexistent JSP Request XSS
12702| [54122] Apache Struts s:a / s:url Tag href Element XSS
12703| [54093] Apache ActiveMQ Web Console JMS Message XSS
12704| [53932] Apache Geronimo Multiple Admin Function CSRF
12705| [53931] Apache Geronimo /console/portal/Server/Monitoring Multiple Parameter XSS
12706| [53930] Apache Geronimo /console/portal/ URI XSS
12707| [53929] Apache Geronimo on Windows Security/Keystores Portlet Traversal Arbitrary File Upload
12708| [53928] Apache Geronimo on Windows Embedded DB/DB Manager Portlet Traversal Arbitrary File Upload
12709| [53927] Apache Geronimo on Windows Services/Repository Portlet Traversal Arbitrary File Upload
12710| [53921] Apache HTTP Server mod_proxy_ajp Cross Thread/Session Information Disclosure
12711| [53766] Oracle BEA WebLogic Server Plug-ins for Apache Certificate Handling Remote Overflow
12712| [53574] PHP on Apache .htaccess mbstring.func_overload Setting Cross Hosted Site Behavior Modification
12713| [53381] Apache Tomcat JK Connector Content-Length Header Cross-user Information Disclosure
12714| [53380] Apache Struts Unspecified XSS
12715| [53289] Apache mod_perl Apache::Status /perl-status Unspecified XSS
12716| [53186] Apache HTTP Server htpasswd Predictable Salt Weakness
12717| [52899] Apache Tomcat Examples Web Application Calendar Application jsp/cal/cal2.jsp time Parameter XSS
12718| [52407] Apache Tomcat doRead Method POST Content Information Disclosure
12719| [51923] Apache HTTP Server mod-auth-mysql Module mod_auth_mysql.c Multibyte Character Encoding SQL Injection
12720| [51613] Apache HTTP Server Third-party Module Child Process File Descriptor Leak
12721| [51612] Apache HTTP Server Internal Redirect Handling Infinite Loop DoS
12722| [51468] Apache Jackrabbit Content Repository (JCR) swr.jsp q Parameter XSS
12723| [51467] Apache Jackrabbit Content Repository (JCR) search.jsp q Parameter XSS
12724| [51151] Apache Roller Search Function q Parameter XSS
12725| [50482] PHP with Apache php_value Order Unspecified Issue
12726| [50475] Novell NetWare ApacheAdmin Console Unauthenticated Access
12727| [49734] Apache Struts DefaultStaticContentLoader Class Traversal Arbitrary File Access
12728| [49733] Apache Struts FilterDispatcher Class Traversal Arbitrary File Access
12729| [49283] Oracle BEA WebLogic Server Plugins for Apache Remote Transfer-Encoding Overflow
12730| [49062] Apache Tomcat Cross-thread Concurrent Request Variable Overwrite Information Disclosure
12731| [48847] ModSecurity (mod_security) Transformation Caching Unspecified Apache DoS
12732| [48788] Apache Xerces-C++ XML Schema maxOccurs Value XML File Handling DoS
12733| [47474] Apache HTTP Server mod_proxy_ftp Directory Component Wildcard Character XSS
12734| [47464] Apache Tomcat allowLinking / UTF-8 Traversal Arbitrary File Access
12735| [47463] Apache Tomcat RequestDispatcher Traversal Arbitrary File Access
12736| [47462] Apache Tomcat HttpServletResponse.sendError Method Message Argument XSS
12737| [47096] Oracle Weblogic Apache Connector POST Request Overflow
12738| [46382] Frontend Filemanager (air_filemanager) Extension for TYPO3 on Apache Unspecified Arbitrary Code Execution
12739| [46285] TYPO3 on Apache Crafted Filename Upload Arbitrary Command Execution
12740| [46085] Apache HTTP Server mod_proxy ap_proxy_http_process_response() Function Interim Response Forwarding Remote DoS
12741| [45905] Apache Tomcat Host Manager host-manager/html/add name Parameter XSS
12742| [45879] Ragnarok Online Control Panel on Apache Crafted Traversal Authentication Bypass
12743| [45742] Apache HTTP Server on Novell Unspecified Request Directive Internal IP Disclosure
12744| [45740] Apache Derby DropSchemaNode Bind Phase Arbitrary Scheme Statement Dropping
12745| [45599] Apache Derby Lock Table Statement Privilege Requirement Bypass Arbitrary Table Lock
12746| [45585] Apache Derby ACCSEC Command RDBNAM Parameter Cleartext Credential Disclosure
12747| [45584] Apache Derby DatabaseMetaData.getURL Function Cleartext Credential Disclosure
12748| [45420] Apache HTTP Server 403 Error Page UTF-7 Encoded XSS
12749| [44728] PHP Toolkit on Gentoo Linux Interpretation Conflict Apache HTTP Server Local DoS
12750| [44618] Oracle JSP Apache/Jserv Path Translation Traversal Arbitrary JSP File Execution
12751| [44159] Apache HTTP Server Remote Virtual Host Name Disclosure
12752| [43997] Apache-SSL ExpandCert() Function Certificate Handling Arbitrary Environment Variables Manipulation
12753| [43994] suPHP for Apache (mod_suphp) Directory Symlink Local Privilege Escalation
12754| [43993] suPHP for Apache (mod_suphp) Owner Mode Race Condition Symlink Local Privilege Escalation
12755| [43663] Apache HTTP Server Mixed Platform AddType Directive Crafted Request PHP Source Disclosure
12756| [43658] AuthCAS Module (AuthCAS.pm) for Apache HTTP Server SESSION_COOKIE_NAME SQL Injection
12757| [43452] Apache Tomcat HTTP Request Smuggling
12758| [43309] Apache Geronimo LoginModule Login Method Bypass
12759| [43290] Apache JSPWiki Entry Page Attachment Unrestricted File Upload
12760| [43259] Apache HTTP Server on Windows mod_proxy_balancer URL Handling Remote Memory Corruption
12761| [43224] Apache Geronimo on SuSE Linux init Script Symlink Unspecified File/Directory Access
12762| [43189] Apache mod_jk2 Host Header Multiple Fields Remote Overflow
12763| [42937] Apache HTTP Server mod_proxy_balancer balancer-manager Unspecified CSRF
12764| [42341] MOD_PLSQL for Apache Unspecified URL SQL Injection
12765| [42340] MOD_PLSQL for Apache CGI Environment Handling Unspecified Overflow
12766| [42214] Apache HTTP Server mod_proxy_ftp UTF-7 Encoded XSS
12767| [42091] Apache Maven Site Plugin Installation Permission Weakness
12768| [42089] Apache Maven .m2/settings.xml Cleartext Password Disclosure
12769| [42088] Apache Maven Defined Repo Process Listing Password Disclosure
12770| [42087] Apache Maven Site Plugin SSH Deployment Permission Setting Weakness
12771| [42036] Apache HTTP Server MS-DOS Device Request Host OS Disclosure
12772| [41891] BEA WebLogic Apache Beehive NetUI Page Flow Unspecified XSS
12773| [41436] Apache Tomcat Native APR Connector Duplicate Request Issue
12774| [41435] Apache Tomcat %5C Cookie Handling Session ID Disclosure
12775| [41434] Apache Tomcat Exception Handling Subsequent Request Information Disclosure
12776| [41400] LimeSurvey save.php Apache Log File PHP Code Injection
12777| [41029] Apache Tomcat Calendar Examples Application cal2.jsp Multiple Parameter CSRF
12778| [41019] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload XSS
12779| [41018] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload CRLF
12780| [40853] Apache Tomcat SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) JSESSIONIDSSO Cookie Security Weakness
12781| [40264] Apache HTTP Server mod_proxy_balancer balancer_handler Function bb Variable Remote DoS
12782| [40263] Apache HTTP Server mod_proxy_balancer balancer-manager Multiple Parameter XSS
12783| [40262] Apache HTTP Server mod_status refresh XSS
12784| [39833] Apache Tomcat JULI Logging Component catalina.policy Security Bypass
12785| [39251] Coppermine Photo Gallery on Apache Multiple File Extension Upload Arbitrary Code Execution
12786| [39166] Apache Tomcat on Windows caseSensitive Attribute Mixed Case Request JSP Source Disclosure
12787| [39134] Apache mod_imagemap Module Imagemap Unspecified XSS
12788| [39133] Apache mod_imap Module Imagemap File Unspecified XSS
12789| [39035] Apache Tomcat examples/servlet/CookieExample Multiple Parameter XSS
12790| [39003] Apache HTTP Server HTTP Method Header Request Entity Too Large XSS
12791| [39000] Apache Tomcat SendMailServlet sendmail.jsp mailfrom Parameter XSS
12792| [38939] Apache HTTP Server Prefork MPM Module Array Modification Local DoS
12793| [38673] Apache Jakarta Slide WebDAV SYSTEM Request Traversal Arbitrary File Access
12794| [38662] Apache Geronimo SQLLoginModule Nonexistent User Authentication Bypass
12795| [38661] Apache Geronimo MEJB Unspecified Authentication Bypass
12796| [38641] Apache HTTP Server mod_mem_cache recall_headers Function Information Disclosure
12797| [38640] Apache HTTP Server suexec Document Root Unauthorized Operations
12798| [38639] Apache HTTP Server suexec Multiple Symlink Privilege Escalation
12799| [38636] Apache HTTP Server mod_autoindex.c P Variable UTF-7 Charset XSS
12800| [38513] BEA WebLogic Server Proxy Plug-in for Apache Protocol Error Handling Remote DoS
12801| [38187] Apache Geronimo / Tomcat WebDAV XML SYSTEM Tag Arbitrary File Access
12802| [37079] Apache HTTP Server mod_cache cache_util.c Malformed Cache-Control Header DoS
12803| [37071] Apache Tomcat Cookie Handling Session ID Disclosure
12804| [37070] Apache Tomcat Cookie Handling Quote Delimiter Session ID Disclosure
12805| [37052] Apache HTTP Server mod_status mod_status.c Unspecified XSS
12806| [37051] Apache HTTP Server mod_proxy modules/proxy/proxy_util.c Crafted Header Remote DoS
12807| [37050] Apache HTTP Server Prefork MPM Module Crafted Code Sequence Local DoS
12808| [36417] Apache Tomcat Host Manager Servlet html/add Action aliases Parameter XSS
12809| [36377] Apache MyFaces Tomahawk JSF Application autoscroll Multiple Script XSS
12810| [36080] Apache Tomcat JSP Examples Crafted URI XSS
12811| [36079] Apache Tomcat Manager Uploaded Filename XSS
12812| [34888] Apache Tomcat Example Calendar Application cal2.jsp time Parameter XSS
12813| [34887] Apache Tomcat implicit-objects.jsp Crafted Header XSS
12814| [34885] Apache Tomcat on IIS Servlet Engine MS-DOS Device Request DoS
12815| [34884] Apache Tomcat on Windows Nonexistent Resource Request Path Disclosure
12816| [34883] Apache Tomcat Crafted JSP File Request Path Disclosure
12817| [34882] Apache Tomcat Default SSL Ciphersuite Configuration Weakness
12818| [34881] Apache Tomcat Malformed Accept-Language Header XSS
12819| [34880] Apache Tomcat HTTP/1.1 Connector NULL Byte Request JSP Source Disclosure
12820| [34879] Apache Tomcat examples/jsp2/jspx/textRotate.jspx XSS
12821| [34878] Apache Tomcat examples/jsp2/el/implicit-objects.jsp XSS
12822| [34877] Apache Tomcat JK Web Server Connector (mod_jk) Double Encoded Traversal Arbitrary File Access
12823| [34876] Apache HTTP Server ScriptAlias CGI Source Disclosure
12824| [34875] Apache Tomcat appdev/sample/web/hello.jsp Multiple Parameter XSS
12825| [34874] Apache Tomcat AJP Connector mod_jk ajp_process_callback Remote Memory Disclosure
12826| [34873] Apache Stats Variable Extraction _REQUEST Ssuperglobal Array Overwrite
12827| [34872] Apache HTTP Server suexec User/Group Combination Weakness Local Privilege Escalation
12828| [34769] Apache Tomcat w/ Proxy Module Double Encoded Traversal Arbitrary File Access
12829| [34541] mod_perl for Apache HTTP Server RegistryCooker.pm PATH_INFO Crafted URI Remote DoS
12830| [34540] mod_perl for Apache HTTP Server PerlRun.pm PATH_INFO Crafted URI Remote DoS
12831| [34398] Apache Tomcat mod_jk Invalid Chunked Encoded Body Information Disclosure
12832| [34154] Apache Axis Nonexistent Java Web Service Path Disclosure
12833| [33855] Apache Tomcat JK Web Server Connector mod_jk.so Long URI Worker Map Remote Overflow
12834| [33816] Apache HTTP Server on Debian Linux TTY Local Privilege Escalation
12835| [33456] Apache HTTP Server Crafted TCP Connection Range Header DoS
12836| [33346] Avaya Multiple Products Apache Tomcat Port Weakness
12837| [32979] Apache Java Mail Enterprise Server (JAMES) Phoenix/MX4J Interface Arbitrary User Creation
12838| [32978] Apache Java Mail Enterprise Server (JAMES) POP3Server Log File Plaintext Password Disclosure
12839| [32724] Apache mod_python _filter_read Freed Memory Disclosure
12840| [32723] Apache Tomcat semicolon Crafted Filename Request Forced Directory Listing
12841| [32396] Apache Open For Business Project (OFBiz) Ecommerce Component Forum Implementation Message Body XSS
12842| [32395] Apache Open For Business Project (OFBiz) Ecommerce Component Form Field Manipulation Privilege Escalation
12843| [30354] Linux Subversion libapache2-svn Search Path Subversion Local Privilege Escalation
12844| [29603] PHP ini_restore() Apache httpd.conf Options Bypass
12845| [29536] Apache Tcl mod_tcl set_var Function Remote Format String
12846| [28919] Apache Roller Weblogger Blog Comment Multiple Field XSS
12847| [28130] PHP with Apache Mixed Case Method Limit Directive Bypass
12848| [27913] Apache HTTP Server on Windows mod_alias URL Validation Canonicalization CGI Source Disclosure
12849| [27588] Apache HTTP Server mod_rewrite LDAP Protocol URL Handling Overflow
12850| [27487] Apache HTTP Server Crafted Expect Header Cross Domain HTML Injection
12851| [26935] FCKeditor on Apache connector.php Crafted File Extension Arbitrary File Upload
12852| [26572] Apache Java Mail Enterprise Server (JAMES) MAIL Command Overflow DoS
12853| [25909] Drupal on Apache files Directory File Upload Arbitrary Code Execution
12854| [24825] Oracle ModPL/SQL for Apache Unspecified Remote HTTP Issue
12855| [24365] Apache Struts Multiple Function Error Message XSS
12856| [24364] Apache Struts getMultipartRequestHandler() Function Crafted Request DoS
12857| [24363] Apache Struts org.apache.struts.taglib.html.Constants.CANCEL Validation Bypass
12858| [24103] Pubcookie Apache mod_pubcookie Unspecified XSS
12859| [23906] Apache mod_python for Apache HTTP Server FileSession Privileged Local Command Execution
12860| [23905] Apache Log4net LocalSyslogAppender Format String Memory Corruption DoS
12861| [23198] Apache WSS4J Library SOAP Signature Verification Bypass
12862| [23124] Generic Apache Request Library (libapreq) apreq_parse_* Functions Remote DoS
12863| [22652] mod_php for Apache HTTP Server Crafted import_request_variables Function DoS
12864| [22475] PHP w/ Apache PDO::FETCH_CLASS __set() Function DoS
12865| [22473] PHP w/ Apache2 Crafted PDOStatement DoS
12866| [22459] Apache Geronimo Error Page XSS
12867| [22458] Apache Tomcat / Geronimo Sample Script cal2.jsp time Parameter XSS
12868| [22301] auth_ldap for Apache HTTP Server auth_ldap_log_reason() Function Remote Format String
12869| [22261] Apache HTTP Server mod_ssl ssl_hook_Access Error Handling DoS
12870| [22259] mod_auth_pgsql for Apache HTTP Server Log Function Format String
12871| [21736] Apache Java Mail Enterprise Server (JAMES) Spooler retrieve Function DoS
12872| [21705] Apache HTTP Server mod_imap Image Map Referer XSS
12873| [21021] Apache Struts Error Message XSS
12874| [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
12875| [20491] PHP mod_php apache2handler SAPI Crafted .htaccess DoS
12876| [20462] Apache HTTP Server worker.c MPM Memory Exhaustion DoS
12877| [20439] Apache Tomcat Directory Listing Saturation DoS
12878| [20373] Apache Tomcat on HP Secure OS for Linux Unspecified Servlet Access Issue
12879| [20285] Apache HTTP Server Log File Control Character Injection
12880| [20242] Apache HTTP Server mod_usertrack Predictable Session ID Generation
12881| [20209] Brainf*ck Module (mod_bf) for Apache HTTP Server Local Overflow
12882| [20033] Apache Tomcat MS-DOS Device Request Error Message Path Disclosure
12883| [19883] apachetop atop.debug Symlink Arbitrary File Overwrite
12884| [19863] mod_auth_shadow for Apache HTTP Server require group Authentication Bypass
12885| [19855] Apache HTTP Server ErrorDocument Directive .htaccess Bypass
12886| [19821] Apache Tomcat Malformed Post Request Information Disclosure
12887| [19769] Apache HTTP Server Double-reverse DNS Lookup Spoofing
12888| [19188] Apache HTTP Server mod_ssl SSLVerifyClient Per-location Context Restriction Bypass
12889| [19137] Apache HTTP Server on Red Hat Linux Double Slash GET Request Forced Directory Listing
12890| [19136] Apache on Mandrake Linux Arbitrary Directory Forced Listing
12891| [18977] Apache HTTP Server Crafted HTTP Range Header DoS
12892| [18389] Ragnarok Online Control Panel Apache Authentication Bypass
12893| [18286] Apache HTTP Server mod_ssl ssl_callback_SSLVerify_CRL( ) Function Overflow
12894| [18233] Apache HTTP Server htdigest user Variable Overfow
12895| [17738] Apache HTTP Server HTTP Request Smuggling
12896| [16586] Apache HTTP Server Win32 GET Overflow DoS
12897| [15889] Apache HTTP Server mod_cgid Threaded MPM CGI Output Misdirection
12898| [14896] mod_dav for Apache HTTP Server Remote Null Dereference Child Process Termination
12899| [14879] Apache HTTP Server ap_log_rerror Function Error Message Path Disclosure
12900| [14770] Apache Tomcat AJP12 Protocol Malformed Packet Remote DoS
12901| [14597] Apache Tomcat IntegerOverflow.jsp Test JSP Script Path Disclosure
12902| [14596] Apache Tomcat pageSession.jsp Test JSP Script Path Disclosure
12903| [14595] Apache Tomcat pageLanguage.jsp Test JSP Script Path Disclosure
12904| [14594] Apache Tomcat pageIsThreadSafe.jsp Test JSP Script Path Disclosure
12905| [14593] Apache Tomcat pageIsErrorPage.jsp Test JSP Script Path Disclosure
12906| [14592] Apache Tomcat pageInvalid.jsp Test JSP Script Path Disclosure
12907| [14591] Apache Tomcat pageExtends.jsp Test JSP Script Path Disclosure
12908| [14590] Apache Tomcat pageDouble.jsp Test JSP Script Path Disclosure
12909| [14589] Apache Tomcat pageAutoFlush.jsp Test JSP Script Path Disclosure
12910| [14588] Apache Tomcat extends2.jsp Test JSP Script Path Disclosure
12911| [14587] Apache Tomcat extends1.jsp Test JSP Script Path Disclosure
12912| [14586] Apache Tomcat comments.jsp Test JSP Script Path Disclosure
12913| [14585] Apache Tomcat buffer4.jsp Test JSP Script Path Disclosure
12914| [14584] Apache Tomcat buffer3.jsp Test JSP Script Path Disclosure
12915| [14583] Apache Tomcat buffer2.jsp Test JSP Script Path Disclosure
12916| [14582] Apache Tomcat buffer1.jsp Test JSP Script Path Disclosure
12917| [14581] Apache Tomcat pageImport2.jsp Test JSP Script Path Disclosure
12918| [14580] Apache Tomcat pageInfo.jsp Test JSP Script Path Disclosure
12919| [14410] mod_frontpage for Apache HTTP Server fpexec Remote Overflow
12920| [14044] Apache Batik Squiggle Browser with Rhino Scripting Engine Unspecified File System Access
12921| [13737] mod_access_referer for Apache HTTP Server Malformed Referer DoS
12922| [13711] Apache mod_python publisher.py Traversal Arbitrary Object Information Disclosure
12923| [13640] mod_auth_any for Apache HTTP Server on Red Hat Linux Metacharacter Command Execution
12924| [13304] Apache Tomcat realPath.jsp Path Disclosure
12925| [13303] Apache Tomcat source.jsp Arbitrary Directory Listing
12926| [13087] Apache HTTP Server mod_log_forensic check_forensic Symlink Arbitrary File Creation / Overwrite
12927| [12849] mod_auth_radius for Apache HTTP Server radcpy() Function Overflow DoS
12928| [12848] Apache HTTP Server htdigest realm Variable Overflow
12929| [12721] Apache Tomcat examples/jsp2/el/functions.jsp XSS
12930| [12720] mod_dosevasive for Apache HTTP Server Symlink Arbitrary File Create/Overwrite
12931| [12558] Apache HTTP Server IPv6 FTP Proxy Socket Failure DoS
12932| [12557] Apache HTTP Server prefork MPM accept Error DoS
12933| [12233] Apache Tomcat MS-DOS Device Name Request DoS
12934| [12232] Apache Tomcat with JDK Arbitrary Directory/Source Disclosure
12935| [12231] Apache Tomcat web.xml Arbitrary File Access
12936| [12193] Apache HTTP Server on Mac OS X File Handler Bypass
12937| [12192] Apache HTTP Server on Mac OS X Unauthorized .ht and .DS_Store File Access
12938| [12178] Apache Jakarta Lucene results.jsp XSS
12939| [12176] mod_digest_apple for Apache HTTP Server on Mac OS X Authentication Replay
12940| [11391] Apache HTTP Server Header Parsing Space Saturation DoS
12941| [11003] Apache HTTP Server mod_include get_tag() Function Local Overflow
12942| [10976] mod_mylo for Apache HTTP Server mylo_log Logging Function HTTP GET Overflow
12943| [10637] Apache HTTP Server mod_ssl SSLCipherSuite Access Restriction Bypass
12944| [10546] Macromedia JRun4 mod_jrun Apache Module Remote Overflow
12945| [10471] Apache Xerces-C++ XML Parser DoS
12946| [10218] Apache HTTP Server Satisfy Directive Access Control Bypass
12947| [10068] Apache HTTP Server htpasswd Local Overflow
12948| [10049] mod_cplusplus For Apache HTTP Server Unspecified Overflow
12949| [9994] Apache HTTP Server apr-util IPV6 Parsing DoS
12950| [9991] Apache HTTP Server ap_resolve_env Environment Variable Local Overflow
12951| [9948] mod_dav for Apache HTTP Server LOCK Request DoS
12952| [9742] Apache HTTP Server mod_ssl char_buffer_read Function Reverse Proxy DoS
12953| [9718] Apache HTTP Server Win32 Single Dot Append Arbitrary File Access
12954| [9717] Apache HTTP Server mod_cookies Cookie Overflow
12955| [9716] Apache::Gallery Gallery.pm Inline::C Predictable Filename Code Execution
12956| [9715] Apache HTTP Server rotatelogs Control Characters Over Pipe DoS
12957| [9714] Apache Authentication Module Threaded MPM DoS
12958| [9713] Apache HTTP Server on OS2 filestat.c Device Name Request DoS
12959| [9712] Apache HTTP Server Multiple Linefeed Request Memory Consumption DoS
12960| [9711] Apache HTTP Server Access Log Terminal Escape Sequence Injection
12961| [9710] Apache HTTP Server on Windows Illegal Character Default Script Mapping Bypass
12962| [9709] Apache HTTP Server on Windows MS-DOS Device Name HTTP Post Code Execution
12963| [9708] Apache HTTP Server on Windows MS-DOS Device Name DoS
12964| [9707] Apache HTTP Server Duplicate MIME Header Saturation DoS
12965| [9706] Apache Web Server Multiple MIME Header Saturation Remote DoS
12966| [9705] Apache Tomcat Invoker/Default Servlet Source Disclosure
12967| [9702] Apache HTTP Server CGI/WebDAV HTTP POST Request Source Disclosure
12968| [9701] Apache HTTP Server for Windows Multiple Slash Forced Directory Listing
12969| [9700] Apache HTTP Server mod_autoindex Multiple Slash Request Forced Directory Listing
12970| [9699] Apache HTTP Server mod_dir Multiple Slash Request Forced Directory Listing
12971| [9698] Apache HTTP Server mod_negotiation Multiple Slash Request Forced Directory Listing
12972| [9697] Apache HTTP Server htdigest Local Symlink Arbitrary File Overwrite
12973| [9696] Apache HTTP Server htpasswd Local Symlink Arbitrary File Overwrite
12974| [9695] Apache Tomcat SnoopServlet Servlet Information Disclosure
12975| [9694] PHP3 on Apache HTTP Server Encoded Traversal Arbitrary File Access
12976| [9693] mod_auth_pgsql_sys for Apache HTTP Server User Name SQL Injection
12977| [9692] Apache HTTP Server mod_vhost_alias Mass Virtual Hosting Arbitrary File Access
12978| [9691] Apache HTTP Server mod_rewrite Mass Virtual Hosting Arbitrary File Access
12979| [9690] Apache HTTP Server mod_vhost_alias CGI Program Source Disclosure
12980| [9689] Trustix httpsd for Apache-SSL Permission Weakness Privilege Escalation
12981| [9688] Apache HTTP Server mod_proxy Malformed FTP Command DoS
12982| [9687] Apache::AuthenSmb smbval SMB Authentication Library Multiple Overflows
12983| [9686] Apache::AuthenSmb smbvalid SMB Authentication Library Multiple Overflows
12984| [9523] Apache HTTP Server mod_ssl Aborted Connection DoS
12985| [9459] Oracle PL/SQL (mod_plsql) Apache Module Help Page Request Remote Overflow
12986| [9208] Apache Tomcat .jsp Encoded Newline XSS
12987| [9204] Apache Tomcat ROOT Application XSS
12988| [9203] Apache Tomcat examples Application XSS
12989| [9068] Apache HTTP Server mod_userdir User Account Information Disclosure
12990| [8773] Apache Tomcat Catalina org.apache.catalina.servlets.DefaultServlet Source Code Disclosure
12991| [8772] Apache Tomcat Catalina org.apache.catalina.connector.http DoS
12992| [7943] Apache HTTP Server mod_ssl sslkeys File Disclosure
12993| [7942] Apache HTTP Server mod_ssl Default Pass Phrase
12994| [7941] Apache HTTP Server mod_ssl Encrypted Private Key File Descriptor Leak
12995| [7935] Apache HTTP Server mod_ssl ssl_gcache Race Conditions
12996| [7934] Apache HTTP Server mod_ssl SSLSessionCache File Content Disclosure
12997| [7933] Apache HTTP Server mod_ssl SSLMutex File Content Disclosure
12998| [7932] Apache HTTP Server mod_ssl mkcert.sh File Creation Permission Weakness
12999| [7931] Apache HTTP Server mod_ssl X.509 Client Certificate Authentication Bypass
13000| [7930] Apache HTTP Server mod_ssl ssl_expr_eval_func_file() Overflow
13001| [7929] Apache HTTP Server mod_ssl ssl_engine_log.c mod_proxy Hook Function Remote Format String
13002| [7611] Apache HTTP Server mod_alias Local Overflow
13003| [7394] Apache Tomcat mod_jk Invalid Transfer-Encoding Chunked Field DoS
13004| [7203] Apache Tomcat source.jsp Traversal Arbitrary File Access
13005| [7039] Apache HTTP Server on Mac OS X HFS+ File System Access Bypass
13006| [6882] Apache mod_python Malformed Query String Variant DoS
13007| [6839] Apache HTTP Server mod_proxy Content-Length Overflow
13008| [6630] Apache Tomcat Java Server Pages (JSP) Engine WPrinterJob() DoS
13009| [6472] Apache HTTP Server mod_ssl ssl_util_uuencode_binary Remote Overflow
13010| [5821] Apache HTTP Server Multiple / GET Remote Overflow DoS
13011| [5580] Apache Tomcat Servlet Malformed URL JSP Source Disclosure
13012| [5552] Apache HTTP Server split-logfile Arbitrary .log File Overwrite
13013| [5526] Apache Tomcat Long .JSP URI Path Disclosure
13014| [5278] Apache Tomcat web.xml Restriction Bypass
13015| [5051] Apache Tomcat Null Character DoS
13016| [4973] Apache Tomcat servlet Mapping XSS
13017| [4650] mod_gzip for Apache HTTP Server Debug Mode Printf Stack Overflow
13018| [4649] mod_gzip for Apache HTTP Server Debug Mode Format String Overflow
13019| [4648] mod_gzip for Apache HTTP Server Debug Mode Race Condition
13020| [4568] mod_survey For Apache ENV Tags SQL Injection
13021| [4553] Apache HTTP Server ApacheBench Overflow DoS
13022| [4552] Apache HTTP Server Shared Memory Scoreboard DoS
13023| [4446] Apache HTTP Server mod_disk_cache Stores Credentials
13024| [4383] Apache HTTP Server Socket Race Condition DoS
13025| [4382] Apache HTTP Server Log Entry Terminal Escape Sequence Injection
13026| [4340] Apache Portable Runtime (APR) apr_psprintf DoS
13027| [4232] Apache Cocoon DatabaseAuthenticatorAction SQL Injection
13028| [4231] Apache Cocoon Error Page Server Path Disclosure
13029| [4182] Apache HTTP Server mod_ssl Plain HTTP Request DoS
13030| [4181] Apache HTTP Server mod_access IP Address Netmask Rule Bypass
13031| [4075] Apache HTTP Sever on Windows .var File Request Path Disclosure
13032| [4037] Apache HTTP Server on Cygwin Encoded GET Request Arbitrary File Access
13033| [3877] Apache-SSL SSLVerifyClient SSLFakeBasicAuth Client Certificate Forgery
13034| [3819] Apache HTTP Server mod_digest Cross Realm Credential Replay
13035| [3322] mod_php for Apache HTTP Server Process Hijack
13036| [3215] mod_php for Apache HTTP Server File Descriptor Leakage
13037| [2885] Apache mod_python Malformed Query String DoS
13038| [2749] Apache Cocoon view-source Sample File Traversal Arbitrary File Access
13039| [2733] Apache HTTP Server mod_rewrite Local Overflow
13040| [2672] Apache HTTP Server mod_ssl SSLCipherSuite Ciphersuite Downgrade Weakness
13041| [2613] Apache HTTP Server mod_cgi stderr Output Handling Local DoS
13042| [2149] Apache::Gallery Privilege Escalation
13043| [2107] Apache HTTP Server mod_ssl Host: Header XSS
13044| [1926] Apache HTTP Server mod_rewrite Crafted URI Rule Bypass
13045| [1833] Apache HTTP Server Multiple Slash GET Request DoS
13046| [1577] Apache HTTP Server mod_rewrite RewriteRule Expansion Arbitrary File Access
13047| [872] Apache Tomcat Multiple Default Accounts
13048| [862] Apache HTTP Server SSI Error Page XSS
13049| [859] Apache HTTP Server Win32 Crafted Traversal Arbitrary File Access
13050| [849] Apache Tomcat TroubleShooter Servlet Information Disclosure
13051| [845] Apache Tomcat MSDOS Device XSS
13052| [844] Apache Tomcat Java Servlet Error Page XSS
13053| [842] Apache HTTP Server mod_ssl ssl_compat_directive Function Overflow
13054| [838] Apache HTTP Server Chunked Encoding Remote Overflow
13055| [827] PHP4 for Apache on Windows php.exe Malformed Request Path Disclosure
13056| [775] Apache mod_python Module Importing Privilege Function Execution
13057| [769] Apache HTTP Server Win32 DOS Batch File Arbitrary Command Execution
13058| [756] Apache HTTP Server mod_ssl i2d_SSL_SESSION Function SSL Client Certificate Overflow
13059| [701] Apache HTTP Server Win32 ScriptAlias php.exe Arbitrary File Access
13060| [674] Apache Tomcat Nonexistent File Error Message Path Disclosure
13061| [637] Apache HTTP Server UserDir Directive Username Enumeration
13062| [623] mod_auth_pgsql for Apache HTTP Server User Name SQL Injection
13063| [582] Apache HTTP Server Multiviews Feature Arbitrary Directory Listing
13064| [562] Apache HTTP Server mod_info /server-info Information Disclosure
13065| [561] Apache Web Servers mod_status /server-status Information Disclosure
13066| [417] Apache HTTP Server on SuSE Linux /doc/packages Remote Information Disclosure
13067| [410] mod_perl for Apache HTTP Server /perl/ Directory Listing
13068| [404] Apache HTTP Server on SuSE Linux WebDAV PROPFIND Arbitrary Directory Listing
13069| [402] Apache HTTP Server on SuSE Linux cgi-bin-sdb Request Script Source Disclosure
13070| [379] Apache ASP module Apache::ASP source.asp Example File Arbitrary File Creation
13071| [377] Apache Tomcat Snoop Servlet Remote Information Disclosure
13072| [376] Apache Tomcat contextAdmin Arbitrary File Access
13073| [342] Apache HTTP Server for Windows Multiple Forward Slash Directory Listing
13074| [222] Apache HTTP Server test-cgi Arbitrary File Access
13075| [143] Apache HTTP Server printenv.pl Multiple Method CGI XSS
13076| [48] Apache HTTP Server on Debian /usr/doc Directory Information Disclosure
13077|_
13078110/tcp open pop3 Dovecot pop3d
13079| vulscan: VulDB - https://vuldb.com:
13080| [139289] cPanel up to 68.0.14 dovecot-xaps-plugin Format privilege escalation
13081| [134480] Dovecot up to 2.3.5.2 Submission-Login Crash denial of service
13082| [134479] Dovecot up to 2.3.5.2 IMAP Server Crash denial of service
13083| [134024] Dovecot up to 2.3.5.1 JSON Encoder Username Crash denial of service
13084| [132543] Dovecot up to 2.2.36.0/2.3.4.0 Certificate Impersonation weak authentication
13085| [119762] Dovecot up to 2.2.28 dict Authentication var_expand() denial of service
13086| [114012] Dovecot up to 2.2.33 TLS SNI Restart denial of service
13087| [114009] Dovecot SMTP Delivery Email Message Out-of-Bounds memory corruption
13088| [112447] Dovecot up to 2.2.33/2.3.0 SASL Auth Memory Leak denial of service
13089| [106837] Dovecot up to 2.2.16 ssl-proxy-openssl.c ssl-proxy-opensslc denial of service
13090| [97052] Dovecot up to 2.2.26 auth-policy Unset Crash denial of service
13091| [69835] Dovecot 2.2.0/2.2.1 denial of service
13092| [13348] Dovecot up to 1.2.15/2.1.15 IMAP4/POP3 SSL/TLS Handshake denial of service
13093| [65684] Dovecot up to 2.2.6 unknown vulnerability
13094| [9807] Dovecot up to 1.2.7 on Exim Input Sanitizer privilege escalation
13095| [63692] Dovecot up to 2.0.15 spoofing
13096| [7062] Dovecot 2.1.10 mail-search.c denial of service
13097| [57517] Dovecot up to 2.0.12 Login directory traversal
13098| [57516] Dovecot up to 2.0.12 Access Restriction directory traversal
13099| [57515] Dovecot up to 2.0.12 Crash denial of service
13100| [54944] Dovecot up to 1.2.14 denial of service
13101| [54943] Dovecot up to 1.2.14 Access Restriction Symlink privilege escalation
13102| [54942] Dovecot up to 2.0.4 Access Restriction denial of service
13103| [54941] Dovecot up to 2.0.4 Access Restriction unknown vulnerability
13104| [54840] Dovecot up to 1.2.12 AGate unknown vulnerability
13105| [53277] Dovecot up to 1.2.10 denial of service
13106| [50082] Dovecot up to 1.1.6 Stack-based memory corruption
13107| [45256] Dovecot up to 1.1.5 directory traversal
13108| [44846] Dovecot 1.1.4/1.1.5 IMAP Client Crash denial of service
13109| [44546] Dovecot up to 1.0.x Access Restriction unknown vulnerability
13110| [44545] Dovecot up to 1.0.x Access Restriction unknown vulnerability
13111| [41430] Dovecot 1.0.12/1.1 Locking unknown vulnerability
13112| [40356] Dovecot 1.0.9 Cache unknown vulnerability
13113| [38222] Dovecot 1.0.2 directory traversal
13114| [36376] Dovecot up to 1.0.x directory traversal
13115| [33332] Timo Sirainen Dovecot up to 1.0test53 Off-By-One memory corruption
13116|
13117| MITRE CVE - https://cve.mitre.org:
13118| [CVE-2011-4318] Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
13119| [CVE-2011-2167] script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
13120| [CVE-2011-2166] script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
13121| [CVE-2011-1929] lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
13122| [CVE-2010-4011] Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
13123| [CVE-2010-3780] Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
13124| [CVE-2010-3779] Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
13125| [CVE-2010-3707] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
13126| [CVE-2010-3706] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
13127| [CVE-2010-3304] The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
13128| [CVE-2010-0745] Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.
13129| [CVE-2010-0535] Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
13130| [CVE-2010-0433] The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
13131| [CVE-2009-3897] Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
13132| [CVE-2009-3235] Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
13133| [CVE-2009-2632] Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
13134| [CVE-2008-5301] Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
13135| [CVE-2008-4907] The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
13136| [CVE-2008-4870] dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
13137| [CVE-2008-4578] The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
13138| [CVE-2008-4577] The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
13139| [CVE-2008-1218] Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.
13140| [CVE-2008-1199] Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
13141| [CVE-2007-6598] Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
13142| [CVE-2007-5794] Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
13143| [CVE-2007-4211] The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
13144| [CVE-2007-2231] Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
13145| [CVE-2007-2173] Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
13146| [CVE-2007-0618] Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
13147| [CVE-2006-5973] Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
13148| [CVE-2006-2502] Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
13149| [CVE-2006-2414] Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
13150| [CVE-2006-0730] Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
13151| [CVE-2002-0925] Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.
13152| [CVE-2001-0143] vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.
13153| [CVE-2000-1197] POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.
13154| [CVE-1999-1445] Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.
13155|
13156| SecurityFocus - https://www.securityfocus.com/bid/:
13157| [103201] Dovecot CVE-2017-14461 Out-Of-Bounds Read Information Disclosure Vulnerability
13158| [97536] Dovecot CVE-2017-2669 Denial of Service Vulnerability
13159| [94639] Dovecot Auth Component CVE-2016-8652 Denial of Service Vulnerability
13160| [91175] Dovecot CVE-2016-4982 Local Information Disclosure Vulnerability
13161| [84736] Dovecot CVE-2008-4870 Local Security Vulnerability
13162| [74335] Dovecot 'ssl-proxy-openssl.c' Remote Denial of Service Vulnerability
13163| [67306] Dovecot Denial of Service Vulnerability
13164| [67219] akpop3d 'pszQuery' Remote Memory Corruption Vulnerability
13165| [63367] Dovecot Checkpassword Authentication Protocol Local Authentication Bypass Vulnerability
13166| [61763] RETIRED: Dovecot 'LIST' Command Denial of Service Vulnerability
13167| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
13168| [60052] Dovecot 'APPEND' Parameter Denial of Service Vulnerability
13169| [56759] RETIRED: Dovecot 'mail-search.c' Denial of Service Vulnerability
13170| [50709] Dovecot SSL Certificate 'Common Name' Field Validation Security Bypass Vulnerability
13171| [48003] Dovecot 'script-login' Multiple Security Bypass Vulnerabilities
13172| [47930] Dovecot Header Name NULL Character Denial of Service Vulnerability
13173| [44874] Apple Mac OS X Dovecot (CVE-2010-4011) Memory Corruption Vulnerability
13174| [43690] Dovecot Access Control List (ACL) Multiple Remote Vulnerabilities
13175| [41964] Dovecot Access Control List (ACL) Plugin Security Bypass Weakness
13176| [39838] tpop3d Remote Denial of Service Vulnerability
13177| [39258] Dovecot Service Control Access List Security Bypass Vulnerability
13178| [37084] Dovecot Insecure 'base_dir' Permissions Local Privilege Escalation Vulnerability
13179| [36377] Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
13180| [32582] Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
13181| [31997] Dovecot Invalid Message Address Parsing Denial of Service Vulnerability
13182| [31587] Dovecot ACL Plugin Multiple Security Bypass Vulnerabilities
13183| [28181] Dovecot 'Tab' Character Password Check Security Bypass Vulnerability
13184| [28092] Dovecot 'mail_extra_groups' Insecure Settings Local Unauthorized Access Vulnerability
13185| [27093] Dovecot Authentication Cache Security Bypass Vulnerability
13186| [25182] Dovecot ACL Plugin Security Bypass Vulnerability
13187| [23552] Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
13188| [22262] IBM AIX Pop3D/Pop3DS/IMapD/IMapDS Authentication Bypass Vulnerability
13189| [21183] Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
13190| [18056] Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
13191| [17961] Dovecot Remote Information Disclosure Vulnerability
13192| [16672] Dovecot Double Free Denial of Service Vulnerability
13193| [8495] akpop3d User Name SQL Injection Vulnerability
13194| [8473] Vpop3d Remote Denial Of Service Vulnerability
13195| [3990] ZPop3D Bad Login Logging Failure Vulnerability
13196| [2781] DynFX MailServer POP3d Denial of Service Vulnerability
13197|
13198| IBM X-Force - https://exchange.xforce.ibmcloud.com:
13199| [86382] Dovecot POP3 Service denial of service
13200| [84396] Dovecot IMAP APPEND denial of service
13201| [80453] Dovecot mail-search.c denial of service
13202| [71354] Dovecot SSL Common Name (CN) weak security
13203| [67675] Dovecot script-login security bypass
13204| [67674] Dovecot script-login directory traversal
13205| [67589] Dovecot header name denial of service
13206| [63267] Apple Mac OS X Dovecot information disclosure
13207| [62340] Dovecot mailbox security bypass
13208| [62339] Dovecot IMAP or POP3 denial of service
13209| [62256] Dovecot mailbox security bypass
13210| [62255] Dovecot ACL entry security bypass
13211| [60639] Dovecot ACL plugin weak security
13212| [57267] Apple Mac OS X Dovecot Kerberos security bypass
13213| [56763] Dovecot header denial of service
13214| [54363] Dovecot base_dir privilege escalation
13215| [53248] CMU Sieve plugin for Dovecot unspecified buffer overflow
13216| [46323] Dovecot dovecot.conf information disclosure
13217| [46227] Dovecot message parsing denial of service
13218| [45669] Dovecot ACL mailbox security bypass
13219| [45667] Dovecot ACL plugin rights security bypass
13220| [41085] Dovecot TAB characters authentication bypass
13221| [41009] Dovecot mail_extra_groups option unauthorized access
13222| [39342] Dovecot LDAP auth cache configuration security bypass
13223| [35767] Dovecot ACL plugin security bypass
13224| [34082] Dovecot mbox-storage.c directory traversal
13225| [30433] Dovecot IMAP/POP3 server dovecot.index.cache buffer overflow
13226| [26578] Cyrus IMAP pop3d buffer overflow
13227| [26536] Dovecot IMAP LIST information disclosure
13228| [24710] Dovecot dovecot-auth and imap/pop3-login denial of service
13229| [24709] Dovecot APPEND command denial of service
13230| [13018] akpop3d authentication code SQL injection
13231| [7345] Slackware Linux imapd and ipop3d core dump
13232| [6269] imap, ipop2d and ipop3d buffer overflows
13233| [5923] Linuxconf vpop3d symbolic link
13234| [4918] IPOP3D, Buffer overflow attack
13235| [1560] IPOP3D, user login successful
13236| [1559] IPOP3D user login to remote host successful
13237| [1525] IPOP3D, user logout
13238| [1524] IPOP3D, user auto-logout
13239| [1523] IPOP3D, user login failure
13240| [1522] IPOP3D, brute force attack
13241| [1521] IPOP3D, user kiss of death logout
13242| [418] pop3d mktemp creates insecure temporary files
13243|
13244| Exploit-DB - https://www.exploit-db.com:
13245| [25297] Dovecot with Exim sender_address Parameter - Remote Command Execution
13246| [23053] Vpop3d Remote Denial of Service Vulnerability
13247| [16836] Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
13248| [11893] tPop3d 1.5.3 DoS
13249| [5257] Dovecot IMAP 1.0.10 <= 1.1rc2 - Remote Email Disclosure Exploit
13250| [2185] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (3)
13251| [2053] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (2)
13252| [1813] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit
13253|
13254| OpenVAS (Nessus) - http://www.openvas.org:
13255| [901026] Dovecot Sieve Plugin Multiple Buffer Overflow Vulnerabilities
13256| [901025] Dovecot Version Detection
13257| [881402] CentOS Update for dovecot CESA-2011:1187 centos5 x86_64
13258| [881358] CentOS Update for dovecot CESA-2011:1187 centos4 x86_64
13259| [880980] CentOS Update for dovecot CESA-2011:1187 centos5 i386
13260| [880967] CentOS Update for dovecot CESA-2011:1187 centos4 i386
13261| [870607] RedHat Update for dovecot RHSA-2011:0600-01
13262| [870471] RedHat Update for dovecot RHSA-2011:1187-01
13263| [870153] RedHat Update for dovecot RHSA-2008:0297-02
13264| [863272] Fedora Update for dovecot FEDORA-2011-7612
13265| [863115] Fedora Update for dovecot FEDORA-2011-7258
13266| [861525] Fedora Update for dovecot FEDORA-2007-664
13267| [861394] Fedora Update for dovecot FEDORA-2007-493
13268| [861333] Fedora Update for dovecot FEDORA-2007-1485
13269| [860845] Fedora Update for dovecot FEDORA-2008-9202
13270| [860663] Fedora Update for dovecot FEDORA-2008-2475
13271| [860169] Fedora Update for dovecot FEDORA-2008-2464
13272| [860089] Fedora Update for dovecot FEDORA-2008-9232
13273| [840950] Ubuntu Update for dovecot USN-1295-1
13274| [840668] Ubuntu Update for dovecot USN-1143-1
13275| [840583] Ubuntu Update for dovecot vulnerabilities USN-1059-1
13276| [840335] Ubuntu Update for dovecot vulnerabilities USN-593-1
13277| [840290] Ubuntu Update for dovecot vulnerability USN-567-1
13278| [840234] Ubuntu Update for dovecot vulnerability USN-666-1
13279| [840072] Ubuntu Update for dovecot vulnerability USN-487-1
13280| [831405] Mandriva Update for dovecot MDVSA-2011:101 (dovecot)
13281| [831230] Mandriva Update for dovecot MDVSA-2010:217 (dovecot)
13282| [831197] Mandriva Update for dovecot MDVSA-2010:196 (dovecot)
13283| [831054] Mandriva Update for dovecot MDVSA-2010:104 (dovecot)
13284| [830496] Mandriva Update for dovecot MDVSA-2008:232 (dovecot)
13285| [801055] Dovecot 'base_dir' Insecure Permissions Security Bypass Vulnerability
13286| [800030] Dovecot ACL Plugin Security Bypass Vulnerabilities
13287| [70767] Gentoo Security Advisory GLSA 201110-04 (Dovecot)
13288| [70259] FreeBSD Ports: dovecot
13289| [69959] Debian Security Advisory DSA 2252-1 (dovecot)
13290| [66522] FreeBSD Ports: dovecot
13291| [65010] Ubuntu USN-838-1 (dovecot)
13292| [64978] Debian Security Advisory DSA 1892-1 (dovecot)
13293| [64953] Mandrake Security Advisory MDVSA-2009:242-1 (dovecot)
13294| [64952] Mandrake Security Advisory MDVSA-2009:242 (dovecot)
13295| [64861] Fedora Core 10 FEDORA-2009-9559 (dovecot)
13296| [62965] Gentoo Security Advisory GLSA 200812-16 (dovecot)
13297| [62854] FreeBSD Ports: dovecot-managesieve
13298| [61916] FreeBSD Ports: dovecot
13299| [60588] Gentoo Security Advisory GLSA 200803-25 (dovecot)
13300| [60568] Debian Security Advisory DSA 1516-1 (dovecot)
13301| [60528] FreeBSD Ports: dovecot
13302| [60134] Debian Security Advisory DSA 1457-1 (dovecot)
13303| [60089] FreeBSD Ports: dovecot
13304| [58578] Debian Security Advisory DSA 1359-1 (dovecot)
13305| [56834] Debian Security Advisory DSA 1080-1 (dovecot)
13306|
13307| SecurityTracker - https://www.securitytracker.com:
13308| [1028585] Dovecot APPEND Parameter Processing Flaw Lets Remote Authenticated Users Deny Service
13309| [1024740] Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User
13310| [1017288] Dovecot POP3/IMAP Cache File Buffer Overflow May Let Remote Users Execute Arbitrary Code
13311|
13312| OSVDB - http://www.osvdb.org:
13313| [96172] Dovecot POP3 Service Terminated LIST Command Remote DoS
13314| [93525] Dovecot IMAP APPEND Command Malformed Parameter Parsing Remote DoS
13315| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
13316| [88058] Dovecot lib-storage/mail-search.c Multiple Keyword Search Handling Remote DoS
13317| [77185] Dovecot SSL Certificate Common Name Field MitM Spoofing Weakness
13318| [74515] Dovecot script-login chroot Configuration Setting Traversal Arbitrary File Access
13319| [74514] Dovecot script-login User / Group Configuration Settings Remote Access Restriction Bypass
13320| [72495] Dovecot lib-mail/message-header-parser.c Mail Header Name NULL Character Handling Remote DoS
13321| [69260] Apple Mac OS X Server Dovecot Memory Aliasing Mail Delivery Issue
13322| [68516] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition User Private Namespace Mailbox Access Restriction Remote Bypass
13323| [68515] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition Specific Entry Order Mailbox Access Restriction Remote Bypass
13324| [68513] Dovecot Non-public Namespace Mailbox ACL Manipulation Access Restriction Remote Bypass
13325| [68512] Dovecot IMAP / POP3 Session Disconnect Master Process Outage Remote DoS
13326| [66625] Dovecot ACL Plugin INBOX ACL Copying Weakness Restriction Bypass
13327| [66113] Dovecot Mail Root Directory Creation Permission Weakness
13328| [66112] Dovecot Installation base_dir Parent Directory Permission Weakness
13329| [66111] Dovecot SEARCH Functionality str_find_init() Function Overflow
13330| [66110] Dovecot Multiple Unspecified Buffer Overflows
13331| [66108] Dovecot Malformed Message Body Processing Unspecified Functions Remote DoS
13332| [64783] Dovecot E-mail Message Header Unspecified DoS
13333| [63372] Apple Mac OS X Dovecot Kerberos Authentication SACL Restriction Bypass
13334| [62796] Dovecot mbox Format Email Header Handling DoS
13335| [60316] Dovecot base_dir Directory Permission Weakness Local Privilege Escalation
13336| [58103] Dovecot CMU Sieve Plugin Script Handling Multiple Overflows
13337| [50253] Dovecot dovecot.conf Permission Weakness Local ssl_key_password Parameter Disclosure
13338| [49918] Dovecot ManageSieve Script Name Handling Traversal Arbitrary File Manipulation
13339| [49429] Dovecot Message Parsing Feature Crafted Email Header Handling Remote DoS
13340| [49099] Dovecot ACL Plugin k Right Mailbox Creation Restriction Bypass
13341| [49098] Dovecot ACL Plugin Negative Access Rights Bypass
13342| [43137] Dovecot mail_extra_groups Symlink File Manipulation
13343| [42979] Dovecot passdbs Argument Injection Authentication Bypass
13344| [39876] Dovecot LDAP Auth Cache Security Bypass
13345| [39386] Dovecot ACL Plugin Insert Right APPEND / COPY Command Unauthorized Flag Manipulation
13346| [35489] Dovecot index/mbox/mbox-storage.c Traversal Arbitrary Gzip File Access
13347| [30524] Dovecot IMAP/POP3 Server dovecot.index.cache Handling Overflow
13348| [25853] Cyrus IMAPD pop3d USER Command Remote Overflow
13349| [25727] Dovecot Multiple Command Traversal Arbitrary Directory Listing
13350| [23281] Dovecot imap/pop3-login dovecot-auth DoS
13351| [23280] Dovecot Malformed APPEND Command DoS
13352| [14459] mmmail mmpop3d USER Command mmsyslog Function Format String
13353| [12033] Slackware Linux imapd/ipop3d Malformed USER/PASS Sequence DoS
13354| [5857] Linux pop3d Arbitrary Mail File Access
13355| [2471] akpop3d username SQL Injection
13356|_
13357143/tcp open imap Dovecot imapd
13358| vulscan: VulDB - https://vuldb.com:
13359| [139289] cPanel up to 68.0.14 dovecot-xaps-plugin Format privilege escalation
13360| [134480] Dovecot up to 2.3.5.2 Submission-Login Crash denial of service
13361| [134479] Dovecot up to 2.3.5.2 IMAP Server Crash denial of service
13362| [134024] Dovecot up to 2.3.5.1 JSON Encoder Username Crash denial of service
13363| [132543] Dovecot up to 2.2.36.0/2.3.4.0 Certificate Impersonation weak authentication
13364| [119762] Dovecot up to 2.2.28 dict Authentication var_expand() denial of service
13365| [114012] Dovecot up to 2.2.33 TLS SNI Restart denial of service
13366| [114009] Dovecot SMTP Delivery Email Message Out-of-Bounds memory corruption
13367| [112447] Dovecot up to 2.2.33/2.3.0 SASL Auth Memory Leak denial of service
13368| [106837] Dovecot up to 2.2.16 ssl-proxy-openssl.c ssl-proxy-opensslc denial of service
13369| [97052] Dovecot up to 2.2.26 auth-policy Unset Crash denial of service
13370| [69835] Dovecot 2.2.0/2.2.1 denial of service
13371| [13348] Dovecot up to 1.2.15/2.1.15 IMAP4/POP3 SSL/TLS Handshake denial of service
13372| [65684] Dovecot up to 2.2.6 unknown vulnerability
13373| [9807] Dovecot up to 1.2.7 on Exim Input Sanitizer privilege escalation
13374| [63692] Dovecot up to 2.0.15 spoofing
13375| [7062] Dovecot 2.1.10 mail-search.c denial of service
13376| [59792] Cyrus IMAPd 2.4.11 weak authentication
13377| [57517] Dovecot up to 2.0.12 Login directory traversal
13378| [57516] Dovecot up to 2.0.12 Access Restriction directory traversal
13379| [57515] Dovecot up to 2.0.12 Crash denial of service
13380| [54944] Dovecot up to 1.2.14 denial of service
13381| [54943] Dovecot up to 1.2.14 Access Restriction Symlink privilege escalation
13382| [54942] Dovecot up to 2.0.4 Access Restriction denial of service
13383| [54941] Dovecot up to 2.0.4 Access Restriction unknown vulnerability
13384| [54840] Dovecot up to 1.2.12 AGate unknown vulnerability
13385| [53277] Dovecot up to 1.2.10 denial of service
13386| [50082] Dovecot up to 1.1.6 Stack-based memory corruption
13387| [45256] Dovecot up to 1.1.5 directory traversal
13388| [44846] Dovecot 1.1.4/1.1.5 IMAP Client Crash denial of service
13389| [44546] Dovecot up to 1.0.x Access Restriction unknown vulnerability
13390| [44545] Dovecot up to 1.0.x Access Restriction unknown vulnerability
13391| [41430] Dovecot 1.0.12/1.1 Locking unknown vulnerability
13392| [40356] Dovecot 1.0.9 Cache unknown vulnerability
13393| [38222] Dovecot 1.0.2 directory traversal
13394| [37927] Ipswitch Ipswitch Collaboration Suite up to 2006.1 IMAP Service imapd32.exe memory corruption
13395| [36376] Dovecot up to 1.0.x directory traversal
13396| [35759] Atrium MERCUR IMAPD IMAP4 mcrimap4.exe memory corruption
13397| [33332] Timo Sirainen Dovecot up to 1.0test53 Off-By-One memory corruption
13398|
13399| MITRE CVE - https://cve.mitre.org:
13400| [CVE-2009-2632] Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
13401| [CVE-2011-4318] Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
13402| [CVE-2011-3481] The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.
13403| [CVE-2011-3372] imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
13404| [CVE-2011-2167] script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
13405| [CVE-2011-2166] script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
13406| [CVE-2011-1929] lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
13407| [CVE-2010-4011] Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
13408| [CVE-2010-3780] Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
13409| [CVE-2010-3779] Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
13410| [CVE-2010-3707] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
13411| [CVE-2010-3706] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
13412| [CVE-2010-3304] The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
13413| [CVE-2010-0745] Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.
13414| [CVE-2010-0535] Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
13415| [CVE-2010-0433] The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
13416| [CVE-2009-3897] Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
13417| [CVE-2009-3235] Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
13418| [CVE-2008-5301] Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
13419| [CVE-2008-4907] The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
13420| [CVE-2008-4870] dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
13421| [CVE-2008-4578] The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
13422| [CVE-2008-4577] The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
13423| [CVE-2008-1218] Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.
13424| [CVE-2008-1199] Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
13425| [CVE-2007-6598] Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
13426| [CVE-2007-5794] Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
13427| [CVE-2007-5740] The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.
13428| [CVE-2007-5018] Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.
13429| [CVE-2007-4211] The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
13430| [CVE-2007-3925] Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.
13431| [CVE-2007-2231] Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
13432| [CVE-2007-2173] Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
13433| [CVE-2007-1579] Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command.
13434| [CVE-2007-1578] Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.
13435| [CVE-2007-0618] Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
13436| [CVE-2006-6762] The IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to cause a denial of service via an APPEND command with a single "(" (parenthesis) in the argument.
13437| [CVE-2006-6761] Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via a long argument to the SUBSCRIBE command.
13438| [CVE-2006-6425] Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via unspecified vectors involving the APPEND command.
13439| [CVE-2006-6424] Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow
13440| [CVE-2006-5973] Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
13441| [CVE-2006-2502] Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
13442| [CVE-2006-2414] Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
13443| [CVE-2006-0730] Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
13444| [CVE-2005-2278] Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.
13445| [CVE-2005-1256] Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.
13446| [CVE-2005-1249] The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop.
13447| [CVE-2005-1015] Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
13448| [CVE-2005-0546] Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapd annotate extension, (2) an off-by-one error in "cached header handling," (3) a stack-based buffer overflow in fetchnews, or (4) a stack-based buffer overflow in imapd.
13449| [CVE-2003-1322] Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10) CREATE, or (11) SELECT command.
13450| [CVE-2002-1782] The default configuration of University of Washington IMAP daemon (wu-imapd), when running on a system that does not allow shell access, allows a local user with a valid IMAP account to read arbitrary files as that user.
13451| [CVE-2002-1604] Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver.
13452| [CVE-2002-0997] Buffer overflows in IMAP Agent (imapd) for Novell NetMail (NIMS) 3.0.3 before 3.0.3A allows remote attackers to cause a denial of service.
13453| [CVE-2002-0379] Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and earlier, allows remote authenticated users to execute arbitrary code via a long BODY request.
13454| [CVE-2001-0691] Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.
13455| [CVE-2000-0284] Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.
13456| [CVE-1999-1557] Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.
13457| [CVE-1999-1445] Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.
13458| [CVE-1999-1224] IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information.
13459|
13460| SecurityFocus - https://www.securityfocus.com/bid/:
13461| [103201] Dovecot CVE-2017-14461 Out-Of-Bounds Read Information Disclosure Vulnerability
13462| [97536] Dovecot CVE-2017-2669 Denial of Service Vulnerability
13463| [94639] Dovecot Auth Component CVE-2016-8652 Denial of Service Vulnerability
13464| [91175] Dovecot CVE-2016-4982 Local Information Disclosure Vulnerability
13465| [84736] Dovecot CVE-2008-4870 Local Security Vulnerability
13466| [84478] imapd CVE-1999-1224 Denial-Of-Service Vulnerability
13467| [74335] Dovecot 'ssl-proxy-openssl.c' Remote Denial of Service Vulnerability
13468| [67306] Dovecot Denial of Service Vulnerability
13469| [65650] Eudora WorldMail imapd 'UID' Command Buffer Overflow Vulnerability
13470| [63367] Dovecot Checkpassword Authentication Protocol Local Authentication Bypass Vulnerability
13471| [61763] RETIRED: Dovecot 'LIST' Command Denial of Service Vulnerability
13472| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
13473| [60052] Dovecot 'APPEND' Parameter Denial of Service Vulnerability
13474| [56759] RETIRED: Dovecot 'mail-search.c' Denial of Service Vulnerability
13475| [51403] Eudora WorldMail imapd 'LIST' Command Buffer Overflow Vulnerability
13476| [50709] Dovecot SSL Certificate 'Common Name' Field Validation Security Bypass Vulnerability
13477| [49949] Cyrus IMAPd NTTP Logic Error Authentication Bypass Vulnerability
13478| [48003] Dovecot 'script-login' Multiple Security Bypass Vulnerabilities
13479| [47930] Dovecot Header Name NULL Character Denial of Service Vulnerability
13480| [44874] Apple Mac OS X Dovecot (CVE-2010-4011) Memory Corruption Vulnerability
13481| [43690] Dovecot Access Control List (ACL) Multiple Remote Vulnerabilities
13482| [41964] Dovecot Access Control List (ACL) Plugin Security Bypass Weakness
13483| [39258] Dovecot Service Control Access List Security Bypass Vulnerability
13484| [37084] Dovecot Insecure 'base_dir' Permissions Local Privilege Escalation Vulnerability
13485| [36377] Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
13486| [32582] Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
13487| [31997] Dovecot Invalid Message Address Parsing Denial of Service Vulnerability
13488| [31587] Dovecot ACL Plugin Multiple Security Bypass Vulnerabilities
13489| [28181] Dovecot 'Tab' Character Password Check Security Bypass Vulnerability
13490| [28092] Dovecot 'mail_extra_groups' Insecure Settings Local Unauthorized Access Vulnerability
13491| [27093] Dovecot Authentication Cache Security Bypass Vulnerability
13492| [26270] Perdition IMAPD __STR_VWRITE Remote Format String Vulnerability
13493| [25733] Mercury/32 IMAPD SEARCH Command Remote Stack Buffer Overflow Vulnerability
13494| [25182] Dovecot ACL Plugin Security Bypass Vulnerability
13495| [23552] Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
13496| [23058] Atrium Mercur IMapD NTLM Buffer Overflow Vulnerability
13497| [22262] IBM AIX Pop3D/Pop3DS/IMapD/IMapDS Authentication Bypass Vulnerability
13498| [21183] Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
13499| [18056] Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
13500| [17961] Dovecot Remote Information Disclosure Vulnerability
13501| [16672] Dovecot Double Free Denial of Service Vulnerability
13502| [15980] Qualcomm WorldMail IMAPD Buffer Overflow Vulnerability
13503| [15753] Ipswitch Collaboration Suite and IMail Server IMAPD LIST Command Denial Of Service Vulnerability
13504| [12636] Cyrus IMAPD Multiple Remote Buffer Overflow Vulnerabilities
13505| [11738] Cyrus IMAPD Multiple Remote Unspecified Vulnerabilities
13506| [11729] Cyrus IMAPD Multiple Remote Vulnerabilities
13507| [6298] Cyrus IMAPD Pre-Login Heap Corruption Vulnerability
13508| [4713] Wu-imapd Partial Mailbox Attribute Remote Buffer Overflow Vulnerability
13509| [2856] Imapd 'Local' Buffer Overflow Vulnerabilities
13510| [1110] Univ. Of Washington imapd Buffer Overflow Vulnerabilities
13511| [502] NT IMail Imapd Buffer Overflow DoS Vulnerability
13512| [130] imapd Buffer Overflow Vulnerability
13513|
13514| IBM X-Force - https://exchange.xforce.ibmcloud.com:
13515| [86382] Dovecot POP3 Service denial of service
13516| [84396] Dovecot IMAP APPEND denial of service
13517| [80453] Dovecot mail-search.c denial of service
13518| [71354] Dovecot SSL Common Name (CN) weak security
13519| [70325] Cyrus IMAPd NNTP security bypass
13520| [67675] Dovecot script-login security bypass
13521| [67674] Dovecot script-login directory traversal
13522| [67589] Dovecot header name denial of service
13523| [63267] Apple Mac OS X Dovecot information disclosure
13524| [62340] Dovecot mailbox security bypass
13525| [62339] Dovecot IMAP or POP3 denial of service
13526| [62256] Dovecot mailbox security bypass
13527| [62255] Dovecot ACL entry security bypass
13528| [60639] Dovecot ACL plugin weak security
13529| [57267] Apple Mac OS X Dovecot Kerberos security bypass
13530| [56763] Dovecot header denial of service
13531| [54363] Dovecot base_dir privilege escalation
13532| [53248] CMU Sieve plugin for Dovecot unspecified buffer overflow
13533| [47526] UW-imapd rfc822_output_char() denial of service
13534| [46323] Dovecot dovecot.conf information disclosure
13535| [46227] Dovecot message parsing denial of service
13536| [45669] Dovecot ACL mailbox security bypass
13537| [45667] Dovecot ACL plugin rights security bypass
13538| [41085] Dovecot TAB characters authentication bypass
13539| [41009] Dovecot mail_extra_groups option unauthorized access
13540| [39342] Dovecot LDAP auth cache configuration security bypass
13541| [35767] Dovecot ACL plugin security bypass
13542| [34082] Dovecot mbox-storage.c directory traversal
13543| [30433] Dovecot IMAP/POP3 server dovecot.index.cache buffer overflow
13544| [26536] Dovecot IMAP LIST information disclosure
13545| [24710] Dovecot dovecot-auth and imap/pop3-login denial of service
13546| [24709] Dovecot APPEND command denial of service
13547| [22629] RHSA-2005:408 updates for cyrus-imapd not installed
13548| [19460] Cyrus IMAP imapd buffer overflow
13549| [19455] Cyrus IMAP imapd extension off-by-one buffer overflow
13550| [18492] Novell NetMail IMAPD 101_mEna buffer overflow
13551| [10803] UW IMAP (wu-imapd) authenticated user buffer overflow
13552| [9238] UW IMAP (wu-imapd) could allow a remote attacker to access arbitrary files
13553| [9055] UW IMAP (wu-imapd) partial mailbox attributes to request buffer overflow
13554| [7345] Slackware Linux imapd and ipop3d core dump
13555| [573] Imapd denial of service
13556|
13557| Exploit-DB - https://www.exploit-db.com:
13558| [30724] Perdition 1.17 IMAPD __STR_VWRITE Remote Format String Vulnerability
13559| [25297] Dovecot with Exim sender_address Parameter - Remote Command Execution
13560| [22061] Cyrus IMAPD 1.4/1.5.19/2.0.12/2.0.16/2.1.9/2.1.10 Pre-Login Heap Corruption Vulnerability
13561| [21443] Wu-imapd 2000/2001 Partial Mailbox Attribute Remote Buffer Overflow Vulnerability (2)
13562| [21442] Wu-imapd 2000/2001 Partial Mailbox Attribute Remote Buffer Overflow Vulnerability (1)
13563| [19849] UoW imapd 10.234/12.264 COPY Buffer Overflow (meta)
13564| [19848] UoW imapd 10.234/12.264 LSUB Buffer Overflow (meta)
13565| [19847] UoW imapd 10.234/12.264 Buffer Overflow Vulnerabilities
13566| [19377] Ipswitch IMail 5.0 Imapd Buffer Overflow DoS Vulnerability
13567| [19107] Netscape Messaging Server 3.55,University of Washington imapd 10.234 Buffer Overflow Vulnerability
13568| [18354] WorldMail imapd 3.0 SEH overflow (egg hunter)
13569| [16836] Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
13570| [16485] MailEnable IMAPD 1.54 - STATUS Request Buffer Overflow
13571| [16482] MDaemon 9.6.4 IMAPD FETCH Buffer Overflow
13572| [16480] MailEnable IMAPD W3C Logging Buffer Overflow
13573| [16477] Mdaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow
13574| [16475] MailEnable IMAPD (2.35) Login Request Buffer Overflow
13575| [16474] Qualcomm WorldMail 3.0 IMAPD LIST Buffer Overflow
13576| [5257] Dovecot IMAP 1.0.10 <= 1.1rc2 - Remote Email Disclosure Exploit
13577| [4429] Mercury/32 4.52 IMAPD SEARCH command Post-Auth Overflow Exploit
13578| [3627] IPSwitch IMail Server <= 8.20 IMAPD Remote Buffer Overflow Exploit
13579| [3527] Mercur IMAPD 5.00.14 Remote Denial of Service Exploit (win32)
13580| [2185] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (3)
13581| [2053] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (2)
13582| [1813] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit
13583| [1380] Eudora Qualcomm WorldMail 3.0 (IMAPd) Remote Overflow Exploit
13584| [1332] MailEnable 1.54 Pro Universal IMAPD W3C Logging BoF Exploit
13585| [1327] FTGate4 Groupware Mail Server 4.1 (imapd) Remote Buffer Overflow PoC
13586| [1151] MDaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow Exploit
13587| [1124] IPSwitch IMail Server <= 8.15 IMAPD Remote Root Exploit
13588| [915] MailEnable Enterprise 1.x Imapd Remote Exploit
13589| [903] Cyrus imapd 2.2.4 - 2.2.8 (imapmagicplus) Remote Exploit
13590| [340] Linux imapd Remote Overflow File Retrieve Exploit
13591|
13592| OpenVAS (Nessus) - http://www.openvas.org:
13593| [901026] Dovecot Sieve Plugin Multiple Buffer Overflow Vulnerabilities
13594| [901025] Dovecot Version Detection
13595| [881425] CentOS Update for cyrus-imapd CESA-2011:1508 centos5 x86_64
13596| [881403] CentOS Update for cyrus-imapd CESA-2011:0859 centos5 x86_64
13597| [881402] CentOS Update for dovecot CESA-2011:1187 centos5 x86_64
13598| [881397] CentOS Update for cyrus-imapd CESA-2011:1317 centos4 x86_64
13599| [881370] CentOS Update for cyrus-imapd CESA-2011:1508 centos4 x86_64
13600| [881358] CentOS Update for dovecot CESA-2011:1187 centos4 x86_64
13601| [881318] CentOS Update for cyrus-imapd CESA-2011:0859 centos4 x86_64
13602| [881255] CentOS Update for cyrus-imapd CESA-2011:1317 centos5 x86_64
13603| [881050] CentOS Update for cyrus-imapd CESA-2011:1508 centos5 i386
13604| [881049] CentOS Update for cyrus-imapd CESA-2011:1508 centos4 i386
13605| [881007] CentOS Update for cyrus-imapd CESA-2011:1317 centos5 i386
13606| [880980] CentOS Update for dovecot CESA-2011:1187 centos5 i386
13607| [880978] CentOS Update for cyrus-imapd CESA-2011:1317 centos4 i386
13608| [880967] CentOS Update for dovecot CESA-2011:1187 centos4 i386
13609| [880958] CentOS Update for cyrus-imapd CESA-2011:0859 centos4 i386
13610| [880905] CentOS Update for cyrus-imapd CESA-2009:1459 centos4 i386
13611| [880864] CentOS Update for cyrus-imapd CESA-2009:1459 centos5 i386
13612| [880826] CentOS Update for cyrus-imapd CESA-2009:1116 centos5 i386
13613| [880536] CentOS Update for cyrus-imapd CESA-2011:0859 centos5 i386
13614| [870607] RedHat Update for dovecot RHSA-2011:0600-01
13615| [870520] RedHat Update for cyrus-imapd RHSA-2011:1508-01
13616| [870489] RedHat Update for cyrus-imapd RHSA-2011:1317-01
13617| [870471] RedHat Update for dovecot RHSA-2011:1187-01
13618| [870443] RedHat Update for cyrus-imapd RHSA-2011:0859-01
13619| [870153] RedHat Update for dovecot RHSA-2008:0297-02
13620| [864075] Fedora Update for cyrus-imapd FEDORA-2011-13832
13621| [863585] Fedora Update for cyrus-imapd FEDORA-2011-13869
13622| [863579] Fedora Update for cyrus-imapd FEDORA-2011-13860
13623| [863281] Fedora Update for cyrus-imapd FEDORA-2011-7193
13624| [863273] Fedora Update for cyrus-imapd FEDORA-2011-7217
13625| [863272] Fedora Update for dovecot FEDORA-2011-7612
13626| [863115] Fedora Update for dovecot FEDORA-2011-7258
13627| [861525] Fedora Update for dovecot FEDORA-2007-664
13628| [861394] Fedora Update for dovecot FEDORA-2007-493
13629| [861333] Fedora Update for dovecot FEDORA-2007-1485
13630| [860845] Fedora Update for dovecot FEDORA-2008-9202
13631| [860663] Fedora Update for dovecot FEDORA-2008-2475
13632| [860169] Fedora Update for dovecot FEDORA-2008-2464
13633| [860089] Fedora Update for dovecot FEDORA-2008-9232
13634| [840950] Ubuntu Update for dovecot USN-1295-1
13635| [840668] Ubuntu Update for dovecot USN-1143-1
13636| [840583] Ubuntu Update for dovecot vulnerabilities USN-1059-1
13637| [840335] Ubuntu Update for dovecot vulnerabilities USN-593-1
13638| [840290] Ubuntu Update for dovecot vulnerability USN-567-1
13639| [840234] Ubuntu Update for dovecot vulnerability USN-666-1
13640| [840072] Ubuntu Update for dovecot vulnerability USN-487-1
13641| [831590] Mandriva Update for cyrus-imapd MDVSA-2012:037 (cyrus-imapd)
13642| [831468] Mandriva Update for cyrus-imapd MDVSA-2011:149 (cyrus-imapd)
13643| [831410] Mandriva Update for cyrus-imapd MDVSA-2011:100 (cyrus-imapd)
13644| [831405] Mandriva Update for dovecot MDVSA-2011:101 (dovecot)
13645| [831230] Mandriva Update for dovecot MDVSA-2010:217 (dovecot)
13646| [831207] Mandriva Update for cyrus-imapd MDVA-2010:208 (cyrus-imapd)
13647| [831197] Mandriva Update for dovecot MDVSA-2010:196 (dovecot)
13648| [831054] Mandriva Update for dovecot MDVSA-2010:104 (dovecot)
13649| [830496] Mandriva Update for dovecot MDVSA-2008:232 (dovecot)
13650| [801055] Dovecot 'base_dir' Insecure Permissions Security Bypass Vulnerability
13651| [800149] UW-imapd tmail and dmail BOF Vulnerabilities (Linux)
13652| [800030] Dovecot ACL Plugin Security Bypass Vulnerabilities
13653| [70767] Gentoo Security Advisory GLSA 201110-04 (Dovecot)
13654| [70696] Debian Security Advisory DSA 2377-1 (cyrus-imapd-2.2)
13655| [70407] Debian Security Advisory DSA 2318-1 (cyrus-imapd-2.2)
13656| [70259] FreeBSD Ports: dovecot
13657| [69965] Debian Security Advisory DSA 2258-1 (kolab-cyrus-imapd)
13658| [69959] Debian Security Advisory DSA 2252-1 (dovecot)
13659| [69740] Debian Security Advisory DSA 2242-1 (cyrus-imapd-2.2)
13660| [66522] FreeBSD Ports: dovecot
13661| [66416] Mandriva Security Advisory MDVSA-2009:229-1 (cyrus-imapd)
13662| [66233] SLES10: Security update for Cyrus IMAPD
13663| [66226] SLES11: Security update for Cyrus IMAPD
13664| [66222] SLES9: Security update for Cyrus IMAPD
13665| [65938] SLES10: Security update for Cyrus IMAPD
13666| [65723] SLES11: Security update for Cyrus IMAPD
13667| [65523] SLES9: Security update for Cyrus IMAPD
13668| [65479] SLES9: Security update for cyrus-imapd
13669| [65094] SLES9: Security update for cyrus-imapd
13670| [65010] Ubuntu USN-838-1 (dovecot)
13671| [64989] CentOS Security Advisory CESA-2009:1459 (cyrus-imapd)
13672| [64978] Debian Security Advisory DSA 1892-1 (dovecot)
13673| [64977] Debian Security Advisory DSA 1893-1 (cyrus-imapd-2.2 kolab-cyrus-imapd)
13674| [64965] Fedora Core 11 FEDORA-2009-9901 (cyrus-imapd)
13675| [64963] Fedora Core 10 FEDORA-2009-9869 (cyrus-imapd)
13676| [64953] Mandrake Security Advisory MDVSA-2009:242-1 (dovecot)
13677| [64952] Mandrake Security Advisory MDVSA-2009:242 (dovecot)
13678| [64898] FreeBSD Ports: cyrus-imapd
13679| [64864] Debian Security Advisory DSA 1881-1 (cyrus-imapd-2.2)
13680| [64861] Fedora Core 10 FEDORA-2009-9559 (dovecot)
13681| [64847] Fedora Core 10 FEDORA-2009-9428 (cyrus-imapd)
13682| [64846] Fedora Core 11 FEDORA-2009-9417 (cyrus-imapd)
13683| [64838] Mandrake Security Advisory MDVSA-2009:229 (cyrus-imapd)
13684| [64271] CentOS Security Advisory CESA-2009:1116 (cyrus-imapd)
13685| [62965] Gentoo Security Advisory GLSA 200812-16 (dovecot)
13686| [62854] FreeBSD Ports: dovecot-managesieve
13687| [61916] FreeBSD Ports: dovecot
13688| [60588] Gentoo Security Advisory GLSA 200803-25 (dovecot)
13689| [60568] Debian Security Advisory DSA 1516-1 (dovecot)
13690| [60528] FreeBSD Ports: dovecot
13691| [60134] Debian Security Advisory DSA 1457-1 (dovecot)
13692| [60089] FreeBSD Ports: dovecot
13693| [58578] Debian Security Advisory DSA 1359-1 (dovecot)
13694| [56834] Debian Security Advisory DSA 1080-1 (dovecot)
13695| [55807] Slackware Advisory SSA:2005-310-06 imapd
13696| [54861] Gentoo Security Advisory GLSA 200502-29 (cyrus-imapd)
13697| [54755] Gentoo Security Advisory GLSA 200411-34 (cyrus-imapd)
13698| [53739] Debian Security Advisory DSA 215-1 (cyrus-imapd)
13699| [53288] Debian Security Advisory DSA 597-1 (cyrus-imapd)
13700| [52297] FreeBSD Ports: cyrus-imapd
13701| [52296] FreeBSD Ports: cyrus-imapd
13702| [52295] FreeBSD Ports: cyrus-imapd
13703| [52294] FreeBSD Ports: cyrus-imapd
13704| [52172] FreeBSD Ports: cyrus-imapd
13705|
13706| SecurityTracker - https://www.securitytracker.com:
13707| [1028585] Dovecot APPEND Parameter Processing Flaw Lets Remote Authenticated Users Deny Service
13708| [1024740] Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User
13709| [1017288] Dovecot POP3/IMAP Cache File Buffer Overflow May Let Remote Users Execute Arbitrary Code
13710| [1013278] Cyrus IMAPd Buffer Overflows in Annotate Extension, Cached Header, and Fetchnews May Let Remote Users Execute Arbitrary Code
13711|
13712| OSVDB - http://www.osvdb.org:
13713| [96172] Dovecot POP3 Service Terminated LIST Command Remote DoS
13714| [93525] Dovecot IMAP APPEND Command Malformed Parameter Parsing Remote DoS
13715| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
13716| [88058] Dovecot lib-storage/mail-search.c Multiple Keyword Search Handling Remote DoS
13717| [78304] Eudora WorldMail imapd SEH LIST Command Parsing Remote Overflow
13718| [77185] Dovecot SSL Certificate Common Name Field MitM Spoofing Weakness
13719| [75445] Cyrus IMAP Server imapd index.c index_get_ids Function References Header NULL Dereference Remote DoS
13720| [74515] Dovecot script-login chroot Configuration Setting Traversal Arbitrary File Access
13721| [74514] Dovecot script-login User / Group Configuration Settings Remote Access Restriction Bypass
13722| [72495] Dovecot lib-mail/message-header-parser.c Mail Header Name NULL Character Handling Remote DoS
13723| [69260] Apple Mac OS X Server Dovecot Memory Aliasing Mail Delivery Issue
13724| [68516] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition User Private Namespace Mailbox Access Restriction Remote Bypass
13725| [68515] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition Specific Entry Order Mailbox Access Restriction Remote Bypass
13726| [68513] Dovecot Non-public Namespace Mailbox ACL Manipulation Access Restriction Remote Bypass
13727| [68512] Dovecot IMAP / POP3 Session Disconnect Master Process Outage Remote DoS
13728| [66625] Dovecot ACL Plugin INBOX ACL Copying Weakness Restriction Bypass
13729| [66113] Dovecot Mail Root Directory Creation Permission Weakness
13730| [66112] Dovecot Installation base_dir Parent Directory Permission Weakness
13731| [66111] Dovecot SEARCH Functionality str_find_init() Function Overflow
13732| [66110] Dovecot Multiple Unspecified Buffer Overflows
13733| [66108] Dovecot Malformed Message Body Processing Unspecified Functions Remote DoS
13734| [64783] Dovecot E-mail Message Header Unspecified DoS
13735| [63372] Apple Mac OS X Dovecot Kerberos Authentication SACL Restriction Bypass
13736| [62796] Dovecot mbox Format Email Header Handling DoS
13737| [60316] Dovecot base_dir Directory Permission Weakness Local Privilege Escalation
13738| [58103] Dovecot CMU Sieve Plugin Script Handling Multiple Overflows
13739| [57843] Cyrus IMAP Server (cyrus-imapd) SIEVE Script Component (sieve/script.c) Crafted Script Handling Overflow
13740| [57681] UoW imap Server (uw-imapd) Arbitrary Remote File Access
13741| [52906] UW-imapd c-client Initial Request Remote Format String
13742| [52905] UW-imapd c-client Library RFC822BUFFER Routines rfc822_output_char Function Off-by-one
13743| [52456] UW-imapd on Debian Linux LOGIN Command Remote DoS
13744| [50253] Dovecot dovecot.conf Permission Weakness Local ssl_key_password Parameter Disclosure
13745| [49918] Dovecot ManageSieve Script Name Handling Traversal Arbitrary File Manipulation
13746| [49485] UW-imapd dmail Utility Mailbox Name Handling Overflow
13747| [49484] UW-imapd tmail Utility Mailbox Name Handling Overflow
13748| [49429] Dovecot Message Parsing Feature Crafted Email Header Handling Remote DoS
13749| [49099] Dovecot ACL Plugin k Right Mailbox Creation Restriction Bypass
13750| [49098] Dovecot ACL Plugin Negative Access Rights Bypass
13751| [43137] Dovecot mail_extra_groups Symlink File Manipulation
13752| [42979] Dovecot passdbs Argument Injection Authentication Bypass
13753| [42004] Perdition Mail Retrieval Proxy IMAPD IMAP Tag Remote Format String Arbitrary Code Execution
13754| [39876] Dovecot LDAP Auth Cache Security Bypass
13755| [39670] Mercury Mail Transport System IMAPD SEARCH Command Remote Overflow
13756| [39386] Dovecot ACL Plugin Insert Right APPEND / COPY Command Unauthorized Flag Manipulation
13757| [35489] Dovecot index/mbox/mbox-storage.c Traversal Arbitrary Gzip File Access
13758| [31362] Novell NetMail IMAP Daemon (IMAPD) APPEND Command Remote Overflow
13759| [31361] Novell NetMail IMAP Daemon (IMAPD) APPEND Command DoS
13760| [31360] Novell NetMail IMAP Daemon (IMAPD) SUBSCRIBE Command Remote Overflow
13761| [30524] Dovecot IMAP/POP3 Server dovecot.index.cache Handling Overflow
13762| [25853] Cyrus IMAPD pop3d USER Command Remote Overflow
13763| [25727] Dovecot Multiple Command Traversal Arbitrary Directory Listing
13764| [23281] Dovecot imap/pop3-login dovecot-auth DoS
13765| [23280] Dovecot Malformed APPEND Command DoS
13766| [18179] HP Tru64 UNIX imapd NLSPATH Environment Variable Local Overflow
13767| [13242] UW-imapd CRAM-MD5 Authentication Bypass
13768| [12385] Novell NetMail IMAPD 101_mEna Script Remote Overflow
13769| [12042] UoW imapd Multiple Unspecified Overflows
13770| [12037] UoW imapd (UW-IMAP) Multiple Command Remote Overflows
13771| [12033] Slackware Linux imapd/ipop3d Malformed USER/PASS Sequence DoS
13772| [911] UoW imapd AUTHENTICATE Command Remote Overflow
13773| [790] UoW imap Server (uw-imapd) BODY Request Remote Overflow
13774| [519] UoW imapd SIGABRT Signal Forced Crash Information Disclosure
13775|_
13776443/tcp open ssl/http Apache httpd
13777|_http-server-header: Apache
13778|_http-trane-info: Problem with XML parsing of /evox/about
13779| vulscan: VulDB - https://vuldb.com:
13780| [141649] Apache OFBiz up to 16.11.05 Form Widget Freemarker Markup Code Execution
13781| [141648] Apache OFBiz up to 16.11.05 Application Stored cross site scripting
13782| [140386] Apache Commons Beanutils 1.9.2 BeanIntrospector unknown vulnerability
13783| [139708] Apache Ranger up to 1.2.0 Policy Import cross site scripting
13784| [139540] cPanel up to 60.0.24 Apache HTTP Server Key information disclosure
13785| [139386] Apache Tike up to 1.21 RecursiveParserWrapper Stack-based memory corruption
13786| [139385] Apache Tika 1.19/1.20/1.21 SAXParsers Hang denial of service
13787| [139384] Apache Tika up to 1.21 RecursiveParserWrapper ZIP File denial of service
13788| [139261] Apache Solr 8.2.0 DataImportHandler Parameter unknown vulnerability
13789| [139259] cPanel up to 68.0.26 WHM Apache Includes Editor information disclosure
13790| [139256] cPanel up to 68.0.26 WHM Apache Configuration Include Editor cross site scripting
13791| [139239] cPanel up to 70.0.22 Apache HTTP Server Log information disclosure
13792| [139141] Apache ActiveMQ Client up to 5.15.4 ActiveMQConnection.java ActiveMQConnection denial of service
13793| [139130] cPanel up to 73.x Apache HTTP Server Injection privilege escalation
13794| [138914] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 VM sql injection
13795| [138913] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Block Argument privilege escalation
13796| [138912] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Cookie sql injection
13797| [138816] Apache Storm up to 1.2.2 Logviewer Daemon Log information disclosure
13798| [138815] Apache Storm up to 1.2.2 UI Daemon Deserialization privilege escalation
13799| [138164] Oracle 2.7.0.1 Apache Log4j unknown vulnerability
13800| [138155] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Tomcat unknown vulnerability
13801| [138151] Oracle Transportation Management 6.3.7 Apache Tomcat unknown vulnerability
13802| [138149] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Commons FileUpload unknown vulnerability
13803| [138131] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Tomcat unknown vulnerability
13804| [138129] Oracle Retail Xstore Point of Service 7.0/7.1 Apache HTTP Server denial of service
13805| [138123] Oracle Retail Order Management System 5.0 Apache Struts 1 unknown vulnerability
13806| [138122] Oracle Retail Order Broker 5.2/15.0 Apache Tomcat unknown vulnerability
13807| [138121] Oracle Retail Order Broker 5.2/15.0 Apache CXF unknown vulnerability
13808| [138112] Oracle Retail Integration Bus 15.0/16.0 Apache Commons FileUpload unknown vulnerability
13809| [138111] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Commons FileUpload unknown vulnerability
13810| [138103] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56/8.57 Apache WSS4J information disclosure
13811| [138053] Oracle JD Edwards EnterpriseOne Tools 9.2 Apache Log4j unknown vulnerability
13812| [138036] Oracle Insurance Rules Palette 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
13813| [138035] Oracle Insurance Policy Administration J2EE 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
13814| [138034] Oracle Insurance Calculation Engine 9.7/10.0/10.1/10.2 Apache Commons FileUpload unknown vulnerability
13815| [138028] Oracle Identity Manager 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
13816| [138020] Oracle BI Publisher 11.1.1.9.0 Apache Tomcat unknown vulnerability
13817| [138019] Oracle BI Publisher (formerly XML Publisher) 11.1.1.9.0 Apache Tomcat unknown vulnerability
13818| [138017] Oracle Outside In Technology 8.5.4 Apache Commons FileUpload unknown vulnerability
13819| [138013] Oracle Outside In Technology 8.5.4 Apache Tomcat unknown vulnerability
13820| [138012] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
13821| [138009] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
13822| [138008] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Struts 1 denial of service
13823| [138007] Oracle WebCenter Sites 12.2.1.3.0 Apache Tomcat denial of service
13824| [138006] Oracle Enterprise Repository 12.1.3.0.0 Apache CXF denial of service
13825| [138000] Oracle WebCenter Sites 12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
13826| [137999] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
13827| [137995] Oracle Hospitality Simphony 18.2.1 Apache WSS4J information disclosure
13828| [137987] Oracle FLEXCUBE Universal Banking up to 12.0.3/12.4.0/14.2.0 Apache Log4j unknown vulnerability
13829| [137981] Oracle Insurance IFRS 17 Analyzer 8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
13830| [137980] Oracle Insurance Data Foundation 8.0.4/8.0.5/8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
13831| [137979] Oracle 8.0.8 Apache Commons FileUpload unknown vulnerability
13832| [137973] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Batik unknown vulnerability
13833| [137970] Oracle Financial Services Profitability Management 8.0.4/8.0.5/8.0.6/8.0.7 Apache ActiveMQ unknown vulnerability
13834| [137967] Oracle up to 8.0.7 Apache httpd unknown vulnerability
13835| [137966] Oracle 8.0.7/8.0.8 Apache Groovy unknown vulnerability
13836| [137965] Oracle Financial Services Liquidity Risk Management 8.0.1/8.0.2/8.0.4/8.0.5/8.0.6 Apache Commons FileUpload unknown vulnerability
13837| [137964] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Log4j unknown vulnerability
13838| [137933] Oracle Banking Platform up to 2.7.1 Apache Tika unknown vulnerability
13839| [137926] Oracle Enterprise Manager for Fusion Middleware 13.2/13.3 Apache Commons FileUpload information disclosure
13840| [137924] Oracle Enterprise Manager Base Platform 12.1.0.5.0/13.2.0.0.0/13.3.0.0.0 Apache Commons FileUpload unknown vulnerability
13841| [137914] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
13842| [137913] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
13843| [137911] Oracle E-Business Suite up to 12.2.8 Apache HTTP Server unknown vulnerability
13844| [137910] Oracle E-Business Suite up to 12.2.8 Apache CXF information disclosure
13845| [137909] Oracle E-Business Suite up to 12.2.8 Apache Commons FileUpload unknown vulnerability
13846| [137905] Oracle Primavera Gateway 15.2/16.2/17.12/18.8 Apache Tika denial of service
13847| [137901] Oracle Primavera Unifier up to 18.8 Apache HTTP Server unknown vulnerability
13848| [137895] Oracle Instant Messaging Server 10.0.1.2.0 Apache Tika information disclosure
13849| [137894] Oracle EAGLE (Software) 46.5/46.6/46.7 Apache Tomcat information disclosure
13850| [137892] Oracle Online Mediation Controller 6.1 Apache Batik denial of service
13851| [137891] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Tomcat unknown vulnerability
13852| [137885] Oracle Diameter Signaling Router (DSR) 8.0/8.1/8.2 Apache cxf unknown vulnerability
13853| [137882] Oracle Unified 8.0.0.2.0 Apache Commons FileUpload unknown vulnerability
13854| [137881] Oracle Online Mediation Controller 6.1 Apache Commons FileUpload unknown vulnerability
13855| [137880] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Log4j unknown vulnerability
13856| [137879] Oracle Convergence 3.0.2 Apache Commons FileUpload unknown vulnerability
13857| [137876] Oracle Application Session Controller 3.7.1/3.8.0 Apache Commons FileUpload unknown vulnerability
13858| [137829] Apache Roller 5.2.3 Math Comment Authenticator Reflected cross site scripting
13859| [137736] Apache Kafka 0.11.0.0/2.1.0 ACL Validation Request privilege escalation
13860| [136858] MakerBot Replicator 5G Printer Apache HTTP Server information disclosure
13861| [136849] Analogic Poste.io 2.1.6 on Apache RoundCube logs/ information disclosure
13862| [136822] Apache Tomcat up to 8.5.40/9.0.19 Incomplete Fix CVE-2019-0199 Resource Exhaustion denial of service
13863| [136808] Apache Geode up to 1.8.0 Secure Mode privilege escalation
13864| [136646] Apache Allura up to 1.10.x Dropdown Selector Stored cross site scripting
13865| [136374] Apache HTTP Server up to 2.4.38 Slash Regular Expression unknown vulnerability
13866| [136373] Apache HTTP Server 2.4.34/2.4.35/2.4.36/2.4.37/2.4.38 HTTP2 Request Crash denial of service
13867| [136372] Apache HTTP Server up to 2.4.38 HTTP2 Request unknown vulnerability
13868| [136370] Apache Fineract up to 1.2.x sql injection
13869| [136369] Apache Fineract up to 1.2.x sql injection
13870| [135731] Apache Hadoop up to 2.8.4/2.9.1/3.1.0 yarn privilege escalation
13871| [135664] Apache Tomcat up to 7.0.93/8.5.39/9.0.0.17 SSI printenv Command cross site scripting
13872| [135663] Apache Camel up to 2.23.x JSON-lib Library XML Data XML External Entity
13873| [135661] Apache Roller up to 5.2.1/5.2.0 XML-RPC Interface XML File Server-Side Request Forgery
13874| [135402] Apache Zookeeper up to 3.4.13/3.5.0-alpha to 3.5.4-beta getACL() information disclosure
13875| [135270] Apache JSPWiki up to 2.11.0.M3 Plugin Link cross site scripting
13876| [135269] Apache JSPWiki up to 2.11.0.M3 InterWiki Link cross site scripting
13877| [135268] Apache JSPWiki up to 2.11.0.M3 Attachment cross site scripting
13878| [134527] Apache Karaf up to 4.2.4 Config Service directory traversal
13879| [134416] Apache Sanselan 0.97-incubator Loop denial of service
13880| [134415] Apache Sanselan 0.97-incubator Hang denial of service
13881| [134291] Apache Axis up to 1.7.8 Server-Side Request Forgery
13882| [134290] Apache UIMA DUCC up to 2.2.2 cross site scripting
13883| [134248] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
13884| [134247] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
13885| [134246] Apache Camel up to 2.19/2.21.3/2.22.2/2.23.0 directory traversal
13886| [134138] Apache Pluto 3.0.0/3.0.1 Chat Room Demo Portlet cross site scripting
13887| [133992] Apache Qpid Proton up to 0.27.0 Certificate Validation Man-in-the-Middle weak authentication
13888| [133977] Apache Zeppelin up to 0.7.x Stored cross site scripting
13889| [133976] Apache Zeppelin up to 0.7.x Cron Scheduler privilege escalation
13890| [133975] Apache Zeppelin up to 0.7.2 Session Fixation weak authentication
13891| [133444] Apache PDFbox 2.0.14 XML Parser XML External Entity
13892| [133573] Oracle FLEXCUBE Private Banking 2.0.0.0/2.2.0.1/12.0.1.0/12.0.3.0/12.1.0.0 Apache ActiveMQ unknown vulnerability
13893| [133407] Apache Tomcat up to 7.0.93/8.5.39/9.0.17 on Windows JRE Command Line Argument Code Execution
13894| [133315] Apache Airflow up to 1.10.2 HTTP Endpoint cross site request forgery
13895| [133314] Apache Airflow up to 1.10.2 Metadata Database cross site scripting
13896| [133290] Apache Tomcat up to 8.5.37/9.0.14 HTTP2 Stream Execution denial of service
13897| [133112] Apache HTTP Server up to 2.4.38 mod_auth_digest race condition privilege escalation
13898| [133111] Apache HTTP Server 2.4.37/2.4.38 mod_ssl Bypass privilege escalation
13899| [133092] Airsonic 10.2.1 org.apache.commons.lang.RandomStringUtils RecoverController.java java.util.Random weak authentication
13900| [132568] Apache JSPWiki up to 2.11.0.M2 URL User information disclosure
13901| [132567] Apache JSPWiki up to 2.11.0.M2 URL cross site scripting
13902| [132566] Apache ActiveMQ up to 5.15.8 MQTT Frame Memory denial of service
13903| [132565] Apache HBase up to 2.1.3 REST Server Request privilege escalation
13904| [132183] Apache Mesos up to pre-1.4.x Docker Image Code Execution
13905| [131988] Apache Karaf up to 4.2.2 kar Deployer directory traversal
13906| [131859] Apache Hadoop up to 2.9.1 privilege escalation
13907| [131479] Apache Solr up to 7.6 HTTP GET Request Server-Side Request Forgery
13908| [131446] Apache Solr up to 5.0.5/6.6.5 Config API HTTP POST Request Code Execution
13909| [131385] Apache Qpid Broker-J up to 6.x/7.0.6/7.1.0 AMQP Command Crash denial of service
13910| [131315] Apache Mesos up to pre-1.4.x Mesos Masters Rendering JSON Payload Recursion denial of service
13911| [131236] Apache Airflow up to 1.10.1 Metadata Database cross site scripting
13912| [130755] Apache JSPWiki up to 2.10.5 URL cross site scripting
13913| [130629] Apache Guacamole Cookie Flag weak encryption
13914| [130628] Apache Hadoop up to 3.0.0 HDFS information disclosure
13915| [130529] Apache Subversion 1.10.0/1.10.1/1.10.2/1.10.3/1.11.0 mod_dav_svn Directory Crash denial of service
13916| [130353] Apache Open Office up to 4.1.5 Document Loader String memory corruption
13917| [130341] Apache HTTP Server 2.4.37 mod_ssl Loop denial of service
13918| [130330] Apache HTTP Server up to 2.4.37 mod_session Expired privilege escalation
13919| [130329] Apache HTTP Server 2.4.37 mod_http2 Slowloris denial of service
13920| [130212] Apache Airflow up to 1.10.0 LDAP Auth Backend Certificate weak authentication
13921| [130123] Apache Airflow up to 1.8.2 information disclosure
13922| [130122] Apache Airflow up to 1.8.2 command injection cross site request forgery
13923| [130121] Apache Airflow up to 1.8.2 Webserver Object Code Execution
13924| [129717] Oracle Secure Global Desktop 5.4 Apache HTTP Server denial of service
13925| [129688] Oracle Tape Library ACSLS 8.4 Apache Log4j unknown vulnerability
13926| [129673] Oracle Retail Returns Management 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
13927| [129672] Oracle Retail Central Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
13928| [129671] Oracle Retail Back Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
13929| [129574] Oracle Outside In Technology 8.5.3/8.5.4 Apache Tomcat denial of service
13930| [129573] Oracle WebLogic Server 10.3.6.0 Apache HTTP Server denial of service
13931| [129563] Oracle Enterprise Repository 12.1.3.0.0 Apache Log4j unknown vulnerability
13932| [129555] Oracle Outside In Technology 8.5.3 Apache Batik denial of service
13933| [129551] Oracle Outside In Technology 8.5.3/8.5.4 Apache Commons FileUpload denial of service
13934| [129542] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
13935| [129538] Oracle SOA Suite 12.1.3.0.0/12.2.1.3.0 Apache Batik unknown vulnerability
13936| [129519] Oracle Enterprise Manager Ops Center 12.2.2/12.3.3 Apache ActiveMQ unknown vulnerability
13937| [129508] Oracle Applications Manager up to 12.2.8 Apache Derby unknown vulnerability
13938| [129507] Oracle Mobile Field Service up to 12.2.8 Apache Log4j unknown vulnerability
13939| [129505] Oracle Email Center up to 12.2.8 Apache Log4j unknown vulnerability
13940| [129504] Oracle CRM Technical Foundation up to 12.2.8 Apache Commons FileUpload unknown vulnerability
13941| [129499] Oracle Partner Management up to 12.2.8 Apache Log4j unknown vulnerability
13942| [129498] Oracle Marketing up to 12.2.8 Apache Commons FileUpload unknown vulnerability
13943| [129480] Oracle Communications WebRTC Session Controller up to 7.1 Apache Batik unknown vulnerability
13944| [129479] Oracle Communications Diameter Signaling Router up to 8.2 Apache Batik unknown vulnerability
13945| [129474] Oracle Communications Diameter Signaling Router up to 8.2 Apache HTTP Server information disclosure
13946| [129472] Oracle Communications WebRTC Session Controller up to 7.1 Apache Struts 1 unknown vulnerability
13947| [129470] Oracle Communications Converged Application Server up to 7.0.0.0 Apache Struts 1 unknown vulnerability
13948| [129463] Oracle Communications WebRTC Session Controller up to 7.1 Apache Log4j unknown vulnerability
13949| [129461] Oracle Communications Services Gatekeeper up to 6.1.0.3.x Apache Commons Collections Fileupload unknown vulnerability
13950| [129460] Oracle Communications Service Broker 6.0 Apache Log4j unknown vulnerability
13951| [129459] Oracle Communications Policy Management up to 12.4 Apache Struts 2 unknown vulnerability
13952| [129458] Oracle Communications Online Mediation Controller 6.1 Apache Log4j unknown vulnerability
13953| [129457] Oracle Communications Diameter Signaling Router up to 8.2 Apache Commons Fileupload unknown vulnerability
13954| [129456] Oracle Communications Converged Application Server 6.1 Apache Log4j unknown vulnerability
13955| [128714] Apache Thrift Java Client Library up to 0.11.0 SASL Negotiation org.apache.thrift.transport.TSaslTransport unknown vulnerability
13956| [128713] Apache Thrift Node.js Static Web Server up to 0.11.0 directory traversal
13957| [128709] Apache Karaf up to 4.1.6/4.2.1 Features Deployer XMLInputFactory XML External Entity
13958| [128575] Apache NetBeans 9.0 Proxy Auto-Config Code Execution
13959| [128369] Apache Tika 1.8-1.19.1 SQLite3Parser Loop sql injection
13960| [128111] Apache NiFi 1.8.0 Template Upload Man-in-the-Middle cross site request forgery
13961| [128110] Apache NiFi 1.8.0 Cluster Request privilege escalation
13962| [128109] Apache NiFi 1.8.0 Error Page message-page.jsp Request Header cross site scripting
13963| [128108] Apache NiFi up to 1.7.x X-Frame-Options Header privilege escalation
13964| [128102] Apache Oozie up to 5.0.0 Workflow XML Impersonation spoofing
13965| [127994] WordPress up to 5.0.0 on Apache httpd MIME Restriction cross site scripting
13966| [127981] Apache OFBiz 16.11.01/16.11.02/16.11.03/16.11.04 HTTP Engine httpService GET Request privilege escalation
13967| [127161] Apache Hadoop 2.7.4/2.7.5/2.7.6 Incomplete Fix CVE-2016-6811 privilege escalation
13968| [127040] Loadbalancer.org Enterprise VA MAX up to 8.3.2 Apache HTTP Server Log cross site scripting
13969| [127007] Apache Spark Request Code Execution
13970| [126791] Apache Hadoop up to 0.23.11/2.7.6/2.8.4/2.9.1/3.0.2 ZIP File unknown vulnerability
13971| [126767] Apache Qpid Proton-J Transport 0.3 Certificate Verification Man-in-the-Middle weak authentication
13972| [126896] Apache Commons FileUpload 1.3.3 on LDAP Manager DiskFileItem File privilege escalation
13973| [126574] Apache Hive up to 2.3.3/3.1.0 Query privilege escalation
13974| [126573] Apache Hive up to 2.3.3/3.1.0 HiveServer2 privilege escalation
13975| [126564] Apache Superset up to 0.22 Pickle Library load Code Execution
13976| [126488] Apache Syncope up to 2.0.10/2.1.1 BPMN Definition xxe privilege escalation
13977| [126487] Apache Syncope up to 2.0.10/2.1.1 cross site scripting
13978| [126346] Apache Tomcat Path privilege escalation
13979| [125922] Apache Impala up to 3.0.0 ALTER privilege escalation
13980| [125921] Apache Impala up to 3.0.0 Queue Injection privilege escalation
13981| [125647] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Install (Apache Tomcat) information disclosure
13982| [125617] Oracle Retail Returns Management 14.1 Apache Batik unknown vulnerability
13983| [125616] Oracle Retail Point-of-Service 13.4/14.0/14.1 Apache Batik unknown vulnerability
13984| [125614] Oracle Retail Central Office 14.1 Apache Batik unknown vulnerability
13985| [125613] Oracle Retail Back Office 13.3/13.4/14/14.1 Apache Batik unknown vulnerability
13986| [125599] Oracle Retail Open Commerce Platform 5.3.0/6.0.0/6.0.1 Apache Log4j unknown vulnerability
13987| [125569] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56 Apache HTTP Server information disclosure
13988| [125494] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat information disclosure
13989| [125447] Oracle Business Intelligence Enterprise Edition 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Batik unknown vulnerability
13990| [125428] Oracle Identity Management Suite 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
13991| [125427] Oracle Identity Analytics 11.1.1.5.8 Apache Log4j unknown vulnerability
13992| [125424] Oracle API Gateway 11.1.2.4.0 Apache Log4j unknown vulnerability
13993| [125423] Oracle BI Publisher 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Log4j unknown vulnerability
13994| [125383] Oracle up to 10.2.0 Apache Trinidad unknown vulnerability
13995| [125379] Oracle up to 10.1.x Apache Struts 1 cross site scripting
13996| [125377] Oracle up to 10.2.0 Apache Commons Collections unknown vulnerability
13997| [125376] Oracle Communications Application Session Controller up to 3.7.0 Apache Commons Collections unknown vulnerability
13998| [125375] Oracle Communications User Data Repository up to 12.1.x Apache Xerces memory corruption
13999| [125248] Apache ActiveMQ up to 5.15.5 Web-based Administration Console queue.jsp Parameter cross site scripting
14000| [125133] Apache Tika up to 1.19 XML Parser reset() denial of service
14001| [124877] Apache PDFbox up to 2.0.11 PDF File denial of service
14002| [124876] Apache Ranger up to 1.1.x UnixAuthenticationService Stack-based memory corruption
14003| [124791] Apache Tomcat up to 7.0.90/8.5.33/9.0.11 URL Open Redirect
14004| [124787] Apache Pony Mail 0.7/0.8/0.9 Statistics Generator Timestamp Data information disclosure
14005| [124447] Apache HTTP Server up to 2.4.34 SETTINGS Frame denial of service
14006| [124346] Apache Mesos pre-1.4.2/1.5.0/1.5.1/1.6.0 on Executor HTTP API String Comparison validation JSON Web Token information disclosure
14007| [124286] Apache Tika up to 1.18 IptcAnpaParser Loop denial of service
14008| [124242] Apache Tika up to 0.18 C:/evil.bat" Directory unknown vulnerability
14009| [124241] Apache Tika up to 0.18 XML Parser Entity Expansion denial of service
14010| [124191] Apache Karaf up to 3.0.8/4.0.8/4.1.0 WebConsole .../gogo/ weak authentication
14011| [124190] Apache Karaf up to 4.1.x sshd privilege escalation
14012| [124152] Apache Camel Mail up to 2.22.0 Path directory traversal
14013| [124143] Apache SpamAssassin up to 3.4.1 PDFInfo Plugin Code Execution
14014| [124134] Apache SpamAssassin up to 3.4.1 Scan Engine HTML::Parser Email denial of service
14015| [124095] PHP up to 5.6.37/7.0.31/7.1.21/7.2.9 Apache2 sapi_apache2.c php_handler cross site scripting
14016| [124024] Apache Mesos 1.4.x/1.5.0 libprocess JSON Payload denial of service
14017| [123814] Apache ActiveMQ Client up to 5.15.5 TLS Hostname Verification Man-in-the-Middle weak authentication
14018| [123393] Apache Traffic Server up to 6.2.2/7.1.3 ESI Plugin Config privilege escalation
14019| [123392] Apache Traffic Server 6.2.2 TLS Handshake Segmentation Fault denial of service
14020| [123391] Apache Traffic Server up to 6.2.2/7.1.3 Range Request Performance denial of service
14021| [123390] Apache Traffic Server up to 6.2.2/7.1.3 Request HTTP Smuggling privilege escalation
14022| [123369] Apache Traffic Server up to 6.2.2/7.1.3 ACL remap.config Request denial of service
14023| [123197] Apache Sentry up to 2.0.0 privilege escalation
14024| [123145] Apache Struts up to 2.3.34/2.5.16 Namespace Code Execution
14025| [123144] Apache Cayenne up to 4.1.M1 CayenneModeler XML File File Transfer privilege escalation
14026| [122981] Apache Commons Compress 1.7 ZipArchiveInputStream ZIP Archive denial of service
14027| [122889] Apache HTTP Server up to 2.2.31/2.4.23 mod_userdir HTTP Response Splitting privilege escalation
14028| [122800] Apache Spark 1.3.0 REST API weak authentication
14029| [122642] Apache Airflow up to 1.8.x 404 Page Reflected cross site scripting
14030| [122568] Apache Tomcat up to 8.5.31/9.0.9 Connection Reuse weak authentication
14031| [122567] Apache Axis 1.0./1.1/1.2/1.3/1.4 cross site scripting
14032| [122556] Apache Tomcat up to 7.0.86/8.0.51/8.5.30/9.0.7 UTF-8 Decoder Loop denial of service
14033| [122531] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.9 WebSocket Client unknown vulnerability
14034| [122456] Apache Camel up to 2.20.3/2.21.0 XSD Validator XML External Entity
14035| [122455] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Revoked Certificate weak authentication
14036| [122454] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Responder Revoked Certificate weak authentication
14037| [122214] Apache Kafka up to 0.9.0.1/0.10.2.1/0.11.0.2/1.0.0 Broker Request Data Loss denial of service
14038| [122202] Apache Kafka up to 0.10.2.1/0.11.0.1 SASL Impersonation spoofing
14039| [122101] Docker Skeleton Runtime for Apache OpenWhisk Docker Action dockerskeleton:1.3.0 privilege escalation
14040| [122100] PHP Runtime for Apache OpenWhisk Docker Action action-php-v7.2:1.0.0 privilege escalation
14041| [122012] Apache Ignite up to 2.5 Serialization privilege escalation
14042| [121911] Apache Ambari up to 2.5.x/2.6.2 Log Message Credentials information disclosure
14043| [121910] Apache HTTP Server 2.4.33 mod_md HTTP Requests denial of service
14044| [121854] Oracle Tape Library ACSLS up to ACSLS 8.4.0-2 Apache Commons Collections unknown vulnerability
14045| [121752] Oracle Insurance Policy Administration 10.0/10.1/10.2/11.0 Apache Log4j unknown vulnerability
14046| [121370] Apache Spark up to 2.1.2/2.2.1/2.3.0 URL cross site scripting
14047| [121354] Apache CouchDB HTTP API Code Execution
14048| [121144] Apache LDAP API up to 1.0.1 SSL Filter information disclosure
14049| [121143] Apache Storm up to 0.10.2/1.0.6/1.1.2/1.2.1 Cluster privilege escalation
14050| [120436] Apache CXF Fediz up to 1.4.3 Application Plugin unknown vulnerability
14051| [120310] Apache PDFbox up to 1.8.14/2.0.10 AFMParser Loop denial of service
14052| [120168] Apache CXF weak authentication
14053| [120080] Apache Cassandra up to 3.11.1 JMX/RMI Interface RMI Request privilege escalation
14054| [120043] Apache HBase up to 1.2.6.0/1.3.2.0/1.4.4/2.0.0 Thrift 1 API Server weak authentication
14055| [119723] Apache Qpid Broker-J 7.0.0/7.0.1/7.0.2/7.0.3/7.0.4 AMQP Messages Crash denial of service
14056| [122569] Apache HTTP Server up to 2.4.33 HTTP2 Request denial of service
14057| [119486] Apache Geode up to 1.4.0 Security Manager Code Execution
14058| [119306] Apache MXNet Network Interface privilege escalation
14059| [118999] Apache Storm up to 1.0.6/1.1.2/1.2.1 Archive directory traversal
14060| [118996] Apache Storm up to 1.0.6/1.1.2/1.2.1 Daemon spoofing
14061| [118644] Apple macOS up to 10.13.5 apache_mod_php unknown vulnerability
14062| [118200] Apache Batik up to 1.9 Deserialization unknown vulnerability
14063| [118143] Apache NiFi activemq-client Library Deserialization denial of service
14064| [118142] Apache NiFi 1.6.0 SplitXML xxe privilege escalation
14065| [118051] Apache Zookeeper up to 3.4.9/3.5.3-beta weak authentication
14066| [117997] Apache ORC up to 1.4.3 ORC File Recursion denial of service
14067| [117825] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.8 CORS Filter privilege escalation
14068| [117405] Apache Derby up to 10.14.1.0 Network Server Network Packet privilege escalation
14069| [117347] Apache Ambari up to 2.6.1 HTTP Request directory traversal
14070| [117265] LibreOffice/Apache Office Writer SMB Connection XML Document information disclosure
14071| [117143] Apache uimaj/uima-as/uimaFIT/uimaDUCC XML XXE information disclosure
14072| [117117] Apache Tika up to 1.17 ChmParser Loop denial of service
14073| [117116] Apache Tika up to 1.17 BPGParser Loop denial of service
14074| [117115] Apache Tika up to 1.17 tika-server command injection
14075| [116929] Apache Fineract getReportType Parameter privilege escalation
14076| [116928] Apache Fineract REST Endpoint Parameter privilege escalation
14077| [116927] Apache Fineract MakercheckersApiResource Parameter sql injection
14078| [116926] Apache Fineract REST Parameter privilege escalation
14079| [116574] Apache wicket-jquery-ui up to 6.29.0/7.10.1/8.0.0-M9.1 WYSIWYG Editor privilege escalation
14080| [116622] Oracle Enterprise Manager for MySQL Database 12.1.0.4 EM Plugin: General (Apache Tomcat) unknown vulnerability
14081| [115931] Apache Solr up to 6.6.2/7.2.1 XML Data Parameter XML External Entity
14082| [115883] Apache Hive up to 2.3.2 privilege escalation
14083| [115882] Apache Hive up to 2.3.2 xpath_short information disclosure
14084| [115881] Apache DriverHive JDBC Driver up to 2.3.2 Escape Argument Bypass privilege escalation
14085| [115518] Apache Ignite 2.3 Deserialization privilege escalation
14086| [115260] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache cross site scripting
14087| [115259] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache Cookie Stack-based memory corruption
14088| [115500] CA Workload Control Center up to r11.4 SP5 Apache MyFaces Component Code Execution
14089| [115121] Apache Struts REST Plugin up to 2.5.15 Xstream XML Data denial of service
14090| [115061] Apache HTTP Server up to 2.4.29 HTTP Digest Authentication Challenge HTTP Requests Replay privilege escalation
14091| [115060] Apache HTTP Server up to 2.4.29 mod_cache_socache Request Header Crash denial of service
14092| [115059] Apache HTTP Server up to 2.4.29 HTTP2 NULL Pointer Dereference denial of service
14093| [115058] Apache HTTP Server up to 2.4.29 HTTP Header Crash denial of service
14094| [115057] Apache HTTP Server up to 2.4.29 mod_session Variable Name Cache privilege escalation
14095| [115039] Apache HTTP Server up to 2.4.29 FilesMatch File Upload privilege escalation
14096| [115038] Apache HTTP Server up to 2.0.65/2.2.34/2.4.29 mod_authnz_ldap Crash denial of service
14097| [114817] Apache Syncope up to 1.2.10/2.0.7 Search Parameter information disclosure
14098| [114816] Apache Syncope up to 1.2.10/2.0.7 XSLT Code Execution
14099| [114717] Apache Commons 1.11/1.12/1.13/1.14/1.15 ZIP Archive ZipFile/ZipArchiveInputStream denial of service
14100| [114661] Apache Allura up to 1.8.0 HTTP Response Splitting privilege escalation
14101| [114400] Apache Tomcat JK ISAPI Connector up to 1.2.42 IIS/ISAPI privilege escalation
14102| [114258] Apache HTTP Server up to 2.4.22 mod_cluster Segmentation Fault denial of service
14103| [114086] Apache ODE 1.3.3 ODE Process Deployment Web Service directory traversal
14104| [113955] Apache Xerces-C up to 3.2.0 XML Parser NULL Pointer Dereference denial of service
14105| [113945] Apache Tomcat up to 7.0.84/8.0.49/8.5.27/9.0.4 URL Pattern Empty String privilege escalation
14106| [113944] Apache OpenMeetings up to 3.x/4.0.1 CRUD Operation denial of service
14107| [113905] Apache Traffic Server up to 5.2.x/5.3.2/6.2.0/7.0.0 TLS Handshake Core Dump denial of service
14108| [113904] Apache Traffic Server up to 6.2.0 Host Header privilege escalation
14109| [113895] Apache Geode up to 1.3.x Code Execution
14110| [113894] Apache Geode up to 1.3.x TcpServer Code Execution
14111| [113888] Apache James Hupa WebMail 0.0.2 cross site scripting
14112| [113813] Apache Geode Cluster up to 1.3.x Secure Mode privilege escalation
14113| [113747] Apache Tomcat Servlets privilege escalation
14114| [113647] Apache Qpid up to 0.30 qpidd Broker AMQP Message Crash denial of service
14115| [113645] Apache VCL up to 2.1/2.2.1/2.3.1 Web GUI/XMLRPC API privilege escalation
14116| [113560] Apache jUDDI Console 3.0.0 Log Entries spoofing
14117| [113571] Apache Oozie up to 4.3.0/5.0.0-beta1 XML Data XML File privilege escalation
14118| [113569] Apache Karaf up to 4.0.7 LDAPLoginModule LDAP injection denial of service
14119| [113273] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
14120| [113198] Apache Qpid Dispatch Router 0.7.0/0.8.0 AMQP denial of service
14121| [113186] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
14122| [113145] Apache Thrift up to 0.9.3 Go Client Library privilege escalation
14123| [113106] Apache jUDDI up to 3.3.3 XML Data WADL2Java/WSDL2Java XML Document privilege escalation
14124| [113105] Apache Qpid Broker-J 7.0.0 AMQP Crash denial of service
14125| [112885] Apache Allura up to 1.8.0 File information disclosure
14126| [112856] Apache CloudStack up to 4.8.1.0/4.9.0.0 API weak authentication
14127| [112855] Apache CloudStack 4.1.0/4.1.1 API information disclosure
14128| [112678] Apache Tomcat up to 7.0.82/8.0.47/8.5.23/9.0.1 Bug Fix 61201 privilege escalation
14129| [112677] Apache Tomcat Native Connector up to 1.1.34/1.2.14 OCSP Checker Client weak authentication
14130| [112625] Apache POI up to 3.16 Loop denial of service
14131| [112448] Apache NiFi up to 1.3.x Deserialization privilege escalation
14132| [112396] Apache Hadoop 2.7.3/2.7.4 YARN NodeManager Credentials information disclosure
14133| [112339] Apache NiFi 1.5.0 Header privilege escalation
14134| [112330] Apache NiFi 1.5.0 Header HTTP Request privilege escalation
14135| [112314] NetGain Enterprise Manager 7.2.730 Build 1034 org.apache.jsp.u.jsp.tools.exec_jsp Servlet Parameter privilege escalation
14136| [112253] Apache Hadoop up to 0.23.x/2.7.4/2.8.2 MapReduce Job History Server Configuration File privilege escalation
14137| [112171] Oracle Secure Global Desktop 5.3 Apache Log4j privilege escalation
14138| [112164] Oracle Agile PLM 9.3.5/9.3.6 Apache Tomcat unknown vulnerability
14139| [112161] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Tomcat privilege escalation
14140| [112158] Oracle Autovue for Agile Product Lifecycle Management 21.0.0/21.0.1 Apache Log4j privilege escalation
14141| [112156] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Log4j privilege escalation
14142| [112155] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Apache Log4j privilege escalation
14143| [112137] Oracle MICROS Relate CRM Software 10.8.x/11.4.x/15.0.x, Apache Tomcat unknown vulnerability
14144| [112136] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat privilege escalation
14145| [112133] Oracle Retail Workforce Management 1.60.7/1.64.0 Apache Log4j privilege escalation
14146| [112129] Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 Apache Log4j privilege escalation
14147| [112114] Oracle 9.1 Apache Log4j privilege escalation
14148| [112113] Oracle 9.1 Apache Log4j privilege escalation
14149| [112045] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat privilege escalation
14150| [112038] Oracle Health Sciences Empirica Inspections 1.0.1.1 Apache Tomcat information disclosure
14151| [112019] Oracle Endeca Information Discovery Integrator 3.1.0/3.2.0 Apache Tomcat privilege escalation
14152| [112017] Oracle WebCenter Portal 11.1.1.9.0/12.2.1.2.0/12.2.1.3.0 Apache Struts 1 cross site scripting
14153| [112011] Oracle Identity Manager 11.1.2.3.0 Apache Commons Collections privilege escalation
14154| [111950] Oracle Database 12.2.0.1 Apache Tomcat information disclosure
14155| [111703] Apache Sling XSS Protection API 1.0.4 URL Encoding cross site scripting
14156| [111556] Apache Geode up to 1.2.x Secure Mode Parameter OQL privilege escalation
14157| [111555] Apache Geode up to 1.2.x Secure Mode OQL privilege escalation
14158| [111540] Apache Geode up to 1.2.x Secure Mode information disclosure
14159| [111519] Apache Sling JCR ContentLoader 2.1.4 xmlreader directory traversal
14160| [111338] Apache DeltaSpike-JSF 1.8.0 cross site scripting
14161| [111330] Apache OFBiz 16.11.01/16.11.02/16.11.03 BIRT Plugin cross site scripting
14162| [110789] Apache Sling up to 1.4.0 Authentication Service Credentials information disclosure
14163| [110785] Apache Drill up to 1.11.0 Query Page unknown vulnerability
14164| [110701] Apache Fineract Query Parameter sql injection
14165| [110484] Apache Synapse up to 3.0.0 Apache Commons Collections Serialized Object Code Injection privilege escalation
14166| [110426] Adobe Experience Manager 6.0/6.1/6.2/6.3 Apache Sling Servlets Post cross site scripting
14167| [110141] Apache Struts up to 2.5.14 REST Plugin denial of service
14168| [110140] Apache Qpid Broker-J up to 0.32 privilege escalation
14169| [110139] Apache Qpid Broker-J up to 6.1.4 AMQP Frame denial of service
14170| [110106] Apache CXF Fediz Spring cross site request forgery
14171| [109766] Apache OpenOffice up to 4.1.3 DOC File Parser WW8Fonts memory corruption
14172| [109750] Apache OpenOffice up to 4.1.3 DOC File Parser ImportOldFormatStyles memory corruption
14173| [109749] Apache OpenOffice up to 4.1.3 PPT File Parser PPTStyleSheet memory corruption
14174| [109606] October CMS Build 412 Apache Configuration File Upload privilege escalation
14175| [109419] Apache Camel up to 2.19.3/2.20.0 camel-castor Java Object Deserialization privilege escalation
14176| [109418] Apache Camel up to 2.19.3/2.20.0 camel-hessian Java Object Deserialization privilege escalation
14177| [109400] Apache CouchDB up to 1.6.x/2.1.0 Database Server Shell privilege escalation
14178| [109399] Apache CouchDB up to 1.6.x/2.1.0 JSON Parser Shell privilege escalation
14179| [109398] Apache CXF 3.1.14/3.2.1 JAX-WS/JAX-RS Attachment denial of service
14180| [108872] Apache Hive up to 2.1.1/2.2.0/2.3.0 Policy Enforcement privilege escalation
14181| [108939] Apple macOS up to 10.13.1 apache unknown vulnerability
14182| [108938] Apple macOS up to 10.13.1 apache denial of service
14183| [108937] Apple macOS up to 10.13.1 apache unknown vulnerability
14184| [108936] Apple macOS up to 10.13.1 apache unknown vulnerability
14185| [108935] Apple macOS up to 10.13.1 apache denial of service
14186| [108934] Apple macOS up to 10.13.1 apache unknown vulnerability
14187| [108933] Apple macOS up to 10.13.1 apache unknown vulnerability
14188| [108932] Apple macOS up to 10.13.1 apache unknown vulnerability
14189| [108931] Apple macOS up to 10.13.1 apache denial of service
14190| [108930] Apple macOS up to 10.13.1 apache unknown vulnerability
14191| [108929] Apple macOS up to 10.13.1 apache denial of service
14192| [108928] Apple macOS up to 10.13.1 apache unknown vulnerability
14193| [108797] Apache Struts up to 2.3.19 TextParseUtiltranslateVariables OGNL Expression privilege escalation
14194| [108795] Apache Traffic Server up to 5.3.0 HTTP2 set_dynamic_table_size memory corruption
14195| [108794] Apache WSS4J up to 1.6.16/2.0.1 Incomplete Fix Leak information disclosure
14196| [108793] Apache Qpid up to 0.30 qpidd Crash denial of service
14197| [108792] Apache Traffic Server up to 5.1.0 Access Restriction privilege escalation
14198| [108791] Apache Wicket up to 1.5.11/6.16.x/7.0.0-M2 Session information disclosure
14199| [108790] Apache Storm 0.9.0.1 Log Viewer directory traversal
14200| [108789] Apache Cordova In-App-Browser Standalone Plugin up to 0.3.1 on iOS CDVInAppBrowser privilege escalation
14201| [108788] Apache Cordova File-Transfer Standalone Plugin up to 0.4.1 on iOS ios/CDVFileTransfer.m spoofing
14202| [108787] Apache HttpClient up to 4.3.0 HttpClientBuilder.java unknown vulnerability
14203| [108786] Apache Wicket up to 1.4.21/1.5.9/6.3.x script Tag cross site scripting
14204| [108783] Apache Hadoop up to 0.23.3/1.0.3/2.0.1 Kerberos Security Feature Key weak encryption
14205| [108782] Apache Xerces2 XML Service denial of service
14206| [108781] Apache jUDDI up to 1.x happyjuddi.jsp Parameter cross site scripting
14207| [108780] Apache jUDDI up to 1.x Log File uddiget.jsp spoofing
14208| [108709] Apache Cordova Android up to 3.7.1/4.0.1 intent URL privilege escalation
14209| [108708] Apache ActiveMQ up to 5.10.0 XML Data XML External Entity
14210| [108707] Apache ActiveMQ up to 1.7.0 XML Data XML External Entity
14211| [108629] Apache OFBiz up to 10.04.01 privilege escalation
14212| [108543] Apache Derby 10.1.2.1/10.2.2.0/10.3.1.4/10.4.1.3 Export File privilege escalation
14213| [108312] Apache HTTP Server on RHEL IP Address Filter privilege escalation
14214| [108297] Apache NiFi up to 0.7.1/1.1.1 Proxy Chain Username Deserialization privilege escalation
14215| [108296] Apache NiFi up to 0.7.1/1.1.1 Cluster Request privilege escalation
14216| [108250] Oracle Secure Global Desktop 5.3 Apache HTTP Server memory corruption
14217| [108245] Oracle Transportation Management up to 6.3.7 Apache Tomcat unknown vulnerability
14218| [108244] Oracle Transportation Management 6.4.1/6.4.2 Apache Commons FileUpload denial of service
14219| [108243] Oracle Agile Engineering Data Management 6.1.3/6.2.0 Apache Commons Collections memory corruption
14220| [108222] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Batik denial of service
14221| [108219] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat unknown vulnerability
14222| [108217] Oracle Retail Store Inventory Management 13.2.9/14.0.4/14.1.3/15.0.1/16.0.1 Apache Groovy unknown vulnerability
14223| [108216] Oracle Retail Convenience and Fuel POS Software 2.1.132 Apache Groovy unknown vulnerability
14224| [108169] Oracle MySQL Enterprise Monitor up to 3.2.8.2223/3.3.4.3247/3.4.2.4181 Apache Tomcat unknown vulnerability
14225| [108113] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Batik denial of service
14226| [108107] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat unknown vulnerability
14227| [108102] Oracle Healthcare Master Person Index 4.x Apache Groovy unknown vulnerability
14228| [108085] Oracle Identity Manager 11.1.2.3.0 Apache Struts 1 memory corruption
14229| [108083] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
14230| [108080] Oracle GlassFish Server 3.1.2 Apache Commons FileUpload denial of service
14231| [108066] Oracle Management Pack for GoldenGate 11.2.1.0.12 Apache Tomcat memory corruption
14232| [108062] Oracle BI Publisher 11.1.1.7.0/12.2.1.1.0/12.2.1.2.0 Apache ActiveMQ memory corruption
14233| [108060] Oracle Enterprise Manager Ops Center 12.2.2/12.3.2 Apache Groovy unknown vulnerability
14234| [108033] Oracle Primavera Unifier 9.13/9.14/10.x/15.x/16.x, Apache Groovy unknown vulnerability
14235| [108013] Oracle Communications WebRTC Session Controller 7.0/7.1/7.2 Apache Groovy unknown vulnerability
14236| [108011] Oracle Communications Services Gatekeeper 5.1/6.0 Apache Trinidad unknown vulnerability
14237| [107904] Apache Struts up to 2.3.28 Double OGNL Evaluation privilege escalation
14238| [107860] Apache Solr up to 7.0 Apache Lucene RunExecutableListener XML External Entity
14239| [107834] Apache Ranger up to 0.6.1 Change Password privilege escalation
14240| [107639] Apache NiFi 1.4.0 XML External Entity
14241| [107606] Apache ZooKeper up to 3.4.9/3.5.2 Command CPU Exhaustion denial of service
14242| [107597] Apache Roller up to 5.0.2 XML-RPC Protocol Support XML External Entity
14243| [107429] Apache Impala up to 2.9.x Kudu Table privilege escalation
14244| [107411] Apache Tomcat up to 7.0.81/8.0.46/8.5.22/9.0.0 JSP File File Upload privilege escalation
14245| [107385] Apache Geode up to 1.2.0 Secure Mode privilege escalation
14246| [107339] Apache OpenNLP up to 1.5.3/1.6.0/1.7.2/1.8.1 XML Data XML External Entity
14247| [107333] Apache Wicket up to 8.0.0-M1 CSRF Prevention HTTP Header privilege escalation
14248| [107323] Apache Wicket 1.5.10/6.13.0 Class Request information disclosure
14249| [107310] Apache Geode up to 1.2.0 Command Line Utility Query privilege escalation
14250| [107276] ArcSight ESM/ArcSight ESM Express up to 6.9.1c Patch 3/6.11.0 Apache Tomcat Version information disclosure
14251| [107266] Apache Tika up to 1.12 XML Parser XML External Entity
14252| [107262] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
14253| [107258] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
14254| [107197] Apache Xerces Jelly Parser XML File XML External Entity
14255| [107193] ZTE NR8950 Apache Commons Collections RMI Request Deserialization privilege escalation
14256| [107084] Apache Struts up to 2.3.19 cross site scripting
14257| [106877] Apache Struts up to 2.0.33/2.5.10 Freemarker Tag privilege escalation
14258| [106875] Apache Struts up to 2.5.5 URL Validator denial of service
14259| [106874] Apache Struts up to 2.3.30 Convention Plugin directory traversal
14260| [106847] Apache Tomcat up to 7.0.80 VirtualDirContext Source information disclosure
14261| [106846] Apache Tomcat up to 7.0.79 on Windows HTTP PUT Method Parameter File Upload privilege escalation
14262| [106777] Apache HTTP Server up to 2.2.34/2.4.27 Limit Directive ap_limit_section HTTP Request information disclosure
14263| [106739] puppetlabs-apache up to 1.11.0/2.0.x weak authentication
14264| [106720] Apache Wicket up to 1.5.12/6.18.x/7.0.0-M4 CryptoMapper privilege escalation
14265| [106586] Apache Brooklyn up to 0.9.x REST Server cross site scripting
14266| [106562] Apache Spark up to 2.1.1 Launcher API Deserialization privilege escalation
14267| [106559] Apache Brooklyn up to 0.9.x SnakeYAML YAML Data Java privilege escalation
14268| [106558] Apache Brooklyn up to 0.9.x REST Server cross site request forgery
14269| [106556] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
14270| [106555] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
14271| [106171] Apache Directory LDAP API up to 1.0.0-M30 Timing unknown vulnerability
14272| [106167] Apache Struts up to 2.5.12 REST Plugin XML Data privilege escalation
14273| [106166] Apache Struts up to 2.3.33/2.5.12 REST Plugin denial of service
14274| [106165] Apache Struts up to 2.3.33/2.5.12 URLValidator Regex CPU Exhaustion denial of service
14275| [106115] Apache Hadoop up to 2.6.4/2.7.2 YARN NodeManager Password information disclosure
14276| [106012] Apache Solr up to 5.5.3/6.4.0 Replication directory traversal
14277| [105980] Apache Engine 16.11.01 Parameter Reflected unknown vulnerability
14278| [105962] Apache Atlas 0.6.0/0.7.0 Frame cross site scripting
14279| [105961] Apache Atlas 0.6.0/0.7.0 Stack Trace information disclosure
14280| [105960] Apache Atlas 0.6.0/0.7.0 Search Reflected cross site scripting
14281| [105959] Apache Atlas 0.6.0/0.7.0 edit Tag DOM cross site scripting
14282| [105958] Apache Atlas 0.6.0/0.7.0 edit Tag Stored cross site scripting
14283| [105957] Apache Atlas 0.6.0/0.7.0 Cookie privilege escalation
14284| [105905] Apache Atlas 0.6.0/0.7.0/0.7.1 /js privilege escalation
14285| [105878] Apache Struts up to 2.3.24.0 privilege escalation
14286| [105682] Apache2Triad 1.5.4 phpsftpd/users.php Parameter cross site scripting
14287| [105681] Apache2Triad 1.5.4 phpsftpd/users.php Request cross site request forgery
14288| [105680] Apache2Triad 1.5.4 Parameter Session Fixation weak authentication
14289| [105643] Apache Pony Mail up to 0.8b weak authentication
14290| [105288] Apache Sling up to 2.3.21 Sling.evalString() String cross site scripting
14291| [105219] Apache Tomcat up to 8.5.15/9.0.0.M21 HTTP2 Bypass directory traversal
14292| [105218] Apache Tomcat up to 7.0.78/8.0.44/8.5.15/9.0.0.M21 CORS Filter Cache Poisoning privilege escalation
14293| [105215] Apache CXF up to 3.0.12/3.1.9 OAuth2 Hawk/JOSE MAC Validation Timing unknown vulnerability
14294| [105206] Apache CXF up to 3.0.11/3.1.8 JAX-RS Module XML External Entity
14295| [105205] Apache CXF up to 3.0.11/3.1.8 HTTP Transport Module Parameter cross site scripting
14296| [105202] Apache Storm 1.0.0/1.0.1/1.0.2/1.0.3/1.1.0 Worker privilege escalation
14297| [104987] Apache Xerces-C++ XML Service CPU Exhaustion denial of service
14298| [104986] Apache CXF 2.4.5/2.5.1 WS-SP UsernameToken Policy SOAP Request weak authentication
14299| [104985] Apache MyFaces Core up to 2.1.4 EL Expression Parameter Injection information disclosure
14300| [104983] Apache Wink up to 1.1.1 XML Document xxe privilege escalation
14301| [104981] Apache Commons Email 1.0/1.1/1.2/1.3/1.4 Subject Linebreak SMTP privilege escalation
14302| [104591] MEDHOST Document Management System Apache Solr Default Credentials weak authentication
14303| [104062] Oracle MySQL Enterprise Monitor up to 3.3.3.1199 Apache Tomcat unknown vulnerability
14304| [104061] Oracle MySQL Enterprise Monitor up to 3.2.7.1204/3.3.3.1199 Apache Tomcat unknown vulnerability
14305| [104060] Oracle MySQL Enterprise Monitor up to 3.1.5.7958/3.2.5.1141/3.3.2.1162 Apache Struts 2 unknown vulnerability
14306| [103995] Oracle 8.3/8.4/15.1/15.2 Apache Trinidad unknown vulnerability
14307| [103993] Oracle Policy Automation up to 12.2.3 Apache Commons FileUplaod denial of service
14308| [103916] Oracle Banking Platform 2.3/2.4/2.4.1/2.5 Apache Commons FileUpload denial of service
14309| [103906] Oracle Communications BRM 11.2.0.0.0 Apache Commons Collections privilege escalation
14310| [103904] Oracle Communications BRM 11.2.0.0.0/11.3.0.0.0 Apache Groovy memory corruption
14311| [103866] Oracle Transportation Management 6.1/6.2 Apache Webserver unknown vulnerability
14312| [103816] Oracle BI Publisher 11.1.1.9.0/12.2.1.1.0/12.2.1.2.0 Apache Commons Fileupload denial of service
14313| [103797] Oracle Tuxedo System and Applications Monitor Apache Commons Collections privilege escalation
14314| [103792] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Commons Fileupload privilege escalation
14315| [103791] Oracle Endeca Server 7.6.0.0/7.6.1.0 Apache Commons Collections privilege escalation
14316| [103788] Oracle Enterprise Repository 11.1.1.7.0/12.1.3.0.0 Apache ActiveMQ memory corruption
14317| [103787] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Groovy memory corruption
14318| [103763] Apache Sling up to 1.0.11 XSS Protection API XSS.getValidXML() Application XML External Entity
14319| [103762] Apache Sling up to 1.0.12 XSS Protection API XSSAPI.encodeForJSString() Script Tag cross site scripting
14320| [103693] Apache OpenMeetings 1.0.0 HTTP Method privilege escalation
14321| [103692] Apache OpenMeetings 1.0.0 Tomcat Error information disclosure
14322| [103691] Apache OpenMeetings 3.2.0 Parameter privilege escalation
14323| [103690] Apache OpenMeetings 1.0.0 sql injection
14324| [103689] Apache OpenMeetings 1.0.0 crossdomain.xml privilege escalation
14325| [103688] Apache OpenMeetings 1.0.0 weak encryption
14326| [103687] Apache OpenMeetings 1.0.0 cross site request forgery
14327| [103556] Apache Roller 5.1.0/5.1.1 Weblog Page Template VTL privilege escalation
14328| [103554] Apache OpenMeetings 1.0.0 Password Update unknown vulnerability
14329| [103553] Apache OpenMeetings 1.0.0 File Upload privilege escalation
14330| [103552] Apache OpenMeetings 3.2.0 Chat cross site scripting
14331| [103551] Apache OpenMeetings 3.1.0 XML unknown vulnerability
14332| [103521] Apache HTTP Server 2.4.26 HTTP2 Free memory corruption
14333| [103520] Apache HTTP Server up to 2.2.33/2.4.26 mod_auth_digest Authorization Header memory corruption
14334| [103519] Apache Struts up to 2.5.11/2.3.32 Spring AOP denial of service
14335| [103518] Apache Struts up to 2.5.11 URLValidator directory traversal
14336| [103492] Apache Spark up to 2.1.x Web UI Reflected cross site scripting
14337| [103401] Apache Struts 2.3.x Struts 1 Plugin ActionMessage privilege escalation
14338| [103399] Apache Traffic Control Traffic Router TCP Connection Slowloris denial of service
14339| [103387] Apache Impala up to 2.8.0 StatestoreSubscriber weak encryption
14340| [103386] Apache Impala up to 2.7.x/2.8.0 Kerberos weak authentication
14341| [103352] Apache Solr Node weak authentication
14342| [102897] Apache Ignite up to 2.0 Update Notifier information disclosure
14343| [102878] Code42 CrashPlan 5.4.x RMI Server org.apache.commons.ssl.rmi.DateRMI privilege escalation
14344| [102698] Apache HTTP Server up to 2.2.32/2.4.25 mod_mime Content-Type memory corruption
14345| [102697] Apache HTTP Server 2.2.24/2.2.32 HTTP Strict Parsing ap_find_token Request Header memory corruption
14346| [102690] Apache HTTP Server up to 2.2.32/2.4.25 mod_ssl ap_hook_process_connection() denial of service
14347| [102689] Apache HTTP Server up to 2.2.32/2.4.25 ap_get_basic_auth_pw weak authentication
14348| [102622] Apache Thrift up to 0.9.2 Client Libraries skip denial of service
14349| [102538] Apache Ranger up to 0.7.0 Authorizer unknown vulnerability
14350| [102537] Apache Ranger up to 0.7.0 Wildcard Character unknown vulnerability
14351| [102536] Apache Ranger up to 0.6 Stored cross site scripting
14352| [102535] Apache Ranger up to 0.6.2 Policy Engine unknown vulnerability
14353| [102255] Apache NiFi up to 0.7.3/1.2.x Response Header privilege escalation
14354| [102254] Apache NiFi up to 0.7.3/1.2.x UI cross site scripting
14355| [102070] Apache CXF Fediz up to 1.1.2/1.2.0 Application Plugin denial of service
14356| [102020] Apache Tomcat up to 9.0.0.M1 Java Servlet HTTP Method unknown vulnerability
14357| [101858] Apache Hive up to 1.2.1/2.0.0 Client weak authentication
14358| [101802] Apache KNOX up to 0.11.0 WebHDFS privilege escalation
14359| [101928] HPE Aruba ClearPass Apache Tomcat information disclosure
14360| [101524] Apache Archiva up to 1.x/2.2.1 REST Endpoint cross site request forgery
14361| [101513] Apache jUDDI 3.1./3.1.2/3.1.3/3.1.4 Logout Open Redirect
14362| [101430] Apache CXF Fediz up to 1.3.1 OIDC Service cross site request forgery
14363| [101429] Apache CXF Fediz up to 1.2.3/1.3.1 Plugins cross site request forgery
14364| [100619] Apache Hadoop up to 2.6.x HDFS Servlet unknown vulnerability
14365| [100618] Apache Hadoop up to 2.7.0 HDFS Web UI cross site scripting
14366| [100621] Adobe ColdFusion 10/11/2016 Apache BlazeDS Library Deserialization privilege escalation
14367| [100205] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Apache Commons FileUpload denial of service
14368| [100191] Oracle Secure Global Desktop 4.71/5.2/5.3 Web Server (Apache HTTP Server) information disclosure
14369| [100162] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Commons Collections privilege escalation
14370| [100160] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Trinidad unknown vulnerability
14371| [99969] Oracle WebCenter Sites 11.1.1.8.0 Apache Tomcat memory corruption
14372| [99937] Apache Batik up to 1.8 privilege escalation
14373| [99936] Apache FOP up to 2.1 privilege escalation
14374| [99935] Apache CXF up to 3.0.12/3.1.10 STSClient Cache information disclosure
14375| [99934] Apache CXF up to 3.0.12/3.1.10 JAX-RS XML Security Streaming Client spoofing
14376| [99930] Apache Traffic Server up to 6.2.0 denial of service
14377| [99929] Apache Log4j up to 2.8.1 Socket Server Deserialization privilege escalation
14378| [99925] Apache Traffic Server 6.0.0/6.1.0/6.2.0 HPACK Bomb denial of service
14379| [99738] Ping Identity OpenID Connect Authentication Module up to 2.13 on Apache Mod_auth_openidc.c spoofing
14380| [117569] Apache Hadoop up to 2.7.3 privilege escalation
14381| [99591] Apache TomEE up to 1.7.3/7.0.0-M2 EjbObjectInputStream Serialized Object privilege escalation
14382| [99370] Apache Ignite up to 1.8 update-notifier Document XML External Entity
14383| [99299] Apache Geode up to 1.1.0 Pulse OQL Query privilege escalation
14384| [99572] Apache Tomcat up to 7.0.75/8.0.41/8.5.11/9.0.0.M17 Application Listener privilege escalation
14385| [99570] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP Connector Cache information disclosure
14386| [99569] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP/2 GOAWAY Frame Resource Exhaustion denial of service
14387| [99568] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 Pipelined Request information disclosure
14388| [99048] Apache Ambari up to 2.3.x REST API Shell Metacharacter privilege escalation
14389| [99014] Apache Camel Jackson/JacksonXML privilege escalation
14390| [98610] Apple macOS up to 10.12.3 apache_mod_php memory corruption
14391| [98609] Apple macOS up to 10.12.3 apache_mod_php denial of service
14392| [98608] Apple macOS up to 10.12.3 apache_mod_php memory corruption
14393| [98607] Apple macOS up to 10.12.3 apache_mod_php denial of service
14394| [98606] Apple macOS up to 10.12.3 apache_mod_php denial of service
14395| [98605] Apple macOS up to 10.12.3 Apache denial of service
14396| [98604] Apple macOS up to 10.12.3 Apache denial of service
14397| [98603] Apple macOS up to 10.12.3 Apache denial of service
14398| [98602] Apple macOS up to 10.12.3 Apache denial of service
14399| [98601] Apple macOS up to 10.12.3 Apache denial of service
14400| [98517] Apache POI up to 3.14 OOXML File XXE denial of service
14401| [98405] Apache Hadoop up to 0.23.10 privilege escalation
14402| [98199] Apache Camel Validation XML External Entity
14403| [97892] Apache Tomcat up to 9.0.0.M15 Reverse-Proxy Http11InputBuffer.java information disclosure
14404| [97617] Apache Camel camel-snakeyaml Deserialization privilege escalation
14405| [97602] Apache Camel camel-jackson/camel-jacksonxml CamelJacksonUnmarshalType privilege escalation
14406| [97732] Apache Struts up to 2.3.31/2.5.10 Jakarta Multipart Parser Content-Type privilege escalation
14407| [97466] mod_auth_openidc up to 2.1.5 on Apache weak authentication
14408| [97455] mod_auth_openidc up to 2.1.4 on Apache weak authentication
14409| [97081] Apache Tomcat HTTPS Request denial of service
14410| [97162] EMC OpenText Documentum D2 BeanShell/Apache Commons privilege escalation
14411| [96949] Hanwha Techwin Smart Security Manager up to 1.5 Redis/Apache Felix Gogo privilege escalation
14412| [96314] Apache Cordova up to 6.1.1 on Android weak authentication
14413| [95945] Apple macOS up to 10.12.2 apache_mod_php denial of service
14414| [95944] Apple macOS up to 10.12.2 apache_mod_php denial of service
14415| [95943] Apple macOS up to 10.12.2 apache_mod_php memory corruption
14416| [95666] Oracle FLEXCUBE Direct Banking 12.0.0/12.0.1/12.0.2/12.0.3 Apache Commons Collections privilege escalation
14417| [95455] Apache NiFi up to 1.0.0/1.1.0 Connection Details Dialogue cross site scripting
14418| [95311] Apache Storm UI Daemon privilege escalation
14419| [95291] ZoneMinder 1.30.0 Apache httpd privilege escalation
14420| [94800] Apache Wicket up to 1.5.16/6.24.x Deserialize DiskFileItem denial of service
14421| [94705] Apache Qpid Broker for Java up to 6.1.0 SCRAM-SHA-1/SCRAM-SHA-256 User information disclosure
14422| [94627] Apache HTTP Server up to 2.4.24 mod_auth_digest Crash denial of service
14423| [94626] Apache HTTP Server up to 2.4.24 mod_session_crypto Padding weak encryption
14424| [94625] Apache HTTP Server up to 2.4.24 Response Split privilege escalation
14425| [94540] Apache Tika 1.9 tika-server File information disclosure
14426| [94600] Apache ActiveMQ up to 5.14.1 Administration Console cross site scripting
14427| [94348] Apple macOS up to 10.12.1 apache_mod_php denial of service
14428| [94347] Apple macOS up to 10.12.1 apache_mod_php denial of service
14429| [94346] Apple macOS up to 10.12.1 apache_mod_php denial of service
14430| [94345] Apple macOS up to 10.12.1 apache_mod_php denial of service
14431| [94344] Apple macOS up to 10.12.1 apache_mod_php denial of service
14432| [94343] Apple macOS up to 10.12.1 apache_mod_php memory corruption
14433| [94342] Apple macOS up to 10.12.1 apache_mod_php memory corruption
14434| [94128] Apache Tomcat up to 9.0.0.M13 Error information disclosure
14435| [93958] Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c denial of service
14436| [93874] Apache Subversion up to 1.8.16/1.9.4 mod_dontdothat XXE denial of service
14437| [93855] Apache Hadoop up to 2.6.4/2.7.2 HDFS Service privilege escalation
14438| [93609] Apache OpenMeetings 3.1.0 RMI Registry privilege escalation
14439| [93555] Apache Tika 1.6-1.13 jmatio MATLAB File privilege escalation
14440| [93799] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
14441| [93798] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
14442| [93797] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 HTTP Split privilege escalation
14443| [93796] Apache Tomcat up to 8.5.6/9.0.0.M11 HTTP/2 Header Parser denial of service
14444| [93532] Apache Commons Collections Library Java privilege escalation
14445| [93210] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 ResourceLinkFactory privilege escalation
14446| [93209] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Realm Authentication User information disclosure
14447| [93208] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 System Property Replacement information disclosure
14448| [93207] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Utility Method privilege escalation
14449| [93206] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Configuration privilege escalation
14450| [93098] Apache Commons FileUpload privilege escalation
14451| [92987] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Commons Collection memory corruption
14452| [92986] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Tomcat memory corruption
14453| [92982] Oracle Insurance IStream 4.3.2 Apache Commons Collections memory corruption
14454| [92981] Oracle Financial Services Lending and Leasing 14.1.0/14.2.0 Apache Commons Collections memory corruption
14455| [92979] Oracle up to 8.0.3 Apache Commons Collections memory corruption
14456| [92977] Oracle FLEXCUBE Universal Banking up to 12.2.0 Apache Commons Collections memory corruption
14457| [92976] Oracle FLEXCUBE Universal Banking 12.87.1/12.87.2 Apache Commons Collections memory corruption
14458| [92975] Oracle FLEXCUBE Private Banking up to 12.1.0 Apache Commons Collections memory corruption
14459| [92974] Oracle FLEXCUBE Investor Servicing 12.0.1 Apache Commons Collections memory corruption
14460| [92973] Oracle 12.0.0/12.1.0 Apache Commons Collections memory corruption
14461| [92972] Oracle FLEXCUBE Core Banking 11.5.0.0.0/11.6.0.0.0 Apache Commons Collections memory corruption
14462| [92962] Oracle Agile PLM 9.3.4/9.3.5 Apache Commons Collections memory corruption
14463| [92909] Oracle Agile PLM 9.3.4/9.3.5 Apache Tomcat unknown vulnerability
14464| [92786] Oracle Banking Digital Experience 15.1 Apache Commons Collections information disclosure
14465| [92549] Apache Tomcat on Red Hat privilege escalation
14466| [92509] Apache Tomcat JK ISAPI Connector up to 1.2.41 jk_uri_worker_map.c memory corruption
14467| [92314] Apache MyFaces Trinidad up to 1.0.13/1.2.15/2.0.1/2.1.1 CoreResponseStateManager memory corruption
14468| [92313] Apache Struts2 up to 2.3.28/2.5.0 Action Name Cleanup cross site request forgery
14469| [92299] Apache Derby up to 10.12.1.0 SqlXmlUtil XML External Entity
14470| [92217] Apache ActiveMQ Artemis up to 1.3.x Broker/REST GetObject privilege escalation
14471| [92174] Apache Ranger up to 0.6.0 Policy cross site scripting
14472| [91831] Apache Jackrabbit up to 2.13.2 HTTP Header cross site request forgery
14473| [91825] Apache Zookeeper up to 3.4.8/3.5.2 C CLI Shell memory corruption
14474| [91818] Apache CXF Fediz up to 1.2.2/1.3.0 Application Plugin privilege escalation
14475| [92056] Apple macOS up to 10.11 apache_mod_php memory corruption
14476| [92055] Apple macOS up to 10.11 apache_mod_php memory corruption
14477| [92054] Apple macOS up to 10.11 apache_mod_php denial of service
14478| [92053] Apple macOS up to 10.11 apache_mod_php denial of service
14479| [92052] Apple macOS up to 10.11 apache_mod_php denial of service
14480| [92051] Apple macOS up to 10.11 apache_mod_php memory corruption
14481| [92050] Apple macOS up to 10.11 apache_mod_php denial of service
14482| [92049] Apple macOS up to 10.11 apache_mod_php memory corruption
14483| [92048] Apple macOS up to 10.11 apache_mod_php denial of service
14484| [92047] Apple macOS up to 10.11 apache_mod_php memory corruption
14485| [92046] Apple macOS up to 10.11 apache_mod_php memory corruption
14486| [92045] Apple macOS up to 10.11 apache_mod_php memory corruption
14487| [92044] Apple macOS up to 10.11 apache_mod_php memory corruption
14488| [92043] Apple macOS up to 10.11 apache_mod_php denial of service
14489| [92042] Apple macOS up to 10.11 apache_mod_php memory corruption
14490| [92041] Apple macOS up to 10.11 apache_mod_php memory corruption
14491| [92040] Apple macOS up to 10.11 Apache Proxy privilege escalation
14492| [91785] Apache Shiro up to 1.3.1 Servlet Filter privilege escalation
14493| [90879] Apache OpenMeetings up to 3.1.1 SWF Panel cross site scripting
14494| [90878] Apache Sentry up to 1.6.x Blacklist Filter reflect/reflect2/java_method privilege escalation
14495| [90610] Apache POI up to 3.13 XLSX2CSV Example OpenXML Document XML External Entity
14496| [90584] Apache ActiveMQ up to 5.11.3/5.12.2/5.13/1 Administration Web Console privilege escalation
14497| [90385] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site scripting
14498| [90384] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site request forgery
14499| [90383] Apache OpenOffice up to 4.1.2 Impress File memory corruption
14500| [89670] Apache Tomcat up to 8.5.4 CGI Servlet Environment Variable Open Redirect
14501| [89669] Apache HTTP Server up to 2.4.23 RFC 3875 Namespace Conflict Environment Variable Open Redirect
14502| [89726] Apple Mac OS X up to 10.11.5 apache_mod_php memory corruption
14503| [89484] Apache Qpid up to 0.13.0 on Windows Proton Library Certificate weak authentication
14504| [89473] HPE iMC PLAT/EAD/APM/iMC NTA/iMC BIMS/iMC UAM_TAM up to 7.2 Apache Commons Collections Library Command privilege escalation
14505| [90263] Apache Archiva Header denial of service
14506| [90262] Apache Archiva Deserialize privilege escalation
14507| [90261] Apache Archiva XML DTD Connection privilege escalation
14508| [88827] Apache Xerces-C++ up to 3.1.3 DTD Stack-Based memory corruption
14509| [88747] Apache HTTP Server 2.4.17/2.4.18 mod_http2 denial of service
14510| [88608] Apache Struts up to 2.3.28.1/2.5.0 URLValidator Null Value denial of service
14511| [88607] Apache Struts up to 2.3.28.1 REST Plugin Expression privilege escalation
14512| [88606] Apache Struts up to 2.3.28.1 Restriction privilege escalation
14513| [88605] Apache Struts up to 2.3.28.1 Restriction privilege escalation
14514| [88604] Apache Struts up to 2.3.28.1 Token Validator cross site request forgery
14515| [88603] Apache Commons FileUpload up to 1.3.1 MultipartStream denial of service
14516| [88602] Apache Struts up to 1.3.10 ActionServlet.java cross site scripting
14517| [88601] Apache Struts up to 1.3.10 Multithreading ActionServlet.java memory corruption
14518| [88600] Apache Struts up to 1.3.10 MultiPageValidator privilege escalation
14519| [89005] Apache Qpid AMQP JMS Client getObject privilege escalation
14520| [87888] Apache Ranger up to 0.5.2 Policy Admin Tool eventTime sql injection
14521| [87835] Apache CloudStack up to 4.5.2.0/4.6.2.0/4.7.1.0/4.8.0.0 SAML-based Authentication privilege escalation
14522| [87806] HPE Discovery and Dependency Mapping Inventory up to 9.32 update 3 Apache Commons Collections Library privilege escalation
14523| [87805] HPE Universal CMDB up to 10.21 Apache Commons Collections Library privilege escalation
14524| [87768] Apache Shiro up to 1.2.4 Cipher Key privilege escalation
14525| [87765] Apache James Server 2.3.2 Command privilege escalation
14526| [88667] Apache HTTP Server up to 2.4.20 mod_http2 Certificate weak authentication
14527| [87718] Apache Struts up to 2.3.24.1 OGNL Caching denial of service
14528| [87717] Apache Struts up to 2.3.28 REST Plugin privilege escalation
14529| [87706] Apache Qpid Java up to 6.0.2 AMQP privilege escalation
14530| [87703] Apache Qbid Java up to 6.0.2 PlainSaslServer.java denial of service
14531| [87702] Apache ActiveMQ up to 5.13.x Fileserver Web Application Upload privilege escalation
14532| [87700] Apache PDFbox up to 1.8.11/2.0.0 XML Parser PDF Document XML External Entity
14533| [87679] HP Release Control 9.13/9.20/9.21 Apache Commons Collections Library Java Object privilege escalation
14534| [87540] Apache Ambari up to 2.2.0 File Browser View information disclosure
14535| [87433] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
14536| [87432] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
14537| [87431] Apple Mac OS X up to 10.11.4 apache_mod_php Format String
14538| [87430] Apple Mac OS X up to 10.11.4 apache_mod_php denial of service
14539| [87429] Apple Mac OS X up to 10.11.4 apache_mod_php information disclosure
14540| [87428] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
14541| [87427] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
14542| [87389] Apache Xerces C++ up to 3.1.3 XML Document DTDScanner.cpp memory corruption
14543| [87172] Adobe ColdFusion 11 Update 7/2016/up to 10 Update 18 Apache Commons Collections Library privilege escalation
14544| [87121] Apache Cordova iOS up to 3.x Plugin privilege escalation
14545| [87120] Apache Cordova iOS up to 3.x URL Whitelist privilege escalation
14546| [83806] HPE Network Node Manager i up to 10.01 Apache Commons Collections Library privilege escalation
14547| [83077] Apache Subversion up to 1.8.15/1.9.3 mod_authz_svn mod_authz_svn.c denial of service
14548| [83076] Apache Subversion up to 1.8.15/1.9.3 svnserve svnserve/cyrus_auth.c privilege escalation
14549| [82790] Apache Struts 2.0.0/2.3.24/2.3.28 Dynamic Method privilege escalation
14550| [82789] Apache Struts 2.0.0/2.3.24/2.3.28 XSLTResult privilege escalation
14551| [82725] HPE P9000 Command View up to 7.x/8.4.0 Apache Commons Collections Library privilege escalation
14552| [82444] Apache Camel up to 2.14.x/2.15.4/2.16.0 HTTP Request privilege escalation
14553| [82389] Apache Subversion up to 1.7.x/1.8.14/1.9.2 mod_dav_svn util.c memory corruption
14554| [82280] Apache Struts up to 1.7 JRE URLDecoder cross site scripting
14555| [82260] Apache OFBiz up to 12.04.05/13.07.02 Java Object privilege escalation
14556| [82259] Apache Qpid Proton up to 0.12.0 proton.reactor.Connector weak encryption
14557| [82250] Apache Ranger up to 0.5.0 Admin UI weak authentication
14558| [82214] Apache Wicket up to 1.5.14/6.21.x/7.1.x Input Element cross site scripting
14559| [82213] Apache Wicket up to 1.5.14/6.21.x/7.1.x ModalWindow Title getWindowOpenJavaScript cross site scripting
14560| [82212] Apache Ranger up to 0.5.0 Policy Admin Tool privilege escalation
14561| [82211] Apache OFBiz up to 12.04.06/13.07.02 ModelFormField.java DisplayEntityField.getDescription cross site scripting
14562| [82082] Apache JetSpeed up to 2.3.0 User Manager Service privilege escalation
14563| [82081] Apache OpenMeetings up to 3.1.0 SOAP API information disclosure
14564| [82080] Apache OpenMeetings up to 3.1.0 Event cross site scripting
14565| [82078] Apache OpenMeetings up to 3.1.0 Import/Export System Backup ZIP Archive directory traversal
14566| [82077] Apache OpenMeetings up to 3.1.0 Password Reset sendHashByUser privilege escalation
14567| [82076] Apache Ranger up to 0.5.1 privilege escalation
14568| [82075] Apache JetSpeed up to 2.3.0 Portal cross site scripting
14569| [82074] Apache JetSpeed up to 2.3.0 cross site scripting
14570| [82073] Apache JetSpeed up to 2.3.0 User Manager Service sql injection
14571| [82072] Apache JetSpeed up to 2.3.0 Portal Site Manager ZIP Archive directory traversal
14572| [82058] Apache LDAP Studio/Directory Studio up to 2.0.0-M9 CSV Export privilege escalation
14573| [82053] Apache Ranger up to 0.4.x Policy Admin Tool privilege escalation
14574| [82052] Apache Ranger up to 0.4.x Policy Admin Tool HTTP Request cross site scripting
14575| [81696] Apache ActiveMQ up to 5.13.1 HTTP Header privilege escalation
14576| [81695] Apache Xerces-C up to 3.1.2 internal/XMLReader.cpp memory corruption
14577| [81622] HPE Asset Manager 9.40/9.41/9.50 Apache Commons Collections Library Java Object privilege escalation
14578| [81406] HPE Service Manager up to 9.35 P3/9.41 P1 Apache Commons Collections Library Command privilege escalation
14579| [81405] HPE Operations Orchestration up to 10.50 Apache Commons Collections Library Command privilege escalation
14580| [81427] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
14581| [81426] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
14582| [81372] Apache Struts up to 2.3.24.1 I18NInterceptor cross site scripting
14583| [81371] Apache Struts up to 2.3.24.1 Double OGNL Evaluation privilege escalation
14584| [81370] Apache Struts up to 2.3.24.1 Java URLDecoder cross site scripting
14585| [81084] Apache Tomcat 6.0/7.0/8.0/9.0 ServletContext directory traversal
14586| [81083] Apache Tomcat 7.0/8.0/9.0 Index Page cross site request forgery
14587| [81082] Apache Tomcat 7.0/8.0/9.0 ResourceLinkFactory.setGlobalContext privilege escalation
14588| [81081] Apache Tomcat 6.0/7.0/8.0/9.0 Error information disclosure
14589| [81080] Apache Tomcat 6.0/7.0/8.0/9.0 Session Persistence privilege escalation
14590| [81079] Apache Tomcat 6.0/7.0/8.0/9.0 StatusManagerServlet information disclosure
14591| [81078] Apache Tomcat 7.0/8.0/9.0 Session privilege escalation
14592| [80970] Apache Solr up to 5.3.0 Admin UI plugins.js cross site scripting
14593| [80969] Apache Solr up to 5.2 Schema schema-browser.js cross site scripting
14594| [80968] Apache Solr up to 5.0 analysis.js cross site scripting
14595| [80940] HP Continuous Delivery Automation 1.30 Apache Commons Collections Library privilege escalation
14596| [80823] Apache CloudStack up to 4.5.1 KVM Virtual Machine Migration privilege escalation
14597| [80822] Apache CloudStack up to 4.5.1 API Call information disclosure
14598| [80778] Apache Camel up to 2.15.4/2.16.0 camel-xstream privilege escalation
14599| [80750] HPE Operations Manager 8.x/9.0 on Windows Apache Commons Collections Library privilege escalation
14600| [80724] Apache Hive up to 1.2.1 Authorization Framework privilege escalation
14601| [80577] Oracle Secure Global Desktop 4.63/4.71/5.2 Apache HTTP Server denial of service
14602| [80165] Intel McAfee ePolicy Orchestrator up to 4.6.9/5.0.3/5.3.1 Apache Commons Collections Library privilege escalation
14603| [80116] Apache Subversion up to 1.9.2 svn Protocol libsvn_ra_svn/marshal.c read_string memory corruption
14604| [80115] Apache ActiveMQ up to 5.12.x Broker Service privilege escalation
14605| [80036] IBM Cognos Business Intelligence Apache Commons Collections Library InvokerTransformer privilege escalation
14606| [79873] VMware vCenter Operations/vRealize Orchestrator Apache Commons Collections Library Serialized Java Object privilege escalation
14607| [79840] Apache Cordova File Transfer Plugin up to 1.2.x on Android unknown vulnerability
14608| [79839] Apache TomEE Serialized Java Stream EjbObjectInputStream privilege escalation
14609| [79791] Cisco Products Apache Commons Collections Library privilege escalation
14610| [79539] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
14611| [79538] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
14612| [79294] Apache Cordova-Android up to 3.6 BridgeSecret Random Generator weak encryption
14613| [79291] Apache Cordova-Android up to 4.0 Javascript Whitelist privilege escalation
14614| [79244] Apache CXF up to 2.7.17/3.0.7/3.1.2 SAML Web SSO Module SAML Response weak authentication
14615| [79243] Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0 WLS Security com.bea.core.apache.commons.collections.jar privilege escalation
14616| [78989] Apache Ambari up to 2.1.1 Open Redirect
14617| [78988] Apache Ambari up to 2.0.1/2.1.0 Password privilege escalation
14618| [78987] Apache Ambari up to 2.0.x cross site scripting
14619| [78986] Apache Ambari up to 2.0.x Proxy Endpoint api/v1/proxy privilege escalation
14620| [78780] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
14621| [78779] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
14622| [78778] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
14623| [78777] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
14624| [78776] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
14625| [78775] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
14626| [78774] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
14627| [78297] Apache Commons Components HttpClient up to 4.3.5 HTTPS Timeout denial of service
14628| [77406] Apache Flex BlazeDS AMF Message XML External Entity
14629| [77429] Apache ActiveMQ up to 5.10.0 LDAPLoginModule privilege escalation
14630| [77399] Apache ActiveMQ up to 5.10.0 LDAPLoginModule weak authentication
14631| [77375] Apache Tapestry up to 5.3.5 Client-Side Object Storage privilege escalation
14632| [77331] Apache ActiveMQ up to 5.11.1 on Windows Fileserver Upload/Download directory traversal
14633| [77299] Apache Solr Real-Time Module up to 7.x-1.1 Index Content information disclosure
14634| [77247] Apache ActiveMQ up to 5.10 TransportConnection.java processControlCommand denial of service
14635| [77083] Apache Groovy up to 2.4.3 MethodClosure.java MethodClosure memory corruption
14636| [76953] Apache Subversion 1.7.0/1.8.0/1.8.10 svn_repos_trace_node_locations information disclosure
14637| [76952] Apache Subversion 1.7.0/1.8.0/1.8.10 mod_authz_svn anonymous/authenticated information disclosure
14638| [76567] Apache Struts 2.3.20 unknown vulnerability
14639| [76733] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 ap_some_auth_required unknown vulnerability
14640| [76732] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 Request apr_brigade_flatten privilege escalation
14641| [76731] Apache HTTP Server 2.4.12 ErrorDocument 400 Crash denial of service
14642| [75690] Apache Camel up to 2.13.3/2.14.1 XPathBuilder.java XML External Entity
14643| [75689] Apache Camel up to 2.13.3/2.14.1 XML Converter Setup XmlConverter.java SAXSource privilege escalation
14644| [75668] Apache Sling API/Sling Servlets Post up to 2.2.1 HtmlResponse cross site scripting
14645| [75601] Apache Jackrabbit up to 2.10.0 WebDAV Request XML External Entity
14646| [75420] Apache Tomcat up to 6.0.43/7.0.58/8.0.16 Security Manager privilege escalation
14647| [75145] Apache OpenOffice up to 4.1.1 HWP Filter Crash denial of service
14648| [75032] Apache Tomcat Connectors up to 1.2.40 mod_jk privilege escalation
14649| [75135] PHP 5.4/5.5 HTTP Request sapi_apache2.c apache2handler privilege escalation
14650| [74793] Apache Tomcat File Upload denial of service
14651| [74708] Apple MacOS X up to 10.10.2 Apache denial of service
14652| [74707] Apple MacOS X up to 10.10.2 Apache denial of service
14653| [74706] Apple MacOS X up to 10.10.2 Apache memory corruption
14654| [74705] Apple MacOS X up to 10.10.2 Apache denial of service
14655| [74704] Apple MacOS X up to 10.10.2 Apache denial of service
14656| [74703] Apple MacOS X up to 10.10.2 Apache denial of service
14657| [74702] Apple MacOS X up to 10.10.2 Apache denial of service
14658| [74701] Apple MacOS X up to 10.10.2 Apache cross site request forgery
14659| [74700] Apple MacOS X up to 10.10.2 Apache unknown vulnerability
14660| [74661] Apache Flex up to 4.14.0 asdoc index.html cross site scripting
14661| [74609] Apache Cassandra up to 1.2.19/2.0.13/2.1.3 JMX/RMI Interface privilege escalation
14662| [74469] Apache Xerces-C up to 7.0 internal/XMLReader.cpp denial of service
14663| [74468] Apache Batik up to 1.6 denial of service
14664| [74414] Apache Mod-gnutls up to 0.5.1 Authentication spoofing
14665| [74371] Apache Standard Taglibs up to 1.2.0 memory corruption
14666| [74367] Apache HTTP Server up to 2.4.12 mod_lua lua_request.c wsupgrade denial of service
14667| [74174] Apache WSS4J up to 2.0.0 privilege escalation
14668| [74172] Apache ActiveMQ up to 5.5.0 Administration Console cross site scripting
14669| [69092] Apache Tomcat up to 6.0.42/7.0.54/8.0.8 HTTP Request Smuggling privilege escalation
14670| [73831] Apache Qpid up to 0.30 Access Restriction unknown vulnerability
14671| [73731] Apache XML Security unknown vulnerability
14672| [68660] Oracle BI Publisher 10.1.3.4.2/11.1.1.7 Apache Tomcat cross site scripting
14673| [73659] Apache CloudStack up to 4.3.0 Stack-Based unknown vulnerability
14674| [73593] Apache Traffic Server up to 5.1.0 denial of service
14675| [73511] Apache POI up to 3.10 Deadlock denial of service
14676| [73510] Apache Solr up to 4.3.0 cross site scripting
14677| [68447] Apache Subversion up to 1.7.18/1.8.10 mod_dav_svn Crash denial of service
14678| [68446] Apache Subversion up to 1.7.18/1.8.10 REPORT Request Crash denial of service
14679| [73173] Apache CloudStack Stack-Based unknown vulnerability
14680| [68357] Apache Struts up to 2.3.16.3 Random Number Generator cross site request forgery
14681| [73106] Apache Hadoop up to 2.4.0 Symlink privilege escalation
14682| [68575] Apache HTTP Server up to 2.4.10 LuaAuthzProvider mod_lua.c privilege escalation
14683| [72890] Apache Qpid 0.30 unknown vulnerability
14684| [72887] Apache Hive 0.13.0 File Permission privilege escalation
14685| [72878] Apache Cordova 3.5.0 cross site request forgery
14686| [72877] Apache Cordova 3.5.0 cross site request forgery
14687| [72876] Apache Cordova 3.5.0 cross site request forgery
14688| [68435] Apache HTTP Server 2.4.10 mod_proxy_fcgi.c handle_headers denial of service
14689| [68065] Apache CXF up to 3.0.1 JAX-RS SAML denial of service
14690| [68064] Apache CXF up to 3.0.0 SAML Token denial of service
14691| [67913] Oracle Retail Markdown Optimization 12.0/13.0/13.1/13.2/13.4 Apache commons-beanutils-1.8.0.jar memory corruption
14692| [67912] Oracle Retail Invoice Matching up to 14.0 Apache commons-beanutils-1.8.0.jar memory corruption
14693| [67911] Oracle Retail Clearance Optimization Engine 13.3/13.4/14.0 Apache commons-beanutils-1.8.0.jar memory corruption
14694| [67910] Oracle Retail Allocation up to 13.2 Apache commons-beanutils-1.8.0.jar memory corruption
14695| [71835] Apache Shiro 1.0.0/1.1.0/1.2.0/1.2.1/1.2.2 unknown vulnerability
14696| [71633] Apachefriends XAMPP 1.8.1 cross site scripting
14697| [71629] Apache Axis2/C spoofing
14698| [67633] Apple Mac OS X up to 10.9.4 apache_mod_php ext/standard/dns.c dns_get_record memory corruption
14699| [67631] Apple Mac OS X up to 10.9.4 apache_mod_php Symlink memory corruption
14700| [67630] Apple Mac OS X up to 10.9.4 apache_mod_php cdf_read_property_info denial of service
14701| [67629] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_count_chain denial of service
14702| [67628] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_check_stream_offset denial of service
14703| [67627] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c mconvert memory corruption
14704| [67626] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c denial of service
14705| [67625] Apple Mac OS X up to 10.9.4 apache_mod_php Crash denial of service
14706| [67624] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_property_info denial of service
14707| [67623] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_unpack_summary_info denial of service
14708| [67622] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_short_sector denial of service
14709| [67620] Apple Mac OS X up to 10.9.4 apache_mod_php magic/Magdir/commands denial of service
14710| [67790] Apache HTTP Server mod_cache NULL Pointer Dereference denial of service
14711| [67522] Apache Tomcat up to 7.0.39 JSP Upload privilege escalation
14712| [70809] Apache POI up to 3.11 Crash denial of service
14713| [70808] Apache POI up to 3.10 unknown vulnerability
14714| [70806] Apache Commons-httpclient 4.2/4.2.1/4.2.2 spoofing
14715| [70749] Apache Axis up to 1.4 getCN spoofing
14716| [70701] Apache Traffic Server up to 3.3.5 denial of service
14717| [70700] Apache OFBiz up to 12.04.03 cross site scripting
14718| [67402] Apache OpenOffice 4.0.0/4.0.1/4.1.0 Calc privilege escalation
14719| [67401] Apache OpenOffice up to 4.1.0 OLE Object information disclosure
14720| [70661] Apache Subversion up to 1.6.17 denial of service
14721| [70660] Apache Subversion up to 1.6.17 spoofing
14722| [70659] Apache Subversion up to 1.6.17 spoofing
14723| [67183] Apache HTTP Server up to 2.4.9 mod_proxy denial of service
14724| [67180] Apache HTTP Server up to 2.4.9 WinNT MPM Memory Leak denial of service
14725| [67185] Apache HTTP Server up to 2.4.9 mod_status Heap-Based memory corruption
14726| [67184] Apache HTTP Server 2.4.5/2.4.6 mod_cache NULL Pointer Dereference denial of service
14727| [67182] Apache HTTP Server up to 2.4.9 mod_deflate Memory Consumption denial of service
14728| [67181] Apache HTTP Server up to 2.4.9 mod_cgid denial of service
14729| [70338] Apache Syncope up to 1.1.7 unknown vulnerability
14730| [70295] Apache CXF up to 2.7.9 Cleartext information disclosure
14731| [70106] Apache Open For Business Project up to 10.04.0 getServerError cross site scripting
14732| [70105] Apache MyFaces up to 2.1.5 JavaServer Faces directory traversal
14733| [69846] Apache HBase up to 0.94.8 information disclosure
14734| [69783] Apache CouchDB up to 1.2.0 memory corruption
14735| [13383] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 XML Parser privilege escalation
14736| [13300] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi setuid privilege escalation
14737| [13299] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi Content-Type Header information disclosure
14738| [13164] Apache CXF up to 2.6.13/2.7.10 SOAP OutgoingChainInterceptor.java Invalid Content denial of service
14739| [13163] Apache CXF up to 2.6.13/2.7.10 SOAP HTML Content denial of service
14740| [13158] Apache Struts up to 2.3.16.2 ParametersInterceptor getClass privilege escalation
14741| [69515] Apache Struts up to 2.3.15.0 CookieInterceptor memory corruption
14742| [13086] Apache Struts up to 1.3.10 Class Loader privilege escalation
14743| [13067] Apache Struts up to 2.3.16.1 Class Loader privilege escalation
14744| [69431] Apache Archiva up to 1.3.6 cross site scripting
14745| [69385] Apache Syncope up to 1.1.6 unknown vulnerability
14746| [69338] Apache Xalan-Java up to 2.7.1 system-property unknown vulnerability
14747| [12742] Trustwave ModSecurity up to 2.7.5 Chunk Extension apache2/modsecurity.c modsecurity_tx_init privilege escalation
14748| [12741] Trustwave ModSecurity up to 2.7.6 Chunked HTTP Transfer apache2/modsecurity.c modsecurity_tx_init Trailing Header privilege escalation
14749| [13387] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Content-Length Header privilege escalation
14750| [13386] Apache Tomcat Security Manager up to 6.0.39/7.0.53/8.0.5 XSLT privilege escalation
14751| [13385] Apache Tomcat 8.0.0/8.0.1/8.0.3 AJP Request Zero Length denial of service
14752| [13384] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Chunked HTTP Request denial of service
14753| [12748] Apache CouchDB 1.5.0 UUIDS /_uuids denial of service
14754| [66739] Apache Camel up to 2.12.2 unknown vulnerability
14755| [66738] Apache Camel up to 2.12.2 unknown vulnerability
14756| [12667] Apache HTTP Server 2.4.7 mod_log_config.c log_cookie denial of service
14757| [66695] Apache CouchDB up to 1.2.0 cross site scripting
14758| [66694] Apache CouchDB up to 1.2.0 Partition partition2 directory traversal
14759| [66689] Apache HTTP Server up to 2.0.33 mod_dav dav_xml_get_cdata denial of service
14760| [12518] Apache Tomcat up to 6.0.38/7.0.49/8.0.0-RC9 HTTP Header denial of service
14761| [66498] Apache expressions up to 3.3.0 Whitelist unknown vulnerability
14762| [12781] Apache Struts up to 2.3.8 ParametersInterceptor getClass denial of service
14763| [12439] Apache Tomcat 6.0.33 XML XXE information disclosure
14764| [12438] Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37 coyoteadapter.java disableURLRewriting privilege escalation
14765| [66356] Apache Wicket up to 6.8.0 information disclosure
14766| [12209] Apache Tomcat 7.0.0/7.0.50/8.0.0-RC1/8.0.1 Content-Type Header for Multi-Part Request Infinite Loop denial of service
14767| [66322] Apache ActiveMQ up to 5.8.0 cross site scripting
14768| [12291] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
14769| [66255] Apache Open For Business Project up to 10.04.3 cross site scripting
14770| [66200] Apache Hadoop up to 2.0.5 Security Feature information disclosure
14771| [66072] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
14772| [66068] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
14773| [11928] Oracle Secure Global Desktop up to 4.71 Apache Tomcat unknown vulnerability
14774| [11924] Oracle Secure Global Desktop up to 4.63 Apache Tomcat denial of service
14775| [11922] Oracle Secure Global Desktop up to 4.63 Apache Tomcat unknown vulnerability
14776| [66049] Apache XML Security for Java up to 1.4.6 Memory Consumption denial of service
14777| [12199] Apache Subversion up to 1.8.5 mod_dav_svn/repos.c get_resource denial of service
14778| [65946] askapache Firefox Adsense up to 3.0 askapache-firefox-adsense.php cross site request forgery
14779| [65668] Apache Solr 4.0.0 Updater denial of service
14780| [65665] Apache Solr up to 4.3.0 denial of service
14781| [65664] Apache Solr 3.6.0/3.6.1/3.6.2/4.0.0 Updater denial of service
14782| [65663] Apache Solr up to 4.5.1 ResourceLoader directory traversal
14783| [65658] Apache roller 4.0/4.0.1/5.0/5.0.1 unknown vulnerability
14784| [65657] Apache Roller 4.0/4.0.1/5.0/5.0.1 cross site scripting
14785| [11325] Apache Subversion 1.7.13 mod_dontdothat Bypass denial of service
14786| [11324] Apache Subversion up to 1.8.4 mod_dav_svn denial of service
14787| [11098] Apache Tomcat 5.5.25 HTTP Request cross site request forgery
14788| [65410] Apache Struts 2.3.15.3 cross site scripting
14789| [65386] Apache Solr up to 2.2.1 on TYPO3 cross site scripting
14790| [65385] Apache Solr up to 2.2.1 on TYPO3 unknown vulnerability
14791| [11044] Apache Struts 2.3.15.3 showConfig.action cross site scripting
14792| [11043] Apache Struts 2.3.15.3 actionNames.action cross site scripting
14793| [11018] cPanel WHM up to 11.40.0.11 Apache mod_userdir Tweak Interface privilege escalation
14794| [65342] Apache Sling 1.0.2/1.0.4/1.0.6/1.1.0/1.1.2 Auth Core cross site scripting
14795| [65340] Apache Shindig 2.5.0 information disclosure
14796| [65316] Apache Mod Fcgid up to 2.3.7 mod_fcgid fcgid_bucket.c fcgid_header_bucket_read memory corruption
14797| [65313] Apache Sling 2.2.0/2.3.0 AbstractCreateOperation.java deepGetOrCreateNode denial of service
14798| [10826] Apache Struts 2 File privilege escalation
14799| [65204] Apache Camel up to 2.10.1 unknown vulnerability
14800| [10460] Apache Struts 2.0.0/2.3.15.1 Action Mapping Mechanism Bypass privilege escalation
14801| [10459] Apache Struts 2.0.0/2.3.15 Dynamic Method Invocation unknown vulnerability
14802| [10160] Apache Subversion 1.8.0/1.8.1/1.8.2 svnwcsub.py handle_options race condition
14803| [10159] Apache Subversion up to 1.8.2 svnserve write_pid_file race condition
14804| [10158] Apache Subversion 1.8.0/1.8.1/1.8.2 daemonize.py daemon::daemonize race condition
14805| [10157] Apache Subversion up to 1.8.1 FSFS Repository Symlink privilege escalation
14806| [64808] Fail2ban up to 0.8.9 apache-auth.conf denial of service
14807| [64760] Best Practical RT up to 4.0.12 Apache::Session::File information disclosure
14808| [64722] Apache XML Security for C++ Heap-based memory corruption
14809| [64719] Apache XML Security for C++ Heap-based memory corruption
14810| [64718] Apache XML Security for C++ verify denial of service
14811| [64717] Apache XML Security for C++ getURIBaseTXFM memory corruption
14812| [64716] Apache XML Security for C++ spoofing
14813| [64701] Apache CXF up to 2.7.3 XML Parser Memory Consumption denial of service
14814| [64700] Apache CloudStack up to 4.1.0 Stack-Based cross site scripting
14815| [64667] Apache Open For Business Project up to 10.04.04 unknown vulnerability
14816| [64666] Apache Open For Business Project up to 10.04.04 cross site scripting
14817| [9891] Apache HTTP Server 2.2.22 suEXEC Feature .htaccess information disclosure
14818| [64509] Apache ActiveMQ up to 5.8.0 scheduled.jsp cross site scripting
14819| [9826] Apache Subversion up to 1.8.0 mod_dav_svn denial of service
14820| [9683] Apache HTTP Server 2.4.5 mod_session_dbd denial of service
14821| [64485] Apache Struts up to 2.2.3.0 privilege escalation
14822| [9568] Apache Struts up to 2.3.15 DefaultActionMapper cross site request forgery
14823| [9567] Apache Struts up to 2.3.15 DefaultActionMapper memory corruption
14824| [64467] Apache Geronimo 3.0 memory corruption
14825| [64466] Apache OpenJPA up to 2.2.1 Serialization memory corruption
14826| [64457] Apache Struts up to 2.2.3.0 cross site scripting
14827| [64326] Alejandro Garza Apachesolr Autocomplete up to 7.x-1.1 cross site scripting
14828| [9184] Apache Qpid up to 0.20 SSL misconfiguration
14829| [8935] Apache Subversion up to 1.7.9 FSFS Format Repository denial of service
14830| [8934] Apache Subversion up to 1.7.9 Svnserve Server denial of service
14831| [8933] Apache Subversion up to 1.6.21 check-mime-type.pl svnlook memory corruption
14832| [8932] Apache Subversion up to 1.6.21 svn-keyword-check.pl svnlook changed memory corruption
14833| [9022] Apache Struts up to 2.3.14.2 OGNL Expression memory corruption
14834| [8873] Apache Struts 2.3.14 privilege escalation
14835| [8872] Apache Struts 2.3.14 privilege escalation
14836| [8746] Apache HTTP Server Log File Terminal Escape Sequence Filtering mod_rewrite.c do_rewritelog privilege escalation
14837| [8666] Apache Tomcat up to 7.0.32 AsyncListener information disclosure
14838| [8665] Apache Tomcat up to 7.0.29 Chunked Transfer Encoding Extension Size denial of service
14839| [8664] Apache Tomcat up to 7.0.32 FORM Authentication weak authentication
14840| [64075] Apache Subversion up to 1.7.7 mod_dav_svn Crash denial of service
14841| [64074] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
14842| [64073] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
14843| [64072] Apache Subversion up to 1.7.7 mod_dav_svn NULL Pointer Dereference denial of service
14844| [64071] Apache Subversion up to 1.7.8 mod_dav_svn Memory Consumption denial of service
14845| [8768] Apache Struts up to 2.3.14 on Mac EL and OGNL Interpreter memory corruption
14846| [64006] Apache ActiveMQ up to 5.7.0 denial of service
14847| [64005] Apache ActiveMQ up to 5.7.0 Default Configuration denial of service
14848| [64004] Apache ActiveMQ up to 5.7.0 PortfolioPublishServlet.java cross site scripting
14849| [8427] Apache Tomcat Session Transaction weak authentication
14850| [63960] Apache Maven 3.0.4 Default Configuration spoofing
14851| [63751] Apache qpid up to 0.20 qpid::framing::Buffer denial of service
14852| [63750] Apache qpid up to 0.20 checkAvailable denial of service
14853| [63749] Apache Qpid up to 0.20 Memory Consumption denial of service
14854| [63748] Apache Qpid up to 0.20 Default Configuration denial of service
14855| [63747] Apache Rave up to 0.20 User Account information disclosure
14856| [7889] Apache Subversion up to 1.6.17 mod_dav_svn/svn_fs_file_length() denial of service
14857| [63646] Apache HTTP Server up to 2.2.23/2.4.3 mod_proxy_balancer.c balancer_handler cross site scripting
14858| [7688] Apache CXF up to 2.7.1 WSS4JInterceptor Bypass weak authentication
14859| [7687] Apache CXF up to 2.7.2 Token weak authentication
14860| [63334] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
14861| [63299] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
14862| [7202] Apache HTTP Server 2.4.2 on Oracle Solaris ld_library_path cross site scripting
14863| [7075] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector NioEndpoint.java denial of service
14864| [7074] Apache Tomcat up to 6.0.35/7.0.29 FORM Authentication RealmBase.java weak authentication
14865| [7073] Apache Tomcat up to 6.0.35/7.0.31 CSRF Prevention Filter cross site request forgery
14866| [63090] Apache Tomcat up to 4.1.24 denial of service
14867| [63089] Apache HTTP Server up to 2.2.13 mod_proxy_ajp denial of service
14868| [62933] Apache Tomcat up to 5.5.0 Access Restriction unknown vulnerability
14869| [62929] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector Memory Consumption denial of service
14870| [62833] Apache CXF -/2.6.0 spoofing
14871| [62832] Apache Axis2 up to 1.6.2 spoofing
14872| [62831] Apache Axis up to 1.4 Java Message Service spoofing
14873| [62830] Apache Commons-httpclient 3.0 Payments spoofing
14874| [62826] Apache Libcloud up to 0.11.0 spoofing
14875| [62757] Apache Open For Business Project up to 10.04.0 unknown vulnerability
14876| [8830] Red Hat JBoss Enterprise Application Platform 6.0.1 org.apache.catalina.connector.Response.encodeURL information disclosure
14877| [62661] Apache Axis2 unknown vulnerability
14878| [62658] Apache Axis2 unknown vulnerability
14879| [62467] Apache Qpid up to 0.17 denial of service
14880| [62417] Apache CXF 2.4.7/2.4.8/2.5.3/2.5.4/2.6.1 spoofing
14881| [6301] Apache HTTP Server mod_pagespeed cross site scripting
14882| [6300] Apache HTTP Server mod_pagespeed Hostname information disclosure
14883| [6123] Apache Wicket up to 1.5.7 Ajax Link cross site scripting
14884| [62035] Apache Struts up to 2.3.4 denial of service
14885| [61916] Apache QPID 0.5/0.6/0.14/0.16 unknown vulnerability
14886| [6998] Apache Tomcat 5.5.35/6.0.35/7.0.28 DIGEST Authentication Session State Caching privilege escalation
14887| [6997] Apache Tomcat 5.5.35/6.0.35/7.0.28 HTTP Digest Authentication Implementation privilege escalation
14888| [6092] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_ajp.c information disclosure
14889| [6090] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_http.c information disclosure
14890| [61507] Apache POI up to 3.8 UnhandledDataStructure denial of service
14891| [6070] Apache Struts up to 2.3.4 Token Name Configuration Parameter privilege escalation
14892| [6069] Apache Struts up to 2.3.4 Request Parameter OGNL Expression denial of service
14893| [5764] Oracle Solaris 10 Apache HTTP Server information disclosure
14894| [5700] Oracle Secure Backup 10.3.0.3/10.4.0.1 Apache denial of service
14895| [61255] Apache Hadoop 2.0.0 Kerberos unknown vulnerability
14896| [61229] Apache Sling up to 2.1.1 denial of service
14897| [61152] Apache Commons-compress 1.0/1.1/1.2/1.3/1.4 denial of service
14898| [61094] Apache Roller up to 5.0 cross site scripting
14899| [61093] Apache Roller up to 5.0 cross site request forgery
14900| [61005] Apache OpenOffice 3.3/3.4 unknown vulnerability
14901| [9673] Apache HTTP Server up to 2.4.4 mod_dav mod_dav.c Request denial of service
14902| [5436] Apache OpenOffice 3.3/3.4 WPXContentListener.cpp _closeTableRow File memory corruption
14903| [5435] Apache OpenOffice 3.3/3.4 vclmi.dll File memory corruption
14904| [60730] PHP 5.4.0/5.4.1/5.4.2 apache_request_headers memory corruption
14905| [60708] Apache Qpid 0.12 unknown vulnerability
14906| [5032] Apache Hadoop up to 0.20.205.0/1.0.1/0.23.1 Kerberos/MapReduce Security Feature privilege escalation
14907| [4949] Apache Struts File Upload XSLTResult.java XSLT File privilege escalation
14908| [4955] Apache Traffic Server 3.0.3/3.1.2 HTTP Header Parser memory corruption
14909| [4882] Apache Wicket up to 1.5.4 directory traversal
14910| [4881] Apache Wicket up to 1.4.19 cross site scripting
14911| [4884] Apache HTTP Server up to 2.3.6 mod_fcgid fcgid_spawn_ctl.c FcgidMaxProcessesPerClass HTTP Requests denial of service
14912| [60352] Apache Struts up to 2.2.3 memory corruption
14913| [60153] Apache Portable Runtime up to 1.4.3 denial of service
14914| [4598] Apache Struts 1.3.10 upload-submit.do cross site scripting
14915| [4597] Apache Struts 1.3.10 processSimple.do cross site scripting
14916| [4596] Apache Struts 2.0.14/2.2.3 struts2-rest-showcase/orders cross site scripting
14917| [4595] Apache Struts 2.0.14/2.2.3 struts2-showcase/person/editPerson.action cross site scripting
14918| [4583] Apache HTTP Server up to 2.2.21 Threaded MPM denial of service
14919| [4582] Apache HTTP Server up to 2.2.21 protocol.c information disclosure
14920| [4571] Apache Struts up to 2.3.1.2 privilege escalation
14921| [4557] Apache Tomcat up to 7.0.21 Caching/Recycling information disclosure
14922| [59934] Apache Tomcat up to 6.0.9 DigestAuthenticator.java unknown vulnerability
14923| [59933] Apache Tomcat up to 6.0.9 Access Restriction unknown vulnerability
14924| [59932] Apache Tomcat up to 6.0.9 unknown vulnerability
14925| [59931] Apache Tomcat up to 6.0.9 Access Restriction information disclosure
14926| [59902] Apache Struts up to 2.2.3 Interfaces unknown vulnerability
14927| [4528] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
14928| [4527] Apache Struts up to 2.2.3 ExceptionDelegator cross site scripting
14929| [59888] Apache Tomcat up to 6.0.6 denial of service
14930| [59886] Apache ActiveMQ up to 5.5.1 Crash denial of service
14931| [4513] Apache Struts up to 2.3.1 ParameterInterceptor directory traversal
14932| [4512] Apache Struts up to 2.2.3 CookieInterceptor privilege escalation
14933| [59850] Apache Geronimo up to 2.2.1 denial of service
14934| [59825] Apache HTTP Server up to 2.1.7 mod_reqtimeout denial of service
14935| [59556] Apache HTTP Server up to 2.0.53 mod_proxy information disclosure
14936| [58467] Apache libcloud 0.2.0/0.3.0/0.3.1/0.4.0 Access Restriction spoofing
14937| [58413] Apache Tomcat up to 6.0.10 spoofing
14938| [58381] Apache Wicket up to 1.4.17 cross site scripting
14939| [58296] Apache Tomcat up to 7.0.19 unknown vulnerability
14940| [57888] Apache HttpClient 4.0/4.0.1/4.1 Authorization information disclosure
14941| [57587] Apache Subversion up to 1.6.16 mod_dav_svn information disclosure
14942| [57585] Apache Subversion up to 1.6.16 mod_dav_svn Memory Consumption denial of service
14943| [57584] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
14944| [57577] Apache Rampart-C 1.3.0 Access Restriction rampart_timestamp_token_validate privilege escalation
14945| [57568] Apache Archiva up to 1.3.4 cross site scripting
14946| [57567] Apache Archiva up to 1.3.4 cross site request forgery
14947| [57481] Apache Tomcat 7.0.12/7.0.13 Access Restriction unknown vulnerability
14948| [4355] Apache HTTP Server APR apr_fnmatch denial of service
14949| [57435] Apache Struts up to 2.2.1.1 FileHandler.java cross site scripting
14950| [57425] Apache Struts up to 2.2.1.1 cross site scripting
14951| [4352] Apache HTTP Server 2.2.x APR apr_fnmatch denial of service
14952| [57025] Apache Tomcat up to 7.0.11 information disclosure
14953| [57024] Apache Tomcat 7.0.11 Access Restriction information disclosure
14954| [56774] IBM WebSphere Application Server up to 7.0.0.14 org.apache.jasper.runtime.JspWriterImpl.response denial of service
14955| [56824] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
14956| [56832] Apache Tomcat up to 7.0.10 Access Restriction information disclosure
14957| [56830] Apache Tomcat up to 7.0.9 Access Restriction privilege escalation
14958| [12440] Apache Tomcat 6.0.33 Malicious Request cross site scripting
14959| [56512] Apache Continuum up to 1.4.0 cross site scripting
14960| [4285] Apache Tomcat 5.x JVM getLocale denial of service
14961| [4284] Apache Tomcat 5.x HTML Manager Infinite Loop cross site scripting
14962| [4283] Apache Tomcat 5.x ServletContect privilege escalation
14963| [56441] Apache Tomcat up to 7.0.6 denial of service
14964| [56300] Apache CouchDB up to 1.0.1 Web Administration Interface cross site scripting
14965| [55967] Apache Subversion up to 1.6.4 rev_hunt.c denial of service
14966| [55966] Apache Subversion up to 1.6.4 mod_dav_svn repos.c walk denial of service
14967| [55095] Apache Axis2 up to 1.6 Default Password memory corruption
14968| [55631] Apache Archiva up to 1.3.1 User Account cross site request forgery
14969| [55556] Apache Tomcat up to 6.0.29 Default Configuration information disclosure
14970| [55553] Apache Tomcat up to 7.0.4 sessionsList.jsp cross site scripting
14971| [55162] Apache MyFaces up to 2.0.0 Authentication Code unknown vulnerability
14972| [54881] Apache Subversion up to 1.6.12 mod_dav_svn authz.c privilege escalation
14973| [54879] Apache APR-util up to 0.9.14 mod_reqtimeout apr_brigade_split_line denial of service
14974| [54693] Apache Traffic Server DNS Cache unknown vulnerability
14975| [54416] Apache CouchDB up to 0.11.0 cross site request forgery
14976| [54394] Apache CXF up to 2.2.8 Memory Consumption denial of service
14977| [54261] Apache Tomcat jsp/cal/cal2.jsp cross site scripting
14978| [54166] Apache HTTP Server up to 2.2.12 mod_cache Crash denial of service
14979| [54385] Apache Struts up to 2.1.8.1 ParameterInterceptor unknown vulnerability
14980| [54012] Apache Tomcat up to 6.0.10 denial of service
14981| [53763] Apache Axis2 1.3/1.4/1.4.1/1.5/1.5.1 Memory Consumption denial of service
14982| [53368] Apache MyFaces 1.1.7/1.2.8 cross site scripting
14983| [53397] Apache axis2 1.4.1/1.5.1 Administration Console cross site scripting
14984| [52894] Apache Tomcat up to 6.0.7 information disclosure
14985| [52960] Apache ActiveMQ up to 5.4-snapshot information disclosure
14986| [52843] Apache HTTP Server mod_auth_shadow unknown vulnerability
14987| [52786] Apache Open For Business Project up to 09.04 cross site scripting
14988| [52587] Apache ActiveMQ up to 5.3.0 cross site request forgery
14989| [52586] Apache ActiveMQ up to 5.3.0 cross site scripting
14990| [52584] Apache CouchDB up to 0.10.1 information disclosure
14991| [51757] Apache HTTP Server 2.0.44 cross site scripting
14992| [51756] Apache HTTP Server 2.0.44 spoofing
14993| [51717] Apache HTTP Server up to 1.3.3 mod_proxy ap_proxy_send_fb memory corruption
14994| [51690] Apache Tomcat up to 6.0 directory traversal
14995| [51689] Apache Tomcat up to 6.0 information disclosure
14996| [51688] Apache Tomcat up to 6.0 directory traversal
14997| [50886] HP Operations Manager 8.10 on Windows File Upload org.apache.catalina.manager.HTMLManagerServlet memory corruption
14998| [50802] Apache Tomcat up to 3.3 Default Password weak authentication
14999| [50626] Apache Solr 1.0.0 cross site scripting
15000| [49857] Apache HTTP Server mod_proxy_ftp cross site scripting
15001| [49856] Apache HTTP Server 2.2.13 mod_proxy_ftp ap_proxy_ftp_handler denial of service
15002| [49348] Apache Xerces-C++ 2.7.0 Stack-Based denial of service
15003| [86789] Apache Portable Runtime memory/unix/apr_pools.c unknown vulnerability
15004| [49283] Apache APR-util up to 1.3.8 apr-util misc/apr_rmm.c apr_rmm_realloc memory corruption
15005| [48952] Apache HTTP Server up to 1.3.6 mod_deflate denial of service
15006| [48626] Apache Tomcat up to 4.1.23 Access Restriction directory traversal
15007| [48431] Apache Tomcat up to 4.1.23 j_security_check cross site scripting
15008| [48430] Apache Tomcat up to 4.1.23 mod_jk denial of service
15009| [47801] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site request forgery
15010| [47800] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site scripting
15011| [47799] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console directory traversal
15012| [47648] Apache Tiles 2.1.0/2.1.1 cross site scripting
15013| [47640] Apache Struts 2.0.6/2.0.8/2.0.9/2.0.11/2.1 cross site scripting
15014| [47638] Apache Tomcat up to 4.1.23 mod_jk information disclosure
15015| [47636] Apache Struts 2.0.9 xip_client.html cross site scripting
15016| [47593] Apache Mod Perl 1 perl-status Apache::Status cross site scripting
15017| [47637] Apache Struts 1.0.2/1.1/1.2.4/1.2.7/1.2.8 cross site scripting
15018| [47239] Apache Struts up to 2.1.2 Beta struts directory traversal
15019| [47214] Apachefriends xampp 1.6.8 spoofing
15020| [47213] Apachefriends xampp 1.6.8 htaccess cross site request forgery
15021| [47162] Apachefriends XAMPP 1.4.4 weak authentication
15022| [47065] Apache Tomcat 4.1.23 cross site scripting
15023| [46834] Apache Tomcat up to 5.5.20 cross site scripting
15024| [46004] Apache Jackrabbit 1.4/1.5.0 search.jsp cross site scripting
15025| [49205] Apache Roller 2.3/3.0/3.1/4.0 Search cross site scripting
15026| [86625] Apache Struts directory traversal
15027| [44461] Apache Tomcat up to 5.5.0 information disclosure
15028| [44389] Apache Xerces-C++ XML Parser Memory Consumption denial of service
15029| [44352] Apache Friends XAMPP 1.6.8 adodb.php cross site scripting
15030| [43663] Apache Tomcat up to 6.0.16 directory traversal
15031| [43612] Apache Friends XAMPP 1.6.7 iart.php cross site scripting
15032| [43556] Apache HTTP Server up to 2.1.8 mod_proxy_ftp proxy_ftp.c cross site scripting
15033| [43516] Apache Tomcat up to 4.1.20 directory traversal
15034| [43509] Apache Tomcat up to 6.0.13 cross site scripting
15035| [42637] Apache Tomcat up to 6.0.16 cross site scripting
15036| [42325] Apache HTTP Server up to 2.1.8 Error Page cross site scripting
15037| [41838] Apache-SSL 1.3.34 1.57 expandcert privilege escalation
15038| [41091] Apache Software Foundation Mod Jk up to 2.0.1 mod_jk2 Stack-based memory corruption
15039| [40924] Apache Tomcat up to 6.0.15 information disclosure
15040| [40923] Apache Tomcat up to 6.0.15 unknown vulnerability
15041| [40922] Apache Tomcat up to 6.0 information disclosure
15042| [40710] Apache HTTP Server up to 2.0.61 mod_negotiation cross site scripting
15043| [40709] Apache HTTP Server up to 2.0.53 mod_negotiation cross site scripting
15044| [40656] Apache Tomcat 5.5.20 information disclosure
15045| [40503] Apache HTTP Server mod_proxy_ftp cross site scripting
15046| [40502] Apache HTTP Server up to 2.2.5 mod_proxy_balancer memory corruption
15047| [40501] Apache HTTP Server 2.2.6 mod_proxy_balancer cross site request forgery
15048| [40398] Apache HTTP Server up to 2.2 mod_proxy_balancer cross site scripting
15049| [40397] Apache HTTP Server up to 2.2 mod_proxy_balancer balancer_handler denial of service
15050| [40234] Apache Tomcat up to 6.0.15 directory traversal
15051| [40221] Apache HTTP Server 2.2.6 information disclosure
15052| [40027] David Castro Apache Authcas 0.4 sql injection
15053| [3495] Apache OpenOffice up to 2.3 Database Document Processor unknown vulnerability
15054| [3489] Apache HTTP Server 2.x HTTP Header cross site scripting
15055| [3414] Apache Tomcat WebDAV Stored privilege escalation
15056| [39489] Apache Jakarta Slide up to 2.1 directory traversal
15057| [39540] Apache Geronimo 2.0/2.0.1/2.0.2/2.1 unknown vulnerability
15058| [3310] Apache OpenOffice 1.1.3/2.0.4/2.2.1 TIFF Image Parser Heap-based memory corruption
15059| [38768] Apache HTTP Server up to 2.1.7 mod_autoindex.c cross site scripting
15060| [38952] Apache Geronimo 2.0.1/2.1 unknown vulnerability
15061| [38658] Apache Tomcat 4.1.31 cal2.jsp cross site request forgery
15062| [38524] Apache Geronimo 2.0 unknown vulnerability
15063| [3256] Apache Tomcat up to 6.0.13 cross site scripting
15064| [38331] Apache Tomcat 4.1.24 information disclosure
15065| [38330] Apache Tomcat 4.1.24 information disclosure
15066| [38185] Apache Tomcat 3.3/3.3.1/3.3.1a/3.3.2 Error Message CookieExample cross site scripting
15067| [37967] Apache Tomcat up to 4.1.36 Error Message sendmail.jsp cross site scripting
15068| [37647] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 Authorization unknown vulnerability
15069| [37646] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 unknown vulnerability
15070| [3141] Apache Tomcat up to 4.1.31 Accept-Language Header cross site scripting
15071| [3133] Apache Tomcat up to 6.0 HTTP cross site scripting
15072| [37292] Apache Tomcat up to 5.5.1 cross site scripting
15073| [3130] Apache OpenOffice 2.2.1 RTF Document Heap-based memory corruption
15074| [36981] Apache Tomcat JK Web Server Connector up to 1.2.22 mod_jk directory traversal
15075| [36892] Apache Tomcat up to 4.0.0 hello.jsp cross site scripting
15076| [37320] Apache MyFaces Tomahawk up to 1.1.4 cross site scripting
15077| [36697] Apache Tomcat up to 5.5.17 implicit-objects.jsp cross site scripting
15078| [36491] Apache Axis 1.0 Installation javaioFileNotFoundException information disclosure
15079| [36400] Apache Tomcat 5.5.15 mod_jk cross site scripting
15080| [36698] Apache Tomcat up to 4.0.0 cal2.jsp cross site scripting
15081| [36224] XAMPP Apache Distribution up to 1.6.0a adodb.php connect memory corruption
15082| [36225] XAMPP Apache Distribution 1.6.0a sql injection
15083| [2997] Apache httpd/Tomcat 5.5/6.0 directory traversal
15084| [35896] Apache Apache Test up to 1.29 mod_perl denial of service
15085| [35653] Avaya S8300 Cm 3.1.2 Apache Tomcat unknown vulnerability
15086| [35402] Apache Tomcat JK Web Server Connector 1.2.19 mod_jk.so map_uri_to_worker memory corruption
15087| [35067] Apache Stats up to 0.0.2 extract unknown vulnerability
15088| [35025] Apache Stats up to 0.0.3 extract unknown vulnerability
15089| [34252] Apache HTTP Server denial of service
15090| [2795] Apache OpenOffice 2.0.4 WMF/EMF File Heap-based memory corruption
15091| [33877] Apache Opentaps 0.9.3 cross site scripting
15092| [33876] Apache Open For Business Project unknown vulnerability
15093| [33875] Apache Open For Business Project cross site scripting
15094| [2703] Apache Jakarta Tomcat up to 5.x der_get_oid memory corruption
15095| [2611] Apache HTTP Server up to 1.0.1 set_var Format String
15096|
15097| MITRE CVE - https://cve.mitre.org:
15098| [CVE-2013-4156] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.
15099| [CVE-2013-4131] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
15100| [CVE-2013-3239] phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.
15101| [CVE-2013-3060] The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
15102| [CVE-2013-2765] The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
15103| [CVE-2013-2251] Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
15104| [CVE-2013-2249] mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
15105| [CVE-2013-2248] Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
15106| [CVE-2013-2189] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.
15107| [CVE-2013-2135] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
15108| [CVE-2013-2134] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
15109| [CVE-2013-2115] Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
15110| [CVE-2013-2071] java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
15111| [CVE-2013-2067] java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
15112| [CVE-2013-1966] Apache Struts 2 before 2.3.14.1 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
15113| [CVE-2013-1965] Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.1, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
15114| [CVE-2013-1896] mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
15115| [CVE-2013-1884] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
15116| [CVE-2013-1879] Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."
15117| [CVE-2013-1862] mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
15118| [CVE-2013-1849] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
15119| [CVE-2013-1847] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
15120| [CVE-2013-1846] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL.
15121| [CVE-2013-1845] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file or directory.
15122| [CVE-2013-1814] The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
15123| [CVE-2013-1777] The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not property implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
15124| [CVE-2013-1768] The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
15125| [CVE-2013-1088] Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
15126| [CVE-2013-1048] The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
15127| [CVE-2013-0966] The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
15128| [CVE-2013-0942] Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
15129| [CVE-2013-0941] EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
15130| [CVE-2013-0253] The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
15131| [CVE-2013-0248] The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
15132| [CVE-2013-0239] Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
15133| [CVE-2012-6573] Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.
15134| [CVE-2012-6551] The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
15135| [CVE-2012-6092] Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
15136| [CVE-2012-5887] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.
15137| [CVE-2012-5886] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
15138| [CVE-2012-5885] The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
15139| [CVE-2012-5786] The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF, possibly 2.6.0, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
15140| [CVE-2012-5785] Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
15141| [CVE-2012-5784] Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
15142| [CVE-2012-5783] Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
15143| [CVE-2012-5633] The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
15144| [CVE-2012-5616] Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.
15145| [CVE-2012-5568] Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
15146| [CVE-2012-5351] Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
15147| [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
15148| [CVE-2012-4557] The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
15149| [CVE-2012-4556] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query.
15150| [CVE-2012-4555] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors.
15151| [CVE-2012-4534] org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
15152| [CVE-2012-4528] The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
15153| [CVE-2012-4501] Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
15154| [CVE-2012-4460] The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an out-of-bounds read, but it might not trigger a crash.
15155| [CVE-2012-4459] Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.
15156| [CVE-2012-4458] The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the client-properties map in a connection.start-ok message.
15157| [CVE-2012-4446] The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
15158| [CVE-2012-4431] org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
15159| [CVE-2012-4418] Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
15160| [CVE-2012-4387] Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
15161| [CVE-2012-4386] The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
15162| [CVE-2012-4360] Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
15163| [CVE-2012-4063] The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via unspecified vectors.
15164| [CVE-2012-4001] The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.
15165| [CVE-2012-3908] Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
15166| [CVE-2012-3546] org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
15167| [CVE-2012-3544] Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
15168| [CVE-2012-3526] The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.
15169| [CVE-2012-3513] munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
15170| [CVE-2012-3506] Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
15171| [CVE-2012-3502] The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
15172| [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
15173| [CVE-2012-3467] Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
15174| [CVE-2012-3451] Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
15175| [CVE-2012-3446] Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
15176| [CVE-2012-3376] DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
15177| [CVE-2012-3373] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
15178| [CVE-2012-3126] Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Products Suite 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Apache Tomcat Agent.
15179| [CVE-2012-3123] Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.
15180| [CVE-2012-2760] mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
15181| [CVE-2012-2733] java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
15182| [CVE-2012-2687] Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
15183| [CVE-2012-2381] Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
15184| [CVE-2012-2380] Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.
15185| [CVE-2012-2379] Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
15186| [CVE-2012-2378] Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
15187| [CVE-2012-2329] Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.
15188| [CVE-2012-2145] Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.
15189| [CVE-2012-2138] The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.
15190| [CVE-2012-2098] Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
15191| [CVE-2012-1574] The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
15192| [CVE-2012-1181] fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.
15193| [CVE-2012-1089] Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
15194| [CVE-2012-1007] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.
15195| [CVE-2012-1006] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
15196| [CVE-2012-0883] envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
15197| [CVE-2012-0840] tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
15198| [CVE-2012-0838] Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
15199| [CVE-2012-0788] The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.
15200| [CVE-2012-0394] ** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
15201| [CVE-2012-0393] The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
15202| [CVE-2012-0392] The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
15203| [CVE-2012-0391] The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
15204| [CVE-2012-0256] Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
15205| [CVE-2012-0216] The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
15206| [CVE-2012-0213] The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
15207| [CVE-2012-0053] protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
15208| [CVE-2012-0047] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
15209| [CVE-2012-0031] scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
15210| [CVE-2012-0022] Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
15211| [CVE-2012-0021] The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
15212| [CVE-2011-5064] DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
15213| [CVE-2011-5063] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
15214| [CVE-2011-5062] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
15215| [CVE-2011-5057] Apache Struts 2.3.1.1 and earlier provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
15216| [CVE-2011-5034] Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
15217| [CVE-2011-4905] Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
15218| [CVE-2011-4858] Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
15219| [CVE-2011-4668] IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
15220| [CVE-2011-4449] actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.
15221| [CVE-2011-4415] The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
15222| [CVE-2011-4317] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
15223| [CVE-2011-3639] The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
15224| [CVE-2011-3620] Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
15225| [CVE-2011-3607] Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.
15226| [CVE-2011-3376] org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
15227| [CVE-2011-3375] Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
15228| [CVE-2011-3368] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
15229| [CVE-2011-3348] The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
15230| [CVE-2011-3192] The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
15231| [CVE-2011-3190] Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
15232| [CVE-2011-2729] native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
15233| [CVE-2011-2712] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
15234| [CVE-2011-2688] SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
15235| [CVE-2011-2526] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.
15236| [CVE-2011-2516] Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
15237| [CVE-2011-2481] Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
15238| [CVE-2011-2329] The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730.
15239| [CVE-2011-2204] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.
15240| [CVE-2011-2088] XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
15241| [CVE-2011-2087] Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
15242| [CVE-2011-1928] The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.
15243| [CVE-2011-1921] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
15244| [CVE-2011-1783] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
15245| [CVE-2011-1772] Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
15246| [CVE-2011-1752] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
15247| [CVE-2011-1610] Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
15248| [CVE-2011-1582] Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
15249| [CVE-2011-1571] Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
15250| [CVE-2011-1570] Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
15251| [CVE-2011-1503] The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.
15252| [CVE-2011-1502] Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
15253| [CVE-2011-1498] Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
15254| [CVE-2011-1475] The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
15255| [CVE-2011-1419] Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
15256| [CVE-2011-1318] Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
15257| [CVE-2011-1184] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
15258| [CVE-2011-1183] Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
15259| [CVE-2011-1176] The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
15260| [CVE-2011-1088] Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
15261| [CVE-2011-1077] Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
15262| [CVE-2011-1026] Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of administrators.
15263| [CVE-2011-0715] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
15264| [CVE-2011-0534] Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
15265| [CVE-2011-0533] Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta
15266| [CVE-2011-0419] Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
15267| [CVE-2011-0013] Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
15268| [CVE-2010-4644] Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
15269| [CVE-2010-4539] The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.
15270| [CVE-2010-4476] The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
15271| [CVE-2010-4455] Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.2 and 11.1.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Apache Plugin.
15272| [CVE-2010-4408] Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.
15273| [CVE-2010-4312] The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
15274| [CVE-2010-4172] Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
15275| [CVE-2010-3872] The fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.6 for the Apache HTTP Server does not use bytewise pointer arithmetic in certain circumstances, which has unspecified impact and attack vectors related to "untrusted FastCGI applications" and a "stack buffer overwrite."
15276| [CVE-2010-3863] Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
15277| [CVE-2010-3854] Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
15278| [CVE-2010-3718] Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
15279| [CVE-2010-3449] Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1
15280| [CVE-2010-3315] authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
15281| [CVE-2010-3083] sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.
15282| [CVE-2010-2952] Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.
15283| [CVE-2010-2791] mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
15284| [CVE-2010-2375] Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
15285| [CVE-2010-2234] Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.
15286| [CVE-2010-2227] Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
15287| [CVE-2010-2103] Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.
15288| [CVE-2010-2086] Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
15289| [CVE-2010-2076] Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
15290| [CVE-2010-2068] mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.
15291| [CVE-2010-2057] shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.
15292| [CVE-2010-1632] Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.
15293| [CVE-2010-1623] Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
15294| [CVE-2010-1587] The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
15295| [CVE-2010-1452] The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
15296| [CVE-2010-1325] Cross-site request forgery (CSRF) vulnerability in the apache2-slms package in SUSE Lifecycle Management Server (SLMS) 1.0 on SUSE Linux Enterprise (SLE) 11 allows remote attackers to hijack the authentication of unspecified victims via vectors related to improper parameter quoting. NOTE: some sources report that this is a vulnerability in a product named "Apache SLMS," but that is incorrect.
15297| [CVE-2010-1244] Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
15298| [CVE-2010-1157] Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.
15299| [CVE-2010-1151] Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.
15300| [CVE-2010-0684] Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
15301| [CVE-2010-0434] The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
15302| [CVE-2010-0432] Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewprofile (aka partymgr/control/login), (3) the start parameter to myportal/control/showPortalPage, (4) an invalid URI beginning with /facility/control/ReceiveReturn (aka /crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the contentId parameter (aka the entityName variable) to ecommerce/control/ViewBlogArticle, (6) the entityName parameter to webtools/control/FindGeneric, or the (7) subject or (8) content parameter to an unspecified component under ecommerce/control/contactus.
15303| [CVE-2010-0425] modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
15304| [CVE-2010-0408] The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
15305| [CVE-2010-0390] Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.
15306| [CVE-2010-0219] Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
15307| [CVE-2010-0010] Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
15308| [CVE-2010-0009] Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.
15309| [CVE-2009-5120] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a Project Woodstock service on this port.
15310| [CVE-2009-5119] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted session data.
15311| [CVE-2009-5006] The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.
15312| [CVE-2009-5005] The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.
15313| [CVE-2009-4355] Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
15314| [CVE-2009-4269] The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
15315| [CVE-2009-3923] The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
15316| [CVE-2009-3890] Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.
15317| [CVE-2009-3843] HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
15318| [CVE-2009-3821] Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
15319| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
15320| [CVE-2009-3548] The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
15321| [CVE-2009-3250] The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.
15322| [CVE-2009-3095] The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
15323| [CVE-2009-3094] The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
15324| [CVE-2009-2902] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
15325| [CVE-2009-2901] The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
15326| [CVE-2009-2823] The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.
15327| [CVE-2009-2699] The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
15328| [CVE-2009-2696] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.
15329| [CVE-2009-2693] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
15330| [CVE-2009-2625] XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
15331| [CVE-2009-2412] Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR
15332| [CVE-2009-2299] The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.
15333| [CVE-2009-1956] Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
15334| [CVE-2009-1955] The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
15335| [CVE-2009-1903] The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
15336| [CVE-2009-1891] The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
15337| [CVE-2009-1890] The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
15338| [CVE-2009-1885] Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.
15339| [CVE-2009-1462] The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.
15340| [CVE-2009-1275] Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
15341| [CVE-2009-1195] The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
15342| [CVE-2009-1191] mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
15343| [CVE-2009-1012] Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.
15344| [CVE-2009-0918] Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.
15345| [CVE-2009-0796] Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.
15346| [CVE-2009-0783] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
15347| [CVE-2009-0781] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
15348| [CVE-2009-0754] PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.
15349| [CVE-2009-0580] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.
15350| [CVE-2009-0486] Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
15351| [CVE-2009-0039] Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.
15352| [CVE-2009-0038] Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring
15353| [CVE-2009-0033] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.
15354| [CVE-2009-0026] Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
15355| [CVE-2009-0023] The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
15356| [CVE-2008-6879] Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
15357| [CVE-2008-6755] ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.
15358| [CVE-2008-6722] Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.
15359| [CVE-2008-6682] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
15360| [CVE-2008-6505] Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.
15361| [CVE-2008-6504] ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.
15362| [CVE-2008-5696] Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
15363| [CVE-2008-5676] Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."
15364| [CVE-2008-5519] The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.
15365| [CVE-2008-5518] Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet)
15366| [CVE-2008-5515] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.
15367| [CVE-2008-5457] Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
15368| [CVE-2008-4308] The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
15369| [CVE-2008-4008] Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.
15370| [CVE-2008-3666] Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured
15371| [CVE-2008-3271] Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
15372| [CVE-2008-3257] Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
15373| [CVE-2008-2939] Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
15374| [CVE-2008-2938] Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
15375| [CVE-2008-2742] Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.
15376| [CVE-2008-2717] TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
15377| [CVE-2008-2579] Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.
15378| [CVE-2008-2384] SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
15379| [CVE-2008-2370] Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
15380| [CVE-2008-2364] The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
15381| [CVE-2008-2168] Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
15382| [CVE-2008-2025] Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
15383| [CVE-2008-1947] Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
15384| [CVE-2008-1734] Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.
15385| [CVE-2008-1678] Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
15386| [CVE-2008-1232] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.
15387| [CVE-2008-0869] Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.
15388| [CVE-2008-0732] The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.
15389| [CVE-2008-0555] The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.
15390| [CVE-2008-0457] Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
15391| [CVE-2008-0456] CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
15392| [CVE-2008-0455] Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
15393| [CVE-2008-0128] The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
15394| [CVE-2008-0005] mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
15395| [CVE-2008-0002] Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
15396| [CVE-2007-6750] The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
15397| [CVE-2007-6726] Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
15398| [CVE-2007-6514] Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
15399| [CVE-2007-6423] ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
15400| [CVE-2007-6422] The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
15401| [CVE-2007-6421] Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
15402| [CVE-2007-6420] Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
15403| [CVE-2007-6388] Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
15404| [CVE-2007-6361] Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
15405| [CVE-2007-6342] SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.
15406| [CVE-2007-6286] Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
15407| [CVE-2007-6258] Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.
15408| [CVE-2007-6231] Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_includepath parameter to (1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php, or (5) libchart-1.1/libchart.php in include/. NOTE: access to include/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
15409| [CVE-2007-6203] Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
15410| [CVE-2007-5797] SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
15411| [CVE-2007-5731] Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.
15412| [CVE-2007-5461] Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
15413| [CVE-2007-5342] The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
15414| [CVE-2007-5333] Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
15415| [CVE-2007-5156] Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
15416| [CVE-2007-5085] Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
15417| [CVE-2007-5000] Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
15418| [CVE-2007-4724] Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.
15419| [CVE-2007-4723] Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
15420| [CVE-2007-4641] Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.
15421| [CVE-2007-4556] Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.
15422| [CVE-2007-4548] The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
15423| [CVE-2007-4465] Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
15424| [CVE-2007-3847] The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
15425| [CVE-2007-3571] The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.
15426| [CVE-2007-3386] Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
15427| [CVE-2007-3385] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
15428| [CVE-2007-3384] Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.
15429| [CVE-2007-3383] Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.
15430| [CVE-2007-3382] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
15431| [CVE-2007-3304] Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
15432| [CVE-2007-3303] Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
15433| [CVE-2007-3101] Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.
15434| [CVE-2007-2450] Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.
15435| [CVE-2007-2449] Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the '
15436| [CVE-2007-2353] Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
15437| [CVE-2007-2025] Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.
15438| [CVE-2007-1863] cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
15439| [CVE-2007-1862] The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
15440| [CVE-2007-1860] mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.
15441| [CVE-2007-1858] The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
15442| [CVE-2007-1842] Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.
15443| [CVE-2007-1801] Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.
15444| [CVE-2007-1743] suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
15445| [CVE-2007-1742] suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
15446| [CVE-2007-1741] Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
15447| [CVE-2007-1720] Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.
15448| [CVE-2007-1636] Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.
15449| [CVE-2007-1633] Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.
15450| [CVE-2007-1577] Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
15451| [CVE-2007-1539] Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.
15452| [CVE-2007-1524] Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.
15453| [CVE-2007-1491] Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.
15454| [CVE-2007-1358] Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
15455| [CVE-2007-1349] PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
15456| [CVE-2007-0975] Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.
15457| [CVE-2007-0930] Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.
15458| [CVE-2007-0792] The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
15459| [CVE-2007-0774] Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
15460| [CVE-2007-0637] Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.
15461| [CVE-2007-0451] Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
15462| [CVE-2007-0450] Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
15463| [CVE-2007-0419] The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).
15464| [CVE-2007-0173] Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
15465| [CVE-2007-0098] Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
15466| [CVE-2007-0086] ** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.
15467| [CVE-2006-7217] Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.
15468| [CVE-2006-7216] Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.
15469| [CVE-2006-7197] The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.
15470| [CVE-2006-7196] Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
15471| [CVE-2006-7195] Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
15472| [CVE-2006-7098] The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
15473| [CVE-2006-6869] Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
15474| [CVE-2006-6675] Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecifeid parameters in Welcome web-app.
15475| [CVE-2006-6613] Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive information via a .. (dot dot) in the pa_lang[include_file] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
15476| [CVE-2006-6589] Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.
15477| [CVE-2006-6588] The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
15478| [CVE-2006-6587] Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.
15479| [CVE-2006-6445] Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
15480| [CVE-2006-6071] TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.
15481| [CVE-2006-6047] Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
15482| [CVE-2006-5894] Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
15483| [CVE-2006-5752] Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
15484| [CVE-2006-5733] Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
15485| [CVE-2006-5263] Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apache HTTP Server log file that apparently contains PHP code.
15486| [CVE-2006-4994] Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted "Program Files" pathname.
15487| [CVE-2006-4636] Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.
15488| [CVE-2006-4625] PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
15489| [CVE-2006-4558] DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
15490| [CVE-2006-4191] Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
15491| [CVE-2006-4154] Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
15492| [CVE-2006-4110] Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
15493| [CVE-2006-4004] Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
15494| [CVE-2006-3918] http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
15495| [CVE-2006-3835] Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (
15496| [CVE-2006-3747] Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
15497| [CVE-2006-3362] Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
15498| [CVE-2006-3102] Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of time under the webroot in the temp/articles directory.
15499| [CVE-2006-3070] write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.
15500| [CVE-2006-2831] Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
15501| [CVE-2006-2806] The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.
15502| [CVE-2006-2743] Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
15503| [CVE-2006-2514] Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
15504| [CVE-2006-2330] PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
15505| [CVE-2006-1777] Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache error_log file, which is then included by doc/index.php.
15506| [CVE-2006-1564] Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.
15507| [CVE-2006-1548] Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
15508| [CVE-2006-1547] ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
15509| [CVE-2006-1546] Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
15510| [CVE-2006-1393] Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
15511| [CVE-2006-1346] Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.
15512| [CVE-2006-1292] Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
15513| [CVE-2006-1243] Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
15514| [CVE-2006-1095] Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
15515| [CVE-2006-1079] htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
15516| [CVE-2006-1078] Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
15517| [CVE-2006-0743] Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
15518| [CVE-2006-0254] Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.
15519| [CVE-2006-0150] Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
15520| [CVE-2006-0144] The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.
15521| [CVE-2006-0042] Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.
15522| [CVE-2005-4857] eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a "memory addressing error".
15523| [CVE-2005-4849] Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information.
15524| [CVE-2005-4836] The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
15525| [CVE-2005-4814] Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.
15526| [CVE-2005-4703] Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
15527| [CVE-2005-3745] Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
15528| [CVE-2005-3630] Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.
15529| [CVE-2005-3510] Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
15530| [CVE-2005-3392] Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.
15531| [CVE-2005-3357] mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
15532| [CVE-2005-3352] Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
15533| [CVE-2005-3319] The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.
15534| [CVE-2005-3164] The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
15535| [CVE-2005-2970] Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
15536| [CVE-2005-2963] The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.
15537| [CVE-2005-2728] The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
15538| [CVE-2005-2660] apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.
15539| [CVE-2005-2088] The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
15540| [CVE-2005-1754] ** DISPUTED ** JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
15541| [CVE-2005-1753] ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
15542| [CVE-2005-1344] Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
15543| [CVE-2005-1268] Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
15544| [CVE-2005-1266] Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
15545| [CVE-2005-0808] Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
15546| [CVE-2005-0182] The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.
15547| [CVE-2005-0108] Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.
15548| [CVE-2004-2734] webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
15549| [CVE-2004-2680] mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
15550| [CVE-2004-2650] Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
15551| [CVE-2004-2343] ** DISPUTED ** Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument.
15552| [CVE-2004-2336] Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.
15553| [CVE-2004-2115] Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.
15554| [CVE-2004-1834] mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
15555| [CVE-2004-1765] Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.
15556| [CVE-2004-1545] UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
15557| [CVE-2004-1438] The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
15558| [CVE-2004-1405] MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
15559| [CVE-2004-1404] Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
15560| [CVE-2004-1387] The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
15561| [CVE-2004-1084] Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
15562| [CVE-2004-1083] Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
15563| [CVE-2004-1082] mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
15564| [CVE-2004-0942] Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
15565| [CVE-2004-0940] Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
15566| [CVE-2004-0885] The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
15567| [CVE-2004-0811] Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
15568| [CVE-2004-0809] The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
15569| [CVE-2004-0786] The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
15570| [CVE-2004-0751] The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
15571| [CVE-2004-0748] mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
15572| [CVE-2004-0747] Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
15573| [CVE-2004-0700] Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
15574| [CVE-2004-0646] Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
15575| [CVE-2004-0529] The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.
15576| [CVE-2004-0493] The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
15577| [CVE-2004-0492] Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
15578| [CVE-2004-0490] cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.
15579| [CVE-2004-0488] Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
15580| [CVE-2004-0263] PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
15581| [CVE-2004-0174] Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
15582| [CVE-2004-0173] Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
15583| [CVE-2004-0113] Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
15584| [CVE-2004-0009] Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.
15585| [CVE-2003-1581] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
15586| [CVE-2003-1580] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
15587| [CVE-2003-1573] The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."
15588| [CVE-2003-1521] Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
15589| [CVE-2003-1516] The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
15590| [CVE-2003-1502] mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.
15591| [CVE-2003-1418] Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child proccess IDs (PID).
15592| [CVE-2003-1307] ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."
15593| [CVE-2003-1172] Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
15594| [CVE-2003-1171] Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.
15595| [CVE-2003-1138] The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
15596| [CVE-2003-1054] mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.
15597| [CVE-2003-0993] mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
15598| [CVE-2003-0987] mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
15599| [CVE-2003-0866] The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
15600| [CVE-2003-0844] mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.
15601| [CVE-2003-0843] Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.
15602| [CVE-2003-0789] mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
15603| [CVE-2003-0771] Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.
15604| [CVE-2003-0658] Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
15605| [CVE-2003-0542] Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
15606| [CVE-2003-0460] The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
15607| [CVE-2003-0254] Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
15608| [CVE-2003-0253] The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
15609| [CVE-2003-0249] ** DISPUTED ** PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."
15610| [CVE-2003-0245] Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
15611| [CVE-2003-0192] Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
15612| [CVE-2003-0189] The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
15613| [CVE-2003-0134] Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.
15614| [CVE-2003-0132] A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.
15615| [CVE-2003-0083] Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
15616| [CVE-2003-0020] Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
15617| [CVE-2003-0017] Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.
15618| [CVE-2003-0016] Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
15619| [CVE-2002-2310] ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
15620| [CVE-2002-2309] php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
15621| [CVE-2002-2272] Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
15622| [CVE-2002-2103] Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
15623| [CVE-2002-2029] PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
15624| [CVE-2002-2012] Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
15625| [CVE-2002-2009] Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
15626| [CVE-2002-2008] Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.
15627| [CVE-2002-2007] The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
15628| [CVE-2002-2006] The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
15629| [CVE-2002-1895] The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
15630| [CVE-2002-1850] mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
15631| [CVE-2002-1793] HTTP Server mod_ssl module running on HP-UX 11.04 with Virtualvault OS (VVOS) 4.5 through 4.6 closes the connection when the Apache server times out during an SSL request, which may allow attackers to cause a denial of service.
15632| [CVE-2002-1658] Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
15633| [CVE-2002-1635] The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin.
15634| [CVE-2002-1593] mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.
15635| [CVE-2002-1592] The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.
15636| [CVE-2002-1567] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
15637| [CVE-2002-1394] Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
15638| [CVE-2002-1233] A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
15639| [CVE-2002-1157] Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
15640| [CVE-2002-1156] Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
15641| [CVE-2002-1148] The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
15642| [CVE-2002-0935] Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
15643| [CVE-2002-0843] Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
15644| [CVE-2002-0840] Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
15645| [CVE-2002-0839] The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
15646| [CVE-2002-0682] Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
15647| [CVE-2002-0661] Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
15648| [CVE-2002-0658] OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.
15649| [CVE-2002-0654] Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
15650| [CVE-2002-0653] Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
15651| [CVE-2002-0513] The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.
15652| [CVE-2002-0493] Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
15653| [CVE-2002-0392] Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
15654| [CVE-2002-0259] InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.
15655| [CVE-2002-0249] PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
15656| [CVE-2002-0240] PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
15657| [CVE-2002-0082] The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
15658| [CVE-2002-0061] Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
15659| [CVE-2001-1556] The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
15660| [CVE-2001-1534] mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
15661| [CVE-2001-1510] Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.
15662| [CVE-2001-1449] The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
15663| [CVE-2001-1385] The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
15664| [CVE-2001-1342] Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
15665| [CVE-2001-1217] Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
15666| [CVE-2001-1216] Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
15667| [CVE-2001-1072] Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
15668| [CVE-2001-1013] Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
15669| [CVE-2001-0925] The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
15670| [CVE-2001-0829] A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
15671| [CVE-2001-0766] Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
15672| [CVE-2001-0731] Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
15673| [CVE-2001-0730] split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
15674| [CVE-2001-0729] Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
15675| [CVE-2001-0590] Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
15676| [CVE-2001-0131] htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
15677| [CVE-2001-0108] PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
15678| [CVE-2001-0042] PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
15679| [CVE-2000-1247] The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
15680| [CVE-2000-1210] Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
15681| [CVE-2000-1206] Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
15682| [CVE-2000-1205] Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.
15683| [CVE-2000-1204] Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
15684| [CVE-2000-1168] IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
15685| [CVE-2000-1016] The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
15686| [CVE-2000-0913] mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
15687| [CVE-2000-0883] The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.
15688| [CVE-2000-0869] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method.
15689| [CVE-2000-0868] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
15690| [CVE-2000-0791] Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.
15691| [CVE-2000-0760] The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
15692| [CVE-2000-0759] Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
15693| [CVE-2000-0628] The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.
15694| [CVE-2000-0505] The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
15695| [CVE-1999-1412] A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
15696| [CVE-1999-1293] mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
15697| [CVE-1999-1237] Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
15698| [CVE-1999-1199] Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
15699| [CVE-1999-1053] guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
15700| [CVE-1999-0926] Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
15701| [CVE-1999-0678] A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
15702| [CVE-1999-0448] IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
15703| [CVE-1999-0289] The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
15704| [CVE-1999-0236] ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
15705| [CVE-1999-0107] Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
15706| [CVE-1999-0071] Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
15707|
15708| SecurityFocus - https://www.securityfocus.com/bid/:
15709| [104554] Apache HBase CVE-2018-8025 Security Bypass Vulnerability
15710| [104465] Apache Geode CVE-2017-15695 Remote Code Execution Vulnerability
15711| [104418] Apache Storm CVE-2018-8008 Arbitrary File Write Vulnerability
15712| [104399] Apache Storm CVE-2018-1332 User Impersonation Vulnerability
15713| [104348] Apache UIMA CVE-2017-15691 XML External Entity Injection Vulnerability
15714| [104313] Apache NiFi XML External Entity Injection and Denial of Service Vulnerability
15715| [104259] Apache Geode CVE-2017-12622 Authorization Bypass Vulnerability
15716| [104257] Apache Sling XSS Protection API CVE-2017-15717 Cross Site Scripting Vulnerability
15717| [104253] Apache ZooKeeper CVE-2018-8012 Security Bypass Vulnerability
15718| [104252] Apache Batik CVE-2018-8013 Information Disclosure Vulnerability
15719| [104239] Apache Solr CVE-2018-8010 XML External Entity Multiple Information Disclosure Vulnerabilities
15720| [104215] Apache ORC CVE-2018-8015 Denial of Service Vulnerability
15721| [104203] Apache Tomcat CVE-2018-8014 Security Bypass Vulnerability
15722| [104161] Apache Ambari CVE-2018-8003 Directory Traversal Vulnerability
15723| [104140] Apache Derby CVE-2018-1313 Security Bypass Vulnerability
15724| [104135] Apache Tika CVE-2018-1338 Denial of Service Vulnerability
15725| [104008] Apache Fineract CVE-2018-1291 SQL Injection Vulnerability
15726| [104007] Apache Fineract CVE-2018-1292 SQL Injection Vulnerability
15727| [104005] Apache Fineract CVE-2018-1289 SQL Injection Vulnerability
15728| [104001] Apache Tika CVE-2018-1335 Remote Command Injection Vulnerability
15729| [103975] Apache Fineract CVE-2018-1290 SQL Injection Vulnerability
15730| [103974] Apache Solr CVE-2018-1308 XML External Entity Injection Vulnerability
15731| [103772] Apache Traffic Server CVE-2017-7671 Denial of Service Vulnerability
15732| [103770] Apache Traffic Server CVE-2017-5660 Security Bypass Vulnerability
15733| [103751] Apache Hive CVE-2018-1282 SQL Injection Vulnerability
15734| [103750] Apache Hive CVE-2018-1284 Security Bypass Vulnerability
15735| [103692] Apache Ignite CVE-2018-1295 Arbitrary Code Execution Vulnerability
15736| [103528] Apache HTTP Server CVE-2018-1302 Denial of Service Vulnerability
15737| [103525] Apache HTTP Server CVE-2017-15715 Remote Security Bypass Vulnerability
15738| [103524] Apache HTTP Server CVE-2018-1312 Remote Security Bypass Vulnerability
15739| [103522] Apache HTTP Server CVE-2018-1303 Denial of Service Vulnerability
15740| [103520] Apache HTTP Server CVE-2018-1283 Remote Security Vulnerability
15741| [103516] Apache Struts CVE-2018-1327 Denial of Service Vulnerability
15742| [103515] Apache HTTP Server CVE-2018-1301 Denial of Service Vulnerability
15743| [103512] Apache HTTP Server CVE-2017-15710 Denial of Service Vulnerability
15744| [103508] Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
15745| [103507] Apache Syncope CVE-2018-1322 Multiple Information Disclosure Vulnerabilities
15746| [103490] Apache Commons Compress CVE-2018-1324 Multiple Denial Of Service Vulnerabilities
15747| [103434] APACHE Allura CVE-2018-1319 HTTP Response Splitting Vulnerability
15748| [103389] Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
15749| [103222] Apache CloudStack CVE-2013-4317 Information Disclosure Vulnerability
15750| [103219] Apache Xerces-C CVE-2017-12627 Null Pointer Dereference Denial of Service Vulnerability
15751| [103206] Apache Geode CVE-2017-15693 Remote Code Execution Vulnerability
15752| [103205] Apache Geode CVE-2017-15692 Remote Code Execution Vulnerability
15753| [103170] Apache Tomcat CVE-2018-1304 Security Bypass Vulnerability
15754| [103144] Apache Tomcat CVE-2018-1305 Security Bypass Vulnerability
15755| [103102] Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
15756| [103098] Apache Karaf CVE-2016-8750 LDAP Injection Vulnerability
15757| [103069] Apache Tomcat CVE-2017-15706 Remote Security Weakness
15758| [103068] Apache JMeter CVE-2018-1287 Security Bypass Vulnerability
15759| [103067] Apache Qpid Dispatch Router 'router_core/connections.c' Denial of Service Vulnerability
15760| [103036] Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
15761| [103025] Apache Thrift CVE-2016-5397 Remote Command Injection Vulnerability
15762| [102879] Apache POI CVE-2017-12626 Multiple Denial of Service Vulnerabilities
15763| [102842] Apache NiFi CVE-2017-12632 Host Header Injection Vulnerability
15764| [102815] Apache NiFi CVE-2017-15697 Multiple Cross Site Scripting Vulnerabilities
15765| [102488] Apache Geode CVE-2017-9795 Remote Code Execution Vulnerability
15766| [102229] Apache Sling CVE-2017-15700 Information Disclosure Vulnerability
15767| [102226] Apache Drill CVE-2017-12630 Cross Site Scripting Vulnerability
15768| [102154] Multiple Apache Products CVE-2017-15708 Remote Code Execution Vulnerability
15769| [102127] Apache CXF Fediz CVE-2017-12631 Multiple Cross Site Request Forgery Vulnerabilities
15770| [102041] Apache Qpid Broker-J CVE-2017-15701 Denial of Service Vulnerability
15771| [102040] Apache Qpid Broker CVE-2017-15702 Security Weakness
15772| [102021] Apache Struts CVE-2017-15707 Denial of Service Vulnerability
15773| [101980] EMC RSA Authentication Agent for Web: Apache Web Server Authentication Bypass Vulnerability
15774| [101876] Apache Camel CVE-2017-12634 Deserialization Remote Code Execution Vulnerability
15775| [101874] Apache Camel CVE-2017-12633 Deserialization Remote Code Execution Vulnerability
15776| [101872] Apache Karaf CVE-2014-0219 Local Denial of Service Vulnerability
15777| [101868] Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
15778| [101859] Apache CXF CVE-2017-12624 Denial of Service Vulnerability
15779| [101844] Apache Sling Servlets Post CVE-2017-11296 Cross Site Scripting Vulnerability
15780| [101686] Apache Hive CVE-2017-12625 Information Disclosure Vulnerability
15781| [101644] Apache Wicket CVE-2012-5636 Cross Site Scripting Vulnerability
15782| [101631] Apache Traffic Server CVE-2015-3249 Multiple Remote Code Execution Vulnerabilities
15783| [101630] Apache Traffic Server CVE-2014-3624 Access Bypass Vulnerability
15784| [101625] Apache jUDDI CVE-2009-1197 Security Bypass Vulnerability
15785| [101623] Apache jUDDI CVE-2009-1198 Cross Site Scripting Vulnerability
15786| [101620] Apache Subversion 'libsvn_fs_fs/fs_fs.c' Denial of Service Vulnerability
15787| [101585] Apache OpenOffice Multiple Remote Code Execution Vulnerabilities
15788| [101577] Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
15789| [101575] Apache Wicket CVE-2014-0043 Information Disclosure Vulnerability
15790| [101570] Apache Geode CVE-2017-9797 Information Disclosure Vulnerability
15791| [101562] Apache Derby CVE-2010-2232 Arbitrary File Overwrite Vulnerability
15792| [101560] Apache Portable Runtime Utility CVE-2017-12613 Multiple Information Disclosure Vulnerabilities
15793| [101558] Apache Portable Runtime Utility Local Out-of-Bounds Read Denial of Service Vulnerability
15794| [101532] Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
15795| [101516] Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
15796| [101261] Apache Solr/Lucene CVE-2017-12629 Information Disclosure and Remote Code Execution Vulnerabilities
15797| [101230] Apache Roller CVE-2014-0030 XML External Entity Injection Vulnerability
15798| [101173] Apache IMPALA CVE-2017-9792 Information Disclosure Vulnerability
15799| [101052] Apache Commons Jelly CVE-2017-12621 Security Bypass Vulnerability
15800| [101027] Apache Mesos CVE-2017-7687 Denial of Service Vulnerability
15801| [101023] Apache Mesos CVE-2017-9790 Denial of Service Vulnerability
15802| [100954] Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
15803| [100946] Apache Wicket CVE-2014-7808 Cross Site Request Forgery Vulnerability
15804| [100901] Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability
15805| [100897] Apache Tomcat CVE-2017-12616 Information Disclosure Vulnerability
15806| [100880] Apache Directory LDAP API CVE-2015-3250 Unspecified Information Disclosure Vulnerability
15807| [100872] Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
15808| [100870] Apache Solr CVE-2017-9803 Remote Privilege Escalation Vulnerability
15809| [100859] puppetlabs-apache CVE-2017-2299 Information Disclosure Vulnerability
15810| [100829] Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
15811| [100823] Apache Spark CVE-2017-12612 Deserialization Remote Code Execution Vulnerability
15812| [100612] Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
15813| [100611] Apache Struts CVE-2017-9793 Denial of Service Vulnerability
15814| [100609] Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
15815| [100587] Apache Atlas CVE-2017-3155 Cross Frame Scripting Vulnerability
15816| [100581] Apache Atlas CVE-2017-3154 Information Disclosure Vulnerability
15817| [100578] Apache Atlas CVE-2017-3153 Cross Site Scripting Vulnerability
15818| [100577] Apache Atlas CVE-2017-3152 Cross Site Scripting Vulnerability
15819| [100547] Apache Atlas CVE-2017-3151 HTML Injection Vulnerability
15820| [100536] Apache Atlas CVE-2017-3150 Cross Site Scripting Vulnerability
15821| [100449] Apache Pony Mail CVE-2016-4460 Authentication Bypass Vulnerability
15822| [100447] Apache2Triad Multiple Security Vulnerabilities
15823| [100284] Apache Sling Servlets Post CVE-2017-9802 Cross Site Scripting Vulnerability
15824| [100280] Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
15825| [100259] Apache Subversion CVE-2017-9800 Remote Command Execution Vulnerability
15826| [100256] Apache Tomcat CVE-2017-7675 Directory Traversal Vulnerability
15827| [100235] Apache Storm CVE-2017-9799 Remote Code Execution Vulnerability
15828| [100082] Apache Commons Email CVE-2017-9801 SMTP Header Injection Vulnerability
15829| [99873] Apache Sling XSS Protection API CVE-2016-6798 XML External Entity Injection Vulnerability
15830| [99870] Apache Sling API CVE-2016-5394 Cross Site Scripting Vulnerability
15831| [99603] Apache Spark CVE-2017-7678 Cross Site Scripting Vulnerability
15832| [99592] Apache OpenMeetings CVE-2017-7685 Security Bypass Vulnerability
15833| [99587] Apache OpenMeetings CVE-2017-7673 Security Bypass Vulnerability
15834| [99586] Apache OpenMeetings CVE-2017-7688 Security Bypass Vulnerability
15835| [99584] Apache OpenMeetings CVE-2017-7684 Denial of Service Vulnerability
15836| [99577] Apache OpenMeetings CVE-2017-7663 Cross Site Scripting Vulnerability
15837| [99576] Apache OpenMeetings CVE-2017-7664 XML External Entity Injection Vulnerability
15838| [99569] Apache HTTP Server CVE-2017-9788 Memory Corruption Vulnerability
15839| [99568] Apache HTTP Server CVE-2017-9789 Denial of Service Vulnerability
15840| [99563] Apache Struts CVE-2017-7672 Denial of Service Vulnerability
15841| [99562] Apache Struts Spring AOP Functionality Denial of Service Vulnerability
15842| [99509] Apache Impala CVE-2017-5652 Information Disclosure Vulnerability
15843| [99508] Apache IMPALA CVE-2017-5640 Authentication Bypass Vulnerability
15844| [99486] Apache Traffic Control CVE-2017-7670 Denial of Service Vulnerability
15845| [99485] Apache Solr CVE-2017-7660 Security Bypass Vulnerability
15846| [99484] Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
15847| [99292] Apache Ignite CVE-2017-7686 Information Disclosure Vulnerability
15848| [99170] Apache HTTP Server CVE-2017-7679 Buffer Overflow Vulnerability
15849| [99137] Apache HTTP Server CVE-2017-7668 Denial of Service Vulnerability
15850| [99135] Apache HTTP Server CVE-2017-3167 Authentication Bypass Vulnerability
15851| [99134] Apache HTTP Server CVE-2017-3169 Denial of Service Vulnerability
15852| [99132] Apache HTTP Server CVE-2017-7659 Denial of Service Vulnerability
15853| [99112] Apache Thrift CVE-2015-3254 Denial of Service Vulnerability
15854| [99067] Apache Ranger CVE-2016-8751 HTML Injection Vulnerability
15855| [99018] Apache NiFi CVE-2017-7667 Cross Frame Scripting Vulnerability
15856| [99009] Apache NiFi CVE-2017-7665 Cross Site Scripting Vulnerability
15857| [98961] Apache Ranger CVE-2017-7677 Security Bypass Vulnerability
15858| [98958] Apache Ranger CVE-2017-7676 Security Bypass Vulnerability
15859| [98888] Apache Tomcat CVE-2017-5664 Security Bypass Vulnerability
15860| [98814] Apache Zookeeper CVE-2017-5637 Denial of Service Vulnerability
15861| [98795] Apache Hadoop CVE-2017-7669 Remote Privilege Escalation Vulnerability
15862| [98739] Apache Knox CVE-2017-5646 User Impersonation Vulnerability
15863| [98669] Apache Hive CVE-2016-3083 Security Bypass Vulnerability
15864| [98646] Apache Atlas CVE-2016-8752 Information Disclosure Vulnerability
15865| [98570] Apache Archiva CVE-2017-5657 Multiple Cross-Site Request Forgery Vulnerabilities
15866| [98489] Apache CXF Fediz CVE-2017-7661 Multiple Cross Site Request Forgery Vulnerabilities
15867| [98485] Apache CXF Fediz CVE-2017-7662 Cross Site Request Forgery Vulnerability
15868| [98466] Apache Ambari CVE-2017-5655 Insecure Temporary File Handling Vulnerability
15869| [98365] Apache Cordova For Android CVE-2016-6799 Information Disclosure Vulnerability
15870| [98025] Apache Hadoop CVE-2017-3161 Cross Site Scripting Vulnerability
15871| [98017] Apache Hadoop CVE-2017-3162 Input Validation Vulnerability
15872| [97971] Apache CXF CVE-2017-5656 Information Disclosure Vulnerability
15873| [97968] Apache CXF CVE-2017-5653 Spoofing Vulnerability
15874| [97967] Apache ActiveMQ CVE-2015-7559 Denial of Service Vulnerability
15875| [97949] Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
15876| [97948] Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
15877| [97947] Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
15878| [97945] Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
15879| [97702] Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
15880| [97582] Apache CXF CVE-2016-6812 Cross Site Scripting Vulnerability
15881| [97579] Apache CXF JAX-RS CVE-2016-8739 XML External Entity Injection Vulnerability
15882| [97544] Apache Tomcat CVE-2017-5651 Information Disclosure Vulnerability
15883| [97531] Apache Tomcat CVE-2017-5650 Denial of Service Vulnerability
15884| [97530] Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
15885| [97509] Apache Ignite CVE-2016-6805 Information Disclosure and XML External Entity Injection Vulnerabilities
15886| [97383] Apache Flex BlazeDS CVE-2017-5641 Remote Code Execution Vulnerability
15887| [97378] Apache Geode CVE-2017-5649 Information Disclosure Vulnerability
15888| [97229] Apache Ambari CVE-2016-4976 Local Information Disclosure Vulnerability
15889| [97226] Apache Camel CVE-2017-5643 Server Side Request Forgery Security Bypass Vulnerability
15890| [97184] Apache Ambari CVE-2016-6807 Remote Command Execution Vulnerability
15891| [97179] Apache Camel CVE-2016-8749 Java Deserialization Multiple Remote Code Execution Vulnerabilities
15892| [96983] Apache POI CVE-2017-5644 Denial Of Service Vulnerability
15893| [96895] Apache Tomcat CVE-2016-8747 Information Disclosure Vulnerability
15894| [96731] Apache NiFi CVE-2017-5636 Remote Code Injection Vulnerability
15895| [96730] Apache NiFi CVE-2017-5635 Security Bypass Vulnerability
15896| [96729] Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
15897| [96540] IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
15898| [96398] Apache CXF CVE-2017-3156 Information Disclosure Vulnerability
15899| [96321] Apache Camel CVE-2017-3159 Remote Code Execution Vulnerability
15900| [96293] Apache Tomcat 'http11/AbstractInputBuffer.java' Denial of Service Vulnerability
15901| [96228] Apache Brooklyn Cross Site Request Forgery and Multiple Cross Site Scripting Vulnerabilities
15902| [95998] Apache Ranger CVE-2016-8746 Security Bypass Vulnerability
15903| [95929] Apache Groovy CVE-2016-6497 Information Disclosure Vulnerability
15904| [95838] Apache Cordova For Android CVE-2017-3160 Man in the Middle Security Bypass Vulnerability
15905| [95675] Apache Struts Remote Code Execution Vulnerability
15906| [95621] Apache NiFi CVE-2106-8748 Cross Site Scripting Vulnerability
15907| [95429] Apache Groovy CVE-2016-6814 Remote Code Execution Vulnerability
15908| [95335] Apache Hadoop CVE-2016-3086 Information Disclosure Vulnerability
15909| [95168] Apache Wicket CVE-2016-6793 Denial of Service Vulnerability
15910| [95136] Apache Qpid Broker for Java CVE-2016-8741 Remote Information Disclosure Vulnerability
15911| [95078] Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
15912| [95077] Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
15913| [95076] Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
15914| [95020] Apache Tika CVE-2015-3271 Remote Information Disclosure Vulnerability
15915| [94950] Apache Hadoop CVE-2016-5001 Local Information Disclosure Vulnerability
15916| [94882] Apache ActiveMQ CVE-2016-6810 HTML Injection Vulnerability
15917| [94828] Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
15918| [94766] Apache CouchDB CVE-2016-8742 Local Privilege Escalation Vulnerability
15919| [94657] Apache Struts CVE-2016-8738 Denial of Service Vulnerability
15920| [94650] Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
15921| [94588] Apache Subversion CVE-2016-8734 XML External Entity Denial of Service Vulnerability
15922| [94513] Apache Karaf CVE-2016-8648 Remote Code Execution Vulnerability
15923| [94463] Apache Tomcat CVE-2016-8735 Remote Code Execution Vulnerability
15924| [94462] Apache Tomcat CVE-2016-6817 Denial of Service Vulnerability
15925| [94461] Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
15926| [94418] Apache OpenOffice CVE-2016-6803 Local Privilege Escalation Vulnerability
15927| [94247] Apache Tika CVE-2016-6809 Remote Code Execution Vulnerability
15928| [94221] Apache Ranger CVE-2016-6815 Local Privilege Escalation Vulnerability
15929| [94145] Apache OpenMeetings CVE-2016-8736 Remote Code Execution Vulnerability
15930| [93945] Apache CloudStack CVE-2016-6813 Authorization Bypass Vulnerability
15931| [93944] Apache Tomcat Security Manager CVE-2016-6796 Security Bypass Vulnerability
15932| [93943] Apache Tomcat CVE-2016-6794 Security Bypass Vulnerability
15933| [93942] Apache Tomcat Security Manager CVE-2016-5018 Security Bypass Vulnerability
15934| [93940] Apache Tomcat CVE-2016-6797 Security Bypass Vulnerability
15935| [93939] Apache Tomcat CVE-2016-0762 Information Disclosure Vulnerability
15936| [93774] Apache OpenOffice CVE-2016-6804 DLL Loading Remote Code Execution Vulnerability
15937| [93773] Apache Struts CVE-2016-6795 Directory Traversal Vulnerability
15938| [93478] Apache Tomcat CVE-2016-6325 Local Privilege Escalation Vulnerability
15939| [93472] Apache Tomcat CVE-2016-5425 Insecure File Permissions Vulnerability
15940| [93429] Apache Tomcat JK Connector CVE-2016-6808 Remote Buffer Overflow Vulnerability
15941| [93263] Apache Tomcat CVE-2016-1240 Local Privilege Escalation Vulnerability
15942| [93236] Apache MyFaces Trinidad CVE-2016-5019 Remote Code Execution Vulnerability
15943| [93142] Apache ActiveMQ Artemis CVE-2016-4978 Remote Code Execution Vulnerability
15944| [93132] Apache Derby CVE-2015-1832 XML External Entity Information Disclosure Vulnerability
15945| [93044] Apache Zookeeper CVE-2016-5017 Buffer Overflow Vulnerability
15946| [92966] Apache Jackrabbit CVE-2016-6801 Cross-Site Request Forgery Vulnerability
15947| [92947] Apache Shiro CVE-2016-6802 Remote Security Bypass Vulnerability
15948| [92905] Apache CXF Fediz CVE-2016-4464 Security Bypass Vulnerability
15949| [92577] Apache Ranger CVE-2016-5395 HTML Injection Vulnerability
15950| [92331] Apache HTTP Server CVE-2016-1546 Remote Denial of Service Vulnerability
15951| [92328] Apache Hive CVE-2016-0760 Multiple Remote Code Execution Vulnerabilities
15952| [92320] Apache APR-util and httpd CVE-2016-6312 Denial of Service Vulnerability
15953| [92100] Apache POI CVE-2016-5000 XML External Entity Injection Vulnerability
15954| [92079] Apache OpenOffice CVE-2016-1513 Remote Code Execution Vulnerability
15955| [91818] Apache Tomcat CVE-2016-5388 Security Bypass Vulnerability
15956| [91816] Apache HTTP Server CVE-2016-5387 Security Bypass Vulnerability
15957| [91788] Apache Qpid Proton CVE-2016-4467 Certificate Verification Security Bypass Vulnerability
15958| [91738] Apache XML-RPC CVE-2016-5003 Remote Code Execution Vulnerability
15959| [91736] Apache XML-RPC Multiple Security Vulnerabilities
15960| [91707] Apache Archiva CVE-2016-5005 HTML Injection Vulnerability
15961| [91703] Apache Archiva CVE-2016-4469 Multiple Cross-Site Request Forgery Vulnerabilities
15962| [91566] Apache HTTP Server CVE-2016-4979 Authentication Bypass Vulnerability
15963| [91537] Apache QPID CVE-2016-4974 Deserialization Security Bypass Vulnerability
15964| [91501] Apache Xerces-C CVE-2016-4463 Stack Buffer Overflow Vulnerability
15965| [91453] Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
15966| [91284] Apache Struts CVE-2016-4431 Security Bypass Vulnerability
15967| [91282] Apache Struts CVE-2016-4433 Security Bypass Vulnerability
15968| [91281] Apache Struts CVE-2016-4430 Cross-Site Request Forgery Vulnerability
15969| [91280] Apache Struts CVE-2016-4436 Security Bypass Vulnerability
15970| [91278] Apache Struts CVE-2016-4465 Denial of Service Vulnerability
15971| [91277] Apache Struts Incomplete Fix Remote Code Execution Vulnerability
15972| [91275] Apache Struts CVE-2016-4438 Remote Code Execution Vulnerability
15973| [91217] Apache Continuum 'saveInstallation.action' Command Execution Vulnerability
15974| [91141] Apache CloudStack CVE-2016-3085 Authentication Bypass Vulnerability
15975| [91068] Apache Struts CVE-2016-1181 Remote Code Execution Vulnerability
15976| [91067] Apache Struts CVE-2016-1182 Security Bypass Vulnerability
15977| [91024] Apache Shiro CVE-2016-4437 Information Disclosure Vulnerability
15978| [90988] Apache Ranger CVE-2016-2174 SQL Injection Vulnerability
15979| [90961] Apache Struts CVE-2016-3093 Denial of Service Vulnerability
15980| [90960] Apache Struts CVE-2016-3087 Remote Code Execution Vulnerability
15981| [90921] Apache Qpid CVE-2016-4432 Authentication Bypass Vulnerability
15982| [90920] Apache Qpid CVE-2016-3094 Denial of Service Vulnerability
15983| [90902] Apache PDFBox CVE-2016-2175 XML External Entity Injection Vulnerability
15984| [90897] Apache Tika CVE-2016-4434 XML External Entity Injection Vulnerability
15985| [90827] Apache ActiveMQ CVE-2016-3088 Multiple Arbitrary File Upload Vulnerabilities
15986| [90755] Apache Ambari CVE-2016-0707 Multiple Local Information Disclosure Vulnerabilities
15987| [90482] Apache CVE-2004-1387 Local Security Vulnerability
15988| [89762] Apache CVE-2001-1556 Remote Security Vulnerability
15989| [89417] Apache Subversion CVE-2016-2167 Authentication Bypass Vulnerability
15990| [89326] RETIRED: Apache Subversion CVE-2016-2167 Security Bypass Vulnerability
15991| [89320] Apache Subversion CVE-2016-2168 Remote Denial of Service Vulnerability
15992| [88826] Apache Struts CVE-2016-3082 Remote Code Execution Vulnerability
15993| [88797] Apache Cordova For iOS CVE-2015-5208 Arbitrary Code Execution Vulnerability
15994| [88764] Apache Cordova iOS CVE-2015-5207 Multiple Security Bypass Vulnerabilities
15995| [88701] Apache CVE-2001-1449 Remote Security Vulnerability
15996| [88635] Apache CVE-2000-1204 Remote Security Vulnerability
15997| [88590] Apache WWW server CVE-1999-1199 Denial-Of-Service Vulnerability
15998| [88496] Apache CVE-2000-1206 Remote Security Vulnerability
15999| [87828] Apache CVE-1999-1237 Remote Security Vulnerability
16000| [87784] Apache CVE-1999-1293 Denial-Of-Service Vulnerability
16001| [87327] Apache Struts CVE-2016-3081 Remote Code Execution Vulnerability
16002| [86622] Apache Stats CVE-2007-0975 Remote Security Vulnerability
16003| [86399] Apache CVE-2007-1743 Local Security Vulnerability
16004| [86397] Apache CVE-2007-1742 Local Security Vulnerability
16005| [86311] Apache Struts CVE-2016-4003 Cross Site Scripting Vulnerability
16006| [86174] Apache Wicket CVE-2015-5347 Cross Site Scripting Vulnerability
16007| [85971] Apache OFBiz CVE-2016-2170 Java Deserialization Remote Code Execution Vulnerability
16008| [85967] Apache OFBiz CVE-2015-3268 HTML Injection Vulnerability
16009| [85759] Apache Jetspeed CVE-2016-2171 Unauthorized Access Vulnerability
16010| [85758] Apache Jetspeed CVE-2016-0712 Cross Site Scripting Vulnerability
16011| [85756] Apache Jetspeed CVE-2016-0710 Multiple SQL Injection Vulnerabilities
16012| [85755] Apache Jetspeed CVE-2016-0711 Mulitple HTML Injection Vulnerabilities
16013| [85754] Apache Jetspeed CVE-2016-0709 Directory Traversal Vulnerability
16014| [85730] Apache Subversion CVE-2015-5343 Integer Overflow Vulnerability
16015| [85691] Apache Ranger CVE-2016-0735 Security Bypass Vulnerability
16016| [85578] Apache ActiveMQ CVE-2010-1244 Cross-Site Request Forgery Vulnerability
16017| [85554] Apache OpenMeetings CVE-2016-2164 Multiple Information Disclosure Vulnerabilities
16018| [85553] Apache OpenMeetings CVE-2016-0783 Information Disclosure Vulnerability
16019| [85552] Apache OpenMeetings CVE-2016-2163 HTML Injection Vulnerability
16020| [85550] Apache OpenMeetings CVE-2016-0784 Directory Traversal Vulnerability
16021| [85386] Apache Hadoop CVE-2015-7430 Local Privilege Escalation Vulnerability
16022| [85377] Apache Qpid Proton Python API CVE-2016-2166 Man in the Middle Security Bypass Vulnerability
16023| [85205] Apache Solr CVE-2015-8796 Cross Site Scripting Vulnerability
16024| [85203] Apache Solr CVE-2015-8795 Mulitple HTML Injection Vulnerabilities
16025| [85163] Apache Geronimo CVE-2008-0732 Local Security Vulnerability
16026| [85131] Apache Struts 'TextParseUtil.translateVariables()' Method Remote Code Execution Vulnerability
16027| [85070] Apache Struts CVE-2016-2162 Cross Site Scripting Vulnerability
16028| [85066] Apache Struts CVE-2016-0785 Remote Code Execution Vulnerability
16029| [84422] Apache TomEE CVE-2016-0779 Unspecified Security Vulnerability
16030| [84321] Apache ActiveMQ CVE-2016-0734 Clickjacking Vulnerability
16031| [84316] Apache ActiveMQ CVE-2016-0782 Multiple Cross Site Scripting Vulnerabilities
16032| [83910] Apache Wicket CVE-2015-7520 Cross Site Scripting Vulnerability
16033| [83423] Apache Xerces-C CVE-2016-0729 Buffer Overflow Vulnerability
16034| [83330] Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability
16035| [83329] Apache Tomcat CVE-2015-5174 Directory Traversal Vulnerability
16036| [83328] Apache Tomcat CVE-2015-5345 Directory Traversal Vulnerability
16037| [83327] Apache Tomcat Security Manager CVE-2016-0714 Remote Code Execution Vulnerability
16038| [83326] Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
16039| [83324] Apache Tomcat Security Manager CVE-2016-0706 Information Disclosure Vulnerability
16040| [83323] Apache Tomcat CVE-2015-5346 Session Fixation Vulnerability
16041| [83259] Apache Hadoop CVE-2015-1776 Information Disclosure Vulnerability
16042| [83243] Apache Solr CVE-2015-8797 Cross Site Scripting Vulnerability
16043| [83119] Apache Sling CVE-2016-0956 Information Disclosure Vulnerability
16044| [83002] Apache CVE-2000-1205 Cross-Site Scripting Vulnerability
16045| [82871] Apache Ranger Authentication Bypass and Security Bypass Vulnerabilities
16046| [82800] Apache CloudStack CVE-2015-3251 Information Disclosure Vulnerability
16047| [82798] Apache CloudStack CVE-2015-3252 Authentication Bypass Vulnerability
16048| [82732] Apache Gallery CVE-2003-0771 Local Security Vulnerability
16049| [82676] Apache CVE-2003-1581 Cross-Site Scripting Vulnerability
16050| [82550] Apache Struts CVE-2015-5209 Security Bypass Vulnerability
16051| [82300] Apache Subversion CVE-2015-5259 Integer Overflow Vulnerability
16052| [82260] Apache Camel CVE-2015-5344 Remote Code Execution Vulnerability
16053| [82234] Apache Hive CVE-2015-7521 Security Bypass Vulnerability
16054| [82082] Apache CVE-1999-0289 Remote Security Vulnerability
16055| [81821] Apache Distribution for Solaris CVE-2007-2080 SQL-Injection Vulnerability
16056| [80696] Apache Camel CVE-2015-5348 Information Disclosure Vulnerability
16057| [80525] Apache CVE-2003-1580 Remote Security Vulnerability
16058| [80354] Drupal Apache Solr Search Module Access Bypass Vulnerability
16059| [80193] Apache CVE-1999-0107 Denial-Of-Service Vulnerability
16060| [79812] Apache Directory Studio CVE-2015-5349 Command Injection Vulnerability
16061| [79744] Apache HBase CVE-2015-1836 Unauthorized Access Vulnerability
16062| [79204] Apache TomEE 'EjbObjectInputStream' Remote Code Execution Vulnerability
16063| [77679] Apache Cordova For Android CVE-2015-8320 Weak Randomization Security Bypass Vulnerability
16064| [77677] Apache Cordova For Android CVE-2015-5256 Security Bypass Vulnerability
16065| [77591] Apache CXF SAML SSO Processing CVE-2015-5253 Security Bypass Vulnerability
16066| [77521] Apache Commons Collections 'InvokerTransformer.java' Remote Code Execution Vulnerability
16067| [77110] Apache HttpComponents HttpClient CVE-2015-5262 Denial of Service Vulnerability
16068| [77086] Apache Ambari CVE-2015-1775 Server Side Request Forgery Security Bypass Vulnerability
16069| [77085] Apache Ambari CVE-2015-3270 Remote Privilege Escalation Vulnerability
16070| [77082] Apache Ambari 'targetURI' Parameter Open Redirection Vulnerability
16071| [77059] Apache Ambari CVE-2015-3186 Cross Site Scripting Vulnerability
16072| [76933] Apache James Server Unspecified Command Execution Vulnerability
16073| [76832] Apache cordova-plugin-file-transfer CVE-2015-5204 HTTP Header Injection Vulnerability
16074| [76625] Apache Struts CVE-2015-5169 Cross Site Scripting Vulnerability
16075| [76624] Apache Struts CVE-2015-2992 Cross Site Scripting Vulnerability
16076| [76522] Apache Tapestry CVE-2014-1972 Security Bypass Vulnerability
16077| [76486] Apache CXF Fediz CVE-2015-5175 Denial of Service Vulnerability
16078| [76452] Apache ActiveMQ CVE-2015-1830 Directory Traversal Vulnerability
16079| [76446] Apache Subversion 'libsvn_fs_fs/tree.c' Denial of Service Vulnerability
16080| [76274] Apache Subversion CVE-2015-3184 Information Disclosure Vulnerability
16081| [76273] Apache Subversion CVE-2015-3187 Information Disclosure Vulnerability
16082| [76272] Apache ActiveMQ CVE-2014-3576 Denial of Service Vulnerability
16083| [76221] Apache Ranger CVE-2015-0266 Access Bypass Vulnerability
16084| [76208] Apache Ranger CVE-2015-0265 JavaScript Code Injection Vulnerability
16085| [76025] Apache ActiveMQ Artemis CVE-2015-3208 XML External Entity Information Disclosure Vulnerability
16086| [75965] Apache HTTP Server CVE-2015-3185 Security Bypass Vulnerability
16087| [75964] Apache HTTP Server CVE-2015-0253 Remote Denial of Service Vulnerability
16088| [75963] Apache HTTP Server CVE-2015-3183 Security Vulnerability
16089| [75940] Apache Struts CVE-2015-1831 Security Bypass Vulnerability
16090| [75919] Apache Groovy CVE-2015-3253 Remote Code Execution Vulnerability
16091| [75338] Apache Storm CVE-2015-3188 Remote Code Execution Vulnerability
16092| [75275] Drupal Apache Solr Real-Time Module Access Bypass Vulnerability
16093| [74866] Apache Cordova For Android CVE-2015-1835 Security Bypass Vulnerability
16094| [74839] Apache Sling API and Sling Servlets CVE-2015-2944 Cross Site Scripting Vulnerability
16095| [74761] Apache Jackrabbit CVE-2015-1833 XML External Entity Information Disclosure Vulnerability
16096| [74686] Apache Ambari '/var/lib/ambari-server/ambari-env.sh' Local Privilege Escalation Vulnerability
16097| [74665] Apache Tomcat CVE-2014-7810 Security Bypass Vulnerability
16098| [74475] Apache Tomcat CVE-2014-0230 Denial of Service Vulnerability
16099| [74423] Apache Struts CVE-2015-0899 Security Bypass Vulnerability
16100| [74338] Apache OpenOffice HWP Filter Memory Corruption Vulnerability
16101| [74265] Apache Tomcat 'mod_jk' CVE-2014-8111 Information Disclosure Vulnerability
16102| [74260] Apache Subversion CVE-2015-0248 Multiple Denial of Service Vulnerabilities
16103| [74259] Apache Subversion 'deadprops.c' Security Bypass Vulnerability
16104| [74204] PHP 'sapi/apache2handler/sapi_apache2.c' Remote Code Execution Vulnerability
16105| [74158] Apache HTTP Server 'protocol.c' Remote Denial of Service Vulnerability
16106| [73954] Apache Flex 'asdoc/templates/index.html' Cross Site Scripting Vulnerability
16107| [73851] Apache2 CVE-2012-0216 Cross-Site Scripting Vulnerability
16108| [73478] Apache Cassandra CVE-2015-0225 Remote Code Execution Vulnerability
16109| [73041] Apache HTTP Server 'mod_lua' Module Denial of Service Vulnerability
16110| [73040] Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
16111| [72809] Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
16112| [72717] Apache Tomcat CVE-2014-0227 Chunk Request Remote Denial Of Service Vulnerability
16113| [72557] Apache WSS4J CVE-2015-0227 Security Bypass Vulnerability
16114| [72553] Apache WSS4J CVE-2015-0226 Information Disclosure Vulnerability
16115| [72513] Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
16116| [72511] Apache ActiveMQ CVE-2014-8110 Multiple Cross Site Scripting Vulnerabilities
16117| [72510] Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
16118| [72508] Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
16119| [72319] Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
16120| [72317] Apache Qpid CVE-2015-0224 Incomplete Fix Multiple Denial of Service Vulnerabilities
16121| [72115] Apache Santuario 'XML Signature Verification' Security Bypass Vulnerability
16122| [72053] Apache HTTP Server 'mod_remoteip.c' IP Address Spoofing Vulnerability
16123| [72030] Apache Qpid CVE-2015-0203 Multiple Denial of Service Vulnerabilities
16124| [71879] Apache Traffic Server 'HttpTransact.cc' Denial of Service Vulnerability
16125| [71726] Apache Subversion CVE-2014-3580 Remote Denial of Service Vulnerability
16126| [71725] Apache Subversion CVE-2014-8108 Remote Denial of Service Vulnerability
16127| [71657] Apache HTTP Server 'mod_proxy_fcgi' Module Denial of Service Vulnerability
16128| [71656] Apache HTTP Server 'mod_cache' Module Denial of Service Vulnerability
16129| [71548] Apache Struts CVE-2014-7809 Security Bypass Vulnerability
16130| [71466] Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
16131| [71353] Apache HTTP Server 'LuaAuthzProvider' Authorization Bypass Vulnerability
16132| [71004] Apache Qpid CVE-2014-3629 XML External Entity Injection Vulnerability
16133| [70970] Apache Traffic Server Cross Site Scripting Vulnerability
16134| [70738] Apache CXF CVE-2014-3584 Denial of Service Vulnerability
16135| [70736] Apache CXF SAML SubjectConfirmation Security Bypass Vulnerability
16136| [69728] Apache Tomcat CVE-2013-4444 Arbitrary File Upload Vulnerability
16137| [69648] Apache POI CVE-2014-3574 Denial Of Service Vulnerability
16138| [69647] Apache POI OpenXML parser CVE-2014-3529 XML External Entity Information Disclosure Vulnerability
16139| [69351] Apache OpenOffice Calc CVE-2014-3524 Command Injection Vulnerability
16140| [69295] Apache Axis Incomplete Fix CVE-2014-3596 SSL Certificate Validation Security Bypass Vulnerability
16141| [69286] Apache OFBiz CVE-2014-0232 Multiple Cross Site Scripting Vulnerabilities
16142| [69258] Apache HttpComponents Incomplete Fix CVE-2014-3577 SSL Validation Security Bypass Vulnerability
16143| [69257] Apache HttpComponents Incomplete Fix SSL Certificate Validation Security Bypass Vulnerability
16144| [69248] Apache HTTP Server CVE-2013-4352 Remote Denial of Service Vulnerability
16145| [69237] Apache Subversion CVE-2014-3522 SSL Certificate Validation Information Disclosure Vulnerability
16146| [69173] Apache Traffic Server CVE-2014-3525 Unspecified Security Vulnerability
16147| [69046] Apache Cordova For Android CVE-2014-3502 Information Disclosure Vulnerability
16148| [69041] Apache Cordova For Android CVE-2014-3501 Security Bypass Vulnerability
16149| [69038] Apache Cordova For Android CVE-2014-3500 Security Bypass Vulnerability
16150| [68995] Apache Subversion CVE-2014-3528 Insecure Authentication Weakness
16151| [68966] Apache Subversion 'irkerbridge.py' Local Privilege Escalation Vulnerability
16152| [68965] Apache Subversion 'svnwcsub.py' Local Privilege Escalation Vulnerability
16153| [68863] Apache HTTP Server 'mod_cache' Module Remote Denial of Service Vulnerability
16154| [68747] Apache HTTP Server CVE-2014-3523 Remote Denial of Service Vulnerability
16155| [68745] Apache HTTP Server CVE-2014-0118 Remote Denial of Service Vulnerability
16156| [68742] Apache HTTP Server CVE-2014-0231 Remote Denial of Service Vulnerability
16157| [68740] Apache HTTP Server CVE-2014-0117 Remote Denial of Service Vulnerability
16158| [68678] Apache HTTP Server 'mod_status' CVE-2014-0226 Remote Code Execution Vulnerability
16159| [68445] Apache CXF UsernameToken Information Disclosure Vulnerability
16160| [68441] Apache CXF SAML Tokens Validation Security Bypass Vulnerability
16161| [68431] Apache Syncope CVE-2014-3503 Insecure Password Generation Weakness
16162| [68229] Apache Harmony PRNG Entropy Weakness
16163| [68111] Apache 'mod_wsgi' Module Privilege Escalation Vulnerability
16164| [68072] Apache Tomcat CVE-2014-0186 Remote Denial of Service Vulnerability
16165| [68039] Apache Hive CVE-2014-0228 Security Bypass Vulnerability
16166| [67673] Apache Tomcat CVE-2014-0095 AJP Request Remote Denial Of Service Vulnerability
16167| [67671] Apache Tomcat CVE-2014-0075 Chunk Request Remote Denial Of Service Vulnerability
16168| [67669] Apache Tomcat CVE-2014-0119 XML External Entity Information Disclosure Vulnerability
16169| [67668] Apache Tomcat CVE-2014-0099 Request Processing Information Disclosure Vulnerability
16170| [67667] Apache Tomcat CVE-2014-0096 XML External Entity Information Disclosure Vulnerability
16171| [67534] Apache 'mod_wsgi' Module CVE-2014-0242 Information Disclosure Vulnerability
16172| [67532] Apache 'mod_wsgi' Module Local Privilege Escalation Vulnerability
16173| [67530] Apache Solr Search Template Cross Site Scripting Vulnerability
16174| [67236] Apache CXF CVE-2014-0109 Remote Denial of Service Vulnerability
16175| [67232] Apache CXF CVE-2014-0110 Denial of Service Vulnerability
16176| [67121] Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
16177| [67081] Apache Struts 'getClass()' Method Security Bypass Vulnerability
16178| [67064] Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
16179| [67013] Apache Zookeeper CVE-2014-0085 Local Information Disclosure Vulnerability
16180| [66998] Apache Archiva CVE-2013-2187 Unspecified Cross Site Scripting Vulnerability
16181| [66991] Apache Archiva CVE-2013-2187 HTML Injection Vulnerability
16182| [66927] Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
16183| [66474] Apache CouchDB Universally Unique IDentifier (UUID) Remote Denial of Service Vulnerability
16184| [66397] Apache Xalan-Java Library CVE-2014-0107 Security Bypass Vulnerability
16185| [66303] Apache HTTP Server Multiple Denial of Service Vulnerabilities
16186| [66041] RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
16187| [65999] Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability
16188| [65967] Apache Cordova File-Transfer Unspecified Security Vulnerability
16189| [65959] Apache Cordova InAppBrowser Remote Privilege Escalation Vulnerability
16190| [65935] Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
16191| [65902] Apache Camel CVE-2014-0003 Remote Code Execution Vulnerability
16192| [65901] Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
16193| [65773] Apache Tomcat CVE-2013-4286 Security Bypass Vulnerability
16194| [65769] Apache Tomcat CVE-2014-0033 Session Fixation Vulnerability
16195| [65768] Apache Tomcat CVE-2013-4590 XML External Entity Information Disclosure Vulnerability
16196| [65767] Apache Tomcat CVE-2013-4322 Incomplete Fix Denial of Service Vulnerability
16197| [65615] Apache ActiveMQ 'refresh' Parameter Cross Site Scripting Vulnerability
16198| [65434] Apache Subversion 'mod_dav_svn' Module SVNListParentPath Denial of Service Vulnerability
16199| [65431] Apache Wicket CVE-2013-2055 Information Disclosure Vulnerability
16200| [65400] Apache Commons FileUpload CVE-2014-0050 Denial Of Service Vulnerability
16201| [64782] Apache CloudStack Virtual Router Component Security Bypass Vulnerability
16202| [64780] Apache CloudStack Unauthorized Access Vulnerability
16203| [64617] Apache Libcloud Digital Ocean API Local Information Disclosure Vulnerability
16204| [64437] Apache Santuario XML Security For JAVA XML Signature Denial of Service Vulnerability
16205| [64427] Apache Solr Multiple XML External Entity Injection Vulnerabilities
16206| [64009] Apache Solr CVE-2013-6408 XML External Entity Injection Vulnerability
16207| [64008] Apache Solr CVE-2013-6407 XML External Entity Injection Vulnerability
16208| [63981] Apache Subversion 'mod_dav_svn' Module Denial of Service Vulnerability
16209| [63966] Apache Subversion CVE-2013-4505 Security Bypass Vulnerability
16210| [63963] Apache Roller CVE-2013-4171 Cross Site Scripting Vulnerability
16211| [63935] Apache Solr 'SolrResourceLoader' Directory Traversal Vulnerability
16212| [63928] Apache Roller CVE-2013-4212 OGNL Expression Injection Remote Code Execution Vulnerability
16213| [63515] Apache Tomcat Manager Component CVE-2013-6357 Cross Site Request Forgery Vulnerability
16214| [63403] Apache Struts Multiple Cross Site Scripting Vulnerabilities
16215| [63400] Apache 'mod_pagespeed' Module Unspecified Cross Site Scripting Vulnerability
16216| [63260] Apache Shindig CVE-2013-4295 XML External Entity Information Disclosure Vulnerability
16217| [63241] Apache Sling 'AbstractAuthenticationFormServlet' Open Redirection Vulnerability
16218| [63174] Apache Commons FileUpload 'DiskFileItem' Class Null Byte Arbitrary File Write Vulnerability
16219| [62939] Apache 'mod_fcgid' Module CVE-2013-4365 Heap Buffer Overflow Vulnerability
16220| [62903] Apache Sling 'deepGetOrCreateNode()' Function Denial Of Service Vulnerability
16221| [62706] Apache Camel CVE-2013-4330 Information Disclosure Vulnerability
16222| [62677] Apache 'mod_accounting' Module CVE-2013-5697 SQL Injection Vulnerability
16223| [62674] TYPO3 Apache Solr Unspecified Cross Site Scripting and PHP Code Execution Vulnerabilities
16224| [62587] Apache Struts CVE-2013-4316 Remote Code Execution Vulnerability
16225| [62584] Apache Struts CVE-2013-4310 Security Bypass Vulnerability
16226| [62266] Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
16227| [61984] Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
16228| [61981] Apache HBase RPC Authentication Man In The Middle Security Bypass Vulnerability
16229| [61638] Apache CloudStack CVE-2013-2136 Multiple Cross Site Scripting Vulnerabilities
16230| [61454] Apache Subversion CVE-2013-4131 Denial Of Service Vulnerability
16231| [61379] Apache HTTP Server CVE-2013-2249 Unspecified Remote Security Vulnerability
16232| [61370] Apache OFBiz CVE-2013-2317 'View Log' Cross Site Scripting Vulnerability
16233| [61369] Apache OFBiz Nested Expression Remote Code Execution Vulnerability
16234| [61196] Apache Struts CVE-2013-2248 Multiple Open Redirection Vulnerabilities
16235| [61189] Apache Struts CVE-2013-2251 Multiple Remote Command Execution Vulnerabilities
16236| [61129] Apache HTTP Server CVE-2013-1896 Remote Denial of Service Vulnerability
16237| [61030] Apache CXF CVE-2013-2160 Multiple Remote Denial of Service Vulnerabilities
16238| [60875] Apache Geronimo RMI Classloader Security Bypass Vulnerability
16239| [60846] Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
16240| [60817] Apache Santuario XML Security for C++ CVE-2013-2210 Heap Buffer Overflow Vulnerability
16241| [60800] Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
16242| [60599] Apache Santuario XML Security for C++ CVE-2013-2156 Remote Heap Buffer Overflow Vulnerability
16243| [60595] Apache Santuario XML Security for C++ XML Signature CVE-2013-2155 Denial of Service Vulnerability
16244| [60594] Apache Santuario XML Security for C++ CVE-2013-2154 Stack Buffer Overflow Vulnerability
16245| [60592] Apache Santuario XML Security for C++ XML Signature CVE-2013-2153 Security Bypass Vulnerability
16246| [60534] Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
16247| [60346] Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
16248| [60345] Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
16249| [60267] Apache Subversion CVE-2013-1968 Remote Denial of Service Vulnerability
16250| [60265] Apache Subversion CVE-2013-2088 Command Injection Vulnerability
16251| [60264] Apache Subversion CVE-2013-2112 Remote Denial of Service Vulnerability
16252| [60187] Apache Tomcat DIGEST Authentication CVE-2013-2051 Incomplete Fix Security Weakness
16253| [60186] Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
16254| [60167] Apache Struts 'includeParams' CVE-2013-2115 Incomplete Fix Security Bypass Vulnerability
16255| [60166] Apache Struts 'includeParams' CVE-2013-1966 Security Bypass Vulnerability
16256| [60082] Apache Struts 'ParameterInterceptor' Class OGNL CVE-2013-1965 Security Bypass Vulnerability
16257| [59826] Apache HTTP Server Terminal Escape Sequence in Logs Command Injection Vulnerability
16258| [59799] Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
16259| [59798] Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
16260| [59797] Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
16261| [59670] Apache VCL Multiple Input Validation Vulnerabilities
16262| [59464] Apache CloudStack CVE-2013-2758 Hash Information Disclosure Vulnerability
16263| [59463] Apache CloudStack CVE-2013-2756 Authentication Bypass Vulnerability
16264| [59402] Apache ActiveMQ CVE-2013-3060 Information Disclosure and Denial of Service Vulnerability
16265| [59401] Apache ActiveMQ CVE-2012-6551 Denial of Service Vulnerability
16266| [59400] Apache ActiveMQ CVE-2012-6092 Multiple Cross Site Scripting Vulnerabilities
16267| [58898] Apache Subversion CVE-2013-1884 Remote Denial of Service Vulnerability
16268| [58897] Apache Subversion 'mod_dav_svn/lock.c' Remote Denial of Service Vulnerability
16269| [58895] Apache Subversion 'mod_dav_svn' Remote Denial of Service Vulnerability
16270| [58455] Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
16271| [58379] Apache Qpid CVE-2012-4446 Authentication Bypass Vulnerability
16272| [58378] Apache Qpid CVE-2012-4460 Denial of Service Vulnerability
16273| [58376] Apache Qpid CVE-2012-4458 Denial of Service Vulnerability
16274| [58337] Apache Qpid CVE-2012-4459 Denial of Service Vulnerability
16275| [58326] Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
16276| [58325] Debian Apache HTTP Server CVE-2013-1048 Symlink Attack Local Privilege Escalation Vulnerability
16277| [58323] Apache Subversion 'svn_fs_file_length()' Remote Denial of Service Vulnerability
16278| [58165] Apache HTTP Server Multiple Cross Site Scripting Vulnerabilities
16279| [58136] Apache Maven CVE-2013-0253 SSL Certificate Validation Security Bypass Vulnerability
16280| [58124] Apache Tomcat 'log/logdir' Directory Insecure File Permissions Vulnerability
16281| [58073] Apache Commons HttpClient CVE-2012-5783 SSL Certificate Validation Security Bypass Vulnerability
16282| [57876] Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
16283| [57874] Apache CXF CVE-2012-5633 Security Bypass Vulnerability
16284| [57463] Apache OFBiz CVE-2013-0177 Multiple Cross Site Scripting Vulnerabilities
16285| [57425] Apache CXF CVE-2012-5786 SSL Certificate Validation Security Bypass Vulnerability
16286| [57321] Apache CouchDB CVE-2012-5650 Cross Site Scripting Vulnerability
16287| [57314] Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
16288| [57267] Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
16289| [57259] Apache CloudStack CVE-2012-5616 Local Information Disclosure Vulnerability
16290| [56814] Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
16291| [56813] Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
16292| [56812] Apache Tomcat CVE-2012-3546 Security Bypass Vulnerability
16293| [56753] Apache Apache HTTP Server 'mod_proxy_ajp Module Denial Of Service Vulnerability
16294| [56686] Apache Tomcat CVE-2012-5568 Denial of Service Vulnerability
16295| [56408] Apache Axis and Axis2/Java SSL Certificate Validation Security Bypass Vulnerability
16296| [56403] Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
16297| [56402] Apache Tomcat CVE-2012-2733 Denial of Service Vulnerability
16298| [56171] Apache OFBiz CVE-2012-3506 Unspecified Security Vulnerability
16299| [55876] Apache CloudStack CVE-2012-4501 Security Bypass Vulnerability
16300| [55628] Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
16301| [55608] Apache Qpid (qpidd) Denial of Service Vulnerability
16302| [55536] Apache 'mod_pagespeed' Module Cross Site Scripting and Security Bypass Vulnerabilities
16303| [55508] Apache Axis2 XML Signature Wrapping Security Vulnerability
16304| [55445] Apache Wicket CVE-2012-3373 Cross Site Scripting Vulnerability
16305| [55346] Apache Struts Cross Site Request Forgery and Denial of Service Vulnerabilities
16306| [55290] Drupal Apache Solr Autocomplete Module Cross Site Scripting Vulnerability
16307| [55165] Apache Struts2 Skill Name Remote Code Execution Vulnerability
16308| [55154] Apache 'mod-rpaf' Module Denial of Service Vulnerability
16309| [55131] Apache HTTP Server HTML-Injection And Information Disclosure Vulnerabilities
16310| [54954] Apache QPID NullAuthenticator Authentication Bypass Vulnerability
16311| [54798] Apache Libcloud Man In The Middle Vulnerability
16312| [54358] Apache Hadoop CVE-2012-3376 Information Disclosure Vulnerability
16313| [54341] Apache Sling CVE-2012-2138 Denial Of Service Vulnerability
16314| [54268] Apache Hadoop Symlink Attack Local Privilege Escalation Vulnerability
16315| [54189] Apache Roller Cross Site Request Forgery Vulnerability
16316| [54187] Apache Roller CVE-2012-2381 Cross Site Scripting Vulnerability
16317| [53880] Apache CXF Child Policies Security Bypass Vulnerability
16318| [53877] Apache CXF Elements Validation Security Bypass Vulnerability
16319| [53676] Apache Commons Compress and Apache Ant CVE-2012-2098 Denial Of Service Vulnerability
16320| [53487] Apache POI CVE-2012-0213 Denial Of Service Vulnerability
16321| [53455] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability
16322| [53305] Apache Qpid CVE-2011-3620 Unauthorized Access Security Bypass Vulnerability
16323| [53046] Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
16324| [53025] Apache OFBiz Unspecified Remote Code Execution Vulnerability
16325| [53023] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
16326| [52939] Apache Hadoop CVE-2012-1574 Unspecified User Impersonation Vulnerability
16327| [52702] Apache Struts2 'XSLTResult.java' Remote Arbitrary File Upload Vulnerability
16328| [52696] Apache Traffic Server HTTP Host Header Handling Heap Based Buffer Overflow Vulnerability
16329| [52680] Apache Wicket 'pageMapName' Parameter Cross Site Scripting Vulnerability
16330| [52679] Apache Wicket Hidden Files Information Disclosure Vulnerability
16331| [52565] Apache 'mod_fcgid' Module Denial Of Service Vulnerability
16332| [52146] TYPO3 Apache Solr Extension Unspecified Cross Site Scripting Vulnerability
16333| [51939] Apache MyFaces 'ln' Parameter Information Disclosure Vulnerability
16334| [51917] Apache APR Hash Collision Denial Of Service Vulnerability
16335| [51902] Apache Struts Multiple HTML Injection Vulnerabilities
16336| [51900] Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
16337| [51886] Apache CXF UsernameToken Policy Validation Security Bypass Vulnerability
16338| [51869] Apache HTTP Server CVE-2011-3639 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
16339| [51706] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
16340| [51705] Apache HTTP Server CVE-2012-0021 mod_log_config Denial Of Service Vulnerability
16341| [51628] Apache Struts 'ParameterInterceptor' Class OGNL (CVE-2011-3923) Security Bypass Vulnerability
16342| [51447] Apache Tomcat Parameter Handling Denial of Service Vulnerability
16343| [51442] Apache Tomcat Request Object Security Bypass Vulnerability
16344| [51407] Apache HTTP Server Scoreboard Local Security Bypass Vulnerability
16345| [51257] Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
16346| [51238] Apache Geronimo Hash Collision Denial Of Service Vulnerability
16347| [51200] Apache Tomcat Hash Collision Denial Of Service Vulnerability
16348| [50940] Apache Struts Session Tampering Security Bypass Vulnerability
16349| [50912] RETIRED: Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
16350| [50904] Apache ActiveMQ Failover Mechanism Remote Denial Of Service Vulnerability
16351| [50848] Apache MyFaces EL Expression Evaluation Security Bypass Vulnerability
16352| [50802] Apache HTTP Server 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
16353| [50639] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
16354| [50603] Apache Tomcat Manager Application Security Bypass Vulnerability
16355| [50494] Apache HTTP Server 'ap_pregsub()' Function Local Privilege Escalation Vulnerability
16356| [49957] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
16357| [49762] Apache Tomcat HTTP DIGEST Authentication Multiple Security Weaknesses
16358| [49728] Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
16359| [49616] Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
16360| [49470] Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
16361| [49353] Apache Tomcat AJP Protocol Security Bypass Vulnerability
16362| [49303] Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability
16363| [49290] Apache Wicket Cross Site Scripting Vulnerability
16364| [49147] Apache Tomcat CVE-2011-2481 Information Disclosure Vulnerability
16365| [49143] Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
16366| [48667] Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability
16367| [48653] Apache 'mod_authnz_external' Module SQL Injection Vulnerability
16368| [48611] Apache XML Security for C++ Signature Key Parsing Denial of Service Vulnerability
16369| [48456] Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability
16370| [48015] Apache Archiva Multiple Cross Site Request Forgery Vulnerabilities
16371| [48011] Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
16372| [47929] Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
16373| [47890] Apache Struts 'javatemplates' Plugin Multiple Cross Site Scripting Vulnerabilities
16374| [47886] Apache Tomcat SecurityConstraints Security Bypass Vulnerability
16375| [47820] Apache APR 'apr_fnmatch()' Denial of Service Vulnerability
16376| [47784] Apache Struts XWork 's:submit' HTML Tag Cross Site Scripting Vulnerability
16377| [47199] Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
16378| [47196] Apache Tomcat Login Constraints Security Bypass Vulnerability
16379| [46974] Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
16380| [46953] Apache MPM-ITK Module Security Weakness
16381| [46734] Subversion 'mod_dav_svn' Apache Server NULL Pointer Dereference Denial Of Service Vulnerability
16382| [46685] Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
16383| [46311] Apache Continuum and Archiva Cross Site Scripting Vulnerability
16384| [46177] Apache Tomcat SecurityManager Security Bypass Vulnerability
16385| [46174] Apache Tomcat HTML Manager Interface HTML Injection Vulnerability
16386| [46166] Apache Tomcat JVM Denial of Service Vulnerability
16387| [46164] Apache Tomcat NIO Connector Denial of Service Vulnerability
16388| [46066] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
16389| [45655] Apache Subversion Server Component Multiple Remote Denial Of Service Vulnerabilities
16390| [45123] Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Vulnerability
16391| [45095] Apache Archiva Cross Site Request Forgery Vulnerability
16392| [45015] Apache Tomcat 'sort' and 'orderBy' Parameters Cross Site Scripting Vulnerabilities
16393| [44900] Apache 'mod_fcgid' Module Unspecified Stack Buffer Overflow Vulnerability
16394| [44616] Apache Shiro Directory Traversal Vulnerability
16395| [44355] Apache MyFaces Encrypted View State Oracle Padding Security Vulnerability
16396| [44068] Apache::AuthenHook Local Information Disclosure Vulnerability
16397| [43862] Apache QPID SSL Connection Denial of Service Vulnerability
16398| [43673] Apache APR-util 'apr_brigade_split_line()' Denial of Service Vulnerability
16399| [43637] Apache XML-RPC SAX Parser Information Disclosure Vulnerability
16400| [43111] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
16401| [42637] Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
16402| [42501] Apache CouchDB Cross Site Request Forgery Vulnerability
16403| [42492] Apache CXF XML DTD Processing Security Vulnerability
16404| [42121] Apache SLMS Insufficient Quoting Cross Site Request Forgery Vulnerability
16405| [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
16406| [41963] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
16407| [41544] Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities
16408| [41076] Apache Axis2 '/axis2/axis2-admin' Session Fixation Vulnerability
16409| [40976] Apache Axis2 Document Type Declaration Processing Security Vulnerability
16410| [40827] Apache 'mod_proxy_http' Timeout Handling Information Disclosure Vulnerability
16411| [40343] Apache Axis2 'xsd' Parameter Directory Traversal Vulnerability
16412| [40327] Apache Axis2 'engagingglobally' Cross-Site Scripting Vulnerability
16413| [39771] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
16414| [39636] Apache ActiveMQ Source Code Information Disclosure Vulnerability
16415| [39635] Apache Tomcat Authentication Header Realm Name Information Disclosure Vulnerability
16416| [39538] Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
16417| [39489] Apache OFBiz Multiple Cross Site Scripting and HTML Injection Vulnerabilities
16418| [39119] Apache ActiveMQ 'createDestination.action' HTML Injection Vulnerability
16419| [38580] Apache Subrequest Handling Information Disclosure Vulnerability
16420| [38494] Apache 'mod_isapi' Memory Corruption Vulnerability
16421| [38491] Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
16422| [37966] Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability
16423| [37945] Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability
16424| [37944] Apache Tomcat WAR File Directory Traversal Vulnerability
16425| [37942] Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability
16426| [37149] Apache Tomcat 404 Error Page Cross Site Scripting Vulnerability
16427| [37027] RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
16428| [36990] Apache HTTP TRACE Cross Site Scripting Vulnerability
16429| [36954] Apache Tomcat Windows Installer Insecure Password Vulnerability
16430| [36889] TYPO3 Apache Solr Search Extension Unspecified Cross Site Scripting Vulnerability
16431| [36596] Apache HTTP Server Solaris Event Port Pollset Support Remote Denial Of Service Vulnerability
16432| [36260] Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
16433| [36254] Apache mod_proxy_ftp Remote Command Injection Vulnerability
16434| [35949] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
16435| [35840] Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
16436| [35623] Apache 'mod_deflate' Remote Denial Of Service Vulnerability
16437| [35565] Apache 'mod_proxy' Remote Denial Of Service Vulnerability
16438| [35416] Apache Tomcat XML Parser Information Disclosure Vulnerability
16439| [35263] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
16440| [35253] Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
16441| [35251] Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
16442| [35221] Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
16443| [35196] Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness
16444| [35193] Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability
16445| [35115] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
16446| [34686] Apache Struts Multiple Cross Site Scripting Vulnerabilities
16447| [34663] Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
16448| [34657] Apache Tiles Cross Site Scripting And Information Disclosure Vulnerabilities
16449| [34562] Apache Geronimo Application Server Multiple Remote Vulnerabilities
16450| [34552] Apache ActiveMQ Web Console Multiple Unspecified HTML Injection Vulnerabilities
16451| [34412] Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability
16452| [34399] Apache Struts Unspecified Cross Site Scripting Vulnerability
16453| [34383] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
16454| [33913] Apache Tomcat POST Data Information Disclosure Vulnerability
16455| [33360] Apache Jackrabbit 'q' Parameter Multiple Cross Site Scripting Vulnerabilities
16456| [33110] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
16457| [32657] Novell NetWare ApacheAdmin Security Bypass Vulnerability
16458| [31805] Apache HTTP Server OS Fingerprinting Unspecified Security Vulnerability
16459| [31761] Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
16460| [31698] Apache Tomcat 'RemoteFilterValve' Security Bypass Vulnerability
16461| [31165] Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
16462| [30560] Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability
16463| [30496] Apache Tomcat 'HttpServletResponse.sendError()' Cross Site Scripting Vulnerability
16464| [30494] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
16465| [29653] Apache 'mod_proxy_http' Interim Response Denial of Service Vulnerability
16466| [29502] Apache Tomcat Host Manager Cross Site Scripting Vulnerability
16467| [28576] Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
16468| [28484] Apache Tomcat Requests Containing MS-DOS Device Names Information Disclosure Vulnerability
16469| [28483] Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
16470| [28482] Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
16471| [28481] Apache Tomcat Cross-Site Scripting Vulnerability
16472| [28477] Apache Tomcat AJP Connector Information Disclosure Vulnerability
16473| [27752] Apache mod_jk2 Host Header Multiple Stack Based Buffer Overflow Vulnerabilities
16474| [27706] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
16475| [27703] Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
16476| [27409] Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
16477| [27365] Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
16478| [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
16479| [27236] Apache 'mod_proxy_balancer' Multiple Vulnerabilities
16480| [27234] Apache 'mod_proxy_ftp' Undefined Charset UTF-7 Cross-Site Scripting Vulnerability
16481| [27006] Apache Tomcat JULI Logging Component Default Security Policy Vulnerability
16482| [26939] Apache HTTP Server Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
16483| [26838] Apache mod_imagemap and mod_imap Cross-Site Scripting Vulnerability
16484| [26762] Apache::AuthCAS Cookie SQL Injection Vulnerability
16485| [26663] Apache HTTP Server 413 Error HTTP Request Method Cross-Site Scripting Weakness
16486| [26287] Apache Geronimo SQLLoginModule Authentication Bypass Vulnerability
16487| [26070] Apache Tomcat WebDav Remote Information Disclosure Vulnerability
16488| [25804] Apache Geronimo Management EJB Security Bypass Vulnerability
16489| [25653] Apache Mod_AutoIndex.C Undefined Charset Cross-Site Scripting Vulnerability
16490| [25531] Apache Tomcat Cal2.JSP Cross-Site Scripting Vulnerability
16491| [25489] Apache HTTP Server Mod_Proxy Denial of Service Vulnerability
16492| [25316] Apache Tomcat Multiple Remote Information Disclosure Vulnerabilities
16493| [25314] Apache Tomcat Host Manager Servlet Cross Site Scripting Vulnerability
16494| [25174] Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
16495| [24999] Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
16496| [24759] MySQLDumper Apache Access Control Authentication Bypass Vulnerability
16497| [24649] Apache HTTP Server Mod_Cache Denial of Service Vulnerability
16498| [24645] Apache HTTP Server Mod_Status Cross-Site Scripting Vulnerability
16499| [24553] Apache Mod_Mem_Cache Information Disclosure Vulnerability
16500| [24524] Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
16501| [24480] Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
16502| [24476] Apache Tomcat JSP Example Web Applications Cross Site Scripting Vulnerability
16503| [24475] Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
16504| [24215] Apache HTTP Server Worker Process Multiple Denial of Service Vulnerabilities
16505| [24147] Apache Tomcat JK Connector Double Encoding Security Bypass Vulnerability
16506| [24058] Apache Tomcat Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
16507| [23687] Apache AXIS Non-Existent WSDL Path Information Disclosure Vulnerability
16508| [23438] Apache HTTPD suEXEC Local Multiple Privilege Escalation Weaknesses
16509| [22960] Apache HTTP Server Tomcat Directory Traversal Vulnerability
16510| [22849] Apache mod_python Output Filter Mode Information Disclosure Vulnerability
16511| [22791] Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability
16512| [22732] Debian Apache Root Shell Local Privilege Escalation Vulnerabilities
16513| [22388] Apache Stats Extract Function Multiple Input Validation Vulnerabilities
16514| [21865] Apache And Microsoft IIS Range Denial of Service Vulnerability
16515| [21214] Apache Mod_Auth_Kerb Off-By-One Denial of Service Vulnerability
16516| [20527] Apache Mod_TCL Remote Format String Vulnerability
16517| [19661] Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
16518| [19447] Apache CGI Script Source Code Information Disclosure Vulnerability
16519| [19204] Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
16520| [19106] Apache Tomcat Information Disclosure Vulnerability
16521| [18138] Apache James SMTP Denial Of Service Vulnerability
16522| [17342] Apache Struts Multiple Remote Vulnerabilities
16523| [17095] Apache Log4Net Denial Of Service Vulnerability
16524| [16916] Apache mod_python FileSession Code Execution Vulnerability
16525| [16710] Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
16526| [16260] Apache Geronimo Multiple Input Validation Vulnerabilities
16527| [16153] Apache mod_auth_pgsql Multiple Format String Vulnerabilities
16528| [16152] Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
16529| [15834] Apache 'mod_imap' Referer Cross-Site Scripting Vulnerability
16530| [15765] Apache James Spooler Memory Leak Denial Of Service Vulnerability
16531| [15762] Apache MPM Worker.C Denial Of Service Vulnerability
16532| [15512] Apache Struts Error Response Cross-Site Scripting Vulnerability
16533| [15413] PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
16534| [15325] Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
16535| [15224] Apache Mod_Auth_Shadow Authentication Bypass Vulnerability
16536| [15177] PHP Apache 2 Local Denial of Service Vulnerability
16537| [14982] ApacheTop Insecure Temporary File Creation Vulnerability
16538| [14721] Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
16539| [14660] Apache CGI Byterange Request Denial of Service Vulnerability
16540| [14366] Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
16541| [14106] Apache HTTP Request Smuggling Vulnerability
16542| [13778] Apache HTPasswd Password Command Line Argument Buffer Overflow Vulnerability
16543| [13777] Apache HTPasswd User Command Line Argument Buffer Overflow Vulnerability
16544| [13756] Apache Tomcat Java Security Manager Bypass Vulnerability
16545| [13537] Apache HTDigest Realm Command Line Argument Buffer Overflow Vulnerability
16546| [12877] Apache mod_ssl ssl_io_filter_cleanup Remote Denial Of Service Vulnerability
16547| [12795] Apache Tomcat Remote Malformed Request Denial Of Service Vulnerability
16548| [12619] Apache Software Foundation Batik Squiggle Browser Access Validation Vulnerability
16549| [12519] Apache mod_python Module Publisher Handler Information Disclosure Vulnerability
16550| [12308] Apache Utilities Insecure Temporary File Creation Vulnerability
16551| [12217] Apache mod_auth_radius Malformed RADIUS Server Reply Integer Overflow Vulnerability
16552| [12181] Mod_DOSEvasive Apache Module Local Insecure Temporary File Creation Vulnerability
16553| [11803] Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
16554| [11471] Apache mod_include Local Buffer Overflow Vulnerability
16555| [11360] Apache mod_ssl SSLCipherSuite Restriction Bypass Vulnerability
16556| [11239] Apache Satisfy Directive Access Control Bypass Vulnerability
16557| [11187] Apache Web Server Remote IPv6 Buffer Overflow Vulnerability
16558| [11185] Apache Mod_DAV LOCK Denial Of Service Vulnerability
16559| [11182] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
16560| [11154] Apache mod_ssl Remote Denial of Service Vulnerability
16561| [11094] Apache mod_ssl Denial Of Service Vulnerability
16562| [10789] Apache mod_userdir Module Information Disclosure Vulnerability
16563| [10736] Apache 'mod_ssl' Log Function Format String Vulnerability
16564| [10619] Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
16565| [10508] Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow Vulnerability
16566| [10478] ClueCentral Apache Suexec Patch Security Weakness
16567| [10355] Apache 'mod_ssl' 'ssl_util_uuencode_binary()' Stack Buffer Overflow Vulnerability
16568| [10212] Apache mod_auth Malformed Password Potential Memory Corruption Vulnerability
16569| [9933] Apache mod_disk_cache Module Client Authentication Credential Storage Weakness
16570| [9930] Apache Error and Access Logs Escape Sequence Injection Vulnerability
16571| [9921] Apache Connection Blocking Denial Of Service Vulnerability
16572| [9885] Apache Mod_Security Module SecFilterScanPost Off-By-One Buffer Overflow Vulnerability
16573| [9874] Apache HTAccess LIMIT Directive Bypass Configuration Error Weakness
16574| [9829] Apache Mod_Access Access Control Rule Bypass Vulnerability
16575| [9826] Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
16576| [9733] Apache Cygwin Directory Traversal Vulnerability
16577| [9599] Apache mod_php Global Variables Information Disclosure Weakness
16578| [9590] Apache-SSL Client Certificate Forging Vulnerability
16579| [9571] Apache mod_digest Client-Supplied Nonce Verification Vulnerability
16580| [9471] Apache mod_perl Module File Descriptor Leakage Vulnerability
16581| [9404] Mod-Auth-Shadow Apache Module Expired User Credential Weakness
16582| [9302] Apache mod_php Module File Descriptor Leakage Vulnerability
16583| [9129] Apache mod_python Module Malformed Query Denial of Service Vulnerability
16584| [8926] Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
16585| [8919] Apache Mod_Security Module Heap Corruption Vulnerability
16586| [8911] Apache Web Server Multiple Module Local Buffer Overflow Vulnerability
16587| [8898] Red Hat Apache Directory Index Default Configuration Error
16588| [8883] Apache Cocoon Directory Traversal Vulnerability
16589| [8824] Apache Tomcat Non-HTTP Request Denial Of Service Vulnerability
16590| [8822] Apache Mod_Throttle Module Local Shared Memory Corruption Vulnerability
16591| [8725] Apache2 MOD_CGI STDERR Denial Of Service Vulnerability
16592| [8707] Apache htpasswd Password Entropy Weakness
16593| [8561] Apache::Gallery Insecure Local File Storage Privilege Escalation Vulnerability
16594| [8287] Mod_Mylo Apache Module REQSTR Buffer Overflow Vulnerability
16595| [8226] Apache HTTP Server Multiple Vulnerabilities
16596| [8138] Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
16597| [8137] Apache Web Server Prefork MPM Denial Of Service Vulnerability
16598| [8136] Macromedia Apache Web Server Encoded Space Source Disclosure Vulnerability
16599| [8135] Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
16600| [8134] Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness
16601| [7768] Apache Tomcat Insecure Directory Permissions Vulnerability
16602| [7725] Apache Basic Authentication Module Valid User Login Denial Of Service Vulnerability
16603| [7723] Apache APR_PSPrintf Memory Corruption Vulnerability
16604| [7448] Apache Mod_Auth_Any Remote Command Execution Vulnerability
16605| [7375] Apache Mod_Access_Referer NULL Pointer Dereference Denial of Service Vulnerability
16606| [7332] Apache Web Server OS2 Filestat Denial Of Service Vulnerability
16607| [7255] Apache Web Server File Descriptor Leakage Vulnerability
16608| [7254] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
16609| [6943] Apache Web Server MIME Boundary Information Disclosure Vulnerability
16610| [6939] Apache Web Server ETag Header Information Disclosure Weakness
16611| [6722] Apache Tomcat Web.XML File Contents Disclosure Vulnerability
16612| [6721] Apache Tomcat Null Byte Directory/File Disclosure Vulnerability
16613| [6720] Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
16614| [6662] Apache Web Server MS-DOS Device Name Denial Of Service Vulnerability
16615| [6661] Apache Web Server Default Script Mapping Bypass Vulnerability
16616| [6660] Apache Web Server Illegal Character HTTP Request File Disclosure Vulnerability
16617| [6659] Apache Web Server MS-DOS Device Name Arbitrary Code Execution Vulnerability
16618| [6562] Apache Tomcat Invoker Servlet File Disclosure Vulnerability
16619| [6320] Apache/Tomcat Mod_JK Chunked Encoding Denial Of Service Vulnerability
16620| [6117] Apache mod_php File Descriptor Leakage Vulnerability
16621| [6065] Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
16622| [5996] Apache AB.C Web Benchmarking Buffer Overflow Vulnerability
16623| [5995] Apache AB.C Web Benchmarking Read_Connection() Buffer Overflow Vulnerability
16624| [5993] Multiple Apache HTDigest Buffer Overflow Vulnerabilities
16625| [5992] Apache HTDigest Insecure Temporary File Vulnerability
16626| [5991] Apache HTDigest Arbitrary Command Execution Vulnerability
16627| [5990] Apache HTPasswd Insecure Temporary File Vulnerability
16628| [5981] Multiple Apache HTDigest and HTPassWD Component Vulnerabilites
16629| [5884] Apache Web Server Scoreboard Memory Segment Overwriting SIGUSR1 Sending Vulnerability
16630| [5847] Apache Server Side Include Cross Site Scripting Vulnerability
16631| [5838] Apache Tomcat 3.2 Directory Disclosure Vulnerability
16632| [5816] Apache 2 mod_dav Denial Of Service Vulnerability
16633| [5791] HP VirtualVault Apache mod_ssl Denial Of Service Vulnerability
16634| [5787] Apache Oversized STDERR Buffer Denial Of Service Vulnerability
16635| [5786] Apache Tomcat DefaultServlet File Disclosure Vulnerability
16636| [5542] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
16637| [5486] Apache 2.0 CGI Path Disclosure Vulnerability
16638| [5485] Apache 2.0 Path Disclosure Vulnerability
16639| [5434] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
16640| [5256] Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
16641| [5194] Apache Tomcat DOS Device Name Cross Site Scripting Vulnerability
16642| [5193] Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
16643| [5067] Apache Tomcat Null Character Malformed Request Denial Of Service Vulnerability
16644| [5054] Apache Tomcat Web Root Path Disclosure Vulnerability
16645| [5033] Apache Chunked-Encoding Memory Corruption Vulnerability
16646| [4995] Apache Tomcat JSP Engine Denial of Service Vulnerability
16647| [4878] Apache Tomcat RealPath.JSP Malformed Request Information Disclosure Vulnerability
16648| [4877] Apache Tomcat Example Files Web Root Path Disclosure Vulnerability
16649| [4876] Apache Tomcat Source.JSP Malformed Request Information Disclosure Vulnerability
16650| [4575] Apache Tomcat Servlet Path Disclosure Vulnerability
16651| [4557] Apache Tomcat System Path Information Disclosure Vulnerability
16652| [4437] Apache Error Message Cross-Site Scripting Vulnerability
16653| [4431] Apache PrintEnv/Test_CGI Script Injection Vulnerability
16654| [4358] Apache Double-Reverse Lookup Log Entry Spoofing Vulnerability
16655| [4335] Apache Win32 Batch File Remote Command Execution Vulnerability
16656| [4292] Oracle 9iAS Apache PL/SQL Module Web Administration Access Vulnerability
16657| [4189] Apache mod_ssl/Apache-SSL Buffer Overflow Vulnerability
16658| [4057] Apache 2 for Windows OPTIONS request Path Disclosure Vulnerability
16659| [4056] Apache 2 for Windows php.exe Path Disclosure Vulnerability
16660| [4037] Oracle 9iAS Apache PL/SQL Module Denial of Service Vulnerability
16661| [4032] Oracle 9iAS Apache PL/SQL Module Multiple Buffer Overflows Vulnerability
16662| [3796] Apache HTTP Request Unexpected Behavior Vulnerability
16663| [3790] Apache Non-Existent Log Directory Denial Of Service Vulnerability
16664| [3786] Apache Win32 PHP.EXE Remote File Disclosure Vulnerability
16665| [3727] Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
16666| [3726] Oracle 9I Application Server PL/SQL Apache Module Buffer Overflow Vulnerability
16667| [3596] Apache Split-Logfile File Append Vulnerability
16668| [3521] Apache mod_usertrack Predictable ID Generation Vulnerability
16669| [3335] Red Hat Linux Apache Remote Username Enumeration Vulnerability
16670| [3316] MacOS X Client Apache Directory Contents Disclosure Vulnerability
16671| [3256] Apache mod_auth_oracle Remote SQL Query Manipulation Vulnerability
16672| [3255] Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
16673| [3254] Apache AuthPG Remote SQL Query Manipulation Vulnerability
16674| [3253] Apache mod_auth_pgsql_sys Remote SQL Query Manipulation Vulnerability
16675| [3251] Apache mod_auth_pgsql Remote SQL Query Manipulation Vulnerability
16676| [3176] Apache Mod ReWrite Rules Bypassing Image Linking Vulnerability
16677| [3169] Apache Server Address Disclosure Vulnerability
16678| [3009] Apache Possible Directory Index Disclosure Vulnerability
16679| [2982] Apache Tomcat Cross-Site Scripting Vulnerability
16680| [2852] MacOS X Client Apache File Protection Bypass Vulnerability
16681| [2740] Apache Web Server HTTP Request Denial of Service Vulnerability
16682| [2518] Apache Tomcat 3.0 Directory Traversal Vulnerability
16683| [2503] Apache Artificially Long Slash Path Directory Listing Vulnerability
16684| [2300] NCSA/Apache httpd ScriptAlias Source Retrieval Vulnerability
16685| [2216] Apache Web Server DoS Vulnerability
16686| [2182] Apache /tmp File Race Vulnerability
16687| [2171] Oracle Apache+WebDB Documented Backdoor Vulnerability
16688| [2060] Apache Web Server with Php 3 File Disclosure Vulnerability
16689| [1821] Apache mod_cookies Buffer Overflow Vulnerability
16690| [1728] Apache Rewrite Module Arbitrary File Disclosure Vulnerability
16691| [1658] SuSE Apache CGI Source Code Viewing Vulnerability
16692| [1656] SuSE Apache WebDAV Directory Listings Vulnerability
16693| [1575] Trustix Apache-SSL RPM Permissions Vulnerability
16694| [1548] Apache Jakarta-Tomcat /admin Context Vulnerability
16695| [1532] Apache Tomcat Snoop Servlet Information Disclosure Vulnerability
16696| [1531] Apache Tomcat 3.1 Path Revealing Vulnerability
16697| [1457] Apache::ASP source.asp Example Script Vulnerability
16698| [1284] Apache HTTP Server (win32) Root Directory Access Vulnerability
16699| [1083] Cobalt Raq Apache .htaccess Disclosure Vulnerability
16700|
16701| IBM X-Force - https://exchange.xforce.ibmcloud.com:
16702| [86258] Apache CloudStack text fields cross-site scripting
16703| [85983] Apache Subversion mod_dav_svn module denial of service
16704| [85875] Apache OFBiz UEL code execution
16705| [85874] Apache OFBiz Webtools View Log screen cross-site scripting
16706| [85871] Apache HTTP Server mod_session_dbd unspecified
16707| [85756] Apache Struts OGNL expression command execution
16708| [85755] Apache Struts DefaultActionMapper class open redirect
16709| [85586] Apache ActiveMQ CVE-2013-1879 cross-site scripting
16710| [85574] Apache HTTP Server mod_dav denial of service
16711| [85573] Apache Struts Showcase App OGNL code execution
16712| [85496] Apache CXF denial of service
16713| [85423] Apache Geronimo RMI classloader code execution
16714| [85326] Apache Santuario XML Security for C++ buffer overflow
16715| [85323] Apache Santuario XML Security for Java spoofing
16716| [85319] Apache Qpid Python client SSL spoofing
16717| [85019] Apache Santuario XML Security for C++ CVE-2013-2156 buffer overflow
16718| [85018] Apache Santuario XML Security for C++ CVE-2013-2155 denial of service
16719| [85017] Apache Santuario XML Security for C++ CVE-2013-2154 buffer overflow
16720| [85016] Apache Santuario XML Security for C++ CVE-2013-2153 spoofing
16721| [84952] Apache Tomcat CVE-2012-3544 denial of service
16722| [84763] Apache Struts CVE-2013-2135 security bypass
16723| [84762] Apache Struts CVE-2013-2134 security bypass
16724| [84719] Apache Subversion CVE-2013-2088 command execution
16725| [84718] Apache Subversion CVE-2013-2112 denial of service
16726| [84717] Apache Subversion CVE-2013-1968 denial of service
16727| [84577] Apache Tomcat security bypass
16728| [84576] Apache Tomcat symlink
16729| [84543] Apache Struts CVE-2013-2115 security bypass
16730| [84542] Apache Struts CVE-2013-1966 security bypass
16731| [84154] Apache Tomcat session hijacking
16732| [84144] Apache Tomcat denial of service
16733| [84143] Apache Tomcat information disclosure
16734| [84111] Apache HTTP Server command execution
16735| [84043] Apache Virtual Computing Lab cross-site scripting
16736| [84042] Apache Virtual Computing Lab cross-site scripting
16737| [83782] Apache CloudStack information disclosure
16738| [83781] Apache CloudStack security bypass
16739| [83720] Apache ActiveMQ cross-site scripting
16740| [83719] Apache ActiveMQ denial of service
16741| [83718] Apache ActiveMQ denial of service
16742| [83263] Apache Subversion denial of service
16743| [83262] Apache Subversion denial of service
16744| [83261] Apache Subversion denial of service
16745| [83259] Apache Subversion denial of service
16746| [83035] Apache mod_ruid2 security bypass
16747| [82852] Apache Qpid federation_tag security bypass
16748| [82851] Apache Qpid qpid::framing::Buffer denial of service
16749| [82758] Apache Rave User RPC API information disclosure
16750| [82663] Apache Subversion svn_fs_file_length() denial of service
16751| [82642] Apache Qpid qpid::framing::Buffer::checkAvailable() denial of service
16752| [82641] Apache Qpid AMQP denial of service
16753| [82626] Apache HTTP Server on Debian GNU/Linux Debian apache2ctl symlink
16754| [82618] Apache Commons FileUpload symlink
16755| [82360] Apache HTTP Server manager interface cross-site scripting
16756| [82359] Apache HTTP Server hostnames cross-site scripting
16757| [82338] Apache Tomcat log/logdir information disclosure
16758| [82328] Apache Maven and Apache Maven Wagon SSL spoofing
16759| [82268] Apache OpenJPA deserialization command execution
16760| [81981] Apache CXF UsernameTokens security bypass
16761| [81980] Apache CXF WS-Security security bypass
16762| [81398] Apache OFBiz cross-site scripting
16763| [81240] Apache CouchDB directory traversal
16764| [81226] Apache CouchDB JSONP code execution
16765| [81225] Apache CouchDB Futon user interface cross-site scripting
16766| [81211] Apache Axis2/C SSL spoofing
16767| [81167] Apache CloudStack DeployVM information disclosure
16768| [81166] Apache CloudStack AddHost API information disclosure
16769| [81165] Apache CloudStack createSSHKeyPair API information disclosure
16770| [80518] Apache Tomcat cross-site request forgery security bypass
16771| [80517] Apache Tomcat FormAuthenticator security bypass
16772| [80516] Apache Tomcat NIO denial of service
16773| [80408] Apache Tomcat replay-countermeasure security bypass
16774| [80407] Apache Tomcat HTTP Digest Access Authentication security bypass
16775| [80317] Apache Tomcat slowloris denial of service
16776| [79984] Apache Commons HttpClient SSL spoofing
16777| [79983] Apache CXF SSL spoofing
16778| [79830] Apache Axis2/Java SSL spoofing
16779| [79829] Apache Axis SSL spoofing
16780| [79809] Apache Tomcat DIGEST security bypass
16781| [79806] Apache Tomcat parseHeaders() denial of service
16782| [79540] Apache OFBiz unspecified
16783| [79487] Apache Axis2 SAML security bypass
16784| [79212] Apache Cloudstack code execution
16785| [78734] Apache CXF SOAP Action security bypass
16786| [78730] Apache Qpid broker denial of service
16787| [78617] Eucalyptus Apache Santuario (XML Security for Java) denial of service
16788| [78563] Apache mod_pagespeed module unspecified cross-site scripting
16789| [78562] Apache mod_pagespeed module security bypass
16790| [78454] Apache Axis2 security bypass
16791| [78452] Websense Web Security and Web Filter Apache Tomcat information disclosure
16792| [78451] Websense Web Security and Web Filter Apache Tomcat cross-site scripting
16793| [78321] Apache Wicket unspecified cross-site scripting
16794| [78183] Apache Struts parameters denial of service
16795| [78182] Apache Struts cross-site request forgery
16796| [78153] Apache Solr Autocomplete module for Drupal autocomplete results cross-site scripting
16797| [77987] mod_rpaf module for Apache denial of service
16798| [77958] Apache Struts skill name code execution
16799| [77914] Apache HTTP Server mod_negotiation module cross-site scripting
16800| [77913] Apache HTTP Server mod_proxy_ajp information disclosure
16801| [77568] Apache Qpid broker security bypass
16802| [77421] Apache Libcloud spoofing
16803| [77059] Oracle Solaris Cluster Apache Tomcat Agent unspecified
16804| [77046] Oracle Solaris Apache HTTP Server information disclosure
16805| [76837] Apache Hadoop information disclosure
16806| [76802] Apache Sling CopyFrom denial of service
16807| [76692] Apache Hadoop symlink
16808| [76535] Apache Roller console cross-site request forgery
16809| [76534] Apache Roller weblog cross-site scripting
16810| [76152] Apache CXF elements security bypass
16811| [76151] Apache CXF child policies security bypass
16812| [75983] MapServer for Windows Apache file include
16813| [75857] Apache Commons Compress and Apache Ant bzip2 denial of service
16814| [75558] Apache POI denial of service
16815| [75545] PHP apache_request_headers() buffer overflow
16816| [75302] Apache Qpid SASL security bypass
16817| [75211] Debian GNU/Linux apache 2 cross-site scripting
16818| [74901] Apache HTTP Server LD_LIBRARY_PATH privilege escalation
16819| [74871] Apache OFBiz FlexibleStringExpander code execution
16820| [74870] Apache OFBiz multiple cross-site scripting
16821| [74750] Apache Hadoop unspecified spoofing
16822| [74319] Apache Struts XSLTResult.java file upload
16823| [74313] Apache Traffic Server header buffer overflow
16824| [74276] Apache Wicket directory traversal
16825| [74273] Apache Wicket unspecified cross-site scripting
16826| [74181] Apache HTTP Server mod_fcgid module denial of service
16827| [73690] Apache Struts OGNL code execution
16828| [73432] Apache Solr extension for TYPO3 unspecified cross-site scripting
16829| [73100] Apache MyFaces in directory traversal
16830| [73096] Apache APR hash denial of service
16831| [73052] Apache Struts name cross-site scripting
16832| [73030] Apache CXF UsernameToken security bypass
16833| [72888] Apache Struts lastName cross-site scripting
16834| [72758] Apache HTTP Server httpOnly information disclosure
16835| [72757] Apache HTTP Server MPM denial of service
16836| [72585] Apache Struts ParameterInterceptor security bypass
16837| [72438] Apache Tomcat Digest security bypass
16838| [72437] Apache Tomcat Digest security bypass
16839| [72436] Apache Tomcat DIGEST security bypass
16840| [72425] Apache Tomcat parameter denial of service
16841| [72422] Apache Tomcat request object information disclosure
16842| [72377] Apache HTTP Server scoreboard security bypass
16843| [72345] Apache HTTP Server HTTP request denial of service
16844| [72229] Apache Struts ExceptionDelegator command execution
16845| [72089] Apache Struts ParameterInterceptor directory traversal
16846| [72088] Apache Struts CookieInterceptor command execution
16847| [72047] Apache Geronimo hash denial of service
16848| [72016] Apache Tomcat hash denial of service
16849| [71711] Apache Struts OGNL expression code execution
16850| [71654] Apache Struts interfaces security bypass
16851| [71620] Apache ActiveMQ failover denial of service
16852| [71617] Apache HTTP Server mod_proxy module information disclosure
16853| [71508] Apache MyFaces EL security bypass
16854| [71445] Apache HTTP Server mod_proxy security bypass
16855| [71203] Apache Tomcat servlets privilege escalation
16856| [71181] Apache HTTP Server ap_pregsub() denial of service
16857| [71093] Apache HTTP Server ap_pregsub() buffer overflow
16858| [70336] Apache HTTP Server mod_proxy information disclosure
16859| [69804] Apache HTTP Server mod_proxy_ajp denial of service
16860| [69472] Apache Tomcat AJP security bypass
16861| [69396] Apache HTTP Server ByteRange filter denial of service
16862| [69394] Apache Wicket multi window support cross-site scripting
16863| [69176] Apache Tomcat XML information disclosure
16864| [69161] Apache Tomcat jsvc information disclosure
16865| [68799] mod_authnz_external module for Apache mysql-auth.pl SQL injection
16866| [68541] Apache Tomcat sendfile information disclosure
16867| [68420] Apache XML Security denial of service
16868| [68238] Apache Tomcat JMX information disclosure
16869| [67860] Apache Rampart/C rampart_timestamp_token_validate security bypass
16870| [67804] Apache Subversion control rules information disclosure
16871| [67803] Apache Subversion control rules denial of service
16872| [67802] Apache Subversion baselined denial of service
16873| [67672] Apache Archiva multiple cross-site scripting
16874| [67671] Apache Archiva multiple cross-site request forgery
16875| [67564] Apache APR apr_fnmatch() denial of service
16876| [67532] IBM WebSphere Application Server org.apache.jasper.runtime.JspWriterImpl.response denial of service
16877| [67515] Apache Tomcat annotations security bypass
16878| [67480] Apache Struts s:submit information disclosure
16879| [67414] Apache APR apr_fnmatch() denial of service
16880| [67356] Apache Struts javatemplates cross-site scripting
16881| [67354] Apache Struts Xwork cross-site scripting
16882| [66676] Apache Tomcat HTTP BIO information disclosure
16883| [66675] Apache Tomcat web.xml security bypass
16884| [66640] Apache HttpComponents HttpClient Proxy-Authorization information disclosure
16885| [66241] Apache HttpComponents information disclosure
16886| [66154] Apache Tomcat ServletSecurity security bypass
16887| [65971] Apache Tomcat ServletSecurity security bypass
16888| [65876] Apache Subversion mod_dav_svn denial of service
16889| [65343] Apache Continuum unspecified cross-site scripting
16890| [65162] Apache Tomcat NIO connector denial of service
16891| [65161] Apache Tomcat javax.servlet.ServletRequest.getLocale() denial of service
16892| [65160] Apache Tomcat HTML Manager interface cross-site scripting
16893| [65159] Apache Tomcat ServletContect security bypass
16894| [65050] Apache CouchDB web-based administration UI cross-site scripting
16895| [64773] Oracle HTTP Server Apache Plugin unauthorized access
16896| [64473] Apache Subversion blame -g denial of service
16897| [64472] Apache Subversion walk() denial of service
16898| [64407] Apache Axis2 CVE-2010-0219 code execution
16899| [63926] Apache Archiva password privilege escalation
16900| [63785] Apache CouchDB LD_LIBRARY_PATH privilege escalation
16901| [63493] Apache Archiva credentials cross-site request forgery
16902| [63477] Apache Tomcat HttpOnly session hijacking
16903| [63422] Apache Tomcat sessionsList.jsp cross-site scripting
16904| [63303] Apache mod_fcgid module fcgid_header_bucket_read() buffer overflow
16905| [62959] Apache Shiro filters security bypass
16906| [62790] Apache Perl cgi module denial of service
16907| [62576] Apache Qpid exchange denial of service
16908| [62575] Apache Qpid AMQP denial of service
16909| [62354] Apache Qpid SSL denial of service
16910| [62235] Apache APR-util apr_brigade_split_line() denial of service
16911| [62181] Apache XML-RPC SAX Parser information disclosure
16912| [61721] Apache Traffic Server cache poisoning
16913| [61202] Apache Derby BUILTIN authentication functionality information disclosure
16914| [61186] Apache CouchDB Futon cross-site request forgery
16915| [61169] Apache CXF DTD denial of service
16916| [61070] Apache Jackrabbit search.jsp SQL injection
16917| [61006] Apache SLMS Quoting cross-site request forgery
16918| [60962] Apache Tomcat time cross-site scripting
16919| [60883] Apache mod_proxy_http information disclosure
16920| [60671] Apache HTTP Server mod_cache and mod_dav denial of service
16921| [60264] Apache Tomcat Transfer-Encoding denial of service
16922| [59746] Apache Axis2 axis2/axis2-admin page session hijacking
16923| [59588] Apache Axis2/Java XML DTD (Document Type Declaration) data denial of service
16924| [59413] Apache mod_proxy_http timeout information disclosure
16925| [59058] Apache MyFaces unencrypted view state cross-site scripting
16926| [58827] Apache Axis2 xsd file include
16927| [58790] Apache Axis2 modules cross-site scripting
16928| [58299] Apache ActiveMQ queueBrowse cross-site scripting
16929| [58169] Apache Tomcat Web Application Manager / Host Manager cross-site request forgery
16930| [58056] Apache ActiveMQ .jsp source code disclosure
16931| [58055] Apache Tomcat realm name information disclosure
16932| [58046] Apache HTTP Server mod_auth_shadow security bypass
16933| [57841] Apache Open For Business Project (OFBiz) subject cross-site scripting
16934| [57840] Apache Open For Business Project (OFBiz) multiple parameters cross-site scripting
16935| [57429] Apache CouchDB algorithms information disclosure
16936| [57398] Apache ActiveMQ Web console cross-site request forgery
16937| [57397] Apache ActiveMQ createDestination.action cross-site scripting
16938| [56653] Apache HTTP Server DNS spoofing
16939| [56652] Apache HTTP Server DNS cross-site scripting
16940| [56625] Apache HTTP Server request header information disclosure
16941| [56624] Apache HTTP Server mod_isapi orphaned callback pointer code execution
16942| [56623] Apache HTTP Server mod_proxy_ajp denial of service
16943| [55941] mod_proxy module for Apache ap_proxy_send_fb() buffer overflow
16944| [55857] Apache Tomcat WAR files directory traversal
16945| [55856] Apache Tomcat autoDeploy attribute security bypass
16946| [55855] Apache Tomcat WAR directory traversal
16947| [55210] Intuit component for Joomla! Apache information disclosure
16948| [54533] Apache Tomcat 404 error page cross-site scripting
16949| [54182] Apache Tomcat admin default password
16950| [53878] Apache Solr Search (solr) extension for TYPO3 unspecified cross-site scripting
16951| [53666] Apache HTTP Server Solaris pollset support denial of service
16952| [53650] Apache HTTP Server HTTP basic-auth module security bypass
16953| [53124] mod_proxy_ftp module for Apache HTTP header security bypass
16954| [53041] mod_proxy_ftp module for Apache denial of service
16955| [52540] Apache Portable Runtime and Apache Portable Utility library multiple buffer overflow
16956| [51953] Apache Tomcat Path Disclosure
16957| [51952] Apache Tomcat Path Traversal
16958| [51951] Apache stronghold-status Information Disclosure
16959| [51950] Apache stronghold-info Information Disclosure
16960| [51949] Apache PHP Source Code Disclosure
16961| [51948] Apache Multiviews Attack
16962| [51946] Apache JServ Environment Status Information Disclosure
16963| [51945] Apache error_log Information Disclosure
16964| [51944] Apache Default Installation Page Pattern Found
16965| [51943] Apache AXIS XML Parser echoheaders.jws Sample Web Service Denial of Service
16966| [51942] Apache AXIS XML External Entity File Retrieval
16967| [51941] Apache AXIS Sample Servlet Information Leak
16968| [51940] Apache access_log Information Disclosure
16969| [51626] Apache mod_deflate denial of service
16970| [51532] mod_proxy module for the Apache HTTP Server stream_reqbody_cl denial of service
16971| [51365] Apache Tomcat RequestDispatcher security bypass
16972| [51273] Apache HTTP Server Incomplete Request denial of service
16973| [51195] Apache Tomcat XML information disclosure
16974| [50994] Apache APR-util xml/apr_xml.c denial of service
16975| [50993] Apache APR-util apr_brigade_vprintf denial of service
16976| [50964] Apache APR-util apr_strmatch_precompile() denial of service
16977| [50930] Apache Tomcat j_security_check information disclosure
16978| [50928] Apache Tomcat AJP denial of service
16979| [50884] Apache HTTP Server XML ENTITY denial of service
16980| [50808] Apache HTTP Server AllowOverride privilege escalation
16981| [50108] Apache Struts s:a tag and s:url tag cross-site scripting
16982| [50059] Apache mod_proxy_ajp information disclosure
16983| [49951] Apache Tiles Expression Language (EL) expressions cross-site scripting
16984| [49925] Apache Geronimo Web Administrative Console cross-site request forgery
16985| [49924] Apache Geronimo console/portal/Server/Monitoring cross-site scripting
16986| [49921] Apache ActiveMQ Web interface cross-site scripting
16987| [49898] Apache Geronimo Services/Repository directory traversal
16988| [49725] Apache Tomcat mod_jk module information disclosure
16989| [49715] Apache mod_perl Apache::Status and Apache2::Status modules cross-site scripting
16990| [49712] Apache Struts unspecified cross-site scripting
16991| [49213] Apache Tomcat cal2.jsp cross-site scripting
16992| [48934] Apache Tomcat POST doRead method information disclosure
16993| [48211] Apache Tomcat header HTTP request smuggling
16994| [48163] libapache2-mod-auth-mysql module for Debian multibyte encoding SQL injection
16995| [48110] Apache Jackrabbit search.jsp and swr.jsp cross-site scripting
16996| [47709] Apache Roller "
16997| [47104] Novell Netware ApacheAdmin console security bypass
16998| [47086] Apache HTTP Server OS fingerprinting unspecified
16999| [46329] Apache Struts FilterDispatcher and DefaultStaticContentLoader class directory traversal
17000| [45791] Apache Tomcat RemoteFilterValve security bypass
17001| [44435] Oracle WebLogic Apache Connector buffer overflow
17002| [44411] Apache Tomcat allowLinking UTF-8 directory traversal
17003| [44223] Apache HTTP Server mod_proxy_ftp cross-site scripting
17004| [44156] Apache Tomcat RequestDispatcher directory traversal
17005| [44155] Apache Tomcat HttpServletResponse.sendError() cross-site scripting
17006| [43885] Oracle WebLogic Server Apache Connector buffer overflow
17007| [42987] Apache HTTP Server mod_proxy module denial of service
17008| [42915] Apache Tomcat JSP files path disclosure
17009| [42914] Apache Tomcat MS-DOS path disclosure
17010| [42892] Apache Tomcat unspecified unauthorized access
17011| [42816] Apache Tomcat Host Manager cross-site scripting
17012| [42303] Apache 403 error cross-site scripting
17013| [41618] Apache-SSL ExpandCert() authentication bypass
17014| [40761] Apache Derby RDBNAM parameter and DatabaseMetaData.getURL information disclosure
17015| [40736] Apache Tomcat HTTP/1.1 connector information disclosure
17016| [40614] Apache mod_jk2 HTTP Host header buffer overflow
17017| [40562] Apache Geronimo init information disclosure
17018| [40478] Novell Web Manager webadmin-apache.conf security bypass
17019| [40411] Apache Tomcat exception handling information disclosure
17020| [40409] Apache Tomcat native (APR based) connector weak security
17021| [40403] Apache Tomcat quotes and %5C cookie information disclosure
17022| [40388] Sun Java Plug-In org.apache.crimson.tree.XmlDocument security bypass
17023| [39893] Apache HTTP Server mod_negotiation HTTP response splitting
17024| [39867] Apache HTTP Server mod_negotiation cross-site scripting
17025| [39804] Apache Tomcat SingleSignOn information disclosure
17026| [39615] Apache HTTP Server mod_proxy_ftp.c UTF-7 cross-site scripting
17027| [39612] Apache HTTP Server mod_proxy_balancer buffer overflow
17028| [39608] Apache HTTP Server balancer manager cross-site request forgery
17029| [39476] Apache mod_proxy_balancer balancer_handler function denial of service
17030| [39474] Apache HTTP Server mod_proxy_balancer cross-site scripting
17031| [39472] Apache HTTP Server mod_status cross-site scripting
17032| [39201] Apache Tomcat JULI logging weak security
17033| [39158] Apache HTTP Server Windows SMB shares information disclosure
17034| [39001] Apache HTTP Server mod_imap and mod_imagemap module cross-site scripting
17035| [38951] Apache::AuthCAS Perl module cookie SQL injection
17036| [38800] Apache HTTP Server 413 error page cross-site scripting
17037| [38211] Apache Geronimo SQLLoginModule authentication bypass
17038| [37243] Apache Tomcat WebDAV directory traversal
17039| [37178] RHSA update for Apache HTTP Server mod_status module cross-site scripting not installed
17040| [37177] RHSA update for Apache HTTP Server Apache child process denial of service not installed
17041| [37119] RHSA update for Apache mod_auth_kerb off-by-one buffer overflow not installed
17042| [37100] RHSA update for Apache and IBM HTTP Server Expect header cross-site scripting not installed
17043| [36782] Apache Geronimo MEJB unauthorized access
17044| [36586] Apache HTTP Server UTF-7 cross-site scripting
17045| [36468] Apache Geronimo LoginModule security bypass
17046| [36467] Apache Tomcat functions.jsp cross-site scripting
17047| [36402] Apache Tomcat calendar cross-site request forgery
17048| [36354] Apache HTTP Server mod_proxy module denial of service
17049| [36352] Apache HTTP Server ap_proxy_date_canon() denial of service
17050| [36336] Apache Derby lock table privilege escalation
17051| [36335] Apache Derby schema privilege escalation
17052| [36006] Apache Tomcat "
17053| [36001] Apache Tomcat Host Manager Servlet alias cross-site scripting
17054| [35999] Apache Tomcat \"
17055| [35795] Apache Tomcat CookieExample cross-site scripting
17056| [35536] Apache Tomcat SendMailServlet example cross-site scripting
17057| [35384] Apache HTTP Server mod_cache module denial of service
17058| [35097] Apache HTTP Server mod_status module cross-site scripting
17059| [35095] Apache HTTP Server Prefork MPM module denial of service
17060| [34984] Apache HTTP Server recall_headers information disclosure
17061| [34966] Apache HTTP Server MPM content spoofing
17062| [34965] Apache HTTP Server MPM information disclosure
17063| [34963] Apache HTTP Server MPM multiple denial of service
17064| [34872] Apache MyFaces Tomahawk autoscroll parameter cross-site scripting
17065| [34869] Apache Tomcat JSP example Web application cross-site scripting
17066| [34868] Apache Tomcat Manager and Host Manager cross-site scripting
17067| [34496] Apache Tomcat JK Connector security bypass
17068| [34377] Apache Tomcat hello.jsp cross-site scripting
17069| [34212] Apache Tomcat SSL configuration security bypass
17070| [34210] Apache Tomcat Accept-Language cross-site scripting
17071| [34209] Apache Tomcat calendar application cross-site scripting
17072| [34207] Apache Tomcat implicit-objects.jsp cross-site scripting
17073| [34167] Apache Axis WSDL file path disclosure
17074| [34068] Apache Tomcat AJP connector information disclosure
17075| [33584] Apache HTTP Server suEXEC privilege escalation
17076| [32988] Apache Tomcat proxy module directory traversal
17077| [32794] Apache Tomcat JK Web Server Connector map_uri_to_worker() buffer overflow
17078| [32708] Debian Apache tty privilege escalation
17079| [32441] ApacheStats extract() PHP call unspecified
17080| [32128] Apache Tomcat default account
17081| [31680] Apache Tomcat RequestParamExample cross-site scripting
17082| [31649] Apache Tomcat Sample Servlet TroubleShooter detected
17083| [31557] BEA WebLogic Server and WebLogic Express Apache proxy plug-in denial of service
17084| [31236] Apache HTTP Server htpasswd.c strcpy buffer overflow
17085| [30456] Apache mod_auth_kerb off-by-one buffer overflow
17086| [29550] Apache mod_tcl set_var() format string
17087| [28620] Apache and IBM HTTP Server Expect header cross-site scripting
17088| [28357] Apache HTTP Server mod_alias script source information disclosure
17089| [28063] Apache mod_rewrite off-by-one buffer overflow
17090| [27902] Apache Tomcat URL information disclosure
17091| [26786] Apache James SMTP server denial of service
17092| [25680] libapache2 /tmp/svn file upload
17093| [25614] Apache Struts lookupMap cross-site scripting
17094| [25613] Apache Struts ActionForm denial of service
17095| [25612] Apache Struts isCancelled() security bypass
17096| [24965] Apache mod_python FileSession command execution
17097| [24716] Apache James spooler memory leak denial of service
17098| [24159] Apache Geronimo Web-Access-Log Viewer cross-site scripting
17099| [24158] Apache Geronimo jsp-examples cross-site scripting
17100| [24030] Apache auth_ldap module multiple format strings
17101| [24008] Apache mod_ssl custom error message denial of service
17102| [24003] Apache mod_auth_pgsql module multiple syslog format strings
17103| [23612] Apache mod_imap referer field cross-site scripting
17104| [23173] Apache Struts error message cross-site scripting
17105| [22942] Apache Tomcat directory listing denial of service
17106| [22858] Apache Multi-Processing Module code allows denial of service
17107| [22602] RHSA-2005:582 updates for Apache httpd not installed
17108| [22520] Apache mod-auth-shadow "
17109| [22466] ApacheTop symlink
17110| [22109] Apache HTTP Server ssl_engine_kernel client certificate validation
17111| [22006] Apache HTTP Server byte-range filter denial of service
17112| [21567] Apache mod_ssl off-by-one buffer overflow
17113| [21195] Apache HTTP Server header HTTP request smuggling
17114| [20383] Apache HTTP Server htdigest buffer overflow
17115| [19681] Apache Tomcat AJP12 request denial of service
17116| [18993] Apache HTTP server check_forensic symlink attack
17117| [18790] Apache Tomcat Manager cross-site scripting
17118| [18349] Apache HTTP server Apple HFS+ filesystem obtain information
17119| [18348] Apache HTTP server Apple HFS+ filesystem .DS_Store and .ht file disclosure
17120| [18347] Apache HTTP server Apple Mac OS X Server mod_digest_apple module could allow an attacker to replay responses
17121| [17961] Apache Web server ServerTokens has not been set
17122| [17930] Apache HTTP Server HTTP GET request denial of service
17123| [17785] Apache mod_include module buffer overflow
17124| [17671] Apache HTTP Server SSLCipherSuite bypass restrictions
17125| [17473] Apache HTTP Server Satisfy directive allows access to resources
17126| [17413] Apache htpasswd buffer overflow
17127| [17384] Apache HTTP Server environment variable configuration file buffer overflow
17128| [17382] Apache HTTP Server IPv6 apr_util denial of service
17129| [17366] Apache HTTP Server mod_dav module LOCK denial of service
17130| [17273] Apache HTTP Server speculative mode denial of service
17131| [17200] Apache HTTP Server mod_ssl denial of service
17132| [16890] Apache HTTP Server server-info request has been detected
17133| [16889] Apache HTTP Server server-status request has been detected
17134| [16705] Apache mod_ssl format string attack
17135| [16524] Apache HTTP Server ap_get_mime_headers_core denial of service
17136| [16387] Apache HTTP Server mod_proxy Content-Length buffer overflow
17137| [16230] Apache HTTP Server PHP denial of service
17138| [16214] Apache mod_ssl ssl_util_uuencode_binary buffer overflow
17139| [15958] Apache HTTP Server authentication modules memory corruption
17140| [15547] Apache HTTP Server mod_disk_cache local information disclosure
17141| [15540] Apache HTTP Server socket starvation denial of service
17142| [15467] Novell GroupWise WebAccess using Apache Web server allows viewing of files on the server
17143| [15422] Apache HTTP Server mod_access information disclosure
17144| [15419] Apache HTTP Server mod_ssl plain HTTP request denial of service
17145| [15293] Apache for Cygwin "
17146| [15065] Apache-SSL has a default password
17147| [15041] Apache HTTP Server mod_digest module could allow an attacker to replay responses
17148| [15015] Apache httpd server httpd.conf could allow a local user to bypass restrictions
17149| [14751] Apache Mod_python output filter information disclosure
17150| [14125] Apache HTTP Server mod_userdir module information disclosure
17151| [14075] Apache HTTP Server mod_php file descriptor leak
17152| [13703] Apache HTTP Server account
17153| [13689] Apache HTTP Server configuration allows symlinks
17154| [13688] Apache HTTP Server configuration allows SSI
17155| [13687] Apache HTTP Server Server: header value
17156| [13685] Apache HTTP Server ServerTokens value
17157| [13684] Apache HTTP Server ServerSignature value
17158| [13672] Apache HTTP Server config allows directory autoindexing
17159| [13671] Apache HTTP Server default content
17160| [13670] Apache HTTP Server config file directive references outside content root
17161| [13668] Apache HTTP Server httpd not running in chroot environment
17162| [13666] Apache HTTP Server CGI directory contains possible command interpreter or compiler
17163| [13664] Apache HTTP Server config file contains ScriptAlias entry
17164| [13663] Apache HTTP Server CGI support modules loaded
17165| [13661] Apache HTTP Server config file contains AddHandler entry
17166| [13660] Apache HTTP Server 500 error page not CGI script
17167| [13659] Apache HTTP Server 413 error page not CGI script
17168| [13658] Apache HTTP Server 403 error page not CGI script
17169| [13657] Apache HTTP Server 401 error page not CGI script
17170| [13552] Apache HTTP Server mod_cgid module information disclosure
17171| [13550] Apache GET request directory traversal
17172| [13516] Apache Cocoon XMLForm and JXForm could allow execution of code
17173| [13499] Apache Cocoon directory traversal allows downloading of boot.ini file
17174| [13429] Apache Tomcat non-HTTP request denial of service
17175| [13400] Apache HTTP server mod_alias and mod_rewrite buffer overflow
17176| [13295] Apache weak password encryption
17177| [13254] Apache Tomcat .jsp cross-site scripting
17178| [13125] Apache::Gallery Inline::C could allow arbitrary code execution
17179| [13086] Apache Jakarta Tomcat mod_jk format string allows remote access
17180| [12681] Apache HTTP Server mod_proxy could allow mail relaying
17181| [12662] Apache HTTP Server rotatelogs denial of service
17182| [12554] Apache Tomcat stores password in plain text
17183| [12553] Apache HTTP Server redirects and subrequests denial of service
17184| [12552] Apache HTTP Server FTP proxy server denial of service
17185| [12551] Apache HTTP Server prefork MPM denial of service
17186| [12550] Apache HTTP Server weaker than expected encryption
17187| [12549] Apache HTTP Server type-map file denial of service
17188| [12206] Apache Tomcat /opt/tomcat directory insecure permissions
17189| [12102] Apache Jakarta Tomcat MS-DOS device name request denial of service
17190| [12091] Apache HTTP Server apr_password_validate denial of service
17191| [12090] Apache HTTP Server apr_psprintf code execution
17192| [11804] Apache HTTP Server mod_access_referer denial of service
17193| [11750] Apache HTTP Server could leak sensitive file descriptors
17194| [11730] Apache HTTP Server error log and access log terminal escape sequence injection
17195| [11703] Apache long slash path allows directory listing
17196| [11695] Apache HTTP Server LF (Line Feed) denial of service
17197| [11694] Apache HTTP Server filestat.c denial of service
17198| [11438] Apache HTTP Server MIME message boundaries information disclosure
17199| [11412] Apache HTTP Server error log terminal escape sequence injection
17200| [11196] Apache Tomcat examples and ROOT Web applications cross-site scripting
17201| [11195] Apache Tomcat web.xml could be used to read files
17202| [11194] Apache Tomcat URL appended with a null character could list directories
17203| [11139] Apache HTTP Server mass virtual hosting with mod_rewrite or mod_vhost_alias could allow an attacker to obtain files
17204| [11126] Apache HTTP Server illegal character file disclosure
17205| [11125] Apache HTTP Server DOS device name HTTP POST code execution
17206| [11124] Apache HTTP Server DOS device name denial of service
17207| [11088] Apache HTTP Server mod_vhost_alias CGI source disclosure
17208| [10938] Apache HTTP Server printenv test CGI cross-site scripting
17209| [10771] Apache Tomcat mod_jk module multiple HTTP GET request buffer overflow
17210| [10575] Apache mod_php module could allow an attacker to take over the httpd process
17211| [10499] Apache HTTP Server WebDAV HTTP POST view source
17212| [10457] Apache HTTP Server mod_ssl "
17213| [10415] Apache HTTP Server htdigest insecure system() call could allow command execution
17214| [10414] Apache HTTP Server htdigest multiple buffer overflows
17215| [10413] Apache HTTP Server htdigest temporary file race condition
17216| [10412] Apache HTTP Server htpasswd temporary file race condition
17217| [10376] Apache Tomcat invoker servlet used in conjunction with the default servlet reveals source code
17218| [10348] Apache Tomcat HTTP GET request DOS device reference could cause a denial of service
17219| [10281] Apache HTTP Server ab.c ApacheBench long response buffer overflow
17220| [10280] Apache HTTP Server shared memory scorecard overwrite
17221| [10263] Apache Tomcat mod_jk or mod_jserv connector directory disclosure
17222| [10241] Apache HTTP Server Host: header cross-site scripting
17223| [10230] Slapper worm variants A, B, and C target OpenSSL/Apache systems
17224| [10208] Apache HTTP Server mod_dav denial of service
17225| [10206] HP VVOS Apache mod_ssl denial of service
17226| [10200] Apache HTTP Server stderr denial of service
17227| [10175] Apache Tomcat org.apache.catalina.servlets.DefaultServlet reveals source code
17228| [10169] Slapper worm variant (Slapper.C) targets OpenSSL/Apache systems
17229| [10154] Slapper worm variant (Slapper.B) targets OpenSSL/Apache systems
17230| [10098] Slapper worm targets OpenSSL/Apache systems
17231| [9876] Apache HTTP Server cgi/cgid request could disclose the path to a requested script
17232| [9875] Apache HTTP Server .var file request could disclose installation path
17233| [9863] Apache Tomcat web.xml file could allow a remote attacker to bypass restrictions
17234| [9808] Apache HTTP Server non-Unix version URL encoded directory traversal
17235| [9623] Apache HTTP Server ap_log_rerror() path disclosure
17236| [9520] Apache Tomcat /servlet/ mapping cross-site scripting
17237| [9415] Apache HTTP Server mod_ssl .htaccess off-by-one buffer overflow
17238| [9396] Apache Tomcat null character to threads denial of service
17239| [9394] Apache Tomcat HTTP request for LPT9 reveals Web root path
17240| [9249] Apache HTTP Server chunked encoding heap buffer overflow
17241| [9208] Apache Tomcat sample file requests could reveal directory listing and path to Web root directory
17242| [8932] Apache Tomcat example class information disclosure
17243| [8633] Apache HTTP Server with mod_rewrite could allow an attacker to bypass directives
17244| [8629] Apache HTTP Server double-reverse DNS lookup spoofing
17245| [8589] Apache HTTP Server for Windows DOS batch file remote command execution
17246| [8457] Oracle9i Application Server Apache PL/SQL HTTP Location header buffer overflow
17247| [8455] Oracle9i Application Server default installation could allow an attacker to access certain Apache Services
17248| [8400] Apache HTTP Server mod_frontpage buffer overflows
17249| [8326] Apache HTTP Server multiple MIME headers (sioux) denial of service
17250| [8308] Apache "
17251| [8275] Apache HTTP Server with Multiviews enabled could disclose directory contents
17252| [8119] Apache and PHP OPTIONS request reveals "
17253| [8054] Apache is running on the system
17254| [8029] Mandrake Linux default Apache configuration could allow an attacker to browse files and directories
17255| [8027] Mandrake Linux default Apache configuration has remote management interface enabled
17256| [8026] Mandrake Linux Apache sample programs could disclose sensitive information about the server
17257| [7836] Apache HTTP Server log directory denial of service
17258| [7815] Apache for Windows "
17259| [7810] Apache HTTP request could result in unexpected behavior
17260| [7599] Apache Tomcat reveals installation path
17261| [7494] Apache "
17262| [7419] Apache Web Server could allow remote attackers to overwrite .log files
17263| [7363] Apache Web Server hidden HTTP requests
17264| [7249] Apache mod_proxy denial of service
17265| [7129] Linux with Apache Web server could allow an attacker to determine if a specified username exists
17266| [7103] Apple Mac OS X used with Apache Web server could disclose directory contents
17267| [7059] Apache "
17268| [7057] Apache "
17269| [7056] Apache "
17270| [7055] Apache "
17271| [7054] Apache "
17272| [6997] Apache Jakarta Tomcat error message may reveal information
17273| [6971] Apache Jakarta Tomcat may reveal JSP source code with missing HTTP protocol specification
17274| [6970] Apache crafted HTTP request could reveal the internal IP address
17275| [6921] Apache long slash path allows directory listing
17276| [6687] Apple Mac OS X used with Apache Web server could allow arbitrary file disclosure
17277| [6527] Apache Web Server for Windows and OS2 denial of service
17278| [6316] Apache Jakarta Tomcat may reveal JSP source code
17279| [6305] Apache Jakarta Tomcat directory traversal
17280| [5926] Linux Apache symbolic link
17281| [5659] Apache Web server discloses files when used with php script
17282| [5310] Apache mod_rewrite allows attacker to view arbitrary files
17283| [5204] Apache WebDAV directory listings
17284| [5197] Apache Web server reveals CGI script source code
17285| [5160] Apache Jakarta Tomcat default installation
17286| [5099] Trustix Secure Linux installs Apache with world writable access
17287| [4968] Apache Jakarta Tomcat snoop servlet gives out information which could be used in attack
17288| [4967] Apache Jakarta Tomcat 404 error reveals the pathname of the requested file
17289| [4931] Apache source.asp example file allows users to write to files
17290| [4575] IBM HTTP Server running Apache allows users to directory listing and file retrieval
17291| [4205] Apache Jakarta Tomcat delivers file contents
17292| [2084] Apache on Debian by default serves the /usr/doc directory
17293| [1630] MessageMedia UnityMail and Apache Web server MIME header flood denial of service
17294| [697] Apache HTTP server beck exploit
17295| [331] Apache cookies buffer overflow
17296|
17297| Exploit-DB - https://www.exploit-db.com:
17298| [31130] Apache Tomcat <= 6.0.15 Cookie Quote Handling Remote Information Disclosure Vulnerability
17299| [31052] Apache <= 2.2.6 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
17300| [30901] Apache HTTP Server 2.2.6 Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
17301| [30835] Apache HTTP Server <= 2.2.4 413 Error HTTP Request Method Cross-Site Scripting Weakness
17302| [30563] Apache Tomcat <= 5.5.15 Cal2.JSP Cross-Site Scripting Vulnerability
17303| [30496] Apache Tomcat <= 6.0.13 Cookie Handling Quote Delimiter Session ID Disclosure
17304| [30495] Apache Tomcat <= 6.0.13 Host Manager Servlet Cross Site Scripting Vulnerability
17305| [30191] Apache MyFaces Tomahawk JSF Framework 1.1.5 Autoscroll Parameter Cross Site Scripting Vulnerability
17306| [30189] Apache Tomcat <= 6.0.13 JSP Example Web Applications Cross Site Scripting Vulnerability
17307| [30052] Apache Tomcat 6.0.10 Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
17308| [29930] Apache AXIS 1.0 Non-Existent WSDL Path Information Disclosure Vulnerability
17309| [29859] Apache Roller OGNL Injection
17310| [29739] Apache HTTP Server Tomcat 5.x/6.0.x Directory Traversal Vulnerability
17311| [29435] Apache Tomcat 5.5.25 - CSRF Vulnerabilities
17312| [29316] Apache + PHP 5.x - Remote Code Execution (Multithreaded Scanner) (2)
17313| [29290] Apache / PHP 5.x Remote Code Execution Exploit
17314| [28713] Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object RCE
17315| [28424] Apache 2.x HTTP Server Arbitrary HTTP Request Headers Security Weakness
17316| [28365] Apache 2.2.2 CGI Script Source Code Information Disclosure Vulnerability
17317| [28254] Apache Tomcat 5 Information Disclosure Vulnerability
17318| [27915] Apache James 2.2 SMTP Denial of Service Vulnerability
17319| [27397] Apache suEXEC Privilege Elevation / Information Disclosure
17320| [27135] Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
17321| [27096] Apache Geronimo 1.0 Error Page XSS
17322| [27095] Apache Tomcat / Geronimo 1.0 Sample Script cal2.jsp time Parameter XSS
17323| [26710] Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4 - Denial of Service
17324| [26542] Apache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability
17325| [25986] Plesk Apache Zeroday Remote Exploit
17326| [25980] Apache Struts includeParams Remote Code Execution
17327| [25625] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (2)
17328| [25624] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (1)
17329| [24874] Apache Struts ParametersInterceptor Remote Code Execution
17330| [24744] Apache Rave 0.11 - 0.20 - User Information Disclosure
17331| [24694] Apache 1.3.x mod_include Local Buffer Overflow Vulnerability
17332| [24590] Apache 2.0.x mod_ssl Remote Denial of Service Vulnerability
17333| [23751] Apache Cygwin 1.3.x/2.0.x Directory Traversal Vulnerability
17334| [23581] Apache 2.0.4x mod_perl Module File Descriptor Leakage Vulnerability
17335| [23482] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (2)
17336| [23481] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (1)
17337| [23296] Red Hat Apache 2.0.40 Directory Index Default Configuration Error
17338| [23282] apache cocoon 2.14/2.2 - Directory Traversal vulnerability
17339| [23245] Apache Tomcat 4.0.x Non-HTTP Request Denial of Service Vulnerability
17340| [23119] Apache::Gallery 0.4/0.5/0.6 Insecure Local File Storage Privilege Escalation Vulnerability
17341| [22505] Apache Mod_Access_Referer 1.0.2 NULL Pointer Dereference Denial of Service Vulnerability
17342| [22205] Apache Tomcat 3.x Null Byte Directory/File Disclosure Vulnerability
17343| [22191] Apache Web Server 2.0.x MS-DOS Device Name Denial of Service Vulnerability
17344| [22068] Apache 1.3.x,Tomcat 4.0.x/4.1.x Mod_JK Chunked Encoding Denial of Service Vulnerability
17345| [21885] Apache 1.3/2.0.x Server Side Include Cross Site Scripting Vulnerability
17346| [21882] Apache Tomcat 3.2 Directory Disclosure Vulnerability
17347| [21854] Apache 2.0.39/40 Oversized STDERR Buffer Denial of Service Vulnerability
17348| [21853] Apache Tomcat 3/4 DefaultServlet File Disclosure Vulnerability
17349| [21734] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
17350| [21719] Apache 2.0 Path Disclosure Vulnerability
17351| [21697] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
17352| [21605] Apache Tomcat 4.0.3 DoS Device Name Cross Site Scripting Vulnerability
17353| [21604] Apache Tomcat 4.0.3 Servlet Mapping Cross Site Scripting Vulnerability
17354| [21560] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (2)
17355| [21559] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (1)
17356| [21534] Apache Tomcat 3/4 JSP Engine Denial of Service Vulnerability
17357| [21492] Apache Tomcat 3.2.3/3.2.4 RealPath.JSP Malformed Request Information Disclosure
17358| [21491] Apache Tomcat 3.2.3/3.2.4 Example Files Web Root Path Disclosure
17359| [21490] Apache Tomcat 3.2.3/3.2.4 Source.JSP Malformed Request Information Disclosure
17360| [21412] Apache Tomcat 4.0/4.1 Servlet Path Disclosure Vulnerability
17361| [21350] Apache Win32 1.3.x/2.0.x Batch File Remote Command Execution Vulnerability
17362| [21204] Apache 1.3.20 Win32 PHP.EXE Remote File Disclosure Vulnerability
17363| [21112] Red Hat Linux 7.0 Apache Remote Username Enumeration Vulnerability
17364| [21067] Apache 1.0/1.2/1.3 Server Address Disclosure Vulnerability
17365| [21002] Apache 1.3 Possible Directory Index Disclosure Vulnerability
17366| [20911] Apache 1.3.14 Mac File Protection Bypass Vulnerability
17367| [20716] apache tomcat 3.0 - Directory Traversal vulnerability
17368| [20695] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (4)
17369| [20694] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (3)
17370| [20693] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (2)
17371| [20692] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (1)
17372| [20595] NCSA 1.3/1.4.x/1.5,Apache httpd 0.8.11/0.8.14 ScriptAlias Source Retrieval Vulnerability
17373| [20558] Apache 1.2 Web Server DoS Vulnerability
17374| [20466] Apache 1.3 Web Server with Php 3 File Disclosure Vulnerability
17375| [20435] Apache 0.8.x/1.0.x,NCSA httpd 1.x test-cgi Directory Listing Vulnerability
17376| [20272] Apache 1.2.5/1.3.1,UnityMail 2.0 MIME Header DoS Vulnerability
17377| [20210] Apache 1.3.12 WebDAV Directory Listings Vulnerability
17378| [20131] Apache Tomcat 3.1 Path Revealing Vulnerability
17379| [19975] Apache 1.3.6/1.3.9/1.3.11/1.3.12/1.3.20 Root Directory Access Vulnerability
17380| [19828] Cobalt RaQ 2.0/3.0 Apache .htaccess Disclosure Vulnerability
17381| [19536] Apache <= 1.1,NCSA httpd <= 1.5.2,Netscape Server 1.12/1.1/2.0 a nph-test-cgi Vulnerability
17382| [19231] PHP apache_request_headers Function Buffer Overflow
17383| [18984] Apache Struts <= 2.2.1.1 - Remote Command Execution
17384| [18897] Oracle Weblogic Apache Connector POST Request Buffer Overflow
17385| [18619] Apache Tomcat Remote Exploit (PUT Request) and Account Scanner
17386| [18452] Apache Struts Multiple Persistent Cross-Site Scripting Vulnerabilities
17387| [18442] Apache httpOnly Cookie Disclosure
17388| [18329] Apache Struts2 <= 2.3.1 - Multiple Vulnerabilities
17389| [18221] Apache HTTP Server Denial of Service
17390| [17969] Apache mod_proxy Reverse Proxy Exposure Vulnerability PoC
17391| [17696] Apache httpd Remote Denial of Service (memory exhaustion)
17392| [17691] Apache Struts < 2.2.0 - Remote Command Execution
17393| [16798] Apache mod_jk 1.2.20 Buffer Overflow
17394| [16782] Apache Win32 Chunked Encoding
17395| [16752] Apache module mod_rewrite LDAP protocol Buffer Overflow
17396| [16317] Apache Tomcat Manager Application Deployer Authenticated Code Execution
17397| [15710] Apache Archiva 1.0 - 1.3.1 CSRF Vulnerability
17398| [15319] Apache 2.2 (Windows) Local Denial of Service
17399| [14617] Apache JackRabbit 2.0.0 webapp XPath Injection
17400| [14489] Apache Tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
17401| [12721] Apache Axis2 1.4.1 - Local File Inclusion Vulnerability
17402| [12689] Authenticated Cross-Site Scripting Vulnerability (XSS) within Apache Axis2 administration console
17403| [12343] Apache Tomcat 5.5.0 to 5.5.29 & 6.0.0 to 6.0.26 - Information Disclosure Vulnerability
17404| [12330] Apache OFBiz - Multiple XSS
17405| [12264] Apache OFBiz - FULLADMIN Creator PoC Payload
17406| [12263] Apache OFBiz - SQL Remote Execution PoC Payload
17407| [11662] Apache Spamassassin Milter Plugin Remote Root Command Execution
17408| [11650] Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit
17409| [10811] Joomla.Tutorials GHDB: Apache directory listing Download Vulnerability
17410| [10292] Apache Tomcat 3.2.1 - 404 Error Page Cross Site Scripting Vulnerability
17411| [9995] Apache Tomcat Form Authentication Username Enumeration Weakness
17412| [9994] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
17413| [9993] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
17414| [8842] Apache mod_dav / svn Remote Denial of Service Exploit
17415| [8458] Apache Geronimo <= 2.1.3 - Multiple Directory Traversal Vulnerabilities
17416| [7264] Apache Tomcat runtime.getRuntime().exec() Privilege Escalation (win)
17417| [6229] apache tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
17418| [6100] Apache mod_jk 1.2.19 Remote Buffer Overflow Exploit (win32)
17419| [6089] Bea Weblogic Apache Connector Code Exec / Denial of Service Exploit
17420| [5386] Apache Tomcat Connector jk2-2.0.2 (mod_jk2) Remote Overflow Exploit
17421| [5330] Apache 2.0 mod_jk2 2.0.2 - Remote Buffer Overflow Exploit (win32)
17422| [4552] Apache Tomcat (webdav) Remote File Disclosure Exploit (ssl support)
17423| [4530] Apache Tomcat (webdav) Remote File Disclosure Exploit
17424| [4162] Apache Tomcat Connector (mod_jk) Remote Exploit (exec-shield)
17425| [4093] Apache mod_jk 1.2.19/1.2.20 Remote Buffer Overflow Exploit
17426| [3996] Apache 2.0.58 mod_rewrite Remote Overflow Exploit (win2k3)
17427| [3680] Apache Mod_Rewrite Off-by-one Remote Overflow Exploit (win32)
17428| [3384] Ubuntu/Debian Apache 1.3.33/1.3.34 (CGI TTY) Local Root Exploit
17429| [2237] Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
17430| [2061] Apache Tomcat < 5.5.17 Remote Directory Listing Vulnerability
17431| [1056] Apache <= 2.0.49 Arbitrary Long HTTP Headers Denial of Service
17432| [855] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit
17433| [764] Apache OpenSSL - Remote Exploit (Multiple Targets) (OpenFuckV2.c)
17434| [587] Apache <= 1.3.31 mod_include Local Buffer Overflow Exploit
17435| [466] htpasswd Apache 1.3.31 - Local Exploit
17436| [371] Apache HTTPd Arbitrary Long HTTP Headers DoS (c version)
17437| [360] Apache HTTPd Arbitrary Long HTTP Headers DoS
17438| [132] Apache 1.3.x - 2.0.48 - mod_userdir Remote Users Disclosure Exploit
17439| [126] Apache mod_gzip (with debug_mode) <= 1.2.26.1a Remote Exploit
17440| [67] Apache 1.3.x mod_mylo Remote Code Execution Exploit
17441| [38] Apache <= 2.0.45 APR Remote Exploit -Apache-Knacker.pl
17442| [34] Webfroot Shoutbox < 2.32 (Apache) Remote Exploit
17443| [11] Apache <= 2.0.44 Linux Remote Denial of Service Exploit
17444| [9] Apache HTTP Server 2.x Memory Leak Exploit
17445|
17446| OpenVAS (Nessus) - http://www.openvas.org:
17447| [902924] Apache Struts2 Showcase Skill Name Remote Code Execution Vulnerability
17448| [902837] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability (Windows)
17449| [902830] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
17450| [902664] Apache Traffic Server HTTP Host Header Denial of Service Vulnerability
17451| [901203] Apache httpd Web Server Range Header Denial of Service Vulnerability
17452| [901110] Apache ActiveMQ Source Code Information Disclosure Vulnerability
17453| [901105] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
17454| [900842] Apache 'mod_proxy_ftp' Module Command Injection Vulnerability (Linux)
17455| [900841] Apache 'mod_proxy_ftp' Module Denial Of Service Vulnerability (Linux)
17456| [900573] Apache APR-Utils XML Parser Denial of Service Vulnerability
17457| [900572] Apache APR-Utils Multiple Denial of Service Vulnerabilities
17458| [900571] Apache APR-Utils Version Detection
17459| [900499] Apache mod_proxy_ajp Information Disclosure Vulnerability
17460| [900496] Apache Tiles Multiple XSS Vulnerability
17461| [900493] Apache Tiles Version Detection
17462| [900107] Apache mod_proxy_ftp Wildcard Characters XSS Vulnerability
17463| [900021] Apache Tomcat Cross-Site Scripting and Security Bypass Vulnerabilities
17464| [880086] CentOS Update for apache CESA-2008:0004-01 centos2 i386
17465| [870175] RedHat Update for apache RHSA-2008:0004-01
17466| [864591] Fedora Update for apache-poi FEDORA-2012-10835
17467| [864383] Fedora Update for apache-commons-compress FEDORA-2012-8428
17468| [864280] Fedora Update for apache-commons-compress FEDORA-2012-8465
17469| [864250] Fedora Update for apache-poi FEDORA-2012-7683
17470| [864249] Fedora Update for apache-poi FEDORA-2012-7686
17471| [863993] Fedora Update for apache-commons-daemon FEDORA-2011-10880
17472| [863466] Fedora Update for apache-commons-daemon FEDORA-2011-10936
17473| [855821] Solaris Update for Apache 1.3 122912-19
17474| [855812] Solaris Update for Apache 1.3 122911-19
17475| [855737] Solaris Update for Apache 1.3 122911-17
17476| [855731] Solaris Update for Apache 1.3 122912-17
17477| [855695] Solaris Update for Apache 1.3 122911-16
17478| [855645] Solaris Update for Apache 1.3 122912-16
17479| [855587] Solaris Update for kernel update and Apache 108529-29
17480| [855566] Solaris Update for Apache 116973-07
17481| [855531] Solaris Update for Apache 116974-07
17482| [855524] Solaris Update for Apache 2 120544-14
17483| [855494] Solaris Update for Apache 1.3 122911-15
17484| [855478] Solaris Update for Apache Security 114145-11
17485| [855472] Solaris Update for Apache Security 113146-12
17486| [855179] Solaris Update for Apache 1.3 122912-15
17487| [855147] Solaris Update for kernel update and Apache 108528-29
17488| [855077] Solaris Update for Apache 2 120543-14
17489| [850196] SuSE Update for apache2 openSUSE-SU-2012:0314-1 (apache2)
17490| [850088] SuSE Update for apache2 SUSE-SA:2007:061
17491| [850009] SuSE Update for apache2,apache SUSE-SA:2008:021
17492| [841209] Ubuntu Update for apache2 USN-1627-1
17493| [840900] Ubuntu Update for apache2 USN-1368-1
17494| [840798] Ubuntu Update for apache2 USN-1259-1
17495| [840734] Ubuntu Update for apache2 USN-1199-1
17496| [840542] Ubuntu Update for apache2 vulnerabilities USN-1021-1
17497| [840504] Ubuntu Update for apache2 vulnerability USN-990-2
17498| [840399] Ubuntu Update for apache2 vulnerabilities USN-908-1
17499| [840304] Ubuntu Update for apache2 vulnerabilities USN-575-1
17500| [840118] Ubuntu Update for libapache2-mod-perl2 vulnerability USN-488-1
17501| [840092] Ubuntu Update for apache2 vulnerabilities USN-499-1
17502| [840039] Ubuntu Update for libapache2-mod-python vulnerability USN-430-1
17503| [835253] HP-UX Update for Apache Web Server HPSBUX02645
17504| [835247] HP-UX Update for Apache-based Web Server HPSBUX02612
17505| [835243] HP-UX Update for Apache Running Tomcat Servlet Engine HPSBUX02579
17506| [835236] HP-UX Update for Apache with PHP HPSBUX02543
17507| [835233] HP-UX Update for Apache-based Web Server HPSBUX02531
17508| [835224] HP-UX Update for Apache-based Web Server HPSBUX02465
17509| [835200] HP-UX Update for Apache Web Server Suite HPSBUX02431
17510| [835190] HP-UX Update for Apache Web Server Suite HPSBUX02401
17511| [835188] HP-UX Update for Apache HPSBUX02308
17512| [835181] HP-UX Update for Apache With PHP HPSBUX02332
17513| [835180] HP-UX Update for Apache with PHP HPSBUX02342
17514| [835172] HP-UX Update for Apache HPSBUX02365
17515| [835168] HP-UX Update for Apache HPSBUX02313
17516| [835148] HP-UX Update for Apache HPSBUX01064
17517| [835139] HP-UX Update for Apache with PHP HPSBUX01090
17518| [835131] HP-UX Update for Apache HPSBUX00256
17519| [835119] HP-UX Update for Apache Remote Execution of Arbitrary Code HPSBUX02186
17520| [835104] HP-UX Update for Apache HPSBUX00224
17521| [835103] HP-UX Update for Apache mod_cgid HPSBUX00301
17522| [835101] HP-UX Update for Apache HPSBUX01232
17523| [835080] HP-UX Update for Apache HPSBUX02273
17524| [835078] HP-UX Update for ApacheStrong HPSBUX00255
17525| [835044] HP-UX Update for Apache HPSBUX01019
17526| [835040] HP-UX Update for Apache PHP HPSBUX00207
17527| [835025] HP-UX Update for Apache HPSBUX00197
17528| [835023] HP-UX Update for Apache HPSBUX01022
17529| [835022] HP-UX Update for Apache HPSBUX02292
17530| [835005] HP-UX Update for Apache HPSBUX02262
17531| [831759] Mandriva Update for apache-mod_security MDVSA-2012:182 (apache-mod_security)
17532| [831737] Mandriva Update for apache MDVSA-2012:154-1 (apache)
17533| [831534] Mandriva Update for apache MDVSA-2012:012 (apache)
17534| [831523] Mandriva Update for apache MDVSA-2012:003 (apache)
17535| [831491] Mandriva Update for apache MDVSA-2011:168 (apache)
17536| [831460] Mandriva Update for apache MDVSA-2011:144 (apache)
17537| [831449] Mandriva Update for apache MDVSA-2011:130 (apache)
17538| [831357] Mandriva Update for apache MDVSA-2011:057 (apache)
17539| [831132] Mandriva Update for apache MDVSA-2010:153 (apache)
17540| [831131] Mandriva Update for apache MDVSA-2010:152 (apache)
17541| [830989] Mandriva Update for apache-mod_auth_shadow MDVSA-2010:081 (apache-mod_auth_shadow)
17542| [830931] Mandriva Update for apache MDVSA-2010:057 (apache)
17543| [830926] Mandriva Update for apache MDVSA-2010:053 (apache)
17544| [830918] Mandriva Update for apache-mod_security MDVSA-2010:050 (apache-mod_security)
17545| [830799] Mandriva Update for apache-conf MDVSA-2009:300-2 (apache-conf)
17546| [830797] Mandriva Update for apache-conf MDVSA-2009:300-1 (apache-conf)
17547| [830791] Mandriva Update for apache-conf MDVA-2010:011 (apache-conf)
17548| [830652] Mandriva Update for apache MDVSA-2008:195 (apache)
17549| [830621] Mandriva Update for apache-conf MDVA-2008:129 (apache-conf)
17550| [830581] Mandriva Update for apache MDVSA-2008:016 (apache)
17551| [830294] Mandriva Update for apache MDKSA-2007:140 (apache)
17552| [830196] Mandriva Update for apache MDKSA-2007:235 (apache)
17553| [830112] Mandriva Update for apache MDKSA-2007:127 (apache)
17554| [830109] Mandriva Update for apache-mod_perl MDKSA-2007:083 (apache-mod_perl)
17555| [802425] Apache Struts2 Showcase Arbitrary Java Method Execution vulnerability
17556| [802423] Apache Struts CookBook/Examples Multiple Cross-Site Scripting Vulnerabilities
17557| [802422] Apache Struts Showcase Multiple Persistence Cross-Site Scripting Vulnerabilities
17558| [802415] Apache Tomcat Multiple Security Bypass Vulnerabilities (Win)
17559| [802385] Apache Tomcat Request Object Security Bypass Vulnerability (Win)
17560| [802384] Apache Tomcat Parameter Handling Denial of Service Vulnerability (Win)
17561| [802378] Apache Tomcat Hash Collision Denial Of Service Vulnerability
17562| [801942] Apache Archiva Multiple Vulnerabilities
17563| [801940] Apache Struts2 'XWork' Information Disclosure Vulnerability
17564| [801663] Apache Struts2/XWork Remote Command Execution Vulnerability
17565| [801521] Apache APR-util 'buckets/apr_brigade.c' Denial Of Service Vulnerability
17566| [801284] Apache Derby Information Disclosure Vulnerability
17567| [801203] Apache ActiveMQ Persistent Cross-Site Scripting Vulnerability
17568| [800837] Apache 'mod_deflate' Denial Of Service Vulnerability - July09
17569| [800827] Apache 'mod_proxy_http.c' Denial Of Service Vulnerability
17570| [800680] Apache APR Version Detection
17571| [800679] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
17572| [800678] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
17573| [800677] Apache Roller Version Detection
17574| [800279] Apache mod_jk Module Version Detection
17575| [800278] Apache Struts Cross Site Scripting Vulnerability
17576| [800277] Apache Tomcat mod_jk Information Disclosure Vulnerability
17577| [800276] Apache Struts Version Detection
17578| [800271] Apache Struts Directory Traversal Vulnerability
17579| [800024] Apache Tomcat RemoteFilterValve Security Bypass Vulnerability
17580| [103333] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
17581| [103293] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
17582| [103122] Apache Web Server ETag Header Information Disclosure Weakness
17583| [103074] Apache Continuum Cross Site Scripting Vulnerability
17584| [103073] Apache Continuum Detection
17585| [103053] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
17586| [101023] Apache Open For Business Weak Password security check
17587| [101020] Apache Open For Business HTML injection vulnerability
17588| [101019] Apache Open For Business service detection
17589| [100924] Apache Archiva Cross Site Request Forgery Vulnerability
17590| [100923] Apache Archiva Detection
17591| [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
17592| [100814] Apache Axis2 Document Type Declaration Processing Security Vulnerability
17593| [100813] Apache Axis2 Detection
17594| [100797] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
17595| [100795] Apache Derby Detection
17596| [100762] Apache CouchDB Cross Site Request Forgery Vulnerability
17597| [100725] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
17598| [100613] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
17599| [100514] Apache Multiple Security Vulnerabilities
17600| [100211] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
17601| [100172] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
17602| [100171] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
17603| [100130] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
17604| [72626] Debian Security Advisory DSA 2579-1 (apache2)
17605| [72612] FreeBSD Ports: apache22
17606| [71551] Gentoo Security Advisory GLSA 201206-25 (apache)
17607| [71550] Gentoo Security Advisory GLSA 201206-24 (apache tomcat)
17608| [71512] FreeBSD Ports: apache
17609| [71485] Debian Security Advisory DSA 2506-1 (libapache-mod-security)
17610| [71256] Debian Security Advisory DSA 2452-1 (apache2)
17611| [71238] Debian Security Advisory DSA 2436-1 (libapache2-mod-fcgid)
17612| [70737] FreeBSD Ports: apache
17613| [70724] Debian Security Advisory DSA 2405-1 (apache2)
17614| [70600] FreeBSD Ports: apache
17615| [70253] FreeBSD Ports: apache, apache-event, apache-itk, apache-peruser, apache-worker
17616| [70235] Debian Security Advisory DSA 2298-2 (apache2)
17617| [70233] Debian Security Advisory DSA 2298-1 (apache2)
17618| [69988] Debian Security Advisory DSA 2279-1 (libapache2-mod-authnz-external)
17619| [69338] Debian Security Advisory DSA 2202-1 (apache2)
17620| [67868] FreeBSD Ports: apache
17621| [66816] FreeBSD Ports: apache
17622| [66553] Mandriva Security Advisory MDVSA-2009:189-1 (apache-mod_auth_mysql)
17623| [66414] Mandriva Security Advisory MDVSA-2009:323 (apache)
17624| [66106] SuSE Security Advisory SUSE-SA:2009:050 (apache2,libapr1)
17625| [66081] SLES11: Security update for Apache 2
17626| [66074] SLES10: Security update for Apache 2
17627| [66070] SLES9: Security update for Apache 2
17628| [65998] SLES10: Security update for apache2-mod_python
17629| [65893] SLES10: Security update for Apache 2
17630| [65888] SLES10: Security update for Apache 2
17631| [65575] SLES9: Security update for apache2,apache2-prefork,apache2-worker
17632| [65510] SLES9: Security update for Apache 2
17633| [65472] SLES9: Security update for Apache
17634| [65467] SLES9: Security update for Apache
17635| [65450] SLES9: Security update for apache2
17636| [65390] SLES9: Security update for Apache2
17637| [65363] SLES9: Security update for Apache2
17638| [65309] SLES9: Security update for Apache and mod_ssl
17639| [65296] SLES9: Security update for webdav apache module
17640| [65283] SLES9: Security update for Apache2
17641| [65249] SLES9: Security update for Apache 2
17642| [65230] SLES9: Security update for Apache 2
17643| [65228] SLES9: Security update for Apache 2
17644| [65212] SLES9: Security update for apache2-mod_python
17645| [65209] SLES9: Security update for apache2-worker
17646| [65207] SLES9: Security update for Apache 2
17647| [65168] SLES9: Security update for apache2-mod_python
17648| [65142] SLES9: Security update for Apache2
17649| [65136] SLES9: Security update for Apache 2
17650| [65132] SLES9: Security update for apache
17651| [65131] SLES9: Security update for Apache 2 oes/CORE
17652| [65113] SLES9: Security update for apache2
17653| [65072] SLES9: Security update for apache and mod_ssl
17654| [65017] SLES9: Security update for Apache 2
17655| [64950] Mandrake Security Advisory MDVSA-2009:240 (apache)
17656| [64783] FreeBSD Ports: apache
17657| [64774] Ubuntu USN-802-2 (apache2)
17658| [64653] Ubuntu USN-813-2 (apache2)
17659| [64559] Debian Security Advisory DSA 1834-2 (apache2)
17660| [64532] Mandrake Security Advisory MDVSA-2009:189 (apache-mod_auth_mysql)
17661| [64527] Mandrake Security Advisory MDVSA-2009:184 (apache-mod_security)
17662| [64526] Mandrake Security Advisory MDVSA-2009:183 (apache-mod_security)
17663| [64500] Mandrake Security Advisory MDVSA-2009:168 (apache)
17664| [64443] Ubuntu USN-802-1 (apache2)
17665| [64426] Gentoo Security Advisory GLSA 200907-04 (apache)
17666| [64423] Debian Security Advisory DSA 1834-1 (apache2)
17667| [64391] Mandrake Security Advisory MDVSA-2009:149 (apache)
17668| [64377] Mandrake Security Advisory MDVSA-2009:124-1 (apache)
17669| [64251] Debian Security Advisory DSA 1816-1 (apache2)
17670| [64201] Ubuntu USN-787-1 (apache2)
17671| [64140] Mandrake Security Advisory MDVSA-2009:124 (apache)
17672| [64136] Mandrake Security Advisory MDVSA-2009:102 (apache)
17673| [63565] FreeBSD Ports: apache
17674| [63562] Ubuntu USN-731-1 (apache2)
17675| [61381] Gentoo Security Advisory GLSA 200807-06 (apache)
17676| [61185] FreeBSD Ports: apache
17677| [60582] Gentoo Security Advisory GLSA 200803-19 (apache)
17678| [60387] Slackware Advisory SSA:2008-045-02 apache
17679| [58826] FreeBSD Ports: apache-tomcat
17680| [58825] FreeBSD Ports: apache-tomcat
17681| [58804] FreeBSD Ports: apache
17682| [58745] Gentoo Security Advisory GLSA 200711-06 (apache)
17683| [58360] Debian Security Advisory DSA 1312-1 (libapache-mod-jk)
17684| [57851] Gentoo Security Advisory GLSA 200608-01 (apache)
17685| [57788] Debian Security Advisory DSA 1247-1 (libapache-mod-auth-kerb)
17686| [57335] Debian Security Advisory DSA 1167-1 (apache)
17687| [57201] Debian Security Advisory DSA 1131-1 (apache)
17688| [57200] Debian Security Advisory DSA 1132-1 (apache2)
17689| [57168] Slackware Advisory SSA:2006-209-01 Apache httpd
17690| [57145] FreeBSD Ports: apache
17691| [56731] Slackware Advisory SSA:2006-129-01 Apache httpd
17692| [56729] Slackware Advisory SSA:2006-130-01 Apache httpd redux
17693| [56246] Gentoo Security Advisory GLSA 200602-03 (Apache)
17694| [56212] Debian Security Advisory DSA 952-1 (libapache-auth-ldap)
17695| [56115] Debian Security Advisory DSA 935-1 (libapache2-mod-auth-pgsql)
17696| [56067] FreeBSD Ports: apache
17697| [55803] Slackware Advisory SSA:2005-310-04 apache
17698| [55519] Debian Security Advisory DSA 839-1 (apachetop)
17699| [55392] Gentoo Security Advisory GLSA 200509-12 (Apache)
17700| [55355] FreeBSD Ports: apache
17701| [55284] Debian Security Advisory DSA 807-1 (libapache-mod-ssl)
17702| [55261] Debian Security Advisory DSA 805-1 (apache2)
17703| [55259] Debian Security Advisory DSA 803-1 (apache)
17704| [55129] Gentoo Security Advisory GLSA 200508-15 (apache)
17705| [54739] Gentoo Security Advisory GLSA 200411-18 (apache)
17706| [54724] Gentoo Security Advisory GLSA 200411-03 (apache)
17707| [54712] Gentoo Security Advisory GLSA 200410-21 (apache)
17708| [54689] Gentoo Security Advisory GLSA 200409-33 (net=www/apache)
17709| [54677] Gentoo Security Advisory GLSA 200409-21 (apache)
17710| [54610] Gentoo Security Advisory GLSA 200407-03 (Apache)
17711| [54601] Gentoo Security Advisory GLSA 200406-16 (Apache)
17712| [54590] Gentoo Security Advisory GLSA 200406-05 (Apache)
17713| [54582] Gentoo Security Advisory GLSA 200405-22 (Apache)
17714| [54529] Gentoo Security Advisory GLSA 200403-04 (Apache)
17715| [54499] Gentoo Security Advisory GLSA 200310-04 (Apache)
17716| [54498] Gentoo Security Advisory GLSA 200310-03 (Apache)
17717| [54439] FreeBSD Ports: apache
17718| [53931] Slackware Advisory SSA:2004-133-01 apache
17719| [53903] Slackware Advisory SSA:2004-299-01 apache, mod_ssl, php
17720| [53902] Slackware Advisory SSA:2004-305-01 apache+mod_ssl
17721| [53878] Slackware Advisory SSA:2003-308-01 apache security update
17722| [53851] Debian Security Advisory DSA 135-1 (libapache-mod-ssl)
17723| [53849] Debian Security Advisory DSA 132-1 (apache-ssl)
17724| [53848] Debian Security Advisory DSA 131-1 (apache)
17725| [53784] Debian Security Advisory DSA 021-1 (apache)
17726| [53738] Debian Security Advisory DSA 195-1 (apache-perl)
17727| [53737] Debian Security Advisory DSA 188-1 (apache-ssl)
17728| [53735] Debian Security Advisory DSA 187-1 (apache)
17729| [53703] Debian Security Advisory DSA 532-1 (libapache-mod-ssl)
17730| [53577] Debian Security Advisory DSA 120-1 (libapache-mod-ssl, apache-ssl)
17731| [53568] Debian Security Advisory DSA 067-1 (apache,apache-ssl)
17732| [53519] Debian Security Advisory DSA 689-1 (libapache-mod-python)
17733| [53433] Debian Security Advisory DSA 181-1 (libapache-mod-ssl)
17734| [53282] Debian Security Advisory DSA 594-1 (apache)
17735| [53248] Debian Security Advisory DSA 558-1 (libapache-mod-dav)
17736| [53224] Debian Security Advisory DSA 532-2 (libapache-mod-ssl)
17737| [53215] Debian Security Advisory DSA 525-1 (apache)
17738| [53151] Debian Security Advisory DSA 452-1 (libapache-mod-python)
17739| [52529] FreeBSD Ports: apache+ssl
17740| [52501] FreeBSD Ports: apache
17741| [52461] FreeBSD Ports: apache
17742| [52390] FreeBSD Ports: apache
17743| [52389] FreeBSD Ports: apache
17744| [52388] FreeBSD Ports: apache
17745| [52383] FreeBSD Ports: apache
17746| [52339] FreeBSD Ports: apache+mod_ssl
17747| [52331] FreeBSD Ports: apache
17748| [52329] FreeBSD Ports: ru-apache+mod_ssl
17749| [52314] FreeBSD Ports: apache
17750| [52310] FreeBSD Ports: apache
17751| [15588] Detect Apache HTTPS
17752| [15555] Apache mod_proxy content-length buffer overflow
17753| [15554] Apache mod_include priviledge escalation
17754| [14771] Apache <= 1.3.33 htpasswd local overflow
17755| [14177] Apache mod_access rule bypass
17756| [13644] Apache mod_rootme Backdoor
17757| [12293] Apache Input Header Folding and mod_ssl ssl_io_filter_cleanup DoS Vulnerabilities
17758| [12280] Apache Connection Blocking Denial of Service
17759| [12239] Apache Error Log Escape Sequence Injection
17760| [12123] Apache Tomcat source.jsp malformed request information disclosure
17761| [12085] Apache Tomcat servlet/JSP container default files
17762| [11438] Apache Tomcat Directory Listing and File disclosure
17763| [11204] Apache Tomcat Default Accounts
17764| [11092] Apache 2.0.39 Win32 directory traversal
17765| [11046] Apache Tomcat TroubleShooter Servlet Installed
17766| [11042] Apache Tomcat DOS Device Name XSS
17767| [11041] Apache Tomcat /servlet Cross Site Scripting
17768| [10938] Apache Remote Command Execution via .bat files
17769| [10839] PHP.EXE / Apache Win32 Arbitrary File Reading Vulnerability
17770| [10773] MacOS X Finder reveals contents of Apache Web files
17771| [10766] Apache UserDir Sensitive Information Disclosure
17772| [10756] MacOS X Finder reveals contents of Apache Web directories
17773| [10752] Apache Auth Module SQL Insertion Attack
17774| [10704] Apache Directory Listing
17775| [10678] Apache /server-info accessible
17776| [10677] Apache /server-status accessible
17777| [10440] Check for Apache Multiple / vulnerability
17778|
17779| SecurityTracker - https://www.securitytracker.com:
17780| [1028865] Apache Struts Bugs Permit Remote Code Execution and URL Redirection Attacks
17781| [1028864] Apache Struts Wildcard Matching and Expression Evaluation Bugs Let Remote Users Execute Arbitrary Code
17782| [1028824] Apache mod_dav_svn URI Processing Flaw Lets Remote Users Deny Service
17783| [1028823] Apache Unspecified Flaw in mod_session_dbd Has Unspecified Impact
17784| [1028724] (HP Issues Fix for HP-UX) Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
17785| [1028722] (Red Hat Issues Fix for JBoss) Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
17786| [1028693] (Red Hat Issues Fix) Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
17787| [1028622] Apache Struts 'includeParams' Bugs Permit Remote Command Execution and Cross-Site Scripting Attacks
17788| [1028621] Apache Subversion Bugs Let Remote Authenticated Users Execute Arbitrary Commands and Deny Service
17789| [1028540] Apache mod_rewrite Input Validation Flaw Lets Remote Users Execute Arbitrary Commands
17790| [1028534] Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
17791| [1028533] Apache Tomcat Lack of Chunked Transfer Encoding Extension Size Limit Lets Remote Users Deny Service
17792| [1028532] Apache Tomcat AsyncListeners Bug May Disclose Information from One Request to Another User
17793| [1028515] Apache VCL Input Validation Flaw Lets Remote Authenticated Users Gain Elevated Privileges
17794| [1028457] Apache ActiveMQ Bugs Let Remote Users Conduct Cross-Site Scripting Attacks, Deny Service, and Obtain Potentially Sensitive Information
17795| [1028287] Apache CXF WSS4JInInterceptor Grants Service Access to Remote Users
17796| [1028286] Apache CXF WS-Security UsernameToken Processing Flaw Lets Remote Users Bypass Authentication
17797| [1028252] Apache Commons FileUpload Unsafe Temporary File Lets Local Users Gain Elevated Privileges
17798| [1028207] Apache Input Validation Bugs Permit Cross-Site Scripting Attacks
17799| [1027836] Apache Tomcat Connection Processing Bug Lets Remote Users Deny Service
17800| [1027834] Apache Tomcat Bug Lets Remote Users Bypass Cross-Site Request Forgery Prevention Filter
17801| [1027833] Apache Tomcat Bug Lets Remote Users Bypass Security Constraints
17802| [1027729] Apache Tomcat Header Processing Bug Lets Remote Users Deny Service
17803| [1027728] Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
17804| [1027554] Apache CXF Lets Remote Authenticated Users Execute Unauthorized SOAP Actions
17805| [1027508] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
17806| [1027421] Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
17807| [1027096] Apache Commons Compress BZip2CompressorOutputStream() Sorting Algorithm Lets Remote or Local Users Deny Service
17808| [1026932] Apache LD_LIBRARY_PATH Processing Lets Local Users Gain Elevated Privileges
17809| [1026928] Apache OFBiz Unspecified Flaw Lets Remote Users Execute Arbitrary Code
17810| [1026927] Apache OFBiz Input Validation Flaws Permit Cross-Site Scripting Attacks
17811| [1026847] Apache Traffic Server Host Header Processing Flaw Lets Remote Users Deny Service
17812| [1026846] Apache Wicket Discloses Hidden Application Files to Remote Users
17813| [1026839] Apache Wicket Input Validation Flaw in 'wicket:pageMapName' Parameter Permits Cross-Site Scripting Attacks
17814| [1026616] Apache Bugs Let Remote Users Deny Service and Obtain Cookie Data
17815| [1026575] Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
17816| [1026484] Apache Struts Bug Lets Remote Users Overwrite Files and Execute Arbitrary Code
17817| [1026477] Apache Tomcat Hash Table Collision Bug Lets Remote Users Deny Service
17818| [1026402] Apache Struts Conversion Error Lets Remote Users Inject Arbitrary Commands
17819| [1026353] Apache mod_proxy/mod_rewrite Bug Lets Remote Users Access Internal Servers
17820| [1026295] Apache Tomcat Lets Untrusted Web Applications Gain Elevated Privileges
17821| [1026267] Apache .htaccess File Integer Overflow Lets Local Users Execute Arbitrary Code
17822| [1026144] Apache mod_proxy Pattern Matching Bug Lets Remote Users Access Internal Servers
17823| [1026095] Apache Tomcat HTTP DIGEST Authentication Weaknesses Let Remote Users Conduct Bypass Attacks
17824| [1026054] Apache mod_proxy_ajp HTTP Processing Error Lets Remote Users Deny Service
17825| [1025993] Apache Tomcat AJP Protocol Processing Bug Lets Remote Users Bypass Authentication or Obtain Information
17826| [1025976] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
17827| [1025960] Apache httpd Byterange Filter Processing Error Lets Remote Users Deny Service
17828| [1025925] Apache Tomcat Commons Daemon jsvc Lets Local Users Gain Elevated Privileges
17829| [1025924] Apache Tomcat XML Validation Flaw Lets Applications Obtain Potentially Sensitive Information
17830| [1025788] Apache Tomcat Lets Malicious Applications Obtain Information and Deny Service
17831| [1025755] Apache Santuario Buffer Overflow Lets Remote Users Deny Service
17832| [1025712] Apache Tomcat Discloses Passwords to Local Users in Certain Cases
17833| [1025577] Apache Archiva Input Validation Hole Permits Cross-Site Scripting Attacks
17834| [1025576] Apache Archiva Request Validation Flaw Permits Cross-Site Request Forgery Attacks
17835| [1025527] Apache APR Library apr_fnmatch() Flaw Lets Remote Users Execute Arbitrary Code
17836| [1025303] Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
17837| [1025215] Apache Tomcat May Ignore @ServletSecurity Annotation Protections
17838| [1025066] Apache Continuum Input Validation Flaw Permits Cross-Site Request Forgery Attacks
17839| [1025065] Apache Continuum Input Validation Hole Permits Cross-Site Scripting Attacks
17840| [1025027] Apache Tomcat maxHttpHeaderSize Parsing Error Lets Remote Users Deny Service
17841| [1025026] Apache Tomcat Manager Input Validation Hole Permits Cross-Site Scripting Attacks
17842| [1025025] Apache Tomcat Security Manager Lets Local Users Bypass File Permissions
17843| [1024764] Apache Tomcat Manager Input Validation Hole in 'sessionList.jsp' Permits Cross-Site Scripting Attacks
17844| [1024417] Apache Traffic Server Insufficient Randomization Lets Remote Users Poison the DNS Cache
17845| [1024332] Apache mod_cache and mod_dav Request Processing Flaw Lets Remote Users Deny Service
17846| [1024180] Apache Tomcat 'Transfer-Encoding' Header Processing Flaw Lets Remote Users Deny Service and Obtain Potentially Sensitive Information
17847| [1024096] Apache mod_proxy_http May Return Results for a Different Request
17848| [1023942] Apache mod_proxy_ajp Error Condition Lets Remote Users Deny Service
17849| [1023941] Apache ap_read_request() Memory Error May Let Remote Users Access Potentially Sensitive Information
17850| [1023778] Apache ActiveMQ Input Validation Flaw Permits Cross-Site Scripting Attacks
17851| [1023701] Apache mod_isapi Error Processing Flaw May Let Remote Users Deny Service
17852| [1023533] Apache mod_proxy Integer Overflow May Let Remote Users Execute Arbitrary Code
17853| [1022988] Apache Solaris Support Code Bug Lets Remote Users Deny Service
17854| [1022529] Apache mod_deflate Connection State Bug Lets Remote Users Deny Service
17855| [1022509] Apache mod_proxy stream_reqbody_cl() Infinite Loop Lets Remote Users Deny Service
17856| [1022296] Apache IncludesNoExec Options Restrictions Can Be Bypass By Local Users
17857| [1022264] Apache mod_proxy_ajp Bug May Disclose Another User's Response Data
17858| [1022001] Apache Tomcat mod_jk May Disclose Responses to the Wrong User
17859| [1021988] mod_perl Input Validation Flaw in Apache::Status and Apache2::Status Permits Cross-Site Scripting Attacks
17860| [1021350] NetWare Bug Lets Remote Users Access the ApacheAdmin Console
17861| [1020635] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
17862| [1020520] Oracle WebLogic Apache Connector Lets Remote Users Execute Arbitrary Code
17863| [1020267] Apache mod_proxy Interim Response Process Bug Lets Remote Users Deny Service
17864| [1019784] Apache-SSL Certificate Processing Bug May Let Remote Users View Portions of Kernel Memory
17865| [1019256] Apache mod_negotiation Input Validation Hole Permits Cross-Site Scripting Attacks
17866| [1019194] Apache Input Validation Hole in Mod_AutoIndex When the Character Set is Undefined May Permit Cross-Site Scripting Attacks
17867| [1019185] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
17868| [1019154] Apache Input Validation Hole in mod_status Permits Cross-Site Scripting Attacks
17869| [1019093] Apache Input Validation Hole in mod_imap Permits Cross-Site Scripting Attacks
17870| [1019030] Apache Input Validation Hole in Default HTTP 413 Error Page Permits Cross-Site Scripting Attacks
17871| [1018633] Apache mod_proxy Bug Lets Remote Users Deny Service
17872| [1018304] Apache HTTPD scoreboard Protection Flaw Lets Local Users Terminate Arbitrary Processes
17873| [1018303] Apache HTTPD mod_cache May Let Remote Users Deny Service
17874| [1018302] Apache mod_status Input Validation Hole Permits Cross-Site Scripting Attacks
17875| [1018269] Apache Tomcat Input Validation Hole in Processing Accept-Language Header Permits Cross-Site Scripting Attacks
17876| [1017904] Apache suEXEC Bugs May Let Local Users Gain Elevated Privileges
17877| [1017719] Apache Tomcat JK Web Server Connector Buffer Overflow in map_uri_to_worker() Lets Remote Users Execute Arbitrary Code
17878| [1017062] Apache mod_tcl Format String Bug in set_var() Function May Let Remote Users Execute Arbitrary Code
17879| [1016601] Apache mod_rewrite Off-by-one Error Lets Remote Users Execute Arbitrary Code
17880| [1016576] Apache Tomcat Discloses Directory Listings to Remote Users
17881| [1015447] Apache mod_ssl Null Pointer Dereference May Let Remote Users Deny Service
17882| [1015344] Apache mod_imap Input Validation Flaw in Referer Field Lets Remote Users Conduct Cross-Site Scripting Attacks
17883| [1015093] Apache Memory Leak in MPM 'worker.c' Code May Let Remote Users Deny Service
17884| [1014996] ApacheTop Unsafe Temporary File May Let Local Users Gain Elevated Privileges
17885| [1014833] Apache ssl_hook_Access() Function May Fail to Verify Client Certificates
17886| [1014826] Apache Memory Leak in 'byterange filter' Lets Remote Users Deny Service
17887| [1014575] Apache mod_ssl Off-by-one Buffer Overflow in Processing CRLs May Let Remote Users Deny Service
17888| [1014323] Apache Chunked Transfer-Encoding and Content-Length Processing Lets Remote Users Smuggle HTTP Requests
17889| [1013156] Apache mod_python Publisher Handler Discloses Information to Remote Users
17890| [1012829] Apache mod_auth_radius radcpy() Integer Overflow Lets Remote Users Deny Service in Certain Cases
17891| [1012416] Apache on Apple OS X Lets Remote Users Bypass Apache File Handlers and Directly Access Files
17892| [1012415] Apache on Apple HFS+ Filesystems May Disclose '.DS_Store' Files to Remote Users
17893| [1012414] Apache mod_digest_apple Lets Remote Users Replay Authentication Credentials
17894| [1012083] Apache Web Server Error in Processing Requests With Many Space Characters Lets Remote Users Deny Service
17895| [1011783] Apache mod_include Buffer Overflow Lets Local Users Execute Arbitrary Code
17896| [1011557] Apache mod_ssl SSLCipherSuite Directive Can By Bypassed in Certain Cases
17897| [1011385] Apache Satsify Directive Error May Let Remote Users Access Restricted Resources
17898| [1011340] Apache SSL Connection Abort State Error Lets Remote Users Deny Service
17899| [1011303] Apache ap_resolve_env() Buffer Overflow in Reading Configuration Files May Let Local Users Gain Elevated Privileges
17900| [1011299] Apache IPv6 Address Parsing Flaw May Let Remote Users Deny Service
17901| [1011248] Apache mod_dav LOCK Method Error May Let Remote Users Deny Service
17902| [1011213] Apache mod_ssl Can Be Crashed By Remote Users When Reverse Proxying SSL Connections
17903| [1010674] Apache Can Be Crashed By PHP Code Invoking Nested Remote Sockets
17904| [1010599] Apache httpd Header Line Memory Allocation Lets Remote Users Crash the Server
17905| [1010462] Apache mod_proxy Buffer Overflow May Let Remote Users Execute Arbitrary Code
17906| [1010322] Apache mod_ssl Stack Overflow in ssl_util_uuencode_binary() May Let Remote Users Execute Arbitrary Code
17907| [1010270] cPanel Apache mod_phpsuexec Options Let Local Users Gain Elevated Privileges
17908| [1009934] Apache Web Server Has Buffer Overflow in ebcdic2ascii() on Older Processor Architectures
17909| [1009516] Apache mod_survey HTML Report Format Lets Remote Users Conduct Cross-Site Scripting Attacks
17910| [1009509] Apache mod_disk_cache Stores Authentication Credentials on Disk
17911| [1009495] Apache Web Server Socket Starvation Flaw May Let Remote Users Deny Service
17912| [1009417] GroupWise WebAccess With Apache on NetWare Has Configuration Flaw That May Grant Web Access to Remote Users
17913| [1009338] Apache mod_access Parsing Flaw May Fail to Enforce Allow/Deny Rules
17914| [1009337] Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon
17915| [1009182] Apache for Cygwin '..%5C' Input Validation Flaw Discloses Files to Remote Users
17916| [1008973] PHP May Apply Incorrect php_admin_* Settings To Requests for Apache Virtual Hosts
17917| [1008967] Apache-SSL 'SSLFakeBasicAuth' Lets Remote Users Forge Client Certificates to Be Authenticated
17918| [1008920] Apache mod_digest May Validate Replayed Client Responses
17919| [1008828] Apache mod_python String Processing Bug Still Lets Remote Users Crash the Web Server
17920| [1008822] Apache mod_perl File Descriptor Leak May Let Local Users Hijack the http and https Services
17921| [1008675] mod_auth_shadow Apache Module Authenticates Expired Passwords
17922| [1008559] Apache mod_php File Descriptor Leak May Let Local Users Hijack the https Service
17923| [1008335] Apache mod_python String Processing Bug Lets Remote Users Crash the Web Server
17924| [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
17925| [1008030] Apache mod_rewrite Contains a Buffer Overflow
17926| [1008029] Apache mod_alias Contains a Buffer Overflow
17927| [1008028] Apache mod_cgid May Disclose CGI Output to Another Client
17928| [1007995] Apache Cocoon Forms May Let Remote Users Execute Arbitrary Java Code on the System
17929| [1007993] Apache Cocoon 'view-source' Sample Script Discloses Files to Remote Users
17930| [1007823] Apache Web Server mod_cgi Error May Let Malicious CGI Scripts Crash the Web Service
17931| [1007664] Apache::Gallery Unsafe Temporary Files May Let Local Users Gain Apache Web Server Privileges
17932| [1007557] Apache Web Server Does Not Filter Terminal Escape Sequences From Log Files
17933| [1007230] Apache HTTP Server 'rotatelogs' Bug on Win32 and OS/2 May Cause the Logging to Stop
17934| [1007146] Apache HTTP Server FTP Proxy Bug May Cause Denial of Service Conditions
17935| [1007145] Apache 'accept()' Errors May Cause Denial of Service Conditions
17936| [1007144] Apache Web Server 'type-map' File Error Permits Local Denial of Service Attacks
17937| [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
17938| [1006864] Apache Web Server Can Be Crashed By Remote Users Via mod_dav Flaws and Also Via Basic Authentication
17939| [1006709] Apache mod_survey Input Validation Flaw Lets Remote Users Fill Up Disk Space
17940| [1006614] Apache mod_ntlm Buffer Overflow and Format String Flaw Let Remote Users Execute Arbitary Code
17941| [1006591] Apache mod_access_referer Module Null Pointer Dereference May Faciliate Denial of Service Attacks
17942| [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
17943| [1006021] Apache Tomcat Server URL Parsing Error May Disclose Otherwise Inaccessible Web Directory Listings and Files to Remote Users
17944| [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
17945| [1005962] Apache Web Server Path Parsing Flaw May Allow Remote Users to Execute Code in Certain Configurations
17946| [1005848] Apache 'printenv' Script Input Validation Bugs in Older Versions May Let Remote Users Conduct Cross-Site Scripting Attacks
17947| [1005765] Apache mod_jk Module Processing Bug When Used With Tomcat May Disclose Information to Remote Users or Crash
17948| [1005548] Apache mod_php Module May Allow Local Users to Gain Control of the Web Port
17949| [1005499] Apache Web Server (2.0.42) May Disclose CGI Source Code to Remote Users When Used With WebDAV
17950| [1005410] Apache Tomcat Java Servlet Engine Can Be Crashed Via Multiple Requests for DOS Device Names
17951| [1005351] Apache Web Server (1.3.x) Shared Memory Scoreboard Bug Lets Certain Local Users Issue Signals With Root Privileges
17952| [1005331] Apache Web Server (2.x) SSI Server Signature Filtering Hole Lets Remote Users Conduct Cross-Site Scripting Attacks
17953| [1005290] Apache Tomcat Java Server Default Servlet Returns JSP Source Code to Remote Users
17954| [1005285] Apache Web Server 'mod_dav' Has Null Pointer Bug That May Allow Remote Users to Cause Denial of Service Conditions
17955| [1005010] Apache Web Server (2.0) Has Unspecified Flaw That Allows Remote Users to Obtain Sensitive Data and Cause Denial of Service Conditions
17956| [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
17957| [1004745] Apache Tomcat Java Server Allows Cross-Site Scripting Attacks
17958| [1004636] Apache mod_ssl 'Off-by-One' Bug May Let Local Users Crash the Web Server or Possibly Execute Arbitrary Code
17959| [1004602] Apache Tomcat Java Server for Windows Can Be Crashed By Remote Users Sending Malicious Requests to Hang All Available Working Threads
17960| [1004586] Apache Tomcat Java Server May Disclose the Installation Path to Remote Users
17961| [1004555] Apache Web Server Chunked Encoding Flaw May Let Remote Users Execute Arbitrary Code on the Server
17962| [1004209] Apache 'mod_python' Python Language Interpreter Bug in Publisher Handler May Allow Remote Users to Modify Files on the System
17963| [1003874] Apache Web Server for Windows Has Batch File Processing Hole That Lets Remote Users Execute Commands on the System
17964| [1003767] 'mod_frontpage' Module for Apache Web Server Has Buffer Overlow in 'fpexec.c' That Allows Remote Users to Execute Arbitrary Code on the System with Root Privileges
17965| [1003723] Apache-SSL for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
17966| [1003664] 'mod_ssl' Security Package for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
17967| [1003602] GNUJSP Java Server Pages Implementation Discloses Web Files and Source Code to Remote Users and Bypasses Apache Access Control Restrictions
17968| [1003465] PHP for Apache Web Server May Disclose Installation Path Information to Remote Users Making 'OPTIONS' Requests
17969| [1003451] Oracle Application Server PL/SQL Module for Apache Has Buffer Overflows That Allow Remote Users to Execute Arbitrary Code and Gain Access to the Server
17970| [1003131] Apache Web Server in Virtual Hosting Mode Can Be Crashed By a Local User Removing a Log Directory
17971| [1003104] PHP.EXE Windows CGI for Apache Web Server May Let Remote Users View Files on the Server Due to Configuration Error
17972| [1003008] Apache 'mod_bf' Module Lets Remote Users Execute Arbitrary Code
17973| [1002629] Apache suEXEC Wrapper Fails to Observe Minimum Group ID Security Settings in Certain Situations
17974| [1002542] Apache Web Server Virtual Hosting Split-Logfile Function Lets Remote Users Write Log Entries to Arbitrary Files on the System
17975| [1002400] Apache mod_gzip Module Has Buffer Overflow That Can Be Exploited By Local Users to Gain Elevated Privileges
17976| [1002303] Several 3rd Party Apache Authentication Modules Allow Remote Users to Execute Arbitrary Code to Gain Access to the System or Execute Stored Procedures to Obtain Arbitrary Database Information
17977| [1002188] Apache Web Server Discloses Internal IP Addresses to Remote Users in Certain Configurations
17978| [1001989] Apache Web Server May Disclose Directory Contents Even If an Index.html File is Present in the Directory
17979| [1001719] Apache Web Server on Mac OS X Client Fails to Enforce File and Directory Access Protections, Giving Remote Users Access to Restricted Pages
17980| [1001572] Apache Web Server on Microsoft Windows Platforms Allows Remote Users to Crash the Web Server
17981| [1001304] Apache Web Server for Windows Lets Remote Users Crash the Web Server Application
17982| [1001083] Apache Web Server May Display Directory Index Listings Even if Directory Listings Are Disabled
17983|
17984| OSVDB - http://www.osvdb.org:
17985| [96078] Apache CloudStack Infrastructure Menu Setup Network Multiple Field XSS
17986| [96077] Apache CloudStack Global Settings Multiple Field XSS
17987| [96076] Apache CloudStack Instances Menu Display Name Field XSS
17988| [96075] Apache CloudStack Instances Menu Add Instances Network Name Field XSS
17989| [96074] Apache CloudStack Instances Menu Add Instances Review Step Multiple Field XSS
17990| [96031] Apache HTTP Server suEXEC Symlink Arbitrary File Access
17991| [95888] Apache Archiva Single / Double Quote Character Handling XSS Weakness
17992| [95885] Apache Subversion mod_dav_svn Module Crafted HTTP Request Handling Remote DoS
17993| [95706] Apache OpenOffice.org (OOo) OOXML Document File XML Element Handling Memory Corruption
17994| [95704] Apache OpenOffice.org (OOo) DOC File PLCF Data Handling Memory Corruption
17995| [95603] Apache Continuum web/util/GenerateRecipentNotifier.java recipient Parameter XSS
17996| [95602] Apache Continuum web/action/notifier/JabberProjectNotifierEditAction-jabberProjectNotifierSave-validation.xml Multiple Parameter XSS
17997| [95601] Apache Continuum web/action/notifier/JabberGroupNotifierEditAction-jabberProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
17998| [95600] Apache Continuum web/action/ScheduleAction-saveSchedule-validation.xml Multiple Parameter XSS
17999| [95599] Apache Continuumweb/action/BuildDefinitionAction-saveBuildDefinition-validation.xml Multiple Parameter XSS
18000| [95598] Apache Continuum web/action/AddProjectAction-addProject-validation.xml Multiple Parameter XSS
18001| [95597] Apache Continuum web/action/ProjectEditAction-projectSave-validation.xml Multiple Parameter XSS
18002| [95596] Apache Continuum web/action/notifier/IrcGroupNotifierEditAction-ircProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
18003| [95595] Apache Continuum web/action/notifier/IrcProjectNotifierEditAction-ircProjectNotifierSave-validation.xml Multiple Parameter XSS
18004| [95594] Apache Continuum web/action/ProjectGroupAction.java Multiple Parameter XSS
18005| [95593] Apache Continuum web/action/AddProjectGroupAction.java Multiple Parameter XSS
18006| [95592] Apache Continuum web/action/AddProjectAction.java Multiple Parameter XSS
18007| [95523] Apache OFBiz Webtools Application View Log Screen Unspecified XSS
18008| [95522] Apache OFBiz Nested Expression Evaluation Arbitrary UEL Function Execution
18009| [95521] Apache HTTP Server mod_session_dbd Session Saving Unspecified Issue
18010| [95498] Apache HTTP Server mod_dav.c Crafted MERGE Request Remote DoS
18011| [95406] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Arbitrary Site Redirect
18012| [95405] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Remote Code Execution
18013| [95011] Apache CXF XML Parser SOAP Message Handling CPU Resource Exhaustion Remote DoS
18014| [94705] Apache Geronimo RMI Classloader Exposure Serialized Object Handling Remote Code Execution
18015| [94651] Apache Santuario (XML Security for C++) XML Signature CanonicalizationMethod Parameter Spoofing Weakness
18016| [94636] Apache Continuum workingCopy.action userDirectory Traversal Arbitrary File Access
18017| [94635] Apache Maven SCM SvnCommandlineUtils Process Listing Local Password Disclosure
18018| [94632] Apache Maven Wagon SSH (wagon-ssh) Host Verification Failure MitM Weakness
18019| [94625] Apache Santuario (XML Security for C++) XML Signature Reference Crafted XPointer Expression Handling Heap Buffer Overflow
18020| [94618] Apache Archiva /archiva/security/useredit.action username Parameter XSS
18021| [94617] Apache Archiva /archiva/security/roleedit.action name Parameter XSS
18022| [94616] Apache Archiva /archiva/security/userlist!show.action roleName Parameter XSS
18023| [94615] Apache Archiva /archiva/deleteArtifact!doDelete.action groupId Parameter XSS
18024| [94614] Apache Archiva /archiva/admin/addLegacyArtifactPath!commit.action legacyArtifactPath.path Parameter XSS
18025| [94613] Apache Archiva /archiva/admin/addRepository.action Multiple Parameter XSS
18026| [94612] Apache Archiva /archiva/admin/editAppearance.action Multiple Parameter XSS
18027| [94611] Apache Archiva /archiva/admin/addLegacyArtifactPath.action Multiple Parameter XSS
18028| [94610] Apache Archiva /archiva/admin/addNetworkProxy.action Multiple Parameter XSS
18029| [94403] Apache Santuario (XML Security for C++) InclusiveNamespace PrefixList Processing Heap Overflow
18030| [94402] Apache Santuario (XML Security for C++) HMAC-based XML Signature Processing DoS
18031| [94401] Apache Santuario (XML Security for C++) XPointer Evaluation Stack Overflow
18032| [94400] Apache Santuario (XML Security for C++) HMAC-Based XML Signature Reference Element Validation Spoofing Weakness
18033| [94279] Apache Qpid CA Certificate Validation Bypass
18034| [94275] Apache Solr JettySolrRunner.java Can Not Find Error Message XSS
18035| [94233] Apache OpenJPA Object Deserialization Arbitrary Executable Creation
18036| [94042] Apache Axis JAX-WS Java Unspecified Exposure
18037| [93969] Apache Struts OGNL Expression Handling Double Evaluation Error Remote Command Execution
18038| [93796] Apache Subversion Filename Handling FSFS Repository Corruption Remote DoS
18039| [93795] Apache Subversion svnserve Server Aborted Connection Message Handling Remote DoS
18040| [93794] Apache Subversion contrib/hook-scripts/check-mime-type.pl svnlook Hyphenated argv Argument Handling Remote DoS
18041| [93793] Apache Subversion contrib/hook-scripts/svn-keyword-check.pl Filename Handling Remote Command Execution
18042| [93646] Apache Struts Crafted Parameter Arbitrary OGNL Code Execution
18043| [93645] Apache Struts URL / Anchor Tag includeParams Attribute Remote Command Execution
18044| [93636] Apache Pig Multiple Physical Operator Memory Exhaustion Remote Remote DoS
18045| [93635] Apache Wink DTD (Document Type Definition) Expansion Data Parsing Information Disclosure
18046| [93605] RT Apache::Session::File Session Replay Reuse Information Disclosure
18047| [93599] Apache Derby SYSCS_UTIL.SYSCS_SET_DATABASE_PROPERTY Boot Password Manipulation Re-encryption Failure Password Corruption
18048| [93555] Apache Commons Codec Invalid Base32 String Information Tunneling Weakness
18049| [93554] Apache HBase bulkLoadHFiles() Method ACL Bypass
18050| [93543] JBoss Enterprise Application Platform org.apache.catalina.connector.Response.encodeURL() Method MitM jsessionid Disclosure
18051| [93542] Apache ManifoldCF (Connectors Framework) org.apache.manifoldcf.crawler.ExportConfiguration Class Configuration Export Password Disclosure
18052| [93541] Apache Solr json.wrf Callback XSS
18053| [93524] Apache Hadoop GetSecurityDescriptorControl() Function Absolute Security Descriptor Handling NULL Descriptor Weakness
18054| [93521] Apache jUDDI Security API Token Session Persistence Weakness
18055| [93520] Apache CloudStack Default SSL Key Weakness
18056| [93519] Apache Shindig /ifr Cross-site Arbitrary Gadget Invocation
18057| [93518] Apache Solr /admin/analysis.jsp name Parameter XSS
18058| [93517] Apache CloudStack setup-cloud-management /etc/sudoers Modification Local Privilege Escalation
18059| [93516] Apache CXF UsernameTokenInterceptor Nonce Caching Replay Weakness
18060| [93515] Apache HBase table.jsp name Parameter XSS
18061| [93514] Apache CloudStack Management Server Unauthenticated Remote JMX Connection Default Setting Weakness
18062| [93463] Apache Struts EL / OGNL Interpretation Unspecified Remote Code Execution
18063| [93462] Apache CXF WS-SecurityPolicy AlgorithmSuite Arbitrary Ciphertext Decryption Weakness
18064| [93401] Apache Hadoop core-site.xml Permission Weakness Local Alfredo Secret Disclosure
18065| [93400] Apache Hadoop Map/Reduce Job Log Directory Symlink Arbitrary File Mode Manipulation
18066| [93397] Apache Wicket Referrer HTTP Header Session ID Disclosure
18067| [93366] Apache HTTP Server modules/mappers/mod_rewrite.c do_rewritelog() Function Log File Terminal Escape Sequence Filtering Remote Command Execution
18068| [93254] Apache Tomcat AsyncListener Method Cross-session Information Disclosure
18069| [93253] Apache Tomcat Chunked Transfer Encoding Data Saturation Remote DoS
18070| [93252] Apache Tomcat FORM Authenticator Session Fixation
18071| [93172] Apache Camel camel/endpoints/ Endpoint XSS
18072| [93171] Apache Sling HtmlResponse Error Message XSS
18073| [93170] Apache Directory DelegatingAuthenticator MitM Spoofing Weakness
18074| [93169] Apache Wave AuthenticationServlet.java Session Fixation Weakness
18075| [93168] Apache Click ErrorReport.java id Parameter XSS
18076| [93167] Apache ActiveMQ JMSXUserId Spoofing Weakness
18077| [93166] Apache CXF Crafted Message Element Count Handling System Resource Exhaustion Remote DoS
18078| [93165] Apache CXF Crafted Message Element Level Handling System Resource Exhaustion Remote DoS
18079| [93164] Apache Harmony DatagramSocket Class connect Method CheckAccept() IP Blacklist Bypass
18080| [93163] Apache Hadoop Map/Reduce Daemon Symlink Arbitrary File Overwrite
18081| [93162] Apache VelocityStruts struts/ErrorsTool.getMsgs Error Message XSS
18082| [93161] Apache CouchDB Rewriter VM Atom Table Memory Exhaustion Remote DoS
18083| [93158] Apache Wicket BookmarkablePageLink Feature XSS CSRF
18084| [93157] Apache Struts UrlHelper.java s:url includeParams Functionality XSS
18085| [93156] Apache Tapestry Calendar Component datefield.js datefield Parameter XSS
18086| [93155] Apache Struts fielderror.ftl fielderror Parameter Error Message XSS
18087| [93154] Apache JSPWiki Edit.jsp createPages WikiPermission Bypass
18088| [93153] Apache PDFBox PDFXrefStreamParser Missing Element Handling PDF Parsing DoS
18089| [93152] Apache Hadoop HttpServer.java Multiple Function XSS
18090| [93151] Apache Shiro Search Filter userName Parameter LDAP Code Injection Weakness
18091| [93150] Apache Harmony java.net.SocketPermission Class boolean equals Function checkConnect() Weakness Host Name Retrieval
18092| [93149] Apache Harmony java.security.Provider Class void load Function checkSecurityAccess() Weakness
18093| [93148] Apache Harmony java.security.ProtectionDomain Class java.lang.String.toString() Function checkPermission() Weakness
18094| [93147] Apache Harmony java.net.URLConnection openConnection Function checkConnect Weakness Proxy Connection Permission Bypass
18095| [93146] Apache Harmony java.net.ServerSocket Class void implAccept Function checkAccept() Weakness SerSocket Subclass Creation
18096| [93145] Apache Qpid JMS Client Detached Session Frame Handling NULL Pointer Dereference Remote DoS
18097| [93144] Apache Solr Admin Command Execution CSRF
18098| [93009] Apache VCL XMLRPC API Unspecified Function Remote Privilege Escalation
18099| [93008] Apache VCL Web GUI Unspecified Remote Privilege Escalation
18100| [92997] Apache Commons Codec org.apache.commons.codec.net.URLCodec Fields Missing 'final' Thread-safety Unspecified Issue
18101| [92976] Apache ActiveMQ scheduled.jsp crontab Command XSS
18102| [92947] Apache Commons Codec org.apache.commons.codec.language.Soundex.US_ENGLISH_MAPPING Missing MS_PKGPROTECT Field Manipulation Unspecified Issue
18103| [92749] Apache CloudStack Predictable Hash Virtual Machine Console Console Access URL Generation
18104| [92748] Apache CloudStack VM Console Access Restriction Bypass
18105| [92709] Apache ActiveMQ Web Console Unauthenticated Remote Access
18106| [92708] Apache ActiveMQ Sample Web Application Broker Resource Consumption Remote DoS
18107| [92707] Apache ActiveMQ webapp/websocket/chat.js Subscribe Message XSS
18108| [92706] Apache ActiveMQ Debug Log Rendering XSS
18109| [92705] Apache ActiveMQ PortfolioPublishServlet.java refresh Parameter XSS
18110| [92270] Apache Tomcat Unspecified CSRF
18111| [92094] Apache Subversion mod_dav_svn Module Nonexistent URL Lock Request Handling NULL Pointer Dereference Remote DoS
18112| [92093] Apache Subversion mod_dav_svn Module Activity URL PROPFIND Request Handling NULL Pointer Dereference Remote DoS
18113| [92092] Apache Subversion mod_dav_svn Module Log REPORT Request Handling NULL Pointer Dereference Remote DoS
18114| [92091] Apache Subversion mod_dav_svn Module Node Property Handling Resource Exhaustion Remote DoS
18115| [92090] Apache Subversion mod_dav_svn Module Activity URL Lock Request Handling NULL Pointer Dereference Remote DoS
18116| [91774] Apache Commons Codec Unspecified Non-private Field Manipulation Weakness
18117| [91628] mod_ruid2 for Apache HTTP Server fchdir() Inherited File Descriptor chroot Restriction Bypass
18118| [91328] Apache Wicket $up$ Traversal Arbitrary File Access
18119| [91295] Apple Mac OS X Apache Unicode Character URI Handling Authentication Bypass
18120| [91235] Apache Rave /app/api/rpc/users/get User Object Hashed Password Remote Disclosure
18121| [91185] Munin Default Apache Configuration Permission Weakness Remote Information Disclosure
18122| [91173] Apache Wicket WebApplicationPath Constructor Bypass /WEB-INF/ Directory File Access
18123| [91172] Apache Wicket PackageResourceGuard File Extension Filter Bypass
18124| [91025] Apache Qpid qpid::framing::Buffer Class Multiple Method Out-of-bounds Access Remote DoS
18125| [91024] Apache Qpid federation_tag Attribute Handling Federated Interbroker Link Access Restriction Bypass
18126| [91023] Apache Qpid AMQP Type Decoder Exposure Array Size Value Handling Memory Consumption Remote DoS
18127| [91022] Apache Qpid qpid/cpp/include/qpid/framing/Buffer.h qpid::framing::Buffer::checkAvailable() Function Integer Overflow
18128| [90986] Apache Jena ARQ INSERT DATA Request Handling Overflow
18129| [90907] Apache Subversion mod_dav_svn / libsvn_fs svn_fs_file_length() Function MKACTIVITY / PROPFIND Option Request Handling Remote DoS
18130| [90906] Apache Commons FileUpload /tmp Storage Symlink Arbitrary File Overwrite
18131| [90864] Apache Batik 1xx Redirect Script Origin Restriction Bypass
18132| [90858] Apache Ant Malformed TAR File Handling Infinite Loop DoS
18133| [90852] Apache HTTP Server for Debian apachectl /var/lock Permission Weakness Symlink Directory Permission Manipulation
18134| [90804] Apache Commons CLI Path Subversion Local Privilege Escalation
18135| [90802] Apache Avro Recursive Schema Handling Infinite Recursion DoS
18136| [90592] Apache Batik ApplicationSecurityEnforcer.java Multiple Method Security Restriction Bypass
18137| [90591] Apache Batik XML External Entity (XXE) Data Parsing Arbitrary File Disclosure
18138| [90565] Apache Tomcat Log Directory Permission Weakness Local Information Disclosure
18139| [90564] Apache Maven / Maven Wagon SSL Certificate Validation MitM Spoofing Weakness
18140| [90557] Apache HTTP Server mod_proxy_balancer balancer-manager Interface Multiple Parameter XSS
18141| [90556] Apache HTTP Server Multiple Module Multiple Parameter XSS
18142| [90276] Apache Axis2 axis2.xml Plaintext Password Local Disclosure
18143| [90249] Apache Axiom ClassLoader XMLInputFactory / XMLOutputFactory Construction Unspecified Issue
18144| [90235] Apache Commons HttpClient Certificate Wildcard Matching Weakness
18145| [90079] Apache CXF WSS4JInInterceptor URIMappingInterceptor WS-Security SOAP Service Access Restriction Bypass
18146| [90078] Apache CXF WS-SecurityPolicy Enabled Plaintext UsernameTokens Handling Authentication Bypass
18147| [89453] Apache Open For Business Project (OFBiz) Screenlet.title Widget Attribute XSS
18148| [89452] Apache Open For Business Project (OFBiz) Image.alt Widget Attribute XSS
18149| [89294] Apache CouchDB Futon UI Browser-based Test Suite Query Parameter XSS
18150| [89293] Apache CouchDB Unspecified Traversal Arbitrary File Access
18151| [89275] Apache HTTP Server mod_proxy_ajp Module Expensive Request Parsing Remote DoS
18152| [89267] Apache CouchDB JSONP Callback Handling Unspecified XSS
18153| [89146] Apache CloudStack Master Server log4j.conf SSH Private Key / Plaintext Password Disclosure
18154| [88603] Apache OpenOffice.org (OOo) Unspecified Information Disclosure
18155| [88602] Apache OpenOffice.org (OOo) Unspecified Manifest-processing Issue
18156| [88601] Apache OpenOffice.org (OOo) Unspecified PowerPoint File Handling Issue
18157| [88285] Apache Tomcat Partial HTTP Request Saturation Remote DoS
18158| [88095] Apache Tomcat NIO Connector Terminated Connection Infinte Loop DoS
18159| [88094] Apache Tomcat FORM Authentication Crafted j_security_check Request Security Constraint Bypass
18160| [88093] Apache Tomcat Null Session Requst CSRF Prevention Filter Bypass
18161| [88043] IBM Tivoli Netcool/Reporter Apache CGI Unspecified Remote Command Execution
18162| [87580] Apache Tomcat DIGEST Authentication Session State Caching Authentication Bypass Weakness
18163| [87579] Apache Tomcat DIGEST Authentication Stale Nonce Verification Authentication Bypass Weakness
18164| [87477] Apache Tomcat Project Woodstock Service Error Page UTF-7 XSS Weakness
18165| [87227] Apache Tomcat InternalNioInputBuffer.java parseHeaders() Function Request Header Size Parsing Remote DoS
18166| [87223] Apache Tomcat DIGEST Authentication replay-countermeasure Functionality cnonce / cn Verification Authentication Bypass Weakness
18167| [87160] Apache Commons HttpClient X.509 Certificate Domain Name Matching MiTM Weakness
18168| [87159] Apache CXF X.509 Certificate Domain Name Matching MiTM Weakness
18169| [87150] Apache Axis / Axis2 X.509 Certificate Domain Name Matching MiTM Weakness
18170| [86902] Apache HTTP Server 3xx Redirect Internal IP Address Remote Disclosure
18171| [86901] Apache Tomcat Error Message Path Disclosure
18172| [86684] Apache CloudStack Unauthorized Arbitrary API Call Invocation
18173| [86556] Apache Open For Business Project (OFBiz) Unspecified Issue
18174| [86503] Visual Tools VS home/apache/DiskManager/cron/init_diskmgr Local Command Execution
18175| [86401] Apache ActiveMQ ResourceHandler Traversal Arbitrary File Access
18176| [86225] Apache Axis2 XML Signature Wrapping (XSW) Authentication Bypass
18177| [86206] Apache Axis2 Crafted SAML Assertion Signature Exclusion Attack Authentication Bypass
18178| [85722] Apache CXF SOAP Request Parsing Access Restriction Bypass
18179| [85704] Apache Qpid Incoming Client Connection Saturation Remote DoS
18180| [85474] Eucalyptus Apache Santuario (XML Security for Java) Library XML Signature Transform Handling DoS
18181| [85430] Apache mod_pagespeed Module Unspecified XSS
18182| [85429] Apache mod_pagespeed Module Hostname Verification Cross-host Resource Disclosure
18183| [85249] Apache Wicket Unspecified XSS
18184| [85236] Apache Hadoop conf/hadoop-env.sh Temporary File Symlink Arbitrary File Manipulation
18185| [85090] Apache HTTP Server mod_proxy_ajp.c mod_proxy_ajp Module Proxy Functionality Cross-client Information Disclosure
18186| [85089] Apache HTTP Server mod_proxy_http.c mod_proxy_http Module Cross-client Information Disclosure
18187| [85062] Apache Solr Autocomplete Module for Drupal Autocomplete Results XSS
18188| [85010] Apache Struts Token Handling Mechanism Token Name Configuration Parameter CSRF Weakness
18189| [85009] Apache Struts Request Parameter OGNL Expression Parsing Remote DoS
18190| [84911] libapache2-mod-rpaf X-Forward-For HTTP Header Parsing Remote DoS
18191| [84823] Apache HTTP Server Multiple Module Back End Server Error Handling HTTP Request Parsing Remote Information Disclosure
18192| [84818] Apache HTTP Server mod_negotiation Module mod_negotiation.c make_variant_list Function XSS
18193| [84562] Apache Qpid Broker Authentication Mechanism AMQP Client Shadow Connection NullAuthenticator Request Parsing Authentication Bypass
18194| [84458] Apache Libcloud SSL Certificate Validation MitM Spoofing Weakness
18195| [84279] PHP on Apache php_default_post_reader POST Request Handling Overflow DoS
18196| [84278] PHP w/ Apache PDO::ATTR_DEFAULT_FETCH_MODE / PDO::FETCH_CLASS DoS
18197| [84231] Apache Hadoop DataNodes Client BlockTokens Arbitrary Block Access
18198| [83943] Oracle Solaris Cluster Apache Tomcat Agent Subcomponent Unspecified Local Privilege Escalation
18199| [83939] Oracle Solaris Apache HTTP Server Subcomponent Unspecified Remote Information Disclosure
18200| [83685] svnauthcheck Apache HTTP Configuration File Permission Revocation Weakness
18201| [83682] Apache Sling POST Servlet @CopyFrom Operation HTTP Request Parsing Infinite Loop Remote DoS
18202| [83339] Apache Roller Blogger Roll Unspecified XSS
18203| [83270] Apache Roller Unspecified Admin Action CSRF
18204| [82782] Apache CXF WS-SecurityPolicy 1.1 SupportingToken Policy Bypass
18205| [82781] Apache CXF WS-SecurityPolicy Supporting Token Children Specification Token Signing Verification Weakness
18206| [82611] cPanel Apache Piped Log Configuration Log Message Formatting Traversal Arbitrary File Creation
18207| [82436] MapServer for Windows Bundled Apache / PHP Configuration Local File Inclusion
18208| [82215] PHP sapi/cgi/cgi_main.c apache_request_headers Function HTTP Header Handling Remote Overflow
18209| [82161] Apache Commons Compress bzip2 File Compression BZip2CompressorOutputStream Class File Handling Remote DoS
18210| [81965] Apache Batik Squiggle SVG Browser JAR File Arbitrary Code Execution
18211| [81790] Apache POI src/org/apache/poi/hwpf/model/UnhandledDataStructure.java UnhandledDataStructure() constructor Length Attribute CDF / CFBF File Handling Remote DoS
18212| [81660] Apache Qpid Credential Checking Cluster Authentication Bypass
18213| [81511] Apache for Debian /usr/share/doc HTTP Request Parsing Local Script Execution
18214| [81359] Apache HTTP Server LD_LIBRARY_PATH Variable Local Privilege Escalation
18215| [81349] Apache Open For Business Project (OFBiz) Webslinger Component Unspecified XSS
18216| [81348] Apache Open For Business Project (OFBiz) Content IDs / Map-Keys Unspecified XSS
18217| [81347] Apache Open For Business Project (OFBiz) Parameter Arrays Unspecified XSS
18218| [81346] Apache Open For Business Project (OFBiz) checkoutProcess.js getServerError() Function Unspecified XSS
18219| [81196] Apache Open For Business Project (OFBiz) FlexibleStringExpander Nested Script String Parsing Remote Code Execution
18220| [80981] Apache Hadoop Kerberos/MapReduce Security Feature User Impersonation Weakness
18221| [80571] Apache Traffic Server Host HTTP Header Parsing Remote Overflow
18222| [80547] Apache Struts XSLTResult.java File Upload Arbitrary Command Execution
18223| [80360] AskApache Password Protector Plugin for WordPress Error Page $_SERVER Superglobal XSS
18224| [80349] Apache HTTP Server mod_fcgid Module fcgid_spawn_ctl.c FcgidMaxProcessesPerClass Virtual Host Directive HTTP Request Parsing Remote DoS
18225| [80301] Apache Wicket /resources/ Absolute Path Arbitrary File Access
18226| [80300] Apache Wicket wicket:pageMapName Parameter XSS
18227| [79478] Apache Solr Extension for TYPO3 Unspecified XSS
18228| [79002] Apache MyFaces javax.faces.resource In Parameter Traversal Arbitrary File Access
18229| [78994] Apache Struts struts-examples/upload/upload-submit.do name Parameter XSS
18230| [78993] Apache Struts struts-cookbook/processDyna.do message Parameter XSS
18231| [78992] Apache Struts struts-cookbook/processSimple.do message Parameter XSS
18232| [78991] Apache Struts struts2-rest-showcase/orders clientName Parameter XSS
18233| [78990] Apache Struts struts2-showcase/person/editPerson.action Multiple Parameter XSS
18234| [78932] Apache APR Hash Collision Form Parameter Parsing Remote DoS
18235| [78903] Apache CXF SOAP Request Parsing WS-Security UsernameToken Policy Bypass
18236| [78600] Apache Tomcat HTTP DIGEST Authentication DigestAuthenticator.java Catalina Weakness Security Bypass
18237| [78599] Apache Tomcat HTTP DIGEST Authentication Realm Value Parsing Security Bypass
18238| [78598] Apache Tomcat HTTP DIGEST Authentication qop Value Parsing Security Bypass
18239| [78573] Apache Tomcat Parameter Saturation CPU Consumption Remote DoS
18240| [78556] Apache HTTP Server Status Code 400 Default Error Response httpOnly Cookie Disclosure
18241| [78555] Apache HTTP Server Threaded MPM %{cookiename}C Log Format String Cookie Handling Remote DoS
18242| [78501] Apache Struts ParameterInterceptor Class OGNL Expression Parsing Remote Command Execution
18243| [78331] Apache Tomcat Request Object Recycling Information Disclosure
18244| [78293] Apache HTTP Server Scoreboard Invalid Free Operation Local Security Bypass
18245| [78277] Apache Struts ExceptionDelegator Component Parameter Parsing Remote Code Execution
18246| [78276] Apache Struts DebuggingInterceptor Component Developer Mode Unspecified Remote Command Execution
18247| [78113] Apache Tomcat Hash Collision Form Parameter Parsing Remote DoS
18248| [78112] Apache Geronimo Hash Collision Form Parameter Parsing Remote DoS
18249| [78109] Apache Struts ParameterInterceptor Traversal Arbitrary File Overwrite
18250| [78108] Apache Struts CookieInterceptor Cookie Name Handling Remote Command Execution
18251| [77593] Apache Struts Conversion Error OGNL Expression Injection
18252| [77496] Apache ActiveMQ Failover Mechanism Openwire Request Parsing Remote DoS
18253| [77444] Apache HTTP Server mod_proxy Mdule Web Request HTTP/0.9 Protocol URL Parsing Proxy Remote Security Bypass
18254| [77374] Apache MyFaces Java Bean includeViewParameters Parsing EL Expression Security Weakness
18255| [77310] Apache HTTP Server mod_proxy Reverse Proxy Mode Security Bypass Weakness (2011-4317)
18256| [77234] Apache HTTP Server on cygwin Encoded Traversal Arbitrary File Access
18257| [77012] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Memory Consumption DoS
18258| [76944] Apache Tomcat Manager Application Servlets Access Restriction Bypass
18259| [76744] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Overflow
18260| [76189] Apache Tomcat HTTP DIGEST Authentication Weakness
18261| [76079] Apache HTTP Server mod_proxy Mdule Web Request URL Parsing Proxy Remote Security Bypass (2011-3368)
18262| [76072] Apache JServ jserv.conf jserv-status Handler jserv/ URI Request Parsing Local Information Disclosure
18263| [75807] Apache HTTP Server Incomplete Header Connection Saturation Remote DoS
18264| [75647] Apache HTTP Server mod_proxy_ajp Module mod_proxy_balancer HTTP Request Remote DoS
18265| [75376] Apache Libcloud SSL Certificate Validation MitM Server Spoofing Weakness
18266| [74853] Domain Technologie Control /etc/apache2/apache2.conf File Permissions Weakness dtcdaemons User Password Disclosure
18267| [74818] Apache Tomcat AJP Message Injection Authentication Bypass
18268| [74725] Apache Wicket Multi Window Support Unspecified XSS
18269| [74721] Apache HTTP Server ByteRange Filter Memory Exhaustion Remote DoS
18270| [74541] Apache Commons Daemon Jsvc Permissions Weakness Arbitrary File Access
18271| [74535] Apache Tomcat XML Parser Cross-application Multiple File Manipulation
18272| [74447] Apache Struts XWork Nonexistent Method s:submit Element Internal Java Class Remote Path Disclosure
18273| [74262] Apache HTTP Server Multi-Processing Module itk.c Configuration Merger mpm-itk root UID / GID Remote Privilege Escalation
18274| [74120] Apache HTTP Server mod_authnz_external mysql/mysql-auth.pl user Field SQL Injection
18275| [73920] Oracle Secure Backup /apache/htdocts/php/common.php username Parameter Remote Code Execution
18276| [73798] Apache Tomcat sendfile Request Start / Endpoint Parsing Local DoS
18277| [73797] Apache Tomcat sendfile Request Attribute Validation Weakness Local Access Restriction Bypass
18278| [73776] Apache Tomcat HTTP BIO Connector HTTP Pipelining Cross-user Remote Response Access
18279| [73644] Apache XML Security Signature Key Parsing Overflow DoS
18280| [73600] Apache Struts javatemplates Plugin Component Handlers .action URI Multiple Parameter XSS
18281| [73462] Apache Rampart/C util/rampart_timestamp_token.c rampart_timestamp_token_validate Function Expired Token Remote Access Restriction Bypass
18282| [73429] Apache Tomcat JMX MemoryUserDatabase Local Password Disclosure
18283| [73384] Apache HTTP Server mod_rewrite PCRE Resource Exhaustion DoS
18284| [73383] Apache HTTP Server Portable Runtime (APR) Library apr_fnmatch() Infinite Loop Remote DoS
18285| [73378] IBM WebSphere Application Server (WAS) JavaServer Pages org.apache.jasper.runtime.JspWriterImpl.response JSP Page Application Restart Remote DoS
18286| [73247] Apache Subversion mod_dav_svn File Permission Weakness Information Disclosure
18287| [73246] Apache Subversion mod_dav_svn Path-based Access Control Rule Handling Remote DoS
18288| [73245] Apache Subversion mod_dav_svn Baselined Resource Request Handling Remote DoS
18289| [73154] Apache Archiva Multiple Unspecified CSRF
18290| [73153] Apache Archiva /archiva/admin/deleteNetworkProxy!confirm.action proxyid Parameter XSS
18291| [72407] Apache Tomcat @ServletSecurity Initial Load Annotation Security Constraint Bypass Information Disclosure
18292| [72238] Apache Struts Action / Method Names <
18293| [71647] Apache HttpComponents HttpClient Proxy-Authorization Credentials Remote Disclosure
18294| [71558] Apache Tomcat SecurityManager ServletContext Attribute Traversal Arbitrary File Manipulation
18295| [71557] Apache Tomcat HTML Manager Multiple XSS
18296| [71075] Apache Archiva User Management Page XSS
18297| [71027] Apache Tomcat @ServletSecurity Annotation Security Constraint Bypass Information Disclosure
18298| [70925] Apache Continuum Project Pages Unspecified XSS (2011-0533)
18299| [70924] Apache Continuum Multiple Admin Function CSRF
18300| [70809] Apache Tomcat NIO HTTP Connector Request Line Processing DoS
18301| [70734] Apache CouchDB Request / Cookie Handling Unspecified XSS
18302| [70585] Oracle Fusion Middleware Oracle HTTP Server Apache Plugin Unspecified Remote Issue
18303| [70333] Apache Subversion rev_hunt.c blame Command Multiple Memory Leak Remote DoS
18304| [70332] Apache Subversion Apache HTTP Server mod_dav_svn repos.c walk FunctionSVNParentPath Collection Remote DoS
18305| [69659] Apache Archiva Admin Authentication Weakness Privilege Escalation
18306| [69520] Apache Archiva Administrator Credential Manipulation CSRF
18307| [69512] Apache Tomcat Set-Cookie Header HTTPOnly Flag Session Hijacking Weakness
18308| [69456] Apache Tomcat Manager manager/html/sessions Multiple Parameter XSS
18309| [69275] Apache mod_fcgid Module fcgid_bucket.c fcgid_header_bucket_read() Function Remote Overflow
18310| [69067] Apache Shiro URI Path Security Traversal Information Disclosure
18311| [68815] Apache MyFaces shared/util/StateUtils.java View State MAC Weakness Cryptographic Padding Remote View State Modification
18312| [68670] Apache Qpid C++ Broker Component broker/SessionAdapter.cpp SessionAdapter::ExchangeHandlerImpl::checkAlternate Function Exchange Alternate Remote DoS
18313| [68669] Apache Qpid cluster/Cluster.cpp Cluster::deliveredEvent Function Invalid AMQP Data Remote DoS
18314| [68662] Apache Axis2 dswsbobje.war Module Admin Account Default Password
18315| [68531] Apache Qpid qpidd sys/ssl/SslSocket.cpp Incomplete SSL Handshake Remote DoS
18316| [68327] Apache APR-util buckets/apr_brigade.c apr_brigade_split_line() Function Memory Consumption DoS
18317| [68314] Apache XML-RPC SAX Parser External Entity Information Disclosure
18318| [67964] Apache Traffic Server Transaction ID / Source Port Randomization Weakness DNS Cache Poisoning
18319| [67846] SUSE Lifecycle Management Server on SUSE Linux Enterprise apache2-slms Parameter Quoting CSRF
18320| [67294] Apache CXF XML SOAP Message Crafted Document Type Declaration Remote DoS
18321| [67240] Apache CouchDB Installation Page Direct Request Arbitrary JavaScript Code Execution CSRF
18322| [67205] Apache Derby BUILTIN Authentication Password Hash Generation Algorithm SHA-1 Transformation Password Substitution
18323| [66745] Apache HTTP Server Multiple Modules Pathless Request Remote DoS
18324| [66319] Apache Tomcat Crafted Transfer-Encoding Header Handling Buffer Recycling Remote DoS
18325| [66280] Apache Struts XWork ParameterInterceptor Server-Side Object Remote Code Execution
18326| [66226] Apache Axis2 Admin Interface Cookie Session Fixation
18327| [65697] Apache Axis2 / Java SOAP Message DTD Rejection Weakness Arbitrary File Access
18328| [65654] Apache HTTP Server mod_proxy_http mod_proxy_http.c Timeout Detection Weakness HTTP Request Response Disclosure
18329| [65429] Apache MyFaces Unencrypted ViewState Serialized View Object Manipulation Arbitrary Expression Language (EL) Statement Execution
18330| [65054] Apache ActiveMQ Jetty Error Handler XSS
18331| [64844] Apache Axis2/Java axis2/axis2-admin/engagingglobally modules Parameter XSS
18332| [64522] Apache Open For Business Project (OFBiz) ecommerce/control/contactus Multiple Parameter XSS
18333| [64521] Apache Open For Business Project (OFBiz) Web Tools Section entityName Parameter XSS
18334| [64520] Apache Open For Business Project (OFBiz) ecommerce/control/ViewBlogArticle contentId Parameter XSS
18335| [64519] Apache Open For Business Project (OFBiz) Control Servlet URI XSS
18336| [64518] Apache Open For Business Project (OFBiz) Show Portal Page Section start Parameter XSS
18337| [64517] Apache Open For Business Project (OFBiz) View Profile Section partyId Parameter XSS
18338| [64516] Apache Open For Business Project (OFBiz) Export Product Listing Section productStoreId Parameter XSS
18339| [64307] Apache Tomcat Web Application Manager/Host Manager CSRF
18340| [64056] mod_auth_shadow for Apache HTTP Server wait() Function Authentication Bypass
18341| [64023] Apache Tomcat WWW-Authenticate Header Local Host Information Disclosure
18342| [64020] Apache ActiveMQ Jetty ResourceHandler Crafted Request JSP File Source Disclosure
18343| [63895] Apache HTTP Server mod_headers Unspecified Issue
18344| [63368] Apache ActiveMQ createDestination.action JMSDestination Parameter CSRF
18345| [63367] Apache ActiveMQ createDestination.action JMSDestination Parameter XSS
18346| [63350] Apache CouchDB Hash Verification Algorithm Predictable Execution Time Weakness
18347| [63140] Apache Thrift Service Malformed Data Remote DoS
18348| [62676] Apache HTTP Server mod_proxy_ajp Module Crafted Request Remote DoS
18349| [62675] Apache HTTP Server Multi-Processing Module (MPM) Subrequest Header Handling Cross-thread Information Disclosure
18350| [62674] Apache HTTP Server mod_isapi Module Unloading Crafted Request Remote DoS
18351| [62231] Apache HTTP Server Logging Format Weakness Crafted DNS Response IP Address Spoofing
18352| [62230] Apache HTTP Server Crafted DNS Response Inverse Lookup Log Corruption XSS
18353| [62054] Apache Tomcat WAR Filename Traversal Work-directory File Deletion
18354| [62053] Apache Tomcat Autodeployment Process appBase File HTTP Request Authentication Bypass
18355| [62052] Apache Tomcat WAR File Traversal Arbitrary File Overwrite
18356| [62009] Apache HTTP Server src/modules/proxy/proxy_util.c mod_proxy ap_proxy_send_fb() Function Overflow
18357| [61379] Apache River Outrigger Entry Storage Saturation Memory Exhaustion DoS
18358| [61378] Apache Hadoop Map/Reduce JobTracker Memory Consumption DoS
18359| [61377] Apache Commons Modeler Multiple Mutable Static Fields Weakness
18360| [61376] Apache Rampart wsse:security Tag Signature Value Checking Weakness
18361| [60687] Apache C++ Standard Library (STDCXX) strxfrm() Function Overflow
18362| [60680] Apache Hadoop JobHistory Job Name Manipulation Weakness
18363| [60679] Apache ODE DeploymentWebService OMElement zipPart CRLF Injection
18364| [60678] Apache Roller Comment Email Notification Manipulation DoS
18365| [60677] Apache CouchDB Unspecified Document Handling Remote DoS
18366| [60428] Sun Java Plug-in org.apache.crimson.tree.XmlDocument Class reateXmlDocument Method Floppy Drive Access Bypass
18367| [60413] mod_throttle for Apache Shared Memory File Manipulation Local Privilege Escalation
18368| [60412] Sun Java Plug-in org.apache.xalan.processor.XSLProcessorVersion Class Unsigned Applet Variable Sharing Privilege Escalation
18369| [60396] Apache HTTP Server on OpenBSD Multipart MIME Boundary Remote Information Disclosure
18370| [60395] Apache HTTP Server on OpenBSD ETag HTTP Header Remote Information Disclosure
18371| [60232] PHP on Apache php.exe Direct Request Remote DoS
18372| [60176] Apache Tomcat Windows Installer Admin Default Password
18373| [60016] Apache HTTP Server on HP Secure OS for Linux HTTP Request Handling Unspecified Issue
18374| [59979] Apache HTTP Server on Apple Mac OS X HTTP TRACE Method Unspecified Client XSS
18375| [59969] Apache HTTP Server mod_ssl SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection
18376| [59944] Apache Hadoop jobhistory.jsp XSS
18377| [59374] Apache Solr Search Extension for TYPO3 Unspecified XSS
18378| [59022] Apache Shindig ConcatProxyServlet HTTP Header Response Splitting
18379| [59021] Apache Cocoon X-Cocoon-Version Header Remote Information Disclosure
18380| [59020] Apache Tapestry HTTPS Session Cookie Secure Flag Weakness
18381| [59019] Apache mod_python Cookie Salting Weakness
18382| [59018] Apache Harmony Error Message Handling Overflow
18383| [59013] Apache Derby SYSCS_EXPORT_TABLE Arbitrary File Overwrite
18384| [59012] Apache Derby Driver Auto-loading Non-deterministic Startup Weakness
18385| [59011] Apache JSPWiki Page Attachment Change Note Function XSS
18386| [59010] Apache Solr get-file.jsp XSS
18387| [59009] Apache Solr action.jsp XSS
18388| [59008] Apache Solr analysis.jsp XSS
18389| [59007] Apache Solr schema.jsp Multiple Parameter XSS
18390| [59006] Apache Beehive select / checkbox Tag XSS
18391| [59005] Apache Beehive jpfScopeID Global Parameter XSS
18392| [59004] Apache Beehive Error Message XSS
18393| [59003] Apache HttpClient POST Request Handling Memory Consumption DoS
18394| [59002] Apache Jetspeed default-page.psml URI XSS
18395| [59001] Apache Axis2 xsd Parameter Traversal Arbitrary File Disclosure
18396| [59000] Apache CXF Unsigned Message Policy Bypass
18397| [58999] Apache WSS4J CallbackHandler Plaintext Password Validation Weakness
18398| [58998] Apache OpenJPA persistence.xml Cleartext Password Local Disclosure
18399| [58997] Apache OpenEJB openejb.xml Cleartext Password Local Disclosure
18400| [58996] Apache Hadoop Map/Reduce LinuxTaskController File Group Ownership Weakness
18401| [58995] Apache Hadoop Map/Reduce Task Ownership Weakness
18402| [58994] Apache Hadoop Map/Reduce DistributedCache Localized File Permission Weakness
18403| [58993] Apache Hadoop browseBlock.jsp XSS
18404| [58991] Apache Hadoop browseDirectory.jsp XSS
18405| [58990] Apache Hadoop Map/Reduce HTTP TaskTrackers User Data Remote Disclosure
18406| [58989] Apache Hadoop Sqoop Process Listing Local Cleartext Password Disclosure
18407| [58988] Apache Hadoop Chukwa HICC Portal Unspecified XSS
18408| [58987] Apache Hadoop Map/Reduce TaskTracker User File Permission Weakness
18409| [58986] Apache Qpid Encrypted Message Handling Remote Overflow DoS
18410| [58985] Apache Qpid Process Listing Local Cleartext Password Disclosure
18411| [58984] Apache Jackrabbit Content Repository (JCR) Default Account Privilege Access Weakness
18412| [58983] Apache Jackrabbit Content Repository (JCR) NamespaceRegistry API Registration Method Race Condition
18413| [58982] Apache Synapse Proxy Service Security Policy Mismatch Weakness
18414| [58981] Apache Geronimo TomcatGeronimoRealm Security Context Persistence Weakness
18415| [58980] Apache Geronimo LDAP Realm Configuration Restart Reversion Weakness
18416| [58979] Apache MyFaces Tomahawk ExtensionsPhaseListener HTML Injection Information Disclosure
18417| [58978] Apache MyFaces Trinidad LocaleInfoScriptlet XSS
18418| [58977] Apache Open For Business Project (OFBiz) Multiple Default Accounts
18419| [58976] Apache Open For Business Project (OFBiz) URI passThru Parameter XSS
18420| [58975] Apache Open For Business Project (OFBiz) PARTYMGR_CREATE/UPDATE Permission Arbitrary User Password Modification
18421| [58974] Apache Sling /apps Script User Session Management Access Weakness
18422| [58973] Apache Tuscany Crafted SOAP Request Access Restriction Bypass
18423| [58931] Apache Geronimo Cookie Parameters Validation Weakness
18424| [58930] Apache Xalan-C++ XPath Handling Remote DoS
18425| [58879] Apache Portable Runtime (APR-util) poll/unix/port.c Event Port Backend Pollset Feature Remote DoS
18426| [58837] Apache Commons Net FTPSClient CipherSuites / Protocols Mutable Object Unspecified Data Security Issue
18427| [58813] Apache MyFaces Trinidad tr:table / HTML Comment Handling DoS
18428| [58812] Apache Open For Business Project (OFBiz) JSESSIONID Session Hijacking Weakness
18429| [58811] Apache Open For Business Project (OFBiz) /catalog/control/EditProductConfigItem configItemId Parameter XSS
18430| [58810] Apache Open For Business Project (OFBiz) /catalog/control/EditProdCatalo prodCatalogId Parameter XSS
18431| [58809] Apache Open For Business Project (OFBiz) /partymgr/control/viewprofile partyId Parameter XSS
18432| [58808] Apache Open For Business Project (OFBiz) /catalog/control/createProduct internalName Parameter XSS
18433| [58807] Apache Open For Business Project (OFBiz) Multiple Unspecified CSRF
18434| [58806] Apache FtpServer MINA Logging Filter Cleartext Credential Local Disclosure
18435| [58805] Apache Derby Unauthenticated Database / Admin Access
18436| [58804] Apache Wicket Header Contribution Unspecified Issue
18437| [58803] Apache Wicket Session Fixation
18438| [58802] Apache Directory Server (ApacheDS) userPassword Attribute Search Password Disclosure
18439| [58801] Apache ActiveMQ Stomp Client Credential Validation Bypass
18440| [58800] Apache Tapestry (context)/servicestatus Internal Service Information Disclosure
18441| [58799] Apache Tapestry Logging Cleartext Password Disclosure
18442| [58798] Apache Jetspeed pipeline Parameter pipeline-map Policy Bypass
18443| [58797] Apache Jetspeed Password Policy Multiple Weaknesses
18444| [58796] Apache Jetspeed Unsalted Password Storage Weakness
18445| [58795] Apache Rampart Crafted SOAP Header Authentication Bypass
18446| [58794] Apache Roller Admin Protocol (RAP) Malformed Header Authentication Bypass
18447| [58793] Apache Hadoop Map/Reduce mapred.system.dir Permission Weakness Job Manipulation
18448| [58792] Apache Shindig gadgets.rpc iframe RPC Call Validation Weakness
18449| [58791] Apache Synapse synapse.properties Cleartext Credential Local Disclosure
18450| [58790] Apache WSS4J SOAP Message UsernameToken Remote Password Disclosure
18451| [58789] Apache WSS4J SOAP Header Malformed UsernameToken Authentication Bypass
18452| [58776] Apache JSPWiki PreviewContent.jsp Edited Text XSS
18453| [58775] Apache JSPWiki preview.jsp action Parameter XSS
18454| [58774] Apache JSPWiki Edit.jsp Multiple Parameter XSS
18455| [58773] Apache JSPWiki Accept-Language Header Multiple Script language Parameter XSS
18456| [58772] Apache JSPWiki EditorManager.java editor Parameter XSS
18457| [58771] Apache JSPWiki GroupContent.jsp Multiple Parameter XSS
18458| [58770] Apache JSPWiki Group.jsp group Parameter XSS
18459| [58769] Apache JSPWiki Database Connection Termination DoS Weakness
18460| [58768] Apache JSPWiki Attachment Servlet nextpage Parameter Arbitrary Site Redirect
18461| [58766] Apache JSPWiki /admin/SecurityConfig.jsp Direct Request Information Disclosure
18462| [58765] Apache JSPWiki Spam Filter UniqueID RNG Weakness
18463| [58764] Apache JSPWiki Edit.jsp Multiple Parameter XSS
18464| [58763] Apache JSPWiki Include Tag Multiple Script XSS
18465| [58762] Apache JSPWiki Multiple .java Tags pageContext Parameter XSS
18466| [58761] Apache JSPWiki Wiki.jsp skin Parameter XSS
18467| [58760] Apache Commons VFS Exception Error Message Cleartext Credential Disclosure
18468| [58759] Apache Jackrabbit Content Repository (JCR) UUID System.currentTimeMillis() RNG Weakness
18469| [58758] Apache River GrantPermission Policy Manipulation Privilege Escalation
18470| [58757] Apache WS-Commons Java2 StaXUtils Multiple Unspecified Minor Issues
18471| [58756] Apache WSS4J WSHandler Client Certificate Signature Validation Weakness
18472| [58755] Apache Harmony DRLVM Non-public Class Member Access
18473| [58754] Apache Harmony File.createTempFile() Temporary File Creation Prediction Weakness
18474| [58751] Apache Geronimo GeronimoIdentityResolver Subject Handling Multiple Issues
18475| [58750] Apache MyFaces Trinidad Generated HTML Information Disclosure
18476| [58749] Apache MyFaces Trinidad Database Access Error Message Information Disclosure
18477| [58748] Apache MyFaces Trinidad Image Resource Loader Traversal Arbitrary Image Access
18478| [58747] Apache MyFaces Trinidad Error Message User Entered Data Disclosure Weakness
18479| [58746] Apache Axis2 JAX-WS Java2 WSDL4J Unspecified Issue
18480| [58744] Apache Wicket Crafted File Upload Disk Space Exhaustion DoS
18481| [58743] Apache Wicket wicket.util.crypt.SunJceCrypt Encryption Reversion Weakness
18482| [58742] Apache Rampart PolicyBasedValiadtor HttpsToken Endpoint Connection Weakness
18483| [58741] Apache Rampart WSSecSignature / WSSecEncryptedKey KeyIdentifierType Validation Weakness
18484| [58740] Apache Rampart TransportBinding Message Payload Cleartext Disclosure
18485| [58739] Apache Open For Business Project (OFBiz) Unsalted Password Storage Weakness
18486| [58738] Apache Open For Business Project (OFBiz) orderId Parameter Arbitrary Order Access
18487| [58737] Apache mod_python w/ mod_python.publisher index.py Underscore Prefixed Variable Disclosure
18488| [58735] Apache Open For Business Project (OFBiz) /ecommerce/control/keywordsearch SEARCH_STRING Parameter XSS
18489| [58734] Apache Torque Log File Cleartext Credential Local Disclosure
18490| [58733] Apache Axis2 doGet Implementation Authentication Bypass Service State Manipulation
18491| [58732] Apache MyFaces UIInput.validate() Null Value Validation Bypass Weakness
18492| [58731] Apache MyFaces /faces/* Prefix Mapping Authentication Bypass
18493| [58725] Apache Tapestry Basic String ACL Bypass Weakness
18494| [58724] Apache Roller Logout Functionality Failure Session Persistence
18495| [58723] Apache Roller User Profile / Admin Page Cleartext Password Disclosure
18496| [58722] Apache Derby Connection URL Encryption Method Reversion Weakness
18497| [58721] Apache Geronimo on Tomcat Security-constraint Resource ACL Bypass
18498| [58720] Apache Geronimo Explicit Servlet Mapping Access Bypass Weakness
18499| [58719] Apache Geronimo Keystore Unprivileged Service Disable DoS
18500| [58718] Apache Geronimo Deployment Plans Remote Password Disclosure
18501| [58717] Apache Jetspeed Portlet Application Edit Access Restriction Bypass
18502| [58716] Apache Jetspeed PSML Management Cached Constraint Authentication Weakness
18503| [58707] Apache WSS4J Crafted PasswordDigest Request Authentication Bypass
18504| [58706] Apache HttpClient Pre-emptive Authorization Remote Credential Disclosure
18505| [58705] Apache Directory Server (ApacheDS) User Passwords Cleartext Disclosure
18506| [58704] Apache Directory Server (ApacheDS) Non-existent User LDAP Bind Remote DoS
18507| [58703] Apache Geronimo Debug Console Unauthenticated Remote Information Disclosure
18508| [58702] Apache Directory Server (ApacheDS) Persistent LDAP Anonymous Bind Weakness
18509| [58701] Apache Jetspeed User Admin Portlet Unpassworded Account Creation Weakness
18510| [58700] Apache MyFaces /faces/* Path Handling Remote Overflow DoS
18511| [58699] Apache MyFaces Disable Property Client Side Manipulation Privilege Escalation
18512| [58698] Apache Roller Remember Me Functionality Cleartext Password Disclosure
18513| [58697] Apache XalanJ2 org.apache.xalan.xsltc.runtime.CallFunction Class Unspecified Issue
18514| [58696] Apache Tapestry Encoded Traversal Arbitrary File Access
18515| [58695] Apache Jetspeed Unauthenticated PSML Tags / Admin Folder Access
18516| [58694] Apache Geronimo Deploy Tool Process List Local Credential Disclosure
18517| [58693] Apache Derby service.properties File Encryption Key Information Disclosure
18518| [58692] Apache Geronimo Default Security Realm Login Brute Force Weakness
18519| [58689] Apache Roller Retrieve Last 5 Post Feature Unauthorized Blog Post Manipulation
18520| [58688] Apache Xalan-Java (XalanJ2) Static Variables Multiple Unspecified Issues
18521| [58687] Apache Axis Invalid wsdl Request XSS
18522| [58686] Apache Cocoon Temporary File Creation Unspecified Race Condition
18523| [58685] Apache Velocity Template Designer Privileged Code Execution
18524| [58684] Apache Jetspeed controls.Customize Action Security Check Bypass
18525| [58675] Apache Open For Business Project (OFBiz) eCommerce/ordermgr Multiple Field XSS
18526| [58674] Apache Open For Business Project (OFBiz) ecommerce/control/login Multiple Field XSS
18527| [58673] Apache Open For Business Project (OFBiz) ecommerce/control/viewprofile Multiple Field XSS
18528| [58672] Apache Open For Business Project (OFBiz) POS Input Panel Cleartext Password Disclosure
18529| [58671] Apache Axis2 JMS Signed Message Crafted WS-Security Header Security Bypass
18530| [58670] Apache Jetspeed JetspeedTool.getPortletFromRegistry Portlet Security Validation Failure
18531| [58669] Apache Jetspeed LDAP Cleartext Passwords Disclosure
18532| [58668] Apache Axis External Entity (XXE) Data Parsing Privilege Escalation
18533| [58667] Apache Roller Database Cleartext Passwords Disclosure
18534| [58666] Apache Xerces-C++ UTF-8 Transcoder Overlong Code Handling Unspecified Issue
18535| [58665] Apache Jetspeed Turbine: Cross-user Privileged Action Execution
18536| [58664] Apache Jetspeed EditAccount.vm Password Modification Weakness
18537| [58663] Apache Jetspeed Role Parameter Arbitrary Portlet Disclosure
18538| [58662] Apache Axis JWS Page Generated .class File Direct Request Information Disclosure
18539| [58661] Apache Jetspeed user-form.vm Password Reset Cleartext Disclosure
18540| [58660] Apache WSS4J checkReceiverResults Function Crafted SOAP Request Authentication Bypass
18541| [58658] Apache Rampart Crafted SOAP Request Security Verification Bypass
18542| [57882] Apache HTTP Server mod_proxy_ftp Authorization HTTP Header Arbitrary FTP Command Injection
18543| [57851] Apache HTTP Server mod_proxy_ftp EPSV Command NULL Dereference Remote DoS
18544| [56984] Apache Xerces2 Java Malformed XML Input DoS
18545| [56903] Apache ODE (Orchestration Director Engine) Process Deployment Web Service Traversal Arbitrary File Manipulation
18546| [56859] Apache Xerces-C++ Multiple Sub-project XML Nested DTD Structures Parsing Recursion Error DoS
18547| [56766] Apache Portable Runtime (APR-util) memory/unix/apr_pools.c Relocatable Memory Block Aligning Overflow
18548| [56765] Apache Portable Runtime (APR-util) misc/apr_rmm.c Multiple Function Overflows
18549| [56517] Apache HTTP Server File Descriptor Leak Arbitrary Local File Append
18550| [56443] PTK Unspecified Apache Sub-process Arbitrary Command Execution
18551| [56414] Apache Tiles Duplicate Expression Language (EL) Expression Evaluation XSS
18552| [55814] mod_NTLM for Apache HTTP Server ap_log_rerror() Function Remote Format String
18553| [55813] mod_NTLM for Apache HTTP Server log() Function Remote Overflow
18554| [55782] Apache HTTP Server mod_deflate Module Aborted Connection DoS
18555| [55553] Apache HTTP Server mod_proxy Module mod_proxy_http.c stream_reqbody_cl Function CPU Consumption DoS
18556| [55059] Apache APR-util strmatch/apr_strmatch.c apr_strmatch_precompile Function Crafted Input Remote DoS
18557| [55058] Apache APR-util apr_brigade_vprintf Function Crafted Input Off-by-one Remote DoS
18558| [55057] Apache APR-util xml/apr_xml.c apr_xml_* Interface Expat XML Parser Crafted XML Document Remote DoS
18559| [55056] Apache Tomcat Cross-application TLD File Manipulation
18560| [55055] Apache Tomcat Illegal URL Encoded Password Request Username Enumeration
18561| [55054] Apache Tomcat Java AJP Connector mod_jk Load Balancing Worker Malformed Header Remote DoS
18562| [55053] Apache Tomcat Crafted Request Security Restraint Bypass Arbitrary Content Access
18563| [54733] Apache HTTP Server AllowOverride Directive .htaccess Options Bypass
18564| [54713] razorCMS Security Manager apache User Account Unspecified File Permission Weakness Issue
18565| [54589] Apache Jserv Nonexistent JSP Request XSS
18566| [54122] Apache Struts s:a / s:url Tag href Element XSS
18567| [54093] Apache ActiveMQ Web Console JMS Message XSS
18568| [53932] Apache Geronimo Multiple Admin Function CSRF
18569| [53931] Apache Geronimo /console/portal/Server/Monitoring Multiple Parameter XSS
18570| [53930] Apache Geronimo /console/portal/ URI XSS
18571| [53929] Apache Geronimo on Windows Security/Keystores Portlet Traversal Arbitrary File Upload
18572| [53928] Apache Geronimo on Windows Embedded DB/DB Manager Portlet Traversal Arbitrary File Upload
18573| [53927] Apache Geronimo on Windows Services/Repository Portlet Traversal Arbitrary File Upload
18574| [53921] Apache HTTP Server mod_proxy_ajp Cross Thread/Session Information Disclosure
18575| [53766] Oracle BEA WebLogic Server Plug-ins for Apache Certificate Handling Remote Overflow
18576| [53574] PHP on Apache .htaccess mbstring.func_overload Setting Cross Hosted Site Behavior Modification
18577| [53381] Apache Tomcat JK Connector Content-Length Header Cross-user Information Disclosure
18578| [53380] Apache Struts Unspecified XSS
18579| [53289] Apache mod_perl Apache::Status /perl-status Unspecified XSS
18580| [53186] Apache HTTP Server htpasswd Predictable Salt Weakness
18581| [52899] Apache Tomcat Examples Web Application Calendar Application jsp/cal/cal2.jsp time Parameter XSS
18582| [52407] Apache Tomcat doRead Method POST Content Information Disclosure
18583| [51923] Apache HTTP Server mod-auth-mysql Module mod_auth_mysql.c Multibyte Character Encoding SQL Injection
18584| [51613] Apache HTTP Server Third-party Module Child Process File Descriptor Leak
18585| [51612] Apache HTTP Server Internal Redirect Handling Infinite Loop DoS
18586| [51468] Apache Jackrabbit Content Repository (JCR) swr.jsp q Parameter XSS
18587| [51467] Apache Jackrabbit Content Repository (JCR) search.jsp q Parameter XSS
18588| [51151] Apache Roller Search Function q Parameter XSS
18589| [50482] PHP with Apache php_value Order Unspecified Issue
18590| [50475] Novell NetWare ApacheAdmin Console Unauthenticated Access
18591| [49734] Apache Struts DefaultStaticContentLoader Class Traversal Arbitrary File Access
18592| [49733] Apache Struts FilterDispatcher Class Traversal Arbitrary File Access
18593| [49283] Oracle BEA WebLogic Server Plugins for Apache Remote Transfer-Encoding Overflow
18594| [49062] Apache Tomcat Cross-thread Concurrent Request Variable Overwrite Information Disclosure
18595| [48847] ModSecurity (mod_security) Transformation Caching Unspecified Apache DoS
18596| [48788] Apache Xerces-C++ XML Schema maxOccurs Value XML File Handling DoS
18597| [47474] Apache HTTP Server mod_proxy_ftp Directory Component Wildcard Character XSS
18598| [47464] Apache Tomcat allowLinking / UTF-8 Traversal Arbitrary File Access
18599| [47463] Apache Tomcat RequestDispatcher Traversal Arbitrary File Access
18600| [47462] Apache Tomcat HttpServletResponse.sendError Method Message Argument XSS
18601| [47096] Oracle Weblogic Apache Connector POST Request Overflow
18602| [46382] Frontend Filemanager (air_filemanager) Extension for TYPO3 on Apache Unspecified Arbitrary Code Execution
18603| [46285] TYPO3 on Apache Crafted Filename Upload Arbitrary Command Execution
18604| [46085] Apache HTTP Server mod_proxy ap_proxy_http_process_response() Function Interim Response Forwarding Remote DoS
18605| [45905] Apache Tomcat Host Manager host-manager/html/add name Parameter XSS
18606| [45879] Ragnarok Online Control Panel on Apache Crafted Traversal Authentication Bypass
18607| [45742] Apache HTTP Server on Novell Unspecified Request Directive Internal IP Disclosure
18608| [45740] Apache Derby DropSchemaNode Bind Phase Arbitrary Scheme Statement Dropping
18609| [45599] Apache Derby Lock Table Statement Privilege Requirement Bypass Arbitrary Table Lock
18610| [45585] Apache Derby ACCSEC Command RDBNAM Parameter Cleartext Credential Disclosure
18611| [45584] Apache Derby DatabaseMetaData.getURL Function Cleartext Credential Disclosure
18612| [45420] Apache HTTP Server 403 Error Page UTF-7 Encoded XSS
18613| [44728] PHP Toolkit on Gentoo Linux Interpretation Conflict Apache HTTP Server Local DoS
18614| [44618] Oracle JSP Apache/Jserv Path Translation Traversal Arbitrary JSP File Execution
18615| [44159] Apache HTTP Server Remote Virtual Host Name Disclosure
18616| [43997] Apache-SSL ExpandCert() Function Certificate Handling Arbitrary Environment Variables Manipulation
18617| [43994] suPHP for Apache (mod_suphp) Directory Symlink Local Privilege Escalation
18618| [43993] suPHP for Apache (mod_suphp) Owner Mode Race Condition Symlink Local Privilege Escalation
18619| [43663] Apache HTTP Server Mixed Platform AddType Directive Crafted Request PHP Source Disclosure
18620| [43658] AuthCAS Module (AuthCAS.pm) for Apache HTTP Server SESSION_COOKIE_NAME SQL Injection
18621| [43452] Apache Tomcat HTTP Request Smuggling
18622| [43309] Apache Geronimo LoginModule Login Method Bypass
18623| [43290] Apache JSPWiki Entry Page Attachment Unrestricted File Upload
18624| [43259] Apache HTTP Server on Windows mod_proxy_balancer URL Handling Remote Memory Corruption
18625| [43224] Apache Geronimo on SuSE Linux init Script Symlink Unspecified File/Directory Access
18626| [43189] Apache mod_jk2 Host Header Multiple Fields Remote Overflow
18627| [42937] Apache HTTP Server mod_proxy_balancer balancer-manager Unspecified CSRF
18628| [42341] MOD_PLSQL for Apache Unspecified URL SQL Injection
18629| [42340] MOD_PLSQL for Apache CGI Environment Handling Unspecified Overflow
18630| [42214] Apache HTTP Server mod_proxy_ftp UTF-7 Encoded XSS
18631| [42091] Apache Maven Site Plugin Installation Permission Weakness
18632| [42089] Apache Maven .m2/settings.xml Cleartext Password Disclosure
18633| [42088] Apache Maven Defined Repo Process Listing Password Disclosure
18634| [42087] Apache Maven Site Plugin SSH Deployment Permission Setting Weakness
18635| [42036] Apache HTTP Server MS-DOS Device Request Host OS Disclosure
18636| [41891] BEA WebLogic Apache Beehive NetUI Page Flow Unspecified XSS
18637| [41436] Apache Tomcat Native APR Connector Duplicate Request Issue
18638| [41435] Apache Tomcat %5C Cookie Handling Session ID Disclosure
18639| [41434] Apache Tomcat Exception Handling Subsequent Request Information Disclosure
18640| [41400] LimeSurvey save.php Apache Log File PHP Code Injection
18641| [41029] Apache Tomcat Calendar Examples Application cal2.jsp Multiple Parameter CSRF
18642| [41019] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload XSS
18643| [41018] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload CRLF
18644| [40853] Apache Tomcat SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) JSESSIONIDSSO Cookie Security Weakness
18645| [40264] Apache HTTP Server mod_proxy_balancer balancer_handler Function bb Variable Remote DoS
18646| [40263] Apache HTTP Server mod_proxy_balancer balancer-manager Multiple Parameter XSS
18647| [40262] Apache HTTP Server mod_status refresh XSS
18648| [39833] Apache Tomcat JULI Logging Component catalina.policy Security Bypass
18649| [39251] Coppermine Photo Gallery on Apache Multiple File Extension Upload Arbitrary Code Execution
18650| [39166] Apache Tomcat on Windows caseSensitive Attribute Mixed Case Request JSP Source Disclosure
18651| [39134] Apache mod_imagemap Module Imagemap Unspecified XSS
18652| [39133] Apache mod_imap Module Imagemap File Unspecified XSS
18653| [39035] Apache Tomcat examples/servlet/CookieExample Multiple Parameter XSS
18654| [39003] Apache HTTP Server HTTP Method Header Request Entity Too Large XSS
18655| [39000] Apache Tomcat SendMailServlet sendmail.jsp mailfrom Parameter XSS
18656| [38939] Apache HTTP Server Prefork MPM Module Array Modification Local DoS
18657| [38673] Apache Jakarta Slide WebDAV SYSTEM Request Traversal Arbitrary File Access
18658| [38662] Apache Geronimo SQLLoginModule Nonexistent User Authentication Bypass
18659| [38661] Apache Geronimo MEJB Unspecified Authentication Bypass
18660| [38641] Apache HTTP Server mod_mem_cache recall_headers Function Information Disclosure
18661| [38640] Apache HTTP Server suexec Document Root Unauthorized Operations
18662| [38639] Apache HTTP Server suexec Multiple Symlink Privilege Escalation
18663| [38636] Apache HTTP Server mod_autoindex.c P Variable UTF-7 Charset XSS
18664| [38513] BEA WebLogic Server Proxy Plug-in for Apache Protocol Error Handling Remote DoS
18665| [38187] Apache Geronimo / Tomcat WebDAV XML SYSTEM Tag Arbitrary File Access
18666| [37079] Apache HTTP Server mod_cache cache_util.c Malformed Cache-Control Header DoS
18667| [37071] Apache Tomcat Cookie Handling Session ID Disclosure
18668| [37070] Apache Tomcat Cookie Handling Quote Delimiter Session ID Disclosure
18669| [37052] Apache HTTP Server mod_status mod_status.c Unspecified XSS
18670| [37051] Apache HTTP Server mod_proxy modules/proxy/proxy_util.c Crafted Header Remote DoS
18671| [37050] Apache HTTP Server Prefork MPM Module Crafted Code Sequence Local DoS
18672| [36417] Apache Tomcat Host Manager Servlet html/add Action aliases Parameter XSS
18673| [36377] Apache MyFaces Tomahawk JSF Application autoscroll Multiple Script XSS
18674| [36080] Apache Tomcat JSP Examples Crafted URI XSS
18675| [36079] Apache Tomcat Manager Uploaded Filename XSS
18676| [34888] Apache Tomcat Example Calendar Application cal2.jsp time Parameter XSS
18677| [34887] Apache Tomcat implicit-objects.jsp Crafted Header XSS
18678| [34885] Apache Tomcat on IIS Servlet Engine MS-DOS Device Request DoS
18679| [34884] Apache Tomcat on Windows Nonexistent Resource Request Path Disclosure
18680| [34883] Apache Tomcat Crafted JSP File Request Path Disclosure
18681| [34882] Apache Tomcat Default SSL Ciphersuite Configuration Weakness
18682| [34881] Apache Tomcat Malformed Accept-Language Header XSS
18683| [34880] Apache Tomcat HTTP/1.1 Connector NULL Byte Request JSP Source Disclosure
18684| [34879] Apache Tomcat examples/jsp2/jspx/textRotate.jspx XSS
18685| [34878] Apache Tomcat examples/jsp2/el/implicit-objects.jsp XSS
18686| [34877] Apache Tomcat JK Web Server Connector (mod_jk) Double Encoded Traversal Arbitrary File Access
18687| [34876] Apache HTTP Server ScriptAlias CGI Source Disclosure
18688| [34875] Apache Tomcat appdev/sample/web/hello.jsp Multiple Parameter XSS
18689| [34874] Apache Tomcat AJP Connector mod_jk ajp_process_callback Remote Memory Disclosure
18690| [34873] Apache Stats Variable Extraction _REQUEST Ssuperglobal Array Overwrite
18691| [34872] Apache HTTP Server suexec User/Group Combination Weakness Local Privilege Escalation
18692| [34769] Apache Tomcat w/ Proxy Module Double Encoded Traversal Arbitrary File Access
18693| [34541] mod_perl for Apache HTTP Server RegistryCooker.pm PATH_INFO Crafted URI Remote DoS
18694| [34540] mod_perl for Apache HTTP Server PerlRun.pm PATH_INFO Crafted URI Remote DoS
18695| [34398] Apache Tomcat mod_jk Invalid Chunked Encoded Body Information Disclosure
18696| [34154] Apache Axis Nonexistent Java Web Service Path Disclosure
18697| [33855] Apache Tomcat JK Web Server Connector mod_jk.so Long URI Worker Map Remote Overflow
18698| [33816] Apache HTTP Server on Debian Linux TTY Local Privilege Escalation
18699| [33456] Apache HTTP Server Crafted TCP Connection Range Header DoS
18700| [33346] Avaya Multiple Products Apache Tomcat Port Weakness
18701| [32979] Apache Java Mail Enterprise Server (JAMES) Phoenix/MX4J Interface Arbitrary User Creation
18702| [32978] Apache Java Mail Enterprise Server (JAMES) POP3Server Log File Plaintext Password Disclosure
18703| [32724] Apache mod_python _filter_read Freed Memory Disclosure
18704| [32723] Apache Tomcat semicolon Crafted Filename Request Forced Directory Listing
18705| [32396] Apache Open For Business Project (OFBiz) Ecommerce Component Forum Implementation Message Body XSS
18706| [32395] Apache Open For Business Project (OFBiz) Ecommerce Component Form Field Manipulation Privilege Escalation
18707| [30354] Linux Subversion libapache2-svn Search Path Subversion Local Privilege Escalation
18708| [29603] PHP ini_restore() Apache httpd.conf Options Bypass
18709| [29536] Apache Tcl mod_tcl set_var Function Remote Format String
18710| [28919] Apache Roller Weblogger Blog Comment Multiple Field XSS
18711| [28130] PHP with Apache Mixed Case Method Limit Directive Bypass
18712| [27913] Apache HTTP Server on Windows mod_alias URL Validation Canonicalization CGI Source Disclosure
18713| [27588] Apache HTTP Server mod_rewrite LDAP Protocol URL Handling Overflow
18714| [27487] Apache HTTP Server Crafted Expect Header Cross Domain HTML Injection
18715| [26935] FCKeditor on Apache connector.php Crafted File Extension Arbitrary File Upload
18716| [26572] Apache Java Mail Enterprise Server (JAMES) MAIL Command Overflow DoS
18717| [25909] Drupal on Apache files Directory File Upload Arbitrary Code Execution
18718| [24825] Oracle ModPL/SQL for Apache Unspecified Remote HTTP Issue
18719| [24365] Apache Struts Multiple Function Error Message XSS
18720| [24364] Apache Struts getMultipartRequestHandler() Function Crafted Request DoS
18721| [24363] Apache Struts org.apache.struts.taglib.html.Constants.CANCEL Validation Bypass
18722| [24103] Pubcookie Apache mod_pubcookie Unspecified XSS
18723| [23906] Apache mod_python for Apache HTTP Server FileSession Privileged Local Command Execution
18724| [23905] Apache Log4net LocalSyslogAppender Format String Memory Corruption DoS
18725| [23198] Apache WSS4J Library SOAP Signature Verification Bypass
18726| [23124] Generic Apache Request Library (libapreq) apreq_parse_* Functions Remote DoS
18727| [22652] mod_php for Apache HTTP Server Crafted import_request_variables Function DoS
18728| [22475] PHP w/ Apache PDO::FETCH_CLASS __set() Function DoS
18729| [22473] PHP w/ Apache2 Crafted PDOStatement DoS
18730| [22459] Apache Geronimo Error Page XSS
18731| [22458] Apache Tomcat / Geronimo Sample Script cal2.jsp time Parameter XSS
18732| [22301] auth_ldap for Apache HTTP Server auth_ldap_log_reason() Function Remote Format String
18733| [22261] Apache HTTP Server mod_ssl ssl_hook_Access Error Handling DoS
18734| [22259] mod_auth_pgsql for Apache HTTP Server Log Function Format String
18735| [21736] Apache Java Mail Enterprise Server (JAMES) Spooler retrieve Function DoS
18736| [21705] Apache HTTP Server mod_imap Image Map Referer XSS
18737| [21021] Apache Struts Error Message XSS
18738| [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
18739| [20491] PHP mod_php apache2handler SAPI Crafted .htaccess DoS
18740| [20462] Apache HTTP Server worker.c MPM Memory Exhaustion DoS
18741| [20439] Apache Tomcat Directory Listing Saturation DoS
18742| [20373] Apache Tomcat on HP Secure OS for Linux Unspecified Servlet Access Issue
18743| [20285] Apache HTTP Server Log File Control Character Injection
18744| [20242] Apache HTTP Server mod_usertrack Predictable Session ID Generation
18745| [20209] Brainf*ck Module (mod_bf) for Apache HTTP Server Local Overflow
18746| [20033] Apache Tomcat MS-DOS Device Request Error Message Path Disclosure
18747| [19883] apachetop atop.debug Symlink Arbitrary File Overwrite
18748| [19863] mod_auth_shadow for Apache HTTP Server require group Authentication Bypass
18749| [19855] Apache HTTP Server ErrorDocument Directive .htaccess Bypass
18750| [19821] Apache Tomcat Malformed Post Request Information Disclosure
18751| [19769] Apache HTTP Server Double-reverse DNS Lookup Spoofing
18752| [19188] Apache HTTP Server mod_ssl SSLVerifyClient Per-location Context Restriction Bypass
18753| [19137] Apache HTTP Server on Red Hat Linux Double Slash GET Request Forced Directory Listing
18754| [19136] Apache on Mandrake Linux Arbitrary Directory Forced Listing
18755| [18977] Apache HTTP Server Crafted HTTP Range Header DoS
18756| [18389] Ragnarok Online Control Panel Apache Authentication Bypass
18757| [18286] Apache HTTP Server mod_ssl ssl_callback_SSLVerify_CRL( ) Function Overflow
18758| [18233] Apache HTTP Server htdigest user Variable Overfow
18759| [17738] Apache HTTP Server HTTP Request Smuggling
18760| [16586] Apache HTTP Server Win32 GET Overflow DoS
18761| [15889] Apache HTTP Server mod_cgid Threaded MPM CGI Output Misdirection
18762| [14896] mod_dav for Apache HTTP Server Remote Null Dereference Child Process Termination
18763| [14879] Apache HTTP Server ap_log_rerror Function Error Message Path Disclosure
18764| [14770] Apache Tomcat AJP12 Protocol Malformed Packet Remote DoS
18765| [14597] Apache Tomcat IntegerOverflow.jsp Test JSP Script Path Disclosure
18766| [14596] Apache Tomcat pageSession.jsp Test JSP Script Path Disclosure
18767| [14595] Apache Tomcat pageLanguage.jsp Test JSP Script Path Disclosure
18768| [14594] Apache Tomcat pageIsThreadSafe.jsp Test JSP Script Path Disclosure
18769| [14593] Apache Tomcat pageIsErrorPage.jsp Test JSP Script Path Disclosure
18770| [14592] Apache Tomcat pageInvalid.jsp Test JSP Script Path Disclosure
18771| [14591] Apache Tomcat pageExtends.jsp Test JSP Script Path Disclosure
18772| [14590] Apache Tomcat pageDouble.jsp Test JSP Script Path Disclosure
18773| [14589] Apache Tomcat pageAutoFlush.jsp Test JSP Script Path Disclosure
18774| [14588] Apache Tomcat extends2.jsp Test JSP Script Path Disclosure
18775| [14587] Apache Tomcat extends1.jsp Test JSP Script Path Disclosure
18776| [14586] Apache Tomcat comments.jsp Test JSP Script Path Disclosure
18777| [14585] Apache Tomcat buffer4.jsp Test JSP Script Path Disclosure
18778| [14584] Apache Tomcat buffer3.jsp Test JSP Script Path Disclosure
18779| [14583] Apache Tomcat buffer2.jsp Test JSP Script Path Disclosure
18780| [14582] Apache Tomcat buffer1.jsp Test JSP Script Path Disclosure
18781| [14581] Apache Tomcat pageImport2.jsp Test JSP Script Path Disclosure
18782| [14580] Apache Tomcat pageInfo.jsp Test JSP Script Path Disclosure
18783| [14410] mod_frontpage for Apache HTTP Server fpexec Remote Overflow
18784| [14044] Apache Batik Squiggle Browser with Rhino Scripting Engine Unspecified File System Access
18785| [13737] mod_access_referer for Apache HTTP Server Malformed Referer DoS
18786| [13711] Apache mod_python publisher.py Traversal Arbitrary Object Information Disclosure
18787| [13640] mod_auth_any for Apache HTTP Server on Red Hat Linux Metacharacter Command Execution
18788| [13304] Apache Tomcat realPath.jsp Path Disclosure
18789| [13303] Apache Tomcat source.jsp Arbitrary Directory Listing
18790| [13087] Apache HTTP Server mod_log_forensic check_forensic Symlink Arbitrary File Creation / Overwrite
18791| [12849] mod_auth_radius for Apache HTTP Server radcpy() Function Overflow DoS
18792| [12848] Apache HTTP Server htdigest realm Variable Overflow
18793| [12721] Apache Tomcat examples/jsp2/el/functions.jsp XSS
18794| [12720] mod_dosevasive for Apache HTTP Server Symlink Arbitrary File Create/Overwrite
18795| [12558] Apache HTTP Server IPv6 FTP Proxy Socket Failure DoS
18796| [12557] Apache HTTP Server prefork MPM accept Error DoS
18797| [12233] Apache Tomcat MS-DOS Device Name Request DoS
18798| [12232] Apache Tomcat with JDK Arbitrary Directory/Source Disclosure
18799| [12231] Apache Tomcat web.xml Arbitrary File Access
18800| [12193] Apache HTTP Server on Mac OS X File Handler Bypass
18801| [12192] Apache HTTP Server on Mac OS X Unauthorized .ht and .DS_Store File Access
18802| [12178] Apache Jakarta Lucene results.jsp XSS
18803| [12176] mod_digest_apple for Apache HTTP Server on Mac OS X Authentication Replay
18804| [11391] Apache HTTP Server Header Parsing Space Saturation DoS
18805| [11003] Apache HTTP Server mod_include get_tag() Function Local Overflow
18806| [10976] mod_mylo for Apache HTTP Server mylo_log Logging Function HTTP GET Overflow
18807| [10637] Apache HTTP Server mod_ssl SSLCipherSuite Access Restriction Bypass
18808| [10546] Macromedia JRun4 mod_jrun Apache Module Remote Overflow
18809| [10471] Apache Xerces-C++ XML Parser DoS
18810| [10218] Apache HTTP Server Satisfy Directive Access Control Bypass
18811| [10068] Apache HTTP Server htpasswd Local Overflow
18812| [10049] mod_cplusplus For Apache HTTP Server Unspecified Overflow
18813| [9994] Apache HTTP Server apr-util IPV6 Parsing DoS
18814| [9991] Apache HTTP Server ap_resolve_env Environment Variable Local Overflow
18815| [9948] mod_dav for Apache HTTP Server LOCK Request DoS
18816| [9742] Apache HTTP Server mod_ssl char_buffer_read Function Reverse Proxy DoS
18817| [9718] Apache HTTP Server Win32 Single Dot Append Arbitrary File Access
18818| [9717] Apache HTTP Server mod_cookies Cookie Overflow
18819| [9716] Apache::Gallery Gallery.pm Inline::C Predictable Filename Code Execution
18820| [9715] Apache HTTP Server rotatelogs Control Characters Over Pipe DoS
18821| [9714] Apache Authentication Module Threaded MPM DoS
18822| [9713] Apache HTTP Server on OS2 filestat.c Device Name Request DoS
18823| [9712] Apache HTTP Server Multiple Linefeed Request Memory Consumption DoS
18824| [9711] Apache HTTP Server Access Log Terminal Escape Sequence Injection
18825| [9710] Apache HTTP Server on Windows Illegal Character Default Script Mapping Bypass
18826| [9709] Apache HTTP Server on Windows MS-DOS Device Name HTTP Post Code Execution
18827| [9708] Apache HTTP Server on Windows MS-DOS Device Name DoS
18828| [9707] Apache HTTP Server Duplicate MIME Header Saturation DoS
18829| [9706] Apache Web Server Multiple MIME Header Saturation Remote DoS
18830| [9705] Apache Tomcat Invoker/Default Servlet Source Disclosure
18831| [9702] Apache HTTP Server CGI/WebDAV HTTP POST Request Source Disclosure
18832| [9701] Apache HTTP Server for Windows Multiple Slash Forced Directory Listing
18833| [9700] Apache HTTP Server mod_autoindex Multiple Slash Request Forced Directory Listing
18834| [9699] Apache HTTP Server mod_dir Multiple Slash Request Forced Directory Listing
18835| [9698] Apache HTTP Server mod_negotiation Multiple Slash Request Forced Directory Listing
18836| [9697] Apache HTTP Server htdigest Local Symlink Arbitrary File Overwrite
18837| [9696] Apache HTTP Server htpasswd Local Symlink Arbitrary File Overwrite
18838| [9695] Apache Tomcat SnoopServlet Servlet Information Disclosure
18839| [9694] PHP3 on Apache HTTP Server Encoded Traversal Arbitrary File Access
18840| [9693] mod_auth_pgsql_sys for Apache HTTP Server User Name SQL Injection
18841| [9692] Apache HTTP Server mod_vhost_alias Mass Virtual Hosting Arbitrary File Access
18842| [9691] Apache HTTP Server mod_rewrite Mass Virtual Hosting Arbitrary File Access
18843| [9690] Apache HTTP Server mod_vhost_alias CGI Program Source Disclosure
18844| [9689] Trustix httpsd for Apache-SSL Permission Weakness Privilege Escalation
18845| [9688] Apache HTTP Server mod_proxy Malformed FTP Command DoS
18846| [9687] Apache::AuthenSmb smbval SMB Authentication Library Multiple Overflows
18847| [9686] Apache::AuthenSmb smbvalid SMB Authentication Library Multiple Overflows
18848| [9523] Apache HTTP Server mod_ssl Aborted Connection DoS
18849| [9459] Oracle PL/SQL (mod_plsql) Apache Module Help Page Request Remote Overflow
18850| [9208] Apache Tomcat .jsp Encoded Newline XSS
18851| [9204] Apache Tomcat ROOT Application XSS
18852| [9203] Apache Tomcat examples Application XSS
18853| [9068] Apache HTTP Server mod_userdir User Account Information Disclosure
18854| [8773] Apache Tomcat Catalina org.apache.catalina.servlets.DefaultServlet Source Code Disclosure
18855| [8772] Apache Tomcat Catalina org.apache.catalina.connector.http DoS
18856| [7943] Apache HTTP Server mod_ssl sslkeys File Disclosure
18857| [7942] Apache HTTP Server mod_ssl Default Pass Phrase
18858| [7941] Apache HTTP Server mod_ssl Encrypted Private Key File Descriptor Leak
18859| [7935] Apache HTTP Server mod_ssl ssl_gcache Race Conditions
18860| [7934] Apache HTTP Server mod_ssl SSLSessionCache File Content Disclosure
18861| [7933] Apache HTTP Server mod_ssl SSLMutex File Content Disclosure
18862| [7932] Apache HTTP Server mod_ssl mkcert.sh File Creation Permission Weakness
18863| [7931] Apache HTTP Server mod_ssl X.509 Client Certificate Authentication Bypass
18864| [7930] Apache HTTP Server mod_ssl ssl_expr_eval_func_file() Overflow
18865| [7929] Apache HTTP Server mod_ssl ssl_engine_log.c mod_proxy Hook Function Remote Format String
18866| [7611] Apache HTTP Server mod_alias Local Overflow
18867| [7394] Apache Tomcat mod_jk Invalid Transfer-Encoding Chunked Field DoS
18868| [7203] Apache Tomcat source.jsp Traversal Arbitrary File Access
18869| [7039] Apache HTTP Server on Mac OS X HFS+ File System Access Bypass
18870| [6882] Apache mod_python Malformed Query String Variant DoS
18871| [6839] Apache HTTP Server mod_proxy Content-Length Overflow
18872| [6630] Apache Tomcat Java Server Pages (JSP) Engine WPrinterJob() DoS
18873| [6472] Apache HTTP Server mod_ssl ssl_util_uuencode_binary Remote Overflow
18874| [5821] Apache HTTP Server Multiple / GET Remote Overflow DoS
18875| [5580] Apache Tomcat Servlet Malformed URL JSP Source Disclosure
18876| [5552] Apache HTTP Server split-logfile Arbitrary .log File Overwrite
18877| [5526] Apache Tomcat Long .JSP URI Path Disclosure
18878| [5278] Apache Tomcat web.xml Restriction Bypass
18879| [5051] Apache Tomcat Null Character DoS
18880| [4973] Apache Tomcat servlet Mapping XSS
18881| [4650] mod_gzip for Apache HTTP Server Debug Mode Printf Stack Overflow
18882| [4649] mod_gzip for Apache HTTP Server Debug Mode Format String Overflow
18883| [4648] mod_gzip for Apache HTTP Server Debug Mode Race Condition
18884| [4568] mod_survey For Apache ENV Tags SQL Injection
18885| [4553] Apache HTTP Server ApacheBench Overflow DoS
18886| [4552] Apache HTTP Server Shared Memory Scoreboard DoS
18887| [4446] Apache HTTP Server mod_disk_cache Stores Credentials
18888| [4383] Apache HTTP Server Socket Race Condition DoS
18889| [4382] Apache HTTP Server Log Entry Terminal Escape Sequence Injection
18890| [4340] Apache Portable Runtime (APR) apr_psprintf DoS
18891| [4232] Apache Cocoon DatabaseAuthenticatorAction SQL Injection
18892| [4231] Apache Cocoon Error Page Server Path Disclosure
18893| [4182] Apache HTTP Server mod_ssl Plain HTTP Request DoS
18894| [4181] Apache HTTP Server mod_access IP Address Netmask Rule Bypass
18895| [4075] Apache HTTP Sever on Windows .var File Request Path Disclosure
18896| [4037] Apache HTTP Server on Cygwin Encoded GET Request Arbitrary File Access
18897| [3877] Apache-SSL SSLVerifyClient SSLFakeBasicAuth Client Certificate Forgery
18898| [3819] Apache HTTP Server mod_digest Cross Realm Credential Replay
18899| [3322] mod_php for Apache HTTP Server Process Hijack
18900| [3215] mod_php for Apache HTTP Server File Descriptor Leakage
18901| [2885] Apache mod_python Malformed Query String DoS
18902| [2749] Apache Cocoon view-source Sample File Traversal Arbitrary File Access
18903| [2733] Apache HTTP Server mod_rewrite Local Overflow
18904| [2672] Apache HTTP Server mod_ssl SSLCipherSuite Ciphersuite Downgrade Weakness
18905| [2613] Apache HTTP Server mod_cgi stderr Output Handling Local DoS
18906| [2149] Apache::Gallery Privilege Escalation
18907| [2107] Apache HTTP Server mod_ssl Host: Header XSS
18908| [1926] Apache HTTP Server mod_rewrite Crafted URI Rule Bypass
18909| [1833] Apache HTTP Server Multiple Slash GET Request DoS
18910| [1577] Apache HTTP Server mod_rewrite RewriteRule Expansion Arbitrary File Access
18911| [872] Apache Tomcat Multiple Default Accounts
18912| [862] Apache HTTP Server SSI Error Page XSS
18913| [859] Apache HTTP Server Win32 Crafted Traversal Arbitrary File Access
18914| [849] Apache Tomcat TroubleShooter Servlet Information Disclosure
18915| [845] Apache Tomcat MSDOS Device XSS
18916| [844] Apache Tomcat Java Servlet Error Page XSS
18917| [842] Apache HTTP Server mod_ssl ssl_compat_directive Function Overflow
18918| [838] Apache HTTP Server Chunked Encoding Remote Overflow
18919| [827] PHP4 for Apache on Windows php.exe Malformed Request Path Disclosure
18920| [775] Apache mod_python Module Importing Privilege Function Execution
18921| [769] Apache HTTP Server Win32 DOS Batch File Arbitrary Command Execution
18922| [756] Apache HTTP Server mod_ssl i2d_SSL_SESSION Function SSL Client Certificate Overflow
18923| [701] Apache HTTP Server Win32 ScriptAlias php.exe Arbitrary File Access
18924| [674] Apache Tomcat Nonexistent File Error Message Path Disclosure
18925| [637] Apache HTTP Server UserDir Directive Username Enumeration
18926| [623] mod_auth_pgsql for Apache HTTP Server User Name SQL Injection
18927| [582] Apache HTTP Server Multiviews Feature Arbitrary Directory Listing
18928| [562] Apache HTTP Server mod_info /server-info Information Disclosure
18929| [561] Apache Web Servers mod_status /server-status Information Disclosure
18930| [417] Apache HTTP Server on SuSE Linux /doc/packages Remote Information Disclosure
18931| [410] mod_perl for Apache HTTP Server /perl/ Directory Listing
18932| [404] Apache HTTP Server on SuSE Linux WebDAV PROPFIND Arbitrary Directory Listing
18933| [402] Apache HTTP Server on SuSE Linux cgi-bin-sdb Request Script Source Disclosure
18934| [379] Apache ASP module Apache::ASP source.asp Example File Arbitrary File Creation
18935| [377] Apache Tomcat Snoop Servlet Remote Information Disclosure
18936| [376] Apache Tomcat contextAdmin Arbitrary File Access
18937| [342] Apache HTTP Server for Windows Multiple Forward Slash Directory Listing
18938| [222] Apache HTTP Server test-cgi Arbitrary File Access
18939| [143] Apache HTTP Server printenv.pl Multiple Method CGI XSS
18940| [48] Apache HTTP Server on Debian /usr/doc Directory Information Disclosure
18941|_
18942465/tcp open ssl/smtp Exim smtpd 4.93
18943| vulscan: VulDB - https://vuldb.com:
18944| [141327] Exim up to 4.92.1 Backslash privilege escalation
18945| [138827] Exim up to 4.92 Expansion Code Execution
18946| [135932] Exim up to 4.92 privilege escalation
18947| [113048] Exim up to 4.90 SMTP Listener Message memory corruption
18948| [109969] Exim 4.88/4.89 SMTP Daemon receive.c bdat_getc denial of service
18949| [109968] Exim 4.88/4.89 SMTP Daemon receive.c receive_msg memory corruption
18950| [94599] Exim up to 4.87 information disclosure
18951| [13422] Exim 4.82 Mail Header dmarc.c expand_string memory corruption
18952| [6817] Exim up to 4.80 src/dkim.c dkim_exim_query_dns_txt memory corruption
18953| [58841] exim up to 4.69 dkim_exim_verify_finish memory corruption
18954| [57462] Exim up to 4.75 Filesystem memory corruption
18955| [4280] Exim Server 4.x open_log race condition
18956|
18957| MITRE CVE - https://cve.mitre.org:
18958| [CVE-2012-5671] Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.
18959| [CVE-2012-0478] The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.
18960| [CVE-2011-1764] Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.
18961| [CVE-2011-1407] The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.
18962| [CVE-2011-0017] The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
18963| [CVE-2010-4345] Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
18964| [CVE-2010-4344] Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
18965| [CVE-2010-2024] transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.
18966| [CVE-2010-2023] transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.
18967| [CVE-2006-1251] Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
18968| [CVE-2005-0022] Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.
18969| [CVE-2005-0021] Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.
18970| [CVE-2004-0400] Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.
18971| [CVE-2004-0399] Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.
18972| [CVE-2003-0743] Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.
18973| [CVE-2002-1381] Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
18974|
18975| SecurityFocus - https://www.securityfocus.com/bid/:
18976| [103049] Exim 'base64d()' Function Buffer Overflow Vulnerability
18977| [99252] Exim CVE-2017-1000369 Local Privilege Escalation Vulnerability
18978| [94947] Exim CVE-2016-9963 Unspecified Information Disclosure Vulnerability
18979| [84132] Exim CVE-2016-1531 Local Privilege Escalation Vulnerability
18980| [68857] Exim CVE-2014-2972 Local Privilege Escalation Vulnerability
18981| [67695] Exim 'dmarc.c' Remote Code Execution Vulnerability
18982| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
18983| [56285] Exim DKIM DNS Decoding CVE-2012-5671 Remote Buffer Overflow Vulnerability
18984| [47836] Exim DKIM CVE-2011-1407 Remote Code Execution Vulnerability
18985| [47736] Exim 'dkim_exim_verify_finish()' Remote Format String Vulnerability
18986| [46065] Exim 'log.c' Local Privilege Escalation Vulnerability
18987| [45341] Exim ALT_CONFIG_ROOT_ONLY 'exim' User Local Privilege Escalation Vulnerability
18988| [45308] Exim Crafted Header Remote Code Execution Vulnerability
18989| [40454] Exim MBX Locking Insecure Temporary File Creation Vulnerability
18990| [40451] Exim Sticky Mail Directory Local Privilege Escalation Vulnerability
18991| [36181] ikiwiki 'teximg' Plugin Insecure TeX Commands Information Disclosure Vulnerability
18992| [23977] Exim SpamAssassin Reply Remote Buffer Overflow Vulnerability
18993| [17110] sa-exim Unauthorized File Access Vulnerability
18994| [12268] Exim IP Address Command Line Argument Local Buffer Overflow Vulnerability
18995| [12188] Exim SPA Authentication Remote Buffer Overflow Vulnerability
18996| [12185] Exim Illegal IPv6 Address Buffer Overflow Vulnerability
18997| [10291] Exim Header Syntax Checking Remote Stack Buffer Overrun Vulnerability
18998| [10290] Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
18999| [8518] Exim EHLO/HELO Remote Heap Corruption Vulnerability
19000| [6314] Exim Internet Mailer Format String Vulnerability
19001| [4096] Exim Configuration File Argument Command Line Buffer Overflow Vulnerability
19002| [3728] Exim Pipe Hostname Arbitrary Command Execution Vulnerability
19003| [2828] Exim Format String Vulnerability
19004| [1859] Exim Buffer Overflow Vulnerability
19005|
19006| IBM X-Force - https://exchange.xforce.ibmcloud.com:
19007| [84758] Exim sender_address parameter command execution
19008| [84015] Exim command execution
19009| [80186] Mozilla Firefox, Thunderbird, and SeaMonkey copyTexImage2D code execution
19010| [80184] Mozilla Firefox, Thunderbird, and SeaMonkey texImage2D calls code execution
19011| [79615] Exim dkim_exim_query_dns_txt() buffer overflow
19012| [75155] Mozilla Firefox, Thunderbird, and SeaMonkey texImage2D denial of service
19013| [67455] Exim DKIM processing code execution
19014| [67299] Exim dkim_exim_verify_finish() format string
19015| [65028] Exim open_log privilege escalation
19016| [63967] Exim config file privilege escalation
19017| [63960] Exim header buffer overflow
19018| [59043] Exim mail directory privilege escalation
19019| [59042] Exim MBX symlink
19020| [52922] ikiwiki teximg plugin information disclosure
19021| [34265] Exim spamd buffer overflow
19022| [25286] Sa-exim greylistclean.cron file deletion
19023| [22687] RHSA-2005:025 updates for exim not installed
19024| [18901] Exim dns_build_reverse buffer overflow
19025| [18764] Exim spa_base64_to_bits function buffer overflow
19026| [18763] Exim host_aton buffer overflow
19027| [16079] Exim require_verify buffer overflow
19028| [16077] Exim header_check_syntax buffer overflow
19029| [16075] Exim sender_verify buffer overflow
19030| [13067] Exim HELO or EHLO command heap overflow
19031| [10761] Exim daemon.c format string
19032| [8194] Exim configuration file -c command-line argument buffer overflow
19033| [7738] Exim allows attacker to hide commands in localhost names using pipes
19034| [6671] Exim "
19035| [1893] Exim MTA allows local users to gain root privileges
19036|
19037| Exploit-DB - https://www.exploit-db.com:
19038| [16925] Exim4 <= 4.69 - string_format Function Heap Buffer Overflow
19039| [15725] Exim 4.63 Remote Root Exploit
19040| [1009] Exim <= 4.41 dns_build_reverse Local Exploit
19041| [812] Exim <= 4.43 auth_spa_server() Remote PoC Exploit
19042| [796] Exim <= 4.42 Local Root Exploit
19043| [756] Exim <= 4.41 dns_build_reverse Local Exploit PoC
19044|
19045| OpenVAS (Nessus) - http://www.openvas.org:
19046| [100663] Exim < 4.72 RC2 Multiple Vulnerabilities
19047|
19048| SecurityTracker - https://www.securitytracker.com:
19049| [1025539] Exim DKIM Processing Flaw Lets Remote Users Execute Arbitrary Code
19050| [1025504] Exim DKIM Signature Format String Flaw Lets Remote Users Execute Arbitrary Code
19051| [1024859] Exim Configuration File Capability Lets Local Users Gain Elevated Privileges
19052| [1024858] Exim Buffer Overfow in string_format() Lets Remote Users Execute Arbitrary Code
19053| [1012904] Exim Buffer Overflow in dns_build_reverse() Lets Local Users Obtain Elevated Privileges
19054| [1012771] Exim Buffer Overflows in host_aton() and spa_base64_to_bits() May Let Local Users Gain Elevated Privileges
19055| [1010081] Exim Buffer Overflows in 'accept.c' and 'verify.c' Let Remote Users Execute Arbitrary Code
19056| [1007609] Exim Heap Overflow in 'smtp_in.c' May Allow Remote Arbitrary Code Execution
19057| [1005756] Exim Mail Server Format String Bug Lets Local Exim Administrators Execute Arbitrary Code With Root Privileges
19058| [1003547] Potential Bug in Exim Mail Server May Let Local Users Execute Code With Root Privileges
19059| [1003014] Exim Mail Server Pipe Address Validation Error May Let Remote Users Execute Arbitrary Code With Root Privileges in a Certain Configuration
19060| [1001694] Exim Mail Server May Allow Remote Users to Execute Arbitrary Code with Root-Level Privileges on the Server
19061|
19062| OSVDB - http://www.osvdb.org:
19063| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
19064| [87599] Mozilla Multiple Product copyTexImage2D Call Image Dimension Handling Memory Corruption
19065| [87581] Mozilla Multiple Product texImage2D Call Handling Memory Corruption
19066| [86616] Exim src/dkim.c dkim_exim_query_dns_txt() Function DNS Record Parsing Remote Overflow
19067| [81523] Mozilla Multiple Product WebGL texImage2D() Function JSVAL_TO_OBJECT Remote Code Execution
19068| [72642] Exim DKIM Identity Lookup Item Remote Code Execution
19069| [72156] Exim src/dkim.c dkim_exim_verify_finish() Function DKIM-Signature Header Format String
19070| [70696] Exim log.c open_log() Function Local Privilege Escalation
19071| [69860] Exim exim User Account Configuration File Directive Local Privilege Escalation
19072| [69685] Exim string_format Function Remote Overflow
19073| [65159] Exim transports/appendfile.c MBX Locking Race Condition Permission Modification
19074| [65158] Exim transports/appendfile.c Hardlink Handling Arbitrary File Overwrite
19075| [57575] teximg Plugin for ikiwiki TEX Command Arbitrary File Local Disclosure
19076| [23849] sa-exim greylistclean.cron Arbitrary File Deletion
19077| [13073] Oracle Database Server Advanced Queuing Component dbms_transform_eximp Unspecified Security Issue
19078| [12946] Exim -bh Command Line Option dns_build_reverse Function Local Overflow
19079| [12727] Exim SPA Authentication spa_base64_to_bits Function Remote Overflow
19080| [12726] Exim -be Command Line Option host_aton Function Local Overflow
19081| [10877] Exim smtp_in.c HELO/EHLO Remote Overflow
19082| [10360] Exim daemon.c pid_file_path Variable Manipulation Arbitrary Command Execution
19083| [10032] libXpm CreateXImage Function Integer Overflow
19084| [7160] Exim .forward :include: Option Privilege Escalation
19085| [6479] Vexim COOKIE Authentication Credential Disclosure
19086| [6478] Vexim Multiple Parameter SQL Injection
19087| [5930] Exim Parenthesis File Name Filter Bypass
19088| [5897] Exim header_syntax Function Remote Overflow
19089| [5896] Exim sender_verify Function Remote Overflow
19090| [5530] Exim Localhost Name Arbitrary Command Execution
19091| [5330] Exim Configuration File Variable Overflow
19092| [1855] Exim Batched SMTP Mail Header Format String
19093|_
19094587/tcp open smtp Exim smtpd 4.93
19095| vulscan: VulDB - https://vuldb.com:
19096| [141327] Exim up to 4.92.1 Backslash privilege escalation
19097| [138827] Exim up to 4.92 Expansion Code Execution
19098| [135932] Exim up to 4.92 privilege escalation
19099| [113048] Exim up to 4.90 SMTP Listener Message memory corruption
19100| [109969] Exim 4.88/4.89 SMTP Daemon receive.c bdat_getc denial of service
19101| [109968] Exim 4.88/4.89 SMTP Daemon receive.c receive_msg memory corruption
19102| [94599] Exim up to 4.87 information disclosure
19103| [13422] Exim 4.82 Mail Header dmarc.c expand_string memory corruption
19104| [6817] Exim up to 4.80 src/dkim.c dkim_exim_query_dns_txt memory corruption
19105| [58841] exim up to 4.69 dkim_exim_verify_finish memory corruption
19106| [57462] Exim up to 4.75 Filesystem memory corruption
19107| [4280] Exim Server 4.x open_log race condition
19108|
19109| MITRE CVE - https://cve.mitre.org:
19110| [CVE-2012-5671] Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.
19111| [CVE-2012-0478] The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.
19112| [CVE-2011-1764] Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.
19113| [CVE-2011-1407] The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.
19114| [CVE-2011-0017] The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
19115| [CVE-2010-4345] Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
19116| [CVE-2010-4344] Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
19117| [CVE-2010-2024] transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.
19118| [CVE-2010-2023] transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.
19119| [CVE-2006-1251] Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
19120| [CVE-2005-0022] Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.
19121| [CVE-2005-0021] Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.
19122| [CVE-2004-0400] Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.
19123| [CVE-2004-0399] Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.
19124| [CVE-2003-0743] Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.
19125| [CVE-2002-1381] Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
19126|
19127| SecurityFocus - https://www.securityfocus.com/bid/:
19128| [103049] Exim 'base64d()' Function Buffer Overflow Vulnerability
19129| [99252] Exim CVE-2017-1000369 Local Privilege Escalation Vulnerability
19130| [94947] Exim CVE-2016-9963 Unspecified Information Disclosure Vulnerability
19131| [84132] Exim CVE-2016-1531 Local Privilege Escalation Vulnerability
19132| [68857] Exim CVE-2014-2972 Local Privilege Escalation Vulnerability
19133| [67695] Exim 'dmarc.c' Remote Code Execution Vulnerability
19134| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
19135| [56285] Exim DKIM DNS Decoding CVE-2012-5671 Remote Buffer Overflow Vulnerability
19136| [47836] Exim DKIM CVE-2011-1407 Remote Code Execution Vulnerability
19137| [47736] Exim 'dkim_exim_verify_finish()' Remote Format String Vulnerability
19138| [46065] Exim 'log.c' Local Privilege Escalation Vulnerability
19139| [45341] Exim ALT_CONFIG_ROOT_ONLY 'exim' User Local Privilege Escalation Vulnerability
19140| [45308] Exim Crafted Header Remote Code Execution Vulnerability
19141| [40454] Exim MBX Locking Insecure Temporary File Creation Vulnerability
19142| [40451] Exim Sticky Mail Directory Local Privilege Escalation Vulnerability
19143| [36181] ikiwiki 'teximg' Plugin Insecure TeX Commands Information Disclosure Vulnerability
19144| [23977] Exim SpamAssassin Reply Remote Buffer Overflow Vulnerability
19145| [17110] sa-exim Unauthorized File Access Vulnerability
19146| [12268] Exim IP Address Command Line Argument Local Buffer Overflow Vulnerability
19147| [12188] Exim SPA Authentication Remote Buffer Overflow Vulnerability
19148| [12185] Exim Illegal IPv6 Address Buffer Overflow Vulnerability
19149| [10291] Exim Header Syntax Checking Remote Stack Buffer Overrun Vulnerability
19150| [10290] Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
19151| [8518] Exim EHLO/HELO Remote Heap Corruption Vulnerability
19152| [6314] Exim Internet Mailer Format String Vulnerability
19153| [4096] Exim Configuration File Argument Command Line Buffer Overflow Vulnerability
19154| [3728] Exim Pipe Hostname Arbitrary Command Execution Vulnerability
19155| [2828] Exim Format String Vulnerability
19156| [1859] Exim Buffer Overflow Vulnerability
19157|
19158| IBM X-Force - https://exchange.xforce.ibmcloud.com:
19159| [84758] Exim sender_address parameter command execution
19160| [84015] Exim command execution
19161| [80186] Mozilla Firefox, Thunderbird, and SeaMonkey copyTexImage2D code execution
19162| [80184] Mozilla Firefox, Thunderbird, and SeaMonkey texImage2D calls code execution
19163| [79615] Exim dkim_exim_query_dns_txt() buffer overflow
19164| [75155] Mozilla Firefox, Thunderbird, and SeaMonkey texImage2D denial of service
19165| [67455] Exim DKIM processing code execution
19166| [67299] Exim dkim_exim_verify_finish() format string
19167| [65028] Exim open_log privilege escalation
19168| [63967] Exim config file privilege escalation
19169| [63960] Exim header buffer overflow
19170| [59043] Exim mail directory privilege escalation
19171| [59042] Exim MBX symlink
19172| [52922] ikiwiki teximg plugin information disclosure
19173| [34265] Exim spamd buffer overflow
19174| [25286] Sa-exim greylistclean.cron file deletion
19175| [22687] RHSA-2005:025 updates for exim not installed
19176| [18901] Exim dns_build_reverse buffer overflow
19177| [18764] Exim spa_base64_to_bits function buffer overflow
19178| [18763] Exim host_aton buffer overflow
19179| [16079] Exim require_verify buffer overflow
19180| [16077] Exim header_check_syntax buffer overflow
19181| [16075] Exim sender_verify buffer overflow
19182| [13067] Exim HELO or EHLO command heap overflow
19183| [10761] Exim daemon.c format string
19184| [8194] Exim configuration file -c command-line argument buffer overflow
19185| [7738] Exim allows attacker to hide commands in localhost names using pipes
19186| [6671] Exim "
19187| [1893] Exim MTA allows local users to gain root privileges
19188|
19189| Exploit-DB - https://www.exploit-db.com:
19190| [16925] Exim4 <= 4.69 - string_format Function Heap Buffer Overflow
19191| [15725] Exim 4.63 Remote Root Exploit
19192| [1009] Exim <= 4.41 dns_build_reverse Local Exploit
19193| [812] Exim <= 4.43 auth_spa_server() Remote PoC Exploit
19194| [796] Exim <= 4.42 Local Root Exploit
19195| [756] Exim <= 4.41 dns_build_reverse Local Exploit PoC
19196|
19197| OpenVAS (Nessus) - http://www.openvas.org:
19198| [100663] Exim < 4.72 RC2 Multiple Vulnerabilities
19199|
19200| SecurityTracker - https://www.securitytracker.com:
19201| [1025539] Exim DKIM Processing Flaw Lets Remote Users Execute Arbitrary Code
19202| [1025504] Exim DKIM Signature Format String Flaw Lets Remote Users Execute Arbitrary Code
19203| [1024859] Exim Configuration File Capability Lets Local Users Gain Elevated Privileges
19204| [1024858] Exim Buffer Overfow in string_format() Lets Remote Users Execute Arbitrary Code
19205| [1012904] Exim Buffer Overflow in dns_build_reverse() Lets Local Users Obtain Elevated Privileges
19206| [1012771] Exim Buffer Overflows in host_aton() and spa_base64_to_bits() May Let Local Users Gain Elevated Privileges
19207| [1010081] Exim Buffer Overflows in 'accept.c' and 'verify.c' Let Remote Users Execute Arbitrary Code
19208| [1007609] Exim Heap Overflow in 'smtp_in.c' May Allow Remote Arbitrary Code Execution
19209| [1005756] Exim Mail Server Format String Bug Lets Local Exim Administrators Execute Arbitrary Code With Root Privileges
19210| [1003547] Potential Bug in Exim Mail Server May Let Local Users Execute Code With Root Privileges
19211| [1003014] Exim Mail Server Pipe Address Validation Error May Let Remote Users Execute Arbitrary Code With Root Privileges in a Certain Configuration
19212| [1001694] Exim Mail Server May Allow Remote Users to Execute Arbitrary Code with Root-Level Privileges on the Server
19213|
19214| OSVDB - http://www.osvdb.org:
19215| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
19216| [87599] Mozilla Multiple Product copyTexImage2D Call Image Dimension Handling Memory Corruption
19217| [87581] Mozilla Multiple Product texImage2D Call Handling Memory Corruption
19218| [86616] Exim src/dkim.c dkim_exim_query_dns_txt() Function DNS Record Parsing Remote Overflow
19219| [81523] Mozilla Multiple Product WebGL texImage2D() Function JSVAL_TO_OBJECT Remote Code Execution
19220| [72642] Exim DKIM Identity Lookup Item Remote Code Execution
19221| [72156] Exim src/dkim.c dkim_exim_verify_finish() Function DKIM-Signature Header Format String
19222| [70696] Exim log.c open_log() Function Local Privilege Escalation
19223| [69860] Exim exim User Account Configuration File Directive Local Privilege Escalation
19224| [69685] Exim string_format Function Remote Overflow
19225| [65159] Exim transports/appendfile.c MBX Locking Race Condition Permission Modification
19226| [65158] Exim transports/appendfile.c Hardlink Handling Arbitrary File Overwrite
19227| [57575] teximg Plugin for ikiwiki TEX Command Arbitrary File Local Disclosure
19228| [23849] sa-exim greylistclean.cron Arbitrary File Deletion
19229| [13073] Oracle Database Server Advanced Queuing Component dbms_transform_eximp Unspecified Security Issue
19230| [12946] Exim -bh Command Line Option dns_build_reverse Function Local Overflow
19231| [12727] Exim SPA Authentication spa_base64_to_bits Function Remote Overflow
19232| [12726] Exim -be Command Line Option host_aton Function Local Overflow
19233| [10877] Exim smtp_in.c HELO/EHLO Remote Overflow
19234| [10360] Exim daemon.c pid_file_path Variable Manipulation Arbitrary Command Execution
19235| [10032] libXpm CreateXImage Function Integer Overflow
19236| [7160] Exim .forward :include: Option Privilege Escalation
19237| [6479] Vexim COOKIE Authentication Credential Disclosure
19238| [6478] Vexim Multiple Parameter SQL Injection
19239| [5930] Exim Parenthesis File Name Filter Bypass
19240| [5897] Exim header_syntax Function Remote Overflow
19241| [5896] Exim sender_verify Function Remote Overflow
19242| [5530] Exim Localhost Name Arbitrary Command Execution
19243| [5330] Exim Configuration File Variable Overflow
19244| [1855] Exim Batched SMTP Mail Header Format String
19245|_
19246993/tcp open imaps?
19247995/tcp open pop3s?
192483306/tcp open mysql MySQL (unauthorized)
19249| vulscan: VulDB - https://vuldb.com:
19250| [141414] LibreNMS up to 1.47 inventory.inc.php mysqli_escape_real_string Parameter cross site scripting
19251| [140101] Yandex ClickHouse MySQL Client information disclosure
19252| [139468] cPanel up to 60.0.24 MySQL Upgrade File privilege escalation
19253| [139350] cPanel up to 64.0.20 convert_roundcube_mysql2sqlite privilege escalation
19254| [139349] cPanel up to 64.0.20 convert_roundcube_mysql2sqlite privilege escalation
19255| [139308] cPanel up to 67.9999.102 WHM MySQL Password Change Interfaces Stored cross site scripting
19256| [138305] SaltStack Salt 2018.3/2019.2 mysqluser_chpass sql injection
19257| [138102] Oracle MySQL Server up to 8.0.16 InnoDB unknown vulnerability
19258| [138101] Oracle MySQL Server up to 8.0.16 Privileges unknown vulnerability
19259| [138100] Oracle MySQL Server up to 5.6.44/5.7.18 Privileges unknown vulnerability
19260| [138099] Oracle MySQL Server up to 5.6.44/5.7.26/8.0.16 Compiling information disclosure
19261| [138098] Oracle MySQL Server up to 5.7.26/8.0.16 Audit Plug-in unknown vulnerability
19262| [138097] Oracle MySQL Server up to 5.7.26/8.0.16 Client programs denial of service
19263| [138096] Oracle MySQL Server up to 8.0.16 Roles denial of service
19264| [138095] Oracle MySQL Server up to 8.0.16 Privileges denial of service
19265| [138094] Oracle MySQL Server up to 5.7.25/8.0.15 Replication denial of service
19266| [138093] Oracle MySQL Server up to 8.0.16 Options denial of service
19267| [138092] Oracle MySQL Server up to 8.0.16 Optimizer denial of service
19268| [138091] Oracle MySQL Server up to 8.0.16 Optimizer denial of service
19269| [138090] Oracle MySQL Server up to 8.0.16 Optimizer denial of service
19270| [138089] Oracle MySQL Server up to 8.0.16 Optimizer denial of service
19271| [138088] Oracle MySQL Server up to 8.0.16 Optimizer denial of service
19272| [138087] Oracle MySQL Server up to 8.0.16 Optimizer denial of service
19273| [138086] Oracle MySQL Server up to 8.0.16 Optimizer denial of service
19274| [138085] Oracle MySQL Server up to 5.7.26/8.0.16 Optimizer denial of service
19275| [138084] Oracle MySQL Server up to 5.7.26/8.0.16 Optimizer denial of service
19276| [138083] Oracle MySQL Server up to 8.0.12 GIS denial of service
19277| [138082] Oracle MySQL Server up to 8.0.16 FTS denial of service
19278| [138081] Oracle MySQL Server up to 8.0.16 DML denial of service
19279| [138080] Oracle MySQL Server up to 8.0.16 Components denial of service
19280| [138079] Oracle MySQL Server up to 5.6.44/5.7.26/8.0.16 Pluggable Auth denial of service
19281| [138078] Oracle MySQL Server up to 8.0.16 InnoDB denial of service
19282| [138077] Oracle MySQL Server up to 8.0.15 InnoDB denial of service
19283| [138076] Oracle MySQL Server up to 8.0.16 InnoDB denial of service
19284| [138074] Oracle MySQL Server up to 8.0.12 Roles denial of service
19285| [138073] Oracle MySQL Server up to 5.7.26/8.0.16 Audit Log denial of service
19286| [138072] Oracle MySQL Server up to 5.7.26/8.0.16 Privileges unknown vulnerability
19287| [138071] Oracle MySQL Server up to 5.7.23 Replication unknown vulnerability
19288| [138070] Oracle MySQL Server up to 5.6.44/5.7.26/8.0.16 Audit unknown vulnerability
19289| [138069] Oracle MySQL Server up to 5.7.26/8.0.16 InnoDB unknown vulnerability
19290| [138068] Oracle MySQL Workbench up to 8.0.16 OpenSSL information disclosure
19291| [138067] Oracle MySQL Server up to 5.6.44/5.7.26/8.0.16 XML denial of service
19292| [138066] Oracle MySQL Server up to 5.6.44/5.7.26/8.0.16 Parser denial of service
19293| [138065] Oracle MySQL Server up to 8.0.16 Optimizer denial of service
19294| [138064] Oracle MySQL Server up to 8.0.16 Optimizer denial of service
19295| [138063] Oracle MySQL Server up to 8.0.12 Data Dictionary denial of service
19296| [138062] Oracle MySQL Server up to 8.0.16 Charsets denial of service
19297| [138061] Oracle MySQL Server up to 8.0.16 Replication unknown vulnerability
19298| [138060] Oracle MySQL Server up to 8.0.16 InnoDB Cluster unknown vulnerability
19299| [138059] Oracle MySQL Enterprise Monitor up to 4.0.9/8.0.14 Spring Framework denial of service
19300| [138058] Oracle MySQL Server up to 5.7.26/8.0.15 cURL unknown vulnerability
19301| [133701] Oracle MySQL Server up to 8.0.15 Replication denial of service
19302| [133700] Oracle MySQL Server up to 8.0.15 Replication denial of service
19303| [133698] Oracle MySQL Server up to 8.0.15 Group Replication Plugin denial of service
19304| [133697] Oracle MySQL Server up to 8.0.15 Roles denial of service
19305| [133695] Oracle MySQL Server up to 8.0.15 Privileges denial of service
19306| [133691] Oracle MySQL Server up to 8.0.15 Replication denial of service
19307| [133687] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19308| [133686] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19309| [133685] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19310| [133684] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19311| [133683] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19312| [133682] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19313| [133681] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19314| [133680] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19315| [133677] Oracle MySQL Server up to 8.0.15 Information Schema denial of service
19316| [133676] Oracle MySQL Server up to 8.0.15 DDL denial of service
19317| [133675] Oracle MySQL Server up to 8.0.15 DDL denial of service
19318| [133672] Oracle MySQL Server up to 8.0.15 InnoDB denial of service
19319| [133668] Oracle MySQL Server up to 8.0.15 Replication denial of service
19320| [133666] Oracle MySQL Server up to 8.0.15 Options denial of service
19321| [133662] Oracle MySQL Connectors up to 8.0.15 Connector/J unknown vulnerability
19322| [133661] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19323| [133660] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19324| [133659] Oracle MySQL Server up to 8.0.15 Optimizer denial of service
19325| [129647] Oracle MySQL Server up to 5.7.24/8.0.13 Privileges denial of service
19326| [129646] Oracle MySQL Server up to 5.7.24/8.0.13 Privileges denial of service
19327| [129645] Oracle MySQL Server up to 5.6.42/5.7.24/8.0.13 Replication denial of service
19328| [129644] Oracle MySQL Server up to 5.7.24/8.0.13 Partition denial of service
19329| [129643] Oracle MySQL Server up to 8.0.13 Optimizer denial of service
19330| [129642] Oracle MySQL Server up to 5.6.42/5.7.24/8.0.13 Optimizer denial of service
19331| [129641] Oracle MySQL Server up to 5.6.42/5.7.24/8.0.13 Optimizer denial of service
19332| [129640] Oracle MySQL Server up to 5.7.24/8.0.13 Optimizer denial of service
19333| [129639] Oracle MySQL Server up to 5.6.42/5.7.24/8.0.13 DDL denial of service
19334| [129638] Oracle MySQL Server up to 8.0.13 DDL denial of service
19335| [129637] Oracle MySQL Server up to 8.0.13 DDL denial of service
19336| [129636] Oracle MySQL Server up to 8.0.13 Connection denial of service
19337| [129635] Oracle MySQL Server up to 5.7.24/8.0.13 InnoDB denial of service
19338| [129634] Oracle MySQL Server up to 8.0.13 InnoDB denial of service
19339| [129631] Oracle MySQL Server up to 8.0.13 Replication denial of service
19340| [129630] Oracle MySQL Server up to 5.6.42/5.7.24/8.0.13 Connection Handling denial of service
19341| [129629] Oracle MySQL Server up to 5.6.42/5.7.24/8.0.13 Parser denial of service
19342| [129628] Oracle MySQL Server up to 5.7.24/8.0.13 Parser denial of service
19343| [129627] Oracle MySQL Server up to 5.6.42/5.7.24/8.0.13 PS denial of service
19344| [129626] Oracle MySQL Server up to 5.6.42/5.7.24/8.0.13 Optimizer denial of service
19345| [129625] Oracle MySQL Server up to 8.0.13 Privileges unknown vulnerability
19346| [129624] Oracle MySQL Server up to 5.6.42/5.7.24/8.0.13 Replication unknown vulnerability
19347| [129623] Oracle MySQL Workbench up to 8.0.13 OpenSSL denial of service
19348| [129622] Oracle MySQL Connectors up to 2.1.8/8.0.13 Connector/Python unknown vulnerability
19349| [129621] Oracle MySQL Workbench up to 8.0.13 unknown vulnerability
19350| [127905] Open Dental up to 18.3 MySQL Database Default Credentials weak authentication
19351| [127404] Drobo 5N2 NAS 4.0.5-13.28.96115 MySQL API Error Page cross site scripting
19352| [127403] Drobo 5N2 NAS 4.0.5-13.28.96115 /mysql/api/droboapp/data information disclosure
19353| [127400] Drobo 5N2 NAS 4.0.5-13.28.96115 Access Control /mysql/api/logfile.php Parameter information disclosure
19354| [127396] Drobo 5N2 NAS 4.0.5-13.28.96115 Access Control /mysql/api/drobo.php information disclosure
19355| [127395] Drobo 5N2 NAS 4.0.5-13.28.96115 Access Control /mysql/api/diags.php Parameter information disclosure
19356| [127350] Dell OpenManage Network Manager up to 6.4.x MySQL privilege escalation
19357| [126982] LAOBANCMS 2.0 install/mysql_hy.php directory traversal
19358| [126687] LAOBANCMS 2.0 mysql_hy.php privilege escalation
19359| [125937] mysql-binuuid-rails up to 1.1.0 Database Column sql injection
19360| [125825] ThinkPHP 3.2.4 Mysql.class.php parseKey Parameter sql injection
19361| [125568] Oracle MySQL Server up to 8.0.12 Privileges unknown vulnerability
19362| [125567] Oracle MySQL Server up to 5.7.23/8.0.12 Logging denial of service
19363| [125566] Oracle MySQL Server up to 5.7.23/8.0.12 InnoDB denial of service
19364| [125565] Oracle MySQL Server up to 8.0.12 Windows denial of service
19365| [125564] Oracle MySQL Server up to 5.5.61/5.6.41/5.7.23/8.0.12 Storage Engines denial of service
19366| [125563] Oracle MySQL Server up to 8.0.12 Roles denial of service
19367| [125562] Oracle MySQL Server up to 5.6.41/5.7.23/8.0.12 RBR denial of service
19368| [125561] Oracle MySQL Server up to 5.7.23/8.0.12 Partition denial of service
19369| [125560] Oracle MySQL Server up to 8.0.12 Optimizer denial of service
19370| [125559] Oracle MySQL Server up to 5.6.41/5.7.23/8.0.12 Memcached denial of service
19371| [125558] Oracle MySQL Server up to 8.0.12 JSON denial of service
19372| [125557] Oracle MySQL Server up to 8.0.12 Information Schema denial of service
19373| [125556] Oracle MySQL Server up to 8.0.12 DDL denial of service
19374| [125555] Oracle MySQL Server up to 5.7.23/8.0.12 InnoDB denial of service
19375| [125554] Oracle MySQL Server up to 5.7.23/8.0.12 InnoDB denial of service
19376| [125553] Oracle MySQL Server up to 5.7.23/8.0.12 InnoDB denial of service
19377| [125552] Oracle MySQL Server up to 5.7.23/8.0.12 InnoDB denial of service
19378| [125551] Oracle MySQL Server up to 5.7.23/8.0.12 Partition denial of service
19379| [125549] Oracle MySQL Server up to 5.7.23/8.0.12 Optimizer denial of service
19380| [125548] Oracle MySQL Server up to 5.6.41/5.7.23/8.0.12 Merge denial of service
19381| [125547] Oracle MySQL Server up to 8.0.12 DDL denial of service
19382| [125546] Oracle MySQL Server up to 5.7.23/8.0.12 InnoDB denial of service
19383| [125545] Oracle MySQL Server up to 5.7.23/8.0.12 Audit denial of service
19384| [125544] Oracle MySQL Server up to 8.0.12 Parser denial of service
19385| [125543] Oracle MySQL Server up to 5.5.61/5.6.41/5.7.23/8.0.12 Parser denial of service
19386| [125542] Oracle MySQL Server up to 8.0.12 Optimizer denial of service
19387| [125541] Oracle MySQL Server up to 8.0.12 Optimizer denial of service
19388| [125540] Oracle MySQL Server up to 8.0.12 DML denial of service
19389| [125539] Oracle MySQL Server up to 5.6.41/5.7.23/8.0.12 InnoDB denial of service
19390| [125538] Oracle MySQL Server up to 5.6.41/5.7.23/8.0.12 InnoDB denial of service
19391| [125537] Oracle MySQL Server up to 5.6.41/5.7.23/8.0.12 InnoDB denial of service
19392| [125536] Oracle MySQL Server up to 5.7.23/8.0.12 Parser denial of service
19393| [125535] Oracle MySQL Server up to 5.5.61/5.6.41/5.7.23/8.0.12 InnoDB unknown vulnerability
19394| [125534] Oracle MySQL Enterprise Monitor up to 3.4.9.4237/4.0.6.5281/8.0.2.8191 Monitoring unknown vulnerability
19395| [125533] Oracle MySQL Connectors up to 8.0.12 Connector/J unknown vulnerability
19396| [125532] Oracle MySQL Enterprise Monitor up to 3.4.9.4237/4.0.6.5281/8.0.2.8191 Monitoring unknown vulnerability
19397| [125531] Oracle MySQL Enterprise Monitor up to 3.4.9.4237/4.0.6.5281/8.0.2.8191 Monitoring unknown vulnerability
19398| [125415] Oracle Enterprise Manager for MySQL Database 13.2 EM Plugin unknown vulnerability
19399| [122549] PHP up to 7.1.5 mysqli_real_escape_string memory corruption
19400| [122201] mysql_user Module up to 2.2.0 on Ansible Password Change weak authentication
19401| [121802] Oracle MySQL Server up to 8.0.11 DDL unknown vulnerability
19402| [121800] Oracle MySQL Server up to 5.5.60/5.6.40/5.7.22 Encryption weak encryption
19403| [121799] Oracle MySQL Server up to 5.5.60/5.6.40/5.7.22 Options unknown vulnerability
19404| [121798] Oracle MySQL Workbench up to 6.3.10 Encryption weak encryption
19405| [121797] Oracle MySQL Server up to 5.7.22/8.0.11 Privileges unknown vulnerability
19406| [121796] Oracle MySQL Server up to 5.5.60/5.6.40/5.7.22 MyISAM information disclosure
19407| [121795] Oracle MySQL Server up to 8.0.11 Privileges denial of service
19408| [121794] Oracle MySQL Server up to 5.5.60 Privileges denial of service
19409| [121793] Oracle MySQL Server up to 8.0.11 Replication denial of service
19410| [121792] Oracle MySQL Server up to 5.7.22 DML denial of service
19411| [121791] Oracle MySQL Server up to 8.0.11 DDL denial of service
19412| [121790] Oracle MySQL Server up to 8.0.11 DDL denial of service
19413| [121789] Oracle MySQL Server up to 5.7.22/8.0.11 DDL denial of service
19414| [121788] Oracle MySQL Server up to 5.7.22/8.0.11 DDL denial of service
19415| [121787] Oracle MySQL Server up to 8.0.11 InnoDB denial of service
19416| [121786] Oracle MySQL Server up to 5.7.22 Audit Log denial of service
19417| [121785] Oracle MySQL Client up to 5.5.60/5.6.40/5.7.22/8.0.11 Client Programs denial of service
19418| [121784] Oracle MySQL Server up to 5.6.40/5.7.22/8.0.11 Memcached denial of service
19419| [121783] Oracle MySQL Server up to 8.0.11 Roles denial of service
19420| [121782] Oracle MySQL Workbench up to 8.0.11 denial of service
19421| [121781] Oracle MySQL Server up to 8.0.11 Optimizer denial of service
19422| [121780] Oracle MySQL Server up to 5.6.40/5.7.22/8.0.11 Installing denial of service
19423| [121779] Oracle MySQL Server up to 5.7.22/8.0.11 DML denial of service
19424| [121778] Oracle MySQL Server up to 5.7.22/8.0.11 InnoDB denial of service
19425| [121777] Oracle MySQL Server up to 5.5.60/5.6.40/5.7.22 Client mysqldump denial of service
19426| [121776] Oracle MySQL Enterprise Monitor up to 3.4.7.4297/4.0.4.5235/8.0.0.8131 Monitoring denial of service
19427| [121775] Oracle MySQL Connectors up to 5.3.10/8.0.11 Connector/ODBC denial of service
19428| [121774] Oracle MySQL Server up to 5.6.40/5.7.22/8.0.11 InnoDB denial of service
19429| [121773] Oracle MySQL Workbench up to 8.0.11 unknown vulnerability
19430| [121772] Oracle MySQL Enterprise Monitor up to 3.4.7.4297/4.0.4.5235/8.0.0.8131 Service Manager unknown vulnerability
19431| [121613] Oracle Enterprise Manager for MySQL Database up to 13.2.2.0.0 EM Plugin unknown vulnerability
19432| [120277] query-mysql 0.0.0/0.0.1/0.0.2 on Node.js sql injection
19433| [118340] mysqljs on Node.js Backdoor privilege escalation
19434| [118305] MySQL Module up to v2.0.0-alpha7 on Node.js mysql.escape sql injection
19435| [117517] MySQL Multi-Master Replication Manager 2.2.1 on Solaris mmm_agentd send_arp MMM Protocol Message command injection
19436| [117516] MySQL Multi-Master Replication Manager 2.2.1 on FreeBSD mmm_agentd clear_ip MMM Protocol Message command injection
19437| [117515] MySQL Multi-Master Replication Manager 2.2.1 on Solaris mmm_agentd clear_ip MMM Protocol Message command injection
19438| [117514] MySQL Multi-Master Replication Manager 2.2.1 on Linux mmm_agentd clear_ip MMM Protocol Message command injection
19439| [117513] MySQL Multi-Master Replication Manager 2.2.1 on FreeBSD mmm_agentd add_ip MMM Protocol Message command injection
19440| [117512] MySQL Multi-Master Replication Manager 2.2.1 on Solaris mmm_agentd add_ip MMM Protocol Message command injection
19441| [117511] MySQL Multi-Master Replication Manager 2.2.1 on Linux mmm_agentd add_ip MMM Protocol Message command injection
19442| [117510] MySQL Multi-Master Replication Manager 2.2.1 mmm_agentd _execute MMM Protocol Message command injection
19443| [117387] CSP MySQL User Manager 2.3.1 Username sql injection
19444| [116762] Oracle MySQL Server up to 5.5.59/5.6.39/5.7.21 DDL information disclosure
19445| [116761] Oracle MySQL Server up to 5.5.59/5.6.39/5.7.21 Locking denial of service
19446| [116759] Oracle MySQL Server up to 5.7.21 Group Replication GCS denial of service
19447| [116758] Oracle MySQL Server up to 5.7.21 Pluggable Auth denial of service
19448| [116757] Oracle MySQL Server up to 5.7.21 Performance Schema denial of service
19449| [116756] Oracle MySQL Server up to 5.7.21 Optimizer denial of service
19450| [116755] Oracle MySQL Server up to 5.5.59/5.6.39/5.7.21 Optimizer denial of service
19451| [116754] Oracle MySQL Server up to 5.7.21 Optimizer denial of service
19452| [116753] Oracle MySQL Server up to 5.7.21 Optimizer denial of service
19453| [116752] Oracle MySQL Server up to 5.7.21 DML denial of service
19454| [116751] Oracle MySQL Server up to 5.5.59/5.6.39/5.7.21 Privileges denial of service
19455| [116750] Oracle MySQL Server up to 5.7.21 InnoDB denial of service
19456| [116749] Oracle MySQL Server up to 5.7.21 InnoDB denial of service
19457| [116748] Oracle MySQL Server up to 5.6.39/5.7.21 InnoDB denial of service
19458| [116747] Oracle MySQL Server up to 5.7.21 InnoDB denial of service
19459| [116745] Oracle MySQL Server up to 5.7.21 Optimizer denial of service
19460| [116744] Oracle MySQL Server up to 5.6.39/5.7.21 InnoDB denial of service
19461| [116743] Oracle MySQL Server up to 5.7.21 InnoDB denial of service
19462| [116742] Oracle MySQL Server up to 5.5.59/5.6.39/5.7.21 Client programs denial of service
19463| [116741] Oracle MySQL Enterprise Monitor up to 3.3.7.3306/3.4.5.4248/4.0.2.5168 Monitoring: Agent (OpenSSL) information disclosure
19464| [116740] Oracle MySQL Server up to 5.7.21 Optimizer denial of service
19465| [116739] Oracle MySQL Server up to 5.7.21 Optimizer denial of service
19466| [116738] Oracle MySQL Server up to 5.5.59/5.6.39/5.7.21 DDL denial of service
19467| [116737] Oracle MySQL Server up to 5.6.39/5.7.21 Privileges denial of service
19468| [116736] Oracle MySQL Server up to 5.5.59/5.6.39/5.7.21 InnoDB denial of service
19469| [116735] Oracle MySQL Server up to 5.6.39/5.7.21 InnoDB denial of service
19470| [116734] Oracle MySQL Server up to 5.6.39/5.7.21 InnoDB denial of service
19471| [116733] Oracle MySQL Server up to 5.6.39 GIS Extension denial of service
19472| [116622] Oracle Enterprise Manager for MySQL Database 12.1.0.4 EM Plugin: General (Apache Tomcat) unknown vulnerability
19473| [116620] Oracle Enterprise Manager for MySQL Database 12.1.0.4 EM Plugin: General (Spring Framework) unknown vulnerability
19474| [116619] Oracle Enterprise Manager for MySQL Database 12.1.0.4 EM Plugin: General unknown vulnerability
19475| [115836] Juniper Junos Space up to 13.3R1.7 MySQL Server Default Credentials weak authentication
19476| [115216] MySQL for PCF Tiles up to 1.7.9 AWS Access Key privilege escalation
19477| [114055] Couch up to 2.0 mysql2i.func.php Request information disclosure
19478| [112112] Oracle MySQL Server up to 5.6.38/5.7.20 Performance Schema information disclosure
19479| [112111] Oracle MySQL Server up to 5.6.38/5.7.20 Performance Schema denial of service
19480| [112110] Oracle MySQL Server up to 5.7.20 Optimizer denial of service
19481| [112109] Oracle MySQL Server up to 5.7.20 Optimizer denial of service
19482| [112108] Oracle MySQL Server up to 5.7.20 InnoDB denial of service
19483| [112107] Oracle MySQL Server up to 5.7.20 DML denial of service
19484| [112106] Oracle MySQL Server up to 5.7.20 DML denial of service
19485| [112105] Oracle MySQL Server up to 5.7.20 DML denial of service
19486| [112104] Oracle MySQL Server up to 5.6.38/5.7.19 Partition denial of service
19487| [112103] Oracle MySQL Server up to 5.6.38/5.7.20 Replication denial of service
19488| [112102] Oracle MySQL Server up to 5.6.38/5.7.20 Packaging information disclosure
19489| [112101] Oracle MySQL Enterprise Monitor up to 3.3.6.3293/3.4.4.4226/4.0.0.5135 Monitoring information disclosure
19490| [112100] Oracle MySQL Connectors up to 5.3.9 ODBC Connector information disclosure
19491| [112099] Oracle MySQL Server up to 5.5.58/5.6.38/5.7.20 Optimizer denial of service
19492| [112098] Oracle MySQL Server up to 5.5.58/5.6.38/5.7.20 Optimizer denial of service
19493| [112097] Oracle MySQL Server up to 5.5.58/5.6.38/5.7.20 Optimizer denial of service
19494| [112096] Oracle MySQL Server up to 5.6.38/5.7.20 GIS denial of service
19495| [112095] Oracle MySQL Server up to 5.5.58/5.6.38/5.7.20 DDL denial of service
19496| [112094] Oracle MySQL Server up to 5.6.38/5.7.20 Privileges denial of service
19497| [112093] Oracle MySQL Server up to 5.6.38/5.7.20 InnoDB denial of service
19498| [112092] Oracle MySQL Server up to 5.6.38/5.7.20 Stored Procedure denial of service
19499| [112091] Oracle MySQL Server up to 5.5.58/5.6.38/5.7.19 Partition denial of service
19500| [112090] Oracle MySQL Server up to 5.6.38/5.7.20 Privileges denial of service
19501| [112089] Oracle MySQL Connectors up to 6.9.9/6.10.4 Connector/Net denial of service
19502| [112088] Oracle MySQL Enterprise Monitor up to 3.3.6.3293/3.4.4.4226/4.0.0.5135 Monitoring privilege escalation
19503| [110974] puppetlabs-mysql up to 3.6.0 Parameter weak authentication
19504| [108192] Oracle MySQL Server up to 5.7.18 InnoDB denial of service
19505| [108190] Oracle MySQL Server up to 5.6.37/5.7.19 InnoDB denial of service
19506| [108189] Oracle MySQL Server up to 5.7.18 Stored Procedure denial of service
19507| [108188] Oracle MySQL Server up to 5.7.19 Replication denial of service
19508| [108187] Oracle MySQL Server up to 5.6.37/5.7.19 Optimizer denial of service
19509| [108186] Oracle MySQL Server up to 5.6.36/5.7.18 Optimizer denial of service
19510| [108185] Oracle MySQL Server up to 5.6.37/5.7.19 Optimizer denial of service
19511| [108184] Oracle MySQL Server up to 5.6.37/5.7.19 Memcached denial of service
19512| [108183] Oracle MySQL Server up to 5.7.19 InnoDB denial of service
19513| [108182] Oracle MySQL Server up to 5.7.19 FTS denial of service
19514| [108181] Oracle MySQL Server up to 5.7.18 DML denial of service
19515| [108180] Oracle MySQL Server up to 5.7.19 Group Replication GCS denial of service
19516| [108179] Oracle MySQL Server up to 5.6.37/5.7.19 Performance Schema denial of service
19517| [108178] Oracle MySQL Connectors up to 6.9.9 Connector/Net denial of service
19518| [108177] Oracle MySQL Connectors up to 6.9.9 Connector/Net unknown vulnerability
19519| [108176] Oracle MySQL Server up to 5.5.57/5.6.37/5.7.11 Optimizer denial of service
19520| [108175] Oracle MySQL Server up to 5.7.19 Optimizer denial of service
19521| [108174] Oracle MySQL Server up to 5.6.37/5.7.19 FTS denial of service
19522| [108173] Oracle MySQL Server up to 5.5.57/5.6.37/5.7.19 DDL denial of service
19523| [108172] Oracle MySQL Server up to 5.5.57/5.6.37/5.7.19 Client programs information disclosure
19524| [108171] Oracle MySQL Server up to 5.6.35/5.7.18 OpenSSL denial of service
19525| [108170] Oracle MySQL Server up to 5.6.37/5.7.19 Pluggable Auth denial of service
19526| [108169] Oracle MySQL Enterprise Monitor up to 3.2.8.2223/3.3.4.3247/3.4.2.4181 Apache Tomcat unknown vulnerability
19527| [108168] Oracle MySQL Enterprise Monitor up to 3.2.8.2223/3.3.4.3247/3.4.2.4181 Web unknown vulnerability
19528| [104089] Oracle MySQL Server up to 5.5.56/5.6.36/5.7.18 DDL unknown vulnerability
19529| [104088] Oracle MySQL Server up to 5.7.18 C API information disclosure
19530| [104087] Oracle MySQL Server up to 5.5.56/5.6.36/5.7.18 DDL unknown vulnerability
19531| [104086] Oracle MySQL Server up to 5.5.56/5.6.36/5.7.18 Client mysqldump unknown vulnerability
19532| [104085] Oracle MySQL Server up to 5.6.36/5.7.18 Replication denial of service
19533| [104084] Oracle MySQL Server up to 5.6.36/5.7.18 Replication denial of service
19534| [104083] Oracle MySQL Server up to 5.5.56/5.6.36/5.7.18 Charsets denial of service
19535| [104082] Oracle MySQL Cluster up to 7.3.5 CLSTCONF memory corruption
19536| [104081] Oracle MySQL Server up to 5.7.16 X Plugin denial of service
19537| [104080] Oracle MySQL Server up to 5.7.18 Optimizer denial of service
19538| [104079] Oracle MySQL Server up to 5.7.18 Optimizer denial of service
19539| [104078] Oracle MySQL Server up to 5.7.18 Optimizer denial of service
19540| [104077] Oracle MySQL Server up to 5.7.18 DML denial of service
19541| [104076] Oracle MySQL Server up to 5.7.18 DML denial of service
19542| [104075] Oracle MySQL Server up to 5.5.56/5.6.36/5.7.18 DML denial of service
19543| [104074] Oracle MySQL Server up to 5.7.18 DML denial of service
19544| [104073] Oracle MySQL Server up to 5.7.18 DML denial of service
19545| [104072] Oracle MySQL Server up to 5.7.18 X Plugin denial of service
19546| [104071] Oracle MySQL Server up to 5.7.18 UDF denial of service
19547| [104069] Oracle MySQL Server up to 5.5.56/5.6.36/5.7.18 C API denial of service
19548| [104068] Oracle MySQL Connectors up to 6.1.10 Connector/C denial of service
19549| [104067] Oracle MySQL Server up to 5.6.35/5.7.17 OpenSSL unknown vulnerability
19550| [104066] Oracle MySQL Connectors up to 5.3.7 OpenSSL unknown vulnerability
19551| [104065] Oracle MySQL Connectors up to 6.1.9 OpenSSL unknown vulnerability
19552| [104064] Oracle MySQL Server up to 5.6.36/5.7.18 DML denial of service
19553| [104063] Oracle MySQL Server up to 5.6.36/5.7.18 Memcached denial of service
19554| [104062] Oracle MySQL Enterprise Monitor up to 3.3.3.1199 Apache Tomcat unknown vulnerability
19555| [104061] Oracle MySQL Enterprise Monitor up to 3.2.7.1204/3.3.3.1199 Apache Tomcat unknown vulnerability
19556| [104060] Oracle MySQL Enterprise Monitor up to 3.1.5.7958/3.2.5.1141/3.3.2.1162 Apache Struts 2 unknown vulnerability
19557| [103583] phpMyAdmin 4.0/4.4/4.6 MySQL Database Connection privilege escalation
19558| [103578] MySQL Dumper 1.24 Stored cross site scripting
19559| [102980] DBD::mysql Module up to 4.043 on Perl SSL weak encryption
19560| [102979] DBD::mysql Module up to 4.043 on Perl Error Use-After-Free memory corruption
19561| [102618] KBVault Mysql Free Knowledge Base 0.16a File Upload Explorer.aspx privilege escalation
19562| [100915] Accellion FTA communication_p2p.php mysql_real_escape_string sql injection
19563| [100543] Oracle MySQL up to 5.1.40 Connector/J privilege escalation
19564| [100232] Oracle MySQL Server up to 5.7.17 Encryption weak encryption
19565| [100231] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Monitoring denial of service
19566| [100228] Oracle MySQL Workbench up to 6.3.8 Encryption information disclosure
19567| [100227] Oracle MySQL Server up to 5.7.17 C API information disclosure
19568| [100226] Oracle MySQL Server up to 5.7.17 Privileges unknown vulnerability
19569| [100225] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 DDL unknown vulnerability
19570| [100224] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 Privileges denial of service
19571| [100223] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 Privileges denial of service
19572| [100222] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 Privileges denial of service
19573| [100221] Oracle MySQL Server up to 5.7.17 Optimizer denial of service
19574| [100220] Oracle MySQL Server up to 5.7.17 DML denial of service
19575| [100219] Oracle MySQL Server up to 5.7.17 DML denial of service
19576| [100218] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 DML denial of service
19577| [100217] Oracle MySQL Server up to 5.7.17 Audit Plug-in denial of service
19578| [100215] Oracle MySQL Server up to 5.5.54/5.6.35 C API information disclosure
19579| [100214] Oracle MySQL Server up to 5.7.17 Privileges unknown vulnerability
19580| [100213] Oracle MySQL Cluster up to 7.2.27/7.3.16/7.4.14/7.5.5 DD denial of service
19581| [100212] Oracle MySQL Server up to 5.7.17 InnoDB denial of service
19582| [100211] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 OpenSSL information disclosure
19583| [100210] Oracle MySQL Enterprise Backup up to 3.12.3/4.0.3 ENTRBACK information disclosure
19584| [100209] Oracle MySQL Connectors up to 5.1.41 Connector/J unknown vulnerability
19585| [100208] Oracle MySQL Server up to 5.6.35 Optimizer denial of service
19586| [100207] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 Optimizer denial of service
19587| [100206] Oracle MySQL Server up to 5.7.17 DML denial of service
19588| [100205] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Apache Commons FileUpload denial of service
19589| [100204] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 Client mysqldump unknown vulnerability
19590| [100203] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 Thread Pooling denial of service
19591| [100202] Oracle MySQL Server up to 5.6.35/5.7.17 Pluggable Auth Integer denial of service
19592| [100201] Oracle MySQL Server up to 5.6.35/5.7.17 Memcached denial of service
19593| [100200] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 Optimizer denial of service
19594| [100199] Oracle MySQL Server up to 5.5.54/5.6.35/5.7.17 DML denial of service
19595| [100198] Oracle MySQL Workbench up to 6.3.7 OpenSSL memory corruption
19596| [100197] Oracle MySQL Enterprise Backup up to 3.12.2/4.0.1 ENTRBACK memory corruption
19597| [100196] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Monitoring: Server denial of service
19598| [100195] Oracle MySQL Workbench up to 6.3.8 OpenSSL denial of service
19599| [100194] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Struts 2 privilege escalation
19600| [99815] ATutor 2.2.1 mysql_connect.inc.php searchFriends sql injection
19601| [97041] MySQL DBD::mysql up to 4.38 denial of service
19602| [96814] MariaDB up to 5.5.54/10.0.29/10.1.21/10.2.3 libmysqlclient.so denial of service
19603| [96808] Oracle MySQL up to 5.6.21/5.7.4 libmysqlclient.so denial of service
19604| [95832] Zabbix up to 2.0.17/2.2.12/3.0.2 Configuration Script userparameter_mysql.conf) privilege escalation
19605| [95730] Oracle MySQL Server up to 5.7.16 Encryption weak encryption
19606| [95729] Oracle MySQL Server up to 5.7.16 X Plugin unknown vulnerability
19607| [95728] Oracle MySQL Cluster 7.2.25/7.3.14/7.4.12 Cluster NDBAPI denial of service
19608| [95727] Oracle MySQL Cluster 7.2.25/7.3.14/7.4.12 denial of service
19609| [95726] Oracle MySQL Cluster 7.2.19/7.3.8/7.4.5 denial of service
19610| [95723] Oracle MySQL Server 5.6.34/5.7.16 Replication denial of service
19611| [95722] Oracle MySQL Server up to 5.5.53 Charsets denial of service
19612| [95720] Oracle MySQL Cluster 7.2.26/7.3.14/7.4.12 NDBAPI denial of service
19613| [95719] Oracle MySQL Server up to 5.7.16 Optimizer denial of service
19614| [95716] Oracle MySQL Server up to 5.7.16 Replication denial of service
19615| [95715] Oracle MySQL Server 5.5.53/5.6.34/5.7.16 Optimizer denial of service
19616| [95714] Oracle MySQL Server 5.6.34 5.7.16 InnoDB denial of service
19617| [95713] Oracle MySQL Server 5.5.53/5.6.34/5.7.16 DML denial of service
19618| [95712] Oracle MySQL Server 5.6.34/5.7.16 DDL denial of service
19619| [95711] Oracle MySQL Server 5.5.53/5.6.34/5.7.16 DDL denial of service
19620| [95709] Oracle MySQL Server 5.6.34/5.7.16 Encryption denial of service
19621| [95708] Oracle MySQL Enterprise Monitor 3.1.3.7856 Monitoring Agent memory corruption
19622| [95707] Oracle MySQL Enterprise Monitor 3.1.4.7895/3.2.4.1102/3.3.0.1098 Monitoring denial of service
19623| [95706] Oracle MySQL Enterprise Monitor 3.1.4.7895/3.2.1.1049 Monitoring memory corruption
19624| [95705] Oracle MySQL Enterprise Monitor 3.1.5.7958/3.2.1.1049, Monitoring privilege escalation
19625| [95704] Oracle MySQL Enterprise Monitor 3.1.4.7895/3.2.1.1049 Monitoring unknown vulnerability
19626| [93866] DBD-mysql up to 3.x/4.040 on Perl Use-After-Free memory corruption
19627| [92923] Oracle MySQL Server up to 5.6.33/5.7.15 Encryption denial of service
19628| [92911] Oracle Communications Policy Management up to 9.7.3/9.9.1/10.4.1/12.1.1 MySQL weak encryption
19629| [92900] Oracle MySQL Server up to 5.5.51/5.6.32/5.7.14 Optimizer denial of service
19630| [92899] Oracle MySQL Server up to 5.6.31/5.7.13 InnoDB denial of service
19631| [92898] Oracle MySQL Server up to 5.5.51/5.6.32/5.7.14 GIS denial of service
19632| [92897] Oracle MySQL Server up to 5.5.51 DML denial of service
19633| [92896] Oracle MySQL Server up to 5.5.50/5.6.31/5.7.13 DML denial of service
19634| [92895] Oracle MySQL Server up to 5.6.31 5.7.13 DML denial of service
19635| [92874] Oracle MySQL Connector up to 2.1.3/2.0.4 Connector/Python unknown vulnerability
19636| [92850] Oracle Communications Policy Management up to 9.7.3/9.9.1/10.4.1/12.1.1 MySQL denial of service
19637| [92835] Oracle MySQL Server up to 5.7.13 Audit denial of service
19638| [92834] Oracle MySQL Server up to 5.7.13 RBR denial of service
19639| [92833] Oracle MySQL Server up to 5.7.13 Performance Schema denial of service
19640| [92832] Oracle MySQL Server up to 5.7.14 Optimizer denial of service
19641| [92831] Oracle MySQL Server up to 5.7.13 Memcached denial of service
19642| [92830] Oracle MySQL Server up to 5.6.32/5.7.14 InnoDB denial of service
19643| [92829] Oracle MySQL Server up to 5.6.31 5.7.13 InnoDB denial of service
19644| [92828] Oracle MySQL Server up to 5.7.13 InnoDB denial of service
19645| [92827] Oracle MySQL Server up to 5.5.51/5.6.32/5.7.14 Federated denial of service
19646| [92826] Oracle MySQL Server up to 5.7.13 DML denial of service
19647| [92821] Oracle MySQL Server up to 5.7.13 Replication denial of service
19648| [92820] Oracle MySQL Server up to 5.7.13 Performance Schema denial of service
19649| [92819] Oracle Communications Policy Management up to 9.7.3/9.9.1/10.4.1/12.1.1 MySQL denial of service
19650| [92818] Oracle MySQL Server up to 5.5.52/5.6.33/5.7.15 Encryption information disclosure
19651| [92817] Oracle MySQL Server up to 5.5.51/5.6.32/5.7.14 Types denial of service
19652| [92815] Oracle Communications Policy Management up to 9.7.3/9.9.1/10.4.1/12.1.1 MySQL denial of service
19653| [92814] Oracle Communications Policy Management up to 9.7.3/9.9.1/10.4.1/12.1.1 MySQL denial of service
19654| [92813] Oracle Communications Policy Management up to 9.7.3/9.9.1/10.4.1/12.1.1 MySQL denial of service
19655| [92798] Oracle Communications Policy Management up to 9.7.3/9.9.1/10.4.1/12.1.1 MySQL denial of service
19656| [92797] Oracle Communications Policy Management up to 9.7.3/9.9.1/10.4.1/12.1.1 MySQL denial of service
19657| [92790] Oracle MySQL Server up to 5.7.14 Privileges information disclosure
19658| [92789] Oracle MySQL Server up to 5.6.30/5.7.12 InnoDB Plugin unknown vulnerability
19659| [92292] libdbd-mysql-perl 4.028 Error Message denial of service
19660| [91920] Open Dental up to 16.1 MySQL Server Default Credentials weak authentication
19661| [91625] PHP up to 5.6.25/7.0.10 mysqlnd Heap-based memory corruption
19662| [91505] Oracle MySQL up to 5.5.52/5.6.33/5.7.15 Logging my.cnf privilege escalation
19663| [90877] DBD::mysql up to 4.033 my_login memory corruption
19664| [90876] DBD::mysql up to 4.028 Use-After-Free memory corruption
19665| [90137] Oracle MySQL Server up to 5.5.48/5.6.29/5.7.10 Encryption information disclosure
19666| [90136] Oracle MySQL Server up to 5.5.48/5.6.29/5.7.11 Connection information disclosure
19667| [90134] Oracle MySQL Server up to 5.7.12 Encryption denial of service
19668| [90133] Oracle MySQL Server up to 5.7.12 Replication denial of service
19669| [90132] Oracle MySQL Server up to 5.5.49/5.6.30/5.7.12 RBR denial of service
19670| [90131] Oracle MySQL Server up to 5.6.30/5.7.12 Privileges denial of service
19671| [90130] Oracle MySQL Server up to 5.7.12 Optimizer denial of service
19672| [90129] Oracle MySQL Server up to 5.7.12 Log denial of service
19673| [90128] Oracle MySQL Server up to 5.6.30/5.7.12 InnoDB denial of service
19674| [90127] Oracle MySQL Server up to 5.7.12 InnoDB denial of service
19675| [90126] Oracle MySQL Server up to 5.6.30/5.7.12 Encryption denial of service
19676| [90125] Oracle MySQL Server up to 5.5.49/5.6.30/5.7.12 DML denial of service
19677| [90124] Oracle MySQL Server up to 5.7.12 InnoDB memory corruption
19678| [90123] Oracle MySQL Server up to 5.5.49/5.6.30/5.7.12 Types denial of service
19679| [90122] Oracle MySQL Server up to 5.7.12 Optimizer denial of service
19680| [90121] Oracle MySQL Server up to 5.6.30/5.7.12 Optimizer denial of service
19681| [90120] Oracle MySQL Server up to 5.6.30/5.7.12 FTS denial of service
19682| [90118] Oracle MySQL Server up to 5.6.30/5.7.12 Encryption denial of service
19683| [90117] Oracle MySQL Server up to 5.7.11 Optimizer denial of service
19684| [87408] PHP up to 5.4.42/5.5.26/5.6.10 SSL ext/mysqlnd/mysqlnd.c weak encryption
19685| [82687] Oracle MySQL Server up to 5.5.48/5.6.29/5.7.11 Connection Handling spoofing
19686| [82685] Oracle MySQL Enterprise Monitor up to 3.0.25/3.1.2 Monitoring unknown vulnerability
19687| [82684] Oracle MySQL Server up to 5.6.28/5.7.10 Encryption denial of service
19688| [82683] Oracle MySQL Server up to 5.6.29/5.7.11 Pluggable Authentication unknown vulnerability
19689| [82682] Oracle MySQL Server up to 5.6.29/5.7.11 Packaging memory corruption
19690| [80605] Oracle MySQL Server up to 5.5.46/5.6.27/5.7.9 Privileges denial of service
19691| [80604] Oracle MySQL Server up to 5.6.26 denial of service
19692| [80603] Oracle MySQL Server up to 5.5.45/5.6.26 Encryption information disclosure
19693| [80602] Oracle MySQL Server up to 5.6.27/5.7.9 Replication denial of service
19694| [80601] Oracle MySQL Server up to 5.5.46/5.6.27/5.7.9 UDF denial of service
19695| [80600] Oracle MySQL Server up to 5.5.46/5.6.27/5.7.9 Encryption weak encryption
19696| [80599] Oracle MySQL Server 5.7.9 Partition denial of service
19697| [80598] Oracle MySQL Server 5.7.9 Optimizer denial of service
19698| [80597] Oracle MySQL Server up to 5.6.27 InnoDB denial of service
19699| [80596] Oracle MySQL Server up to 5.5.46/5.6.27/5.7.9 InnoDB denial of service
19700| [80595] Oracle MySQL Server up to 5.5.46/5.6.27/5.7.9 DML denial of service
19701| [80594] Oracle MySQL Server up to 5.5.46 Optimizer denial of service
19702| [80593] Oracle MySQL Server up to 5.6.27/5.7.9 Optimizer denial of service
19703| [80592] Oracle MySQL Server up to 5.5.46/5.6.27/5.7.9 Optimizer denial of service
19704| [80591] Oracle MySQL Server up to 5.5.31/5.6.11 Optimizer denial of service
19705| [80590] Oracle MySQL Server up to 5.5.46/5.6.27 DML denial of service
19706| [80589] Oracle MySQL Server up to 5.6.27/5.7.9 DML denial of service
19707| [80588] Oracle MySQL Server up to 5.6.27 DML denial of service
19708| [80587] Oracle MySQL Server up to 5.6.21 DML denial of service
19709| [80586] Oracle MySQL Server up to 5.5.46/5.6.27/5.7.9 Options unknown vulnerability
19710| [80585] Oracle MySQL Server up to 5.6.27/5.7.9 DML memory corruption
19711| [80184] Rename Plugin 1.0 on WordPress mysqldump_download.php directory traversal
19712| [78705] Oracle MySQL Server up to 5.5.45/5.6.26 Partition denial of service
19713| [78703] Oracle MySQL Server up to 5.6.26 Memcached denial of service
19714| [78702] Oracle MySQL Server up to 5.5.45/5.6.26 SP denial of service
19715| [78701] Oracle MySQL Server up to 5.5.43/5.6.24 Privileges information disclosure
19716| [78700] Oracle MySQL Server up to 5.6.26 Privileges denial of service
19717| [78699] Oracle MySQL Server up to 5.6.26 Replication denial of service
19718| [78698] Oracle MySQL Server up to 5.5.45/5.6.26 Query Cache denial of service
19719| [78697] Oracle MySQL Server up to 5.5.45/5.6.26 InnoDB denial of service
19720| [78696] Oracle MySQL Server up to 5.6.25 InnoDB denial of service
19721| [78695] Oracle MySQL Server up to 5.5.45/5.6.26 DML denial of service
19722| [78694] Oracle MySQL Server up to 5.6.25 libmysqld denial of service
19723| [78693] Oracle MySQL Server up to 5.5.45/5.6.26 Types unknown vulnerability
19724| [78692] Oracle MySQL Server up to 5.6.20 Types denial of service
19725| [78691] Oracle MySQL Server up to 5.5.45/5.6.26 Privileges unknown vulnerability
19726| [78690] Oracle MySQL Server up to 5.6.25 Partition denial of service
19727| [78689] Oracle MySQL Server up to 5.5.45/5.6.26 Partition denial of service
19728| [78688] Oracle MySQL Server up to 5.5.45/5.6.26 Parser denial of service
19729| [78687] Oracle MySQL Server up to 5.6.26 Optimizer denial of service
19730| [78686] Oracle MySQL Server up to 5.5.44 InnoDB denial of service
19731| [78685] Oracle MySQL Server up to 5.6.23 InnoDB denial of service
19732| [78684] Oracle MySQL Server up to 5.6.26 DML denial of service
19733| [78683] Oracle MySQL Server up to 5.5.45/5.6.26 DML denial of service
19734| [78682] Oracle MySQL Server up to 5.6.23 DML denial of service
19735| [78681] Oracle MySQL Server up to 5.5.45/5.6.26 DDL denial of service
19736| [78680] Oracle MySQL Server up to 5.5.44/5.6.25 DML unknown vulnerability
19737| [78679] Oracle MySQL Enterprise Monitor up to 2.3.20/3.0.20 C-Agent / Service Manager denial of service
19738| [78678] Oracle MySQL Server up to 5.6.25 Encryption spoofing
19739| [78676] Oracle MySQL Enterprise Monitor up to 2.3.20/3.0.22 C-Agent denial of service
19740| [77699] JSP/MySQL Administrador Web 1 sys/sys/listaBD2.jsp cross site scripting
19741| [77698] JSP/MySQL Administrador Web 1 sys/sys/listaBD2.jsp cross site request forgery
19742| [76704] Oracle MySQL Server up to 5.6.24 Partition denial of service
19743| [76703] Oracle MySQL Server up to 5.6.24 RBR denial of service
19744| [76701] Oracle MySQL Server up to 5.6.24 Firewall denial of service
19745| [76699] Oracle MySQL Server up to 5.6.24 Firewall denial of service
19746| [76695] Oracle MySQL Server up to 5.6.24 MemCached denial of service
19747| [76691] Oracle MySQL Server up to 5.5.42 Optimizer denial of service
19748| [76690] Oracle MySQL Server up to 5.6.22 InnoDB denial of service
19749| [76686] Oracle MySQL Server up to 5.5.43/5.6.24 denial of service
19750| [76671] Oracle MySQL Server up to 5.5.43/5.6.23 Pluggable Auth information disclosure
19751| [76634] Oracle MySQL Server up to 5.5.43/5.6.24 DML denial of service
19752| [76629] Oracle MySQL Server up to 5.5.43/5.6.24 Optimizer denial of service
19753| [76628] Oracle MySQL Server up to 5.6.24 denial of service
19754| [76626] Oracle MySQL Server up to 5.6.24 Firewall information disclosure
19755| [76608] Oracle MySQL Server up to 5.5.43/5.6.23 information disclosure
19756| [76605] Oracle MySQL Server up to 5.6.24 Partition information disclosure
19757| [76599] Oracle MySQL Server up to 5.6.24 DML information disclosure
19758| [76571] Oracle MySQL Server up to 5.5.43/5.6.24 GIS denial of service
19759| [76081] MySQL Lite Administrator Beta-1 tabella.php cross site scripting
19760| [75579] lighttpd 1.4.35 Log File mod_mysql_vhost.c privilege escalation
19761| [75159] Oracle MySQL up to 5.7.2 SSL Client weak encryption
19762| [74969] Oracle MySQL Server up to 5.6.23 Replication denial of service
19763| [74967] Oracle MySQL Server up to 5.6.23 SP denial of service
19764| [74966] Oracle MySQL Server up to 5.6.22 DML weak encryption
19765| [74965] Oracle MySQL Server up to 5.6.23 Privileges denial of service
19766| [74964] Oracle MySQL Server up to 5.6.23 Memcached denial of service
19767| [74963] Oracle MySQL Server up to 5.6.23 InnoDB denial of service
19768| [74962] Oracle MySQL Server up to 5.5.42/5.6.23 Federated unknown vulnerability
19769| [74961] Oracle MySQL Server up to 5.5.42/5.6.23 DDL unknown vulnerability
19770| [74960] Oracle MySQL Server up to 5.6.22 XA weak encryption
19771| [74959] Oracle MySQL Server up to 5.5.41/5.6.22 Encryption weak encryption
19772| [74958] Oracle MySQL Server up to 5.6.23 Partition denial of service
19773| [74957] Oracle MySQL Server up to 5.6.22 Partition weak encryption
19774| [74956] Oracle MySQL Server up to 5.5.42/5.6.23 Optimizer unknown vulnerability
19775| [74955] Oracle MySQL Server up to 5.6.22 Optimizer weak encryption
19776| [74954] Oracle MySQL Server up to 5.5.41/5.6.22 DML unknown vulnerability
19777| [74953] Oracle MySQL Server up to 5.6.23 InnoDB denial of service
19778| [74952] Oracle MySQL Server up to 5.6.22 InnoDB weak encryption
19779| [74951] Oracle MySQL Server up to 5.6.23 Information Schema denial of service
19780| [74950] Oracle MySQL Server up to 5.5.41/5.6.22 DDL unknown vulnerability
19781| [74949] Oracle MySQL Connectors up to 5.1.34 Connector/J unknown vulnerability
19782| [74948] Oracle MySQL Server up to 5.5.41/5.6.22 Privileges unknown vulnerability
19783| [74947] Oracle MySQL Server up to 5.6.22 Encryption s23_srvr.c ssl23_get_client_hello denial of service
19784| [74946] Oracle MySQL Server up to 5.5.42/5.6.23 Compiling unknown vulnerability
19785| [74945] Oracle MySQL Enterprise Monitor up to 2.3.19/3.0.18 Service Manager s:token/ cross site request forgery
19786| [74944] Oracle MySQL Enterprise Monitor up to 2.3.16/3.0.10 Service Manager memory corruption
19787| [68810] Oracle MySQL Server up to 5.5.40/5.6.21 Foreign Key information disclosure
19788| [68809] Oracle MySQL Server up to 5.6.21 Pluggable Auth denial of service
19789| [68808] Oracle MySQL Server up to 5.5.40/5.6.21 DML denial of service
19790| [68807] Oracle MySQL Server up to 5.6.21 Optimizer denial of service
19791| [68806] Oracle MySQL Server up to 5.5.40 Foreign Key denial of service
19792| [68805] Oracle MySQL Server up to 5.5.38/5.6.19 DDL denial of service
19793| [68804] Oracle MySQL Server up to 5.5.40/5.6.21 Replication denial of service
19794| [68803] Oracle MySQL Server up to 5.5.40/5.6.21 Replication denial of service
19795| [68802] Oracle MySQL Server up to 5.5.40/5.6.21 Encryption weak encryption
19796| [67988] Oracle MySQL Server up to 5.5.38/5.6.19 denial of service
19797| [67987] Oracle MySQL Server up to 5.6.19 denial of service
19798| [67986] Oracle MySQL Server up to 5.5.38/5.6.19 denial of service
19799| [67985] Oracle MySQL Server up to 5.6.19 denial of service
19800| [67984] Oracle MySQL Server up to 5.5.39/5.6.20 denial of service
19801| [67983] Oracle MySQL Server up to 5.5.38/5.6.19 denial of service
19802| [67982] Oracle MySQL Server up to 5.5.38 denial of service
19803| [67981] Oracle MySQL Server up to 5.5.38/5.6.19 denial of service
19804| [67979] Oracle MySQL Server up to 5.5.38/5.6.19 unknown vulnerability
19805| [67978] Oracle MySQL Server up to 5.5.38/5.6.19 denial of service
19806| [67977] Oracle MySQL Server up to 5.5.39/5.6.20 denial of service
19807| [67976] Oracle MySQL Server up to 5.5.39/5.6.20 denial of service
19808| [67975] Oracle MySQL Server up to 5.5.39/5.6.20 information disclosure
19809| [67974] Oracle MySQL Server up to 5.5.38/5.6.19 Messages Stack-Based sql injection
19810| [67973] Oracle MySQL Server up to 5.6.19 unknown vulnerability
19811| [67972] Oracle MySQL Server up to 5.5.39/5.6.20 unknown vulnerability
19812| [67971] Oracle MySQL Server up to 5.5.38/5.6.19 unknown vulnerability
19813| [67970] Oracle MySQL Server up to 5.6.19 Messages NULL Pointer Dereference denial of service
19814| [67969] Oracle MySQL Server up to 5.5.39/5.6.20 directory traversal
19815| [67968] Oracle MySQL Server up to 5.5.39/5.6.20 denial of service
19816| [67967] Oracle MySQL Server up to 5.5.39/5.6.20 denial of service
19817| [67966] Oracle MySQL Server up to 5.5.39/5.6.20 unknown vulnerability
19818| [68555] McAfee Network Data Loss Prevention 9.2.0 MySQL Database weak authentication
19819| [67245] phpMyAdmin up to 4.2.5 MySQL User List server_user_groups.php privilege escalation
19820| [67166] Oracle MySQL Server up to 5.5.35/5.6.15 denial of service
19821| [67165] Oracle MySQL Server up to 5.6.17 denial of service
19822| [67163] Oracle MySQL Server up to 5.6.17 denial of service
19823| [67162] Oracle MySQL Server up to 5.5.37 denial of service
19824| [67161] Oracle MySQL Server up to 5.6.17 denial of service
19825| [67160] Oracle MySQL Server up to 5.5.37 denial of service
19826| [67159] Oracle MySQL Server up to 5.5.37/5.6.17 unknown vulnerability
19827| [67158] Oracle MySQL Server up to 5.5.37/5.6.17 unknown vulnerability
19828| [67157] Oracle MySQL Server up to 5.6.17 unknown vulnerability
19829| [13065] Django up to 1.7 MySQL Typecast privilege escalation
19830| [12983] Oracle MySQL Server up to 5.5.36/5.6.16 Options denial of service
19831| [12982] Oracle MySQL Server up to 5.5.35/5.6.15 Federated denial of service
19832| [12981] Oracle MySQL Server up to 5.5.35/5.6.15 Replication denial of service
19833| [12980] Oracle MySQL Server up to 5.6.15 Privileges denial of service
19834| [12979] Oracle MySQL Server up to 5.5.36/5.6.16 Performance Schema denial of service
19835| [12978] Oracle MySQL Server up to 5.5.35/5.6.15 XML denial of service
19836| [12977] Oracle MySQL Server up to 5.5.35/5.6.15 Partition denial of service
19837| [12976] Oracle MySQL Server up to 5.6.15 Optimizer denial of service
19838| [12975] Oracle MySQL Server up to 5.6.15 MyISAM denial of service
19839| [12974] Oracle MySQL Server up to 5.6.16 InnoDB denial of service
19840| [12973] Oracle MySQL Server up to 5.6.15 DML denial of service
19841| [12972] Oracle MySQL Client up to 5.5.36/5.6.16 unknown vulnerability
19842| [12971] Oracle MySQL Server up to 5.5.36/5.6.16 RBR unknown vulnerability
19843| [12970] Oracle MySQL Server up to 5.6.15 InnoDB unknown vulnerability
19844| [12613] lighttpd up to 1.4.34 MySQL Virtual Hosting Module mod_mysql_vhost.c sql injection
19845| [12135] Oracle MySQL client/mysql.cc Server Version memory corruption
19846| [66191] Cisco Video Surveillance Operations Manager MySQL Database denial of service
19847| [66079] CSP MySQL User Manager 2.3 Login Page sql injection
19848| [11948] Oracle MySQL Server up to 5.1.72/5.5.34/5.6.14 Error Handling Crash denial of service
19849| [11947] Oracle MySQL Server up to 5.5.34/5.6.14 Replication denial of service
19850| [11946] Oracle MySQL Server up to 5.6.13 Performance Schema Stored denial of service
19851| [11945] Oracle MySQL Server up to 5.1.71/5.5.33/5.6.13 InnoDB memory corruption
19852| [11944] Oracle MySQL Server up to 5.1.72/5.5.34/5.6.14 Optimizer Crash denial of service
19853| [11943] Oracle MySQL Server up to 5.6.14 InnoDB Stored denial of service
19854| [11942] Oracle MySQL Server up to 5.6.13 FTS Stored denial of service
19855| [11941] Oracle MySQL Server up to 5.1.72/5.5.34/5.6.14 Privileges Crash denial of service
19856| [11940] Oracle MySQL Server up to 5.5.33/5.6.13 Partition denial of service
19857| [11939] Oracle MySQL Server up to 5.1.71/5.5.33/5.6.13 Optimizer Crash denial of service
19858| [11938] Oracle MySQL Server up to 5.1.71/5.5.33/5.6.13 Locking Crash denial of service
19859| [11937] Oracle MySQL Server up to 5.1.72/5.5.34/5.6.14 InnoDB Crash denial of service
19860| [11936] Oracle MySQL Server up to 5.6.14 InnoDB Stored denial of service
19861| [11935] Oracle MySQL Server up to 5.6.13 InnoDB Stored denial of service
19862| [11934] Oracle MySQL Server up to 5.6.13 Thread Pooling Stored denial of service
19863| [11933] Oracle MySQL Server up to 5.6.13 Stored Procedure denial of service
19864| [11932] Oracle MySQL Server up to 5.6.14 GIS Stored denial of service
19865| [11931] Oracle MySQL Enterprise Monitor up to 2.3.14/3.0.4 Service Manager unknown vulnerability
19866| [10822] Oracle MySQL Server up to 5.6.12 Locking unknown vulnerability
19867| [10821] Oracle MySQL Server up to 5.6.12 InnoDB unknown vulnerability
19868| [10820] Oracle MySQL Server up to 5.6.12 Optimizer unknown vulnerability
19869| [10819] Oracle MySQL Server up to 5.1.70/5.5.32/5.6.12 Optimizer memory corruption
19870| [10818] Oracle MySQL Server up to 5.1/5.5.22 Optimizer denial of service
19871| [10817] Oracle MySQL Server up to 5.6.12 InnoDB unknown vulnerability
19872| [10816] Oracle MySQL Server up to 5.5.32/5.6.12 Replication unknown vulnerability
19873| [10815] Oracle MySQL Enterprise Monitor up to 2.3.13 Service Manager privilege escalation
19874| [65143] MariaDB up to 5.5.28 MySQL privilege escalation
19875| [9672] Oracle MySQL Server up to 5.6.11 XA Transactions denial of service
19876| [9671] Oracle MySQL Server up to 5.5.31/5.6.11 Server Replication denial of service
19877| [9670] Oracle MySQL Server up to 5.6.11 InnoDB denial of service
19878| [9669] Oracle MySQL Server up to 5.6.11 Server Privileges unknown vulnerability
19879| [9668] Oracle MySQL Server up to 5.5.30/5.6.10 Server Partition Stored unknown vulnerability
19880| [9667] Oracle MySQL Server up to 5.5.31 Server Parser denial of service
19881| [9666] Oracle MySQL Server up to 5.5.30/5.6.10 Server Options Stored unknown vulnerability
19882| [9665] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Server Options denial of service
19883| [9664] Oracle MySQL Server up to 5.6.11 Server Optimizer unknown vulnerability
19884| [9663] Oracle MySQL Server up to 5.1.69/5.5.31/5.6.11 Server Optimizer denial of service
19885| [9662] Oracle MySQL Server up to 5.5.30/5.6.10 Prepared Statement Stored unknown vulnerability
19886| [9661] Oracle MySQL Server up to 5.6.11 InnoDB denial of service
19887| [9660] Oracle MySQL Server up to 5.1.69/5.5.31/5.6.11 Full Text Search denial of service
19888| [9659] Oracle MySQL Server up to 5.6.11 Data Manipulation Language unknown vulnerability
19889| [9658] Oracle MySQL Server up to 5.5.31/5.6.11 Data Manipulation Language denial of service
19890| [9657] Oracle MySQL Server up to 5.5.31/5.6.11 Audit Log information disclosure
19891| [9656] Oracle MySQL Server up to 5.6.11 MemCached unknown vulnerability
19892| [9655] Oracle MySQL Server up to 5.1.69/5.5.31/5.6.11 GIS Crash denial of service
19893| [64198] Wireshark up to 1.8.6 MySQL Dissector Integer denial of service
19894| [64010] Ruby on Rails 3.1.0 MySQL Database Stored unknown vulnerability
19895| [8418] Oracle MySQL Server up to 5.1.67/5.5.29/5.6.10 Server Locking unknown vulnerability
19896| [8416] Oracle MySQL Server up to 5.1.63 Server Types unknown vulnerability
19897| [8415] Oracle MySQL Server up to 5.6.10 Server Privileges denial of service
19898| [8414] Oracle MySQL Server up to 5.6.10 InnoDB denial of service
19899| [8413] Oracle MySQL Server up to 5.5.30/5.6.10 InnoDB unknown vulnerability
19900| [8412] Oracle MySQL Server up to 5.6.10 Data Manipulation Language denial of service
19901| [8411] Oracle MySQL Server up to 5.5.30/5.6.10 Stored Procedure unknown vulnerability
19902| [8410] Oracle MySQL Server up to 5.1.67/5.5.29 Server XML denial of service
19903| [8409] Oracle MySQL Server up to 5.5.29 Server Replication denial of service
19904| [8408] Oracle MySQL Server up to 5.1.67/5.5.29 Server Partition unknown vulnerability
19905| [8407] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Server Optimizer unknown vulnerability
19906| [8406] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 InnoDB unknown vulnerability
19907| [8405] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Information Schema unknown vulnerability
19908| [8404] Oracle MySQL Server up to 5.5.29 Data Manipulation Language denial of service
19909| [8403] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Data Manipulation Language unknown vulnerability
19910| [8402] Oracle MySQL Server up to 5.5.29/5.6.10 Server Optimizer denial of service
19911| [8401] Oracle MySQL Server up to 5.6.10 MemCached denial of service
19912| [8400] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Server Privileges unknown vulnerability
19913| [8399] Oracle MySQL Server up to 5.1.66/5.5.28 Server Privileges unknown vulnerability
19914| [8398] Oracle MySQL Server up to 5.1.67/5.5.29 unknown vulnerability
19915| [8397] Oracle MySQL Server up to 5.1.67/5.5.29/5.6.10 Information Schema unknown vulnerability
19916| [8396] Oracle MySQL Server up to 5.1.67/5.5.29 Server Locking unknown vulnerability
19917| [8395] Oracle MySQL Server up to 5.6.10 Data Manipulation Language denial of service
19918| [10871] Oracle MySQL 5.3.12/5.5.30/10.0.1 MyISAM Engine init_search SELECT Statement denial of service
19919| [8065] Oracle MySQL up to 5.5.27 yaSSL memory corruption
19920| [8064] Oracle MySQL up to 5.5.29 yaSSL memory corruption
19921| [8816] Wireshark up to 1.8.5 MySQL Dissector packet-mysql.c Packet denial of service
19922| [8019] Oracle MySQL 5.2.11 Representation Converter Eingabe Crash denial of service
19923| [7431] Oracle MySQL Server up to 5.5.28 Privileges denial of service
19924| [7430] Oracle MySQL Server up to 5.5.28 Partition denial of service
19925| [7429] Oracle MySQL Server up to 5.5.28 Optimizer denial of service
19926| [7428] Oracle MySQL Server up to 5.1.66/5.5.28 Optimizer unknown vulnerability
19927| [7427] Oracle MySQL Server up to 5.1.66/5.5.28 unknown vulnerability
19928| [7426] Oracle MySQL Server up to 5.5.28 MyISAM denial of service
19929| [7425] Oracle MySQL Server up to 5.1.66/5.5.28 InnoDB unknown vulnerability
19930| [7424] Oracle MySQL Server up to 5.5.28 InnoDB denial of service
19931| [7423] Oracle MySQL Server up to 5.1.66/5.5.28 Locking unknown vulnerability
19932| [7422] Oracle MySQL Server up to 5.1.66/5.5.28 unknown vulnerability
19933| [7421] Oracle MySQL Server up to 5.1.66/5.1.28 Replication unknown vulnerability
19934| [7419] Oracle MySQL Server up to 5.5.28 Stored Procedure denial of service
19935| [7418] Oracle MySQL Server up to 5.1.66/5.5.28 Server Optimizer unknown vulnerability
19936| [7417] Oracle MySQL Server up to 5.1.66/5.5.28 Information Schema unknown vulnerability
19937| [7416] Oracle MySQL Server up to 5.1.65/5.5.27 GIS Extension denial of service
19938| [7415] Oracle MySQL Server up to 5.1.66/5.5.28 Privileges Stack-based memory corruption
19939| [7414] Oracle MySQL Server up to 5.5.28 Parser Heap-based memory corruption
19940| [63111] Oracle MySQL 5.5.19 Installation denial of service
19941| [7068] Oracle MySQL Server up to 5.5.19 Authentication information disclosure
19942| [7067] Oracle MySQL Server up to 5.5.19 sql/sql_acl.cc acl_get memory corruption
19943| [7066] Oracle MySQL Server up to 5.5.19 SELECT Command Crash denial of service
19944| [7065] Oracle MySQL Server up to 5.5.19 Create Table MDL_key::mdl_key_init memory corruption
19945| [6795] Oracle MySQL Server up to 5.1.64/5.5.26 Server Replication denial of service
19946| [6794] Oracle MySQL Server up to 5.1.63/5.5.25 Server Full Text Search denial of service
19947| [6793] Oracle MySQL Server up to 5.5.25 unknown vulnerability
19948| [6792] Oracle MySQL Server up to 5.5.26 MySQL Client information disclosure
19949| [6791] Oracle MySQL Server up to 5.1.65/5.5.27 Server Optimizer denial of service
19950| [6790] Oracle MySQL Server up to 5.1.64/5.5.26 Server Optimizer denial of service
19951| [6789] Oracle MySQL Server up to 5.5.26 unknown vulnerability
19952| [6788] Oracle MySQL Server up to 5.1.63/5.5.25 InnoDB Plugin denial of service
19953| [6787] Oracle MySQL Server up to 5.1.63/5.5.25 InnoDB unknown vulnerability
19954| [6786] Oracle MySQL Server up to 5.5.26 MySQL Client sql injection
19955| [6785] Oracle MySQL Server up to 5.1.65/5.5.27 denial of service
19956| [6784] Oracle MySQL Server up to 5.1.64/5.5.26 Protocol unknown vulnerability
19957| [6783] Oracle MySQL Server up to 5.1.64/5.5.26 Information Schema memory corruption
19958| [62299] SilverStripe up to 2.4.5 MySQL Database sql injection
19959| [61672] MySQL unknown vulnerability
19960| [61567] MySQLDumper 1.24.4 Error Message information disclosure
19961| [61566] MySQLDumper 1.24.4 Restore information disclosure
19962| [61565] MySQLDumper 1.24.4 directory traversal
19963| [61564] MySQLDumper 1.24.4 deletehtaccess cross site request forgery
19964| [61563] MySQLDumper 1.24.4 index.php cross site scripting
19965| [5783] Oracle MySQL Server up to 5.1.62/5.5.22 Server Optimizer denial of service
19966| [5782] Oracle MySQL Server up to 5.1.62/5.5.23 Server Optimizer denial of service
19967| [5781] Oracle MySQL Server up to 5.5.23 denial of service
19968| [5780] Oracle MySQL Server up to 5.5.23 InnoDB denial of service
19969| [5779] Oracle MySQL Server up to 5.1.62/5.5.23 GIS Extension unknown vulnerability
19970| [5778] Oracle MySQL Server up to 5.5.23 Server Optimizer denial of service
19971| [5635] Oracle MySQL Server up to 5.5.25 on Linux InnoDB UPDATE denial of service
19972| [5503] Oracle MySQL up to 5.6.5 Password Authentication sql/password.c memcmp weak authentication
19973| [5168] Oracle MySQL Server Optimizer denial of service
19974| [5166] Oracle MySQL Server up to 5.5.21 Partition denial of service
19975| [5165] Oracle MySQL Server up to 5.5.19 Optimizer denial of service
19976| [5159] Oracle MySQL Server up to 5.1.61/5.5.21 Optimizer denial of service
19977| [5158] Oracle MySQL Server up to 5.1.61/5.5.21 DML denial of service
19978| [5151] Oracle MySQL Server up to 5.1.60/5.5.19 MyISAM denial of service
19979| [5981] Oracle MySQL Server 5.1.62/5.5.23 Sort Order Index Calculation denial of service
19980| [5072] Oracle MySQL Server up to 5.5.21 denial of service
19981| [4627] Oracle MySQL up to 5.5.20 memory corruption
19982| [60055] WordPress up to 1.2 MySQL Database denial of service
19983| [5236] Oracle MySQL Server 5.5.x unknown vulnerability
19984| [5235] Oracle MySQL Server 5.5.x denial of service
19985| [5233] Oracle MySQL Server 5.5.x denial of service
19986| [5232] Oracle MySQL Server 5.5.x denial of service
19987| [5231] Oracle MySQL Server 5.5.x denial of service
19988| [5230] Oracle MySQL Server 5.5.x denial of service
19989| [5229] Oracle MySQL Server 5.5.x denial of service
19990| [5228] Oracle MySQL Server 5.5.x denial of service
19991| [5227] Oracle MySQL Server 5.5.x unknown vulnerability
19992| [5226] Oracle MySQL Server 5.1.x/5.5.x denial of service
19993| [5225] Oracle MySQL Server 5.1.x/5.5.x denial of service
19994| [5224] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
19995| [5223] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
19996| [5222] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
19997| [5221] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
19998| [5220] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
19999| [5219] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
20000| [5218] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
20001| [5217] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
20002| [5216] Oracle MySQL Server 5.0.x/5.1.x/5.5.x denial of service
20003| [5215] Oracle MySQL Server 5.0.x/5.1.x/5.5.x information disclosure
20004| [5213] Oracle MySQL Server 5.0.x/5.1.x/5.5.x unknown vulnerability
20005| [5212] Oracle MySQL Server 5.0.x/5.1.x denial of service
20006| [5211] Oracle MySQL Server 5.0.x/5.1.x denial of service
20007| [5210] Oracle MySQL Server 5.0.x/5.1.x denial of service
20008| [59882] MySQL 5.5.8 NULL Pointer Dereference denial of service
20009| [59384] Hiroyuki Oyama DBD::mysqlPP up to 0.04 MySQL sql injection
20010| [58706] Taskfreak! Multi-mysql 0.6 Error Message information disclosure
20011| [57356] Trustwave WebDefend 2.0/3.0/5.0 MySQL Database unknown vulnerability
20012| [56109] PHP 5.3.2/5.3.3 mysqli mysqli_fetch_assoc sql injection
20013| [56085] MySQL up to 5.1.25 init_from_wkb denial of service
20014| [56084] MySQL up to 5.1.25 Stored Procedure denial of service
20015| [56083] MySQL Crash denial of service
20016| [56082] MySQL Use-After-Free denial of service
20017| [56081] MySQL Optimizer Crash denial of service
20018| [56080] MySQL up to 5.1.25 Stored denial of service
20019| [56079] MySQL Crash denial of service
20020| [56078] MySQL Create Table Crash denial of service
20021| [56025] MySQL up to 5.1.25 Crash denial of service
20022| [56024] MySQL up to 5.1.25 store denial of service
20023| [56023] MySQL up to 5.1.25 Crash denial of service
20024| [56022] MySQL up to 5.1.25 Crash denial of service
20025| [56021] MySQL up to 5.1.25 Uninitialized Memory denial of service
20026| [56020] MySQL up to 5.1.25 Crash denial of service
20027| [56019] MySQL up to 5.1.25 Crash denial of service
20028| [56018] mysql up to 5.1.25 Configuration Parameter denial of service
20029| [60789] TYPO3 up to 4.4.4 MySQL Database escapeStrForLike information disclosure
20030| [62294] SilverStripe 2.4.0/2.4.1/2.4.2/2.4.3 MySQLDatabase.php unknown vulnerability
20031| [54434] PHP 5.3.0/5.3.1/5.3.2 php_mysqlnd_auth_write sql injection
20032| [54433] PHP 5.3.0/5.3.1/5.3.2 MySQL php_mysqlnd_read_error_from_line memory corruption
20033| [54432] PHP 5.3.0/5.3.1/5.3.2 mysqlnd_wireprotocol.c php_mysqlnd_rset_header_read memory corruption
20034| [54026] MySQL up to 5.1.25 Crash denial of service
20035| [53483] MySQL up to 5.0.0.0 memory corruption
20036| [53482] MySQL up to 5.0.0.0 my_net_skip_rest denial of service
20037| [53481] MySQL up to 5.0.0.0 directory traversal
20038| [53212] mysql 5.1.45 mysql_uninstall_plugin unknown vulnerability
20039| [53118] Csphere ClanSphere up to 2009.0.3 MySQL Database generate.php cs_sql_select sql injection
20040| [53053] TaskFreak TaskFreak! up to 0.1.3 tzn_mysql.php loadByKey sql injection
20041| [52985] Oracle MySQLConnector NET up to 6.0.2 SSL Certificate spoofing
20042| [51369] mysql 5.0.51a CertDecoder::GetName memory corruption
20043| [51581] TYPO3 Kiddog Mysqldumper up to 0.0.3 information disclosure
20044| [50962] MySQL Certificates viosslfactories.c vio_verify_callback spoofing
20045| [50961] mysql GeomFromWKB denial of service
20046| [50960] MySQL up to 5.0.0.0 Access Restriction Symlink privilege escalation
20047| [50531] mysql-ocaml 1.0.4 MySQL mysql_real_escape_string unknown vulnerability
20048| [48981] MySQL up to 4.0.23 sql_parse.cc dispatch_command denial of service
20049| [48263] Surat Kabar phpWebNews 0.2 MySQL index.php sql injection
20050| [48262] Surat Kabar phpWebNews 0.1/0.2 MySQL bukutamu.php sql injection
20051| [47455] auth2db up to 0.2.6 MySQL mysql_real_escape_string sql injection
20052| [46983] MySQL up to 6.0.10-bzr ExtractValue denial of service
20053| [46798] Getmiro Broadcast Machine 0.1 MySQLController.php privilege escalation
20054| [46636] MyBlog MySQL Database Cleartext information disclosure
20055| [46500] ProFTPD 1.3.1 mod_sql_mysql sql injection
20056| [46028] Joey Schulze Mod Auth Mysql 2.x mod_auth_mysql.c sql injection
20057| [45774] Constructr CMS up to 3.02.5 MySQL Database Cleartext information disclosure
20058| [45668] Nodstrum MySQL Calendar 1.1 index.php sql injection
20059| [45669] Nodstrum MySQL Calendar 1.1 unknown vulnerability
20060| [45016] Deeserver Panuwat PromoteWeb MySQL go.php sql injection
20061| [44358] MySQL up to 5.0.67 cross site scripting
20062| [44357] MySQL Quick Admin up to 1.5.5 index.php directory traversal
20063| [44356] MySQL Quick Admin 1.5.5 actions.php directory traversal
20064| [44131] NooMS 1.1 MySQL db.php information disclosure
20065| [44076] MySQL Create Table Symlink privilege escalation
20066| [44075] MySQL 5.0.51a Create Table Symlink privilege escalation
20067| [43987] MySQL Crash denial of service
20068| [43825] Aquagardensoft mysql-lists 1.2 cross site scripting
20069| [43819] Craftysyntax Crafty Syntax Live Help up to 1.7 MySQL Database Cleartext information disclosure
20070| [43625] Keld PHP-MySQL News Script 0.7.1 login.php sql injection
20071| [43123] BlognPlus 2.5.5 MySQL index.php sql injection
20072| [42939] Relative Real Estate Systems up to 3.0 MySQL Database Cleartext information disclosure
20073| [42912] AlstraSoft AskMe 2.1 MySQL Database Cleartext information disclosure
20074| [42868] BlognPlus 2.5.4 MySQL sql injection
20075| [42205] miniBB 2.2 MySQL setup_mysql.php sql injection
20076| [41891] Terong Advanced Web Photo Gallery 1.0 MySQL Database Cleartext information disclosure
20077| [40486] MySQL up to 1.7.5 handshake.cpp processoldclienthello memory corruption
20078| [40219] PHP MySQL Banner Exchange 2.2.1 inc/lib.inc unknown vulnerability
20079| [39993] MySQL denial of service
20080| [3499] Sun MySQL up to 6.0.3 System Table Information privilege escalation
20081| [40030] aurora framework 20071208 MySQL db_mysql.lib pack_var sql injection
20082| [3469] Sun MySQL 5.1.23 Bk InnoDB denial of service
20083| [39991] MySQL up to 6.0.4 denial of service
20084| [39292] Asterisk-Addons 1.2.7/1.4.3 MySQL sql injection
20085| [41090] MySQL Mysql Community Server up to 5.1.4 unknown vulnerability
20086| [38781] PHP 5.2.4 MySQL memory corruption
20087| [38618] PHP 4.4.7/5.2.3 mysqli sql injection
20088| [85747] InterWorx SiteWorx mysql.php cross site scripting
20089| [85735] InterWorx NodeWorx mysql.php cross site scripting
20090| [37818] MySQL Community Server up to 5.0.40 denial of service
20091| [39994] MySQL Federated Crash denial of service
20092| [37641] MySQLDumper htaccess privilege escalation
20093| [86077] NetClassifieds Mysql_db.php information disclosure
20094| [37816] MySQL Community Server up to 5.0.40 Crash denial of service
20095| [36814] MySQL up to 5.1.17 information disclosure
20096| [36669] MySQL 4.0.1 unknown vulnerability
20097| [36813] mysql up to 5.1.17 thd::db_access denial of service
20098| [36812] MySQL up to 5.1.17 unknown vulnerability
20099| [36502] Burnstone burnCMS 0.2 mysql.class.php privilege escalation
20100| [36364] GPL PHP Board unstable-2001.11.14-1 mysqli db.mysql.inc.php privilege escalation
20101| [36700] MySQL up to 5.0.39 item_cmpfunc.cc in_decimal::set denial of service
20102| [35917] Advanced Website Creator MySQL sql injection
20103| [35916] Eve-Nuke Forum 0.1 MySQL db/mysql.php privilege escalation
20104| [35605] bitesser MySQL Commander up to 2.7 ressourcen/dbopen.php privilege escalation
20105| [85480] Fantastico includes/mysqlconfig.php directory traversal
20106| [85141] ActiveCalendar data/mysqlevents.php cross site scripting
20107| [85212] WGS-PPC config/mysql_config.php privilege escalation
20108| [34894] MySQLNewsEngine MySQL affichearticles.php3 privilege escalation
20109| [34576] MyODBC MySQL Database denial of service
20110| [37817] MySQL Community Server up to 5.0.40 Create Table information disclosure
20111| [34117] The Address Book 1.04e MySQL Database export.php information disclosure
20112| [34223] MySQL 5.0.30/5.1.13 sql_select.cc denial of service
20113| [33690] Widcomm BTSaveMySql 1.2 MySQL information disclosure
20114| [33257] iWonder Designs Storystream 0.4.0.0 mysql.php sql injection
20115| [33092] Pentaho Business Intelligence Suite up to 1.1 MySQL sql injection
20116| [32736] MysqlDumper 1.21 B6 sql.php cross site scripting
20117|
20118| MITRE CVE - https://cve.mitre.org:
20119| [CVE-2013-3812] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
20120| [CVE-2013-3811] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-3806.
20121| [CVE-2013-3810] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA Transactions.
20122| [CVE-2013-3809] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Audit Log.
20123| [CVE-2013-3808] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
20124| [CVE-2013-3807] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Server Privileges.
20125| [CVE-2013-3806] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-3811.
20126| [CVE-2013-3805] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Prepared Statements.
20127| [CVE-2013-3804] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20128| [CVE-2013-3802] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Full Text Search.
20129| [CVE-2013-3801] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
20130| [CVE-2013-3798] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote attackers to affect integrity and availability via unknown vectors related to MemCached.
20131| [CVE-2013-3796] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20132| [CVE-2013-3795] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
20133| [CVE-2013-3794] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
20134| [CVE-2013-3793] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
20135| [CVE-2013-3783] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Parser.
20136| [CVE-2013-3561] Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.
20137| [CVE-2013-3221] The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
20138| [CVE-2013-2395] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language, a different vulnerability than CVE-2013-1567.
20139| [CVE-2013-2392] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20140| [CVE-2013-2391] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows local users to affect confidentiality and integrity via unknown vectors related to Server Install.
20141| [CVE-2013-2389] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
20142| [CVE-2013-2381] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server Privileges.
20143| [CVE-2013-2378] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, 5.5.29 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
20144| [CVE-2013-2376] Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
20145| [CVE-2013-2375] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
20146| [CVE-2013-1861] MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.
20147| [CVE-2013-1570] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote attackers to affect availability via unknown vectors related to MemCached.
20148| [CVE-2013-1567] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language, a different vulnerability than CVE-2013-2395.
20149| [CVE-2013-1566] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
20150| [CVE-2013-1555] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, and 5.5.29 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
20151| [CVE-2013-1552] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
20152| [CVE-2013-1548] Unspecified vulnerability in Oracle MySQL 5.1.63 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Types.
20153| [CVE-2013-1544] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
20154| [CVE-2013-1532] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Information Schema.
20155| [CVE-2013-1531] Unspecified vulnerability in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server Privileges.
20156| [CVE-2013-1526] Unspecified vulnerability in Oracle MySQL 5.5.29 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
20157| [CVE-2013-1523] Unspecified vulnerability in Oracle MySQL 5.5.29 and earlier and 5.6.10 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server Optimizer.
20158| [CVE-2013-1521] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server Locking.
20159| [CVE-2013-1512] Unspecified vulnerability in Oracle MySQL 5.5.29 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
20160| [CVE-2013-1511] Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
20161| [CVE-2013-1506] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, 5.5.29 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Locking.
20162| [CVE-2013-1502] Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.9 and earlier allows local users to affect availability via unknown vectors related to Server Partition.
20163| [CVE-2013-1492] Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulnerability than CVE-2012-0553.
20164| [CVE-2013-0389] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20165| [CVE-2013-0386] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
20166| [CVE-2013-0385] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows local users to affect confidentiality and integrity via unknown vectors related to Server Replication.
20167| [CVE-2013-0384] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Information Schema.
20168| [CVE-2013-0383] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote attackers to affect availability via unknown vectors related to Server Locking.
20169| [CVE-2013-0375] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.1.28 and earlier, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Server Replication.
20170| [CVE-2013-0371] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.
20171| [CVE-2013-0368] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
20172| [CVE-2013-0367] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
20173| [CVE-2012-5615] MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.
20174| [CVE-2012-5614] Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.
20175| [CVE-2012-5613] ** DISPUTED ** MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.
20176| [CVE-2012-5612] Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.
20177| [CVE-2012-5611] Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.
20178| [CVE-2012-5383] ** DISPUTED ** Untrusted search path vulnerability in the installation functionality in Oracle MySQL 5.5.28, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the "C:\MySQL\MySQL Server 5.5\bin" directory, which may be added to the PATH system environment variable by an administrator, as demonstrated by a Trojan horse wlbsctrl.dll file used by the "IKE and AuthIP IPsec Keying Modules" system service in Windows Vista SP1, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 Release Preview. NOTE: CVE disputes this issue because the unsafe PATH is established only by a separate administrative action that is not a default part of the MySQL installation.
20179| [CVE-2012-5096] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors.
20180| [CVE-2012-5060] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and earlier allows remote authenticated users to affect availability, related to GIS Extension.
20181| [CVE-2012-4452] MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of a CVE-2009-4030 regression, which was not omitted in other packages and versions such as MySQL 5.0.95 in Red Hat Enterprise Linux 6.
20182| [CVE-2012-4414] Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete.
20183| [CVE-2012-4255] MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.
20184| [CVE-2012-4254] MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.
20185| [CVE-2012-4253] Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter learn/cubemail/filemanagement.php, or execute arbitrary local files via a .. (dot dot) in the (3) config parameter to learn/cubemail/menu.php.
20186| [CVE-2012-4252] Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a deletehtaccess action, (2) drop a database via a kill value in a db action, (3) uninstall the application via a 101 value in the phase parameter to learn/cubemail/install.php, (4) delete config.php via a 2 value in the phase parameter to learn/cubemail/install.php, (5) change a password via a schutz action, or (6) execute arbitrary SQL commands via the sql_statement parameter to learn/cubemail/sql.php.
20187| [CVE-2012-4251] Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
20188| [CVE-2012-3951] The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.
20189| [CVE-2012-3441] The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via unspecified vectors.
20190| [CVE-2012-3197] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
20191| [CVE-2012-3180] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20192| [CVE-2012-3177] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server.
20193| [CVE-2012-3173] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin.
20194| [CVE-2012-3167] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.
20195| [CVE-2012-3166] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
20196| [CVE-2012-3163] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
20197| [CVE-2012-3160] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows local users to affect confidentiality via unknown vectors related to Server Installation.
20198| [CVE-2012-3158] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Protocol.
20199| [CVE-2012-3156] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server.
20200| [CVE-2012-3150] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20201| [CVE-2012-3149] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote authenticated users to affect confidentiality, related to MySQL Client.
20202| [CVE-2012-3147] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote attackers to affect integrity and availability, related to MySQL Client.
20203| [CVE-2012-3144] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server.
20204| [CVE-2012-2750] Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this might be a duplicate of CVE-2012-1689, but as of 20120816, Oracle has not commented on this possibility.
20205| [CVE-2012-2749] MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.
20206| [CVE-2012-2122] sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
20207| [CVE-2012-2102] MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
20208| [CVE-2012-1757] Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
20209| [CVE-2012-1756] Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated users to affect availability via unknown vectors.
20210| [CVE-2012-1735] Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20211| [CVE-2012-1734] Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20212| [CVE-2012-1705] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20213| [CVE-2012-1703] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20214| [CVE-2012-1702] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote attackers to affect availability via unknown vectors.
20215| [CVE-2012-1697] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.
20216| [CVE-2012-1696] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20217| [CVE-2012-1690] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20218| [CVE-2012-1689] Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20219| [CVE-2012-1688] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability, related to Server DML.
20220| [CVE-2012-0937] ** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time.
20221| [CVE-2012-0882] Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VulnDisco Pack Professional 9.17. NOTE: as of 20120224, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. NOTE: due to lack of details, it is not clear whether this issue is a duplicate of CVE-2012-0492 or another CVE.
20222| [CVE-2012-0583] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.
20223| [CVE-2012-0578] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
20224| [CVE-2012-0574] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors.
20225| [CVE-2012-0572] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
20226| [CVE-2012-0553] Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulnerability than CVE-2013-1492.
20227| [CVE-2012-0540] Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier and 5.5.23 and earlier allows remote authenticated users to affect availability, related to GIS Extension.
20228| [CVE-2012-0496] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
20229| [CVE-2012-0495] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, and CVE-2012-0493.
20230| [CVE-2012-0494] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows local users to affect availability via unknown vectors.
20231| [CVE-2012-0493] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, and CVE-2012-0495.
20232| [CVE-2012-0492] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0485.
20233| [CVE-2012-0491] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0493, and CVE-2012-0495.
20234| [CVE-2012-0490] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect availability via unknown vectors.
20235| [CVE-2012-0489] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
20236| [CVE-2012-0488] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
20237| [CVE-2012-0487] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
20238| [CVE-2012-0486] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
20239| [CVE-2012-0485] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0492.
20240| [CVE-2012-0484] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect confidentiality via unknown vectors.
20241| [CVE-2012-0120] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0485, and CVE-2012-0492.
20242| [CVE-2012-0119] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.
20243| [CVE-2012-0118] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and availability via unknown vectors, a different vulnerability than CVE-2012-0113.
20244| [CVE-2012-0117] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
20245| [CVE-2012-0116] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
20246| [CVE-2012-0115] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.
20247| [CVE-2012-0114] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows local users to affect confidentiality and integrity via unknown vectors.
20248| [CVE-2012-0113] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and availability via unknown vectors, a different vulnerability than CVE-2012-0118.
20249| [CVE-2012-0112] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.
20250| [CVE-2012-0102] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0087 and CVE-2012-0101.
20251| [CVE-2012-0101] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0087 and CVE-2012-0102.
20252| [CVE-2012-0087] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0101 and CVE-2012-0102.
20253| [CVE-2012-0075] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect integrity via unknown vectors.
20254| [CVE-2011-5049] MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port 3306.
20255| [CVE-2011-4959] SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
20256| [CVE-2011-4899] ** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor disputes the significance of this issue
20257| [CVE-2011-4898] ** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue
20258| [CVE-2011-3989] SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
20259| [CVE-2011-3805] TaskFreak! multi-mysql-0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/language/zh/register_info.php and certain other files.
20260| [CVE-2011-2688] SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
20261| [CVE-2011-2531] Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remote attackers to cause a denial of service (data truncation) by sending a large amount of data.
20262| [CVE-2011-2262] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote attackers to affect availability via unknown vectors.
20263| [CVE-2011-1906] Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event collection table via requests to the management port, a different vulnerability than CVE-2011-0756.
20264| [CVE-2011-1513] Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.
20265| [CVE-2011-0432] Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.
20266| [CVE-2010-5104] The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, which allows remote attackers to obtain sensitive information via wildcard characters in a LIKE query.
20267| [CVE-2010-4822] core/model/MySQLDatabase.php in SilverStripe 2.4.x before 2.4.4, when the site is running in "live mode," allows remote attackers to obtain the SQL queries for a page via the showqueries and ajax parameters.
20268| [CVE-2010-4700] The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.
20269| [CVE-2010-3840] The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a crafted number of (1) line strings or (2) line points.
20270| [CVE-2010-3839] MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (infinite loop) via multiple invocations of a (1) prepared statement or (2) stored procedure that creates a query with nested JOIN statements.
20271| [CVE-2010-3838] MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a query that uses the (1) GREATEST or (2) LEAST function with a mixed list of numeric and LONGBLOB arguments, which is not properly handled when the function's result is "processed using an intermediate temporary table."
20272| [CVE-2010-3837] MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a prepared statement that uses GROUP_CONCAT with the WITH ROLLUP modifier, probably triggering a use-after-free error when a copied object is modified in a way that also affects the original object.
20273| [CVE-2010-3836] MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (assertion failure and server crash) via vectors related to view preparation, pre-evaluation of LIKE predicates, and IN Optimizers.
20274| [CVE-2010-3835] MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (mysqld server crash) by performing a user-variable assignment in a logical expression that is calculated and stored in a temporary table for GROUP BY, then causing the expression value to be used after the table is created, which causes the expression to be re-evaluated instead of accessing its value from the table.
20275| [CVE-2010-3834] Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vectors related to "materializing a derived table that required a temporary table for grouping" and "user variable assignments."
20276| [CVE-2010-3833] MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a denial of service (server crash) via crafted arguments to extreme-value functions such as (1) LEAST and (2) GREATEST, related to KILL_BAD_DATA and a "CREATE TABLE ... SELECT."
20277| [CVE-2010-3683] Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a crafted request.
20278| [CVE-2010-3682] Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
20279| [CVE-2010-3681] Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the HANDLER interface and performing "alternate reads from two indexes on a table," which triggers an assertion failure.
20280| [CVE-2010-3680] Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by creating temporary tables with nullable columns while using InnoDB, which triggers an assertion failure.
20281| [CVE-2010-3679] Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLOG command, which triggers an access of uninitialized memory, as demonstrated by valgrind.
20282| [CVE-2010-3678] Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.
20283| [CVE-2010-3677] Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a join query that uses a table with a unique SET column.
20284| [CVE-2010-3676] storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertion failure) by modifying the (1) innodb_file_format or (2) innodb_file_per_table configuration parameters for the InnoDB storage engine, then executing a DDL statement.
20285| [CVE-2010-3064] Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.
20286| [CVE-2010-3063] The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that cause a negative length value to be used.
20287| [CVE-2010-3062] mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function
20288| [CVE-2010-3056] Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.
20289| [CVE-2010-2008] MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.
20290| [CVE-2010-2003] Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML via the mysql_host parameter.
20291| [CVE-2010-1865] Multiple SQL injection vulnerabilities in ClanSphere 2009.0.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the IP address to the cs_getip function in generate.php in the Captcha module, or (2) the s_email parameter to the cs_sql_select function in the MySQL database driver (mysql.php).
20292| [CVE-2010-1850] Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.
20293| [CVE-2010-1849] The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.
20294| [CVE-2010-1848] Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.
20295| [CVE-2010-1626] MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.
20296| [CVE-2010-1621] The mysql_uninstall_plugin function in sql/sql_plugin.cc in MySQL 5.1 before 5.1.46 does not check privileges before uninstalling a plugin, which allows remote attackers to uninstall arbitrary plugins via the UNINSTALL PLUGIN command.
20297| [CVE-2010-1583] SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! before 0.6.3, allows remote attackers to execute arbitrary SQL commands via the username field in a login action.
20298| [CVE-2010-0336] Unspecified vulnerability in the kiddog_mysqldumper (kiddog_mysqldumper) extension 0.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.
20299| [CVE-2010-0124] Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
20300| [CVE-2009-5026] The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.
20301| [CVE-2009-4833] MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate.
20302| [CVE-2009-4484] Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.
20303| [CVE-2009-4030] MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
20304| [CVE-2009-4028] The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.
20305| [CVE-2009-4019] mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
20306| [CVE-2009-3696] Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.
20307| [CVE-2009-3102] The doHotCopy subroutine in socket-server.pl in Zmanda Recovery Manager (ZRM) for MySQL 2.x before 2.1.1 allows remote attackers to execute arbitrary commands via vectors involving a crafted $MYSQL_BINPATH variable.
20308| [CVE-2009-2942] The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
20309| [CVE-2009-2446] Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request. NOTE: some of these details are obtained from third party information.
20310| [CVE-2009-1246] Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) row_mysql_blocks_center_down[file] parameter to includes/block_center_down.php
20311| [CVE-2009-1208] SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.
20312| [CVE-2009-0919] XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet."
20313| [CVE-2009-0819] sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.
20314| [CVE-2009-0617] Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL root password, which makes it easier for remote attackers to execute arbitrary operating-system commands or change system files.
20315| [CVE-2009-0543] ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.
20316| [CVE-2008-7247] sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.
20317| [CVE-2008-6992] GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.
20318| [CVE-2008-6813] SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the id_kat parameter.
20319| [CVE-2008-6812] SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter.
20320| [CVE-2008-6655] Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via the (1) nom_branche and (2) nom parameters to php/prenom.php
20321| [CVE-2008-6287] Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4) VideoController.php, and (5) ViewController.php in controllers/.
20322| [CVE-2008-6193] Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
20323| [CVE-2008-5847] Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.
20324| [CVE-2008-5738] Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the nodstrumCalendarV2 cookie to 1. NOTE: some of these details are obtained from third party information.
20325| [CVE-2008-5737] SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the username parameter.
20326| [CVE-2008-5069] SQL injection vulnerability in go.php in Panuwat PromoteWeb MySQL, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
20327| [CVE-2008-4456] Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
20328| [CVE-2008-4455] Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the language cookie.
20329| [CVE-2008-4454] Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the lang parameter to actions.php. NOTE: the provenance of this information is unknown
20330| [CVE-2008-4180] Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a "localhost" g_dbhost parameter value, related to a "Mysql Remote Brute Force Vulnerability."
20331| [CVE-2008-4106] WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.
20332| [CVE-2008-4098] MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
20333| [CVE-2008-4097] MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.
20334| [CVE-2008-3963] MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.
20335| [CVE-2008-3846] Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
20336| [CVE-2008-3840] Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
20337| [CVE-2008-3820] Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.
20338| [CVE-2008-3582] SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
20339| [CVE-2008-3090] Multiple SQL injection vulnerabilities in index.php in BlognPlus (BURO GUN +) 2.5.5 MySQL and PostgreSQL editions allow remote attackers to execute arbitrary SQL commands via the (1) p, (2) e, (3) d, and (4) m parameters, a different vulnerability than CVE-2008-2819.
20340| [CVE-2008-2881] Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
20341| [CVE-2008-2857] AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
20342| [CVE-2008-2819] SQL injection vulnerability in BlognPlus (BURO GUN +) 2.5.4 and earlier MySQL and PostgreSQL editions allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
20343| [CVE-2008-2667] SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
20344| [CVE-2008-2384] SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
20345| [CVE-2008-2079] MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.
20346| [CVE-2008-2029] Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary SQL commands via the xtr parameter in a userinfo action to index.php.
20347| [CVE-2008-1711] Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
20348| [CVE-2008-1567] phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
20349| [CVE-2008-1486] SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commands via the non-fulltext search.
20350| [CVE-2008-0249] PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails. NOTE: this might only be an issue in limited environments.
20351| [CVE-2008-0227] yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.
20352| [CVE-2008-0226] Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
20353| [CVE-2007-6512] PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database information via a direct request to inc/lib.inc.
20354| [CVE-2007-6418] The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.
20355| [CVE-2007-6345] SQL injection vulnerability in aurora framework before 20071208 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the value parameter to the pack_var function in module/db.lib/db_mysql.lib. NOTE: some of these details are obtained from third party information.
20356| [CVE-2007-6313] MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements.
20357| [CVE-2007-6304] The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.
20358| [CVE-2007-6303] MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.
20359| [CVE-2007-6081] AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" account without a password, which allows remote attackers to gain privileges and modify logs.
20360| [CVE-2007-5970] MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use of table-level DATA DIRECTORY and INDEX DIRECTORY options when creating a partitioned table with the same name as a table on which the user lacks privileges.
20361| [CVE-2007-5969] MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.
20362| [CVE-2007-5925] The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error.
20363| [CVE-2007-5646] SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php.
20364| [CVE-2007-5626] make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.
20365| [CVE-2007-5488] Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to execute arbitrary SQL commands via the (1) source and (2) destination numbers, and probably (3) SIP URI, when inserting a record.
20366| [CVE-2007-4889] The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.
20367| [CVE-2007-3997] The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.
20368| [CVE-2007-3782] MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table.
20369| [CVE-2007-3781] MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.
20370| [CVE-2007-3780] MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.
20371| [CVE-2007-3567] MySQLDumper 1.21b through 1.23 REV227 uses a "Limit GET" statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests.
20372| [CVE-2007-2857] PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the parser_path parameter.
20373| [CVE-2007-2766] lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing the process and its arguments, related to lib/backup-methods.sh.
20374| [CVE-2007-2693] MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
20375| [CVE-2007-2692] The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.
20376| [CVE-2007-2691] MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
20377| [CVE-2007-2583] The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
20378| [CVE-2007-2554] Associated Press (AP) Newspower 4.0.1 and earlier uses a default blank password for the MySQL root account, which allows remote attackers to insert or modify news articles via shows.tblscript.
20379| [CVE-2007-2429] ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of this information is unknown
20380| [CVE-2007-2364] Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) mysql.class.php or (2) postgres.class.php in lib/db/
20381| [CVE-2007-2204] Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3) theme parameter to themes/ubb/login.php.
20382| [CVE-2007-2016] Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.
20383| [CVE-2007-1779] Multiple SQL injection vulnerabilities in the MySQL back-end in Advanced Website Creator (AWC) before 1.9.0 might allow remote attackers to execute arbitrary SQL commands via unspecified parameters, related to use of mysql_escape_string instead of mysql_real_escape_string.
20384| [CVE-2007-1778] PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
20385| [CVE-2007-1548] SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.
20386| [CVE-2007-1455] Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbitrary local files via (1) the userlanguage parameter to includes/load_language.php or (2) the fantasticopath parameter to includes/mysqlconfig.php and certain other files.
20387| [CVE-2007-1439] PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.
20388| [CVE-2007-1420] MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.
20389| [CVE-2007-1167] inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.
20390| [CVE-2007-1111] Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
20391| [CVE-2007-0926] The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables.
20392| [CVE-2007-0890] Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter.
20393| [CVE-2007-0828] PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in the newsenginedir parameter.
20394| [CVE-2007-0167] Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/
20395| [CVE-2007-0124] Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.
20396| [CVE-2006-7232] sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.
20397| [CVE-2006-7194] PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PATH_COMPOSANT] parameter.
20398| [CVE-2006-6948] MyODBC Japanese conversion edition 3.51.06, 2.50.29, and 2.50.25 allows remote attackers to cause a denial of service via a certain string in a response, which has unspecified impact on the MySQL database.
20399| [CVE-2006-6457] tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.
20400| [CVE-2006-6378] BTSaveMySql 1.2 stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain configuration and save files via direct requests.
20401| [CVE-2006-6254] administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from conn_cahier_de_texte.php. NOTE: it is not clear whether the scope of this issue extends above the web document root, and whether directory traversal is the primary vulnerability.
20402| [CVE-2006-5893] Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) mysql.php and (2) mysqli.php in include/classes/pear/DB/.
20403| [CVE-2006-5702] Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6) tiki-directory_add_site.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-forums.php, (10) tiki-view_forum.php, (11) tiki-friends.php, (12) tiki-list_blogs.php, (13) tiki-list_faqs.php, (14) tiki-list_trackers.php, (15) tiki-list_users.php, (16) tiki-my_tiki.php, (17) tiki-notepad_list.php, (18) tiki-orphan_pages.php, (19) tiki-shoutbox.php, (20) tiki-usermenu.php, and (21) tiki-webmail_contacts.php, which reveal the information in certain database error messages.
20404| [CVE-2006-5675] Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unknown impact and attack vectors, related to "MySQL Scripts need changes for security," possibly SQL injection vulnerabilities associated with these scripts.
20405| [CVE-2006-5381] Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a direct request to (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysqli.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, (7) db_pgsql.inc, or (8) db_sybase.inc in the conlib/ directory.
20406| [CVE-2006-5264] Cross-site scripting (XSS) vulnerability in sql.php in MysqlDumper 1.21 b6 allows remote attackers to inject arbitrary web script or HTML via the db parameter.
20407| [CVE-2006-5127] Multiple cross-site scripting (XSS) vulnerabilities in Bartels Schoene ConPresso before 4.0.5a allow remote attackers to inject arbitrary web script or HTML via (1) the nr parameter in detail.php, (2) the msg parameter in db_mysql.inc.php, and (3) the pos parameter in index.php.
20408| [CVE-2006-5079] PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter.
20409| [CVE-2006-5065] PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[lib][db][path] parameter.
20410| [CVE-2006-5029] SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report was disputed by a third party for 2.3.3 and 2.3.4.
20411| [CVE-2006-5027] Jeroen Vennegoor JevonCMS, possibly pre alpha, allows remote attackers to obtain sensitive information via a direct request for php/main/phplib files (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysql.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, and (7) db_pgsql.inc
20412| [CVE-2006-5014] Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
20413| [CVE-2006-4994] Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted "Program Files" pathname.
20414| [CVE-2006-4835] Bluview Blue Magic Board (BMB) (aka BMForum) 5.5 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) db_mysql_error.php, (4) langlist.php, (5) sendmail.php, or (6) style.php, which reveals the path in various error messages.
20415| [CVE-2006-4578] export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain sensitive information.
20416| [CVE-2006-4380] MySQL before 4.1.13 allows local users to cause a denial of service (persistent replication slave crash) via a query with multiupdate and subselects.
20417| [CVE-2006-4277] Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to (1) include/novalib/class.novaAdmin.mysql.php and (2) novalib/class.novaRead.mysql.php. NOTE: the provenance of this information is unknown
20418| [CVE-2006-4276] PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.
20419| [CVE-2006-4227] MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.
20420| [CVE-2006-4226] MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions.
20421| [CVE-2006-4031] MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
20422| [CVE-2006-3965] Banex PHP MySQL Banner Exchange 2.21 stores lib.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as database usernames and passwords.
20423| [CVE-2006-3964] PHP remote file inclusion vulnerability in members.php in Banex PHP MySQL Banner Exchange 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_root parameter.
20424| [CVE-2006-3963] Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner Exchange 2.21 allow remote attackers to execute arbitrary SQL commands via the (1) site_name parameter to (a) signup.php, and the (2) id, (3) deleteuserbanner, (4) viewmem, (5) viewmemunb, (6) viewunmem,or (7) deleteuser parameters to (b) admin.php.
20425| [CVE-2006-3878] Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysql with insecure permissions, which allows local users to read the root password for the MySQL MAX database or gain privileges by modifying /etc/init.d/mysql.
20426| [CVE-2006-3486] ** DISPUTED ** Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) via unspecified vectors, which triggers the overflow when the convert_dirname function is called. NOTE: the vendor has disputed this issue via e-mail to CVE, saying that it is only exploitable when the user has access to the configuration file or the Instance Manager daemon. Due to intended functionality, this level of access would already allow the user to disrupt program operation, so this does not cross security boundaries and is not a vulnerability.
20427| [CVE-2006-3469] Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.
20428| [CVE-2006-3330] Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title" field), (2) url, and (3) Description parameters, possibly related to issues in add1.php.
20429| [CVE-2006-3329] SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter.
20430| [CVE-2006-3081] mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
20431| [CVE-2006-2753] SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
20432| [CVE-2006-2750] Cross-site scripting (XSS) vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary web scripts or HTML via failed SQL queries, which is reflected in an error message.
20433| [CVE-2006-2748] SQL injection vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary SQL commands via multiple vectors, as demonstrated by the (1) type parameter in adminfunctions.php and the (2) catalogue_id parameter in editcatalogue.php.
20434| [CVE-2006-2742] SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.
20435| [CVE-2006-2543] Xtreme Topsites 1.1 allows remote attackers to trigger MySQL errors and possibly conduct SQL injection attacks via unspecified vectors in join.php.
20436| [CVE-2006-2329] AngelineCMS 0.6.5 and earlier allow remote attackers to obtain sensitive information via a direct request for (1) adodb-access.inc.php, (2) adodb-ado.inc.php, (3) adodb-ado_access.inc, (4) adodb-ado_mssql.inc.php, (5) adodb-borland_ibase, (6) adodb-csv.inc.php, (7) adodb-db2.inc.php, (8) adodb-fbsql.inc.php, (9) adodb-firebird.inc.php, (10) adodb-ibase.inc.php, (11) adodb-informix.inc.php, (12) adodb-informix72.inc, (13) adodb-mssql.inc.php, (14) adodb-mssqlpo.inc.php, (15) adodb-mysql.inc.php, (16) adodb-mysqlt.inc.php, (17) adodb-oci8.inc.php, (18) adodb-oci805.inc.php, (19) adodb-oci8po.inc.php, and (20) adodb-odbc.inc.php, which reveal the path in various error messages
20437| [CVE-2006-2042] Adobe Dreamweaver 8 before 8.0.2 and MX 2004 can generate code that allows SQL injection attacks in the (1) ColdFusion, (2) PHP mySQL, (3) ASP, (4) ASP.NET, and (5) JSP server models.
20438| [CVE-2006-1930] ** DISPUTED ** Multiple SQL injection vulnerabilities in userscript.php in Green Minute 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) huserid, (2) pituus, or (3) date parameters. NOTE: this issue has been disputed by the vendor, saying "those parameters mentioned ARE checked (preg_match) before they are used in SQL-query... If someone decided to add SQL-injection stuff to certain parameter, they would see an error text, but only because _nothing_ was passed inside that parameter (to MySQL-database)." As allowed by the vendor, CVE investigated this report on 20060525 and found that the demo site demonstrated a non-sensitive SQL error when given standard SQL injection manipulations.
20439| [CVE-2006-1518] Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.
20440| [CVE-2006-1517] sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.
20441| [CVE-2006-1516] The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.
20442| [CVE-2006-1451] MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges to that database.
20443| [CVE-2006-1396] Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown
20444| [CVE-2006-1395] SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown
20445| [CVE-2006-1324] Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.
20446| [CVE-2006-1211] IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 configures a MySQL database to allow connections from any source IP address with the ns database account, which allows remote attackers to bypass the Netcool/NeuSecure application layer and perform unauthorized database actions. NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.
20447| [CVE-2006-1210] The web interface for IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 includes the MySQL database username and password in cleartext in body.phtml, which allows remote attackers to gain privileges by reading the source. NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.
20448| [CVE-2006-1112] Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which displays the installation path in a MySQL error message.
20449| [CVE-2006-1111] Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, which reveals usernames and passwords in a MySQL error message, possibly due to a forced SQL error or SQL injection.
20450| [CVE-2006-0909] Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) class_db.php, (5) class_db_mysql.php, and (6) class_xml.php in the ips_kernel/ directory
20451| [CVE-2006-0903] MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.
20452| [CVE-2006-0692] Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
20453| [CVE-2006-0369] ** DISPUTED ** MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views
20454| [CVE-2006-0200] Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.
20455| [CVE-2006-0146] The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
20456| [CVE-2006-0097] Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.
20457| [CVE-2006-0056] Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function. NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.
20458| [CVE-2005-4713] Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP address argument to an sprintf call.
20459| [CVE-2005-4661] The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.
20460| [CVE-2005-4626] The default configuration of Recruitment Software installs admin/site.xml under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (MySQL database credentials) via a direct request.
20461| [CVE-2005-4237] Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module.
20462| [CVE-2005-2865] Multiple PHP remote file inclusion vulnerabilities in aMember Pro 2.3.4 allow remote attackers to execute arbitrary PHP code via the config[root_dir] parameter to (1) mysql.inc.php, (2) efsnet.inc.php, (3) theinternetcommerce.inc.php, (4) cdg.inc.php, (5) compuworld.inc.php, (6) directone.inc.php, (7) authorize_aim.inc.php, (8) beanstream.inc.php, (9) config.inc.php, (10) eprocessingnetwork.inc.php, (11) eway.inc.php, (12) linkpoint.inc.php, (13) logiccommerce.inc.php, (14) netbilling.inc.php, (15) payflow_pro.inc.php, (16) paymentsgateway.inc.php, (17) payos.inc.php, (18) payready.inc.php, or (19) plugnplay.inc.php.
20463| [CVE-2005-2573] The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character.
20464| [CVE-2005-2572] MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute arbitrary code via (1) a request for a non-library file, which causes the Windows LoadLibraryEx function to block, or (2) a request for a function in a library that has the XXX_deinit or XXX_init functions defined but is not tailored for mySQL, such as jpeg1x32.dll and jpeg2x32.dll.
20465| [CVE-2005-2571] FunkBoard 0.66CF, and possibly earlier versions, does not properly restrict access to the (1) admin/mysql_install.php and (2) admin/pg_install.php scripts, which allows attackers to obtain the database username and password or inject arbitrary PHP code into info.php.
20466| [CVE-2005-2558] Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.
20467| [CVE-2005-2468] Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or the insert function in (7) releases.php or (8) class.release.php.
20468| [CVE-2005-2467] Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.
20469| [CVE-2005-2174] Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.
20470| [CVE-2005-1944] xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.
20471| [CVE-2005-1636] mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.
20472| [CVE-2005-1274] Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter.
20473| [CVE-2005-1121] Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.
20474| [CVE-2005-0799] MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.
20475| [CVE-2005-0711] MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.
20476| [CVE-2005-0710] MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.
20477| [CVE-2005-0709] MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
20478| [CVE-2005-0684] Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.
20479| [CVE-2005-0646] SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.
20480| [CVE-2005-0544] phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exists.lib.php, (11) charset_conversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.
20481| [CVE-2005-0111] Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.
20482| [CVE-2005-0083] MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.
20483| [CVE-2005-0082] The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash.
20484| [CVE-2005-0081] MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers.
20485| [CVE-2005-0004] The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
20486| [CVE-2004-2632] phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
20487| [CVE-2004-2398] Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.
20488| [CVE-2004-2357] The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, which allows remote attackers to read or modify the backend database.
20489| [CVE-2004-2354] SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
20490| [CVE-2004-2149] Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.
20491| [CVE-2004-2138] Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Comments field.
20492| [CVE-2004-1228] The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.
20493| [CVE-2004-0957] Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
20494| [CVE-2004-0956] MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.
20495| [CVE-2004-0931] MySQL MaxDB before 7.5.00.18 allows remote attackers to cause a denial of service (crash) via an HTTP request to webdbm with high ASCII values in the Server field, which triggers an assert error in the IsAscii7 function.
20496| [CVE-2004-0837] MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
20497| [CVE-2004-0836] Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).
20498| [CVE-2004-0835] MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
20499| [CVE-2004-0628] Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scramble string.
20500| [CVE-2004-0627] The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.
20501| [CVE-2004-0457] The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
20502| [CVE-2004-0388] The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.
20503| [CVE-2004-0381] mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.
20504| [CVE-2003-1480] MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.
20505| [CVE-2003-1421] Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.
20506| [CVE-2003-1383] WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the MySQL database username and password.
20507| [CVE-2003-1331] Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.
20508| [CVE-2003-0780] Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.
20509| [CVE-2003-0515] SQL injection vulnerabilities in the (1) PostgreSQL or (2) MySQL authentication modules for teapop 0.3.5 and earlier allow attackers to execute arbitrary SQL and possibly gain privileges.
20510| [CVE-2003-0150] MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
20511| [CVE-2003-0073] Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.
20512| [CVE-2002-2043] SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.
20513| [CVE-2002-1952] phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable.
20514| [CVE-2002-1923] The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.
20515| [CVE-2002-1921] The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.
20516| [CVE-2002-1809] The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers to gain unauthorized root access to the MySQL database.
20517| [CVE-2002-1479] Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users modify databases as the Cacti user and possibly gain privileges.
20518| [CVE-2002-1376] libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
20519| [CVE-2002-1375] The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
20520| [CVE-2002-1374] The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.
20521| [CVE-2002-1373] Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.
20522| [CVE-2002-0969] Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.
20523| [CVE-2002-0229] Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.
20524| [CVE-2001-1454] Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.
20525| [CVE-2001-1453] Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.
20526| [CVE-2001-1275] MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
20527| [CVE-2001-1274] Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
20528| [CVE-2001-1255] WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.
20529| [CVE-2001-1226] AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.
20530| [CVE-2001-1044] Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.
20531| [CVE-2001-0990] Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.
20532| [CVE-2001-0645] Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.
20533| [CVE-2001-0407] Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
20534| [CVE-2000-0981] MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
20535| [CVE-2000-0957] The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.
20536| [CVE-2000-0707] PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.
20537| [CVE-2000-0148] MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.
20538| [CVE-2000-0045] MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
20539| [CVE-1999-1188] mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.
20540|
20541| SecurityFocus - https://www.securityfocus.com/bid/:
20542| [104370] MySQL Multi-Master Replication Manager Multiple Remote Command Injection Vulnerabilities
20543| [103954] Oracle MySQL CVE-2018-2767 Incomplete Fix SSL Certificate Validation Security Bypass Vulnerability
20544| [103876] Oracle MySQL Server CVE-2018-2769 Remote Security Vulnerability
20545| [103845] Oracle MySQL Server CVE-2018-2839 Remote Security Vulnerability
20546| [103838] Oracle MySQL Cluster CVE-2018-2877 Local Security Vulnerability
20547| [103836] Oracle MySQL Server CVE-2018-2812 Remote Security Vulnerability
20548| [103831] Oracle MySQL Server CVE-2018-2805 Remote Security Vulnerability
20549| [103830] Oracle MySQL Server CVE-2018-2813 Remote Security Vulnerability
20550| [103828] Oracle MySQL Server CVE-2018-2771 Remote Security Vulnerability
20551| [103825] Oracle MySQL Server CVE-2018-2781 Remote Security Vulnerability
20552| [103824] Oracle MySQL Server CVE-2018-2818 Remote Security Vulnerability
20553| [103820] Oracle MySQL Server CVE-2018-2761 Remote Security Vulnerability
20554| [103818] Oracle MySQL Server CVE-2018-2817 Remote Security Vulnerability
20555| [103814] Oracle MySQL Server CVE-2018-2819 Remote Security Vulnerability
20556| [103811] Oracle MySQL Server CVE-2018-2773 Local Security Vulnerability
20557| [103807] Oracle MySQL Server CVE-2018-2755 Local Security Vulnerability
20558| [103805] Oracle MySQL Server CVE-2018-2766 Remote Security Vulnerability
20559| [103804] Oracle MySQL Server CVE-2018-2787 Remote Security Vulnerability
20560| [103802] Oracle MySQL Server CVE-2018-2758 Remote Security Vulnerability
20561| [103801] Oracle MySQL Server CVE-2018-2784 Remote Security Vulnerability
20562| [103799] Oracle MySQL Server CVE-2018-2782 Remote Security Vulnerability
20563| [103794] Oracle MySQL Server CVE-2018-2762 Remote Security Vulnerability
20564| [103791] Oracle MySQL Server CVE-2018-2776 Remote Security Vulnerability
20565| [103790] Oracle MySQL Server CVE-2018-2846 Remote Security Vulnerability
20566| [103789] Oracle MySQL Server CVE-2018-2816 Remote Security Vulnerability
20567| [103787] Oracle MySQL Server CVE-2018-2779 Remote Security Vulnerability
20568| [103785] Oracle MySQL Server CVE-2018-2778 Remote Security Vulnerability
20569| [103783] Oracle MySQL Server CVE-2018-2810 Remote Security Vulnerability
20570| [103781] Oracle MySQL Server CVE-2018-2777 Remote Security Vulnerability
20571| [103780] Oracle MySQL Server CVE-2018-2759 Remote Security Vulnerability
20572| [103779] Oracle MySQL Server CVE-2018-2786 Remote Security Vulnerability
20573| [103778] Oracle MySQL Server CVE-2018-2780 Remote Security Vulnerability
20574| [103777] Oracle MySQL Server CVE-2018-2775 Remote Security Vulnerability
20575| [102714] Oracle MySQL Server CVE-2018-2591 Remote Security Vulnerability
20576| [102713] Oracle MySQL Server CVE-2018-2562 Remote Security Vulnerability
20577| [102712] Oracle MySQL Server CVE-2018-2565 Remote Security Vulnerability
20578| [102711] Oracle MySQL Server CVE-2018-2647 Remote Security Vulnerability
20579| [102710] Oracle MySQL Server CVE-2018-2573 Remote Security Vulnerability
20580| [102709] Oracle MySQL Server CVE-2018-2612 Remote Security Vulnerability
20581| [102708] Oracle MySQL Server CVE-2018-2583 Remote Security Vulnerability
20582| [102706] Oracle MySQL Server CVE-2018-2622 Remote Security Vulnerability
20583| [102704] Oracle MySQL Server CVE-2018-2703 Remote Security Vulnerability
20584| [102703] Oracle MySQL Server CVE-2018-2646 Remote Security Vulnerability
20585| [102701] Oracle MySQL Server CVE-2018-2696 Remote Security Vulnerability
20586| [102700] Oracle MySQL Server CVE-2018-2586 Remote Security Vulnerability
20587| [102698] Oracle MySQL Server CVE-2018-2645 Remote Security Vulnerability
20588| [102697] Oracle MySQL Server CVE-2018-2590 Remote Security Vulnerability
20589| [102696] Oracle MySQL Server CVE-2018-2600 Remote Security Vulnerability
20590| [102695] Oracle MySQL Server CVE-2018-2576 Remote Security Vulnerability
20591| [102685] Oracle MySQL Server CVE-2018-2667 Remote Security Vulnerability
20592| [102682] Oracle MySQL Server CVE-2018-2668 Remote Security Vulnerability
20593| [102681] Oracle MySQL Server CVE-2018-2665 Remote Security Vulnerability
20594| [102678] Oracle MySQL Server CVE-2018-2640 Remote Security Vulnerability
20595| [102674] Oracle MySQL Connectors CVE-2018-2585 Remote Security Vulnerability
20596| [101448] Oracle MySQL Server CVE-2017-10313 Remote Security Vulnerability
20597| [101446] Oracle MySQL Server CVE-2017-10311 Remote Security Vulnerability
20598| [101444] Oracle MySQL Server CVE-2017-10294 Remote Security Vulnerability
20599| [101441] Oracle MySQL Server CVE-2017-10276 Remote Security Vulnerability
20600| [101439] Oracle MySQL Connectors CVE-2017-10277 Remote Security Vulnerability
20601| [101433] Oracle MySQL Server CVE-2017-10167 Remote Security Vulnerability
20602| [101429] Oracle MySQL Server CVE-2017-10365 Remote Security Vulnerability
20603| [101424] Oracle MySQL Server CVE-2017-10165 Remote Security Vulnerability
20604| [101420] Oracle MySQL Server CVE-2017-10283 Remote Security Vulnerability
20605| [101415] Oracle MySQL Server CVE-2017-10379 Remote Security Vulnerability
20606| [101410] Oracle MySQL Server CVE-2017-10320 Remote Security Vulnerability
20607| [101406] Oracle MySQL Server CVE-2017-10384 Remote Security Vulnerability
20608| [101402] Oracle MySQL Server CVE-2017-10155 Remote Security Vulnerability
20609| [101397] Oracle MySQL Server CVE-2017-10286 Remote Security Vulnerability
20610| [101390] Oracle MySQL Server CVE-2017-10268 Local Security Vulnerability
20611| [101385] Oracle MySQL Server CVE-2017-10284 Remote Security Vulnerability
20612| [101381] Oracle MySQL Enterprise Monitor CVE-2017-10424 Remote Security Vulnerability
20613| [101375] Oracle MySQL Server CVE-2017-10378 Remote Security Vulnerability
20614| [101373] Oracle MySQL Server CVE-2017-10296 Remote Security Vulnerability
20615| [101337] Oracle MySQL Server CVE-2017-10227 Remote Security Vulnerability
20616| [101324] Oracle MySQL Connectors CVE-2017-10203 Remote Security Vulnerability
20617| [101316] Oracle MySQL Server CVE-2017-10279 Remote Security Vulnerability
20618| [101314] Oracle MySQL Server CVE-2017-10314 Remote Security Vulnerability
20619| [99810] Oracle MySQL Server CVE-2017-3653 Remote Security Vulnerability
20620| [99808] Oracle MySQL Server CVE-2017-3650 Remote Security Vulnerability
20621| [99805] Oracle MySQL Server CVE-2017-3652 Remote Security Vulnerability
20622| [99802] Oracle MySQL Server CVE-2017-3651 Remote Security Vulnerability
20623| [99799] Oracle MySQL Server CVE-2017-3649 Remote Security Vulnerability
20624| [99796] Oracle MySQL Server CVE-2017-3647 Remote Security Vulnerability
20625| [99789] Oracle MySQL Server CVE-2017-3648 Remote Security Vulnerability
20626| [99786] Oracle MySQL Server CVE-2017-3646 Remote Security Vulnerability
20627| [99783] Oracle MySQL Server CVE-2017-3645 Remote Security Vulnerability
20628| [99779] Oracle MySQL Server CVE-2017-3642 Remote Security Vulnerability
20629| [99778] Oracle MySQL Server CVE-2017-3638 Remote Security Vulnerability
20630| [99775] Oracle MySQL Server CVE-2017-3644 Remote Security Vulnerability
20631| [99772] Oracle MySQL Server CVE-2017-3643 Remote Security Vulnerability
20632| [99767] Oracle MySQL Server CVE-2017-3641 Remote Security Vulnerability
20633| [99765] Oracle MySQL Server CVE-2017-3640 Remote Security Vulnerability
20634| [99753] Oracle MySQL Server CVE-2017-3639 Remote Security Vulnerability
20635| [99748] Oracle MySQL Server CVE-2017-3637 Remote Security Vulnerability
20636| [99746] Oracle MySQL Server CVE-2017-3529 Remote Security Vulnerability
20637| [99736] Oracle MySQL Server CVE-2017-3636 Local Security Vulnerability
20638| [99730] Oracle MySQL Connectors/MySQL Server CVE-2017-3635 Remote Security Vulnerability
20639| [99729] Oracle MySQL Server CVE-2017-3634 Remote Security Vulnerability
20640| [99722] Oracle MySQL Server CVE-2017-3633 Remote Security Vulnerability
20641| [99374] Perl DBD::mysql Module CVE-2017-10788 Use After Free Denial of Service Vulnerability
20642| [99364] Perl DBD::mysql Module CVE-2017-10789 Man in the Middle Security Bypass Vulnerability
20643| [97982] Oracle MySQL Connectors CVE-2017-3523 Remote Security Vulnerability
20644| [97960] MySQL-GUI-tools CVE-2010-4178 Local Information Disclosure Vulnerability
20645| [97959] MySQL-GUI-tools CVE-2010-4177 Local Information Disclosure Vulnerability
20646| [97851] Oracle MySQL Server CVE-2017-3462 Remote Security Vulnerability
20647| [97849] Oracle MySQL Server CVE-2017-3463 Remote Security Vulnerability
20648| [97848] Oracle MySQL Server CVE-2017-3468 Remote Security Vulnerability
20649| [97847] Oracle MySQL Server CVE-2017-3459 Remote Security Vulnerability
20650| [97845] Oracle MySQL Server CVE-2017-3457 Remote Security Vulnerability
20651| [97844] Oracle MySQL Enterprise Monitor CVE-2017-3307 Remote Security Vulnerability
20652| [97840] Oracle MySQL Connectors CVE-2017-3590 Local Security Vulnerability
20653| [97837] Oracle MySQL Server CVE-2017-3458 Remote Security Vulnerability
20654| [97836] Oracle MySQL Connectors CVE-2017-3589 Local Security Vulnerability
20655| [97833] Oracle MySQL Workbench CVE-2017-3469 Remote Security Vulnerability
20656| [97831] Oracle MySQL Server CVE-2017-3456 Remote Security Vulnerability
20657| [97826] Oracle MySQL Server CVE-2017-3460 Remote Security Vulnerability
20658| [97825] Oracle MySQL Server CVE-2017-3467 Remote Security Vulnerability
20659| [97822] Oracle MySQL Server CVE-2017-3465 Remote Security Vulnerability
20660| [97820] Oracle MySQL Server CVE-2017-3455 Remote Security Vulnerability
20661| [97818] Oracle MySQL Server CVE-2017-3464 Remote Security Vulnerability
20662| [97815] Oracle MySQL Cluster CVE-2017-3304 Remote Security Vulnerability
20663| [97812] Oracle MySQL Server CVE-2017-3461 Remote Security Vulnerability
20664| [97791] Oracle MySQL Server CVE-2017-3454 Remote Security Vulnerability
20665| [97784] Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
20666| [97779] Oracle MySQL Server CVE-2017-3452 Remote Security Vulnerability
20667| [97776] Oracle MySQL Server CVE-2017-3453 Remote Security Vulnerability
20668| [97772] Oracle MySQL Server CVE-2017-3331 Remote Security Vulnerability
20669| [97765] Oracle MySQL Server CVE-2017-3600 Remote Security Vulnerability
20670| [97763] Oracle MySQL Server CVE-2017-3329 Remote Security Vulnerability
20671| [97754] Oracle MySQL Server CVE-2017-3599 Remote Security Vulnerability
20672| [97747] Oracle MySQL Server CVE-2017-3450 Remote Security Vulnerability
20673| [97742] Oracle MySQL Server CVE-2017-3309 Remote Security Vulnerability
20674| [97725] Oracle MySQL Server CVE-2017-3308 Remote Security Vulnerability
20675| [97724] Oracle MySQL Enterprise Monitor CVE-2017-3306 Remote Security Vulnerability
20676| [97023] MySQL CVE-2017-3305 Man in the Middle Security Bypass Vulnerability
20677| [96300] PHP 'ext/mysqli/mysqli.c' Denial of Service Vulnerability
20678| [96162] MariaDB and MySQL CVE-2017-3302 Denial of Service Vulnerability
20679| [95592] Oracle MySQL Cluster CVE-2016-5541 Remote Security Vulnerability
20680| [95589] Oracle MySQL Server CVE-2017-3257 Remote Security Vulnerability
20681| [95588] Oracle MySQL Server CVE-2017-3318 Local Security Vulnerability
20682| [95585] Oracle MySQL Server CVE-2017-3317 Local Security Vulnerability
20683| [95583] Oracle MySQL Server CVE-2017-3273 Remote Security Vulnerability
20684| [95580] Oracle MySQL Server CVE-2016-8318 Remote Security Vulnerability
20685| [95575] Oracle MySQL Cluster CVE-2017-3323 Remote Security Vulnerability
20686| [95574] Oracle MySQL Cluster CVE-2017-3322 Remote Security Vulnerability
20687| [95571] Oracle MySQL Server CVE-2017-3238 Remote Security Vulnerability
20688| [95565] Oracle MySQL Server CVE-2017-3244 Remote Security Vulnerability
20689| [95562] Oracle MySQL Cluster CVE-2017-3321 Remote Security Vulnerability
20690| [95560] Oracle MySQL Server CVE-2017-3258 Remote Security Vulnerability
20691| [95542] Oracle MySQL Enterprise Monitor CVE-2016-5590 Remote Security Vulnerability
20692| [95538] Oracle MySQL Server CVE-2017-3243 Remote Security Vulnerability
20693| [95527] Oracle MySQL Server CVE-2017-3313 Local Security Vulnerability
20694| [95520] Oracle MySQL Server CVE-2017-3265 Local Security Vulnerability
20695| [95501] Oracle MySQL Server CVE-2017-3291 Local Security Vulnerability
20696| [95491] Oracle MySQL Server CVE-2017-3312 Local Security Vulnerability
20697| [95486] Oracle MySQL Server CVE-2017-3256 Remote Security Vulnerability
20698| [95482] Oracle MySQL Server CVE-2017-3251 Remote Security Vulnerability
20699| [95479] Oracle MySQL Server CVE-2017-3319 Remote Security Vulnerability
20700| [95470] Oracle MySQL Server CVE-2017-3320 Remote Security Vulnerability
20701| [95146] Pivotal MySQL for PCF CVE-2016-0898 Information Disclosure Vulnerability
20702| [94350] DBD::mysql CVE-2016-1249 Out-Of-Bounds Read Information Disclosure Vulnerability
20703| [93755] Oracle MySQL CVE-2016-8284 Local Security Vulnerability
20704| [93745] Oracle MySQL CVE-2016-8286 Remote Security Vulnerability
20705| [93740] Oracle MySQL CVE-2016-8288 Remote Security Vulnerability
20706| [93737] Oracle MySQL CVE-2016-8283 Remote Security Vulnerability
20707| [93735] Oracle MySQL CVE-2016-5584 Remote Security Vulnerability
20708| [93733] Oracle MySQL CVE-2016-8290 Remote Security Vulnerability
20709| [93727] Oracle MySQL CVE-2016-8287 Remote Security Vulnerability
20710| [93720] Oracle MySQL CVE-2016-8289 Local Security Vulnerability
20711| [93715] Oracle MySQL CVE-2016-5635 Remote Security Vulnerability
20712| [93709] Oracle MySQL CVE-2016-5634 Remote Security Vulnerability
20713| [93702] Oracle MySQL CVE-2016-5633 Remote Security Vulnerability
20714| [93693] Oracle MySQL CVE-2016-5632 Remote Security Vulnerability
20715| [93684] Oracle MySQL CVE-2016-5631 Remote Security Vulnerability
20716| [93678] Oracle MySQL CVE-2016-5507 Remote Security Vulnerability
20717| [93674] Oracle MySQL CVE-2016-5630 Remote Security Vulnerability
20718| [93670] Oracle MySQL CVE-2016-3495 Remote Security Vulnerability
20719| [93668] Oracle MySQL CVE-2016-5629 Remote Security Vulnerability
20720| [93662] Oracle MySQL CVE-2016-5628 Remote Security Vulnerability
20721| [93659] Oracle MySQL CVE-2016-7440 Local Security Vulnerability
20722| [93653] Oracle MySQL Connector CVE-2016-5598 Remote Security Vulnerability
20723| [93650] Oracle MySQL CVE-2016-3492 Remote Security Vulnerability
20724| [93642] Oracle MySQL CVE-2016-5627 Remote Security Vulnerability
20725| [93638] Oracle MySQL CVE-2016-5626 Remote Security Vulnerability
20726| [93635] Oracle MySQL CVE-2016-5624 Remote Security Vulnerability
20727| [93630] Oracle MySQL CVE-2016-5612 Remote Security Vulnerability
20728| [93622] Oracle MySQL CVE-2016-5609 Remote Security Vulnerability
20729| [93617] Oracle MySQL CVE-2016-5625 Local Security Vulnerability
20730| [93614] RETIRED: Oracle MySQL CVE-2016-5616 Local Security Vulnerability
20731| [93612] Oracle MySQL CVE-2016-6664 Local Security Vulnerability
20732| [93480] Pivotal Cloud Foundry cf-mysql CVE-2016-6653 Information Disclosure Vulnerability
20733| [93337] perl-DBD-MySQL CVE-2016-1246 Remote Buffer Overflow Vulnerability
20734| [92912] Oracle MySQL CVE-2016-6662 Remote Code Execution Vulnerability
20735| [92911] Oracle MySQL CVE-2016-6663 Unspecified Security Vulnerability
20736| [92149] DBD::mysql CVE-2014-9906 Incomplete Fix Use After Free Remote Code Execution Vulnerability
20737| [92118] DBD::mysql 'my_login()' Function Use After Free Remote Code Execution Vulnerability
20738| [91999] Oracle MySQL CVE-2016-3452 Remote Security Vulnerability
20739| [91992] Oracle MySQL CVE-2016-3614 Remote Security Vulnerability
20740| [91987] Oracle MySQL CVE-2016-5444 Remote Security Vulnerability
20741| [91983] Oracle MySQL CVE-2016-3588 Remote Security Vulnerability
20742| [91980] Oracle MySQL CVE-2016-3486 Remote Security Vulnerability
20743| [91976] Oracle MySQL CVE-2016-3424 Remote Security Vulnerability
20744| [91974] Oracle MySQL CVE-2016-5442 Remote Security Vulnerability
20745| [91969] Oracle MySQL CVE-2016-5439 Remote Security Vulnerability
20746| [91967] Oracle MySQL CVE-2016-3518 Remote Security Vulnerability
20747| [91963] Oracle MySQL CVE-2016-5443 Local Security Vulnerability
20748| [91960] Oracle MySQL CVE-2016-3615 Remote Security Vulnerability
20749| [91953] Oracle MySQL CVE-2016-5440 Remote Security Vulnerability
20750| [91949] Oracle MySQL CVE-2016-3501 Remote Security Vulnerability
20751| [91943] Oracle MySQL CVE-2016-3459 Remote Security Vulnerability
20752| [91932] Oracle MySQL CVE-2016-3521 Remote Security Vulnerability
20753| [91917] Oracle MySQL CVE-2016-5437 Remote Security Vulnerability
20754| [91915] Oracle MySQL CVE-2016-5441 Remote Security Vulnerability
20755| [91913] Oracle MySQL CVE-2016-3471 Local Security Vulnerability
20756| [91910] Oracle MySQL CVE-2016-3440 Remote Security Vulnerability
20757| [91906] Oracle MySQL CVE-2016-5436 Remote Security Vulnerability
20758| [91902] Oracle MySQL CVE-2016-3477 Local Security Vulnerability
20759| [90165] MySQL CVE-2005-0799 Denial-Of-Service Vulnerability
20760| [89812] xMySQLadmin CVE-2005-1944 Local Security Vulnerability
20761| [89412] MySQL CVE-2005-2573 Directory Traversal Vulnerability
20762| [88627] MySQL CVE-1999-1188 Local Security Vulnerability
20763| [88032] MySQL CVE-2001-1275 Local Security Vulnerability
20764| [87310] Btsavemysql CVE-2006-6378 Remote Security Vulnerability
20765| [86999] MySQL CVE-2001-1274 Denial-Of-Service Vulnerability
20766| [86513] Oracle MySQL CVE-2016-0665 Remote Security Vulnerability
20767| [86511] Oracle MySQL CVE-2016-0661 Remote Security Vulnerability
20768| [86509] Oracle MySQL CVE-2016-0666 Remote Security Vulnerability
20769| [86506] Oracle MySQL CVE-2016-0662 Remote Security Vulnerability
20770| [86504] Oracle MySQL CVE-2016-0654 Remote Security Vulnerability
20771| [86501] Oracle MySQL CVE-2016-0651 Remote Security Vulnerability
20772| [86498] Oracle MySQL CVE-2016-0649 Remote Security Vulnerability
20773| [86496] Oracle MySQL CVE-2016-0650 Remote Security Vulnerability
20774| [86495] Oracle MySQL CVE-2016-0647 Remote Security Vulnerability
20775| [86493] Oracle MySQL CVE-2016-0659 Remote Security Vulnerability
20776| [86489] Oracle MySQL CVE-2016-3461 Remote Security Vulnerability
20777| [86486] Oracle MySQL CVE-2016-0643 Remote Security Vulnerability
20778| [86484] Oracle MySQL CVE-2016-0667 Remote Security Vulnerability
20779| [86470] Oracle MySQL CVE-2016-0641 Remote Security Vulnerability
20780| [86467] Oracle MySQL CVE-2016-0668 Remote Security Vulnerability
20781| [86463] Oracle MySQL CVE-2016-0658 Remote Security Vulnerability
20782| [86457] Oracle MySQL CVE-2016-0648 Remote Security Vulnerability
20783| [86454] Oracle MySQL CVE-2016-0652 Remote Security Vulnerability
20784| [86451] Oracle MySQL CVE-2016-0663 Remote Security Vulnerability
20785| [86445] Oracle MySQL CVE-2016-0642 Remote Security Vulnerability
20786| [86442] Oracle MySQL CVE-2016-0644 Remote Security Vulnerability
20787| [86439] Oracle MySQL CVE-2016-0653 Remote Security Vulnerability
20788| [86436] Oracle MySQL CVE-2016-0646 Remote Security Vulnerability
20789| [86433] Oracle MySQL CVE-2016-0657 Remote Security Vulnerability
20790| [86431] Oracle MySQL CVE-2016-0656 Remote Security Vulnerability
20791| [86427] Oracle MySQL CVE-2016-0640 Remote Security Vulnerability
20792| [86424] Oracle MySQL CVE-2016-0655 Remote Security Vulnerability
20793| [86418] Oracle MySQL CVE-2016-0639 Remote Security Vulnerability
20794| [85985] MariaDB and MySQL CVE-2015-5969 Local Information Disclosure Vulnerability
20795| [85262] MySQL CVE-2007-5970 Remote Security Vulnerability
20796| [85246] Mysql Community Server CVE-2007-6313 Remote Security Vulnerability
20797| [85215] Mysql Banner Exchange CVE-2007-6512 Denial-Of-Service Vulnerability
20798| [83639] MySQLDumper CVE-2006-5264 Cross-Site Scripting Vulnerability
20799| [83232] MySQL Connector/Net CVE-2006-4227 Remote Security Vulnerability
20800| [83194] MySQL CVE-2004-0628 Denial Of Service Vulnerability
20801| [82913] MySQL CVE-2001-1453 Remote Security Vulnerability
20802| [82911] MySQL CVE-2001-1454 Remote Security Vulnerability
20803| [81810] MariaDB/MySQL/Percona Server CVE-2016-2047 SSL Certificate Validation Security Bypass Vulnerability
20804| [81258] Oracle MySQL CVE-2016-0609 Remote Security Vulnerability
20805| [81253] Oracle MySQL CVE-2016-0605 Remote Security Vulnerability
20806| [81245] Oracle MySQL CVE-2015-7744 Remote Security Vulnerability
20807| [81238] Oracle MySQL CVE-2016-0607 Remote Security Vulnerability
20808| [81226] Oracle MySQL CVE-2016-0608 Remote Security Vulnerability
20809| [81211] Oracle MySQL CVE-2016-0601 Remote Security Vulnerability
20810| [81203] Oracle MySQL CVE-2016-0599 Remote Security Vulnerability
20811| [81198] Oracle MySQL CVE-2016-0610 Remote Security Vulnerability
20812| [81188] Oracle MySQL CVE-2016-0600 Remote Security Vulnerability
20813| [81182] Oracle MySQL CVE-2016-0598 Remote Security Vulnerability
20814| [81176] Oracle MySQL CVE-2016-0616 Remote Security Vulnerability
20815| [81164] Oracle MySQL CVE-2016-0611 Remote Security Vulnerability
20816| [81151] Oracle MySQL CVE-2016-0597 Remote Security Vulnerability
20817| [81136] Oracle MySQL CVE-2016-0502 Remote Security Vulnerability
20818| [81130] Oracle MySQL CVE-2016-0596 Remote Security Vulnerability
20819| [81126] Oracle MySQL CVE-2016-0503 Remote Security Vulnerability
20820| [81121] Oracle MySQL CVE-2016-0595 Remote Security Vulnerability
20821| [81108] Oracle MySQL CVE-2016-0594 Remote Security Vulnerability
20822| [81088] Oracle MySQL CVE-2016-0505 Remote Security Vulnerability
20823| [81077] Oracle MySQL CVE-2016-0504 Remote Security Vulnerability
20824| [81066] Oracle MySQL CVE-2016-0546 Local Security Vulnerability
20825| [79408] Mysql-Ocaml CVE-2009-2942 Remote Security Vulnerability
20826| [79044] kiddog_mysqldumper CVE-2010-0336 Information Disclosure Vulnerability
20827| [78373] MySQL CVE-2011-5049 Denial-Of-Service Vulnerability
20828| [77237] Oracle MySQL Server CVE-2015-4826 Remote Security Vulnerability
20829| [77234] Oracle MySQL Server CVE-2015-4910 Remote Security Vulnerability
20830| [77232] Oracle MySQL Server CVE-2015-4766 Local Security Vulnerability
20831| [77231] Oracle MySQL Server CVE-2015-4890 Remote Security Vulnerability
20832| [77228] Oracle MySQL Server CVE-2015-4830 Remote Security Vulnerability
20833| [77222] Oracle MySQL Server CVE-2015-4815 Remote Security Vulnerability
20834| [77219] Oracle MySQL Server CVE-2015-4904 Remote Security Vulnerability
20835| [77216] Oracle MySQL Server CVE-2015-4800 Remote Security Vulnerability
20836| [77213] Oracle MySQL Server CVE-2015-4791 Remote Security Vulnerability
20837| [77208] Oracle MySQL Server CVE-2015-4870 Remote Security Vulnerability
20838| [77205] Oracle MySQL Server CVE-2015-4807 Remote Security Vulnerability
20839| [77199] Oracle MySQL Server CVE-2015-4730 Remote Security Vulnerability
20840| [77196] Oracle MySQL Server CVE-2015-4819 Local Security Vulnerability
20841| [77190] Oracle MySQL Server CVE-2015-4836 Remote Security Vulnerability
20842| [77187] Oracle MySQL Server CVE-2015-4864 Remote Security Vulnerability
20843| [77171] Oracle MySQL Server CVE-2015-4792 Remote Security Vulnerability
20844| [77170] Oracle MySQL Server CVE-2015-4833 Remote Security Vulnerability
20845| [77165] Oracle MySQL Server CVE-2015-4802 Remote Security Vulnerability
20846| [77153] Oracle MySQL Server CVE-2015-4913 Remote Security Vulnerability
20847| [77147] Oracle MySQL Server CVE-2015-4862 Remote Security Vulnerability
20848| [77145] Oracle MySQL Server CVE-2015-4858 Remote Security Vulnerability
20849| [77143] Oracle MySQL Server CVE-2015-4905 Remote Security Vulnerability
20850| [77140] Oracle MySQL Server CVE-2015-4879 Remote Security Vulnerability
20851| [77137] Oracle MySQL Server CVE-2015-4861 Remote Security Vulnerability
20852| [77136] Oracle MySQL Server CVE-2015-4895 Remote Security Vulnerability
20853| [77134] Oracle MySQL Server CVE-2015-4816 Remote Security Vulnerability
20854| [77132] Oracle MySQL Server CVE-2015-4866 Remote Security Vulnerability
20855| [77015] Oracle MySQL Multiple Buffer Overflow Vulnerabilities
20856| [75849] Oracle MySQL Server CVE-2015-4752 Remote Security Vulnerability
20857| [75844] Oracle MySQL Server CVE-2015-4767 Remote Security Vulnerability
20858| [75837] Oracle MySQL Server CVE-2015-2620 Remote Security Vulnerability
20859| [75835] Oracle MySQL Server CVE-2015-4771 Remote Security Vulnerability
20860| [75830] Oracle MySQL Server CVE-2015-2643 Remote Security Vulnerability
20861| [75822] Oracle MySQL Server CVE-2015-2648 Remote Security Vulnerability
20862| [75815] Oracle MySQL Server CVE-2015-2641 Remote Security Vulnerability
20863| [75813] Oracle MySQL Server CVE-2015-2661 Local Security Server Vulnerability
20864| [75802] Oracle MySQL Server CVE-2015-4737 Remote Security Vulnerability
20865| [75785] Oracle MySQL Server CVE-2015-4756 Remote Security Vulnerability
20866| [75781] Oracle MySQL Server CVE-2015-4772 Remote Security Vulnerability
20867| [75774] Oracle MySQL Server CVE-2015-2617 Remote Security Vulnerability
20868| [75770] Oracle MySQL Server CVE-2015-4761 Remote Security Vulnerability
20869| [75762] Oracle MySQL Server CVE-2015-2611 Remote Security Vulnerability
20870| [75760] Oracle MySQL Server CVE-2015-2639 Remote Security Vulnerability
20871| [75759] Oracle MySQL Server CVE-2015-4757 Remote Security Vulnerability
20872| [75753] Oracle MySQL Server CVE-2015-4769 Remote Security Vulnerability
20873| [75751] Oracle MySQL Server CVE-2015-2582 Remote Security Vulnerability
20874| [75397] MySql Lite Administrator Multiple Cross Site Scripting Vulnerabilities
20875| [75394] WordPress wp-instance-rename Plugin 'mysqldump_download.php' Arbitrary File Download Vulnerability
20876| [74695] Tiny MySQL 'tinymy.php' Cross Site Scripting Vulnerability
20877| [74398] Oracle MySQL CVE-2015-3152 SSL Certificate Validation Security Bypass Vulnerability
20878| [74137] Oracle MySQL Utilities CVE-2015-2576 Local Security Vulnerability
20879| [74133] Oracle MySQL Server CVE-2015-0498 Remote Security Vulnerability
20880| [74130] Oracle MySQL Server CVE-2015-0511 Remote Security Vulnerability
20881| [74126] Oracle MySQL Server CVE-2015-2566 Remote Security Vulnerability
20882| [74123] Oracle MySQL Server CVE-2015-2567 Remote Security Vulnerability
20883| [74121] Oracle MySQL Server CVE-2015-0507 Remote Security Vulnerability
20884| [74120] Oracle MySQL Server CVE-2015-0506 Remote Security Vulnerability
20885| [74115] Oracle MySQL Server CVE-2015-0499 Remote Security Vulnerability
20886| [74112] Oracle MySQL Server CVE-2015-0505 Remote Security Vulnerability
20887| [74110] Oracle MySQL Server CVE-2015-0405 Remote Security Vulnerability
20888| [74103] Oracle MySQL Server CVE-2015-0441 Remote Security Vulnerability
20889| [74102] Oracle MySQL Server CVE-2015-0503 Remote Security Vulnerability
20890| [74098] Oracle MySQL Server CVE-2015-0438 Remote Security Vulnerability
20891| [74095] Oracle MySQL Server CVE-2015-2571 Remote Security Vulnerability
20892| [74091] Oracle MySQL Server CVE-2015-0423 Remote Security Vulnerability
20893| [74089] Oracle MySQL Server CVE-2015-0433 Remote Security Vulnerability
20894| [74086] Oracle MySQL Server CVE-2015-0508 Remote Security Vulnerability
20895| [74085] Oracle MySQL Server CVE-2015-0439 Remote Security Vulnerability
20896| [74081] Oracle MySQL Server CVE-2015-0500 Remote Security Vulnerability
20897| [74078] Oracle MySQL Server CVE-2015-2573 Remote Security Vulnerability
20898| [74075] Oracle MySQL Connectors CVE-2015-2575 Remote Security Vulnerability
20899| [74073] Oracle MySQL Server CVE-2015-2568 Remote Security Vulnerability
20900| [74070] Oracle MySQL Server CVE-2015-0501 Remote Security Vulnerability
20901| [72728] RubyGems xaviershay-dm-rails 'storage.rb' MySQL Credential Information Disclosure Vulnerability
20902| [72229] Oracle MySQL Server CVE-2015-0385 Remote Security Vulnerability
20903| [72227] Oracle MySQL Server CVE-2015-0374 Remote Security Vulnerability
20904| [72223] Oracle MySQL Server CVE-2015-0409 Remote Security Vulnerability
20905| [72217] Oracle MySQL Server CVE-2015-0432 Remote Security Vulnerability
20906| [72214] Oracle MySQL Server CVE-2015-0381 Remote Security Vulnerability
20907| [72210] Oracle MySQL Server CVE-2014-6568 Remote Security Vulnerability
20908| [72205] Oracle MySQL Server CVE-2015-0391 Remote Security Vulnerability
20909| [72200] Oracle MySQL Server CVE-2015-0382 Remote Security Vulnerability
20910| [72191] Oracle MySQL Server CVE-2015-0411 Remote Security Vulnerability
20911| [70550] Oracle MySQL Server CVE-2014-6507 Remote Security Vulnerability
20912| [70540] RETIRED: Oracle MySQL Server CVE-2012-5615 Remote Security Vulnerability
20913| [70532] Oracle MySQL Server CVE-2014-6463 Remote Security Vulnerability
20914| [70530] Oracle MySQL Server CVE-2014-6555 Remote Security Vulnerability
20915| [70525] Oracle MySQL Server CVE-2014-6489 Remote Security Vulnerability
20916| [70517] Oracle MySQL Server CVE-2014-4287 Remote Security Vulnerability
20917| [70516] Oracle MySQL Server CVE-2014-6505 Remote Security Vulnerability
20918| [70511] Oracle MySQL Server CVE-2014-6564 Remote Security Vulnerability
20919| [70510] Oracle MySQL Server CVE-2014-6520 Remote Security Vulnerability
20920| [70497] Oracle MySQL Server CVE-2014-6494 Remote Security Vulnerability
20921| [70496] Oracle MySQL Server CVE-2014-6495 Remote Security Vulnerability
20922| [70489] Oracle MySQL Server CVE-2014-6478 Remote Security Vulnerability
20923| [70487] Oracle MySQL Server CVE-2014-6559 Remote Security Vulnerability
20924| [70486] Oracle MySQL Server CVE-2014-6530 Remote Security Vulnerability
20925| [70478] Oracle MySQL Server CVE-2014-6500 Remote Security Vulnerability
20926| [70469] Oracle MySQL Server CVE-2014-6496 Remote Security Vulnerability
20927| [70462] Oracle MySQL Server CVE-2014-6551 Local Security Vulnerability
20928| [70455] Oracle MySQL Server CVE-2014-6484 Remote Security Vulnerability
20929| [70451] Oracle MySQL Server CVE-2014-6464 Remote Security Vulnerability
20930| [70448] Oracle MySQL Server CVE-2014-6474 Remote Security Vulnerability
20931| [70446] Oracle MySQL Server CVE-2014-6469 Remote Security Vulnerability
20932| [70444] Oracle MySQL Server CVE-2014-6491 Remote Security Vulnerability
20933| [69743] Oracle MySQL Client yaSSL Certificate Decode Buffer Overflow Vulnerability
20934| [69732] MySQL MyISAM Insecure Temporary File Creation Vulnerability
20935| [68736] RubyGems lean-ruport MySQL Credential Local Information Disclosure Vulnerability
20936| [68607] Oracle MySQL Server CVE-2014-4214 Remote Security Vulnerability
20937| [68602] Oracle MySQL Server CVE-2014-4240 Local Security Vulnerability
20938| [68598] Oracle MySQL Server CVE-2014-4233 Remote Security Vulnerability
20939| [68593] Oracle MySQL Server CVE-2014-4207 Remote Security Vulnerability
20940| [68587] Oracle MySQL Server CVE-2014-4238 Remote Security Vulnerability
20941| [68579] Oracle MySQL Server CVE-2014-2494 Remote Security Vulnerability
20942| [68573] Oracle MySQL Server CVE-2014-4260 Remote Security Vulnerability
20943| [68564] Oracle MySQL Server CVE-2014-4258 Remote Security Vulnerability
20944| [66896] Oracle MySQL Server CVE-2014-2436 Remote Security Vulnerability
20945| [66890] Oracle MySQL Server CVE-2014-2431 Remote Security Vulnerability
20946| [66885] Oracle MySQL Server CVE-2014-2444 Remote Security Vulnerability
20947| [66880] Oracle MySQL Server CVE-2014-2419 Remote Security Vulnerability
20948| [66872] Oracle MySQL Server CVE-2014-2434 Remote Security Vulnerability
20949| [66863] Oracle MySQL Server CVE-2014-2450 Remote Security Vulnerability
20950| [66858] Oracle MySQL Server CVE-2014-2430 Remote Security Vulnerability
20951| [66853] Oracle MySQL Server CVE-2014-2435 Remote Security Vulnerability
20952| [66850] Oracle MySQL Client CVE-2014-2440 Remote Security Vulnerability
20953| [66846] Oracle MySQL Server CVE-2014-2438 Remote Security Vulnerability
20954| [66835] Oracle MySQL Server CVE-2014-0384 Remote Security Vulnerability
20955| [66828] Oracle MySQL Server CVE-2014-2451 Remote Security Vulnerability
20956| [66823] Oracle MySQL Server CVE-2014-2442 Remote Security Vulnerability
20957| [66153] lighttpd 'mod_mysql_vhost.c' SQL Injection Vulnerability
20958| [65890] InterWorx MySQL Password Information Disclosure Vulnerability
20959| [65621] Percona Toolkit for MySQL Automatic Version Check Information Disclosure Vulnerability
20960| [65298] Oracle MySQL Client 'main()' Function Buffer Overflow Vulnerability
20961| [64908] Oracle MySQL Server CVE-2014-0402 Remote Security Vulnerability
20962| [64904] Oracle MySQL Server CVE-2014-0386 Remote Security Vulnerability
20963| [64898] Oracle MySQL Server CVE-2014-0401 Remote Security Vulnerability
20964| [64897] Oracle MySQL Server CVE-2014-0431 Remote Security Vulnerability
20965| [64896] Oracle MySQL Server CVE-2013-5908 Remote Security Vulnerability
20966| [64895] Oracle MySQL Server CVE-2014-0433 Remote Security Vulnerability
20967| [64893] Oracle MySQL Server CVE-2014-0430 Remote Security Vulnerability
20968| [64891] Oracle MySQL Server CVE-2013-5891 Remote Security Vulnerability
20969| [64888] Oracle MySQL Server CVE-2014-0420 Remote Security Vulnerability
20970| [64885] Oracle MySQL Server CVE-2013-5881 Remote Security Vulnerability
20971| [64880] Oracle MySQL Server CVE-2014-0412 Remote Security Vulnerability
20972| [64877] Oracle MySQL Server CVE-2014-0393 Remote Security Vulnerability
20973| [64873] Oracle MySQL Server CVE-2013-5894 Remote Security Vulnerability
20974| [64868] Oracle MySQL Server CVE-2014-0427 Remote Security Vulnerability
20975| [64864] Oracle MySQL Server CVE-2013-5860 Remote Security Vulnerability
20976| [64854] Oracle MySQL Server CVE-2013-5882 Remote Security Vulnerability
20977| [64849] Oracle MySQL Server CVE-2014-0437 Remote Security Vulnerability
20978| [64731] CSP MySQL User Manager 'login.php' Script SQL Injection Vulnerability
20979| [64630] Zen Cart 'mysql_zencart.sql' Information Disclosure Vulnerability
20980| [63125] Oracle MySQL Server CVE-2012-2750 Remote Security Vulnerability
20981| [63119] Oracle MySQL Server CVE-2013-5770 Remote Security Vulnerability
20982| [63116] Oracle MySQL Server CVE-2013-5793 Remote Security Vulnerability
20983| [63113] Oracle MySQL Server CVE-2013-5767 Remote Security Vulnerability
20984| [63109] Oracle MySQL Server CVE-2013-3839 Remote Security Vulnerability
20985| [63107] Oracle MySQL Server CVE-2013-5786 Remote Security Vulnerability
20986| [63105] Oracle MySQL Server CVE-2013-5807 Remote Security Vulnerability
20987| [62358] Oracle MySQL CVE-2005-2572 Remote Code Execution Vulnerability
20988| [61274] Oracle MySQL Server CVE-2013-3798 Remote Security Vulnerability
20989| [61272] Oracle MySQL Server CVE-2013-3809 Remote Security Vulnerability
20990| [61269] Oracle MySQL Server CVE-2013-3801 Remote Security Vulnerability
20991| [61264] Oracle MySQL Server CVE-2013-3793 Remote Security Vulnerability
20992| [61260] Oracle MySQL Server CVE-2013-3804 Remote Security Vulnerability
20993| [61256] Oracle MySQL Server CVE-2013-3805 Remote Security Vulnerability
20994| [61252] Oracle MySQL Server CVE-2013-3811 Remote Security Vulnerability
20995| [61249] Oracle MySQL Server CVE-2013-3812 Remote Security Vulnerability
20996| [61244] Oracle MySQL Server CVE-2013-3802 Remote Security Vulnerability
20997| [61241] Oracle MySQL Server CVE-2013-3795 Remote Security Vulnerability
20998| [61238] Oracle MySQL Server CVE-2013-3807 Remote Security Vulnerability
20999| [61235] Oracle MySQL Server CVE-2013-3806 Remote Security Vulnerability
21000| [61233] Oracle MySQL Server CVE-2013-3796 Remote Security Vulnerability
21001| [61227] Oracle MySQL Server CVE-2013-3808 Remote Security Vulnerability
21002| [61222] Oracle MySQL Server CVE-2013-3794 Remote Security Vulnerability
21003| [61214] Oracle MySQL Server CVE-2013-3810 Remote Security Vulnerability
21004| [61210] Oracle MySQL Server CVE-2013-3783 Remote Security Vulnerability
21005| [60424] Debian mysql-server CVE-2013-2162 Insecure File Creation Vulnerability
21006| [60001] Wireshark MySQL Dissector Denial of Service Vulnerability
21007| [59242] Oracle MySQL CVE-2013-2391 Local MySQL Server Vulnerability
21008| [59239] Oracle MySQL CVE-2013-1502 Local MySQL Server Vulnerability
21009| [59237] Oracle MySQL CVE-2013-1506 Remote MySQL Server Vulnerability
21010| [59232] Oracle MySQL CVE-2013-1567 Remote MySQL Server Vulnerability
21011| [59229] Oracle MySQL Server CVE-2013-1544 Remote Security Vulnerability
21012| [59227] Oracle MySQL CVE-2013-2376 Remote MySQL Server Vulnerability
21013| [59225] Oracle MySQL CVE-2013-1523 Remote MySQL Server Vulnerability
21014| [59224] Oracle MySQL Server CVE-2013-2392 Remote Security Vulnerability
21015| [59223] Oracle MySQL Server CVE-2013-1548 Remote Security Vulnerability
21016| [59222] RETIRED: Oracle MySQL CVE-2012-5614 Remote MySQL Server Vulnerability
21017| [59218] Oracle MySQL Server CVE-2013-1512 Remote Security Vulnerability
21018| [59217] Oracle MySQL CVE-2013-1526 Remote MySQL Server Vulnerability
21019| [59216] Oracle MySQL CVE-2013-1570 Remote MySQL Server Vulnerability
21020| [59215] Oracle MySQL Server CVE-2013-2381 Remote Security Vulnerability
21021| [59211] Oracle MySQL Server CVE-2013-1532 Remote Security Vulnerability
21022| [59210] Oracle MySQL CVE-2013-1555 Remote MySQL Server Vulnerability
21023| [59209] Oracle MySQL CVE-2013-2375 Remote MySQL Server Vulnerability
21024| [59207] Oracle MySQL Server CVE-2013-2389 Remote Security Vulnerability
21025| [59205] Oracle MySQL Server CVE-2013-1566 Remote Security Vulnerability
21026| [59202] Oracle MySQL CVE-2013-1531 Remote MySQL Server Vulnerability
21027| [59201] Oracle MySQL Server CVE-2013-1511 Remote Security Vulnerability
21028| [59196] Oracle MySQL CVE-2013-1552 Remote MySQL Server Vulnerability
21029| [59188] Oracle MySQL CVE-2013-2378 Remote MySQL Server Vulnerability
21030| [59180] Oracle MySQL CVE-2013-1521 Remote MySQL Server Vulnerability
21031| [59173] Oracle MySQL CVE-2013-2395 Remote MySQL Server Vulnerability
21032| [58511] MySQL and MariaDB Geometry Query Denial Of Service Vulnerability
21033| [57418] Oracle MySQL Server CVE-2013-0386 Remote Security Vulnerability
21034| [57417] Oracle MySQL Server CVE-2013-0389 Remote Security Vulnerability
21035| [57416] Oracle MySQL Server CVE-2013-0384 Remote Security Vulnerability
21036| [57415] Oracle MySQL Server CVE-2013-0371 Remote Security Vulnerability
21037| [57414] Oracle MySQL Server CVE-2012-0574 Remote Security Vulnerability
21038| [57412] Oracle MySQL Server CVE-2013-0385 Local Security Vulnerability
21039| [57411] Oracle MySQL Server CVE-2012-5060 Remote Security Vulnerability
21040| [57410] Oracle MySQL Server CVE-2012-1705 Remote Security Vulnerability
21041| [57408] Oracle MySQL Server CVE-2013-0367 Remote Security Vulnerability
21042| [57405] Oracle MySQL Server CVE-2013-0383 Remote Security Vulnerability
21043| [57400] Oracle MySQL Server CVE-2012-5096 Remote Security Vulnerability
21044| [57397] Oracle MySQL Server CVE-2013-0368 Remote Security Vulnerability
21045| [57391] Oracle MySQL Server CVE-2013-0375 Remote Security Vulnerability
21046| [57388] Oracle MySQL Server CVE-2012-1702 Remote Security Vulnerability
21047| [57385] Oracle MySQL Server CVE-2012-0572 Remote Security Vulnerability
21048| [57334] Oracle MySQL Server CVE-2012-0578 Remote Security Vulnerability
21049| [56837] Oracle MySQL and MariaDB CVE-2012-5627 Insecure Salt Generation Security Bypass Weakness
21050| [56791] Oracle MySQL Remote Code Execution Vulnerability
21051| [56776] Oracle MySQL CVE-2012-5614 Denial of Service Vulnerability
21052| [56772] Oracle MySQL Remote Code Execution Vulnerability
21053| [56771] Oracle MySQL Server Privilege Escalation Vulnerability
21054| [56769] Oracle MySQL and MariaDB 'acl_get()' Buffer Overflow Vulnerability
21055| [56768] Oracle MySQL Server Heap Overflow Vulnerability
21056| [56766] Oracle MySQL Server Username Enumeration Weakness
21057| [56041] Oracle MySQL Server CVE-2012-3173 Remote MySQL Security Vulnerability
21058| [56036] Oracle MySQL Server CVE-2012-3163 Remote MySQL Security Vulnerability
21059| [56028] Oracle MySQL Server CVE-2012-3166 Remote Security Vulnerability
21060| [56027] Oracle MySQL Server CVE-2012-3160 Local Security Vulnerability
21061| [56022] Oracle MySQL Server CVE-2012-3147 Remote Security Vulnerability
21062| [56021] Oracle MySQL Server CVE-2012-3197 Remote Security Vulnerability
21063| [56018] Oracle MySQL Server CVE-2012-3167 Remote Security Vulnerability
21064| [56017] Oracle MySQL Server CVE-2012-3158 Remote Security Vulnerability
21065| [56013] Oracle MySQL Server CVE-2012-3156 Remote Security Vulnerability
21066| [56008] Oracle MySQL Server CVE-2012-3144 Remote Security Vulnerability
21067| [56006] Oracle MySQL Server CVE-2012-3149 Remote Security Vulnerability
21068| [56005] Oracle MySQL Server CVE-2012-3177 Remote Security Vulnerability
21069| [56003] Oracle MySQL Server CVE-2012-3180 Remote Security Vulnerability
21070| [55990] Oracle MySQL Server CVE-2012-3150 Remote Security Vulnerability
21071| [55715] MySQL MyISAM Table Symbolic Link CVE-2012-4452 Local Privilege Escalation Vulnerability
21072| [55120] Oracle MySQL CVE-2012-2749 Denial Of Service Vulnerability
21073| [54551] Oracle MySQL Server CVE-2012-0540 Remote Security Vulnerability
21074| [54549] Oracle MySQL Server CVE-2012-1735 Remote Security Vulnerability
21075| [54547] Oracle MySQL Server CVE-2012-1689 Remote Security Vulnerability
21076| [54540] Oracle MySQL Server CVE-2012-1734 Remote Security Vulnerability
21077| [54526] Oracle MySQL Server CVE-2012-1757 Remote Security Vulnerability
21078| [54524] Oracle MySQL Server CVE-2012-1756 Remote Security Vulnerability
21079| [53922] RETIRED: MySQL and MariaDB 'sql/password.c' Authentication Bypass Vulnerability
21080| [53911] Oracle MySQL CVE-2012-2122 User Login Security Bypass Vulnerability
21081| [53310] MySQLDumper 'menu.php' Remote PHP Code Execution Vulnerability
21082| [53306] MySQLDumper Multiple Security Vulnerabilities
21083| [53074] Oracle MySQL CVE-2012-1690 Remote MySQL Server Vulnerability
21084| [53071] Oracle MySQL CVE-2012-1696 Remote MySQL Server Vulnerability
21085| [53067] Oracle MySQL CVE-2012-1688 Remote MySQL Server Vulnerability
21086| [53064] Oracle MySQL CVE-2012-1697 Remote MySQL Server Vulnerability
21087| [53061] Oracle MySQL CVE-2012-0583 Remote MySQL Server Vulnerability
21088| [53058] Oracle MySQL CVE-2012-1703 Remote MySQL Server Vulnerability
21089| [52931] Oracle MySQL Server Multiple Unspecified Security Vulnerabilities
21090| [52154] RETIRED: MySQL 5.5.20 Unspecified Remote Code Execution Vulnerability
21091| [51925] MySQL Unspecified Remote Code Execution Vulnerability
21092| [51526] Oracle MySQL CVE-2012-0075 Remote MySQL Server Vulnerability
21093| [51525] Oracle MySQL CVE-2012-0493 Remote Vulnerability
21094| [51524] Oracle MySQL Server CVE-2012-0490 Remote Security Vulnerability
21095| [51523] Oracle MySQL Server CVE-2012-0494 Local Security Vulnerability
21096| [51522] Oracle MySQL Server CVE-2012-0495 Remote Security Vulnerability
21097| [51521] Oracle MySQL Server CVE-2012-0117 Remote MySQL Server Vulnerability
21098| [51520] Oracle MySQL Server CVE-2012-0114 Local Security Vulnerability
21099| [51519] Oracle MySQL Server CVE-2012-0112 Remote MySQL Server Vulnerability
21100| [51518] Oracle MySQL Server CVE-2012-0491 Remote Security Vulnerability
21101| [51517] Oracle MySQL CVE-2012-0120 Remote Vulnerability
21102| [51516] Oracle MySQL Server CVE-2012-0492 Remote MySQL Server Vulnerability
21103| [51515] Oracle MySQL Server CVE-2012-0484 Remote Security Vulnerability
21104| [51514] Oracle MySQL Server CVE-2012-0486 Remote Security Vulnerability
21105| [51513] Oracle MySQL Server CVE-2012-0485 Remote Security Vulnerability
21106| [51512] Oracle MySQL CVE-2012-0119 Remote Vulnerability
21107| [51511] Oracle MySQL CVE-2012-0118 Remote MySQL Server Vulnerability
21108| [51510] Oracle MySQL Server CVE-2012-0489 Remote MySQL Server Vulnerability
21109| [51509] Oracle MySQL Server CVE-2012-0087 Remote Security Vulnerability
21110| [51508] Oracle MySQL CVE-2012-0116 Remote MySQL Server Vulnerability
21111| [51507] Oracle MySQL Server CVE-2012-0496 Remote Security Vulnerability
21112| [51506] Oracle MySQL Server CVE-2012-0488 Remote MySQL Server Vulnerability
21113| [51505] Oracle MySQL Server CVE-2012-0101 Remote Security Vulnerability
21114| [51504] Oracle MySQL CVE-2012-0115 Remote Vulnerability
21115| [51503] Oracle MySQL Server CVE-2012-0487 Remote MySQL Server Vulnerability
21116| [51502] Oracle MySQL Server CVE-2012-0102 Remote Security Vulnerability
21117| [51493] Oracle MySQL CVE-2011-2262 Remote MySQL Server Vulnerability
21118| [51488] Oracle MySQL CVE-2012-0113 Remote MySQL Server Vulnerability
21119| [50139] DBD::mysqlPP Unspecified SQL Injection Vulnerability
21120| [48466] MySQLDriverCS SQL Injection Vulnerability
21121| [47919] Zend Framework 'PDO_MySql' Security Bypass Vulnerability
21122| [47871] Oracle MySQL Prior to 5.1.52 Multiple Denial Of Service Vulnerabilities
21123| [47693] DirectAdmin 'mysql_backup' Folder Permissions Information Disclosure Vulnerability
21124| [46655] pywebdav MySQL Authentication Module SQL Injection Vulnerability
21125| [46456] MySQL Eventum 'full_name' Field HTML Injection Vulnerability
21126| [46380] MySQL Eventum Multiple HTML Injection Vulnerabilities
21127| [46056] PHP MySQLi Extension 'set_magic_quotes_runtime' Function Security-Bypass Weakness
21128| [43884] phpFK - PHP Forum Script ohne MySQL 'page_bottom.php' Local File Include Vulnerability
21129| [43677] Oracle MySQL Prior to 5.1.50 Privilege Escalation Vulnerability
21130| [43676] Oracle MySQL Prior to 5.1.51 Multiple Denial Of Service Vulnerabilities
21131| [42646] Oracle MySQL Prior to 5.1.49 'JOIN' Statement Denial Of Service Vulnerability
21132| [42643] Oracle MySQL Prior to 5.1.49 'DDL' Statements Denial Of Service Vulnerability
21133| [42638] Oracle MySQL Prior to 5.1.49 Malformed 'BINLOG' Arguments Denial Of Service Vulnerability
21134| [42633] Oracle MySQL 'HANDLER' interface Denial Of Service Vulnerability
21135| [42625] Oracle MySQL 'LOAD DATA INFILE' Denial Of Service Vulnerability
21136| [42599] Oracle MySQL 'EXPLAIN' Denial Of Service Vulnerability
21137| [42598] Oracle MySQL 'TEMPORARY InnoDB' Tables Denial Of Service Vulnerability
21138| [42596] Oracle MySQL Prior to 5.1.49 'WITH ROLLUP' Denial Of Service Vulnerability
21139| [42586] RETIRED: Oracle MySQL Prior to 5.1.49 Multiple Denial Of Service Vulnerabilities
21140| [42417] Zmanda Recovery Manager for MySQL Multiple Local Privilege Escalation Vulnerabilities
21141| [41440] phpFK - PHP Forum Script ohne MySQL 'upload.php' Arbitrary File Upload Vulnerability
21142| [41198] Oracle MySQL 'ALTER DATABASE' Remote Denial Of Service Vulnerability
21143| [40537] MySQL Enterprise Monitor Multiple Unspecified Cross Site Request Forgery Vulnerabilities
21144| [40506] RETIRED: phpGraphy 'mysql_cleanup.php' Remote File Include Vulnerability
21145| [40461] PHP Mysqlnd Extension Information Disclosure and Multiple Buffer Overflow Vulnerabilities
21146| [40257] Oracle MySQL DROP TABLE MyISAM Symbolic Link Local Security Bypass Vulnerability
21147| [40109] Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability
21148| [40106] Oracle MySQL 'COM_FIELD_LIST' Command Buffer Overflow Vulnerability
21149| [40100] Oracle MySQL Malformed Packet Handling Remote Denial of Service Vulnerability
21150| [40045] Advanced Poll 'mysql_host' Parameter Cross Site Scripting Vulnerability
21151| [39918] FlexAppsStore Flex MySQL Connector Unauthorized Access Vulnerability
21152| [39543] MySQL UNINSTALL PLUGIN Security Bypass Vulnerability
21153| [38642] Timeclock Software 'mysqldump' Local Information Disclosure Vulnerability
21154| [38043] MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
21155| [37943] MySQL with yaSSL SSL Certificate Handling Remote Stack Buffer Overflow Vulnerability
21156| [37770] TYPO3 kiddog_mysqldumper Unspecified Information Disclosure Vulnerability
21157| [37640] MySQL 5.0.51a Unspecified Remote Code Execution Vulnerability
21158| [37297] MySQL Multiple Remote Denial Of Service Vulnerabilities
21159| [37076] MySQL OpenSSL Server Certificate yaSSL Security Bypass Vulnerability
21160| [37075] MySQL MyISAM Table Symbolic Link Local Privilege Escalation Vulnerability
21161| [36242] MySQL 5.x Unspecified Buffer Overflow Vulnerability
21162| [35858] MySQL Connector/J Unicode Character String SQL Injection Vulnerability
21163| [35609] MySQL 'sql_parse.cc' Multiple Format String Vulnerabilities
21164| [35514] MySQL Connector/Net SSL Certificate Validation Security Bypass Vulnerability
21165| [33972] MySQL XPath Expression Remote Denial Of Service Vulnerability
21166| [33392] 'mod_auth_mysql' Package Multibyte Character Encoding SQL Injection Vulnerability
21167| [32978] MySQL Calendar 'username' Parameter SQL Injection Vulnerability
21168| [32914] MySQL Calendar Cookie Authentication Bypass Vulnerability
21169| [32157] MySQL Quick Admin 'actions.php' Local File Include Vulnerability
21170| [32000] Agora 'MysqlfinderAdmin.php' Remote File Include Vulnerability
21171| [31517] MySQL Quick Admin 'index.php' Local File Include Vulnerability
21172| [31486] MySQL Command Line Client HTML Special Characters HTML Injection Vulnerability
21173| [31425] PromoteWeb MySQL 'go.php' SQL Injection Vulnerability
21174| [31081] MySQL Empty Binary String Literal Remote Denial Of Service Vulnerability
21175| [30835] mysql-lists Unspecified Cross Site Scripting Vulnerability
21176| [30529] Keld PHP-MySQL News Script 'login.php' SQL Injection Vulnerability
21177| [30383] phpwebnews-mysql Multiple SQL Injection Vulnerabilities
21178| [29106] MySQL MyISAM Table Privileges Secuity Bypass Vulnerability
21179| [29048] GEDCOM_to_MySQL2 Multiple Cross-Site Scripting Vulnerabilities
21180| [28351] MySQL INFORMATION_SCHEMA Remote Denial Of Service Vulnerability
21181| [27938] DSPAM Debian 'libdspam7-drv-mysql' Cron Job MySQL Calls Local Information Disclosure Vulnerability
21182| [27202] PHP Webquest MySQL Credentials Information Disclosure Vulnerability
21183| [27032] PHP MySQL Open Source Help Desk 'form.php' Code Injection Vulnerability
21184| [26947] MySQL Server Unspecified Remote Arbitrary Command Execution Vulnerability
21185| [26832] MySQL Server Privilege Escalation And Denial Of Service Vulnerabilities
21186| [26829] aurora framework Db_mysql.LIB SQL Injection Vulnerability
21187| [26765] MySQL Server RENAME TABLE System Table Overwrite Vulnerability
21188| [26353] MySQL Server InnoDB CONVERT_SEARCH_MODE_TO_INNOBASE Function Denial Of Service Vulnerability
21189| [26304] AdventNet EventLog Analyzer Insecure Default MySQL Password Unauthorized Access Vulnerability
21190| [26156] Bacula MySQL Password Information Disclosure Vulnerability
21191| [26095] Asterisk 'asterisk-addons' CDR_ADDON_MYSQL Module SQL Injection Vulnerability
21192| [25017] MySQL Access Validation and Denial of Service Vulnerabilities
21193| [24759] MySQLDumper Apache Access Control Authentication Bypass Vulnerability
21194| [24016] MySQL Rename Table Function Access Validation Vulnerability
21195| [24011] MySQL Security Invoker Privilege Escalation Vulnerability
21196| [24008] MySQL Alter Table Function Information Disclosure Vulnerability
21197| [23911] MySQL IF Query Handling Remote Denial Of Service Vulnerability
21198| [23176] Eve-Nuke Forums MySQL.PHP Remote File Include Vulnerability
21199| [22941] MySQL Commander Remote File Include Vulnerability
21200| [22900] MySQL Single Row SubSelect Remote Denial Of Service Vulnerability
21201| [22474] CPanel PassWDMySQL Cross-Site Scripting Vulnerability
21202| [22431] MySQLNewsEngine Affichearticles.PHP3 Remote File Include Vulnerability
21203| [20460] MySQLDumper SQL.PHP Cross-Site Scripting Vulnerability
21204| [20222] PABugs Class.MySQL.PHP Remote File Include Vulnerability
21205| [20165] ZoomStats MySQL.PHP Remote File Include Vulnerability
21206| [19794] MySQL Multiupdate and Subselects Denial Of Service Vulnerability
21207| [19559] MySQL Privilege Elevation and Security Bypass Vulnerabilities
21208| [19279] MySQL MERGE Privilege Revoke Bypass Vulnerability
21209| [19240] Banex PHP MySQL Banner Exchange Multiple Remote Vulnerabilities
21210| [19032] MySQL Server Date_Format Denial Of Service Vulnerability
21211| [18717] PHP/MySQL Classifieds AddAsset1.PHP Multiple HTML Injection Vulnerabilities
21212| [18439] MySQL Server Str_To_Date Remote Denial Of Service Vulnerability
21213| [18219] MySQL Mysql_real_escape Function SQL Injection Vulnerability
21214| [17780] MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
21215| [17224] Cholod MySQL Based Message Board Mb.CGI SQL Injection Vulnerability
21216| [17223] Cholod MySQL Based Message Board Multiple HTML Injection Vulnerabilities
21217| [17147] Woltlab Burning Board Class_DB_MySQL.PHP Cross-Site Scripting Vulnerability
21218| [16850] MySQL Query Logging Bypass Vulnerability
21219| [16620] PHP/MYSQL Timesheet Multiple SQL Injection Vulnerabilities
21220| [16564] PAM-MySQL Code Execution And Denial Of Service Vulnerabilities
21221| [16219] PHP MySQLI Error Logging Remote Format String Vulnerability
21222| [16145] PHP MySQL_Connect Remote Buffer Overflow Vulnerability
21223| [15852] MySQL Auction Search Module Cross-Site Scripting Vulnerability
21224| [14509] MySQL User-Defined Function Buffer Overflow Vulnerability
21225| [14437] MySQL Eventum Multiple SQL Injection Vulnerabilities
21226| [14436] MySQL Eventum Multiple Cross-Site Scripting Vulnerabilities
21227| [13913] xMySQLadmin Insecure Temporary File Creation Vulnerability
21228| [13660] MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
21229| [13378] MySQL MaxDB WebDAV IF Parameter Remote Buffer Overflow Vulnerability
21230| [13369] MySQL MaxDB WebDAV Lock Token Remote Buffer Overflow Vulnerability
21231| [13368] MySQL MaxDB HTTP GET Request Remote Buffer Overflow Vulnerability
21232| [12805] MySQL MaxDB WebAgent Input Validation Multiple Remote Denial Of Service Vulnerabilities
21233| [12781] MySQL AB MySQL Multiple Remote Vulnerabilities
21234| [12313] MySQL MaxDB WebAgent Remote Denial of Service Vulnerabilities
21235| [12277] MySQL Database MySQLAccess Local Insecure Temporary File Creation Vulnerability
21236| [12265] MySQL MaxDB WebAgent WebSQL Password Parameter Remote Buffer Overflow Vulnerability
21237| [12133] MySQL Eventum Multiple Input Validation Vulnerabilities
21238| [11844] MySQL MaxDB WebDav Handler Overwrite Header Remote Buffer Overflow Vulnerability
21239| [11843] MySQL MaxDB WAHTTP Server Remote Denial Of Service Vulnerability
21240| [11435] MySQL Database Unauthorized GRANT Privilege Vulnerability
21241| [11432] MySQL Remote FULLTEXT Search Denial Of Service Vulnerability
21242| [11357] MySQL Multiple Local Vulnerabilities
21243| [11346] MySQL MaxDB WebDBM Server Name Denial of Service Vulnerability
21244| [11291] MySQL Unspecified Insecure Temporary File Creation Vulnerability
21245| [11261] MySQL Bounded Parameter Statement Execution Remote Buffer Overflow Vulnerability
21246| [11234] AllWebScripts MySQLGuest HTML Injection Vulnerability
21247| [10986] Ben Yacoub Hatem MySQL Backup Pro Undisclosed 'getbackup()' Vulnerability
21248| [10981] MySQL Mysql_real_connect Function Potential Remote Buffer Overflow Vulnerability
21249| [10969] MySQL Mysqlhotcopy Script Insecure Temporary File Creation Vulnerability
21250| [10655] MySQL Password Length Remote Buffer Overflow Vulnerability
21251| [10654] MySQL Authentication Bypass Vulnerability
21252| [10142] MySQL MYSQLD_Multi Insecure Temporary File Creation Vulnerability
21253| [9976] MySQL Aborted Bug Report Insecure Temporary File Creation Vulnerability
21254| [8796] MySQL Multiple Vulnerabilities
21255| [8590] MySQL Password Handler Buffer Overflow Vulnerability
21256| [8245] MySQL AB ODBC Driver Plain Text Password Vulnerability
21257| [7887] MySQL libmysqlclient Library mysql_real_connect() Buffer Overrun Vulnerability
21258| [7500] MySQL Weak Password Encryption Vulnerability
21259| [7052] MySQL mysqld Privilege Escalation Vulnerability
21260| [7041] MySQL Control Center Insecure Default File Permission Vulnerability
21261| [6718] MySQL Double Free Heap Corruption Vulnerability
21262| [6375] MySQL COM_CHANGE_USER Password Memory Corruption Vulnerability
21263| [6374] MySQL libmysqlclient Library Read_One_Row Buffer Overflow Vulnerability
21264| [6373] MySQL COM_CHANGE_USER Password Length Account Compromise Vulnerability
21265| [6370] MySQL libmysqlclient Library Read_Rows Buffer Overflow Vulnerability
21266| [6368] MySQL COM_TABLE_DUMP Memory Corruption Vulnerability
21267| [5948] PHPRank MySQL Error Unauthorized Access Vulnerability
21268| [5853] MySQL DataDir Parameter Local Buffer Overflow Vulnerability
21269| [5513] MySQL Logging Not Enabled Weak Default Configuration Vulnerability
21270| [5511] MySQL Bind Address Not Enabled Weak Default Configuration Vulnerability
21271| [5503] MySQL Null Root Password Weak Default Configuration Vulnerability
21272| [4409] Cyrus SASL LDAP+MySQL Authentication Patch SQL Command Execution Vulnerability
21273| [4026] PHP MySQL Safe_Mode Filesystem Circumvention Vulnerability
21274| [3907] Conectiva Linux MySQL World Readable Log File Vulnerability
21275| [3381] WinMySQLadmin Plain Text Password Storage Vulnerability
21276| [3284] Inter7 vpopmail MySQL Authentication Data Recovery Vulnerability
21277| [3255] Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
21278| [2522] MySQL Root Operation Symbolic Link File Overwriting Vulnerability
21279| [2380] MySQL SHOW GRANTS Pasword Hash Disclosure Vulnerability
21280| [2262] Mysql Local Buffer Overflow Vulnerability
21281| [1850] pam_mysql Authentication Input Validation Vulnerability
21282| [1826] MySQL Authentication Algorithm Vulnerability
21283| [1557] PCCS Mysql Database Admin Tool Username/Password Exposure Vulnerability
21284| [975] MySQL Unauthenticated Remote Access Vulnerability
21285| [926] MySQL GRANT Global Password Changing Vulnerability
21286|
21287| IBM X-Force - https://exchange.xforce.ibmcloud.com:
21288| [85724] Oracle MySQL Server XA Transactions denial of service
21289| [85723] Oracle MySQL Server Server Replication denial of service
21290| [85722] Oracle MySQL Server InnoDB denial of service
21291| [85721] Oracle MySQL Server Server Privileges unspecified
21292| [85720] Oracle MySQL Server Server Partition denial of service
21293| [85719] Oracle MySQL Server Server Parser denial of service
21294| [85718] Oracle MySQL Server Server Options denial of service
21295| [85717] Oracle MySQL Server Server Options denial of service
21296| [85716] Oracle MySQL Server Server Optimizer denial of service
21297| [85715] Oracle MySQL Server Server Optimizer denial of service
21298| [85714] Oracle MySQL Server Prepared Statements denial of service
21299| [85713] Oracle MySQL Server InnoDB denial of service
21300| [85712] Oracle MySQL Server Full Text Search denial of service
21301| [85711] Oracle MySQL Server Data Manipulation Language denial of service
21302| [85710] Oracle MySQL Server Data Manipulation Language denial of service
21303| [85709] Oracle MySQL Server Audit Log unspecified
21304| [85708] Oracle MySQL Server MemCached unspecified
21305| [84846] Debian mysql-server package information disclosure
21306| [84375] Wireshark MySQL dissector denial of service
21307| [83554] Oracle MySQL Server Server Partition denial of service
21308| [83553] Oracle MySQL Server Server Locking denial of service
21309| [83552] Oracle MySQL Server Server Install unspecified
21310| [83551] Oracle MySQL Server Server Types denial of service
21311| [83550] Oracle MySQL Server Server Privileges unspecified
21312| [83549] Oracle MySQL Server InnoDB denial of service
21313| [83548] Oracle MySQL Server InnoDB denial of service
21314| [83547] Oracle MySQL Server Data Manipulation Language denial of service
21315| [83546] Oracle MySQL Server Stored Procedure denial of service
21316| [83545] Oracle MySQL Server Server Replication denial of service
21317| [83544] Oracle MySQL Server Server Partition denial of service
21318| [83543] Oracle MySQL Server Server Optimizer denial of service
21319| [83542] Oracle MySQL Server InnoDB denial of service
21320| [83541] Oracle MySQL Server Information Schema denial of service
21321| [83540] Oracle MySQL Server Data Manipulation Language denial of service
21322| [83539] Oracle MySQL Server Data Manipulation Language denial of service
21323| [83538] Oracle MySQL Server Server Optimizer unspecified
21324| [83537] Oracle MySQL Server MemCached denial of service
21325| [83536] Oracle MySQL Server Server Privileges unspecified
21326| [83535] Oracle MySQL Server Server Privileges unspecified
21327| [83534] Oracle MySQL Server Server unspecified
21328| [83533] Oracle MySQL Server Information Schema unspecified
21329| [83532] Oracle MySQL Server Server Locking unspecified
21330| [83531] Oracle MySQL Server Data Manipulation Language denial of service
21331| [83388] MySQL administrative login attempt detected
21332| [82963] Mambo MySQL database information disclosure
21333| [82946] Oracle MySQL buffer overflow
21334| [82945] Oracle MySQL buffer overflow
21335| [82895] Oracle MySQL and MariaDB geometry queries denial of service
21336| [81577] MySQL2JSON extension for TYPO3 unspecified SQL injection
21337| [81325] Oracle MySQL Server Server Privileges denial of service
21338| [81324] Oracle MySQL Server Server Partition denial of service
21339| [81323] Oracle MySQL Server Server Optimizer denial of service
21340| [81322] Oracle MySQL Server Server Optimizer denial of service
21341| [81321] Oracle MySQL Server Server denial of service
21342| [81320] Oracle MySQL Server MyISAM denial of service
21343| [81319] Oracle MySQL Server InnoDB denial of service
21344| [81318] Oracle MySQL Server InnoDB denial of service
21345| [81317] Oracle MySQL Server Server Locking denial of service
21346| [81316] Oracle MySQL Server Server denial of service
21347| [81315] Oracle MySQL Server Server Replication unspecified
21348| [81314] Oracle MySQL Server Server Replication unspecified
21349| [81313] Oracle MySQL Server Stored Procedure denial of service
21350| [81312] Oracle MySQL Server Server Optimizer denial of service
21351| [81311] Oracle MySQL Server Information Schema denial of service
21352| [81310] Oracle MySQL Server GIS Extension denial of service
21353| [80790] Oracle MySQL yaSSL buffer overflow
21354| [80553] Oracle MySQL and MariaDB salt security bypass
21355| [80443] Oracle MySQL Server unspecified code execution
21356| [80442] Oracle MySQL Server acl_get() buffer overflow
21357| [80440] Oracle MySQL Server table buffer overflow
21358| [80435] Oracle MySQL Server database privilege escalation
21359| [80434] Oracle MySQL Server COM_BINLOG_DUMP denial of service
21360| [80433] Oracle MySQL Server Stuxnet privilege escalation
21361| [80432] Oracle MySQL Server authentication information disclosure
21362| [79394] Oracle MySQL Server Server Installation information disclosure
21363| [79393] Oracle MySQL Server Server Replication denial of service
21364| [79392] Oracle MySQL Server Server Full Text Search denial of service
21365| [79391] Oracle MySQL Server Server denial of service
21366| [79390] Oracle MySQL Server Client information disclosure
21367| [79389] Oracle MySQL Server Server Optimizer denial of service
21368| [79388] Oracle MySQL Server Server Optimizer denial of service
21369| [79387] Oracle MySQL Server Server denial of service
21370| [79386] Oracle MySQL Server InnoDB Plugin denial of service
21371| [79385] Oracle MySQL Server InnoDB denial of service
21372| [79384] Oracle MySQL Server Client unspecified
21373| [79383] Oracle MySQL Server Server denial of service
21374| [79382] Oracle MySQL Server Protocol unspecified
21375| [79381] Oracle MySQL Server Information Schema unspecified
21376| [78954] SilverStripe MySQLDatabase.php information disclosure
21377| [78948] MySQL MyISAM table symlink
21378| [77865] MySQL unknown vuln
21379| [77864] MySQL sort order denial of service
21380| [77768] MySQLDumper refresh_dblist.php information disclosure
21381| [77177] MySQL Squid Access Report unspecified cross-site scripting
21382| [77065] Oracle MySQL Server Optimizer denial of service
21383| [77064] Oracle MySQL Server Optimizer denial of service
21384| [77063] Oracle MySQL Server denial of service
21385| [77062] Oracle MySQL InnoDB denial of service
21386| [77061] Oracle MySQL GIS Extension denial of service
21387| [77060] Oracle MySQL Server Optimizer denial of service
21388| [76189] MySQL unspecified error
21389| [76188] MySQL attempts security bypass
21390| [75287] MySQLDumper restore.php information disclosure
21391| [75286] MySQLDumper filemanagement.php directory traversal
21392| [75285] MySQLDumper main.php cross-site request forgery
21393| [75284] MySQLDumper install.php cross-site scripting
21394| [75283] MySQLDumper install.php file include
21395| [75282] MySQLDumper menu.php code execution
21396| [75022] Oracle MySQL Server Server Optimizer denial of service
21397| [75021] Oracle MySQL Server Server Optimizer denial of service
21398| [75020] Oracle MySQL Server Server DML denial of service
21399| [75019] Oracle MySQL Server Partition denial of service
21400| [75018] Oracle MySQL Server MyISAM denial of service
21401| [75017] Oracle MySQL Server Server Optimizer denial of service
21402| [74672] Oracle MySQL Server multiple unspecified
21403| [73092] MySQL unspecified code execution
21404| [72540] Oracle MySQL Server denial of service
21405| [72539] Oracle MySQL Server unspecified
21406| [72538] Oracle MySQL Server denial of service
21407| [72537] Oracle MySQL Server denial of service
21408| [72536] Oracle MySQL Server unspecified
21409| [72535] Oracle MySQL Server denial of service
21410| [72534] Oracle MySQL Server denial of service
21411| [72533] Oracle MySQL Server denial of service
21412| [72532] Oracle MySQL Server denial of service
21413| [72531] Oracle MySQL Server denial of service
21414| [72530] Oracle MySQL Server denial of service
21415| [72529] Oracle MySQL Server denial of service
21416| [72528] Oracle MySQL Server denial of service
21417| [72527] Oracle MySQL Server denial of service
21418| [72526] Oracle MySQL Server denial of service
21419| [72525] Oracle MySQL Server information disclosure
21420| [72524] Oracle MySQL Server denial of service
21421| [72523] Oracle MySQL Server denial of service
21422| [72522] Oracle MySQL Server denial of service
21423| [72521] Oracle MySQL Server denial of service
21424| [72520] Oracle MySQL Server denial of service
21425| [72519] Oracle MySQL Server denial of service
21426| [72518] Oracle MySQL Server unspecified
21427| [72517] Oracle MySQL Server unspecified
21428| [72516] Oracle MySQL Server unspecified
21429| [72515] Oracle MySQL Server denial of service
21430| [72514] Oracle MySQL Server unspecified
21431| [71965] MySQL port denial of service
21432| [70680] DBD::mysqlPP unspecified SQL injection
21433| [70370] TaskFreak! multi-mysql unspecified path disclosure
21434| [68799] mod_authnz_external module for Apache mysql-auth.pl SQL injection
21435| [68294] MySQLDriverCS statement.cs sql injection
21436| [68175] Prosody MySQL denial of service
21437| [67539] Zend Framework MySQL PDO security bypass
21438| [67254] DirectAdmin MySQL information disclosure
21439| [66567] Xoops mysql.sql information disclosure
21440| [65871] PyWebDAV MySQLAuthHandler class SQL injection
21441| [65543] MySQL Select Arbitrary data into a File
21442| [65529] MySQL Eventum full_name field cross-site scripting
21443| [65380] Oracle MySQL Eventum forgot_password.php cross-site scripting
21444| [65379] Oracle MySQL Eventum list.php cross-site scripting
21445| [65266] Accellion File Transfer Appliance MySQL default password
21446| [64878] MySQL Geometry denial of service
21447| [64877] MySQL EXPLAIN EXTENDED denial of service
21448| [64876] MySQL prepared statement denial of service
21449| [64845] MySQL extreme-value denial of service
21450| [64844] MySQL Gis_line_string::init_from_wkb denial of service
21451| [64843] MySQL user-variable denial of service
21452| [64842] MySQL view preparation denial of service
21453| [64841] MySQL prepared statement denial of service
21454| [64840] MySQL LONGBLOB denial of service
21455| [64839] MySQL invocations denial of service
21456| [64838] MySQL Gis_line_string::init_from_wkb denial of service
21457| [64689] MySQL dict0crea.c denial of service
21458| [64688] MySQL SET column denial of service
21459| [64687] MySQL BINLOG command denial of service
21460| [64686] MySQL InnoDB denial of service
21461| [64685] MySQL HANDLER interface denial of service
21462| [64684] MySQL Item_singlerow_subselect::store denial of service
21463| [64683] MySQL OK packet denial of service
21464| [63518] MySQL Query Browser GUI Tools information disclosure
21465| [63517] MySQL Administrator GUI Tools information disclosure
21466| [62272] MySQL PolyFromWKB() denial of service
21467| [62269] MySQL LIKE predicates denial of service
21468| [62268] MySQL joins denial of service
21469| [62267] MySQL GREATEST() or LEAST() denial of service
21470| [62266] MySQL GROUP_CONCAT() denial of service
21471| [62265] MySQL expression values denial of service
21472| [62264] MySQL temporary table denial of service
21473| [62263] MySQL LEAST() or GREATEST() denial of service
21474| [62262] MySQL replication privilege escalation
21475| [61739] MySQL WITH ROLLUP denial of service
21476| [61343] MySQL LOAD DATA INFILE denial of service
21477| [61342] MySQL EXPLAIN denial of service
21478| [61341] MySQL HANDLER denial of service
21479| [61340] MySQL BINLOG denial of service
21480| [61339] MySQL IN() or CASE denial of service
21481| [61338] MySQL SET denial of service
21482| [61337] MySQL DDL denial of service
21483| [61318] PHP mysqlnd_wireprotocol.c buffer overflow
21484| [61317] PHP php_mysqlnd_read_error_from_line buffer overflow
21485| [61316] PHP php_mysqlnd_auth_write buffer overflow
21486| [61274] MySQL TEMPORARY InnoDB denial of service
21487| [59905] MySQL ALTER DATABASE denial of service
21488| [59841] CMySQLite updateUser.php cross-site request forgery
21489| [59112] MySQL Enterprise Monitor unspecified cross-site request forgery
21490| [59075] PHP php_mysqlnd_auth_write() buffer overflow
21491| [59074] PHP php_mysqlnd_read_error_from_line() buffer overflow
21492| [59073] PHP php_mysqlnd_rset_header_read() buffer overflow
21493| [59072] PHP php_mysqlnd_ok_read() information disclosure
21494| [58842] MySQL DROP TABLE file deletion
21495| [58676] Template Shares MySQL information disclosure
21496| [58531] MySQL COM_FIELD_LIST buffer overflow
21497| [58530] MySQL packet denial of service
21498| [58529] MySQL COM_FIELD_LIST security bypass
21499| [58311] ClanSphere the captcha generator and MySQL driver SQL injection
21500| [57925] MySQL UNINSTALL PLUGIN security bypass
21501| [57006] Quicksilver Forums mysqldump information disclosure
21502| [56800] Employee Timeclock Software mysqldump information disclosure
21503| [56200] Flex MySQL Connector ActionScript SQL injection
21504| [55877] MySQL yaSSL buffer overflow
21505| [55622] kiddog_mysqldumper extension for TYPO3 information disclosure
21506| [55416] MySQL unspecified buffer overflow
21507| [55382] Ublog UblogMySQL.sql information disclosure
21508| [55251] PHP-MySQL-Quiz editquiz.php SQL injection
21509| [54597] MySQL sql_table.cc security bypass
21510| [54596] MySQL mysqld denial of service
21511| [54365] MySQL OpenSSL security bypass
21512| [54364] MySQL MyISAM table symlink
21513| [53950] The mysql-ocaml mysql_real_escape_string weak security
21514| [52978] Zmanda Recovery Manager for MySQL mysqlhotcopy privilege escalation
21515| [52977] Zmanda Recovery Manager for MySQL socket-server.pl command execution
21516| [52660] iScouter PHP Web Portal MySQL Password Retrieval
21517| [52220] aa33code mysql.inc information disclosure
21518| [52122] MySQL Connector/J unicode SQL injection
21519| [51614] MySQL dispatch_command() denial of service
21520| [51406] MySQL Connector/NET SSL spoofing
21521| [49202] MySQL UDF command execution
21522| [49050] MySQL XPath denial of service
21523| [48919] Cisco Application Networking Manager MySQL default account password
21524| [48163] libapache2-mod-auth-mysql module for Debian multibyte encoding SQL injection
21525| [47544] MySQL Calendar index.php SQL injection
21526| [47476] MySQL Calendar index.php nodstrumCalendarV2 security bypass
21527| [45649] MySQL MyISAM symlink security bypass
21528| [45648] MySQL MyISAM symlinks security bypass
21529| [45607] MySQL Quick Admin actions.php file include
21530| [45606] MySQL Quick Admin index.php file include
21531| [45590] MySQL command-line client cross-site scripting
21532| [45436] PromoteWeb MySQL go.php SQL injection
21533| [45042] MySQL empty bit-string literal denial of service
21534| [44662] mysql-lists unspecified cross-site scripting
21535| [42267] MySQL MyISAM security bypass
21536| [42211] GEDCOM_to_MySQL2 index.php, info.php and prenom.php cross-site scripting
21537| [42014] miniBB setup_mysql.php and setup_options.php SQL injection
21538| [40920] MySQL sql_select.cc denial of service
21539| [40734] MySQL Server BINLOG privilege escalation
21540| [40350] MySQL password information disclosure
21541| [39415] Debian GNU/Linux libdspam7-drv-mysql cron job password disclosure
21542| [39402] PHP LOCAL INFILE and MySQL extension security bypass
21543| [38999] aurora framework db_mysql.lib SQL injection
21544| [38990] MySQL federated engine denial of service
21545| [38989] MySQL DEFINER value privilege escalation
21546| [38988] MySQL DATA DIRECTORY and INDEX DIRECTORY privilege escalation
21547| [38964] MySQL RENAME TABLE symlink
21548| [38733] ManageEngine EventLog Analyzer MySQL default password
21549| [38284] MySQL ha_innodb.cc convert_search_mode_to_innobase() denial of service
21550| [38189] MySQL default root password
21551| [37235] Asterisk-Addons cdr_addon_mysql module SQL injection
21552| [37099] RHSA update for MySQL case sensistive database name privilege escalation not installed
21553| [36555] PHP MySQL extension multiple functions security bypass
21554| [35960] MySQL view privilege escalation
21555| [35959] MySQL CREATE TABLE LIKE information disclosure
21556| [35958] MySQL connection protocol denial of service
21557| [35291] MySQLDumper main.php security bypass
21558| [34811] MySQL udf_init and mysql_create_function command execution
21559| [34809] MySQL mysql_update privilege escalation
21560| [34349] MySQL ALTER information disclosure
21561| [34348] MySQL mysql_change_db privilege escalation
21562| [34347] MySQL RENAME TABLE weak security
21563| [34232] MySQL IF clause denial of service
21564| [33388] Advanced Website Creator (AWC) mysql_escape_string SQL injection
21565| [33285] Eve-Nuke mysql.php file include
21566| [32957] MySQL Commander dbopen.php file include
21567| [32933] cPanel load_language.php and mysqlconfig.php file include
21568| [32911] MySQL filesort function denial of service
21569| [32462] cPanel passwdmysql cross-site scripting
21570| [32288] RHSA-2006:0544 updates for mysql not installed
21571| [32266] MySQLNewsEngine affichearticles.php3 file include
21572| [31244] The Address Book MySQL export.php password information disclosure
21573| [31037] Php/Mysql Site Builder (PHPBuilder) htm2php.php directory traversal
21574| [30760] BTSaveMySql URL file disclosure
21575| [30191] StoryStream mysql.php and mysqli.php file include
21576| [30085] MySQL MS-DOS device name denial of service
21577| [30031] Agora MysqlfinderAdmin.php file include
21578| [29438] MySQLDumper mysqldumper_path/sql.php cross-site scripting
21579| [29179] paBugs class.mysql.php file include
21580| [29120] ZoomStats MySQL file include
21581| [28448] MySQL case sensitive database name privilege escalation
21582| [28442] MySQL GRANT EXECUTE privilege escalation
21583| [28387] FunkBoard admin/mysql_install.php and admin/pg_install.php unauthorized access
21584| [28202] MySQL multiupdate subselect query denial of service
21585| [28180] MySQL MERGE table security bypass
21586| [28176] PHP MySQL Banner Exchange lib.inc information disclosure
21587| [27995] Opsware Network Automation System MySQL plaintext password
21588| [27904] MySQL date_format() format string
21589| [27635] MySQL Instance Manager denial of service
21590| [27212] MySQL SELECT str_to_date denial of service
21591| [26875] MySQL ASCII escaping SQL injection
21592| [26420] Apple Mac OS X MySQL Manager blank password
21593| [26236] MySQL login packet information disclosure
21594| [26232] MySQL COM_TABLE_DUMP buffer overflow
21595| [26228] MySQL sql_parce.cc information disclosure
21596| [26042] MySQL running
21597| [25313] WoltLab Burning Board class_db_mysql.php cross-site scripting
21598| [24966] MySQL mysql_real_query logging bypass
21599| [24653] PAM-MySQL logging function denial of service
21600| [24652] PAM-MySQL authentication double free code execution
21601| [24567] PHP/MYSQL Timesheet index.php and changehrs.php SQL injection
21602| [24095] PHP ext/mysqli exception handling format string
21603| [23990] PHP mysql_connect() buffer overflow
21604| [23596] MySQL Auction search module could allow cross-site scripting
21605| [22642] RHSA-2005:334 updates for mysql not installed
21606| [21757] MySQL UDF library functions command execution
21607| [21756] MySQL LoadLibraryEx function denial of service
21608| [21738] MySQL UDF mysql_create_function function directory traversal
21609| [21737] MySQL user defined function buffer overflow
21610| [21640] MySQL Eventum multiple class SQL injection
21611| [21638] MySQL Eventum multiple scripts cross-site scripting
21612| [20984] xmysqladmin temporary file symlink
21613| [20656] MySQL mysql_install_db script symlink
21614| [20333] Plans MySQL password information disclosure
21615| [19659] MySQL CREATE TEMPORARY TABLE command creates insecure files
21616| [19658] MySQL udf_init function gain access
21617| [19576] auraCMS mysql_fetch_row function path disclosure
21618| [18922] MySQL mysqlaccess script symlink attack
21619| [18824] MySQL UDF root privileges
21620| [18464] mysql_auth unspecified vulnerability
21621| [18449] Sugar Sales plaintext MySQL password
21622| [17783] MySQL underscore allows elevated privileges
21623| [17768] MySQL MATCH ... AGAINST SQL statement denial of service
21624| [17667] MySQL UNION change denial of service
21625| [17666] MySQL ALTER TABLE RENAME bypass restriction
21626| [17493] MySQL libmysqlclient bulk inserts buffer overflow
21627| [17462] MySQLGuest AWSguest.php script cross-site scripting
21628| [17047] MySQL mysql_real_connect buffer overflow
21629| [17030] MySQL mysqlhotcopy insecure temporary file
21630| [16612] MySQL my_rnd buffer overflow
21631| [16604] MySQL check_scramble_323 function allows unauthorized access
21632| [15883] MySQL mysqld_multi script symlink attack
21633| [15617] MySQL mysqlbug script symlink attack
21634| [15417] Confixx db_mysql_loeschen2.php SQL injection
21635| [15280] Proofpoint Protection Server MySQL allows unauthorized access
21636| [13404] HP Servicecontrol Manager multiple vulnerabilities in MySQL could allow execution of code
21637| [13153] MySQL long password buffer overflow
21638| [12689] MySQL AB ODBC Driver stores ODBC passwords and usernames in plain text
21639| [12540] Teapop PostSQL and MySQL modules SQL injection
21640| [12337] MySQL mysql_real_connect function buffer overflow
21641| [11510] MySQL datadir/my.cnf modification could allow root privileges
21642| [11493] mysqlcc configuration and connection files are world writable
21643| [11340] SuckBot mod_mysql_logger denial of service
21644| [11199] MySQL mysql_change_user() double-free memory pointer denial of service
21645| [10850] MySQL libmysql client read_one_row buffer overflow
21646| [10849] MySQL libmysql client read_rows buffer overflow
21647| [10848] MySQL COM_CHANGE_USER password buffer overflow
21648| [10847] MySQL COM_CHANGE_USER command password authentication bypass
21649| [10846] MySQL COM_TABLE_DUMP unsigned integer denial of service
21650| [10483] Bugzilla stores passwords in plain text in the MySQL database
21651| [10455] gBook MySQL could allow administrative access
21652| [10243] MySQL my.ini "
21653| [9996] MySQL SHOW GRANTS command discloses adminstrator`s encrypted password
21654| [9909] MySQL logging disabled by default on Windows
21655| [9908] MySQL binding to the loopback adapter is disabled
21656| [9902] MySQL default root password could allow unauthorized access
21657| [8748] Cyrus SASL LDAP+MySQL patch allows user unauthorized POP access
21658| [8105] PHP MySQL client library allows an attacker to bypass safe_mode restrictions
21659| [7923] Conectiva Linux MySQL /var/log/mysql file has insecure permissions
21660| [7206] WinMySQLadmin stores MySQL password in plain text
21661| [6617] MySQL "
21662| [6419] MySQL drop database command buffer overflow
21663| [6418] MySQL libmysqlclient.so buffer overflow
21664| [5969] MySQL select buffer overflow
21665| [5447] pam_mysql authentication input
21666| [5409] MySQL authentication algorithm obtain password hash
21667| [5057] PCCS MySQL Database Admin Tool could reveal username and password
21668| [4228] MySQL unauthenticated remote access
21669| [3849] MySQL default test account could allow any user to connect to the database
21670| [1568] MySQL creates readable log files
21671|
21672| Exploit-DB - https://www.exploit-db.com:
21673| [30744] MySQL <= 5.1.23 Server InnoDB CONVERT_SEARCH_MODE_TO_INNOBASE Function Denial Of Service Vulnerability
21674| [30677] Asterisk 'asterisk-addons' 1.2.7/1.4.3 CDR_ADDON_MYSQL Module SQL Injection Vulnerability
21675| [30020] MySQL 5.0.x - IF Query Handling Remote Denial of Service Vulnerability
21676| [29724] MySQL 5.0.x Single Row SubSelect Remote Denial of Service Vulnerability
21677| [29653] Active Calendar 1.2 data/mysqlevents.php css Parameter XSS
21678| [29572] CPanel <= 11 PassWDMySQL Cross-Site Scripting Vulnerability
21679| [29569] MySQLNewsEngine Affichearticles.PHP3 Remote File Include Vulnerability
21680| [28783] MySQLDumper 1.21 SQL.PHP Cross-Site Scripting Vulnerability
21681| [28398] MySQL 4/5 SUID Routine Miscalculation Arbitrary DML Statement Execution
21682| [28308] Banex PHP MySQL Banner Exchange 2.21 members.php cfg_root Parameter Remote File Inclusion
21683| [28307] Banex PHP MySQL Banner Exchange 2.21 admin.php Multiple Parameter SQL Injection
21684| [28306] Banex PHP MySQL Banner Exchange 2.21 signup.php site_name Parameter SQL Injection
21685| [28234] MySQL 4.x/5.x Server Date_Format Denial of Service Vulnerability
21686| [28026] MySQL Server 4/5 Str_To_Date Remote Denial of Service Vulnerability
21687| [27464] Cholod MySQL Based Message Board Mb.CGI SQL Injection Vulnerability
21688| [27444] Woltlab Burning Board 2.3.4 Class_DB_MySQL.PHP Cross-Site Scripting Vulnerability
21689| [27326] MySQL 5.0.18 Query Logging Bypass Vulnerability
21690| [26058] MySQL AB Eventum 1.x get_jsrs_data.php F Parameter XSS
21691| [26057] MySQL AB Eventum 1.x list.php release Parameter XSS
21692| [26056] MySQL AB Eventum 1.x view.php id Parameter XSS
21693| [25211] MySQL 4.x CREATE TEMPORARY TABLE Symlink Privilege Escalation
21694| [25210] MySQL 4.x CREATE FUNCTION mysql.func Table Arbitrary Library Injection
21695| [25209] MySQL 4.x CREATE FUNCTION Arbitrary libc Code Execution
21696| [24805] MySQL MaxDB 7.5 WAHTTP Server Remote Denial of Service Vulnerability
21697| [24669] MySQL 3.x/4.x ALTER TABLE/RENAME Forces Old Permission Checks
21698| [24250] MySQL 4.1/5.0 Authentication Bypass Vulnerability
21699| [23179] Oracle MySQL for Microsoft Windows MOF Execution
21700| [23138] MySQL 3.23.x/4.0.x Password Handler Buffer Overflow Vulnerability
21701| [23083] MySQL Windows Remote System Level Exploit (Stuxnet technique) 0day
21702| [23081] MySQL Remote Preauth User Enumeration Zeroday
21703| [23078] MySQL Denial of Service Zeroday PoC
21704| [23077] MySQL (Linux) Database Privilege Elevation Zeroday Exploit
21705| [23076] MySQL (Linux) Heap Based Overrun PoC Zeroday
21706| [23075] MySQL (Linux) Stack Based Buffer Overrun PoC Zeroday
21707| [23073] MySQL 5.1/5.5 WiNDOWS REMOTE R00T (mysqljackpot)
21708| [22946] MySQL AB ODBC Driver 3.51 Plain Text Password Vulnerability
21709| [22565] MySQL 3.x/4.0.x Weak Password Encryption Vulnerability
21710| [22340] MySQL 3.23.x mysqld Privilege Escalation Vulnerability
21711| [22085] MySQL 3.23.x/4.0.x COM_CHANGE_USER Password Memory Corruption Vulnerability
21712| [22084] MySQL 3.23.x/4.0.x COM_CHANGE_USER Password Length Account Compromise Vulnerability
21713| [21726] MySQL 3.20.32/3.22.x/3.23.x Null Root Password Weak Default Configuration Vulnerability (2)
21714| [21725] MySQL 3.20.32/3.22.x/3.23.x Null Root Password Weak Default Configuration Vulnerability (1)
21715| [21266] PHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability (3)
21716| [21265] PHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability (2)
21717| [21264] PHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability (1)
21718| [20718] MySQL 3.20.32 a/3.23.34 Root Operation Symbolic Link File Overwriting Vulnerability
21719| [20581] Mysql 3.22.x/3.23.x Local Buffer Overflow Vulnerability
21720| [20355] Plixer Scrutinizer NetFlow and sFlow Analyzer 9 Default MySQL Credential
21721| [20055] MySQL Squid Access Report 2.1.4 HTML Injection
21722| [20044] Symantec Web Gateway 5.0.3.18 Blind SQLi Backdoor via MySQL Triggers
21723| [19721] MySQL 3.22.27/3.22.29/3.23.8 GRANT Global Password Changing Vulnerability
21724| [19092] MySQL Remote Root Authentication Bypass
21725| [18269] MySQL 5.5.8 - Remote Denial of Service (DOS)
21726| [16957] Oracle MySQL for Microsoft Windows Payload Execution
21727| [16850] MySQL yaSSL CertDecoder::GetName Buffer Overflow
21728| [16849] MySQL yaSSL SSL Hello Message Buffer Overflow
21729| [16701] MySQL yaSSL SSL Hello Message Buffer Overflow
21730| [15467] Oracle MySQL < 5.1.49 'WITH ROLLUP' Denial of Service Vulnerability
21731| [14654] CMSQLite <= 1.2 & CMySQLite <= 1.3.1 - Remote Code Execution Exploit
21732| [14537] Oracle MySQL 'ALTER DATABASE' Remote Denial of Service Vulnerability
21733| [14096] CMSQlite & CMySQLite CSRF Vulnerability
21734| [10876] PHP-MySQL-Quiz SQL Injection Vulnerability
21735| [10450] Linkster PHP/MySQL SQL Injection Vulnerability
21736| [10260] Robert Zimmerman PHP / MYSQL Scripts Admin Bypass
21737| [9953] MySQL <= 6.0 yaSSL <= 1.7.5 Hello Message Buffer Overflow
21738| [9085] MySQL <= 5.0.45 COM_CREATE_DB Format String PoC (auth)
21739| [8037] ProFTPd with mod_mysql Authentication Bypass Vulnerability
21740| [7856] MySQL 4/5/6 UDF for Command Execution
21741| [7020] MySQL Quick Admin 1.5.5 - Local File Inclusion Vulnerability
21742| [6641] MySQL Quick Admin <= 1.5.5 (COOKIE) Local File Inclusion Vulnerability
21743| [6577] PromoteWeb MySQL (go.php id) Remote SQL Injection Vulnerability
21744| [6136] phpWebNews 0.2 MySQL Edition (SQL) Insecure Cookie Handling Vuln
21745| [5999] phpWebNews 0.2 MySQL Edition (det) SQL Injection Vulnerability
21746| [5998] phpWebNews 0.2 MySQL Edition (id_kat) SQL Injection Vulnerability
21747| [5913] MyBlog: PHP and MySQL Blog/CMS software (SQL/XSS) Vulnerabilities
21748| [4615] MySQL <= 5.0.45 (Alter) Denial of Service Vulnerability
21749| [4392] PHP <= 4.4.7 / 5.2.3 MySQL/MySQLi Safe Mode Bypass Vulnerability
21750| [3685] MyBlog: PHP and MySQL Blog/CMS software RFI Vulnerability
21751| [3591] PHP-Nuke Module Eve-Nuke 0.1 (mysql.php) RFI Vulnerability
21752| [3468] MySQL Commander <= 2.7 (home) Remote File Inclusion Vulnerability
21753| [3450] NukeSentinel <= 2.5.06 (MySQL => 4.0.24) - Remote SQL Injection Exploit
21754| [3344] PHP-Nuke <= 8.0 Final (INSERT) Blind SQL Injection Exploit (mysql)
21755| [3274] MySQL 4.x/5.0 User-Defined Function Command Execution Exploit (win)
21756| [2969] Php/Mysql Site Builder 0.0.2 (htm2php.php) File Disclosure Vulnerability
21757| [2726] Agora 1.4 RC1 (MysqlfinderAdmin.php) Remote File Include Vulnerability
21758| [2554] cPanel <= 10.8.x (cpwrap via mysqladmin) Local Root Exploit (php)
21759| [2466] cPanel <= 10.8.x (cpwrap via mysqladmin) Local Root Exploit
21760| [2437] paBugs <= 2.0 Beta 3 (class.mysql.php) Remote File Include Exploit
21761| [2420] ZoomStats <= 1.0.2 (mysql.php) Remote File Include Vulnerability
21762| [1742] MySQL (<= 4.1.18, 5.0.20) Local/Remote Information Leakage Exploit
21763| [1741] MySQL <= 5.0.20 COM_TABLE_DUMP Memory Leak/Remote BoF Exploit
21764| [1518] MySQL 4.x/5.0 User-Defined Function Local Privilege Escalation Exploit
21765| [1406] PHP <= 4.4.0 (mysql_connect function) Local Buffer Overflow Exploit
21766| [1181] MySQL 4.0.17 UDF Dynamic Library Exploit
21767| [1134] MySQL Eventum <= 1.5.5 (login.php) SQL Injection Exploit
21768| [960] MySQL MaxDB Webtool <= 7.5.00.23 Remote Stack Overflow Exploit
21769| [311] MySQL 4.1/5.0 zero-length password Auth. Bypass Exploit
21770| [98] MySQL 3.23.x/4.0.x Remote Exploit
21771|
21772| OpenVAS (Nessus) - http://www.openvas.org:
21773| [902675] MySQLDumper Multiple Vulnerabilities
21774| [881549] CentOS Update for mysql CESA-2012:1551 centos6
21775| [881538] CentOS Update for mysql CESA-2012:1462 centos6
21776| [881225] CentOS Update for mysql CESA-2012:0105 centos6
21777| [881185] CentOS Update for mysql CESA-2012:0127 centos5
21778| [881061] CentOS Update for mysql CESA-2012:0874 centos6
21779| [880760] CentOS Update for mysql CESA-2009:1289 centos5 i386
21780| [880613] CentOS Update for mysql CESA-2010:0109 centos5 i386
21781| [880577] CentOS Update for mysql CESA-2010:0442 centos5 i386
21782| [880452] CentOS Update for mysql CESA-2010:0824 centos4 i386
21783| [880366] CentOS Update for mysql CESA-2010:0110 centos4 i386
21784| [880329] CentOS Update for mysql CESA-2007:1155 centos4 x86_64
21785| [880324] CentOS Update for mysql CESA-2007:1155 centos4 i386
21786| [870870] RedHat Update for mysql RHSA-2012:1551-01
21787| [870861] RedHat Update for mysql RHSA-2012:1462-01
21788| [870778] RedHat Update for mysql RHSA-2012:0874-04
21789| [870736] RedHat Update for mysql RHSA-2011:0164-01
21790| [870647] RedHat Update for mysql RHSA-2012:0105-01
21791| [870547] RedHat Update for mysql RHSA-2012:0127-01
21792| [870357] RedHat Update for mysql RHSA-2010:0824-01
21793| [870356] RedHat Update for mysql RHSA-2010:0825-01
21794| [870272] RedHat Update for mysql RHSA-2010:0442-01
21795| [870218] RedHat Update for mysql RHSA-2010:0110-01
21796| [870216] RedHat Update for mysql RHSA-2010:0109-01
21797| [870195] RedHat Update for mysql RHSA-2007:1155-01
21798| [870069] RedHat Update for mysql RHSA-2008:0364-01
21799| [870033] RedHat Update for mysql RHSA-2008:0768-01
21800| [864951] Fedora Update for mysql FEDORA-2012-19823
21801| [864945] Fedora Update for mysql FEDORA-2012-19833
21802| [864504] Fedora Update for mysql FEDORA-2012-9324
21803| [864474] Fedora Update for mysql FEDORA-2012-9308
21804| [863910] Fedora Update for mysql FEDORA-2012-0972
21805| [863725] Fedora Update for mysql FEDORA-2012-0987
21806| [862844] Fedora Update for mod_auth_mysql FEDORA-2011-0100
21807| [862840] Fedora Update for mod_auth_mysql FEDORA-2011-0114
21808| [862676] Fedora Update for mysql FEDORA-2010-15147
21809| [862444] Fedora Update for mysql FEDORA-2010-15166
21810| [862300] Fedora Update for mysql FEDORA-2010-11126
21811| [862290] Fedora Update for mysql FEDORA-2010-11135
21812| [862149] Fedora Update for mysql FEDORA-2010-9053
21813| [862148] Fedora Update for mysql FEDORA-2010-9061
21814| [862136] Fedora Update for mysql FEDORA-2010-9016
21815| [861948] Fedora Update for mysql FEDORA-2010-7355
21816| [861936] Fedora Update for mysql FEDORA-2010-7414
21817| [861707] Fedora Update for mysql FEDORA-2010-1300
21818| [861651] Fedora Update for mysql FEDORA-2010-1348
21819| [861544] Fedora Update for php-pear-MDB2-Driver-mysql FEDORA-2007-3369
21820| [861392] Fedora Update for mysql FEDORA-2007-4471
21821| [861180] Fedora Update for php-pear-MDB2-Driver-mysqli FEDORA-2007-3369
21822| [861162] Fedora Update for php-pear-MDB2-Driver-mysql FEDORA-2007-3376
21823| [861108] Fedora Update for php-pear-MDB2-Driver-mysqli FEDORA-2007-3376
21824| [861033] Fedora Update for mysql FEDORA-2007-4465
21825| [855481] Solaris Update for mysql 120292-02
21826| [855333] Solaris Update for mysql 120293-02
21827| [850182] SuSE Update for mysql openSUSE-SU-2012:0860-1 (mysql)
21828| [841248] Ubuntu Update for mysql-5.5 USN-1658-1
21829| [841207] Ubuntu Update for mysql-5.5 USN-1621-1
21830| [841039] Ubuntu Update for mysql-5.5 USN-1467-1
21831| [840989] Ubuntu Update for mysql-5.1 USN-1427-1
21832| [840944] Ubuntu Update for mysql-5.1 USN-1397-1
21833| [840533] Ubuntu Update for MySQL vulnerabilities USN-1017-1
21834| [840442] Ubuntu Update for MySQL vulnerabilities USN-950-1
21835| [840384] Ubuntu Update for MySQL vulnerabilities USN-897-1
21836| [840292] Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-671-1
21837| [840240] Ubuntu Update for mysql-dfsg-5.0 regression USN-588-2
21838| [840219] Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-588-1
21839| [840106] Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-559-1
21840| [840042] Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-528-1
21841| [840012] Ubuntu Update for mysql-dfsg-5.0 vulnerability USN-440-1
21842| [835096] HP-UX Update for on HP 9000 Servers Running MySQL HPSBUX00287
21843| [831755] Mandriva Update for mysql MDVSA-2012:178 (mysql)
21844| [831684] Mandriva Update for mysql MDVA-2012:049 (mysql)
21845| [831547] Mandriva Update for mysql MDVA-2012:022 (mysql)
21846| [831532] Mandriva Update for mysql MDVA-2012:005 (mysql)
21847| [831519] Mandriva Update for mysql MDVA-2011:099 (mysql)
21848| [831425] Mandriva Update for mysql MDVA-2011:025 (mysql)
21849| [831327] Mandriva Update for mysql MDVA-2011:005 (mysql)
21850| [831315] Mandriva Update for mysql MDVSA-2011:012 (mysql)
21851| [831295] Mandriva Update for mysql MDVA-2010:240 (mysql)
21852| [831244] Mandriva Update for mysql MDVSA-2010:155-1 (mysql)
21853| [831243] Mandriva Update for mysql MDVSA-2010:222 (mysql)
21854| [831237] Mandriva Update for mysql MDVSA-2010:223 (mysql)
21855| [831202] Mandriva Update for mysql MDVA-2010:210 (mysql)
21856| [831134] Mandriva Update for mysql MDVSA-2010:155 (mysql)
21857| [831049] Mandriva Update for mysql MDVSA-2010:107 (mysql)
21858| [831048] Mandriva Update for mysql MDVSA-2010:101 (mysql)
21859| [831034] Mandriva Update for mysql MDVA-2010:146 (mysql)
21860| [831033] Mandriva Update for mysql MDVSA-2010:093 (mysql)
21861| [830902] Mandriva Update for mysql MDVSA-2010:044 (mysql)
21862| [830821] Mandriva Update for mysql MDVSA-2010:011 (mysql)
21863| [830806] Mandriva Update for mysql MDVSA-2010:012 (mysql)
21864| [830772] Mandriva Update for mysql MDVSA-2008:150 (mysql)
21865| [830664] Mandriva Update for mysql MDVA-2008:018 (mysql)
21866| [830659] Mandriva Update for mysql MDVSA-2008:017 (mysql)
21867| [830513] Mandriva Update for mysql MDVSA-2008:028 (mysql)
21868| [830421] Mandriva Update for mysql MDVSA-2008:149 (mysql)
21869| [830297] Mandriva Update for MySQL MDKSA-2007:177 (MySQL)
21870| [830223] Mandriva Update for perl-DBD-mysql MDKA-2007:066 (perl-DBD-mysql)
21871| [830063] Mandriva Update for MySQL MDKSA-2007:139 (MySQL)
21872| [830032] Mandriva Update for MySQL MDKSA-2007:243 (MySQL)
21873| [801593] Oracle MySQL Eventum Multiple Cross Site Scripting Vulnerabilities
21874| [801205] MySQL Connector/Net SSL Certificate Validation Security Bypass Vulnerability
21875| [103051] PHP MySQLi Extension 'set_magic_quotes_runtime' Function Security-Bypass Weakness
21876| [100662] PHP Mysqlnd Extension Information Disclosure and Multiple Buffer Overflow Vulnerabilities
21877| [71475] Debian Security Advisory DSA 2496-1 (mysql-5.1)
21878| [71233] Debian Security Advisory DSA 2429-1 (mysql-5.1)
21879| [70803] Gentoo Security Advisory GLSA 201201-02 (MySQL)
21880| [70586] FreeBSD Ports: proftpd, proftpd-mysql
21881| [67541] Debian Security Advisory DSA 2057-1 (mysql-dfsg-5.0)
21882| [66577] Fedora Core 11 FEDORA-2009-13504 (mysql)
21883| [66573] Fedora Core 12 FEDORA-2009-13466 (mysql)
21884| [66553] Mandriva Security Advisory MDVSA-2009:189-1 (apache-mod_auth_mysql)
21885| [66508] Fedora Core 10 FEDORA-2009-12180 (mysql)
21886| [66425] Mandriva Security Advisory MDVSA-2009:326 (mysql)
21887| [66256] Fedora Core 11 FEDORA-2009-10701 (ocaml-mysql)
21888| [66251] Fedora Core 10 FEDORA-2009-10582 (ocaml-mysql)
21889| [66056] Debian Security Advisory DSA 1910-1 (mysql-ocaml)
21890| [66035] Mandrake Security Advisory MDVSA-2009:279 (ocaml-mysql)
21891| [65937] SLES10: Security update for MySQL
21892| [65884] SLES10: Security update for MySQL
21893| [65827] SLES10: Security update for MySQL
21894| [65710] SLES11: Security update for MySQL
21895| [65610] SLES9: Security update for MySQL
21896| [65566] SLES9: Security update for MySQL
21897| [65507] SLES9: Security update for MySQL
21898| [65502] SLES9: Security update for mysql
21899| [65426] SLES9: Security update for MySQL
21900| [65385] SLES9: Security update for mysql
21901| [65341] SLES9: Security update for MySQL
21902| [65181] SLES9: Security update for MySQL
21903| [65176] SLES9: Security update for MySQL
21904| [64932] CentOS Security Advisory CESA-2009:1289 (mysql)
21905| [64820] Debian Security Advisory DSA 1877-1 (mysql-dfsg-5.0)
21906| [64532] Mandrake Security Advisory MDVSA-2009:189 (apache-mod_auth_mysql)
21907| [64522] Mandrake Security Advisory MDVSA-2009:179 (mysql)
21908| [64461] Mandrake Security Advisory MDVSA-2009:159 (mysql)
21909| [63872] Mandrake Security Advisory MDVSA-2009:094 (mysql)
21910| [63630] FreeBSD Ports: proftpd, proftpd-mysql
21911| [63171] FreeBSD Ports: mysql-server
21912| [63170] FreeBSD Ports: mysql-server
21913| [63169] FreeBSD Ports: mysql-server
21914| [63168] FreeBSD Ports: mysql-server
21915| [63095] FreeBSD Ports: mysql-server
21916| [61852] Debian Security Advisory DSA 1662-1 (mysql-dfsg-5.0)
21917| [61699] FreeBSD Ports: mysql-client
21918| [61656] FreeBSD Ports: proftpd, proftpd-mysql
21919| [61618] FreeBSD Ports: mysql-server
21920| [61599] Gentoo Security Advisory GLSA 200809-04 (mysql)
21921| [61283] Debian Security Advisory DSA 1608-1 (mysql-dfsg-5.0)
21922| [60804] Gentoo Security Advisory GLSA 200804-04 (mysql)
21923| [60271] Debian Security Advisory DSA 1478-1 (mysql-dfsg-5.0)
21924| [60106] Debian Security Advisory DSA 1451-1 (mysql-dfsg-5.0)
21925| [60017] Slackware Advisory SSA:2007-348-01 mysql
21926| [59638] Debian Security Advisory DSA 1413-1 (mysql-dfsg, mysql-dfsg-5.0, mysql-dfsg-4.1)
21927| [59245] Gentoo Security Advisory GLSA 200711-25 (mysql)
21928| [58863] FreeBSD Ports: freeradius, freeradius-mysql
21929| [58545] Gentoo Security Advisory GLSA 200708-10 (mysql)
21930| [58261] Gentoo Security Advisory GLSA 200705-11 (MySQL)
21931| [57859] Gentoo Security Advisory GLSA 200608-09 (mysql)
21932| [57725] FreeBSD Ports: proftpd, proftpd-mysql
21933| [57576] FreeBSD Ports: proftpd, proftpd-mysql
21934| [57527] FreeBSD Ports: mysql-server
21935| [57526] FreeBSD Ports: mysql-server
21936| [57337] Debian Security Advisory DSA 1169-1 (mysql-dfsg-4.1)
21937| [57257] FreeBSD Ports: mysql-server
21938| [57167] Slackware Advisory SSA:2006-211-01 mysql
21939| [57109] Debian Security Advisory DSA 1112-1 (mysql-dfsg-4.1)
21940| [56964] Gentoo Security Advisory GLSA 200606-18 (pam_mysql)
21941| [56940] Gentoo Security Advisory GLSA 200606-13 (MySQL)
21942| [56924] Debian Security Advisory DSA 1092-1 (mysql-dfsg-4.1)
21943| [56861] Slackware Advisory SSA:2006-155-01 mysql
21944| [56850] FreeBSD Ports: mysql-server
21945| [56849] FreeBSD Ports: mysql-server
21946| [56833] Debian Security Advisory DSA 1079-1 (mysql-dfsg)
21947| [56789] Debian Security Advisory DSA 1073-1 (mysql-dfsg-4.1)
21948| [56788] Debian Security Advisory DSA 1071-1 (mysql)
21949| [56730] Slackware Advisory SSA:2006-129-02 mysql
21950| [56728] Gentoo Security Advisory GLSA 200605-13 (MySQL)
21951| [56714] FreeBSD Ports: mysql-server
21952| [55520] Debian Security Advisory DSA 833-2 (mysql-dfsg-4.1)
21953| [55514] Debian Security Advisory DSA 833-1 (mysql-dfsg-4.1)
21954| [55493] Debian Security Advisory DSA 829-1 (mysql)
21955| [55492] Debian Security Advisory DSA 831-1 (mysql-dfsg)
21956| [55164] Debian Security Advisory DSA 783-1 (mysql-dfsg-4.1)
21957| [54884] Gentoo Security Advisory GLSA 200503-19 (mysql)
21958| [54819] Gentoo Security Advisory GLSA 200501-33 (mysql)
21959| [54713] Gentoo Security Advisory GLSA 200410-22 (MySQL)
21960| [54659] Gentoo Security Advisory GLSA 200409-02 (MySQL)
21961| [54580] Gentoo Security Advisory GLSA 200405-20 (MySQL)
21962| [54483] FreeBSD Ports: proftpd, proftpd-mysql
21963| [54201] FreeBSD Ports: mysql-server
21964| [53776] Debian Security Advisory DSA 013-1 (mysql)
21965| [53755] Debian Security Advisory DSA 483-1 (mysql)
21966| [53750] Debian Security Advisory DSA 707-1 (mysql)
21967| [53666] Debian Security Advisory DSA 381-1 (mysql)
21968| [53595] Debian Security Advisory DSA 303-1 (mysql)
21969| [53585] Debian Security Advisory DSA 212-1 (mysql)
21970| [53481] Debian Security Advisory DSA 647-1 (mysql)
21971| [53251] Debian Security Advisory DSA 562-1 (mysql)
21972| [53230] Debian Security Advisory DSA 540-1 (mysql)
21973| [52466] FreeBSD Ports: exim, exim-ldap2, exim-mysql, exim-postgresql
21974| [52459] FreeBSD Ports: mysql-client
21975| [52419] FreeBSD Ports: mysql-scripts
21976| [52406] FreeBSD Ports: mysql-server
21977| [52375] FreeBSD Ports: mysql-server, mysql-client
21978| [52274] FreeBSD Ports: mysql-server
21979| [52273] FreeBSD Ports: mysql-server
21980| [52272] FreeBSD Ports: mysql-server
21981| [52271] FreeBSD Ports: mysql-server
21982| [52270] FreeBSD Ports: mysql-server
21983| [52233] FreeBSD Ports: mysql-scripts
21984| [52158] FreeBSD Ports: mysql-server
21985| [16093] MySQL Eventum Multiple flaws
21986| [12639] MySQL Authentication bypass through a zero-length password
21987| [10783] PCCS-Mysql User/Password Exposure
21988|
21989| SecurityTracker - https://www.securitytracker.com:
21990| [1028790] MySQL Multiple Bugs Let Remote Users Deny Service and Partially Access and Modify Data
21991| [1028449] MySQL Multiple Bugs Let Remote Authenticated Users Deny Service and Partially Access and Modify Data
21992| [1028004] MySQL Multiple Bugs Let Remote Authenticated Users Take Full Control or Deny Service and Let Local Users Access and Modify Data
21993| [1027829] MySQL Bug in UpdateXML() Lets Remote Authenticated Users Deny Service
21994| [1027828] MySQL Heap Overflow May Let Remote Authenticated Users Execute Arbitrary Code
21995| [1027827] MySQL Stack Overflow May Let Remote Authenticated Users Execute Arbitrary Code
21996| [1027665] MySQL Multiple Bugs Let Remote Authenticated Users Access and Modify Data and Deny Service and Local Users Access Data
21997| [1027263] MySQL Multiple Bugs Let Remote Authenticated Users Deny Service
21998| [1027143] MySQL memcmp() Comparison Error Lets Remote Users Bypass Authentication
21999| [1026934] MySQL Multiple Bugs Let Remote Users Deny Service
22000| [1026896] MySQL Unspecified Flaws Have Unspecified Impact
22001| [1026659] MySQL Unspecified Flaw Lets Remote Users Execute Arbitrary Code
22002| [1026530] MySQL Multiple Bugs Let Local and Remote Users Partially Access and Modifiy Data and Partially Deny Service
22003| [1024508] MySQL Replication Flaw Lets Remote Authenticated Users Gain Elevated Privileges
22004| [1024507] MySQL Multiple Flaws Let Remote Authenticated Users Deny Service
22005| [1024360] MySQL Multiple Flaws Let Remote Authenticated Users Deny Service
22006| [1024160] MySQL ALTER DATABASE Processing Error Lets Remote Authenticated Users Deny Service
22007| [1024033] MySQL COM_FIELD_LIST Packet Buffer Overflow Lets Remote Authenticated Users Execute Arbitrary Code
22008| [1024032] MySQL Large Packet Processing Flaw in my_net_skip_rest() Lets Remote Users Deny Service
22009| [1024031] MySQL COM_FIELD_LIST Validation Flaw Lets Remote Authenticated Users Gain Elevated Privileges
22010| [1024004] MySQL mi_delete_table() Symlink Flaw Lets Remote Authenticated Users Delete Data and Index Files
22011| [1023402] MySQL Unspecified Flaw Lets Remote Users Execute Arbitrary Code
22012| [1023220] MySQL Client Fails to Check Server Certificates in Certain Cases
22013| [1022812] MySQL Unspecified Buffer Overflow Lets Remote Users Execute Arbitrary Code
22014| [1022533] MySQL Format String Bug in dispatch_command() Lets Remote Users Deny Service
22015| [1022482] MySQL Connector/Net is Missing SSL Certificate Validation
22016| [1021786] MySQL Bug in ExtractValue()/UpdateXML() in Processing XPath Expressions Lets Remote Authenticated Users Deny Service
22017| [1021714] (Red Hat Issues Fix) mod_auth_mysql Input Validation Flaw Lets Remote Users Inject SQL Commands
22018| [1020858] MySQL Item_bin_string::Item_bin_string() Binary Value Processing Bug Lets Remote Authenticated Users Deny Service
22019| [1019995] MySQL MyISAM Options Let Local Users Overwrite Table Files
22020| [1019085] MySQL Bugs Let Remote Authenticated Users Gain Elevated Privileges and Deny Service
22021| [1019084] MySQL DATA DIRECTORY and INDEX DIRECTORY Options May Let Remote Authenticated Users Gain Elevated Privileges
22022| [1019083] MySQL BINLOG Filename Path Bug May Let Remote Authenticated Users Gain Elevated Privileges
22023| [1019060] MySQL Rename Table Bug Lets Remote Authenticated Users Modify System Table Information
22024| [1018978] MySQL convert_search_mode_to_innobase() Bug Lets Remote Authenticated Users Deny Service
22025| [1018824] Asterisk-Addons Input Validation Flaw in cdr_addon_mysql Lets Remote Users Inject SQL Commands
22026| [1018663] MySQL Table View Access Bug Lets Remote Authenticated Users Gain Elevated Privileges
22027| [1018629] MySQL Authentication Protocol Bug Lets Remote Users Deny Service
22028| [1018071] MySQL ALTER TABLE Function Lets Remote Authenticated Users Obtain Potentially Sensitive Information
22029| [1018070] MySQL SQL SECURITY INVOKER Routines Let Remote Authenticated Users Gain Elevated Privileges
22030| [1018069] MySQL Lets Remote Authenticated Users Issue the RENAME TABLE Command
22031| [1017746] MySQL Single Row Subselect Statements Let Remote Users Deny Service
22032| [1016790] MySQL Replication Error Lets Local Users Deny Service
22033| [1016710] MySQL Case-Sensitive Database Names May Let Users Access Restricted Databases
22034| [1016709] MySQL Error in Checking suid Routine Arguments May Let Users Gain Elevated Privileges
22035| [1016617] MySQL MERGE Access Control Error May Let Users Access a Restricted Table
22036| [1016566] Opsware Network Automation System Discloses MySQL Password to Local Users
22037| [1016216] MySQL Error in Parsing Multibyte Encoded Data in mysql_real_escape() Lets Remote Users Inject SQL Commands
22038| [1016077] Apple MySQL Manager Database Initialization Bug May Let Local Users Access the Database
22039| [1016017] MySQL Anonymous Login Processing May Disclose Some Memory Contents to Remote Users
22040| [1016016] MySQL COM_TABLE_DUMP Processing Lets Remote Authenticated Users Execute Arbitrary Code or Obtain Information
22041| [1015789] Woltlab Burning Board Input Validation Hole in 'class_db_mysql.php' Permits Cross-Site Scripting Attacks
22042| [1015693] MySQL Query Bug Lets Remote Users Bypass Query Logging
22043| [1015603] PAM-MySQL pam_get_item() Double Free May Let Remote Users Execute Arbitrary Code
22044| [1015485] PHP mysqli Extension Error Mode Format String Flaw May Let Users Execute Arbitrary Code
22045| [1014603] MySQL Eventum Input Validation Hole in 'class.auth.php' Permits SQL Injection and Other Input Validation Bugs Permit Cross-Site Scripting Attacks
22046| [1014172] xMySQLadmin Lets Local Users Delete Files
22047| [1013995] MySQL 'mysql_install_db' Uses Unsafe Temporary Files and May Let Local Users Gain Elevated Privilege
22048| [1013994] MySQL Non-existent '--user' Error May Allow the Database to Run With Incorrect Privileges
22049| [1013415] MySQL CREATE FUNCTION Lets Authenticated Users Invoke libc Functions to Execute Arbitrary Code
22050| [1013414] MySQL udf_init() Path Validation Flaw Lets Authenticated Users Execute Arbitrary Libraries
22051| [1013413] MySQL CREATE TEMPORARY TABLE Uses Predictable Temporary Files That May Let Users Gain Elevated Privileges
22052| [1012914] MySQL 'mysqlaccess.sh' Unsafe Temporary Files May Let Local Users Gain Elevated Privileges
22053| [1012893] MySQL MaxDB Buffer Overflow in websql Password Parameter Lets Remote Users Execute Arbitrary Code
22054| [1012500] mysql_auth Memory Leak Has Unspecified Impact
22055| [1011741] MySQL Access Control Error in Databases With Underscore Wildcard Character May Grant Unauthorized Access
22056| [1011606] MySQL May Let Remote Authenticated Users Access Restricted Tables or Crash the System
22057| [1011408] MySQL libmysqlclient Buffer Overflow in Executing Prepared Statements Has Unspecified Impact
22058| [1011376] MySQLGuest Lack of Input Validation Lets Remote Users Conduct Cross-Site Scripting Attacks
22059| [1011008] MySQL Buffer Overflow in mysql_real_connect() May Let Remote Users Execute Arbitrary Code
22060| [1010979] MySQL 'mysqlhotcopy' Unsafe Temporary Files May Let Local Users Gain Elevated Privileges
22061| [1010645] MySQL check_scramble_323() Zero-Length Comparison Lets Remote Users Bypass Authentication
22062| [1009784] MySQL 'mysqld_multi' Temporary File Flaw Lets Local Users Overwrite Files
22063| [1009554] MySQL 'mysqlbug' Temporary File Flaw Lets Local Users Overwrite Files
22064| [1007979] MySQL mysql_change_user() Double Free Error Lets Remote Authenticated Users Crash mysqld
22065| [1007673] MySQL acl_init() Buffer Overflow Permits Remote Authenticated Administrators to Execute Arbitrary Code
22066| [1007518] DWebPro Discloses MySQL Database Password to Local Users
22067| [1007312] MySQL World-Writable Configuration File May Let Local Users Gain Root Privileges
22068| [1006976] MySQL Buffer Overflow in 'mysql_real_connect()' Client Function May Let Remote or Local Users Execute Arbitrary Code
22069| [1005800] MySQL Overflow and Authentication Bugs May Let Remote Users Execute Code or Access Database Accounts
22070| [1005345] MySQL Buffer Overflow Lets Local Users Gain System Privileges on Windows NT
22071| [1004506] vBulletin PHP-based Forum Software Has Unspecified Security Flaw in the 'db_mysql.php' Module
22072| [1004172] PHP-Survey Script Discloses Underlying MySQL Database Username and Password to Remote Users
22073| [1003955] 3rd Party Patch for Cyrus SASL ('auxprop for mysql and ldap') Lets Remote Users Access Protected POP Mail Accounts Without Authentication
22074| [1003290] Conectiva Linux MySQL Distribution May Allow Local Users to Obtain Sensitive Information
22075| [1002993] PurePostPro Script Add-on for PureFTPd and MySQL Allows Remote Users to Execute SQL Commands on the Server
22076| [1002485] WinMySQLadmin Database Administration Tool Discloses MySQL Password to Local Users
22077| [1002324] Vpopmail Mail Server Discloses Database Password to Local Users When Installed with MySQL
22078| [1001411] phpMyAdmin Administration Tool for MySQL Allows Remote Users to Execute Commands on the Server
22079| [1001118] MySQL Database Allows Authorized Users to Modify Server Files to Deny Service or Obtain Additional Access
22080|
22081| OSVDB - http://www.osvdb.org:
22082| [95337] Oracle MySQL Server XA Transactions Subcomponent Unspecified Remote DoS
22083| [95336] Oracle MySQL Server Replication Subcomponent Unspecified Remote DoS
22084| [95335] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS
22085| [95334] Oracle MySQL Server Privileges Subcomponent Unspecified Remote Issue
22086| [95333] Oracle MySQL Server Partition Subcomponent Unspecified Remote DoS
22087| [95332] Oracle MySQL Server Parser Subcomponent Unspecified Remote DoS
22088| [95331] Oracle MySQL Server Options Subcomponent Unspecified Remote DoS (2013-3801)
22089| [95330] Oracle MySQL Server Options Subcomponent Unspecified Remote DoS (2013-3808)
22090| [95329] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2013-3796)
22091| [95328] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2013-3804)
22092| [95327] Oracle MySQL Server Prepared Statements Subcomponent Unspecified Remote DoS
22093| [95326] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS
22094| [95325] Oracle MySQL Server Full Text Search Subcomponent Unspecified Remote DoS
22095| [95324] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-3795)
22096| [95323] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-3793)
22097| [95322] Oracle MySQL Server Audit Log Subcomponent Unspecified Remote Issue
22098| [95321] Oracle MySQL Server MemCached Subcomponent Unspecified Remote Issue
22099| [95131] AutoMySQLBackup /usr/sbin/automysqlbackup Database Name Arbitrary Code Injection
22100| [94076] Debian Linux MySQL Server mysql-server-5.5.postinst Race Condition debian.cnf Plaintext Credential Local Disclosure
22101| [93505] Wireshark MySQL Dissector (packet-mysql.c) Malformed Packet Handling Infinite Loop Remote DoS
22102| [93174] MySQL Crafted Derived Table Handling DoS
22103| [92967] MySQL2JSON (mn_mysql2json) Extension for TYPO3 Unspecified SQL Injection
22104| [92950] MySQL Running START SLAVE Statement Process Listing Plaintext Local Password Disclosure
22105| [92485] Oracle MySQL Server Partition Subcomponent Unspecified Local DoS
22106| [92484] Oracle MySQL Server Locking Subcomponent Unspecified Remote DoS (2013-1506)
22107| [92483] Oracle MySQL Server Install Subcomponent Unspecified Local Issue
22108| [92482] Oracle MySQL Server Types Subcomponent Unspecified Remote DoS
22109| [92481] Oracle MySQL Server Privileges Subcomponent Unspecified Remote Issue (2013-2381)
22110| [92480] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2013-1566)
22111| [92479] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2013-1511)
22112| [92478] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-1567)
22113| [92477] Oracle MySQL Server Stored Procedure Subcomponent Unspecified Remote DoS
22114| [92476] Oracle MySQL Server Replication Subcomponent Unspecified Remote DoS
22115| [92475] Oracle MySQL Server Partition Subcomponent Unspecified Remote DoS
22116| [92474] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS
22117| [92473] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2013-2389)
22118| [92472] Oracle MySQL Server Information Schema Subcomponent Unspecified Remote DoS
22119| [92471] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-1512)
22120| [92470] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-1544)
22121| [92469] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote Issue
22122| [92468] Oracle MySQL Server MemCached Subcomponent Unspecified Remote DoS
22123| [92467] Oracle MySQL Server Privileges Subcomponent Unspecified Remote Issue (2013-2375)
22124| [92466] Oracle MySQL Server Privileges Subcomponent Unspecified Remote Issue (2013-1531)
22125| [92465] Oracle MySQL Server Server Subcomponent Unspecified Remote Issue
22126| [92464] Oracle MySQL Server Information Schema Subcomponent Unspecified Remote Issue
22127| [92463] Oracle MySQL Server Locking Subcomponent Unspecified Remote Issue (2013-1521)
22128| [92462] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-2395)
22129| [91536] Oracle MySQL yaSSL Unspecified Overflow (2012-0553)
22130| [91534] Oracle MySQL yaSSL Unspecified Overflow (2013-1492)
22131| [91415] MySQL Raw Geometry Object String Conversion Remote DoS
22132| [91108] Juju mysql Charm Install Script mysql.passwd MySQL Password Plaintext Local Disclosure
22133| [89970] Site Go /site-go/admin/extra/mysql/index.php idm Parameter Traversal Arbitrary File Access
22134| [89265] Oracle MySQL Server Server Privileges Subcomponent Unspecified Remote DoS
22135| [89264] Oracle MySQL Server Server Partition Subcomponent Unspecified Remote DoS
22136| [89263] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS (2012-0578)
22137| [89262] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS (2012-1705)
22138| [89261] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-0574)
22139| [89260] Oracle MySQL Server MyISAM Subcomponent Unspecified Remote DoS
22140| [89259] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2012-0572)
22141| [89258] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2013-0368)
22142| [89257] Oracle MySQL Server Server Locking Subcomponent Unspecified Remote DoS
22143| [89256] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-1702)
22144| [89255] Oracle MySQL Server Server Replication Subcomponent Unspecified Remote Issue
22145| [89254] Oracle MySQL Server Server Replication Subcomponent Unspecified Local Issue
22146| [89253] Oracle MySQL Server Stored Procedure Subcomponent Unspecified Remote DoS
22147| [89252] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS
22148| [89251] Oracle MySQL Server Information Schema Subcomponent Unspecified Remote DoS
22149| [89250] Oracle MySQL Server GIS Extension Subcomponent Unspecified Remote DoS
22150| [89042] ViciBox Server MySQL cron Service Default Credentials
22151| [88415] Oracle MySQL Server COM_CHANGE_USER Account Password Brute-Force Weakness
22152| [88118] Oracle MySQL Server FILE Privilege Database Privilege Escalation
22153| [88067] Oracle MySQL Server Authentication Error Message User Enumeration
22154| [88066] Oracle MySQL Server for Linux Access Rights Checking Routine Database Name Handling Stack Buffer Overflow
22155| [88065] Oracle MySQL Server COM_BINLOG_DUMP Invalid Data Handling DoS
22156| [88064] Oracle MySQL Server Multiple-Table DELETE Heap Buffer Overflow
22157| [87704] CodeIgniter MySQL / MySQLi Driver Database Client Multi-byte Character Set Unspecified SQL Injection
22158| [87507] Oracle MySQL Statement Logging Multiple Log Plaintext Local Password Disclosure
22159| [87501] Oracle MySQL optimizer_switch Malformed Value Processing Local DoS
22160| [87494] Oracle MySQL on Windows Field_new_decimal::store_value dbug_buff Variable Overflow DoS
22161| [87480] MySQL Malformed XML Comment Handling DoS
22162| [87466] MySQL SSL Certificate Revocation Weakness
22163| [87356] Oracle MySQL do_div_mod DIV Expression Handling Remote DoS
22164| [87355] Oracle MySQL handler::pushed_cond Table Cache Handling mysqld DoS
22165| [87354] Oracle MySQL Polygon Union / Intersection Spatial Operations DoS
22166| [86273] Oracle MySQL Server Server Installation Subcomponent Unspecified Local Information Disclosure
22167| [86272] Oracle MySQL Server Server Replication Subcomponent Unspecified Remote DoS
22168| [86271] Oracle MySQL Server Server Full Text Search Subcomponent Unspecified Remote DoS
22169| [86270] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-3156)
22170| [86269] Oracle MySQL Server MySQL Client Subcomponent Unspecified Remote Information Disclosure
22171| [86268] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS (2012-3180)
22172| [86267] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS (2012-3150)
22173| [86266] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-3144)
22174| [86265] Oracle MySQL Server InnoDB Plugin Subcomponent Unspecified Remote DoS
22175| [86264] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS
22176| [86263] Oracle MySQL Server MySQL Client Subcomponent Unspecified Remote Issue
22177| [86262] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-3177)
22178| [86261] Oracle MySQL Server Protocol Subcomponent Unspecified Remote Issue
22179| [86260] Oracle MySQL Server Information Schema Subcomponent Unspecified Remote Code Execution
22180| [86175] Oracle MySQL on Windows Path Subversion Arbitrary DLL Injection Code Execution
22181| [85155] Icinga module/idoutils/db/scripts/create_mysqldb.sh Icinga User Database Access Restriction Bypass
22182| [84755] Oracle MySQL Sort Order Index Calculation Remote DoS
22183| [84719] MySQLDumper index.php page Parameter XSS
22184| [84680] MySQL Squid Access Report access.log File Path XSS
22185| [83980] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2012-1689)
22186| [83979] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2012-1734)
22187| [83978] Oracle MySQL Server Subcomponent Unspecified Remote DoS
22188| [83977] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS
22189| [83976] Oracle MySQL Server GIS Extension Subcomponent Unspecified Remote DoS
22190| [83975] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2012-1735)
22191| [83661] Oracle MySQL Unspecified Issue (59533)
22192| [82804] Oracle MySQL Authentication Protocol Token Comparison Casting Failure Password Bypass
22193| [82803] Oracle MySQL Unspecified Issue (59387)
22194| [82120] Oracle MySQL Version Specific Comment Handling Arbitrary SQL Command Execution
22195| [81897] Viscacha classes/database/mysql.inc.php Multiple Parameter SQL Injection
22196| [81616] MySQLDumper Multiple Script Direct Request Information Disclosure
22197| [81615] MySQLDumper filemanagement.php f Parameter Traversal Arbitrary File Access
22198| [81614] MySQLDumper File Upload PHP Code Execution
22199| [81613] MySQLDumper main.php Multiple Function CSRF
22200| [81612] MySQLDumper restore.php filename Parameter XSS
22201| [81611] MySQLDumper sql.php Multiple Parameter XSS
22202| [81610] MySQLDumper install.php Multiple Parameter XSS
22203| [81609] MySQLDumper install.php language Parameter Traversal Arbitrary File Access
22204| [81378] Oracle MySQL Server Server Optimizer Component Unspecified Remote DoS (2012-1690)
22205| [81377] Oracle MySQL Server Server Optimizer Component Unspecified Remote DoS (2012-1696)
22206| [81376] Oracle MySQL Server Server DML Component Unspecified Remote DoS
22207| [81375] Oracle MySQL Server Partition Component Unspecified Remote DoS
22208| [81374] Oracle MySQL Server MyISAM Component Unspecified Remote DoS
22209| [81373] Oracle MySQL Server Server Optimizer Component Unspecified Remote DoS (2012-1703)
22210| [81059] Oracle MySQL Server Multiple Unspecified Issues
22211| [79038] Webmin Process Listing MySQL Password Local Disclosure
22212| [78919] Oracle MySQL Unspecified Pre-authentication Remote Code Execution
22213| [78710] WordPress wp-admin/setup-config.php MySQL Query Saturation Brute-Force Proxy Weakness
22214| [78708] WordPress wp-admin/setup-config.php MySQL Database Verification Code Injection Weakness
22215| [78707] WordPress wp-admin/setup-config.php MySQL Credentials Error Message Brute-Force Weakness
22216| [78394] Oracle MySQL Server Unspecified Remote DoS (2012-0493)
22217| [78393] Oracle MySQL Server Unspecified Remote DoS (2012-0492)
22218| [78392] Oracle MySQL Server Unspecified Remote DoS (2012-0117)
22219| [78391] Oracle MySQL Server Unspecified Remote DoS (2012-0112)
22220| [78390] Oracle MySQL Server Unspecified Remote DoS (2012-0495)
22221| [78389] Oracle MySQL Server Unspecified Remote DoS (2012-0491)
22222| [78388] Oracle MySQL Server Unspecified Remote DoS (2012-0490)
22223| [78387] Oracle MySQL Server Unspecified Remote DoS (2012-0489)
22224| [78386] Oracle MySQL Server Unspecified Remote DoS (2012-0488)
22225| [78385] Oracle MySQL Server Unspecified Remote DoS (2012-0487)
22226| [78384] Oracle MySQL Server Unspecified Remote DoS (2012-0486)
22227| [78383] Oracle MySQL Server Unspecified Remote DoS (2012-0485)
22228| [78382] Oracle MySQL Server Unspecified Remote DoS (2012-0120)
22229| [78381] Oracle MySQL Server Unspecified Remote DoS (2012-0119)
22230| [78380] Oracle MySQL Server Unspecified Remote DoS (2012-0115)
22231| [78379] Oracle MySQL Server Unspecified Remote DoS (2012-0102)
22232| [78378] Oracle MySQL Server Unspecified Remote DoS (2012-0101)
22233| [78377] Oracle MySQL Server Unspecified Remote DoS (2012-0087)
22234| [78376] Oracle MySQL Server Unspecified Remote DoS (2011-2262)
22235| [78375] Oracle MySQL Server Unspecified Local DoS
22236| [78374] Oracle MySQL Server Unspecified Remote Issue (2012-0075)
22237| [78373] Oracle MySQL Server Unspecified Local Issue
22238| [78372] Oracle MySQL Server Unspecified Remote Information Disclosure
22239| [78371] Oracle MySQL Server Unspecified Remote Issue (2012-0496)
22240| [78370] Oracle MySQL Server Unspecified Remote Issue (2012-0118)
22241| [78369] Oracle MySQL Server Unspecified Remote Issue (2012-0116)
22242| [78368] Oracle MySQL Server Unspecified Remote Issue (2012-0113)
22243| [78283] Oracle MySQL NULL Pointer Dereference Packet Parsing Remote DoS
22244| [77042] e107 CMS install_.php MySQL Server Name Parsing Remote PHP Code Execution
22245| [77040] DBD::mysqlPP Unspecified SQL Injection
22246| [75888] TaskFreak! multi-mysql Multiple Script Direct Request Path Disclosure
22247| [74120] Apache HTTP Server mod_authnz_external mysql/mysql-auth.pl user Field SQL Injection
22248| [73555] Prosody MySQL Value Column Invalid Data Type Handling DoS
22249| [73387] Zend Framework PDO_MySql Character Set Security Bypass
22250| [72836] Arctic Fox CMS Multiple Script Direct Request MySQL Settings Disclosure
22251| [72660] MySQL GUI Tools Administrator / Query Browser Command Line Credentials Local Disclosure
22252| [72120] DirectAdmin mysql_backups Folder MySQL Database Backup Local Disclosure
22253| [71368] Accellion File Transfer Appliance Weak MySQL root Password
22254| [70967] MySQL Eventum Admin User Creation CSRF
22255| [70966] MySQL Eventum preferences.php full_name Parameter XSS
22256| [70961] MySQL Eventum list.php Multiple Parameter XSS
22257| [70960] MySQL Eventum forgot_password.php URI XSS
22258| [70947] PyWebDAV DAVServer/mysqlauth.py get_userinfo() Multiple Parameter SQL Injection
22259| [70610] PHP MySQLi Extension set_magic_quotes_runtime Function mysqli_fetch_assoc Function Interaction Weakness
22260| [69885] SilverStripe modules/sapphire/trunk/core/model/MySQLDatabase.php showqueries Parameter SQL Command Disclosure
22261| [69395] MySQL Derived Table Grouping DoS
22262| [69394] MySQL Temporary Table Expression Re-Evaluation DoS
22263| [69393] MySQL GROUP_CONCAT() WITH ROLLUP Modifier DoS
22264| [69392] MySQL Extreme-Value Functions Mixed Arguments DoS
22265| [69391] MySQL Stored Procedures / Prepared Statements Nested Joins DoS
22266| [69390] MySQL Extreme-Value Functions Argument Parsing Type Error DoS
22267| [69389] MySQL CONVERT_TZ() Function Empty SET Column DoS
22268| [69388] MySQL InnoDB Storage Engine Table Handling Overflow
22269| [69387] MySQL LIKE Predicates Pre-Evaluation DoS
22270| [69001] MySQL PolyFromWKB() Function WKB Data Remote DoS
22271| [69000] MySQL HANDLER Interface Unspecified READ Request DoS
22272| [68997] MySQL Prepared-Statement Mode EXPLAIN DoS
22273| [68996] MySQL EXPLAIN EXTENDED Statement DoS
22274| [68995] MySQL GeometryCollection non-Geometry Value Assignment DoS
22275| [67488] phpMyAdmin libraries/dbi/mysqli.dbi.lib.php Unspecified Parameter XSS
22276| [67487] phpMyAdmin libraries/dbi/mysql.dbi.lib.php Unspecified Parameter XSS
22277| [67421] PHP Mysqlnd Extension mysqlnd_wireprotocol.c php_mysqlnd_rset_header_read Function Overflow
22278| [67420] PHP Mysqlnd Extension mysqlnd_wireprotocol.c php_mysqlnd_ok_read Function Arbitrary Memory Content Disclosure
22279| [67419] PHP Mysqlnd Extension php_mysqlnd_read_error_from_line Function Negative Buffer Length Value Overflow
22280| [67418] PHP Mysqlnd Extension php_mysqlnd_auth_write Function Multiple Overflows
22281| [67384] MySQL LOAD DATA INFILE Statement Incorrect OK Packet DoS
22282| [67383] MySQL EXPLAIN Statement Item_singlerow_subselect::store Function NULL Dereference DoS
22283| [67381] MySQL InnoDB Temporary Table Handling DoS
22284| [67380] MySQL BINLOG Statement Unspecified Argument DoS
22285| [67379] MySQL Multiple Operation NULL Argument Handling DoS
22286| [67378] MySQL Unique SET Column Join Statement Remote DoS
22287| [67377] MySQL DDL Statement Multiple Configuration Parameter DoS
22288| [66800] PHP Multiple mysqlnd_* Function Unspecified Overflow
22289| [66799] PHP mysqlnd Error Packet Handling Multiple Overflows
22290| [66731] PHP Bundled MySQL Library Unspecified Issue
22291| [66665] PHP MySQL LOAD DATA LOCAL open_basedir Bypass
22292| [65851] MySQL ALTER DATABASE #mysql50# Prefix Handling DoS
22293| [65450] phpGraphy mysql_cleanup.php include_path Parameter Remote File Inclusion
22294| [65085] MySQL Enterprise Monitor Unspecified CSRF
22295| [64843] MySQL DROP TABLE Command Symlink MyISAM Table Local Data Deletion
22296| [64588] MySQL sql/net_serv.cc my_net_skip_rest Function Large Packet Handling Remote DoS
22297| [64587] MySQL COM_FIELD_LIST Command Packet Table Name Argument Overflow
22298| [64586] MySQL COM_FIELD_LIST Command Packet Authentication Bypass
22299| [64524] Advanced Poll misc/get_admin.php mysql_host Parameter XSS
22300| [64447] Tirzen Framework (TZN) tzn_mysql.php Username Parameter SQL Injection Authentication Bypass
22301| [64320] ClanSphere MySQL Driver s_email Parameter SQL Injection
22302| [63903] MySQL sql/sql_plugin.cc mysql_uninstall_plugin Function UNINSTALL PLUGIN Command Privilege Check Weakness
22303| [63115] Quicksilver Forums mysqldump Process List Database Password Disclosure
22304| [62830] Employee Timeclock Software mysqldump Command-line Database Password Disclosure
22305| [62640] PHP mysqli_real_escape_string() Function Error Message Path Disclosure
22306| [62216] Flex MySQL Connector ActionScript SQL Query Arbitrary Code Execution
22307| [61752] kiddog_mysqldumper Extension for TYPO3 Unspecified Information Disclosure
22308| [61497] microTopic admin/mysql.php rating Parameter SQL Injection
22309| [60665] MySQL CREATE TABLE MyISAM Table mysql_unpacked_real_data_home Local Restriction Bypass
22310| [60664] MySQL sql/sql_table.cc Data Home Directory Symlink CREATE TABLE Access Restriction Bypass
22311| [60516] RADIO istek scripti estafresgaftesantusyan.inc Direct Request MySQL Database Credentials Disclosure
22312| [60489] MySQL GeomFromWKB() Function First Argument Geometry Value Handling DoS
22313| [60488] MySQL SELECT Statement WHERE Clause Sub-query DoS
22314| [60487] MySQL vio_verify_callback() Function Crafted Certificate MiTM Weakness
22315| [60356] MySql Client Library (libmysqlclient) mysql_real_connect Function Local Overflow
22316| [59907] MySQL on Windows bind-address Remote Connection Weakness
22317| [59906] MySQL on Windows Default Configuration Logging Weakness
22318| [59616] MySQL Hashed Password Weakness
22319| [59609] Suckbot mod_mysql_logger Shared Object Unspecified Remote DoS
22320| [59495] Cyrus SASL LDAP / MySQL Authentication Patch password Field SQL Injection Authentication Bypass
22321| [59062] phpMyAdmin Extension for TYPO3 MySQL Table Name Unspecified XSS
22322| [59045] phpMyAdmin Crafted MYSQL Table Name XSS
22323| [59030] mysql-ocaml for MySQL mysql_real_escape_string() Function Character Escaping Weakness
22324| [57587] Zmanda Recovery Manager for MySQL socket-server.pl system() Function Local Privilege Escalation
22325| [57586] Zmanda Recovery Manager for MySQL socket-server.pl system() Function Remote Shell Command Execution
22326| [56741] MySQL Connector/J Unicode w/ SJIS/Windows-31J Charset SQL Injection
22327| [56134] Virtualmin MySQL Module Execute SQL Feature Arbitrary File Access
22328| [55734] MySQL sql_parse.cc dispatch_command() Function Format String DoS
22329| [55566] MySQL Connector/NET SSL Certificate Verification Weakness
22330| [53525] MyBlog /config/mysqlconnection.inc Direct Request Information Disclosure
22331| [53524] blog+ includes/window_top.php row_mysql_bloginfo[theme] Parameter Traversal Local File Inclusion
22332| [53523] blog+ includes/block_center_down.php row_mysql_blocks_center_down[file] Parameter Traversal Local File Inclusion
22333| [53522] blog+ includes/block_center_top.php row_mysql_blocks_center_top[file] Parameter Traversal Local File Inclusion
22334| [53521] blog+ includes/block_left.php row_mysql_blocks_left[file] Parameter Traversal Local File Inclusion
22335| [53520] blog+ includes/block_right.php row_mysql_blocks_right[file] Parameter Traversal Local File Inclusion
22336| [53519] blog+ includes/window_down.php row_mysql_bloginfo[theme] Parameter Traversal Local File Inclusion
22337| [53366] GEDCOM_TO_MYSQL php/info.php Multiple Parameter XSS
22338| [53365] GEDCOM_TO_MYSQL php/index.php nom_branche Parameter XSS
22339| [53364] GEDCOM_TO_MYSQL php/prenom.php Multiple Parameter XSS
22340| [53360] Blogplus includes/window_top.php row_mysql_bloginfo[theme] Parameter Traversal Local File Inclusion
22341| [53359] Blogplus includes/window_down.php row_mysql_bloginfo[theme] Parameter Traversal Local File Inclusion
22342| [53358] Blogplus includes/block_right.php row_mysql_blocks_right[file] Parameter Traversal Local File Inclusion
22343| [53357] Blogplus includes/block_left.php row_mysql_blocks_left[file] Parameter Traversal Local File Inclusion
22344| [53356] Blogplus block_center_top.php row_mysql_blocks_center_top[file] Parameter Traversal Local File Inclusion
22345| [53355] Blogplus includes/block_center_down.php row_mysql_blocks_center_down[file] Parameter Traversal Local File Inclusion
22346| [53110] XOOPS Cube Legacy ErrorHandler::show() Function MySQL Error Message XSS
22347| [52729] Asterisk-addon cdr_addon_mysql.c Call Detail Record SQL Injection
22348| [52728] Tribox cdr_addon_mysql.c Call Detail Record XSS
22349| [52727] FreePBX cdr_addon_mysql.c Call Detail Record XSS
22350| [52726] Areski cdr_addon_mysql.c Call Detail Record XSS
22351| [52464] MySQL charset Column Truncation Weakness
22352| [52453] MySQL sql/item_xmlfunc.cc ExtractValue() / UpdateXML() Functions Scalar XPath DoS
22353| [52378] Cisco ANM MySQL root Account Default Password
22354| [52264] Broadcast Machine MySQLController.php controllers/baseDir Parameter Remote File Inclusion
22355| [51923] Apache HTTP Server mod-auth-mysql Module mod_auth_mysql.c Multibyte Character Encoding SQL Injection
22356| [51171] MySQL InnoDB convert_search_mode_to_innobase Function DoS
22357| [50892] MySQL Calendar index.php username Parameter SQL Injection
22358| [50827] Nodstrum MySQL Calendar nodstrumCalendarV2 Cookie Manipulation Admin Authentication Bypass
22359| [49875] PromoteWeb MySQL go.php id Parameter SQL Injection
22360| [48710] MySQL Command Line Client HTML Output XSS
22361| [48709] MySQL Quick Admin actions.php lang Parameter Traversal Local File Inclusion
22362| [48708] MySQL Quick Admin index.php language Cookie Traversal Local File Inclusion
22363| [48021] MySQL Empty Bit-String Literal Token SQL Statement DoS
22364| [47789] mysql-lists Unspecified XSS
22365| [47394] Keld PHP-MySQL News Script login.php username Parameter SQL Injection
22366| [45073] MySQLDumper Extension for TYPO3 Unspecified Authentication Bypass
22367| [44937] MySQL MyISAM Table CREATE TABLE Privilege Check Bypass
22368| [44138] Debian GNU/Linux libdspam7-drv-mysql Cron MySQL dspam Database Password Local Disclosure
22369| [44071] Phorum /include/db/mysql.php Unspecified Search SQL Injection
22370| [43180] MySQL sql_select.cc INFORMATION_SCHEMA Table Crafted Query Remote DoS
22371| [43179] MySQL Server BINLOG Statement Rights Checking Failure
22372| [42610] MySQL DEFINER View Value Crafted Statements Remote Privilege Escalation
22373| [42609] MySQL Federated Engine SHOW TABLE STATUS Query Remote DoS
22374| [42608] MySQL RENAME TABLE Symlink System Table Overwrite
22375| [42607] MySQL Multiple table-level DIRECTORY Remote Privilege Escalation
22376| [42460] MySQLDumper HTTP POST Request Remote Authentication Bypass
22377| [42423] AdventNet EventLog Analyzer MySQL Installation Default root Account
22378| [41861] Bacula make_catalog_backup Function MySQL Director Password Cleartext Disclosure
22379| [40232] PHP MySQL Banner Exchange inc/lib.inc Direct Request Database Disclosure
22380| [40188] Password Manager Pro (PMP) mysql Unspecified Remote Command Injection
22381| [39279] PHP mysql_error() Function XSS
22382| [39145] aurora framework db_mysql.lib pack_var() value Parameter SQL Injection
22383| [38567] NetClassifieds Mysql_db.php Halt_On_Error Setting Error Message Path Disclosure
22384| [38112] Excel Parser Pro sample/xls2mysql parser_path Parameter Remote File Inclusion
22385| [37880] Asterisk-Addons source/destination Numbers cdr_addon_mysql Module SQL Injection
22386| [37784] PHP MySQL Extension Multiple Function Security Restriction Bypass
22387| [37783] MySQL Community Server CREATE TABLE LIKE Table Structure Disclosure
22388| [37782] MySQL Community Server External Table View Privilege Escalation
22389| [37781] MySQL ALTER TABLE Information Disclosure
22390| [37539] GPL PHP Board db.mysql.inc.php root_path Parameter Remote File Inclusion
22391| [37195] Eve-Nuke Module for PHP-Nuke db/mysql.php phpbb_root_path
22392| [37015] paBugs class.mysql.php path_to_bt_dir Parameter Remote File Inclusion
22393| [36868] PHP MySQLi Extension LOCAL INFILE Operation Security Restriction Bypass
22394| [36867] PHP MySQL Extension LOCAL INFILE Operation Security Restriction Bypass
22395| [36771] InterWorx-CP SiteWorx mysql.php PATH_INFO Parameter XSS
22396| [36757] InterWorx-CP NodeWorx mysql.php PATH_INFO Parameter XSS
22397| [36732] MySQL Community Server Connection Protocol Malformed Password Packet Remote DoS
22398| [36251] Associated Press (AP) Newspower Default MySQL root Password
22399| [35168] Study Planner (Studiewijzer) db/mysql/db.inc.php SPL_CFG[dirroot] Parameter Remote File Inclusion
22400| [35037] Fantastico for cPanel includes/mysqlconfig.php fantasticopath Parameter Traversal Local File Inclusion
22401| [34780] Backup Manager Command Line Cleartext MySQL Password Disclosure
22402| [34766] MySQL RENAME TABLE Statement Arbitrary Table Name Modification
22403| [34765] MySQL mysql_change_db Function THD::db_access Privilege Escalation
22404| [34734] MySQL Crafted IF Clause Divide-by-zero NULL Dereference DoS
22405| [34038] MySQL Commander ressourcen/dbopen.php home Parameter Remote File Inclusion
22406| [33974] MySQL information_schema Table Subselect Single-Row DoS
22407| [33678] MySQLNewsEngine affichearticles.php3 newsenginedir Parameter Remote File Inclusion
22408| [33447] WGS-PPC (PPC Search Engine) config/mysql_config.php INC Parameter Remote File Inclusion
22409| [33372] deV!L'z Clanportal inc/filebrowser/browser.php MySQL Data Disclosure
22410| [33147] ActiveCalendar data/mysqlevents.php css Parameter XSS
22411| [32784] Storystream mysqli.php baseDir Parameter Remote File Inclusion
22412| [32783] Storystream mysql.php baseDir Parameter Remote File Inclusion
22413| [32421] Contenido CMS conlib/db_mysqli.inc Direct Request Path Disclosure
22414| [32272] JevonCMS /phplib/db_mysql.inc Direct Request Path Disclosure
22415| [32171] Blue Magic Board db_mysql_error.php Direct Request Path Disclosure
22416| [32056] BTSaveMySql Direct Request Config File Disclosure
22417| [32044] cPanel WebHost Manager (WHM) scripts/passwdmysql password Parameter XSS
22418| [32024] TikiWiki tiki-wiki_rss.php ver MySQL Credential Disclosure
22419| [31963] Agora MysqlfinderAdmin.php _SESSION[PATH_COMPOSANT] Parameter Remote File Inclusion
22420| [31431] ZoomStats libs/dbmax/mysql.php GLOBALS[lib][db][path] Parameter Remote File Inclusion
22421| [30172] TikiWiki Multiple Script Empty sort_mode Parameter MySQL Authentication Credential Disclosure
22422| [29696] MySQLDumper sql.php db Parameter XSS
22423| [29453] ConPresso CMS db_mysql.inc.php msg Parameter XSS
22424| [29122] cPanel mysqladmin/hooksadmin Unspecified Privilege Escalation
22425| [28296] MySQL Crafted multiupdate / subselects Query Local DoS
22426| [28288] MySQL Instance_options::complete_initialization Function Overflow
22427| [28030] Tutti Nova class.novaRead.mysql.php TNLIB_DIR Parameter Remote File Inclusion
22428| [28029] Tutti Nova class.novaAdmin.mysql.php TNLIB_DIR Parameter Remote File Inclusion
22429| [28028] Tutti Nova class.novaEdit.mysql.php TNLIB_DIR Parameter Remote File Inclusion
22430| [28013] MySQL SUID Routine Miscalculation Arbitrary DML Statement Execution
22431| [28012] MySQL Case Sensitivity Unauthorized Database Creation
22432| [27919] MySQL VIEW Access information_schema.views Information Disclosure
22433| [27703] MySQL MERGE Table Privilege Persistence
22434| [27593] Drupal database.mysqli.inc Multiple Parameter SQL Injection
22435| [27549] Opsware NAS /etc/init.d/mysqll MySQL root Cleartext Password Local Disclosure
22436| [27416] MySQL Server time.cc date_format Function Format String
22437| [27054] MySQL mysqld str_to_date Function NULL Argument DoS
22438| [26923] PHP/MySQL Classifieds (PHP Classifieds) search.php rate Parameter SQL Injection
22439| [26922] PHP/MySQL Classifieds (PHP Classifieds) AddAsset1.php Multiple Field XSS
22440| [26822] Bee-hive Lite include/listall.inc.php mysqlcall Parameter Remote File Inclusion
22441| [26821] Bee-hive Lite conad/include/mysqlCall.inc.php config Parameter Remote File Inclusion
22442| [26820] Bee-hive Lite conad/logout.inc.php mysqlCall Parameter Remote File Inclusion
22443| [26819] Bee-hive Lite conad/login.inc.php mysqlCall Parameter Remote File Inclusion
22444| [26818] Bee-hive Lite conad/checkPasswd.inc.php mysqlCall Parameter Remote File Inclusion
22445| [26817] Bee-hive Lite conad/changeUserDetails.inc.php mysqlCall Parameter Remote File Inclusion
22446| [26816] Bee-hive Lite conad/changeEmail.inc.php mysqlCall Parameter Remote File Inclusion
22447| [26125] Open Searchable Image Catalogue core.php do_mysql_query Function Error Message XSS
22448| [26123] Open Searchable Image Catalogue core.php do_mysql_query Function SQL Injection
22449| [25987] MySQL Multibyte Encoding SQL Injection Filter Bypass
22450| [25908] Drupal database.mysql.inc Multiple Parameter SQL Injection
22451| [25595] Apple Mac OS X MySQL Manager Blank root Password
22452| [25228] MySQL Crafted COM_TABLE_DUMP Request Arbitrary Memory Disclosure
22453| [25227] MySQL COM_TABLE_DUMP Packet Overflow
22454| [25226] MySQL Malformed Login Packet Remote Memory Disclosure
22455| [24245] Cholod Mysql Based Message Board Unspecified XSS
22456| [24244] Cholod Mysql Based Message Board mb.cgi showmessage Action SQL Injection
22457| [23963] WoltLab Burning Board class_db_mysql.php SQL Error Message XSS
22458| [23915] Netcool/NeuSecure MySQL Database Connection Restriction Bypass
22459| [23611] Aztek Forum index.php msg Variable Forced MySQL Error Information Disclosure
22460| [23526] MySQL Query NULL Charcter Logging Bypass
22461| [23157] PHP/MYSQL Timesheet changehrs.php Multiple Parameter SQL Injection
22462| [23156] PHP/MYSQL Timesheet index.php Multiple Parameter SQL Injection
22463| [22995] PAM-MySQL Authentication pam_get_item() Function Unspecified Privilege Escalation
22464| [22994] PAM-MySQL SQL Logging Facility Segfault DoS
22465| [22485] Recruitment Software admin/site.xml MySQL Authentication Credential Disclosure
22466| [22479] PHP mysqli Extension Error Message Format String
22467| [22232] PHP Pipe Variable mysql_connect() Function Overflow
22468| [21685] MySQL Auction Search Module keyword XSS
22469| [20698] Campsite notifyendsubs Cron MySQL Password Cleartext Remote Disclosure
22470| [20145] Proofpoint Protection Server Embedded MySQL Server Unpassworded root Account
22471| [19457] aMember Pro mysql.inc.php Remote File Inclusion
22472| [19377] MAXdev MD-Pro /MySQL_Tools/admin.php Path Disclosure
22473| [18899] MySQL UDF Library Arbitrary Function Load Privilege Escalation
22474| [18898] MySQL UDF LoadLibraryEx Function Nonexistent Library Load DoS
22475| [18897] MySQL on Windows UDF Create Function Traversal Privilege Escalation
22476| [18896] MySQL User-Defined Function init_syms() Function Overflow
22477| [18895] MySQL libmysqlclient.so host Parameter Remote Overflow
22478| [18894] MySQL drop database Request Remote Overflow
22479| [18622] FunkBoard mysql_install.php Email Field Arbitrary PHP Code Injection
22480| [18620] FunkBoard mysql_install.php Admin/Database Password Manipulation
22481| [18406] MySQL Eventum releases.php SQL Injection
22482| [18405] MySQL Eventum custom_fields_graph.php SQL Injection
22483| [18404] MySQL Eventum custom_fields.php SQL Injection
22484| [18403] MySQL Eventum login.php email Parameter SQL Injection Authentication Bypass
22485| [18402] MySQL Eventum get_jsrs_data.php F Parameter XSS
22486| [18401] MySQL Eventum list.php release Parameter XSS
22487| [18400] MySQL Eventum view.php id Parameter XSS
22488| [18173] MySQL on Windows USE Command MS-DOS Device Name DoS
22489| [17801] Bugzilla MySQL Replication Race Condition Information Disclosure
22490| [17223] xMySQLadmin Symlink Arbitrary File Deletion
22491| [16727] MySQL Nonexistent '--user' Error Incorrect Privilege Database Invocation
22492| [16689] MySQL mysql_install_db Symlink Arbitrary File Overwrite
22493| [16056] Plans Unspecified mySQL Remote Password Disclosure
22494| [15993] MySQL MaxDB Webtool Remote getIfHeader() WebDAV Function Remote Overflow
22495| [15817] MySQL MaxDB Web Tool getLockTokenHeader() Function Remote Overflow
22496| [15816] MySQL MaxDB Web Administration Service Malformed GET Request Overflow
22497| [15451] paNews auth.php mysql_prefix Parameter SQL Injection
22498| [14748] MySQL MS-DOS Device Names Request DoS
22499| [14678] MySQL CREATE FUNCTION Arbitrary libc Code Execution
22500| [14677] MySQL CREATE FUNCTION mysql.func Table Arbitrary Library Injection
22501| [14676] MySQL CREATE TEMPORARY TABLE Symlink Privilege Escalation
22502| [14386] phpMyAdmin mysqli.dbi.lib.php Path Disclosure
22503| [14052] Symantec Brightmail AntiSpam Multiple Default MySQL Accounts
22504| [13086] MySQL MaxDB Web Agent Malformed HTTP Header DoS
22505| [13085] MySQL MaxDB Web Agent WebDAV sapdbwa_GetUserData() Function Remote DoS
22506| [13013] MySQL mysqlaccess.sh Symlink Arbitrary File Manipulation
22507| [12919] MySQL MaxDB WebAgent websql Remote Overflow
22508| [12779] MySQL User Defined Function Privilege Escalation
22509| [12609] MySQL Eventum projects.php Multiple Parameter XSS
22510| [12608] MySQL Eventum preferences.php Multiple Parameter XSS
22511| [12607] MySQL Eventum forgot_password.php email Parameter XSS
22512| [12606] MySQL Eventum index.php email Parameter XSS
22513| [12605] MySQL Eventum Default Vendor Account
22514| [12275] MySQL MaxDB Web Tools wahttp Nonexistent File Request DoS
22515| [12274] MySQL MaxDB Web Tools WebDAV Handler Remote Overflow
22516| [11689] Roxen Web Server MySQL Socket Permission Weakness
22517| [10985] MySQL MATCH..AGAINST Query DoS
22518| [10959] MySQL GRANT ALL ON Privilege Escalation
22519| [10660] MySQL ALTER TABLE/RENAME Forces Old Permission Checks
22520| [10659] MySQL ALTER MERGE Tables to Change the UNION DoS
22521| [10658] MySQL mysql_real_connect() Function Remote Overflow
22522| [10532] MySQL MaxDB webdbm Server Field DoS
22523| [10491] AWS MySQLguest AWSguest.php Script Insertion
22524| [10244] MySQL libmysqlclient Prepared Statements API Overflow
22525| [10226] MySQLGuest AWSguest.php Multiple Field XSS
22526| [9912] PHP safe_mode MySQL Database Access Restriction Bypass
22527| [9911] Inter7 vpopmail MySQL Module Authentication Credential Disclosure
22528| [9910] MySQL mysql_change_user() Double-free Memory Pointer DoS
22529| [9909] MySQL datadir/my.cnf Modification Privilege Escalation
22530| [9908] MySQL my.ini Initialization File datadir Parameter Overflow
22531| [9907] MySQL SELECT Statement String Handling Overflow
22532| [9906] MySQL GRANT Privilege Arbitrary Password Modification
22533| [9509] teapop MySQL Authentication Module SQL Injection
22534| [9018] MySQL Backup Pro getbackup() Method Unspecified Issue
22535| [9015] MySQL mysqlhotcopy Insecure Temporary File Creation
22536| [8997] Cacti config.php MySQL Authentication Credential Cleartext Disclosure
22537| [8979] MySQL SHOW GRANTS Encrypted Password Disclosure
22538| [8889] MySQL COM_TABLE_DUMP Package Negative Integer DoS
22539| [8888] MySQL COM_CHANGE_USER Command Long Repsonse Overflow
22540| [8887] MySQL COM_CHANGE_USER Command One Character Password Brute Force
22541| [8886] MySQL libmysqlclient Library read_one_row Overflow
22542| [8885] MySQL libmysqlclient Library read_rows Overflow
22543| [7476] MySQL Protocol 4.1 Authentication Scramble String Overflow
22544| [7475] MySQL Zero-length Scrambled String Crafted Packet Authentication Bypass
22545| [7245] MySQL Pluggable Authentication Module (pam_mysql) Password Disclosure
22546| [7128] MySQL show database Database Name Exposure
22547| [6716] MySQL Database Engine Weak Authentication Information Disclosure
22548| [6605] MySQL mysqld Readable Log File Information Disclosure
22549| [6443] PowerPhlogger db_dump.php View Arbitrary mySQL Dump
22550| [6421] MySQL mysqld_multi Symlink Arbitrary File Overwrite
22551| [6420] MySQL mysqlbug Symlink Arbitrary File Overwrite
22552| [2537] MySQL sql_acl.cc get_salt_from_password Function Password Handling Remote Overflow
22553| [2144] WinMySQLadmin my.ini Cleartext Password Disclosure
22554| [653] PCCS-Linux MySQL Database Admin Tool Authentication Credential Disclosure
22555| [520] MySQL Database Name Traversal Arbitrary File Modification
22556| [380] MySQL Server on Windows Default Null Root Password
22557| [261] MySQL Short Check String Authentication Bypass
22558|_
22559Service Info: Host: xbabes.com
22560################################################################################################################################
22561 Anonymous JTSEC #OpDeathEathers Full Recon #34