· 6 years ago · Jan 19, 2020, 10:24 AM
1#######################################################################################################################################
2======================================================================================================================================
3 Hostname www.sinjyuku-taruichi.co.jp ISP GMO Internet,Inc
4Continent Asia Flag
5JP
6Country Japan Country Code JP
7Region Unknown Local time 19 Jan 2020 18:22 JST
8City Unknown Postal Code Unknown
9IP Address 133.130.64.112 Latitude 35.69
10 Longitude 139.69
11=======================================================================================================================================
12#######################################################################################################################################
13> www.sinjyuku-taruichi.co.jp
14Server: 38.132.106.139
15Address: 38.132.106.139#53
16
17Non-authoritative answer:
18Name: www.sinjyuku-taruichi.co.jp
19Address: 133.130.64.112
20>
21#######################################################################################################################################
22omain Information:
23a. [Domain Name] SINJYUKU-TARUICHI.CO.JP
24g. [Organization] Kabusikigaisyaneoyunibasu
25l. [Organization Type] corporation
26m. [Administrative Contact] SS37693JP
27n. [Technical Contact] SS37694JP
28p. [Name Server] dns01.gmoserver.jp
29p. [Name Server] dns02.gmoserver.jp
30s. [Signing Key]
31[State] Connected (2020/01/31)
32[Registered Date] 2018/01/05
33[Connected Date] 2018/01/05
34[Last Update] 2019/08/21 07:53:58 (JST)
35#######################################################################################################################################
36[+] Target : www.sinjyuku-taruichi.co.jp
37
38[+] IP Address : 133.130.64.112
39
40[+] Headers :
41
42[+] Date : Sun, 19 Jan 2020 09:28:28 GMT
43[+] Server : Apache
44[+] Last-Modified : Mon, 06 Jan 2020 05:41:54 GMT
45[+] Accept-Ranges : bytes
46[+] Content-Length : 4489
47[+] Keep-Alive : timeout=5, max=100
48[+] Connection : Keep-Alive
49[+] Content-Type : text/html
50
51[+] SSL Certificate Information :
52
53[+] organizationalUnitName : Domain Control Validated
54[+] commonName : *.gmoserver.jp
55[+] countryName : BE
56[+] organizationName : GlobalSign nv-sa
57[+] commonName : GlobalSign RSA DV SSL CA 2018
58[+] Version : 3
59[+] Serial Number : 5AD28AD71E87898D07DF7F50
60[+] Not Before : Dec 20 06:01:34 2019 GMT
61[+] Not After : Feb 14 07:59:06 2022 GMT
62[+] OCSP : ('http://ocsp.globalsign.com/gsrsadvsslca2018',)
63[+] subject Alt Name : (('DNS', '*.gmoserver.jp'), ('DNS', 'gmoserver.jp'))
64[+] CA Issuers : ('http://secure.globalsign.com/cacert/gsrsadvsslca2018.crt',)
65[+] CRL Distribution Points : ('http://crl.globalsign.com/gsrsadvsslca2018.crl',)
66
67[+] Whois Lookup :
68
69[+] NIR : {'query': '133.130.64.112', 'raw': None, 'nets': [{'cidr': '133.130.64.0/24', 'name': 'GMO Internet, Inc.', 'handle': 'SD', 'range': '133.130.64.1 - 133.130.64.255', 'country': 'JP', 'address': None, 'postal_code': None, 'nameservers': ['ns1.gmointernet.com', 'ns1.gmointernet.jp'], 'created': None, 'updated': '2019-01-04T06:02:05', 'contacts': {'admin': {'email': 'hosting-ipinfo@gmo.jp', 'organization': 'GMO Internet,Inc', 'division': '', 'phone': '03-5456-2555', 'fax': '', 'updated': '2012-05-08T11:50:03'}, 'tech': {'email': 'hosting-ipinfo@gmo.jp', 'organization': 'GMO Internet,Inc', 'division': '', 'phone': '03-5456-2555', 'fax': '', 'updated': '2012-05-08T11:50:03'}}}]}
70[+] ASN Registry : apnic
71[+] ASN : 7506
72[+] ASN CIDR : 133.130.64.0/18
73[+] ASN Country Code : JP
74[+] ASN Date : 1997-03-01
75[+] ASN Description : INTERQ GMO Internet,Inc, JP
76[+] cidr : 133.0.0.0/8
77[+] name : JPNIC-NET-JP-ERX
78[+] handle : JNIC1-AP
79[+] range : 133.0.0.0 - 133.255.255.255
80[+] description : Japan Network Information Center
81[+] country : JP
82[+] state : None
83[+] city : None
84[+] address : Urbannet-Kanda Bldg 4F
853-6-2 Uchi-Kanda
86Chiyoda-ku, Tokyo 101-0047,Japan
87[+] postal_code : None
88[+] emails : ['hostmaster@nic.ad.jp']
89[+] created : None
90[+] updated : None
91
92[+] Crawling Target...
93
94[+] Looking for robots.txt........[ Not Found ]
95[+] Looking for sitemap.xml.......[ Not Found ]
96[+] Extracting CSS Links..........[ 1 ]
97[+] Extracting Javascript Links...[ 0 ]
98[+] Extracting Internal Links.....[ 0 ]
99[+] Extracting External Links.....[ 4 ]
100[+] Extracting Images.............[ 10 ]
101
102[+] Total Links Extracted : 15
103
104[+] Dumping Links in /opt/FinalRecon/dumps/www.sinjyuku-taruichi.co.jp.dump
105[+] Completed!
106#######################################################################################################################################
107[i] Scanning Site: http://133.130.64.112
108
109
110
111B A S I C I N F O
112====================
113
114
115[+] Site Title:
116[+] IP address: 133.130.64.112
117[+] Web Server: Apache
118[+] CMS: Could Not Detect
119[+] Cloudflare: Not Detected
120[+] Robots File: Could NOT Find robots.txt!
121
122
123
124
125W H O I S L O O K U P
126========================
127
128 % This is the RIPE Database query service.
129% The objects are in RPSL format.
130%
131% The RIPE Database is subject to Terms and Conditions.
132% See http://www.ripe.net/db/support/db-terms-conditions.pdf
133
134% Note: this output has been filtered.
135% To receive output for a database update, use the "-B" flag.
136
137% Information related to '132.253.0.0 - 133.255.255.255'
138
139% No abuse contact registered for 132.253.0.0 - 133.255.255.255
140
141inetnum: 132.253.0.0 - 133.255.255.255
142netname: NON-RIPE-NCC-MANAGED-ADDRESS-BLOCK
143descr: IPv4 address block not managed by the RIPE NCC
144remarks: ------------------------------------------------------
145remarks:
146remarks: For registration information,
147remarks: you can consult the following sources:
148remarks:
149remarks: IANA
150remarks: http://www.iana.org/assignments/ipv4-address-space
151remarks: http://www.iana.org/assignments/iana-ipv4-special-registry
152remarks: http://www.iana.org/assignments/ipv4-recovered-address-space
153remarks:
154remarks: AFRINIC (Africa)
155remarks: http://www.afrinic.net/ whois.afrinic.net
156remarks:
157remarks: APNIC (Asia Pacific)
158remarks: http://www.apnic.net/ whois.apnic.net
159remarks:
160remarks: ARIN (Northern America)
161remarks: http://www.arin.net/ whois.arin.net
162remarks:
163remarks: LACNIC (Latin America and the Carribean)
164remarks: http://www.lacnic.net/ whois.lacnic.net
165remarks:
166remarks: ------------------------------------------------------
167country: EU # Country is really world wide
168admin-c: IANA1-RIPE
169tech-c: IANA1-RIPE
170status: ALLOCATED UNSPECIFIED
171mnt-by: RIPE-NCC-HM-MNT
172created: 2019-01-07T10:46:31Z
173last-modified: 2019-01-07T10:46:31Z
174source: RIPE
175
176% This query was served by the RIPE Database Query Service version 1.96 (BLAARKOP)
177
178
179
180
181
182
183G E O I P L O O K U P
184=========================
185
186[i] IP Address: 133.130.64.112
187[i] Country: Japan
188[i] State:
189[i] City:
190[i] Latitude: 35.69
191[i] Longitude: 139.69
192
193
194
195
196H T T P H E A D E R S
197=======================
198
199
200[i] HTTP/1.1 404 Not Found
201[i] Date: Sun, 19 Jan 2020 09:28:50 GMT
202[i] Server: Apache
203[i] Last-Modified: Wed, 02 Aug 2017 08:47:14 GMT
204[i] Accept-Ranges: bytes
205[i] Content-Length: 1242
206[i] Connection: close
207[i] Content-Type: text/html
208
209
210
211
212D N S L O O K U P
213===================
214
215no records found
216
217
218
219S U B N E T C A L C U L A T I O N
220====================================
221
222Address = 133.130.64.112
223Network = 133.130.64.112 / 32
224Netmask = 255.255.255.255
225Broadcast = not needed on Point-to-Point links
226Wildcard Mask = 0.0.0.0
227Hosts Bits = 0
228Max. Hosts = 1 (2^0 - 0)
229Host Range = { 133.130.64.112 - 133.130.64.112 }
230
231
232
233N M A P P O R T S C A N
234============================
235
236Starting Nmap 7.70 ( https://nmap.org ) at 2020-01-19 09:28 UTC
237Nmap scan report for www18.gmoserver.jp (133.130.64.112)
238Host is up (0.15s latency).
239
240PORT STATE SERVICE
24121/tcp closed ftp
24222/tcp closed ssh
24323/tcp closed telnet
24480/tcp open http
245110/tcp closed pop3
246143/tcp closed imap
247443/tcp open https
2483389/tcp closed ms-wbt-server
249
250Nmap done: 1 IP address (1 host up) scanned in 0.52 seconds
251#######################################################################################################################################
252[+] Starting At 2020-01-19 04:30:19.943036
253[+] Collecting Information On: http://www.sinjyuku-taruichi.co.jp/
254[#] Status: 200
255--------------------------------------------------
256[#] Web Server Detected: Apache
257[!] X-Frame-Options Headers not detect! target might be vulnerable Click Jacking
258- Date: Sun, 19 Jan 2020 09:30:15 GMT
259- Server: Apache
260- Last-Modified: Mon, 06 Jan 2020 05:41:54 GMT
261- Accept-Ranges: bytes
262- Content-Length: 4489
263- Keep-Alive: timeout=5, max=100
264- Connection: Keep-Alive
265- Content-Type: text/html
266--------------------------------------------------
267[#] Finding Location..!
268[#] status: success
269[#] country: Japan
270[#] countryCode: JP
271[#] region: 13
272[#] regionName: Tokyo
273[#] city: Chiyoda
274[#] zip: 100-0001
275[#] lat: 35.6906
276[#] lon: 139.77
277[#] timezone: Asia/Tokyo
278[#] isp: Japan Network Information Center
279[#] org: GMO Internet, Inc.
280[#] as: AS7506 GMO Internet,Inc
281[#] query: 133.130.64.112
282--------------------------------------------------
283[x] Didn't Detect WAF Presence on: http://www.sinjyuku-taruichi.co.jp/
284--------------------------------------------------
285[#] Starting Reverse DNS
286[-] Failed ! Fail
287--------------------------------------------------
288[!] Scanning Open Port
289[#] 80/tcp open http
290[#] 443/tcp open https
291--------------------------------------------------
292[+] Getting SSL Info
293[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: Hostname mismatch, certificate is not valid for 'sinjyuku-taruichi.co.jp'. (_ssl.c:1076)
294--------------------------------------------------
295[+] Collecting Information Disclosure!
296[#] Detecting sitemap.xml file
297[-] sitemap.xml file not Found!?
298[#] Detecting robots.txt file
299[-] robots.txt file not Found!?
300[#] Detecting GNU Mailman
301[-] GNU Mailman App Not Detected!?
302--------------------------------------------------
303[+] Crawling Url Parameter On: http://www.sinjyuku-taruichi.co.jp/
304--------------------------------------------------
305[#] Searching Html Form !
306[-] No Html Form Found!?
307--------------------------------------------------
308[!] Found 1 dom parameter
309[#] http://www.sinjyuku-taruichi.co.jp//#
310--------------------------------------------------
311[-] No internal Dynamic Parameter Found!?
312--------------------------------------------------
313[-] No external Dynamic Paramter Found!?
314--------------------------------------------------
315[!] 5 Internal links Discovered
316[+] http://www.sinjyuku-taruichi.co.jp//index.css
317[+] http://www.sinjyuku-taruichi.co.jp//reservation.html
318[+] http://www.sinjyuku-taruichi.co.jp//kodawari.html
319[+] http://www.sinjyuku-taruichi.co.jp//tenpo.html
320[+] http://www.sinjyuku-taruichi.co.jp//honten_menu.html
321--------------------------------------------------
322[!] 4 External links Discovered
323[#] https://youtu.be/3JR55yZx5SQ
324[#] http://www.neouniverse.tokyo/story.html
325[#] http://www.neouniverse.tokyo/
326[#] http://www.neouniverse.tokyo/taruichi-kyujin.html
327--------------------------------------------------
328[#] Mapping Subdomain..
329[-] No Any Subdomain Found
330[!] Found 0 Subdomain
331--------------------------------------------------
332[!] Done At 2020-01-19 04:30:38.046882
333#######################################################################################################################################
334[INFO] ------TARGET info------
335[*] TARGET: http://www.sinjyuku-taruichi.co.jp/
336[*] TARGET IP: 133.130.64.112
337[INFO] NO load balancer detected for www.sinjyuku-taruichi.co.jp...
338[*] DNS servers: dns01.gmoserver.jp.
339[*] TARGET server: Apache
340[*] CC: JP
341[*] Country: Japan
342[*] RegionCode: 13
343[*] RegionName: Tokyo
344[*] City: Chiyoda
345[*] ASN: AS7506
346[*] BGP_PREFIX: 133.130.64.0/18
347[*] ISP: INTERQ GMO Internet,Inc, JP
348[INFO] DNS enumeration:
349[*] ftp.sinjyuku-taruichi.co.jp 133.130.64.114
350[*] mx.sinjyuku-taruichi.co.jp 133.130.64.116
351[INFO] Possible abuse mails are:
352[*] abuse@gmo.jp
353[*] abuse@sinjyuku-taruichi.co.jp
354[*] abuse@www.sinjyuku-taruichi.co.jp
355[INFO] NO PAC (Proxy Auto Configuration) file FOUND
356[INFO] Starting FUZZing in http://www.sinjyuku-taruichi.co.jp/FUzZzZzZzZz...
357[INFO] Status code Folders
358[ALERT] Look in the source code. It may contain passwords
359[INFO] Links found from http://www.sinjyuku-taruichi.co.jp/ http://133.130.64.112/:
360[*] https://www.facebook.com/plugins/page.php?href=https://www.facebook.com/樽一-166700486707000/&tabs=timeline&width=380&height=330&small_header=false&adapt_container_width=true&hide_cover=false&show_facepile=true&appId
361[*] https://youtu.be/3JR55yZx5SQ
362[*] http://www.neouniverse.tokyo/
363[*] http://www.neouniverse.tokyo/story.html
364[*] http://www.neouniverse.tokyo/taruichi-kyujin.html
365[*] http://www.onamae.com/?banner_id=634
366[*] http://www.onamae-server.com/
367[*] http://www.sinjyuku-taruichi.co.jp/
368[*] http://www.sinjyuku-taruichi.co.jp/honten_menu.html
369[*] http://www.sinjyuku-taruichi.co.jp/kodawari.html
370[*] http://www.sinjyuku-taruichi.co.jp/reservation.html
371[*] http://www.sinjyuku-taruichi.co.jp/tenpo.html
372cut: intervalle de champ incorrecte
373Saisissez « cut --help » pour plus d'informations.
374[INFO] Shodan detected the following opened ports on 133.130.64.112:
375[*] 0
376[*] 443
377[*] 80
378[INFO] ------VirusTotal SECTION------
379[INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
380[INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
381[INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
382[INFO] ------Alexa Rank SECTION------
383[INFO] Percent of Visitors Rank in Country:
384[INFO] Percent of Search Traffic:
385[INFO] Percent of Unique Visits:
386[INFO] Total Sites Linking In:
387[*] Total Sites
388[INFO] Useful links related to www.sinjyuku-taruichi.co.jp - 133.130.64.112:
389[*] https://www.virustotal.com/pt/ip-address/133.130.64.112/information/
390[*] https://www.hybrid-analysis.com/search?host=133.130.64.112
391[*] https://www.shodan.io/host/133.130.64.112
392[*] https://www.senderbase.org/lookup/?search_string=133.130.64.112
393[*] https://www.alienvault.com/open-threat-exchange/ip/133.130.64.112
394[*] http://pastebin.com/search?q=133.130.64.112
395[*] http://urlquery.net/search.php?q=133.130.64.112
396[*] http://www.alexa.com/siteinfo/www.sinjyuku-taruichi.co.jp
397[*] http://www.google.com/safebrowsing/diagnostic?site=www.sinjyuku-taruichi.co.jp
398[*] https://censys.io/ipv4/133.130.64.112
399[*] https://www.abuseipdb.com/check/133.130.64.112
400[*] https://urlscan.io/search/#133.130.64.112
401[*] https://github.com/search?q=133.130.64.112&type=Code
402[INFO] Useful links related to AS7506 - 133.130.64.0/18:
403[*] http://www.google.com/safebrowsing/diagnostic?site=AS:7506
404[*] https://www.senderbase.org/lookup/?search_string=133.130.64.0/18
405[*] http://bgp.he.net/AS7506
406[*] https://stat.ripe.net/AS7506
407[INFO] Date: 19/01/20 | Time: 04:31:22
408[INFO] Total time: 0 minute(s) and 50 second(s)
409#######################################################################################################################################
410Trying "sinjyuku-taruichi.co.jp"
411;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 44213
412;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0
413
414;; QUESTION SECTION:
415;sinjyuku-taruichi.co.jp. IN ANY
416
417;; ANSWER SECTION:
418sinjyuku-taruichi.co.jp. 600 IN SOA dns01.gmoserver.jp. hostmaster.sinjyuku-taruichi.co.jp. 2018020203 28800 7200 604800 600
419sinjyuku-taruichi.co.jp. 600 IN MX 10 mx18.gmoserver.jp.
420sinjyuku-taruichi.co.jp. 600 IN A 133.130.64.112
421sinjyuku-taruichi.co.jp. 600 IN TXT "v=spf1 include:spf18.gmoserver.jp ~all"
422sinjyuku-taruichi.co.jp. 600 IN NS dns01.gmoserver.jp.
423sinjyuku-taruichi.co.jp. 600 IN NS dns02.gmoserver.jp.
424
425Received 226 bytes from 2001:18c0:121:6900:724f:b8ff:fefd:5b6a#53 in 421 ms
426######################################################################################################################################
427
428; <<>> DiG 9.11.5-P4-5.1+b1-Debian <<>> +trace sinjyuku-taruichi.co.jp any
429;; global options: +cmd
430. 85411 IN NS i.root-servers.net.
431. 85411 IN NS g.root-servers.net.
432. 85411 IN NS a.root-servers.net.
433. 85411 IN NS c.root-servers.net.
434. 85411 IN NS m.root-servers.net.
435. 85411 IN NS d.root-servers.net.
436. 85411 IN NS l.root-servers.net.
437. 85411 IN NS e.root-servers.net.
438. 85411 IN NS b.root-servers.net.
439. 85411 IN NS h.root-servers.net.
440. 85411 IN NS k.root-servers.net.
441. 85411 IN NS f.root-servers.net.
442. 85411 IN NS j.root-servers.net.
443. 85411 IN RRSIG NS 8 0 518400 20200201050000 20200119040000 33853 . zmM/gCiOlLmdrcx1+Ae8f4vXVmEtCAXXPhHJqMb961AXYWvZuEn3BWPM Tna3OX1y2igyKyCGE5fgYMz7y3XGxwpmPIP2xD9XswGsrzBhqsyCq+kg Is2+iTIy2vTfPnsmLCx/id/H6Sn9XzAFwt/omepqOMQQdt/TsRDZUrV9 5X1LuL0ulI/Dm2wu8lart4Zv8RnGNsbABoVzs9KFwUwqItP5QDa6thja SbLwqOhV0tY0zyZ45lXfDWCvTmVRvyZ2NcamONxWDzTEutf2X9uGayjq Yd+bA0ebXTRv3nkEJet82QbGP9xdPvIapeJ2vQosPYdXFkqpAp5FP3Q7 Mu85hQ==
444;; Received 525 bytes from 38.132.106.139#53(38.132.106.139) in 156 ms
445
446jp. 172800 IN NS a.dns.jp.
447jp. 172800 IN NS b.dns.jp.
448jp. 172800 IN NS c.dns.jp.
449jp. 172800 IN NS d.dns.jp.
450jp. 172800 IN NS e.dns.jp.
451jp. 172800 IN NS f.dns.jp.
452jp. 172800 IN NS g.dns.jp.
453jp. 172800 IN NS h.dns.jp.
454jp. 86400 IN DS 39595 8 1 1CC05D3654844B375BE8FDFB8933A21C9E9897DD
455jp. 86400 IN DS 39595 8 2 2871D562754FD45AC0452440D806ABB8E6BA967B2032B166FD2761E8 73553387
456jp. 86400 IN RRSIG DS 8 1 86400 20200201050000 20200119040000 33853 . hmRn8aCNVdDKRxHU7SKsYtqiLr5/7g3b0J+7WRp+8x3ParsyK+yE0OtT eNOv3jn2JBopqop08+R3QTCrvG8mA9cG8dhZTGVviKfw7aWSvxQxBSNj q4k8bMVIsRsopzC51mQS9bbDZniynQ+oO+oYaseFYgavbN9lD9m1BSYC lihqX9D+1f29nyB+PEqraZOySEAwuYnQnXgaV7i2DmxCGw+1jgueBJQk 5pLBnTd8BcZPOianamXweLc2IMId+LDkKHEhqrSzopKpjCzzqijGLQ0v 9HUaK0ntok0J7m68dszbBFBbJd5bn2Ci7uJYnjcEaeaf9a7oQmtDaIA8 20Q6Yg==
457;; Received 879 bytes from 2001:503:c27::2:30#53(j.root-servers.net) in 150 ms
458
459sinjyuku-taruichi.co.jp. 86400 IN NS dns01.gmoserver.jp.
460sinjyuku-taruichi.co.jp. 86400 IN NS dns02.gmoserver.jp.
461C0TKH27SBTDJ80JJM75A6OC1VODH95FE.jp. 900 IN NSEC3 1 1 5 F07F38698C C1DM9UBG36HHH1SLU9ARR061EKTKL7DO TXT RRSIG
462C0TKH27SBTDJ80JJM75A6OC1VODH95FE.jp. 900 IN RRSIG NSEC3 8 2 900 20200217174502 20200118174502 58203 jp. icUJUkptggqsuL/U73JpoZhbifNESc+3Rjcf5+ptUhRlXpHYtQLvtDfV fQ8lcrok5oPQRe+D4ahq3HGouxO3mQaIlSCZv7lkzPwhXaSguyvD/TfG FwnOFAHjZT1MLoqd4AZIFo4/qiZAKXpRSpTCdHiRtvGJEW72h/JhRmYo z2s=
463G94RICS8AC0PUR8MKIK035MGVEGO66P2.jp. 900 IN NSEC3 1 1 5 F07F38698C GASFF3A5CQIB5UQCEL24JDFSLNIVU0A3 TXT RRSIG
464G94RICS8AC0PUR8MKIK035MGVEGO66P2.jp. 900 IN RRSIG NSEC3 8 2 900 20200217174502 20200118174502 58203 jp. 0//jElK7RBaMQJuJmfPeu9jfILvVMijTfyHR9L+YvYnmftgBqJGWRcAC 2J5nZYRWrYG6ANdoW1p6ymotuG33uUqMkWsjkuo9GS9Rb/HYkpNwjRgd RBm6qegk236zAQ7Z99/I5PyukKabDDbdYzt7oOt+SrhhCToHcXcMCbDL JnU=
465;; Received 622 bytes from 2001:502:ad09::5#53(c.dns.jp) in 32 ms
466
467sinjyuku-taruichi.co.jp. 600 IN TXT "v=spf1 include:spf18.gmoserver.jp ~all"
468sinjyuku-taruichi.co.jp. 600 IN A 133.130.64.112
469sinjyuku-taruichi.co.jp. 600 IN MX 10 mx18.gmoserver.jp.
470sinjyuku-taruichi.co.jp. 600 IN NS dns01.gmoserver.jp.
471sinjyuku-taruichi.co.jp. 600 IN NS dns02.gmoserver.jp.
472sinjyuku-taruichi.co.jp. 600 IN SOA dns01.gmoserver.jp. hostmaster.sinjyuku-taruichi.co.jp. 2018020203 28800 7200 604800 600
473;; Received 297 bytes from 157.7.231.209#53(dns02.gmoserver.jp) in 257 ms
474######################################################################################################################################
475[*] Performing General Enumeration of Domain: sinjyuku-taruichi.co.jp
476[-] DNSSEC is not configured for sinjyuku-taruichi.co.jp
477[*] SOA dns01.gmoserver.jp 163.44.90.113
478[*] NS dns02.gmoserver.jp 157.7.231.209
479[*] Bind Version for 157.7.231.209 C-64 DNS Responder (QBasic 0.96) 1984
480[*] NS dns01.gmoserver.jp 163.44.90.113
481[*] Bind Version for 163.44.90.113 C-64 DNS Responder (QBasic 0.96) 1984
482[*] MX mx18.gmoserver.jp 133.130.64.116
483[*] A sinjyuku-taruichi.co.jp 133.130.64.112
484[*] TXT sinjyuku-taruichi.co.jp v=spf1 include:spf18.gmoserver.jp ~all
485[*] Enumerating SRV Records
486[-] No SRV Records Found for sinjyuku-taruichi.co.jp
487[+] 0 Records Found
488#######################################################################################################################################
489[*] Processing domain sinjyuku-taruichi.co.jp
490[*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
491[+] Getting nameservers
492157.7.231.209 - dns02.gmoserver.jp
493163.44.90.113 - dns01.gmoserver.jp
494[-] Zone transfer failed
495
496[+] TXT records found
497"v=spf1 include:spf18.gmoserver.jp ~all"
498
499[+] MX records found, added to target list
50010 mx18.gmoserver.jp.
501
502[*] Scanning sinjyuku-taruichi.co.jp for A records
503133.130.64.112 - sinjyuku-taruichi.co.jp
504133.130.64.114 - ftp.sinjyuku-taruichi.co.jp
505133.130.64.115 - imap.sinjyuku-taruichi.co.jp
506133.130.64.116 - mx.sinjyuku-taruichi.co.jp
507133.130.64.115 - pop.sinjyuku-taruichi.co.jp
508133.130.64.117 - smtp.sinjyuku-taruichi.co.jp
509133.130.64.112 - www.sinjyuku-taruichi.co.jp
510######################################################################################################################################
511
512 AVAILABLE PLUGINS
513 -----------------
514
515 SessionResumptionPlugin
516 CertificateInfoPlugin
517 SessionRenegotiationPlugin
518 HeartbleedPlugin
519 OpenSslCipherSuitesPlugin
520 CompressionPlugin
521 FallbackScsvPlugin
522 HttpHeadersPlugin
523 RobotPlugin
524 EarlyDataPlugin
525 OpenSslCcsInjectionPlugin
526
527
528
529 CHECKING HOST(S) AVAILABILITY
530 -----------------------------
531
532 133.130.64.112:443 => 133.130.64.112
533
534
535
536
537 SCAN RESULTS FOR 133.130.64.112:443 - 133.130.64.112
538 ----------------------------------------------------
539
540 * SSLV2 Cipher Suites:
541 Server rejected all cipher suites.
542
543 * OpenSSL CCS Injection:
544 OK - Not vulnerable to OpenSSL CCS injection
545
546 * Session Renegotiation:
547 Client-initiated Renegotiation: OK - Rejected
548 Secure Renegotiation: OK - Supported
549
550 * TLS 1.2 Session Resumption Support:
551 With Session IDs: NOT SUPPORTED (0 successful, 5 failed, 0 errors, 5 total attempts).
552 With TLS Tickets: OK - Supported
553
554 * OpenSSL Heartbleed:
555 OK - Not vulnerable to Heartbleed
556
557 * TLSV1_3 Cipher Suites:
558 Server rejected all cipher suites.
559
560 * SSLV3 Cipher Suites:
561 Server rejected all cipher suites.
562
563 * Deflate Compression:
564 OK - Compression disabled
565
566 * Certificate Information:
567 Content
568 SHA1 Fingerprint: 3e249581ec6ec03f94df7624da0eda39aa23759d
569 Common Name: *.gmoserver.jp
570 Issuer: GlobalSign RSA DV SSL CA 2018
571 Serial Number: 28108180960864618352320937808
572 Not Before: 2019-12-20 06:01:34
573 Not After: 2022-02-14 07:59:06
574 Signature Algorithm: sha256
575 Public Key Algorithm: RSA
576 Key Size: 2048
577 Exponent: 65537 (0x10001)
578 DNS Subject Alternative Names: ['*.gmoserver.jp', 'gmoserver.jp']
579
580 Trust
581 Hostname Validation: FAILED - Certificate does NOT match 133.130.64.112
582 Android CA Store (9.0.0_r9): OK - Certificate is trusted
583 Apple CA Store (iOS 12, macOS 10.14, watchOS 5, and tvOS 12):OK - Certificate is trusted
584 Java CA Store (jdk-12.0.1): OK - Certificate is trusted
585 Mozilla CA Store (2019-03-14): OK - Certificate is trusted
586 Windows CA Store (2019-05-27): OK - Certificate is trusted
587 Symantec 2018 Deprecation: WARNING: Certificate distrusted by Google and Mozilla on September 2018
588 Received Chain: *.gmoserver.jp --> GlobalSign RSA DV SSL CA 2018
589 Verified Chain: *.gmoserver.jp --> GlobalSign RSA DV SSL CA 2018 --> GlobalSign
590 Received Chain Contains Anchor: OK - Anchor certificate not sent
591 Received Chain Order: OK - Order is valid
592 Verified Chain contains SHA1: OK - No SHA1-signed certificate in the verified certificate chain
593
594 Extensions
595 OCSP Must-Staple: NOT SUPPORTED - Extension not found
596 Certificate Transparency: OK - 3 SCTs included
597
598 OCSP Stapling
599 NOT SUPPORTED - Server did not send back an OCSP response
600
601 * TLSV1_1 Cipher Suites:
602 Server rejected all cipher suites.
603
604 * Downgrade Attacks:
605 TLS_FALLBACK_SCSV: OK - Supported
606
607 * TLSV1_2 Cipher Suites:
608 Forward Secrecy OK - Supported
609 RC4 OK - Not Supported
610
611 Preferred:
612 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 404 Not Found
613 Accepted:
614 TLS_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 404 Not Found
615 TLS_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 404 Not Found
616 TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
617 TLS_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 404 Not Found
618 TLS_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 404 Not Found
619 TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 404 Not Found
620 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 404 Not Found
621 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 256 bits HTTP 404 Not Found
622 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
623 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 404 Not Found
624 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 404 Not Found
625 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 404 Not Found
626 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 404 Not Found
627 TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 404 Not Found
628 TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 404 Not Found
629 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 404 Not Found
630 TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 404 Not Found
631 TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 404 Not Found
632
633 * TLSV1 Cipher Suites:
634 Server rejected all cipher suites.
635
636 * ROBOT Attack:
637 OK - Not vulnerable
638
639
640 SCAN COMPLETED IN 25.12 S
641 -------------------------
642######################################################################################################################################
643Domains still to check: 1
644 Checking if the hostname sinjyuku-taruichi.co.jp. given is in fact a domain...
645
646Analyzing domain: sinjyuku-taruichi.co.jp.
647 Checking NameServers using system default resolver...
648 IP: 157.7.231.209 (Japan)
649 HostName: dns02.gmoserver.jp Type: NS
650 HostName: dns02.gmoserver.jp Type: PTR
651 IP: 163.44.90.113 (Japan)
652 HostName: dns01.gmoserver.jp Type: NS
653 HostName: dns01.gmoserver.jp Type: PTR
654
655 Checking MailServers using system default resolver...
656 IP: 133.130.64.116 (Japan)
657 HostName: mx18.gmoserver.jp Type: MX
658 HostName: mx18.gmoserver.jp Type: PTR
659
660 Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
661 No zone transfer found on nameserver 157.7.231.209
662 No zone transfer found on nameserver 163.44.90.113
663
664 Checking SPF record...
665
666 Checking SPF record...
667 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 133.130.64.120/29, but only the network IP
668 New IP found: 133.130.64.120
669 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 133.130.64.112/29, but only the network IP
670 New IP found: 133.130.64.112
671 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 157.7.183.0/24, but only the network IP
672 New IP found: 157.7.183.0
673 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 210.157.19.64/26, but only the network IP
674 New IP found: 210.157.19.64
675 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 157.7.151.0/24, but only the network IP
676 New IP found: 157.7.151.0
677 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 163.44.89.0/24, but only the network IP
678 New IP found: 163.44.89.0
679 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 150.95.48.0/24, but only the network IP
680 New IP found: 150.95.48.0
681
682 Checking SPF record...
683
684 Checking SPF record...
685 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 157.7.228.0/23, but only the network IP
686 New IP found: 157.7.228.0
687 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 157.7.224.144/28, but only the network IP
688 New IP found: 157.7.224.144
689 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 163.44.74.0/24, but only the network IP
690 New IP found: 163.44.74.0
691 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 157.7.174.0/24, but only the network IP
692 New IP found: 157.7.174.0
693 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 150.95.170.0/23, but only the network IP
694 New IP found: 150.95.170.0
695 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 118.27.82.0/23, but only the network IP
696 New IP found: 118.27.82.0
697 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 118.27.67.0/27, but only the network IP
698 New IP found: 118.27.67.0
699 WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 118.27.54.0/23, but only the network IP
700 New IP found: 118.27.54.0
701
702 Checking 192 most common hostnames using system default resolver...
703 IP: 133.130.64.112 (Japan)
704 Type: SPF
705 HostName: www.sinjyuku-taruichi.co.jp. Type: A
706 HostName: www18.gmoserver.jp Type: PTR
707 IP: 133.130.64.114 (Japan)
708 HostName: ftp.sinjyuku-taruichi.co.jp. Type: A
709 IP: 133.130.64.116 (Japan)
710 HostName: mx18.gmoserver.jp Type: MX
711 HostName: mx18.gmoserver.jp Type: PTR
712 HostName: mx.sinjyuku-taruichi.co.jp. Type: A
713 IP: 133.130.64.117 (Japan)
714 HostName: smtp.sinjyuku-taruichi.co.jp. Type: A
715 IP: 133.130.64.115 (Japan)
716 HostName: pop.sinjyuku-taruichi.co.jp. Type: A
717 IP: 133.130.64.115 (Japan)
718 HostName: pop.sinjyuku-taruichi.co.jp. Type: A
719 HostName: imap.sinjyuku-taruichi.co.jp. Type: A
720 HostName: pop18.gmoserver.jp Type: PTR
721
722 Checking with nmap the reverse DNS hostnames of every <ip>/24 netblock using system default resolver...
723 Checking netblock 163.44.90.0
724 Checking netblock 157.7.228.0
725 Checking netblock 133.130.64.0
726 Checking netblock 210.157.19.0
727 Checking netblock 157.7.231.0
728 Checking netblock 163.44.89.0
729 Checking netblock 157.7.151.0
730 Checking netblock 157.7.183.0
731 Checking netblock 157.7.224.0
732 Checking netblock 118.27.67.0
733 Checking netblock 157.7.174.0
734 Checking netblock 118.27.82.0
735 Checking netblock 118.27.54.0
736 Checking netblock 150.95.48.0
737 Checking netblock 163.44.74.0
738 Checking netblock 150.95.170.0
739
740 Searching for sinjyuku-taruichi.co.jp. emails in Google
741 taruichi@sinjyuku-taruichi.co.jp
742
743 Checking 21 active hosts using nmap... (nmap -sn -n -v -PP -PM -PS80,25 -PA -PY -PU53,40125 -PE --reason <ip> -oA <output_directory>/nmap/<ip>.sn)
744 Host 163.44.90.113 is up (reset ttl 64)
745 Host 157.7.228.0 is up (reset ttl 64)
746 Host 133.130.64.120 is up (reset ttl 64)
747 Host 133.130.64.115 is up (reset ttl 64)
748 Host 210.157.19.64 is up (reset ttl 64)
749 Host 157.7.231.209 is up (reset ttl 64)
750 Host 163.44.89.0 is up (reset ttl 64)
751 Host 133.130.64.114 is up (reset ttl 64)
752 Host 133.130.64.112 is up (reset ttl 64)
753 Host 157.7.151.0 is up (reset ttl 64)
754 Host 157.7.183.0 is up (reset ttl 64)
755 Host 133.130.64.117 is up (reset ttl 64)
756 Host 133.130.64.116 is up (reset ttl 64)
757 Host 157.7.224.144 is up (reset ttl 64)
758 Host 118.27.67.0 is up (reset ttl 64)
759 Host 157.7.174.0 is up (reset ttl 64)
760 Host 118.27.82.0 is up (reset ttl 64)
761 Host 118.27.54.0 is up (reset ttl 64)
762 Host 150.95.48.0 is up (reset ttl 64)
763 Host 163.44.74.0 is up (reset ttl 64)
764 Host 150.95.170.0 is up (reset ttl 64)
765
766 Checking ports on every active host using nmap... (nmap -O --reason --webxml --traceroute -sS -sV -sC -Pn -n -v -F <ip> -oA <output_directory>/nmap/<ip>)
767 Scanning ip 163.44.90.113 (dns01.gmoserver.jp (PTR)):
768 53/tcp open domain syn-ack ttl 45 (unknown banner: C-64 DNS Responder (QBasic 0.96) 1984)
769 | dns-nsid:
770 |_ bind.version: C-64 DNS Responder (QBasic 0.96) 1984
771 | fingerprint-strings:
772 | DNSVersionBindReqTCP:
773 | version
774 | bind
775 |_ &%C-64 DNS Responder (QBasic 0.96) 1984
776 Scanning ip 157.7.228.0 ():
777 Scanning ip 133.130.64.120 ():
778 Scanning ip 133.130.64.115 (pop18.gmoserver.jp (PTR)):
779 Scanning ip 210.157.19.64 ():
780 Scanning ip 157.7.231.209 (dns02.gmoserver.jp (PTR)):
781 53/tcp open domain syn-ack ttl 46 (unknown banner: C-64 DNS Responder (QBasic 0.96) 1984)
782 | dns-nsid:
783 |_ bind.version: C-64 DNS Responder (QBasic 0.96) 1984
784 | fingerprint-strings:
785 | DNSVersionBindReqTCP:
786 | version
787 | bind
788 |_ &%C-64 DNS Responder (QBasic 0.96) 1984
789 Scanning ip 163.44.89.0 ():
790 Scanning ip 133.130.64.114 (ftp.sinjyuku-taruichi.co.jp.):
791 21/tcp open ftp syn-ack ttl 46 ProFTPD 1.3.5
792 |_ssl-date: TLS randomness does not represent time
793 | vulners:
794 | cpe:/a:proftpd:proftpd:1.3.5:
795 | CVE-2015-3306 10.0 https://vulners.com/cve/CVE-2015-3306
796 | CVE-2019-19272 5.0 https://vulners.com/cve/CVE-2019-19272
797 | CVE-2019-19271 5.0 https://vulners.com/cve/CVE-2019-19271
798 |_ CVE-2013-4359 5.0 https://vulners.com/cve/CVE-2013-4359
799 80/tcp open http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
800 | http-methods:
801 |_ Supported Methods: GET HEAD POST OPTIONS
802 |_http-server-header: Apache/2.2.34 (Unix)
803 |_http-title: Did not follow redirect to https://sd-webmail18.rentalserver.jp/
804 | vulners:
805 | cpe:/a:apache:http_server:2.2.34:
806 | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
807 |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
808 389/tcp open ldap? syn-ack ttl 46
809 | fingerprint-strings:
810 | LDAPSearchReq:
811 | 0'0%
812 | objectClass1
813 |_ OpenLDAProotDSE0
814 443/tcp open ssl/http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
815 | http-git:
816 | 133.130.64.114:443/.git/
817 | Git repository found!
818 | Repository description: Unnamed repository; edit this file 'description' to name the...
819 | Remotes:
820 |_ https://sys-git.gmo.jp/shared-hosting/webtools/sd/roundcube
821 | http-methods:
822 |_ Supported Methods: GET HEAD POST OPTIONS
823 |_http-server-header: Apache/2.2.34 (Unix)
824 |_http-title: \xE3\x81\x8A\xE5\x90\x8D\xE5\x89\x8D.com Webmail :: \xE3\x81\x8A\xE5\x90\x8D\xE5\x89\x8D.com Webmail\xE3\x81\xAB\xE3\x82\x88\xE3\x81\x86\xE3\x81\x93\xE3\x81\x9D
825 | ssl-cert: Subject: commonName=*.rentalserver.jp
826 | Subject Alternative Name: DNS:*.rentalserver.jp, DNS:rentalserver.jp
827 | Issuer: commonName=GlobalSign RSA DV SSL CA 2018/organizationName=GlobalSign nv-sa/countryName=BE
828 | Public Key type: rsa
829 | Public Key bits: 2048
830 | Signature Algorithm: sha256WithRSAEncryption
831 | Not valid before: 2019-12-23T07:02:26
832 | Not valid after: 2021-03-14T10:30:09
833 | MD5: 33c6 0448 4d43 e82f d3c3 85de 1c57 35b6
834 |_SHA-1: d05a e65c 9657 2f23 e7a7 0389 6783 c759 1ae3 f5ae
835 |_ssl-date: TLS randomness does not represent time
836 | vulners:
837 | cpe:/a:apache:http_server:2.2.34:
838 | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
839 |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
840 5666/tcp open tcpwrapped syn-ack ttl 46
841 8443/tcp open ssl/http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
842 | http-cookie-flags:
843 | /:
844 | PHPSESSID:
845 |_ httponly flag not set
846 | http-methods:
847 |_ Supported Methods: GET HEAD POST OPTIONS
848 |_http-server-header: Apache/2.2.34 (Unix)
849 |_http-title: ZERO Filemanager
850 | ssl-cert: Subject: commonName=*.rentalserver.jp
851 | Subject Alternative Name: DNS:*.rentalserver.jp, DNS:rentalserver.jp
852 | Issuer: commonName=GlobalSign RSA DV SSL CA 2018/organizationName=GlobalSign nv-sa/countryName=BE
853 | Public Key type: rsa
854 | Public Key bits: 2048
855 | Signature Algorithm: sha256WithRSAEncryption
856 | Not valid before: 2019-12-23T07:02:26
857 | Not valid after: 2021-03-14T10:30:09
858 | MD5: 33c6 0448 4d43 e82f d3c3 85de 1c57 35b6
859 |_SHA-1: d05a e65c 9657 2f23 e7a7 0389 6783 c759 1ae3 f5ae
860 |_ssl-date: TLS randomness does not represent time
861 | vulners:
862 | cpe:/a:apache:http_server:2.2.34:
863 | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
864 |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
865 OS Info: Service Info: OS: Unix
866 Scanning ip 133.130.64.112 (www18.gmoserver.jp (PTR)):
867 80/tcp open http syn-ack ttl 42 Apache httpd
868 | http-methods:
869 |_ Supported Methods: GET HEAD POST OPTIONS
870 |_http-server-header: Apache
871 |_http-title: 404 Error - Not Found
872 443/tcp open ssl/http syn-ack ttl 42 Apache httpd
873 |_http-server-header: Apache
874 |_http-title: 403 Forbidden
875 | ssl-cert: Subject: commonName=*.gmoserver.jp
876 | Subject Alternative Name: DNS:*.gmoserver.jp, DNS:gmoserver.jp
877 | Issuer: commonName=GlobalSign RSA DV SSL CA 2018/organizationName=GlobalSign nv-sa/countryName=BE
878 | Public Key type: rsa
879 | Public Key bits: 2048
880 | Signature Algorithm: sha256WithRSAEncryption
881 | Not valid before: 2019-12-20T06:01:34
882 | Not valid after: 2022-02-14T07:59:06
883 | MD5: 607a b818 8000 9d67 3207 4386 b763 75a9
884 |_SHA-1: 3e24 9581 ec6e c03f 94df 7624 da0e da39 aa23 759d
885 |_ssl-date: TLS randomness does not represent time
886 Device type: storage-misc|general purpose
887 Running (JUST GUESSING): HP embedded (86%), Sun Solaris 9|10 (85%), Sun OpenSolaris (85%)
888 Scanning ip 157.7.151.0 ():
889 Scanning ip 157.7.183.0 ():
890 Scanning ip 133.130.64.117 (smtp.sinjyuku-taruichi.co.jp.):
891 80/tcp open http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
892 | http-methods:
893 |_ Supported Methods: POST OPTIONS GET HEAD
894 |_http-server-header: Apache/2.2.34 (Unix)
895 |_http-title: Site doesn't have a title (text/html).
896 | vulners:
897 | cpe:/a:apache:http_server:2.2.34:
898 | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
899 |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
900 443/tcp open ssl/http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
901 | http-methods:
902 |_ Supported Methods: GET HEAD POST OPTIONS
903 |_http-server-header: Apache/2.2.34 (Unix)
904 | http-title: [\xE3\x83\xAD\xE3\x82\xB0\xE3\x82\xA4\xE3\x83\xB3]
905 |_Requested resource was /login.php
906 | ssl-cert: Subject: commonName=*.rentalserver.jp
907 | Subject Alternative Name: DNS:*.rentalserver.jp, DNS:rentalserver.jp
908 | Issuer: commonName=GlobalSign RSA DV SSL CA 2018/organizationName=GlobalSign nv-sa/countryName=BE
909 | Public Key type: rsa
910 | Public Key bits: 2048
911 | Signature Algorithm: sha256WithRSAEncryption
912 | Not valid before: 2019-12-23T07:02:26
913 | Not valid after: 2021-03-14T10:30:09
914 | MD5: 33c6 0448 4d43 e82f d3c3 85de 1c57 35b6
915 |_SHA-1: d05a e65c 9657 2f23 e7a7 0389 6783 c759 1ae3 f5ae
916 |_ssl-date: TLS randomness does not represent time
917 | vulners:
918 | cpe:/a:apache:http_server:2.2.34:
919 | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
920 |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
921 465/tcp open ssl/smtps? syn-ack ttl 46
922 |_smtp-commands: Couldn't establish connection on port 465
923 |_ssl-date: TLS randomness does not represent time
924 587/tcp open smtp syn-ack ttl 46 Postfix smtpd
925 |_smtp-commands: smtp18.gmoserver.jp, PIPELINING, SIZE 150000000, ETRN, STARTTLS, AUTH PLAIN LOGIN, AUTH=PLAIN LOGIN, ENHANCEDSTATUSCODES, 8BITMIME, DSN,
926 |_ssl-date: TLS randomness does not represent time
927 Device type: storage-misc|general purpose
928 Running (JUST GUESSING): HP embedded (86%), Sun Solaris 9|10 (85%), Sun OpenSolaris (85%)
929 OS Info: Service Info: Host: smtp18.gmoserver.jp
930 Scanning ip 133.130.64.116 (mx.sinjyuku-taruichi.co.jp.):
931 Scanning ip 157.7.224.144 ():
932 Scanning ip 118.27.67.0 ():
933 Scanning ip 157.7.174.0 ():
934 Scanning ip 118.27.82.0 ():
935 Scanning ip 118.27.54.0 ():
936 Scanning ip 150.95.48.0 ():
937 Scanning ip 163.44.74.0 ():
938 Scanning ip 150.95.170.0 ():
939 WebCrawling domain's web servers... up to 50 max links.
940
941 + URL to crawl: http://ftp.sinjyuku-taruichi.co.jp.
942 + Date: 2020-01-19
943
944 + Crawling URL: http://ftp.sinjyuku-taruichi.co.jp.:
945 + Links:
946 + Crawling http://ftp.sinjyuku-taruichi.co.jp.
947 + Crawling http://ftp.sinjyuku-taruichi.co.jp./skins/larry/styles.min.css?s=1570769197 (File! Not crawling it.)
948 + Crawling http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/themes/larry/jquery-ui.css?s=1570769196 (File! Not crawling it.)
949 + Crawling http://ftp.sinjyuku-taruichi.co.jp./skins/larry/ui.min.js?s=1570769197 (File! Not crawling it.)
950 + Crawling http://ftp.sinjyuku-taruichi.co.jp./skins/rs/rs.css?s=1570769197 (File! Not crawling it.)
951 + Crawling http://ftp.sinjyuku-taruichi.co.jp./skins/rs/js/jquery-3.3.1.min.js?s=1570769197 (File! Not crawling it.)
952 + Crawling http://ftp.sinjyuku-taruichi.co.jp./skins/rs/js/login.js?s=1571300831 (File! Not crawling it.)
953 + Crawling http://ftp.sinjyuku-taruichi.co.jp./program/js/jquery.min.js?s=1570769196 (File! Not crawling it.)
954 + Crawling http://ftp.sinjyuku-taruichi.co.jp./program/js/common.min.js?s=1570769196 (File! Not crawling it.)
955 + Crawling http://ftp.sinjyuku-taruichi.co.jp./program/js/app.min.js?s=1570769196 (File! Not crawling it.)
956 + Crawling http://ftp.sinjyuku-taruichi.co.jp./program/js/jstz.min.js?s=1570769196 (File! Not crawling it.)
957 + Crawling http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/js/jquery-ui.min.js?s=1570769196 (File! Not crawling it.)
958 + Crawling http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/js/i18n/jquery.ui.datepicker-ja.js?s=1570769196 (File! Not crawling it.)
959 + Crawling http://ftp.sinjyuku-taruichi.co.jp./skins/rs/images/logo_white.svg (File! Not crawling it.)
960 + Searching for directories...
961 - Found: http://ftp.sinjyuku-taruichi.co.jp./skins/
962 - Found: http://ftp.sinjyuku-taruichi.co.jp./skins/larry/
963 - Found: http://ftp.sinjyuku-taruichi.co.jp./skins/larry/images/
964 - Found: http://ftp.sinjyuku-taruichi.co.jp./skins/rs/
965 - Found: http://ftp.sinjyuku-taruichi.co.jp./skins/rs/images/
966 - Found: http://ftp.sinjyuku-taruichi.co.jp./plugins/
967 - Found: http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/
968 - Found: http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/themes/
969 - Found: http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/themes/larry/
970 - Found: http://ftp.sinjyuku-taruichi.co.jp./skins/rs/js/
971 - Found: http://ftp.sinjyuku-taruichi.co.jp./program/
972 - Found: http://ftp.sinjyuku-taruichi.co.jp./program/js/
973 - Found: http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/js/
974 - Found: http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/js/i18n/
975 + Searching open folders...
976 - http://ftp.sinjyuku-taruichi.co.jp./skins/ (403 Forbidden)
977 - http://ftp.sinjyuku-taruichi.co.jp./skins/larry/ (403 Forbidden)
978 - http://ftp.sinjyuku-taruichi.co.jp./skins/larry/images/ (403 Forbidden)
979 - http://ftp.sinjyuku-taruichi.co.jp./skins/rs/ (403 Forbidden)
980 - http://ftp.sinjyuku-taruichi.co.jp./skins/rs/images/ (403 Forbidden)
981 - http://ftp.sinjyuku-taruichi.co.jp./plugins/ (403 Forbidden)
982 - http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/ (403 Forbidden)
983 - http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/themes/ (403 Forbidden)
984 - http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/themes/larry/ (403 Forbidden)
985 - http://ftp.sinjyuku-taruichi.co.jp./skins/rs/js/ (403 Forbidden)
986 - http://ftp.sinjyuku-taruichi.co.jp./program/ (403 Forbidden)
987 - http://ftp.sinjyuku-taruichi.co.jp./program/js/ (403 Forbidden)
988 - http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/js/ (403 Forbidden)
989 - http://ftp.sinjyuku-taruichi.co.jp./plugins/jqueryui/js/i18n/ (403 Forbidden)
990
991
992 + URL to crawl: https://ftp.sinjyuku-taruichi.co.jp.
993 + Date: 2020-01-19
994
995 + Crawling URL: https://ftp.sinjyuku-taruichi.co.jp.:
996 + Links:
997 + Crawling https://ftp.sinjyuku-taruichi.co.jp.
998 + Searching for directories...
999 + Searching open folders...
1000
1001
1002 + URL to crawl: https://ftp.sinjyuku-taruichi.co.jp.:8443
1003 + Date: 2020-01-19
1004
1005 + Crawling URL: https://ftp.sinjyuku-taruichi.co.jp.:8443:
1006 + Links:
1007 + Crawling https://ftp.sinjyuku-taruichi.co.jp.:8443 ([Errno 111] Connection refused)
1008 + Searching for directories...
1009 + Searching open folders...
1010
1011
1012 + URL to crawl: http://www.sinjyuku-taruichi.co.jp.
1013 + Date: 2020-01-19
1014
1015 + Crawling URL: http://www.sinjyuku-taruichi.co.jp.:
1016 + Links:
1017 + Crawling http://www.sinjyuku-taruichi.co.jp.
1018 + Crawling http://www.sinjyuku-taruichi.co.jp./reservation.html
1019 + Crawling http://www.sinjyuku-taruichi.co.jp./kodawari.html
1020 + Crawling http://www.sinjyuku-taruichi.co.jp./tenpo.html
1021 + Crawling http://www.sinjyuku-taruichi.co.jp./honten_menu.html
1022 + Crawling http://www.sinjyuku-taruichi.co.jp./index.html
1023 + Crawling http://www.sinjyuku-taruichi.co.jp./miuraya_menu.html
1024 + Crawling http://www.sinjyuku-taruichi.co.jp./honten_coursemenu.html
1025 + Searching for directories...
1026 - Found: http://www.sinjyuku-taruichi.co.jp./images/
1027 - Found: http://www.sinjyuku-taruichi.co.jp./images/header/
1028 - Found: http://www.sinjyuku-taruichi.co.jp./images/yoyaku/
1029 - Found: http://www.sinjyuku-taruichi.co.jp./images/kodawari/
1030 - Found: http://www.sinjyuku-taruichi.co.jp./images/tenpo/
1031 - Found: http://www.sinjyuku-taruichi.co.jp./images/menu/
1032 + Searching open folders...
1033 - http://www.sinjyuku-taruichi.co.jp./images/ (403 Forbidden)
1034 - http://www.sinjyuku-taruichi.co.jp./images/header/ (403 Forbidden)
1035 - http://www.sinjyuku-taruichi.co.jp./images/yoyaku/ (403 Forbidden)
1036 - http://www.sinjyuku-taruichi.co.jp./images/kodawari/ (403 Forbidden)
1037 - http://www.sinjyuku-taruichi.co.jp./images/tenpo/ (403 Forbidden)
1038 - http://www.sinjyuku-taruichi.co.jp./images/menu/ (403 Forbidden)
1039 + Crawl finished successfully.
1040----------------------------------------------------------------------
1041Summary of http://http://www.sinjyuku-taruichi.co.jp.
1042----------------------------------------------------------------------
1043+ Links crawled:
1044 - http://www.sinjyuku-taruichi.co.jp.
1045 - http://www.sinjyuku-taruichi.co.jp./honten_coursemenu.html
1046 - http://www.sinjyuku-taruichi.co.jp./honten_menu.html
1047 - http://www.sinjyuku-taruichi.co.jp./index.html
1048 - http://www.sinjyuku-taruichi.co.jp./kodawari.html
1049 - http://www.sinjyuku-taruichi.co.jp./miuraya_menu.html
1050 - http://www.sinjyuku-taruichi.co.jp./reservation.html
1051 - http://www.sinjyuku-taruichi.co.jp./tenpo.html
1052 Total links crawled: 8
1053
1054+ Links to files found:
1055 - http://www.sinjyuku-taruichi.co.jp./honten_coursemenu.css
1056 - http://www.sinjyuku-taruichi.co.jp./honten_menu.css
1057 - http://www.sinjyuku-taruichi.co.jp./images/header/kigyou.png
1058 - http://www.sinjyuku-taruichi.co.jp./images/header/kodawari.png
1059 - http://www.sinjyuku-taruichi.co.jp./images/header/kodawari_over.png
1060 - http://www.sinjyuku-taruichi.co.jp./images/header/logo.png
1061 - http://www.sinjyuku-taruichi.co.jp./images/header/menu.png
1062 - http://www.sinjyuku-taruichi.co.jp./images/header/menu_over.png
1063 - http://www.sinjyuku-taruichi.co.jp./images/header/monogatari.png
1064 - http://www.sinjyuku-taruichi.co.jp./images/header/saiyou.png
1065 - http://www.sinjyuku-taruichi.co.jp./images/header/tenpo_chizu.png
1066 - http://www.sinjyuku-taruichi.co.jp./images/header/tenpo_chizu_over.png
1067 - http://www.sinjyuku-taruichi.co.jp./images/jouhou.png
1068 - http://www.sinjyuku-taruichi.co.jp./images/kigyou.png
1069 - http://www.sinjyuku-taruichi.co.jp./images/kodawari.png
1070 - http://www.sinjyuku-taruichi.co.jp./images/kodawari/kujira.png
1071 - http://www.sinjyuku-taruichi.co.jp./images/kodawari/nihonsyu.png
1072 - http://www.sinjyuku-taruichi.co.jp./images/kodawari/nihonsyu2.png
1073 - http://www.sinjyuku-taruichi.co.jp./images/kodawari/sanriku.png
1074 - http://www.sinjyuku-taruichi.co.jp./images/kodawari/title.png
1075 - http://www.sinjyuku-taruichi.co.jp./images/logo_top.png
1076 - http://www.sinjyuku-taruichi.co.jp./images/menu.png
1077 - http://www.sinjyuku-taruichi.co.jp./images/menu/enkai_course.png
1078 - http://www.sinjyuku-taruichi.co.jp./images/menu/enkai_course2.png
1079 - http://www.sinjyuku-taruichi.co.jp./images/menu/gnavi.png
1080 - http://www.sinjyuku-taruichi.co.jp./images/menu/groundmenu.png
1081 - http://www.sinjyuku-taruichi.co.jp./images/menu/honten.png
1082 - http://www.sinjyuku-taruichi.co.jp./images/menu/honten_over.png
1083 - http://www.sinjyuku-taruichi.co.jp./images/menu/miuraya.png
1084 - http://www.sinjyuku-taruichi.co.jp./images/menu/miuraya_over.png
1085 - http://www.sinjyuku-taruichi.co.jp./images/monogatari.png
1086 - http://www.sinjyuku-taruichi.co.jp./images/movie.png
1087 - http://www.sinjyuku-taruichi.co.jp./images/saiyou.png
1088 - http://www.sinjyuku-taruichi.co.jp./images/seki_jouhou.png
1089 - http://www.sinjyuku-taruichi.co.jp./images/tenpo/jouhou_bl.png
1090 - http://www.sinjyuku-taruichi.co.jp./images/tenpo/jouhou_wh.png
1091 - http://www.sinjyuku-taruichi.co.jp./images/tenpo/map_bl.png
1092 - http://www.sinjyuku-taruichi.co.jp./images/tenpo/map_wh.png
1093 - http://www.sinjyuku-taruichi.co.jp./images/top_main.png
1094 - http://www.sinjyuku-taruichi.co.jp./images/yoyaku/yoyaku.png
1095 - http://www.sinjyuku-taruichi.co.jp./index.css
1096 - http://www.sinjyuku-taruichi.co.jp./kodawari.css
1097 - http://www.sinjyuku-taruichi.co.jp./miuraya_menu.css
1098 - http://www.sinjyuku-taruichi.co.jp./reservation.css
1099 - http://www.sinjyuku-taruichi.co.jp./tenpo.css
1100 Total links to files: 45
1101
1102+ Externals links found:
1103 - http://www.neouniverse.tokyo/
1104 - http://www.neouniverse.tokyo/story.html
1105 - http://www.neouniverse.tokyo/taruichi-kyujin.html
1106 - https://calendar.google.com/calendar/embed?showTitle=0&showPrint=0&showTabs=0&showCalendars=0&showTz=0&height=300&wkst=1&bgcolor=%23FFFFFF&
1107 - https://r.gnavi.co.jp/bp7s74y70000/menu1/
1108 - https://r.gnavi.co.jp/bp7s74y70000/menu10/
1109 - https://r.gnavi.co.jp/mzwy8vre0000/menu1/
1110 - https://www.facebook.com/plugins/page.php?href=https%3A%2F%2Fwww.facebook.com%2F%E6%A8%BD%E4%B8%80-166700486707000%2F&tabs=timeline&width=380&height=330&small_header=false&adapt_container_width=true&hide_cover=false&show_facepile=true&appId
1111 - https://www.google.com/maps/embed?pb=!1m18!1m12!1m3!1d3240.2899438570894!2d139.70212131568462!3d35.694481980191235!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0x60188cd9d648700d%3A0x315aed7d685d3af0!2z5qi95LiAIOaWsOWuv-W6lw!5e0!3m2!1sja!2sjp!4v1557244634048!5m2!1sja!2sjp
1112 - https://www.google.com/maps/embed?pb=!1m18!1m12!1m3!1d3240.439596726833!2d139.70086521568444!3d35.69079848019215!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0x60188d7736d912a1%3A0xf6b8b4041c1f5f9c!2z5qi95LiAIOS4iea1puWxi-W6lw!5e0!3m2!1sja!2sjp!4v1557244379133!5m2!1sja!2sjp
1113 - https://youtu.be/3JR55yZx5SQ
1114 - https://yoyaku.toreta.in/taruichihonten/
1115 - https://yoyaku.toreta.in/taruichisanchome/
1116 Total external links: 13
1117
1118+ Email addresses found:
1119 Total email address found: 0
1120
1121+ Directories found:
1122 - http://www.sinjyuku-taruichi.co.jp./images/ (403 Forbidden)
1123 - http://www.sinjyuku-taruichi.co.jp./images/header/ (403 Forbidden)
1124 - http://www.sinjyuku-taruichi.co.jp./images/kodawari/ (403 Forbidden)
1125 - http://www.sinjyuku-taruichi.co.jp./images/menu/ (403 Forbidden)
1126 - http://www.sinjyuku-taruichi.co.jp./images/tenpo/ (403 Forbidden)
1127 - http://www.sinjyuku-taruichi.co.jp./images/yoyaku/ (403 Forbidden)
1128 Total directories: 6
1129
1130+ Directory indexing found:
1131 Total directories with indexing: 0
1132
1133----------------------------------------------------------------------
1134
1135
1136 + URL to crawl: https://www.sinjyuku-taruichi.co.jp.
1137 + Date: 2020-01-19
1138
1139 + Crawling URL: https://www.sinjyuku-taruichi.co.jp.:
1140 + Links:
1141 + Crawling https://www.sinjyuku-taruichi.co.jp.
1142 + Searching for directories...
1143 + Searching open folders...
1144
1145
1146 + URL to crawl: http://smtp.sinjyuku-taruichi.co.jp.
1147 + Date: 2020-01-19
1148
1149 + Crawling URL: http://smtp.sinjyuku-taruichi.co.jp.:
1150 + Links:
1151 + Crawling http://smtp.sinjyuku-taruichi.co.jp.
1152 + Searching for directories...
1153 + Searching open folders...
1154
1155
1156 + URL to crawl: https://smtp.sinjyuku-taruichi.co.jp.
1157 + Date: 2020-01-19
1158
1159 + Crawling URL: https://smtp.sinjyuku-taruichi.co.jp.:
1160 + Links:
1161 + Crawling https://smtp.sinjyuku-taruichi.co.jp.
1162 + Searching for directories...
1163 + Searching open folders...
1164
1165--Finished--
1166Summary information for domain sinjyuku-taruichi.co.jp.
1167-----------------------------------------
1168 Domain Specific Information:
1169 Email: taruichi@sinjyuku-taruichi.co.jp
1170
1171 Domain Ips Information:
1172 IP: 163.44.90.113
1173 HostName: dns01.gmoserver.jp Type: NS
1174 HostName: dns01.gmoserver.jp Type: PTR
1175 Country: Japan
1176 Is Active: True (reset ttl 64)
1177 Port: 53/tcp open domain syn-ack ttl 45 (unknown banner: C-64 DNS Responder (QBasic 0.96) 1984)
1178 Script Info: | dns-nsid:
1179 Script Info: |_ bind.version: C-64 DNS Responder (QBasic 0.96) 1984
1180 Script Info: | fingerprint-strings:
1181 Script Info: | DNSVersionBindReqTCP:
1182 Script Info: | version
1183 Script Info: | bind
1184 Script Info: |_ &%C-64 DNS Responder (QBasic 0.96) 1984
1185 IP: 157.7.228.0
1186 Type: SPF
1187 Is Active: True (reset ttl 64)
1188 IP: 133.130.64.120
1189 Type: SPF
1190 Is Active: True (reset ttl 64)
1191 IP: 133.130.64.115
1192 HostName: pop.sinjyuku-taruichi.co.jp. Type: A
1193 HostName: imap.sinjyuku-taruichi.co.jp. Type: A
1194 HostName: pop18.gmoserver.jp Type: PTR
1195 Country: Japan
1196 Is Active: True (reset ttl 64)
1197 IP: 210.157.19.64
1198 Type: SPF
1199 Is Active: True (reset ttl 64)
1200 IP: 157.7.231.209
1201 HostName: dns02.gmoserver.jp Type: NS
1202 HostName: dns02.gmoserver.jp Type: PTR
1203 Country: Japan
1204 Is Active: True (reset ttl 64)
1205 Port: 53/tcp open domain syn-ack ttl 46 (unknown banner: C-64 DNS Responder (QBasic 0.96) 1984)
1206 Script Info: | dns-nsid:
1207 Script Info: |_ bind.version: C-64 DNS Responder (QBasic 0.96) 1984
1208 Script Info: | fingerprint-strings:
1209 Script Info: | DNSVersionBindReqTCP:
1210 Script Info: | version
1211 Script Info: | bind
1212 Script Info: |_ &%C-64 DNS Responder (QBasic 0.96) 1984
1213 IP: 163.44.89.0
1214 Type: SPF
1215 Is Active: True (reset ttl 64)
1216 IP: 133.130.64.114
1217 HostName: ftp.sinjyuku-taruichi.co.jp. Type: A
1218 Country: Japan
1219 Is Active: True (reset ttl 64)
1220 Port: 21/tcp open ftp syn-ack ttl 46 ProFTPD 1.3.5
1221 Script Info: |_ssl-date: TLS randomness does not represent time
1222 Script Info: | vulners:
1223 Script Info: | cpe:/a:proftpd:proftpd:1.3.5:
1224 Script Info: | CVE-2015-3306 10.0 https://vulners.com/cve/CVE-2015-3306
1225 Script Info: | CVE-2019-19272 5.0 https://vulners.com/cve/CVE-2019-19272
1226 Script Info: | CVE-2019-19271 5.0 https://vulners.com/cve/CVE-2019-19271
1227 Script Info: |_ CVE-2013-4359 5.0 https://vulners.com/cve/CVE-2013-4359
1228 Port: 80/tcp open http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
1229 Script Info: | http-methods:
1230 Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
1231 Script Info: |_http-server-header: Apache/2.2.34 (Unix)
1232 Script Info: |_http-title: Did not follow redirect to https://sd-webmail18.rentalserver.jp/
1233 Script Info: | vulners:
1234 Script Info: | cpe:/a:apache:http_server:2.2.34:
1235 Script Info: | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
1236 Script Info: |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
1237 Port: 389/tcp open ldap? syn-ack ttl 46
1238 Script Info: | fingerprint-strings:
1239 Script Info: | LDAPSearchReq:
1240 Script Info: | 0'0%
1241 Script Info: | objectClass1
1242 Script Info: |_ OpenLDAProotDSE0
1243 Port: 443/tcp open ssl/http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
1244 Script Info: | http-git:
1245 Script Info: | 133.130.64.114:443/.git/
1246 Script Info: | Git repository found!
1247 Script Info: | Repository description: Unnamed repository; edit this file 'description' to name the...
1248 Script Info: | Remotes:
1249 Script Info: |_ https://sys-git.gmo.jp/shared-hosting/webtools/sd/roundcube
1250 Script Info: | http-methods:
1251 Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
1252 Script Info: |_http-server-header: Apache/2.2.34 (Unix)
1253 Script Info: |_http-title: \xE3\x81\x8A\xE5\x90\x8D\xE5\x89\x8D.com Webmail :: \xE3\x81\x8A\xE5\x90\x8D\xE5\x89\x8D.com Webmail\xE3\x81\xAB\xE3\x82\x88\xE3\x81\x86\xE3\x81\x93\xE3\x81\x9D
1254 Script Info: | ssl-cert: Subject: commonName=*.rentalserver.jp
1255 Script Info: | Subject Alternative Name: DNS:*.rentalserver.jp, DNS:rentalserver.jp
1256 Script Info: | Issuer: commonName=GlobalSign RSA DV SSL CA 2018/organizationName=GlobalSign nv-sa/countryName=BE
1257 Script Info: | Public Key type: rsa
1258 Script Info: | Public Key bits: 2048
1259 Script Info: | Signature Algorithm: sha256WithRSAEncryption
1260 Script Info: | Not valid before: 2019-12-23T07:02:26
1261 Script Info: | Not valid after: 2021-03-14T10:30:09
1262 Script Info: | MD5: 33c6 0448 4d43 e82f d3c3 85de 1c57 35b6
1263 Script Info: |_SHA-1: d05a e65c 9657 2f23 e7a7 0389 6783 c759 1ae3 f5ae
1264 Script Info: |_ssl-date: TLS randomness does not represent time
1265 Script Info: | vulners:
1266 Script Info: | cpe:/a:apache:http_server:2.2.34:
1267 Script Info: | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
1268 Script Info: |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
1269 Port: 5666/tcp open tcpwrapped syn-ack ttl 46
1270 Port: 8443/tcp open ssl/http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
1271 Script Info: | http-cookie-flags:
1272 Script Info: | /:
1273 Script Info: | PHPSESSID:
1274 Script Info: |_ httponly flag not set
1275 Script Info: | http-methods:
1276 Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
1277 Script Info: |_http-server-header: Apache/2.2.34 (Unix)
1278 Script Info: |_http-title: ZERO Filemanager
1279 Script Info: | ssl-cert: Subject: commonName=*.rentalserver.jp
1280 Script Info: | Subject Alternative Name: DNS:*.rentalserver.jp, DNS:rentalserver.jp
1281 Script Info: | Issuer: commonName=GlobalSign RSA DV SSL CA 2018/organizationName=GlobalSign nv-sa/countryName=BE
1282 Script Info: | Public Key type: rsa
1283 Script Info: | Public Key bits: 2048
1284 Script Info: | Signature Algorithm: sha256WithRSAEncryption
1285 Script Info: | Not valid before: 2019-12-23T07:02:26
1286 Script Info: | Not valid after: 2021-03-14T10:30:09
1287 Script Info: | MD5: 33c6 0448 4d43 e82f d3c3 85de 1c57 35b6
1288 Script Info: |_SHA-1: d05a e65c 9657 2f23 e7a7 0389 6783 c759 1ae3 f5ae
1289 Script Info: |_ssl-date: TLS randomness does not represent time
1290 Script Info: | vulners:
1291 Script Info: | cpe:/a:apache:http_server:2.2.34:
1292 Script Info: | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
1293 Script Info: |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
1294 Os Info: OS: Unix
1295 IP: 133.130.64.112
1296 Type: SPF
1297 HostName: www.sinjyuku-taruichi.co.jp. Type: A
1298 HostName: www18.gmoserver.jp Type: PTR
1299 Country: Japan
1300 Is Active: True (reset ttl 64)
1301 Port: 80/tcp open http syn-ack ttl 42 Apache httpd
1302 Script Info: | http-methods:
1303 Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
1304 Script Info: |_http-server-header: Apache
1305 Script Info: |_http-title: 404 Error - Not Found
1306 Port: 443/tcp open ssl/http syn-ack ttl 42 Apache httpd
1307 Script Info: |_http-server-header: Apache
1308 Script Info: |_http-title: 403 Forbidden
1309 Script Info: | ssl-cert: Subject: commonName=*.gmoserver.jp
1310 Script Info: | Subject Alternative Name: DNS:*.gmoserver.jp, DNS:gmoserver.jp
1311 Script Info: | Issuer: commonName=GlobalSign RSA DV SSL CA 2018/organizationName=GlobalSign nv-sa/countryName=BE
1312 Script Info: | Public Key type: rsa
1313 Script Info: | Public Key bits: 2048
1314 Script Info: | Signature Algorithm: sha256WithRSAEncryption
1315 Script Info: | Not valid before: 2019-12-20T06:01:34
1316 Script Info: | Not valid after: 2022-02-14T07:59:06
1317 Script Info: | MD5: 607a b818 8000 9d67 3207 4386 b763 75a9
1318 Script Info: |_SHA-1: 3e24 9581 ec6e c03f 94df 7624 da0e da39 aa23 759d
1319 Script Info: |_ssl-date: TLS randomness does not represent time
1320 Script Info: Device type: storage-misc|general purpose
1321 Script Info: Running (JUST GUESSING): HP embedded (86%), Sun Solaris 9|10 (85%), Sun OpenSolaris (85%)
1322 IP: 157.7.151.0
1323 Type: SPF
1324 Is Active: True (reset ttl 64)
1325 IP: 157.7.183.0
1326 Type: SPF
1327 Is Active: True (reset ttl 64)
1328 IP: 133.130.64.117
1329 HostName: smtp.sinjyuku-taruichi.co.jp. Type: A
1330 Country: Japan
1331 Is Active: True (reset ttl 64)
1332 Port: 80/tcp open http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
1333 Script Info: | http-methods:
1334 Script Info: |_ Supported Methods: POST OPTIONS GET HEAD
1335 Script Info: |_http-server-header: Apache/2.2.34 (Unix)
1336 Script Info: |_http-title: Site doesn't have a title (text/html).
1337 Script Info: | vulners:
1338 Script Info: | cpe:/a:apache:http_server:2.2.34:
1339 Script Info: | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
1340 Script Info: |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
1341 Port: 443/tcp open ssl/http syn-ack ttl 42 Apache httpd 2.2.34 ((Unix))
1342 Script Info: | http-methods:
1343 Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
1344 Script Info: |_http-server-header: Apache/2.2.34 (Unix)
1345 Script Info: | http-title: [\xE3\x83\xAD\xE3\x82\xB0\xE3\x82\xA4\xE3\x83\xB3]
1346 Script Info: |_Requested resource was /login.php
1347 Script Info: | ssl-cert: Subject: commonName=*.rentalserver.jp
1348 Script Info: | Subject Alternative Name: DNS:*.rentalserver.jp, DNS:rentalserver.jp
1349 Script Info: | Issuer: commonName=GlobalSign RSA DV SSL CA 2018/organizationName=GlobalSign nv-sa/countryName=BE
1350 Script Info: | Public Key type: rsa
1351 Script Info: | Public Key bits: 2048
1352 Script Info: | Signature Algorithm: sha256WithRSAEncryption
1353 Script Info: | Not valid before: 2019-12-23T07:02:26
1354 Script Info: | Not valid after: 2021-03-14T10:30:09
1355 Script Info: | MD5: 33c6 0448 4d43 e82f d3c3 85de 1c57 35b6
1356 Script Info: |_SHA-1: d05a e65c 9657 2f23 e7a7 0389 6783 c759 1ae3 f5ae
1357 Script Info: |_ssl-date: TLS randomness does not represent time
1358 Script Info: | vulners:
1359 Script Info: | cpe:/a:apache:http_server:2.2.34:
1360 Script Info: | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
1361 Script Info: |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
1362 Port: 465/tcp open ssl/smtps? syn-ack ttl 46
1363 Script Info: |_smtp-commands: Couldn't establish connection on port 465
1364 Script Info: |_ssl-date: TLS randomness does not represent time
1365 Port: 587/tcp open smtp syn-ack ttl 46 Postfix smtpd
1366 Script Info: |_smtp-commands: smtp18.gmoserver.jp, PIPELINING, SIZE 150000000, ETRN, STARTTLS, AUTH PLAIN LOGIN, AUTH=PLAIN LOGIN, ENHANCEDSTATUSCODES, 8BITMIME, DSN,
1367 Script Info: |_ssl-date: TLS randomness does not represent time
1368 Script Info: Device type: storage-misc|general purpose
1369 Script Info: Running (JUST GUESSING): HP embedded (86%), Sun Solaris 9|10 (85%), Sun OpenSolaris (85%)
1370 Os Info: Host: smtp18.gmoserver.jp
1371 IP: 133.130.64.116
1372 HostName: mx18.gmoserver.jp Type: MX
1373 HostName: mx18.gmoserver.jp Type: PTR
1374 HostName: mx.sinjyuku-taruichi.co.jp. Type: A
1375 Country: Japan
1376 Is Active: True (reset ttl 64)
1377 IP: 157.7.224.144
1378 Type: SPF
1379 Is Active: True (reset ttl 64)
1380 IP: 118.27.67.0
1381 Type: SPF
1382 Is Active: True (reset ttl 64)
1383 IP: 157.7.174.0
1384 Type: SPF
1385 Is Active: True (reset ttl 64)
1386 IP: 118.27.82.0
1387 Type: SPF
1388 Is Active: True (reset ttl 64)
1389 IP: 118.27.54.0
1390 Type: SPF
1391 Is Active: True (reset ttl 64)
1392 IP: 150.95.48.0
1393 Type: SPF
1394 Is Active: True (reset ttl 64)
1395 IP: 163.44.74.0
1396 Type: SPF
1397 Is Active: True (reset ttl 64)
1398 IP: 150.95.170.0
1399 Type: SPF
1400 Is Active: True (reset ttl 64)
1401
1402--------------End Summary --------------
1403-----------------------------------------
1404######################################################################################################################################
1405traceroute to www.sinjyuku-taruichi.co.jp (133.130.64.112), 30 hops max, 60 byte packets
1406 1 10.253.204.1 (10.253.204.1) 59.305 ms 93.882 ms 93.886 ms
1407 2 104.245.145.177 (104.245.145.177) 93.875 ms 93.863 ms 93.818 ms
1408 3 te0-0-2-1.225.nr11.b010988-1.yyz02.atlas.cogentco.com (38.104.156.9) 93.908 ms 119.209 ms 119.219 ms
1409 4 te0-0-0-1.agr14.yyz02.atlas.cogentco.com (154.24.54.41) 93.769 ms te0-0-0-1.agr13.yyz02.atlas.cogentco.com (154.24.54.37) 93.769 ms te0-0-0-1.agr14.yyz02.atlas.cogentco.com (154.24.54.41) 93.722 ms
1410 5 te0-9-1-9.ccr31.yyz02.atlas.cogentco.com (154.54.43.161) 93.646 ms 93.630 ms te0-9-1-9.ccr32.yyz02.atlas.cogentco.com (154.54.43.169) 93.569 ms
1411 6 be2994.ccr22.cle04.atlas.cogentco.com (154.54.31.233) 119.020 ms 88.621 ms 38.569 ms
1412 7 be2718.ccr42.ord01.atlas.cogentco.com (154.54.7.129) 115.034 ms 115.053 ms be2717.ccr41.ord01.atlas.cogentco.com (154.54.6.221) 84.018 ms
1413 8 be2832.ccr22.mci01.atlas.cogentco.com (154.54.44.169) 115.062 ms 115.031 ms be2831.ccr21.mci01.atlas.cogentco.com (154.54.42.165) 114.998 ms
1414 9 be3036.ccr22.den01.atlas.cogentco.com (154.54.31.89) 115.023 ms 115.030 ms be3035.ccr21.den01.atlas.cogentco.com (154.54.5.89) 114.995 ms
141510 be3037.ccr21.slc01.atlas.cogentco.com (154.54.41.145) 144.913 ms 144.912 ms be3038.ccr32.slc01.atlas.cogentco.com (154.54.42.97) 144.844 ms
141611 be3109.ccr21.sfo01.atlas.cogentco.com (154.54.44.137) 144.938 ms 144.903 ms be3110.ccr22.sfo01.atlas.cogentco.com (154.54.44.141) 144.890 ms
141712 be3669.ccr41.sjc03.atlas.cogentco.com (154.54.43.10) 141.609 ms be3670.ccr41.sjc03.atlas.cogentco.com (154.54.43.14) 127.165 ms be3669.ccr41.sjc03.atlas.cogentco.com (154.54.43.10) 93.985 ms
141813 38.88.224.178 (38.88.224.178) 173.641 ms 173.565 ms 173.517 ms
141914 111.87.3.105 (111.87.3.105) 173.524 ms 111.87.3.117 (111.87.3.117) 173.543 ms 111.87.3.113 (111.87.3.113) 173.485 ms
142015 106.187.13.25 (106.187.13.25) 263.600 ms 215.020 ms 106.187.13.29 (106.187.13.29) 291.429 ms
142116 27.85.224.142 (27.85.224.142) 291.398 ms 27.85.224.158 (27.85.224.158) 291.350 ms 27.85.224.146 (27.85.224.146) 291.390 ms
142217 125.29.26.58 (125.29.26.58) 291.396 ms 291.367 ms 291.374 ms
142318 133.208.191.139 (133.208.191.139) 220.505 ms 301.175 ms 301.219 ms
142419 133.208.55.50 (133.208.55.50) 301.131 ms 301.134 ms 301.092 ms
142520 unused-133-130-015-097.interq.or.jp (133.130.15.97) 301.050 ms 301.051 ms 211.131 ms
142621 unused-133-130-013-018.interq.or.jp (133.130.13.18) 289.471 ms 289.459 ms 289.423 ms
142722 g-o-p-2w-a18-1-e-1-10.interq.or.jp (157.7.40.130) 289.380 ms 289.382 ms 289.350 ms
142823 unused-157-007-038-082.interq.or.jp (157.7.38.82) 289.309 ms 198.237 ms 273.981 ms
1429######################################################################################################################################
1430----- sinjyuku-taruichi.co.jp -----
1431
1432
1433Host's addresses:
1434__________________
1435
1436sinjyuku-taruichi.co.jp. 116 IN A 133.130.64.112
1437
1438
1439Name Servers:
1440______________
1441
1442dns01.gmoserver.jp. 27 IN A 163.44.90.113
1443dns02.gmoserver.jp. 6 IN A 157.7.231.209
1444
1445
1446Mail (MX) Servers:
1447___________________
1448
1449mx18.gmoserver.jp. 86129 IN A 133.130.64.116
1450
1451
1452Brute forcing with /usr/share/dnsenum/dns.txt:
1453_______________________________________________
1454
1455ftp.sinjyuku-taruichi.co.jp. 101 IN A 133.130.64.114
1456mx.sinjyuku-taruichi.co.jp. 88 IN A 133.130.64.116
1457pop.sinjyuku-taruichi.co.jp. 297 IN A 133.130.64.115
1458smtp.sinjyuku-taruichi.co.jp. 291 IN A 133.130.64.117
1459www.sinjyuku-taruichi.co.jp. 290 IN A 133.130.64.112
1460
1461
1462Launching Whois Queries:
1463_________________________
1464
1465 whois ip result: 133.130.64.0 -> 133.130.64.0/24
1466
1467
1468sinjyuku-taruichi.co.jp_______________________
1469
1470 133.130.64.0/24
1471######################################################################################################################################
1472WARNING: Duplicate port number(s) specified. Are you alert enough to be using Nmap? Have some coffee or Jolt(tm).
1473Starting Nmap 7.80 ( https://nmap.org ) at 2020-01-19 04:32 EST
1474Nmap scan report for www18.gmoserver.jp (133.130.64.112)
1475Host is up (0.23s latency).
1476Not shown: 494 closed ports
1477PORT STATE SERVICE
147880/tcp open http
1479443/tcp open https
1480
1481Nmap done: 1 IP address (1 host up) scanned in 1.85 seconds
1482#######################################################################################################################################
1483Starting Nmap 7.80 ( https://nmap.org ) at 2020-01-19 04:32 EST
1484Nmap scan report for www18.gmoserver.jp (133.130.64.112)
1485Host is up (0.037s latency).
1486Not shown: 2 filtered ports
1487PORT STATE SERVICE
148853/udp open|filtered domain
148967/udp open|filtered dhcps
149068/udp open|filtered dhcpc
149169/udp open|filtered tftp
149288/udp open|filtered kerberos-sec
1493123/udp open|filtered ntp
1494139/udp open|filtered netbios-ssn
1495161/udp open|filtered snmp
1496162/udp open|filtered snmptrap
1497389/udp open|filtered ldap
1498500/udp open|filtered isakmp
1499520/udp open|filtered route
15002049/udp open|filtered nfs
1501
1502Nmap done: 1 IP address (1 host up) scanned in 1.76 seconds
1503#######################################################################################################################################
1504HTTP/1.1 404 Not Found
1505Date: Sun, 19 Jan 2020 09:32:11 GMT
1506Server: Apache
1507Last-Modified: Wed, 02 Aug 2017 08:47:14 GMT
1508Accept-Ranges: bytes
1509Content-Length: 1242
1510Content-Type: text/html
1511
1512Allow: GET,HEAD,POST,OPTIONS
1513#######################################################################################################################################
1514Starting Nmap 7.80 ( https://nmap.org ) at 2020-01-19 04:33 EST
1515NSE: Loaded 162 scripts for scanning.
1516NSE: Script Pre-scanning.
1517Initiating NSE at 04:33
1518Completed NSE at 04:33, 0.00s elapsed
1519Initiating NSE at 04:33
1520Completed NSE at 04:33, 0.00s elapsed
1521Initiating Parallel DNS resolution of 1 host. at 04:33
1522Completed Parallel DNS resolution of 1 host. at 04:33, 0.02s elapsed
1523Initiating SYN Stealth Scan at 04:33
1524Scanning www18.gmoserver.jp (133.130.64.112) [1 port]
1525Discovered open port 80/tcp on 133.130.64.112
1526Completed SYN Stealth Scan at 04:33, 0.28s elapsed (1 total ports)
1527Initiating Service scan at 04:33
1528Scanning 1 service on www18.gmoserver.jp (133.130.64.112)
1529Completed Service scan at 04:33, 6.50s elapsed (1 service on 1 host)
1530Initiating OS detection (try #1) against www18.gmoserver.jp (133.130.64.112)
1531Retrying OS detection (try #2) against www18.gmoserver.jp (133.130.64.112)
1532Initiating Traceroute at 04:33
1533Completed Traceroute at 04:33, 3.24s elapsed
1534Initiating Parallel DNS resolution of 24 hosts. at 04:33
1535Completed Parallel DNS resolution of 24 hosts. at 04:33, 0.96s elapsed
1536NSE: Script scanning 133.130.64.112.
1537Initiating NSE at 04:33
1538Completed NSE at 04:34, 51.00s elapsed
1539Initiating NSE at 04:34
1540Completed NSE at 04:34, 0.99s elapsed
1541Nmap scan report for www18.gmoserver.jp (133.130.64.112)
1542Host is up (0.23s latency).
1543
1544PORT STATE SERVICE VERSION
154580/tcp open http Apache httpd
1546| http-brute:
1547|_ Path "/" does not require authentication
1548|_http-chrono: Request times for /; avg: 658.55ms; min: 620.54ms; max: 713.52ms
1549|_http-csrf: Couldn't find any CSRF vulnerabilities.
1550|_http-date: Sun, 19 Jan 2020 09:33:32 GMT; -5s from local time.
1551|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
1552|_http-dombased-xss: Couldn't find any DOM based XSS.
1553|_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
1554| http-errors:
1555| Spidering limited to: maxpagecount=40; withinhost=www18.gmoserver.jp
1556| Found the following error pages:
1557|
1558| Error Code: 404
1559|_ http://www18.gmoserver.jp:80/
1560|_http-feed: Couldn't find any feeds.
1561|_http-fetch: Please enter the complete path of the directory to save data in.
1562| http-headers:
1563| Date: Sun, 19 Jan 2020 09:33:36 GMT
1564| Server: Apache
1565| Last-Modified: Wed, 02 Aug 2017 08:47:14 GMT
1566| Accept-Ranges: bytes
1567| Content-Length: 1242
1568| Connection: close
1569| Content-Type: text/html
1570|
1571|_ (Request type: GET)
1572|_http-jsonp-detection: Couldn't find any JSONP endpoints.
1573| http-methods:
1574|_ Supported Methods: GET HEAD POST OPTIONS
1575|_http-mobileversion-checker: No mobile version detected.
1576|_http-security-headers:
1577|_http-server-header: Apache
1578| http-sitemap-generator:
1579| Directory structure:
1580| Longest directory structure:
1581| Depth: 0
1582| Dir: /
1583| Total files found (by extension):
1584|_
1585|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
1586|_http-title: 404 Error - Not Found
1587| http-vhosts:
1588| www.gmoserver.jp : 503
1589|_126 names had status 404
1590|_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
1591|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
1592|_http-xssed: No previously reported XSS vuln.
1593| vulscan: VulDB - https://vuldb.com:
1594| [141649] Apache OFBiz up to 16.11.05 Form Widget Freemarker Markup Code Execution
1595| [141648] Apache OFBiz up to 16.11.05 Application Stored cross site scripting
1596| [140386] Apache Commons Beanutils 1.9.2 BeanIntrospector unknown vulnerability
1597| [139708] Apache Ranger up to 1.2.0 Policy Import cross site scripting
1598| [139540] cPanel up to 60.0.24 Apache HTTP Server Key information disclosure
1599| [139386] Apache Tike up to 1.21 RecursiveParserWrapper Stack-based memory corruption
1600| [139385] Apache Tika 1.19/1.20/1.21 SAXParsers Hang denial of service
1601| [139384] Apache Tika up to 1.21 RecursiveParserWrapper ZIP File denial of service
1602| [139261] Apache Solr 8.2.0 DataImportHandler Parameter unknown vulnerability
1603| [139259] cPanel up to 68.0.26 WHM Apache Includes Editor information disclosure
1604| [139256] cPanel up to 68.0.26 WHM Apache Configuration Include Editor cross site scripting
1605| [139239] cPanel up to 70.0.22 Apache HTTP Server Log information disclosure
1606| [139141] Apache ActiveMQ Client up to 5.15.4 ActiveMQConnection.java ActiveMQConnection denial of service
1607| [139130] cPanel up to 73.x Apache HTTP Server Injection privilege escalation
1608| [138914] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 VM sql injection
1609| [138913] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Block Argument privilege escalation
1610| [138912] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Cookie sql injection
1611| [138816] Apache Storm up to 1.2.2 Logviewer Daemon Log information disclosure
1612| [138815] Apache Storm up to 1.2.2 UI Daemon Deserialization privilege escalation
1613| [138164] Oracle 2.7.0.1 Apache Log4j unknown vulnerability
1614| [138155] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Tomcat unknown vulnerability
1615| [138151] Oracle Transportation Management 6.3.7 Apache Tomcat unknown vulnerability
1616| [138149] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Commons FileUpload unknown vulnerability
1617| [138131] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Tomcat unknown vulnerability
1618| [138129] Oracle Retail Xstore Point of Service 7.0/7.1 Apache HTTP Server denial of service
1619| [138123] Oracle Retail Order Management System 5.0 Apache Struts 1 unknown vulnerability
1620| [138122] Oracle Retail Order Broker 5.2/15.0 Apache Tomcat unknown vulnerability
1621| [138121] Oracle Retail Order Broker 5.2/15.0 Apache CXF unknown vulnerability
1622| [138112] Oracle Retail Integration Bus 15.0/16.0 Apache Commons FileUpload unknown vulnerability
1623| [138111] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Commons FileUpload unknown vulnerability
1624| [138103] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56/8.57 Apache WSS4J information disclosure
1625| [138053] Oracle JD Edwards EnterpriseOne Tools 9.2 Apache Log4j unknown vulnerability
1626| [138036] Oracle Insurance Rules Palette 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
1627| [138035] Oracle Insurance Policy Administration J2EE 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
1628| [138034] Oracle Insurance Calculation Engine 9.7/10.0/10.1/10.2 Apache Commons FileUpload unknown vulnerability
1629| [138028] Oracle Identity Manager 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
1630| [138020] Oracle BI Publisher 11.1.1.9.0 Apache Tomcat unknown vulnerability
1631| [138019] Oracle BI Publisher (formerly XML Publisher) 11.1.1.9.0 Apache Tomcat unknown vulnerability
1632| [138017] Oracle Outside In Technology 8.5.4 Apache Commons FileUpload unknown vulnerability
1633| [138013] Oracle Outside In Technology 8.5.4 Apache Tomcat unknown vulnerability
1634| [138012] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
1635| [138009] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
1636| [138008] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Struts 1 denial of service
1637| [138007] Oracle WebCenter Sites 12.2.1.3.0 Apache Tomcat denial of service
1638| [138006] Oracle Enterprise Repository 12.1.3.0.0 Apache CXF denial of service
1639| [138000] Oracle WebCenter Sites 12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
1640| [137999] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
1641| [137995] Oracle Hospitality Simphony 18.2.1 Apache WSS4J information disclosure
1642| [137987] Oracle FLEXCUBE Universal Banking up to 12.0.3/12.4.0/14.2.0 Apache Log4j unknown vulnerability
1643| [137981] Oracle Insurance IFRS 17 Analyzer 8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
1644| [137980] Oracle Insurance Data Foundation 8.0.4/8.0.5/8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
1645| [137979] Oracle 8.0.8 Apache Commons FileUpload unknown vulnerability
1646| [137973] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Batik unknown vulnerability
1647| [137970] Oracle Financial Services Profitability Management 8.0.4/8.0.5/8.0.6/8.0.7 Apache ActiveMQ unknown vulnerability
1648| [137967] Oracle up to 8.0.7 Apache httpd unknown vulnerability
1649| [137966] Oracle 8.0.7/8.0.8 Apache Groovy unknown vulnerability
1650| [137965] Oracle Financial Services Liquidity Risk Management 8.0.1/8.0.2/8.0.4/8.0.5/8.0.6 Apache Commons FileUpload unknown vulnerability
1651| [137964] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Log4j unknown vulnerability
1652| [137933] Oracle Banking Platform up to 2.7.1 Apache Tika unknown vulnerability
1653| [137926] Oracle Enterprise Manager for Fusion Middleware 13.2/13.3 Apache Commons FileUpload information disclosure
1654| [137924] Oracle Enterprise Manager Base Platform 12.1.0.5.0/13.2.0.0.0/13.3.0.0.0 Apache Commons FileUpload unknown vulnerability
1655| [137914] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
1656| [137913] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
1657| [137911] Oracle E-Business Suite up to 12.2.8 Apache HTTP Server unknown vulnerability
1658| [137910] Oracle E-Business Suite up to 12.2.8 Apache CXF information disclosure
1659| [137909] Oracle E-Business Suite up to 12.2.8 Apache Commons FileUpload unknown vulnerability
1660| [137905] Oracle Primavera Gateway 15.2/16.2/17.12/18.8 Apache Tika denial of service
1661| [137901] Oracle Primavera Unifier up to 18.8 Apache HTTP Server unknown vulnerability
1662| [137895] Oracle Instant Messaging Server 10.0.1.2.0 Apache Tika information disclosure
1663| [137894] Oracle EAGLE (Software) 46.5/46.6/46.7 Apache Tomcat information disclosure
1664| [137892] Oracle Online Mediation Controller 6.1 Apache Batik denial of service
1665| [137891] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Tomcat unknown vulnerability
1666| [137885] Oracle Diameter Signaling Router (DSR) 8.0/8.1/8.2 Apache cxf unknown vulnerability
1667| [137882] Oracle Unified 8.0.0.2.0 Apache Commons FileUpload unknown vulnerability
1668| [137881] Oracle Online Mediation Controller 6.1 Apache Commons FileUpload unknown vulnerability
1669| [137880] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Log4j unknown vulnerability
1670| [137879] Oracle Convergence 3.0.2 Apache Commons FileUpload unknown vulnerability
1671| [137876] Oracle Application Session Controller 3.7.1/3.8.0 Apache Commons FileUpload unknown vulnerability
1672| [137829] Apache Roller 5.2.3 Math Comment Authenticator Reflected cross site scripting
1673| [137736] Apache Kafka 0.11.0.0/2.1.0 ACL Validation Request privilege escalation
1674| [136858] MakerBot Replicator 5G Printer Apache HTTP Server information disclosure
1675| [136849] Analogic Poste.io 2.1.6 on Apache RoundCube logs/ information disclosure
1676| [136822] Apache Tomcat up to 8.5.40/9.0.19 Incomplete Fix CVE-2019-0199 Resource Exhaustion denial of service
1677| [136808] Apache Geode up to 1.8.0 Secure Mode privilege escalation
1678| [136646] Apache Allura up to 1.10.x Dropdown Selector Stored cross site scripting
1679| [136374] Apache HTTP Server up to 2.4.38 Slash Regular Expression unknown vulnerability
1680| [136373] Apache HTTP Server 2.4.34/2.4.35/2.4.36/2.4.37/2.4.38 HTTP2 Request Crash denial of service
1681| [136372] Apache HTTP Server up to 2.4.38 HTTP2 Request unknown vulnerability
1682| [136370] Apache Fineract up to 1.2.x sql injection
1683| [136369] Apache Fineract up to 1.2.x sql injection
1684| [135731] Apache Hadoop up to 2.8.4/2.9.1/3.1.0 yarn privilege escalation
1685| [135664] Apache Tomcat up to 7.0.93/8.5.39/9.0.0.17 SSI printenv Command cross site scripting
1686| [135663] Apache Camel up to 2.23.x JSON-lib Library XML Data XML External Entity
1687| [135661] Apache Roller up to 5.2.1/5.2.0 XML-RPC Interface XML File Server-Side Request Forgery
1688| [135402] Apache Zookeeper up to 3.4.13/3.5.0-alpha to 3.5.4-beta getACL() information disclosure
1689| [135270] Apache JSPWiki up to 2.11.0.M3 Plugin Link cross site scripting
1690| [135269] Apache JSPWiki up to 2.11.0.M3 InterWiki Link cross site scripting
1691| [135268] Apache JSPWiki up to 2.11.0.M3 Attachment cross site scripting
1692| [134527] Apache Karaf up to 4.2.4 Config Service directory traversal
1693| [134416] Apache Sanselan 0.97-incubator Loop denial of service
1694| [134415] Apache Sanselan 0.97-incubator Hang denial of service
1695| [134291] Apache Axis up to 1.7.8 Server-Side Request Forgery
1696| [134290] Apache UIMA DUCC up to 2.2.2 cross site scripting
1697| [134248] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
1698| [134247] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
1699| [134246] Apache Camel up to 2.19/2.21.3/2.22.2/2.23.0 directory traversal
1700| [134138] Apache Pluto 3.0.0/3.0.1 Chat Room Demo Portlet cross site scripting
1701| [133992] Apache Qpid Proton up to 0.27.0 Certificate Validation Man-in-the-Middle weak authentication
1702| [133977] Apache Zeppelin up to 0.7.x Stored cross site scripting
1703| [133976] Apache Zeppelin up to 0.7.x Cron Scheduler privilege escalation
1704| [133975] Apache Zeppelin up to 0.7.2 Session Fixation weak authentication
1705| [133444] Apache PDFbox 2.0.14 XML Parser XML External Entity
1706| [133573] Oracle FLEXCUBE Private Banking 2.0.0.0/2.2.0.1/12.0.1.0/12.0.3.0/12.1.0.0 Apache ActiveMQ unknown vulnerability
1707| [133407] Apache Tomcat up to 7.0.93/8.5.39/9.0.17 on Windows JRE Command Line Argument Code Execution
1708| [133315] Apache Airflow up to 1.10.2 HTTP Endpoint cross site request forgery
1709| [133314] Apache Airflow up to 1.10.2 Metadata Database cross site scripting
1710| [133290] Apache Tomcat up to 8.5.37/9.0.14 HTTP2 Stream Execution denial of service
1711| [133112] Apache HTTP Server up to 2.4.38 mod_auth_digest race condition privilege escalation
1712| [133111] Apache HTTP Server 2.4.37/2.4.38 mod_ssl Bypass privilege escalation
1713| [133092] Airsonic 10.2.1 org.apache.commons.lang.RandomStringUtils RecoverController.java java.util.Random weak authentication
1714| [132568] Apache JSPWiki up to 2.11.0.M2 URL User information disclosure
1715| [132567] Apache JSPWiki up to 2.11.0.M2 URL cross site scripting
1716| [132566] Apache ActiveMQ up to 5.15.8 MQTT Frame Memory denial of service
1717| [132565] Apache HBase up to 2.1.3 REST Server Request privilege escalation
1718| [132183] Apache Mesos up to pre-1.4.x Docker Image Code Execution
1719| [131988] Apache Karaf up to 4.2.2 kar Deployer directory traversal
1720| [131859] Apache Hadoop up to 2.9.1 privilege escalation
1721| [131479] Apache Solr up to 7.6 HTTP GET Request Server-Side Request Forgery
1722| [131446] Apache Solr up to 5.0.5/6.6.5 Config API HTTP POST Request Code Execution
1723| [131385] Apache Qpid Broker-J up to 6.x/7.0.6/7.1.0 AMQP Command Crash denial of service
1724| [131315] Apache Mesos up to pre-1.4.x Mesos Masters Rendering JSON Payload Recursion denial of service
1725| [131236] Apache Airflow up to 1.10.1 Metadata Database cross site scripting
1726| [130755] Apache JSPWiki up to 2.10.5 URL cross site scripting
1727| [130629] Apache Guacamole Cookie Flag weak encryption
1728| [130628] Apache Hadoop up to 3.0.0 HDFS information disclosure
1729| [130529] Apache Subversion 1.10.0/1.10.1/1.10.2/1.10.3/1.11.0 mod_dav_svn Directory Crash denial of service
1730| [130353] Apache Open Office up to 4.1.5 Document Loader String memory corruption
1731| [130341] Apache HTTP Server 2.4.37 mod_ssl Loop denial of service
1732| [130330] Apache HTTP Server up to 2.4.37 mod_session Expired privilege escalation
1733| [130329] Apache HTTP Server 2.4.37 mod_http2 Slowloris denial of service
1734| [130212] Apache Airflow up to 1.10.0 LDAP Auth Backend Certificate weak authentication
1735| [130123] Apache Airflow up to 1.8.2 information disclosure
1736| [130122] Apache Airflow up to 1.8.2 command injection cross site request forgery
1737| [130121] Apache Airflow up to 1.8.2 Webserver Object Code Execution
1738| [129717] Oracle Secure Global Desktop 5.4 Apache HTTP Server denial of service
1739| [129688] Oracle Tape Library ACSLS 8.4 Apache Log4j unknown vulnerability
1740| [129673] Oracle Retail Returns Management 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
1741| [129672] Oracle Retail Central Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
1742| [129671] Oracle Retail Back Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
1743| [129574] Oracle Outside In Technology 8.5.3/8.5.4 Apache Tomcat denial of service
1744| [129573] Oracle WebLogic Server 10.3.6.0 Apache HTTP Server denial of service
1745| [129563] Oracle Enterprise Repository 12.1.3.0.0 Apache Log4j unknown vulnerability
1746| [129555] Oracle Outside In Technology 8.5.3 Apache Batik denial of service
1747| [129551] Oracle Outside In Technology 8.5.3/8.5.4 Apache Commons FileUpload denial of service
1748| [129542] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
1749| [129538] Oracle SOA Suite 12.1.3.0.0/12.2.1.3.0 Apache Batik unknown vulnerability
1750| [129519] Oracle Enterprise Manager Ops Center 12.2.2/12.3.3 Apache ActiveMQ unknown vulnerability
1751| [129508] Oracle Applications Manager up to 12.2.8 Apache Derby unknown vulnerability
1752| [129507] Oracle Mobile Field Service up to 12.2.8 Apache Log4j unknown vulnerability
1753| [129505] Oracle Email Center up to 12.2.8 Apache Log4j unknown vulnerability
1754| [129504] Oracle CRM Technical Foundation up to 12.2.8 Apache Commons FileUpload unknown vulnerability
1755| [129499] Oracle Partner Management up to 12.2.8 Apache Log4j unknown vulnerability
1756| [129498] Oracle Marketing up to 12.2.8 Apache Commons FileUpload unknown vulnerability
1757| [129480] Oracle Communications WebRTC Session Controller up to 7.1 Apache Batik unknown vulnerability
1758| [129479] Oracle Communications Diameter Signaling Router up to 8.2 Apache Batik unknown vulnerability
1759| [129474] Oracle Communications Diameter Signaling Router up to 8.2 Apache HTTP Server information disclosure
1760| [129472] Oracle Communications WebRTC Session Controller up to 7.1 Apache Struts 1 unknown vulnerability
1761| [129470] Oracle Communications Converged Application Server up to 7.0.0.0 Apache Struts 1 unknown vulnerability
1762| [129463] Oracle Communications WebRTC Session Controller up to 7.1 Apache Log4j unknown vulnerability
1763| [129461] Oracle Communications Services Gatekeeper up to 6.1.0.3.x Apache Commons Collections Fileupload unknown vulnerability
1764| [129460] Oracle Communications Service Broker 6.0 Apache Log4j unknown vulnerability
1765| [129459] Oracle Communications Policy Management up to 12.4 Apache Struts 2 unknown vulnerability
1766| [129458] Oracle Communications Online Mediation Controller 6.1 Apache Log4j unknown vulnerability
1767| [129457] Oracle Communications Diameter Signaling Router up to 8.2 Apache Commons Fileupload unknown vulnerability
1768| [129456] Oracle Communications Converged Application Server 6.1 Apache Log4j unknown vulnerability
1769| [128714] Apache Thrift Java Client Library up to 0.11.0 SASL Negotiation org.apache.thrift.transport.TSaslTransport unknown vulnerability
1770| [128713] Apache Thrift Node.js Static Web Server up to 0.11.0 directory traversal
1771| [128709] Apache Karaf up to 4.1.6/4.2.1 Features Deployer XMLInputFactory XML External Entity
1772| [128575] Apache NetBeans 9.0 Proxy Auto-Config Code Execution
1773| [128369] Apache Tika 1.8-1.19.1 SQLite3Parser Loop sql injection
1774| [128111] Apache NiFi 1.8.0 Template Upload Man-in-the-Middle cross site request forgery
1775| [128110] Apache NiFi 1.8.0 Cluster Request privilege escalation
1776| [128109] Apache NiFi 1.8.0 Error Page message-page.jsp Request Header cross site scripting
1777| [128108] Apache NiFi up to 1.7.x X-Frame-Options Header privilege escalation
1778| [128102] Apache Oozie up to 5.0.0 Workflow XML Impersonation spoofing
1779| [127994] WordPress up to 5.0.0 on Apache httpd MIME Restriction cross site scripting
1780| [127981] Apache OFBiz 16.11.01/16.11.02/16.11.03/16.11.04 HTTP Engine httpService GET Request privilege escalation
1781| [127161] Apache Hadoop 2.7.4/2.7.5/2.7.6 Incomplete Fix CVE-2016-6811 privilege escalation
1782| [127040] Loadbalancer.org Enterprise VA MAX up to 8.3.2 Apache HTTP Server Log cross site scripting
1783| [127007] Apache Spark Request Code Execution
1784| [126791] Apache Hadoop up to 0.23.11/2.7.6/2.8.4/2.9.1/3.0.2 ZIP File unknown vulnerability
1785| [126767] Apache Qpid Proton-J Transport 0.3 Certificate Verification Man-in-the-Middle weak authentication
1786| [126896] Apache Commons FileUpload 1.3.3 on LDAP Manager DiskFileItem File privilege escalation
1787| [126574] Apache Hive up to 2.3.3/3.1.0 Query privilege escalation
1788| [126573] Apache Hive up to 2.3.3/3.1.0 HiveServer2 privilege escalation
1789| [126564] Apache Superset up to 0.22 Pickle Library load Code Execution
1790| [126488] Apache Syncope up to 2.0.10/2.1.1 BPMN Definition xxe privilege escalation
1791| [126487] Apache Syncope up to 2.0.10/2.1.1 cross site scripting
1792| [126346] Apache Tomcat Path privilege escalation
1793| [125922] Apache Impala up to 3.0.0 ALTER privilege escalation
1794| [125921] Apache Impala up to 3.0.0 Queue Injection privilege escalation
1795| [125647] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Install (Apache Tomcat) information disclosure
1796| [125617] Oracle Retail Returns Management 14.1 Apache Batik unknown vulnerability
1797| [125616] Oracle Retail Point-of-Service 13.4/14.0/14.1 Apache Batik unknown vulnerability
1798| [125614] Oracle Retail Central Office 14.1 Apache Batik unknown vulnerability
1799| [125613] Oracle Retail Back Office 13.3/13.4/14/14.1 Apache Batik unknown vulnerability
1800| [125599] Oracle Retail Open Commerce Platform 5.3.0/6.0.0/6.0.1 Apache Log4j unknown vulnerability
1801| [125569] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56 Apache HTTP Server information disclosure
1802| [125494] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat information disclosure
1803| [125447] Oracle Business Intelligence Enterprise Edition 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Batik unknown vulnerability
1804| [125428] Oracle Identity Management Suite 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
1805| [125427] Oracle Identity Analytics 11.1.1.5.8 Apache Log4j unknown vulnerability
1806| [125424] Oracle API Gateway 11.1.2.4.0 Apache Log4j unknown vulnerability
1807| [125423] Oracle BI Publisher 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Log4j unknown vulnerability
1808| [125383] Oracle up to 10.2.0 Apache Trinidad unknown vulnerability
1809| [125379] Oracle up to 10.1.x Apache Struts 1 cross site scripting
1810| [125377] Oracle up to 10.2.0 Apache Commons Collections unknown vulnerability
1811| [125376] Oracle Communications Application Session Controller up to 3.7.0 Apache Commons Collections unknown vulnerability
1812| [125375] Oracle Communications User Data Repository up to 12.1.x Apache Xerces memory corruption
1813| [125248] Apache ActiveMQ up to 5.15.5 Web-based Administration Console queue.jsp Parameter cross site scripting
1814| [125133] Apache Tika up to 1.19 XML Parser reset() denial of service
1815| [124877] Apache PDFbox up to 2.0.11 PDF File denial of service
1816| [124876] Apache Ranger up to 1.1.x UnixAuthenticationService Stack-based memory corruption
1817| [124791] Apache Tomcat up to 7.0.90/8.5.33/9.0.11 URL Open Redirect
1818| [124787] Apache Pony Mail 0.7/0.8/0.9 Statistics Generator Timestamp Data information disclosure
1819| [124447] Apache HTTP Server up to 2.4.34 SETTINGS Frame denial of service
1820| [124346] Apache Mesos pre-1.4.2/1.5.0/1.5.1/1.6.0 on Executor HTTP API String Comparison validation JSON Web Token information disclosure
1821| [124286] Apache Tika up to 1.18 IptcAnpaParser Loop denial of service
1822| [124242] Apache Tika up to 0.18 C:/evil.bat" Directory unknown vulnerability
1823| [124241] Apache Tika up to 0.18 XML Parser Entity Expansion denial of service
1824| [124191] Apache Karaf up to 3.0.8/4.0.8/4.1.0 WebConsole .../gogo/ weak authentication
1825| [124190] Apache Karaf up to 4.1.x sshd privilege escalation
1826| [124152] Apache Camel Mail up to 2.22.0 Path directory traversal
1827| [124143] Apache SpamAssassin up to 3.4.1 PDFInfo Plugin Code Execution
1828| [124134] Apache SpamAssassin up to 3.4.1 Scan Engine HTML::Parser Email denial of service
1829| [124095] PHP up to 5.6.37/7.0.31/7.1.21/7.2.9 Apache2 sapi_apache2.c php_handler cross site scripting
1830| [124024] Apache Mesos 1.4.x/1.5.0 libprocess JSON Payload denial of service
1831| [123814] Apache ActiveMQ Client up to 5.15.5 TLS Hostname Verification Man-in-the-Middle weak authentication
1832| [123393] Apache Traffic Server up to 6.2.2/7.1.3 ESI Plugin Config privilege escalation
1833| [123392] Apache Traffic Server 6.2.2 TLS Handshake Segmentation Fault denial of service
1834| [123391] Apache Traffic Server up to 6.2.2/7.1.3 Range Request Performance denial of service
1835| [123390] Apache Traffic Server up to 6.2.2/7.1.3 Request HTTP Smuggling privilege escalation
1836| [123369] Apache Traffic Server up to 6.2.2/7.1.3 ACL remap.config Request denial of service
1837| [123197] Apache Sentry up to 2.0.0 privilege escalation
1838| [123145] Apache Struts up to 2.3.34/2.5.16 Namespace Code Execution
1839| [123144] Apache Cayenne up to 4.1.M1 CayenneModeler XML File File Transfer privilege escalation
1840| [122981] Apache Commons Compress 1.7 ZipArchiveInputStream ZIP Archive denial of service
1841| [122889] Apache HTTP Server up to 2.2.31/2.4.23 mod_userdir HTTP Response Splitting privilege escalation
1842| [122800] Apache Spark 1.3.0 REST API weak authentication
1843| [122642] Apache Airflow up to 1.8.x 404 Page Reflected cross site scripting
1844| [122568] Apache Tomcat up to 8.5.31/9.0.9 Connection Reuse weak authentication
1845| [122567] Apache Axis 1.0./1.1/1.2/1.3/1.4 cross site scripting
1846| [122556] Apache Tomcat up to 7.0.86/8.0.51/8.5.30/9.0.7 UTF-8 Decoder Loop denial of service
1847| [122531] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.9 WebSocket Client unknown vulnerability
1848| [122456] Apache Camel up to 2.20.3/2.21.0 XSD Validator XML External Entity
1849| [122455] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Revoked Certificate weak authentication
1850| [122454] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Responder Revoked Certificate weak authentication
1851| [122214] Apache Kafka up to 0.9.0.1/0.10.2.1/0.11.0.2/1.0.0 Broker Request Data Loss denial of service
1852| [122202] Apache Kafka up to 0.10.2.1/0.11.0.1 SASL Impersonation spoofing
1853| [122101] Docker Skeleton Runtime for Apache OpenWhisk Docker Action dockerskeleton:1.3.0 privilege escalation
1854| [122100] PHP Runtime for Apache OpenWhisk Docker Action action-php-v7.2:1.0.0 privilege escalation
1855| [122012] Apache Ignite up to 2.5 Serialization privilege escalation
1856| [121911] Apache Ambari up to 2.5.x/2.6.2 Log Message Credentials information disclosure
1857| [121910] Apache HTTP Server 2.4.33 mod_md HTTP Requests denial of service
1858| [121854] Oracle Tape Library ACSLS up to ACSLS 8.4.0-2 Apache Commons Collections unknown vulnerability
1859| [121752] Oracle Insurance Policy Administration 10.0/10.1/10.2/11.0 Apache Log4j unknown vulnerability
1860| [121370] Apache Spark up to 2.1.2/2.2.1/2.3.0 URL cross site scripting
1861| [121354] Apache CouchDB HTTP API Code Execution
1862| [121144] Apache LDAP API up to 1.0.1 SSL Filter information disclosure
1863| [121143] Apache Storm up to 0.10.2/1.0.6/1.1.2/1.2.1 Cluster privilege escalation
1864| [120436] Apache CXF Fediz up to 1.4.3 Application Plugin unknown vulnerability
1865| [120310] Apache PDFbox up to 1.8.14/2.0.10 AFMParser Loop denial of service
1866| [120168] Apache CXF weak authentication
1867| [120080] Apache Cassandra up to 3.11.1 JMX/RMI Interface RMI Request privilege escalation
1868| [120043] Apache HBase up to 1.2.6.0/1.3.2.0/1.4.4/2.0.0 Thrift 1 API Server weak authentication
1869| [119723] Apache Qpid Broker-J 7.0.0/7.0.1/7.0.2/7.0.3/7.0.4 AMQP Messages Crash denial of service
1870| [122569] Apache HTTP Server up to 2.4.33 HTTP2 Request denial of service
1871| [119486] Apache Geode up to 1.4.0 Security Manager Code Execution
1872| [119306] Apache MXNet Network Interface privilege escalation
1873| [118999] Apache Storm up to 1.0.6/1.1.2/1.2.1 Archive directory traversal
1874| [118996] Apache Storm up to 1.0.6/1.1.2/1.2.1 Daemon spoofing
1875| [118644] Apple macOS up to 10.13.5 apache_mod_php unknown vulnerability
1876| [118200] Apache Batik up to 1.9 Deserialization unknown vulnerability
1877| [118143] Apache NiFi activemq-client Library Deserialization denial of service
1878| [118142] Apache NiFi 1.6.0 SplitXML xxe privilege escalation
1879| [118051] Apache Zookeeper up to 3.4.9/3.5.3-beta weak authentication
1880| [117997] Apache ORC up to 1.4.3 ORC File Recursion denial of service
1881| [117825] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.8 CORS Filter privilege escalation
1882| [117405] Apache Derby up to 10.14.1.0 Network Server Network Packet privilege escalation
1883| [117347] Apache Ambari up to 2.6.1 HTTP Request directory traversal
1884| [117265] LibreOffice/Apache Office Writer SMB Connection XML Document information disclosure
1885| [117143] Apache uimaj/uima-as/uimaFIT/uimaDUCC XML XXE information disclosure
1886| [117117] Apache Tika up to 1.17 ChmParser Loop denial of service
1887| [117116] Apache Tika up to 1.17 BPGParser Loop denial of service
1888| [117115] Apache Tika up to 1.17 tika-server command injection
1889| [116929] Apache Fineract getReportType Parameter privilege escalation
1890| [116928] Apache Fineract REST Endpoint Parameter privilege escalation
1891| [116927] Apache Fineract MakercheckersApiResource Parameter sql injection
1892| [116926] Apache Fineract REST Parameter privilege escalation
1893| [116574] Apache wicket-jquery-ui up to 6.29.0/7.10.1/8.0.0-M9.1 WYSIWYG Editor privilege escalation
1894| [116622] Oracle Enterprise Manager for MySQL Database 12.1.0.4 EM Plugin: General (Apache Tomcat) unknown vulnerability
1895| [115931] Apache Solr up to 6.6.2/7.2.1 XML Data Parameter XML External Entity
1896| [115883] Apache Hive up to 2.3.2 privilege escalation
1897| [115882] Apache Hive up to 2.3.2 xpath_short information disclosure
1898| [115881] Apache DriverHive JDBC Driver up to 2.3.2 Escape Argument Bypass privilege escalation
1899| [115518] Apache Ignite 2.3 Deserialization privilege escalation
1900| [115260] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache cross site scripting
1901| [115259] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache Cookie Stack-based memory corruption
1902| [115500] CA Workload Control Center up to r11.4 SP5 Apache MyFaces Component Code Execution
1903| [115121] Apache Struts REST Plugin up to 2.5.15 Xstream XML Data denial of service
1904| [115061] Apache HTTP Server up to 2.4.29 HTTP Digest Authentication Challenge HTTP Requests Replay privilege escalation
1905| [115060] Apache HTTP Server up to 2.4.29 mod_cache_socache Request Header Crash denial of service
1906| [115059] Apache HTTP Server up to 2.4.29 HTTP2 NULL Pointer Dereference denial of service
1907| [115058] Apache HTTP Server up to 2.4.29 HTTP Header Crash denial of service
1908| [115057] Apache HTTP Server up to 2.4.29 mod_session Variable Name Cache privilege escalation
1909| [115039] Apache HTTP Server up to 2.4.29 FilesMatch File Upload privilege escalation
1910| [115038] Apache HTTP Server up to 2.0.65/2.2.34/2.4.29 mod_authnz_ldap Crash denial of service
1911| [114817] Apache Syncope up to 1.2.10/2.0.7 Search Parameter information disclosure
1912| [114816] Apache Syncope up to 1.2.10/2.0.7 XSLT Code Execution
1913| [114717] Apache Commons 1.11/1.12/1.13/1.14/1.15 ZIP Archive ZipFile/ZipArchiveInputStream denial of service
1914| [114661] Apache Allura up to 1.8.0 HTTP Response Splitting privilege escalation
1915| [114400] Apache Tomcat JK ISAPI Connector up to 1.2.42 IIS/ISAPI privilege escalation
1916| [114258] Apache HTTP Server up to 2.4.22 mod_cluster Segmentation Fault denial of service
1917| [114086] Apache ODE 1.3.3 ODE Process Deployment Web Service directory traversal
1918| [113955] Apache Xerces-C up to 3.2.0 XML Parser NULL Pointer Dereference denial of service
1919| [113945] Apache Tomcat up to 7.0.84/8.0.49/8.5.27/9.0.4 URL Pattern Empty String privilege escalation
1920| [113944] Apache OpenMeetings up to 3.x/4.0.1 CRUD Operation denial of service
1921| [113905] Apache Traffic Server up to 5.2.x/5.3.2/6.2.0/7.0.0 TLS Handshake Core Dump denial of service
1922| [113904] Apache Traffic Server up to 6.2.0 Host Header privilege escalation
1923| [113895] Apache Geode up to 1.3.x Code Execution
1924| [113894] Apache Geode up to 1.3.x TcpServer Code Execution
1925| [113888] Apache James Hupa WebMail 0.0.2 cross site scripting
1926| [113813] Apache Geode Cluster up to 1.3.x Secure Mode privilege escalation
1927| [113747] Apache Tomcat Servlets privilege escalation
1928| [113647] Apache Qpid up to 0.30 qpidd Broker AMQP Message Crash denial of service
1929| [113645] Apache VCL up to 2.1/2.2.1/2.3.1 Web GUI/XMLRPC API privilege escalation
1930| [113560] Apache jUDDI Console 3.0.0 Log Entries spoofing
1931| [113571] Apache Oozie up to 4.3.0/5.0.0-beta1 XML Data XML File privilege escalation
1932| [113569] Apache Karaf up to 4.0.7 LDAPLoginModule LDAP injection denial of service
1933| [113273] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
1934| [113198] Apache Qpid Dispatch Router 0.7.0/0.8.0 AMQP denial of service
1935| [113186] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
1936| [113145] Apache Thrift up to 0.9.3 Go Client Library privilege escalation
1937| [113106] Apache jUDDI up to 3.3.3 XML Data WADL2Java/WSDL2Java XML Document privilege escalation
1938| [113105] Apache Qpid Broker-J 7.0.0 AMQP Crash denial of service
1939| [112885] Apache Allura up to 1.8.0 File information disclosure
1940| [112856] Apache CloudStack up to 4.8.1.0/4.9.0.0 API weak authentication
1941| [112855] Apache CloudStack 4.1.0/4.1.1 API information disclosure
1942| [112678] Apache Tomcat up to 7.0.82/8.0.47/8.5.23/9.0.1 Bug Fix 61201 privilege escalation
1943| [112677] Apache Tomcat Native Connector up to 1.1.34/1.2.14 OCSP Checker Client weak authentication
1944| [112625] Apache POI up to 3.16 Loop denial of service
1945| [112448] Apache NiFi up to 1.3.x Deserialization privilege escalation
1946| [112396] Apache Hadoop 2.7.3/2.7.4 YARN NodeManager Credentials information disclosure
1947| [112339] Apache NiFi 1.5.0 Header privilege escalation
1948| [112330] Apache NiFi 1.5.0 Header HTTP Request privilege escalation
1949| [112314] NetGain Enterprise Manager 7.2.730 Build 1034 org.apache.jsp.u.jsp.tools.exec_jsp Servlet Parameter privilege escalation
1950| [112253] Apache Hadoop up to 0.23.x/2.7.4/2.8.2 MapReduce Job History Server Configuration File privilege escalation
1951| [112171] Oracle Secure Global Desktop 5.3 Apache Log4j privilege escalation
1952| [112164] Oracle Agile PLM 9.3.5/9.3.6 Apache Tomcat unknown vulnerability
1953| [112161] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Tomcat privilege escalation
1954| [112158] Oracle Autovue for Agile Product Lifecycle Management 21.0.0/21.0.1 Apache Log4j privilege escalation
1955| [112156] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Log4j privilege escalation
1956| [112155] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Apache Log4j privilege escalation
1957| [112137] Oracle MICROS Relate CRM Software 10.8.x/11.4.x/15.0.x, Apache Tomcat unknown vulnerability
1958| [112136] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat privilege escalation
1959| [112133] Oracle Retail Workforce Management 1.60.7/1.64.0 Apache Log4j privilege escalation
1960| [112129] Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 Apache Log4j privilege escalation
1961| [112114] Oracle 9.1 Apache Log4j privilege escalation
1962| [112113] Oracle 9.1 Apache Log4j privilege escalation
1963| [112045] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat privilege escalation
1964| [112038] Oracle Health Sciences Empirica Inspections 1.0.1.1 Apache Tomcat information disclosure
1965| [112019] Oracle Endeca Information Discovery Integrator 3.1.0/3.2.0 Apache Tomcat privilege escalation
1966| [112017] Oracle WebCenter Portal 11.1.1.9.0/12.2.1.2.0/12.2.1.3.0 Apache Struts 1 cross site scripting
1967| [112011] Oracle Identity Manager 11.1.2.3.0 Apache Commons Collections privilege escalation
1968| [111950] Oracle Database 12.2.0.1 Apache Tomcat information disclosure
1969| [111703] Apache Sling XSS Protection API 1.0.4 URL Encoding cross site scripting
1970| [111556] Apache Geode up to 1.2.x Secure Mode Parameter OQL privilege escalation
1971| [111555] Apache Geode up to 1.2.x Secure Mode OQL privilege escalation
1972| [111540] Apache Geode up to 1.2.x Secure Mode information disclosure
1973| [111519] Apache Sling JCR ContentLoader 2.1.4 xmlreader directory traversal
1974| [111338] Apache DeltaSpike-JSF 1.8.0 cross site scripting
1975| [111330] Apache OFBiz 16.11.01/16.11.02/16.11.03 BIRT Plugin cross site scripting
1976| [110789] Apache Sling up to 1.4.0 Authentication Service Credentials information disclosure
1977| [110785] Apache Drill up to 1.11.0 Query Page unknown vulnerability
1978| [110701] Apache Fineract Query Parameter sql injection
1979| [110484] Apache Synapse up to 3.0.0 Apache Commons Collections Serialized Object Code Injection privilege escalation
1980| [110426] Adobe Experience Manager 6.0/6.1/6.2/6.3 Apache Sling Servlets Post cross site scripting
1981| [110141] Apache Struts up to 2.5.14 REST Plugin denial of service
1982| [110140] Apache Qpid Broker-J up to 0.32 privilege escalation
1983| [110139] Apache Qpid Broker-J up to 6.1.4 AMQP Frame denial of service
1984| [110106] Apache CXF Fediz Spring cross site request forgery
1985| [109766] Apache OpenOffice up to 4.1.3 DOC File Parser WW8Fonts memory corruption
1986| [109750] Apache OpenOffice up to 4.1.3 DOC File Parser ImportOldFormatStyles memory corruption
1987| [109749] Apache OpenOffice up to 4.1.3 PPT File Parser PPTStyleSheet memory corruption
1988| [109606] October CMS Build 412 Apache Configuration File Upload privilege escalation
1989| [109419] Apache Camel up to 2.19.3/2.20.0 camel-castor Java Object Deserialization privilege escalation
1990| [109418] Apache Camel up to 2.19.3/2.20.0 camel-hessian Java Object Deserialization privilege escalation
1991| [109400] Apache CouchDB up to 1.6.x/2.1.0 Database Server Shell privilege escalation
1992| [109399] Apache CouchDB up to 1.6.x/2.1.0 JSON Parser Shell privilege escalation
1993| [109398] Apache CXF 3.1.14/3.2.1 JAX-WS/JAX-RS Attachment denial of service
1994| [108872] Apache Hive up to 2.1.1/2.2.0/2.3.0 Policy Enforcement privilege escalation
1995| [108939] Apple macOS up to 10.13.1 apache unknown vulnerability
1996| [108938] Apple macOS up to 10.13.1 apache denial of service
1997| [108937] Apple macOS up to 10.13.1 apache unknown vulnerability
1998| [108936] Apple macOS up to 10.13.1 apache unknown vulnerability
1999| [108935] Apple macOS up to 10.13.1 apache denial of service
2000| [108934] Apple macOS up to 10.13.1 apache unknown vulnerability
2001| [108933] Apple macOS up to 10.13.1 apache unknown vulnerability
2002| [108932] Apple macOS up to 10.13.1 apache unknown vulnerability
2003| [108931] Apple macOS up to 10.13.1 apache denial of service
2004| [108930] Apple macOS up to 10.13.1 apache unknown vulnerability
2005| [108929] Apple macOS up to 10.13.1 apache denial of service
2006| [108928] Apple macOS up to 10.13.1 apache unknown vulnerability
2007| [108797] Apache Struts up to 2.3.19 TextParseUtiltranslateVariables OGNL Expression privilege escalation
2008| [108795] Apache Traffic Server up to 5.3.0 HTTP2 set_dynamic_table_size memory corruption
2009| [108794] Apache WSS4J up to 1.6.16/2.0.1 Incomplete Fix Leak information disclosure
2010| [108793] Apache Qpid up to 0.30 qpidd Crash denial of service
2011| [108792] Apache Traffic Server up to 5.1.0 Access Restriction privilege escalation
2012| [108791] Apache Wicket up to 1.5.11/6.16.x/7.0.0-M2 Session information disclosure
2013| [108790] Apache Storm 0.9.0.1 Log Viewer directory traversal
2014| [108789] Apache Cordova In-App-Browser Standalone Plugin up to 0.3.1 on iOS CDVInAppBrowser privilege escalation
2015| [108788] Apache Cordova File-Transfer Standalone Plugin up to 0.4.1 on iOS ios/CDVFileTransfer.m spoofing
2016| [108787] Apache HttpClient up to 4.3.0 HttpClientBuilder.java unknown vulnerability
2017| [108786] Apache Wicket up to 1.4.21/1.5.9/6.3.x script Tag cross site scripting
2018| [108783] Apache Hadoop up to 0.23.3/1.0.3/2.0.1 Kerberos Security Feature Key weak encryption
2019| [108782] Apache Xerces2 XML Service denial of service
2020| [108781] Apache jUDDI up to 1.x happyjuddi.jsp Parameter cross site scripting
2021| [108780] Apache jUDDI up to 1.x Log File uddiget.jsp spoofing
2022| [108709] Apache Cordova Android up to 3.7.1/4.0.1 intent URL privilege escalation
2023| [108708] Apache ActiveMQ up to 5.10.0 XML Data XML External Entity
2024| [108707] Apache ActiveMQ up to 1.7.0 XML Data XML External Entity
2025| [108629] Apache OFBiz up to 10.04.01 privilege escalation
2026| [108543] Apache Derby 10.1.2.1/10.2.2.0/10.3.1.4/10.4.1.3 Export File privilege escalation
2027| [108312] Apache HTTP Server on RHEL IP Address Filter privilege escalation
2028| [108297] Apache NiFi up to 0.7.1/1.1.1 Proxy Chain Username Deserialization privilege escalation
2029| [108296] Apache NiFi up to 0.7.1/1.1.1 Cluster Request privilege escalation
2030| [108250] Oracle Secure Global Desktop 5.3 Apache HTTP Server memory corruption
2031| [108245] Oracle Transportation Management up to 6.3.7 Apache Tomcat unknown vulnerability
2032| [108244] Oracle Transportation Management 6.4.1/6.4.2 Apache Commons FileUpload denial of service
2033| [108243] Oracle Agile Engineering Data Management 6.1.3/6.2.0 Apache Commons Collections memory corruption
2034| [108222] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Batik denial of service
2035| [108219] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat unknown vulnerability
2036| [108217] Oracle Retail Store Inventory Management 13.2.9/14.0.4/14.1.3/15.0.1/16.0.1 Apache Groovy unknown vulnerability
2037| [108216] Oracle Retail Convenience and Fuel POS Software 2.1.132 Apache Groovy unknown vulnerability
2038| [108169] Oracle MySQL Enterprise Monitor up to 3.2.8.2223/3.3.4.3247/3.4.2.4181 Apache Tomcat unknown vulnerability
2039| [108113] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Batik denial of service
2040| [108107] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat unknown vulnerability
2041| [108102] Oracle Healthcare Master Person Index 4.x Apache Groovy unknown vulnerability
2042| [108085] Oracle Identity Manager 11.1.2.3.0 Apache Struts 1 memory corruption
2043| [108083] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
2044| [108080] Oracle GlassFish Server 3.1.2 Apache Commons FileUpload denial of service
2045| [108066] Oracle Management Pack for GoldenGate 11.2.1.0.12 Apache Tomcat memory corruption
2046| [108062] Oracle BI Publisher 11.1.1.7.0/12.2.1.1.0/12.2.1.2.0 Apache ActiveMQ memory corruption
2047| [108060] Oracle Enterprise Manager Ops Center 12.2.2/12.3.2 Apache Groovy unknown vulnerability
2048| [108033] Oracle Primavera Unifier 9.13/9.14/10.x/15.x/16.x, Apache Groovy unknown vulnerability
2049| [108013] Oracle Communications WebRTC Session Controller 7.0/7.1/7.2 Apache Groovy unknown vulnerability
2050| [108011] Oracle Communications Services Gatekeeper 5.1/6.0 Apache Trinidad unknown vulnerability
2051| [107904] Apache Struts up to 2.3.28 Double OGNL Evaluation privilege escalation
2052| [107860] Apache Solr up to 7.0 Apache Lucene RunExecutableListener XML External Entity
2053| [107834] Apache Ranger up to 0.6.1 Change Password privilege escalation
2054| [107639] Apache NiFi 1.4.0 XML External Entity
2055| [107606] Apache ZooKeper up to 3.4.9/3.5.2 Command CPU Exhaustion denial of service
2056| [107597] Apache Roller up to 5.0.2 XML-RPC Protocol Support XML External Entity
2057| [107429] Apache Impala up to 2.9.x Kudu Table privilege escalation
2058| [107411] Apache Tomcat up to 7.0.81/8.0.46/8.5.22/9.0.0 JSP File File Upload privilege escalation
2059| [107385] Apache Geode up to 1.2.0 Secure Mode privilege escalation
2060| [107339] Apache OpenNLP up to 1.5.3/1.6.0/1.7.2/1.8.1 XML Data XML External Entity
2061| [107333] Apache Wicket up to 8.0.0-M1 CSRF Prevention HTTP Header privilege escalation
2062| [107323] Apache Wicket 1.5.10/6.13.0 Class Request information disclosure
2063| [107310] Apache Geode up to 1.2.0 Command Line Utility Query privilege escalation
2064| [107276] ArcSight ESM/ArcSight ESM Express up to 6.9.1c Patch 3/6.11.0 Apache Tomcat Version information disclosure
2065| [107266] Apache Tika up to 1.12 XML Parser XML External Entity
2066| [107262] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
2067| [107258] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
2068| [107197] Apache Xerces Jelly Parser XML File XML External Entity
2069| [107193] ZTE NR8950 Apache Commons Collections RMI Request Deserialization privilege escalation
2070| [107084] Apache Struts up to 2.3.19 cross site scripting
2071| [106877] Apache Struts up to 2.0.33/2.5.10 Freemarker Tag privilege escalation
2072| [106875] Apache Struts up to 2.5.5 URL Validator denial of service
2073| [106874] Apache Struts up to 2.3.30 Convention Plugin directory traversal
2074| [106847] Apache Tomcat up to 7.0.80 VirtualDirContext Source information disclosure
2075| [106846] Apache Tomcat up to 7.0.79 on Windows HTTP PUT Method Parameter File Upload privilege escalation
2076| [106777] Apache HTTP Server up to 2.2.34/2.4.27 Limit Directive ap_limit_section HTTP Request information disclosure
2077| [106739] puppetlabs-apache up to 1.11.0/2.0.x weak authentication
2078| [106720] Apache Wicket up to 1.5.12/6.18.x/7.0.0-M4 CryptoMapper privilege escalation
2079| [106586] Apache Brooklyn up to 0.9.x REST Server cross site scripting
2080| [106562] Apache Spark up to 2.1.1 Launcher API Deserialization privilege escalation
2081| [106559] Apache Brooklyn up to 0.9.x SnakeYAML YAML Data Java privilege escalation
2082| [106558] Apache Brooklyn up to 0.9.x REST Server cross site request forgery
2083| [106556] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
2084| [106555] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
2085| [106171] Apache Directory LDAP API up to 1.0.0-M30 Timing unknown vulnerability
2086| [106167] Apache Struts up to 2.5.12 REST Plugin XML Data privilege escalation
2087| [106166] Apache Struts up to 2.3.33/2.5.12 REST Plugin denial of service
2088| [106165] Apache Struts up to 2.3.33/2.5.12 URLValidator Regex CPU Exhaustion denial of service
2089| [106115] Apache Hadoop up to 2.6.4/2.7.2 YARN NodeManager Password information disclosure
2090| [106012] Apache Solr up to 5.5.3/6.4.0 Replication directory traversal
2091| [105980] Apache Engine 16.11.01 Parameter Reflected unknown vulnerability
2092| [105962] Apache Atlas 0.6.0/0.7.0 Frame cross site scripting
2093| [105961] Apache Atlas 0.6.0/0.7.0 Stack Trace information disclosure
2094| [105960] Apache Atlas 0.6.0/0.7.0 Search Reflected cross site scripting
2095| [105959] Apache Atlas 0.6.0/0.7.0 edit Tag DOM cross site scripting
2096| [105958] Apache Atlas 0.6.0/0.7.0 edit Tag Stored cross site scripting
2097| [105957] Apache Atlas 0.6.0/0.7.0 Cookie privilege escalation
2098| [105905] Apache Atlas 0.6.0/0.7.0/0.7.1 /js privilege escalation
2099| [105878] Apache Struts up to 2.3.24.0 privilege escalation
2100| [105682] Apache2Triad 1.5.4 phpsftpd/users.php Parameter cross site scripting
2101| [105681] Apache2Triad 1.5.4 phpsftpd/users.php Request cross site request forgery
2102| [105680] Apache2Triad 1.5.4 Parameter Session Fixation weak authentication
2103| [105643] Apache Pony Mail up to 0.8b weak authentication
2104| [105288] Apache Sling up to 2.3.21 Sling.evalString() String cross site scripting
2105| [105219] Apache Tomcat up to 8.5.15/9.0.0.M21 HTTP2 Bypass directory traversal
2106| [105218] Apache Tomcat up to 7.0.78/8.0.44/8.5.15/9.0.0.M21 CORS Filter Cache Poisoning privilege escalation
2107| [105215] Apache CXF up to 3.0.12/3.1.9 OAuth2 Hawk/JOSE MAC Validation Timing unknown vulnerability
2108| [105206] Apache CXF up to 3.0.11/3.1.8 JAX-RS Module XML External Entity
2109| [105205] Apache CXF up to 3.0.11/3.1.8 HTTP Transport Module Parameter cross site scripting
2110| [105202] Apache Storm 1.0.0/1.0.1/1.0.2/1.0.3/1.1.0 Worker privilege escalation
2111| [104987] Apache Xerces-C++ XML Service CPU Exhaustion denial of service
2112| [104986] Apache CXF 2.4.5/2.5.1 WS-SP UsernameToken Policy SOAP Request weak authentication
2113| [104985] Apache MyFaces Core up to 2.1.4 EL Expression Parameter Injection information disclosure
2114| [104983] Apache Wink up to 1.1.1 XML Document xxe privilege escalation
2115| [104981] Apache Commons Email 1.0/1.1/1.2/1.3/1.4 Subject Linebreak SMTP privilege escalation
2116| [104591] MEDHOST Document Management System Apache Solr Default Credentials weak authentication
2117| [104062] Oracle MySQL Enterprise Monitor up to 3.3.3.1199 Apache Tomcat unknown vulnerability
2118| [104061] Oracle MySQL Enterprise Monitor up to 3.2.7.1204/3.3.3.1199 Apache Tomcat unknown vulnerability
2119| [104060] Oracle MySQL Enterprise Monitor up to 3.1.5.7958/3.2.5.1141/3.3.2.1162 Apache Struts 2 unknown vulnerability
2120| [103995] Oracle 8.3/8.4/15.1/15.2 Apache Trinidad unknown vulnerability
2121| [103993] Oracle Policy Automation up to 12.2.3 Apache Commons FileUplaod denial of service
2122| [103916] Oracle Banking Platform 2.3/2.4/2.4.1/2.5 Apache Commons FileUpload denial of service
2123| [103906] Oracle Communications BRM 11.2.0.0.0 Apache Commons Collections privilege escalation
2124| [103904] Oracle Communications BRM 11.2.0.0.0/11.3.0.0.0 Apache Groovy memory corruption
2125| [103866] Oracle Transportation Management 6.1/6.2 Apache Webserver unknown vulnerability
2126| [103816] Oracle BI Publisher 11.1.1.9.0/12.2.1.1.0/12.2.1.2.0 Apache Commons Fileupload denial of service
2127| [103797] Oracle Tuxedo System and Applications Monitor Apache Commons Collections privilege escalation
2128| [103792] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Commons Fileupload privilege escalation
2129| [103791] Oracle Endeca Server 7.6.0.0/7.6.1.0 Apache Commons Collections privilege escalation
2130| [103788] Oracle Enterprise Repository 11.1.1.7.0/12.1.3.0.0 Apache ActiveMQ memory corruption
2131| [103787] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Groovy memory corruption
2132| [103763] Apache Sling up to 1.0.11 XSS Protection API XSS.getValidXML() Application XML External Entity
2133| [103762] Apache Sling up to 1.0.12 XSS Protection API XSSAPI.encodeForJSString() Script Tag cross site scripting
2134| [103693] Apache OpenMeetings 1.0.0 HTTP Method privilege escalation
2135| [103692] Apache OpenMeetings 1.0.0 Tomcat Error information disclosure
2136| [103691] Apache OpenMeetings 3.2.0 Parameter privilege escalation
2137| [103690] Apache OpenMeetings 1.0.0 sql injection
2138| [103689] Apache OpenMeetings 1.0.0 crossdomain.xml privilege escalation
2139| [103688] Apache OpenMeetings 1.0.0 weak encryption
2140| [103687] Apache OpenMeetings 1.0.0 cross site request forgery
2141| [103556] Apache Roller 5.1.0/5.1.1 Weblog Page Template VTL privilege escalation
2142| [103554] Apache OpenMeetings 1.0.0 Password Update unknown vulnerability
2143| [103553] Apache OpenMeetings 1.0.0 File Upload privilege escalation
2144| [103552] Apache OpenMeetings 3.2.0 Chat cross site scripting
2145| [103551] Apache OpenMeetings 3.1.0 XML unknown vulnerability
2146| [103521] Apache HTTP Server 2.4.26 HTTP2 Free memory corruption
2147| [103520] Apache HTTP Server up to 2.2.33/2.4.26 mod_auth_digest Authorization Header memory corruption
2148| [103519] Apache Struts up to 2.5.11/2.3.32 Spring AOP denial of service
2149| [103518] Apache Struts up to 2.5.11 URLValidator directory traversal
2150| [103492] Apache Spark up to 2.1.x Web UI Reflected cross site scripting
2151| [103401] Apache Struts 2.3.x Struts 1 Plugin ActionMessage privilege escalation
2152| [103399] Apache Traffic Control Traffic Router TCP Connection Slowloris denial of service
2153| [103387] Apache Impala up to 2.8.0 StatestoreSubscriber weak encryption
2154| [103386] Apache Impala up to 2.7.x/2.8.0 Kerberos weak authentication
2155| [103352] Apache Solr Node weak authentication
2156| [102897] Apache Ignite up to 2.0 Update Notifier information disclosure
2157| [102878] Code42 CrashPlan 5.4.x RMI Server org.apache.commons.ssl.rmi.DateRMI privilege escalation
2158| [102698] Apache HTTP Server up to 2.2.32/2.4.25 mod_mime Content-Type memory corruption
2159| [102697] Apache HTTP Server 2.2.24/2.2.32 HTTP Strict Parsing ap_find_token Request Header memory corruption
2160| [102690] Apache HTTP Server up to 2.2.32/2.4.25 mod_ssl ap_hook_process_connection() denial of service
2161| [102689] Apache HTTP Server up to 2.2.32/2.4.25 ap_get_basic_auth_pw weak authentication
2162| [102622] Apache Thrift up to 0.9.2 Client Libraries skip denial of service
2163| [102538] Apache Ranger up to 0.7.0 Authorizer unknown vulnerability
2164| [102537] Apache Ranger up to 0.7.0 Wildcard Character unknown vulnerability
2165| [102536] Apache Ranger up to 0.6 Stored cross site scripting
2166| [102535] Apache Ranger up to 0.6.2 Policy Engine unknown vulnerability
2167| [102255] Apache NiFi up to 0.7.3/1.2.x Response Header privilege escalation
2168| [102254] Apache NiFi up to 0.7.3/1.2.x UI cross site scripting
2169| [102070] Apache CXF Fediz up to 1.1.2/1.2.0 Application Plugin denial of service
2170| [102020] Apache Tomcat up to 9.0.0.M1 Java Servlet HTTP Method unknown vulnerability
2171| [101858] Apache Hive up to 1.2.1/2.0.0 Client weak authentication
2172| [101802] Apache KNOX up to 0.11.0 WebHDFS privilege escalation
2173| [101928] HPE Aruba ClearPass Apache Tomcat information disclosure
2174| [101524] Apache Archiva up to 1.x/2.2.1 REST Endpoint cross site request forgery
2175| [101513] Apache jUDDI 3.1./3.1.2/3.1.3/3.1.4 Logout Open Redirect
2176| [101430] Apache CXF Fediz up to 1.3.1 OIDC Service cross site request forgery
2177| [101429] Apache CXF Fediz up to 1.2.3/1.3.1 Plugins cross site request forgery
2178| [100619] Apache Hadoop up to 2.6.x HDFS Servlet unknown vulnerability
2179| [100618] Apache Hadoop up to 2.7.0 HDFS Web UI cross site scripting
2180| [100621] Adobe ColdFusion 10/11/2016 Apache BlazeDS Library Deserialization privilege escalation
2181| [100205] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Apache Commons FileUpload denial of service
2182| [100191] Oracle Secure Global Desktop 4.71/5.2/5.3 Web Server (Apache HTTP Server) information disclosure
2183| [100162] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Commons Collections privilege escalation
2184| [100160] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Trinidad unknown vulnerability
2185| [99969] Oracle WebCenter Sites 11.1.1.8.0 Apache Tomcat memory corruption
2186| [99937] Apache Batik up to 1.8 privilege escalation
2187| [99936] Apache FOP up to 2.1 privilege escalation
2188| [99935] Apache CXF up to 3.0.12/3.1.10 STSClient Cache information disclosure
2189| [99934] Apache CXF up to 3.0.12/3.1.10 JAX-RS XML Security Streaming Client spoofing
2190| [99930] Apache Traffic Server up to 6.2.0 denial of service
2191| [99929] Apache Log4j up to 2.8.1 Socket Server Deserialization privilege escalation
2192| [99925] Apache Traffic Server 6.0.0/6.1.0/6.2.0 HPACK Bomb denial of service
2193| [99738] Ping Identity OpenID Connect Authentication Module up to 2.13 on Apache Mod_auth_openidc.c spoofing
2194| [117569] Apache Hadoop up to 2.7.3 privilege escalation
2195| [99591] Apache TomEE up to 1.7.3/7.0.0-M2 EjbObjectInputStream Serialized Object privilege escalation
2196| [99370] Apache Ignite up to 1.8 update-notifier Document XML External Entity
2197| [99299] Apache Geode up to 1.1.0 Pulse OQL Query privilege escalation
2198| [99572] Apache Tomcat up to 7.0.75/8.0.41/8.5.11/9.0.0.M17 Application Listener privilege escalation
2199| [99570] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP Connector Cache information disclosure
2200| [99569] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP/2 GOAWAY Frame Resource Exhaustion denial of service
2201| [99568] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 Pipelined Request information disclosure
2202| [99048] Apache Ambari up to 2.3.x REST API Shell Metacharacter privilege escalation
2203| [99014] Apache Camel Jackson/JacksonXML privilege escalation
2204| [98610] Apple macOS up to 10.12.3 apache_mod_php memory corruption
2205| [98609] Apple macOS up to 10.12.3 apache_mod_php denial of service
2206| [98608] Apple macOS up to 10.12.3 apache_mod_php memory corruption
2207| [98607] Apple macOS up to 10.12.3 apache_mod_php denial of service
2208| [98606] Apple macOS up to 10.12.3 apache_mod_php denial of service
2209| [98605] Apple macOS up to 10.12.3 Apache denial of service
2210| [98604] Apple macOS up to 10.12.3 Apache denial of service
2211| [98603] Apple macOS up to 10.12.3 Apache denial of service
2212| [98602] Apple macOS up to 10.12.3 Apache denial of service
2213| [98601] Apple macOS up to 10.12.3 Apache denial of service
2214| [98517] Apache POI up to 3.14 OOXML File XXE denial of service
2215| [98405] Apache Hadoop up to 0.23.10 privilege escalation
2216| [98199] Apache Camel Validation XML External Entity
2217| [97892] Apache Tomcat up to 9.0.0.M15 Reverse-Proxy Http11InputBuffer.java information disclosure
2218| [97617] Apache Camel camel-snakeyaml Deserialization privilege escalation
2219| [97602] Apache Camel camel-jackson/camel-jacksonxml CamelJacksonUnmarshalType privilege escalation
2220| [97732] Apache Struts up to 2.3.31/2.5.10 Jakarta Multipart Parser Content-Type privilege escalation
2221| [97466] mod_auth_openidc up to 2.1.5 on Apache weak authentication
2222| [97455] mod_auth_openidc up to 2.1.4 on Apache weak authentication
2223| [97081] Apache Tomcat HTTPS Request denial of service
2224| [97162] EMC OpenText Documentum D2 BeanShell/Apache Commons privilege escalation
2225| [96949] Hanwha Techwin Smart Security Manager up to 1.5 Redis/Apache Felix Gogo privilege escalation
2226| [96314] Apache Cordova up to 6.1.1 on Android weak authentication
2227| [95945] Apple macOS up to 10.12.2 apache_mod_php denial of service
2228| [95944] Apple macOS up to 10.12.2 apache_mod_php denial of service
2229| [95943] Apple macOS up to 10.12.2 apache_mod_php memory corruption
2230| [95666] Oracle FLEXCUBE Direct Banking 12.0.0/12.0.1/12.0.2/12.0.3 Apache Commons Collections privilege escalation
2231| [95455] Apache NiFi up to 1.0.0/1.1.0 Connection Details Dialogue cross site scripting
2232| [95311] Apache Storm UI Daemon privilege escalation
2233| [95291] ZoneMinder 1.30.0 Apache httpd privilege escalation
2234| [94800] Apache Wicket up to 1.5.16/6.24.x Deserialize DiskFileItem denial of service
2235| [94705] Apache Qpid Broker for Java up to 6.1.0 SCRAM-SHA-1/SCRAM-SHA-256 User information disclosure
2236| [94627] Apache HTTP Server up to 2.4.24 mod_auth_digest Crash denial of service
2237| [94626] Apache HTTP Server up to 2.4.24 mod_session_crypto Padding weak encryption
2238| [94625] Apache HTTP Server up to 2.4.24 Response Split privilege escalation
2239| [94540] Apache Tika 1.9 tika-server File information disclosure
2240| [94600] Apache ActiveMQ up to 5.14.1 Administration Console cross site scripting
2241| [94348] Apple macOS up to 10.12.1 apache_mod_php denial of service
2242| [94347] Apple macOS up to 10.12.1 apache_mod_php denial of service
2243| [94346] Apple macOS up to 10.12.1 apache_mod_php denial of service
2244| [94345] Apple macOS up to 10.12.1 apache_mod_php denial of service
2245| [94344] Apple macOS up to 10.12.1 apache_mod_php denial of service
2246| [94343] Apple macOS up to 10.12.1 apache_mod_php memory corruption
2247| [94342] Apple macOS up to 10.12.1 apache_mod_php memory corruption
2248| [94128] Apache Tomcat up to 9.0.0.M13 Error information disclosure
2249| [93958] Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c denial of service
2250| [93874] Apache Subversion up to 1.8.16/1.9.4 mod_dontdothat XXE denial of service
2251| [93855] Apache Hadoop up to 2.6.4/2.7.2 HDFS Service privilege escalation
2252| [93609] Apache OpenMeetings 3.1.0 RMI Registry privilege escalation
2253| [93555] Apache Tika 1.6-1.13 jmatio MATLAB File privilege escalation
2254| [93799] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
2255| [93798] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
2256| [93797] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 HTTP Split privilege escalation
2257| [93796] Apache Tomcat up to 8.5.6/9.0.0.M11 HTTP/2 Header Parser denial of service
2258| [93532] Apache Commons Collections Library Java privilege escalation
2259| [93210] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 ResourceLinkFactory privilege escalation
2260| [93209] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Realm Authentication User information disclosure
2261| [93208] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 System Property Replacement information disclosure
2262| [93207] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Utility Method privilege escalation
2263| [93206] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Configuration privilege escalation
2264| [93098] Apache Commons FileUpload privilege escalation
2265| [92987] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Commons Collection memory corruption
2266| [92986] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Tomcat memory corruption
2267| [92982] Oracle Insurance IStream 4.3.2 Apache Commons Collections memory corruption
2268| [92981] Oracle Financial Services Lending and Leasing 14.1.0/14.2.0 Apache Commons Collections memory corruption
2269| [92979] Oracle up to 8.0.3 Apache Commons Collections memory corruption
2270| [92977] Oracle FLEXCUBE Universal Banking up to 12.2.0 Apache Commons Collections memory corruption
2271| [92976] Oracle FLEXCUBE Universal Banking 12.87.1/12.87.2 Apache Commons Collections memory corruption
2272| [92975] Oracle FLEXCUBE Private Banking up to 12.1.0 Apache Commons Collections memory corruption
2273| [92974] Oracle FLEXCUBE Investor Servicing 12.0.1 Apache Commons Collections memory corruption
2274| [92973] Oracle 12.0.0/12.1.0 Apache Commons Collections memory corruption
2275| [92972] Oracle FLEXCUBE Core Banking 11.5.0.0.0/11.6.0.0.0 Apache Commons Collections memory corruption
2276| [92962] Oracle Agile PLM 9.3.4/9.3.5 Apache Commons Collections memory corruption
2277| [92909] Oracle Agile PLM 9.3.4/9.3.5 Apache Tomcat unknown vulnerability
2278| [92786] Oracle Banking Digital Experience 15.1 Apache Commons Collections information disclosure
2279| [92549] Apache Tomcat on Red Hat privilege escalation
2280| [92509] Apache Tomcat JK ISAPI Connector up to 1.2.41 jk_uri_worker_map.c memory corruption
2281| [92314] Apache MyFaces Trinidad up to 1.0.13/1.2.15/2.0.1/2.1.1 CoreResponseStateManager memory corruption
2282| [92313] Apache Struts2 up to 2.3.28/2.5.0 Action Name Cleanup cross site request forgery
2283| [92299] Apache Derby up to 10.12.1.0 SqlXmlUtil XML External Entity
2284| [92217] Apache ActiveMQ Artemis up to 1.3.x Broker/REST GetObject privilege escalation
2285| [92174] Apache Ranger up to 0.6.0 Policy cross site scripting
2286| [91831] Apache Jackrabbit up to 2.13.2 HTTP Header cross site request forgery
2287| [91825] Apache Zookeeper up to 3.4.8/3.5.2 C CLI Shell memory corruption
2288| [91818] Apache CXF Fediz up to 1.2.2/1.3.0 Application Plugin privilege escalation
2289| [92056] Apple macOS up to 10.11 apache_mod_php memory corruption
2290| [92055] Apple macOS up to 10.11 apache_mod_php memory corruption
2291| [92054] Apple macOS up to 10.11 apache_mod_php denial of service
2292| [92053] Apple macOS up to 10.11 apache_mod_php denial of service
2293| [92052] Apple macOS up to 10.11 apache_mod_php denial of service
2294| [92051] Apple macOS up to 10.11 apache_mod_php memory corruption
2295| [92050] Apple macOS up to 10.11 apache_mod_php denial of service
2296| [92049] Apple macOS up to 10.11 apache_mod_php memory corruption
2297| [92048] Apple macOS up to 10.11 apache_mod_php denial of service
2298| [92047] Apple macOS up to 10.11 apache_mod_php memory corruption
2299| [92046] Apple macOS up to 10.11 apache_mod_php memory corruption
2300| [92045] Apple macOS up to 10.11 apache_mod_php memory corruption
2301| [92044] Apple macOS up to 10.11 apache_mod_php memory corruption
2302| [92043] Apple macOS up to 10.11 apache_mod_php denial of service
2303| [92042] Apple macOS up to 10.11 apache_mod_php memory corruption
2304| [92041] Apple macOS up to 10.11 apache_mod_php memory corruption
2305| [92040] Apple macOS up to 10.11 Apache Proxy privilege escalation
2306| [91785] Apache Shiro up to 1.3.1 Servlet Filter privilege escalation
2307| [90879] Apache OpenMeetings up to 3.1.1 SWF Panel cross site scripting
2308| [90878] Apache Sentry up to 1.6.x Blacklist Filter reflect/reflect2/java_method privilege escalation
2309| [90610] Apache POI up to 3.13 XLSX2CSV Example OpenXML Document XML External Entity
2310| [90584] Apache ActiveMQ up to 5.11.3/5.12.2/5.13/1 Administration Web Console privilege escalation
2311| [90385] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site scripting
2312| [90384] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site request forgery
2313| [90383] Apache OpenOffice up to 4.1.2 Impress File memory corruption
2314| [89670] Apache Tomcat up to 8.5.4 CGI Servlet Environment Variable Open Redirect
2315| [89669] Apache HTTP Server up to 2.4.23 RFC 3875 Namespace Conflict Environment Variable Open Redirect
2316| [89726] Apple Mac OS X up to 10.11.5 apache_mod_php memory corruption
2317| [89484] Apache Qpid up to 0.13.0 on Windows Proton Library Certificate weak authentication
2318| [89473] HPE iMC PLAT/EAD/APM/iMC NTA/iMC BIMS/iMC UAM_TAM up to 7.2 Apache Commons Collections Library Command privilege escalation
2319| [90263] Apache Archiva Header denial of service
2320| [90262] Apache Archiva Deserialize privilege escalation
2321| [90261] Apache Archiva XML DTD Connection privilege escalation
2322| [88827] Apache Xerces-C++ up to 3.1.3 DTD Stack-Based memory corruption
2323| [88747] Apache HTTP Server 2.4.17/2.4.18 mod_http2 denial of service
2324| [88608] Apache Struts up to 2.3.28.1/2.5.0 URLValidator Null Value denial of service
2325| [88607] Apache Struts up to 2.3.28.1 REST Plugin Expression privilege escalation
2326| [88606] Apache Struts up to 2.3.28.1 Restriction privilege escalation
2327| [88605] Apache Struts up to 2.3.28.1 Restriction privilege escalation
2328| [88604] Apache Struts up to 2.3.28.1 Token Validator cross site request forgery
2329| [88603] Apache Commons FileUpload up to 1.3.1 MultipartStream denial of service
2330| [88602] Apache Struts up to 1.3.10 ActionServlet.java cross site scripting
2331| [88601] Apache Struts up to 1.3.10 Multithreading ActionServlet.java memory corruption
2332| [88600] Apache Struts up to 1.3.10 MultiPageValidator privilege escalation
2333| [89005] Apache Qpid AMQP JMS Client getObject privilege escalation
2334| [87888] Apache Ranger up to 0.5.2 Policy Admin Tool eventTime sql injection
2335| [87835] Apache CloudStack up to 4.5.2.0/4.6.2.0/4.7.1.0/4.8.0.0 SAML-based Authentication privilege escalation
2336| [87806] HPE Discovery and Dependency Mapping Inventory up to 9.32 update 3 Apache Commons Collections Library privilege escalation
2337| [87805] HPE Universal CMDB up to 10.21 Apache Commons Collections Library privilege escalation
2338| [87768] Apache Shiro up to 1.2.4 Cipher Key privilege escalation
2339| [87765] Apache James Server 2.3.2 Command privilege escalation
2340| [88667] Apache HTTP Server up to 2.4.20 mod_http2 Certificate weak authentication
2341| [87718] Apache Struts up to 2.3.24.1 OGNL Caching denial of service
2342| [87717] Apache Struts up to 2.3.28 REST Plugin privilege escalation
2343| [87706] Apache Qpid Java up to 6.0.2 AMQP privilege escalation
2344| [87703] Apache Qbid Java up to 6.0.2 PlainSaslServer.java denial of service
2345| [87702] Apache ActiveMQ up to 5.13.x Fileserver Web Application Upload privilege escalation
2346| [87700] Apache PDFbox up to 1.8.11/2.0.0 XML Parser PDF Document XML External Entity
2347| [87679] HP Release Control 9.13/9.20/9.21 Apache Commons Collections Library Java Object privilege escalation
2348| [87540] Apache Ambari up to 2.2.0 File Browser View information disclosure
2349| [87433] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
2350| [87432] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
2351| [87431] Apple Mac OS X up to 10.11.4 apache_mod_php Format String
2352| [87430] Apple Mac OS X up to 10.11.4 apache_mod_php denial of service
2353| [87429] Apple Mac OS X up to 10.11.4 apache_mod_php information disclosure
2354| [87428] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
2355| [87427] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
2356| [87389] Apache Xerces C++ up to 3.1.3 XML Document DTDScanner.cpp memory corruption
2357| [87172] Adobe ColdFusion 11 Update 7/2016/up to 10 Update 18 Apache Commons Collections Library privilege escalation
2358| [87121] Apache Cordova iOS up to 3.x Plugin privilege escalation
2359| [87120] Apache Cordova iOS up to 3.x URL Whitelist privilege escalation
2360| [83806] HPE Network Node Manager i up to 10.01 Apache Commons Collections Library privilege escalation
2361| [83077] Apache Subversion up to 1.8.15/1.9.3 mod_authz_svn mod_authz_svn.c denial of service
2362| [83076] Apache Subversion up to 1.8.15/1.9.3 svnserve svnserve/cyrus_auth.c privilege escalation
2363| [82790] Apache Struts 2.0.0/2.3.24/2.3.28 Dynamic Method privilege escalation
2364| [82789] Apache Struts 2.0.0/2.3.24/2.3.28 XSLTResult privilege escalation
2365| [82725] HPE P9000 Command View up to 7.x/8.4.0 Apache Commons Collections Library privilege escalation
2366| [82444] Apache Camel up to 2.14.x/2.15.4/2.16.0 HTTP Request privilege escalation
2367| [82389] Apache Subversion up to 1.7.x/1.8.14/1.9.2 mod_dav_svn util.c memory corruption
2368| [82280] Apache Struts up to 1.7 JRE URLDecoder cross site scripting
2369| [82260] Apache OFBiz up to 12.04.05/13.07.02 Java Object privilege escalation
2370| [82259] Apache Qpid Proton up to 0.12.0 proton.reactor.Connector weak encryption
2371| [82250] Apache Ranger up to 0.5.0 Admin UI weak authentication
2372| [82214] Apache Wicket up to 1.5.14/6.21.x/7.1.x Input Element cross site scripting
2373| [82213] Apache Wicket up to 1.5.14/6.21.x/7.1.x ModalWindow Title getWindowOpenJavaScript cross site scripting
2374| [82212] Apache Ranger up to 0.5.0 Policy Admin Tool privilege escalation
2375| [82211] Apache OFBiz up to 12.04.06/13.07.02 ModelFormField.java DisplayEntityField.getDescription cross site scripting
2376| [82082] Apache JetSpeed up to 2.3.0 User Manager Service privilege escalation
2377| [82081] Apache OpenMeetings up to 3.1.0 SOAP API information disclosure
2378| [82080] Apache OpenMeetings up to 3.1.0 Event cross site scripting
2379| [82078] Apache OpenMeetings up to 3.1.0 Import/Export System Backup ZIP Archive directory traversal
2380| [82077] Apache OpenMeetings up to 3.1.0 Password Reset sendHashByUser privilege escalation
2381| [82076] Apache Ranger up to 0.5.1 privilege escalation
2382| [82075] Apache JetSpeed up to 2.3.0 Portal cross site scripting
2383| [82074] Apache JetSpeed up to 2.3.0 cross site scripting
2384| [82073] Apache JetSpeed up to 2.3.0 User Manager Service sql injection
2385| [82072] Apache JetSpeed up to 2.3.0 Portal Site Manager ZIP Archive directory traversal
2386| [82058] Apache LDAP Studio/Directory Studio up to 2.0.0-M9 CSV Export privilege escalation
2387| [82053] Apache Ranger up to 0.4.x Policy Admin Tool privilege escalation
2388| [82052] Apache Ranger up to 0.4.x Policy Admin Tool HTTP Request cross site scripting
2389| [81696] Apache ActiveMQ up to 5.13.1 HTTP Header privilege escalation
2390| [81695] Apache Xerces-C up to 3.1.2 internal/XMLReader.cpp memory corruption
2391| [81622] HPE Asset Manager 9.40/9.41/9.50 Apache Commons Collections Library Java Object privilege escalation
2392| [81406] HPE Service Manager up to 9.35 P3/9.41 P1 Apache Commons Collections Library Command privilege escalation
2393| [81405] HPE Operations Orchestration up to 10.50 Apache Commons Collections Library Command privilege escalation
2394| [81427] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
2395| [81426] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
2396| [81372] Apache Struts up to 2.3.24.1 I18NInterceptor cross site scripting
2397| [81371] Apache Struts up to 2.3.24.1 Double OGNL Evaluation privilege escalation
2398| [81370] Apache Struts up to 2.3.24.1 Java URLDecoder cross site scripting
2399| [81084] Apache Tomcat 6.0/7.0/8.0/9.0 ServletContext directory traversal
2400| [81083] Apache Tomcat 7.0/8.0/9.0 Index Page cross site request forgery
2401| [81082] Apache Tomcat 7.0/8.0/9.0 ResourceLinkFactory.setGlobalContext privilege escalation
2402| [81081] Apache Tomcat 6.0/7.0/8.0/9.0 Error information disclosure
2403| [81080] Apache Tomcat 6.0/7.0/8.0/9.0 Session Persistence privilege escalation
2404| [81079] Apache Tomcat 6.0/7.0/8.0/9.0 StatusManagerServlet information disclosure
2405| [81078] Apache Tomcat 7.0/8.0/9.0 Session privilege escalation
2406| [80970] Apache Solr up to 5.3.0 Admin UI plugins.js cross site scripting
2407| [80969] Apache Solr up to 5.2 Schema schema-browser.js cross site scripting
2408| [80968] Apache Solr up to 5.0 analysis.js cross site scripting
2409| [80940] HP Continuous Delivery Automation 1.30 Apache Commons Collections Library privilege escalation
2410| [80823] Apache CloudStack up to 4.5.1 KVM Virtual Machine Migration privilege escalation
2411| [80822] Apache CloudStack up to 4.5.1 API Call information disclosure
2412| [80778] Apache Camel up to 2.15.4/2.16.0 camel-xstream privilege escalation
2413| [80750] HPE Operations Manager 8.x/9.0 on Windows Apache Commons Collections Library privilege escalation
2414| [80724] Apache Hive up to 1.2.1 Authorization Framework privilege escalation
2415| [80577] Oracle Secure Global Desktop 4.63/4.71/5.2 Apache HTTP Server denial of service
2416| [80165] Intel McAfee ePolicy Orchestrator up to 4.6.9/5.0.3/5.3.1 Apache Commons Collections Library privilege escalation
2417| [80116] Apache Subversion up to 1.9.2 svn Protocol libsvn_ra_svn/marshal.c read_string memory corruption
2418| [80115] Apache ActiveMQ up to 5.12.x Broker Service privilege escalation
2419| [80036] IBM Cognos Business Intelligence Apache Commons Collections Library InvokerTransformer privilege escalation
2420| [79873] VMware vCenter Operations/vRealize Orchestrator Apache Commons Collections Library Serialized Java Object privilege escalation
2421| [79840] Apache Cordova File Transfer Plugin up to 1.2.x on Android unknown vulnerability
2422| [79839] Apache TomEE Serialized Java Stream EjbObjectInputStream privilege escalation
2423| [79791] Cisco Products Apache Commons Collections Library privilege escalation
2424| [79539] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
2425| [79538] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
2426| [79294] Apache Cordova-Android up to 3.6 BridgeSecret Random Generator weak encryption
2427| [79291] Apache Cordova-Android up to 4.0 Javascript Whitelist privilege escalation
2428| [79244] Apache CXF up to 2.7.17/3.0.7/3.1.2 SAML Web SSO Module SAML Response weak authentication
2429| [79243] Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0 WLS Security com.bea.core.apache.commons.collections.jar privilege escalation
2430| [78989] Apache Ambari up to 2.1.1 Open Redirect
2431| [78988] Apache Ambari up to 2.0.1/2.1.0 Password privilege escalation
2432| [78987] Apache Ambari up to 2.0.x cross site scripting
2433| [78986] Apache Ambari up to 2.0.x Proxy Endpoint api/v1/proxy privilege escalation
2434| [78780] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
2435| [78779] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
2436| [78778] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
2437| [78777] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
2438| [78776] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
2439| [78775] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
2440| [78774] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
2441| [78297] Apache Commons Components HttpClient up to 4.3.5 HTTPS Timeout denial of service
2442| [77406] Apache Flex BlazeDS AMF Message XML External Entity
2443| [77429] Apache ActiveMQ up to 5.10.0 LDAPLoginModule privilege escalation
2444| [77399] Apache ActiveMQ up to 5.10.0 LDAPLoginModule weak authentication
2445| [77375] Apache Tapestry up to 5.3.5 Client-Side Object Storage privilege escalation
2446| [77331] Apache ActiveMQ up to 5.11.1 on Windows Fileserver Upload/Download directory traversal
2447| [77299] Apache Solr Real-Time Module up to 7.x-1.1 Index Content information disclosure
2448| [77247] Apache ActiveMQ up to 5.10 TransportConnection.java processControlCommand denial of service
2449| [77083] Apache Groovy up to 2.4.3 MethodClosure.java MethodClosure memory corruption
2450| [76953] Apache Subversion 1.7.0/1.8.0/1.8.10 svn_repos_trace_node_locations information disclosure
2451| [76952] Apache Subversion 1.7.0/1.8.0/1.8.10 mod_authz_svn anonymous/authenticated information disclosure
2452| [76567] Apache Struts 2.3.20 unknown vulnerability
2453| [76733] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 ap_some_auth_required unknown vulnerability
2454| [76732] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 Request apr_brigade_flatten privilege escalation
2455| [76731] Apache HTTP Server 2.4.12 ErrorDocument 400 Crash denial of service
2456| [75690] Apache Camel up to 2.13.3/2.14.1 XPathBuilder.java XML External Entity
2457| [75689] Apache Camel up to 2.13.3/2.14.1 XML Converter Setup XmlConverter.java SAXSource privilege escalation
2458| [75668] Apache Sling API/Sling Servlets Post up to 2.2.1 HtmlResponse cross site scripting
2459| [75601] Apache Jackrabbit up to 2.10.0 WebDAV Request XML External Entity
2460| [75420] Apache Tomcat up to 6.0.43/7.0.58/8.0.16 Security Manager privilege escalation
2461| [75145] Apache OpenOffice up to 4.1.1 HWP Filter Crash denial of service
2462| [75032] Apache Tomcat Connectors up to 1.2.40 mod_jk privilege escalation
2463| [75135] PHP 5.4/5.5 HTTP Request sapi_apache2.c apache2handler privilege escalation
2464| [74793] Apache Tomcat File Upload denial of service
2465| [74708] Apple MacOS X up to 10.10.2 Apache denial of service
2466| [74707] Apple MacOS X up to 10.10.2 Apache denial of service
2467| [74706] Apple MacOS X up to 10.10.2 Apache memory corruption
2468| [74705] Apple MacOS X up to 10.10.2 Apache denial of service
2469| [74704] Apple MacOS X up to 10.10.2 Apache denial of service
2470| [74703] Apple MacOS X up to 10.10.2 Apache denial of service
2471| [74702] Apple MacOS X up to 10.10.2 Apache denial of service
2472| [74701] Apple MacOS X up to 10.10.2 Apache cross site request forgery
2473| [74700] Apple MacOS X up to 10.10.2 Apache unknown vulnerability
2474| [74661] Apache Flex up to 4.14.0 asdoc index.html cross site scripting
2475| [74609] Apache Cassandra up to 1.2.19/2.0.13/2.1.3 JMX/RMI Interface privilege escalation
2476| [74469] Apache Xerces-C up to 7.0 internal/XMLReader.cpp denial of service
2477| [74468] Apache Batik up to 1.6 denial of service
2478| [74414] Apache Mod-gnutls up to 0.5.1 Authentication spoofing
2479| [74371] Apache Standard Taglibs up to 1.2.0 memory corruption
2480| [74367] Apache HTTP Server up to 2.4.12 mod_lua lua_request.c wsupgrade denial of service
2481| [74174] Apache WSS4J up to 2.0.0 privilege escalation
2482| [74172] Apache ActiveMQ up to 5.5.0 Administration Console cross site scripting
2483| [69092] Apache Tomcat up to 6.0.42/7.0.54/8.0.8 HTTP Request Smuggling privilege escalation
2484| [73831] Apache Qpid up to 0.30 Access Restriction unknown vulnerability
2485| [73731] Apache XML Security unknown vulnerability
2486| [68660] Oracle BI Publisher 10.1.3.4.2/11.1.1.7 Apache Tomcat cross site scripting
2487| [73659] Apache CloudStack up to 4.3.0 Stack-Based unknown vulnerability
2488| [73593] Apache Traffic Server up to 5.1.0 denial of service
2489| [73511] Apache POI up to 3.10 Deadlock denial of service
2490| [73510] Apache Solr up to 4.3.0 cross site scripting
2491| [68447] Apache Subversion up to 1.7.18/1.8.10 mod_dav_svn Crash denial of service
2492| [68446] Apache Subversion up to 1.7.18/1.8.10 REPORT Request Crash denial of service
2493| [73173] Apache CloudStack Stack-Based unknown vulnerability
2494| [68357] Apache Struts up to 2.3.16.3 Random Number Generator cross site request forgery
2495| [73106] Apache Hadoop up to 2.4.0 Symlink privilege escalation
2496| [68575] Apache HTTP Server up to 2.4.10 LuaAuthzProvider mod_lua.c privilege escalation
2497| [72890] Apache Qpid 0.30 unknown vulnerability
2498| [72887] Apache Hive 0.13.0 File Permission privilege escalation
2499| [72878] Apache Cordova 3.5.0 cross site request forgery
2500| [72877] Apache Cordova 3.5.0 cross site request forgery
2501| [72876] Apache Cordova 3.5.0 cross site request forgery
2502| [68435] Apache HTTP Server 2.4.10 mod_proxy_fcgi.c handle_headers denial of service
2503| [68065] Apache CXF up to 3.0.1 JAX-RS SAML denial of service
2504| [68064] Apache CXF up to 3.0.0 SAML Token denial of service
2505| [67913] Oracle Retail Markdown Optimization 12.0/13.0/13.1/13.2/13.4 Apache commons-beanutils-1.8.0.jar memory corruption
2506| [67912] Oracle Retail Invoice Matching up to 14.0 Apache commons-beanutils-1.8.0.jar memory corruption
2507| [67911] Oracle Retail Clearance Optimization Engine 13.3/13.4/14.0 Apache commons-beanutils-1.8.0.jar memory corruption
2508| [67910] Oracle Retail Allocation up to 13.2 Apache commons-beanutils-1.8.0.jar memory corruption
2509| [71835] Apache Shiro 1.0.0/1.1.0/1.2.0/1.2.1/1.2.2 unknown vulnerability
2510| [71633] Apachefriends XAMPP 1.8.1 cross site scripting
2511| [71629] Apache Axis2/C spoofing
2512| [67633] Apple Mac OS X up to 10.9.4 apache_mod_php ext/standard/dns.c dns_get_record memory corruption
2513| [67631] Apple Mac OS X up to 10.9.4 apache_mod_php Symlink memory corruption
2514| [67630] Apple Mac OS X up to 10.9.4 apache_mod_php cdf_read_property_info denial of service
2515| [67629] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_count_chain denial of service
2516| [67628] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_check_stream_offset denial of service
2517| [67627] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c mconvert memory corruption
2518| [67626] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c denial of service
2519| [67625] Apple Mac OS X up to 10.9.4 apache_mod_php Crash denial of service
2520| [67624] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_property_info denial of service
2521| [67623] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_unpack_summary_info denial of service
2522| [67622] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_short_sector denial of service
2523| [67620] Apple Mac OS X up to 10.9.4 apache_mod_php magic/Magdir/commands denial of service
2524| [67790] Apache HTTP Server mod_cache NULL Pointer Dereference denial of service
2525| [67522] Apache Tomcat up to 7.0.39 JSP Upload privilege escalation
2526| [70809] Apache POI up to 3.11 Crash denial of service
2527| [70808] Apache POI up to 3.10 unknown vulnerability
2528| [70806] Apache Commons-httpclient 4.2/4.2.1/4.2.2 spoofing
2529| [70749] Apache Axis up to 1.4 getCN spoofing
2530| [70701] Apache Traffic Server up to 3.3.5 denial of service
2531| [70700] Apache OFBiz up to 12.04.03 cross site scripting
2532| [67402] Apache OpenOffice 4.0.0/4.0.1/4.1.0 Calc privilege escalation
2533| [67401] Apache OpenOffice up to 4.1.0 OLE Object information disclosure
2534| [70661] Apache Subversion up to 1.6.17 denial of service
2535| [70660] Apache Subversion up to 1.6.17 spoofing
2536| [70659] Apache Subversion up to 1.6.17 spoofing
2537| [67183] Apache HTTP Server up to 2.4.9 mod_proxy denial of service
2538| [67180] Apache HTTP Server up to 2.4.9 WinNT MPM Memory Leak denial of service
2539| [67185] Apache HTTP Server up to 2.4.9 mod_status Heap-Based memory corruption
2540| [67184] Apache HTTP Server 2.4.5/2.4.6 mod_cache NULL Pointer Dereference denial of service
2541| [67182] Apache HTTP Server up to 2.4.9 mod_deflate Memory Consumption denial of service
2542| [67181] Apache HTTP Server up to 2.4.9 mod_cgid denial of service
2543| [70338] Apache Syncope up to 1.1.7 unknown vulnerability
2544| [70295] Apache CXF up to 2.7.9 Cleartext information disclosure
2545| [70106] Apache Open For Business Project up to 10.04.0 getServerError cross site scripting
2546| [70105] Apache MyFaces up to 2.1.5 JavaServer Faces directory traversal
2547| [69846] Apache HBase up to 0.94.8 information disclosure
2548| [69783] Apache CouchDB up to 1.2.0 memory corruption
2549| [13383] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 XML Parser privilege escalation
2550| [13300] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi setuid privilege escalation
2551| [13299] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi Content-Type Header information disclosure
2552| [13164] Apache CXF up to 2.6.13/2.7.10 SOAP OutgoingChainInterceptor.java Invalid Content denial of service
2553| [13163] Apache CXF up to 2.6.13/2.7.10 SOAP HTML Content denial of service
2554| [13158] Apache Struts up to 2.3.16.2 ParametersInterceptor getClass privilege escalation
2555| [69515] Apache Struts up to 2.3.15.0 CookieInterceptor memory corruption
2556| [13086] Apache Struts up to 1.3.10 Class Loader privilege escalation
2557| [13067] Apache Struts up to 2.3.16.1 Class Loader privilege escalation
2558| [69431] Apache Archiva up to 1.3.6 cross site scripting
2559| [69385] Apache Syncope up to 1.1.6 unknown vulnerability
2560| [69338] Apache Xalan-Java up to 2.7.1 system-property unknown vulnerability
2561| [12742] Trustwave ModSecurity up to 2.7.5 Chunk Extension apache2/modsecurity.c modsecurity_tx_init privilege escalation
2562| [12741] Trustwave ModSecurity up to 2.7.6 Chunked HTTP Transfer apache2/modsecurity.c modsecurity_tx_init Trailing Header privilege escalation
2563| [13387] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Content-Length Header privilege escalation
2564| [13386] Apache Tomcat Security Manager up to 6.0.39/7.0.53/8.0.5 XSLT privilege escalation
2565| [13385] Apache Tomcat 8.0.0/8.0.1/8.0.3 AJP Request Zero Length denial of service
2566| [13384] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Chunked HTTP Request denial of service
2567| [12748] Apache CouchDB 1.5.0 UUIDS /_uuids denial of service
2568| [66739] Apache Camel up to 2.12.2 unknown vulnerability
2569| [66738] Apache Camel up to 2.12.2 unknown vulnerability
2570| [12667] Apache HTTP Server 2.4.7 mod_log_config.c log_cookie denial of service
2571| [66695] Apache CouchDB up to 1.2.0 cross site scripting
2572| [66694] Apache CouchDB up to 1.2.0 Partition partition2 directory traversal
2573| [66689] Apache HTTP Server up to 2.0.33 mod_dav dav_xml_get_cdata denial of service
2574| [12518] Apache Tomcat up to 6.0.38/7.0.49/8.0.0-RC9 HTTP Header denial of service
2575| [66498] Apache expressions up to 3.3.0 Whitelist unknown vulnerability
2576| [12781] Apache Struts up to 2.3.8 ParametersInterceptor getClass denial of service
2577| [12439] Apache Tomcat 6.0.33 XML XXE information disclosure
2578| [12438] Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37 coyoteadapter.java disableURLRewriting privilege escalation
2579| [66356] Apache Wicket up to 6.8.0 information disclosure
2580| [12209] Apache Tomcat 7.0.0/7.0.50/8.0.0-RC1/8.0.1 Content-Type Header for Multi-Part Request Infinite Loop denial of service
2581| [66322] Apache ActiveMQ up to 5.8.0 cross site scripting
2582| [12291] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
2583| [66255] Apache Open For Business Project up to 10.04.3 cross site scripting
2584| [66200] Apache Hadoop up to 2.0.5 Security Feature information disclosure
2585| [66072] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
2586| [66068] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
2587| [11928] Oracle Secure Global Desktop up to 4.71 Apache Tomcat unknown vulnerability
2588| [11924] Oracle Secure Global Desktop up to 4.63 Apache Tomcat denial of service
2589| [11922] Oracle Secure Global Desktop up to 4.63 Apache Tomcat unknown vulnerability
2590| [66049] Apache XML Security for Java up to 1.4.6 Memory Consumption denial of service
2591| [12199] Apache Subversion up to 1.8.5 mod_dav_svn/repos.c get_resource denial of service
2592| [65946] askapache Firefox Adsense up to 3.0 askapache-firefox-adsense.php cross site request forgery
2593| [65668] Apache Solr 4.0.0 Updater denial of service
2594| [65665] Apache Solr up to 4.3.0 denial of service
2595| [65664] Apache Solr 3.6.0/3.6.1/3.6.2/4.0.0 Updater denial of service
2596| [65663] Apache Solr up to 4.5.1 ResourceLoader directory traversal
2597| [65658] Apache roller 4.0/4.0.1/5.0/5.0.1 unknown vulnerability
2598| [65657] Apache Roller 4.0/4.0.1/5.0/5.0.1 cross site scripting
2599| [11325] Apache Subversion 1.7.13 mod_dontdothat Bypass denial of service
2600| [11324] Apache Subversion up to 1.8.4 mod_dav_svn denial of service
2601| [11098] Apache Tomcat 5.5.25 HTTP Request cross site request forgery
2602| [65410] Apache Struts 2.3.15.3 cross site scripting
2603| [65386] Apache Solr up to 2.2.1 on TYPO3 cross site scripting
2604| [65385] Apache Solr up to 2.2.1 on TYPO3 unknown vulnerability
2605| [11044] Apache Struts 2.3.15.3 showConfig.action cross site scripting
2606| [11043] Apache Struts 2.3.15.3 actionNames.action cross site scripting
2607| [11018] cPanel WHM up to 11.40.0.11 Apache mod_userdir Tweak Interface privilege escalation
2608| [65342] Apache Sling 1.0.2/1.0.4/1.0.6/1.1.0/1.1.2 Auth Core cross site scripting
2609| [65340] Apache Shindig 2.5.0 information disclosure
2610| [65316] Apache Mod Fcgid up to 2.3.7 mod_fcgid fcgid_bucket.c fcgid_header_bucket_read memory corruption
2611| [65313] Apache Sling 2.2.0/2.3.0 AbstractCreateOperation.java deepGetOrCreateNode denial of service
2612| [10826] Apache Struts 2 File privilege escalation
2613| [65204] Apache Camel up to 2.10.1 unknown vulnerability
2614| [10460] Apache Struts 2.0.0/2.3.15.1 Action Mapping Mechanism Bypass privilege escalation
2615| [10459] Apache Struts 2.0.0/2.3.15 Dynamic Method Invocation unknown vulnerability
2616| [10160] Apache Subversion 1.8.0/1.8.1/1.8.2 svnwcsub.py handle_options race condition
2617| [10159] Apache Subversion up to 1.8.2 svnserve write_pid_file race condition
2618| [10158] Apache Subversion 1.8.0/1.8.1/1.8.2 daemonize.py daemon::daemonize race condition
2619| [10157] Apache Subversion up to 1.8.1 FSFS Repository Symlink privilege escalation
2620| [64808] Fail2ban up to 0.8.9 apache-auth.conf denial of service
2621| [64760] Best Practical RT up to 4.0.12 Apache::Session::File information disclosure
2622| [64722] Apache XML Security for C++ Heap-based memory corruption
2623| [64719] Apache XML Security for C++ Heap-based memory corruption
2624| [64718] Apache XML Security for C++ verify denial of service
2625| [64717] Apache XML Security for C++ getURIBaseTXFM memory corruption
2626| [64716] Apache XML Security for C++ spoofing
2627| [64701] Apache CXF up to 2.7.3 XML Parser Memory Consumption denial of service
2628| [64700] Apache CloudStack up to 4.1.0 Stack-Based cross site scripting
2629| [64667] Apache Open For Business Project up to 10.04.04 unknown vulnerability
2630| [64666] Apache Open For Business Project up to 10.04.04 cross site scripting
2631| [9891] Apache HTTP Server 2.2.22 suEXEC Feature .htaccess information disclosure
2632| [64509] Apache ActiveMQ up to 5.8.0 scheduled.jsp cross site scripting
2633| [9826] Apache Subversion up to 1.8.0 mod_dav_svn denial of service
2634| [9683] Apache HTTP Server 2.4.5 mod_session_dbd denial of service
2635| [64485] Apache Struts up to 2.2.3.0 privilege escalation
2636| [9568] Apache Struts up to 2.3.15 DefaultActionMapper cross site request forgery
2637| [9567] Apache Struts up to 2.3.15 DefaultActionMapper memory corruption
2638| [64467] Apache Geronimo 3.0 memory corruption
2639| [64466] Apache OpenJPA up to 2.2.1 Serialization memory corruption
2640| [64457] Apache Struts up to 2.2.3.0 cross site scripting
2641| [64326] Alejandro Garza Apachesolr Autocomplete up to 7.x-1.1 cross site scripting
2642| [9184] Apache Qpid up to 0.20 SSL misconfiguration
2643| [8935] Apache Subversion up to 1.7.9 FSFS Format Repository denial of service
2644| [8934] Apache Subversion up to 1.7.9 Svnserve Server denial of service
2645| [8933] Apache Subversion up to 1.6.21 check-mime-type.pl svnlook memory corruption
2646| [8932] Apache Subversion up to 1.6.21 svn-keyword-check.pl svnlook changed memory corruption
2647| [9022] Apache Struts up to 2.3.14.2 OGNL Expression memory corruption
2648| [8873] Apache Struts 2.3.14 privilege escalation
2649| [8872] Apache Struts 2.3.14 privilege escalation
2650| [8746] Apache HTTP Server Log File Terminal Escape Sequence Filtering mod_rewrite.c do_rewritelog privilege escalation
2651| [8666] Apache Tomcat up to 7.0.32 AsyncListener information disclosure
2652| [8665] Apache Tomcat up to 7.0.29 Chunked Transfer Encoding Extension Size denial of service
2653| [8664] Apache Tomcat up to 7.0.32 FORM Authentication weak authentication
2654| [64075] Apache Subversion up to 1.7.7 mod_dav_svn Crash denial of service
2655| [64074] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
2656| [64073] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
2657| [64072] Apache Subversion up to 1.7.7 mod_dav_svn NULL Pointer Dereference denial of service
2658| [64071] Apache Subversion up to 1.7.8 mod_dav_svn Memory Consumption denial of service
2659| [8768] Apache Struts up to 2.3.14 on Mac EL and OGNL Interpreter memory corruption
2660| [64006] Apache ActiveMQ up to 5.7.0 denial of service
2661| [64005] Apache ActiveMQ up to 5.7.0 Default Configuration denial of service
2662| [64004] Apache ActiveMQ up to 5.7.0 PortfolioPublishServlet.java cross site scripting
2663| [8427] Apache Tomcat Session Transaction weak authentication
2664| [63960] Apache Maven 3.0.4 Default Configuration spoofing
2665| [63751] Apache qpid up to 0.20 qpid::framing::Buffer denial of service
2666| [63750] Apache qpid up to 0.20 checkAvailable denial of service
2667| [63749] Apache Qpid up to 0.20 Memory Consumption denial of service
2668| [63748] Apache Qpid up to 0.20 Default Configuration denial of service
2669| [63747] Apache Rave up to 0.20 User Account information disclosure
2670| [7889] Apache Subversion up to 1.6.17 mod_dav_svn/svn_fs_file_length() denial of service
2671| [63646] Apache HTTP Server up to 2.2.23/2.4.3 mod_proxy_balancer.c balancer_handler cross site scripting
2672| [7688] Apache CXF up to 2.7.1 WSS4JInterceptor Bypass weak authentication
2673| [7687] Apache CXF up to 2.7.2 Token weak authentication
2674| [63334] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
2675| [63299] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
2676| [7202] Apache HTTP Server 2.4.2 on Oracle Solaris ld_library_path cross site scripting
2677| [7075] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector NioEndpoint.java denial of service
2678| [7074] Apache Tomcat up to 6.0.35/7.0.29 FORM Authentication RealmBase.java weak authentication
2679| [7073] Apache Tomcat up to 6.0.35/7.0.31 CSRF Prevention Filter cross site request forgery
2680| [63090] Apache Tomcat up to 4.1.24 denial of service
2681| [63089] Apache HTTP Server up to 2.2.13 mod_proxy_ajp denial of service
2682| [62933] Apache Tomcat up to 5.5.0 Access Restriction unknown vulnerability
2683| [62929] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector Memory Consumption denial of service
2684| [62833] Apache CXF -/2.6.0 spoofing
2685| [62832] Apache Axis2 up to 1.6.2 spoofing
2686| [62831] Apache Axis up to 1.4 Java Message Service spoofing
2687| [62830] Apache Commons-httpclient 3.0 Payments spoofing
2688| [62826] Apache Libcloud up to 0.11.0 spoofing
2689| [62757] Apache Open For Business Project up to 10.04.0 unknown vulnerability
2690| [8830] Red Hat JBoss Enterprise Application Platform 6.0.1 org.apache.catalina.connector.Response.encodeURL information disclosure
2691| [62661] Apache Axis2 unknown vulnerability
2692| [62658] Apache Axis2 unknown vulnerability
2693| [62467] Apache Qpid up to 0.17 denial of service
2694| [62417] Apache CXF 2.4.7/2.4.8/2.5.3/2.5.4/2.6.1 spoofing
2695| [6301] Apache HTTP Server mod_pagespeed cross site scripting
2696| [6300] Apache HTTP Server mod_pagespeed Hostname information disclosure
2697| [6123] Apache Wicket up to 1.5.7 Ajax Link cross site scripting
2698| [62035] Apache Struts up to 2.3.4 denial of service
2699| [61916] Apache QPID 0.5/0.6/0.14/0.16 unknown vulnerability
2700| [6998] Apache Tomcat 5.5.35/6.0.35/7.0.28 DIGEST Authentication Session State Caching privilege escalation
2701| [6997] Apache Tomcat 5.5.35/6.0.35/7.0.28 HTTP Digest Authentication Implementation privilege escalation
2702| [6092] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_ajp.c information disclosure
2703| [6090] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_http.c information disclosure
2704| [61507] Apache POI up to 3.8 UnhandledDataStructure denial of service
2705| [6070] Apache Struts up to 2.3.4 Token Name Configuration Parameter privilege escalation
2706| [6069] Apache Struts up to 2.3.4 Request Parameter OGNL Expression denial of service
2707| [5764] Oracle Solaris 10 Apache HTTP Server information disclosure
2708| [5700] Oracle Secure Backup 10.3.0.3/10.4.0.1 Apache denial of service
2709| [61255] Apache Hadoop 2.0.0 Kerberos unknown vulnerability
2710| [61229] Apache Sling up to 2.1.1 denial of service
2711| [61152] Apache Commons-compress 1.0/1.1/1.2/1.3/1.4 denial of service
2712| [61094] Apache Roller up to 5.0 cross site scripting
2713| [61093] Apache Roller up to 5.0 cross site request forgery
2714| [61005] Apache OpenOffice 3.3/3.4 unknown vulnerability
2715| [9673] Apache HTTP Server up to 2.4.4 mod_dav mod_dav.c Request denial of service
2716| [5436] Apache OpenOffice 3.3/3.4 WPXContentListener.cpp _closeTableRow File memory corruption
2717| [5435] Apache OpenOffice 3.3/3.4 vclmi.dll File memory corruption
2718| [60730] PHP 5.4.0/5.4.1/5.4.2 apache_request_headers memory corruption
2719| [60708] Apache Qpid 0.12 unknown vulnerability
2720| [5032] Apache Hadoop up to 0.20.205.0/1.0.1/0.23.1 Kerberos/MapReduce Security Feature privilege escalation
2721| [4949] Apache Struts File Upload XSLTResult.java XSLT File privilege escalation
2722| [4955] Apache Traffic Server 3.0.3/3.1.2 HTTP Header Parser memory corruption
2723| [4882] Apache Wicket up to 1.5.4 directory traversal
2724| [4881] Apache Wicket up to 1.4.19 cross site scripting
2725| [4884] Apache HTTP Server up to 2.3.6 mod_fcgid fcgid_spawn_ctl.c FcgidMaxProcessesPerClass HTTP Requests denial of service
2726| [60352] Apache Struts up to 2.2.3 memory corruption
2727| [60153] Apache Portable Runtime up to 1.4.3 denial of service
2728| [4598] Apache Struts 1.3.10 upload-submit.do cross site scripting
2729| [4597] Apache Struts 1.3.10 processSimple.do cross site scripting
2730| [4596] Apache Struts 2.0.14/2.2.3 struts2-rest-showcase/orders cross site scripting
2731| [4595] Apache Struts 2.0.14/2.2.3 struts2-showcase/person/editPerson.action cross site scripting
2732| [4583] Apache HTTP Server up to 2.2.21 Threaded MPM denial of service
2733| [4582] Apache HTTP Server up to 2.2.21 protocol.c information disclosure
2734| [4571] Apache Struts up to 2.3.1.2 privilege escalation
2735| [4557] Apache Tomcat up to 7.0.21 Caching/Recycling information disclosure
2736| [59934] Apache Tomcat up to 6.0.9 DigestAuthenticator.java unknown vulnerability
2737| [59933] Apache Tomcat up to 6.0.9 Access Restriction unknown vulnerability
2738| [59932] Apache Tomcat up to 6.0.9 unknown vulnerability
2739| [59931] Apache Tomcat up to 6.0.9 Access Restriction information disclosure
2740| [59902] Apache Struts up to 2.2.3 Interfaces unknown vulnerability
2741| [4528] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
2742| [4527] Apache Struts up to 2.2.3 ExceptionDelegator cross site scripting
2743| [59888] Apache Tomcat up to 6.0.6 denial of service
2744| [59886] Apache ActiveMQ up to 5.5.1 Crash denial of service
2745| [4513] Apache Struts up to 2.3.1 ParameterInterceptor directory traversal
2746| [4512] Apache Struts up to 2.2.3 CookieInterceptor privilege escalation
2747| [59850] Apache Geronimo up to 2.2.1 denial of service
2748| [59825] Apache HTTP Server up to 2.1.7 mod_reqtimeout denial of service
2749| [59556] Apache HTTP Server up to 2.0.53 mod_proxy information disclosure
2750| [58467] Apache libcloud 0.2.0/0.3.0/0.3.1/0.4.0 Access Restriction spoofing
2751| [58413] Apache Tomcat up to 6.0.10 spoofing
2752| [58381] Apache Wicket up to 1.4.17 cross site scripting
2753| [58296] Apache Tomcat up to 7.0.19 unknown vulnerability
2754| [57888] Apache HttpClient 4.0/4.0.1/4.1 Authorization information disclosure
2755| [57587] Apache Subversion up to 1.6.16 mod_dav_svn information disclosure
2756| [57585] Apache Subversion up to 1.6.16 mod_dav_svn Memory Consumption denial of service
2757| [57584] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
2758| [57577] Apache Rampart-C 1.3.0 Access Restriction rampart_timestamp_token_validate privilege escalation
2759| [57568] Apache Archiva up to 1.3.4 cross site scripting
2760| [57567] Apache Archiva up to 1.3.4 cross site request forgery
2761| [57481] Apache Tomcat 7.0.12/7.0.13 Access Restriction unknown vulnerability
2762| [4355] Apache HTTP Server APR apr_fnmatch denial of service
2763| [57435] Apache Struts up to 2.2.1.1 FileHandler.java cross site scripting
2764| [57425] Apache Struts up to 2.2.1.1 cross site scripting
2765| [4352] Apache HTTP Server 2.2.x APR apr_fnmatch denial of service
2766| [57025] Apache Tomcat up to 7.0.11 information disclosure
2767| [57024] Apache Tomcat 7.0.11 Access Restriction information disclosure
2768| [56774] IBM WebSphere Application Server up to 7.0.0.14 org.apache.jasper.runtime.JspWriterImpl.response denial of service
2769| [56824] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
2770| [56832] Apache Tomcat up to 7.0.10 Access Restriction information disclosure
2771| [56830] Apache Tomcat up to 7.0.9 Access Restriction privilege escalation
2772| [12440] Apache Tomcat 6.0.33 Malicious Request cross site scripting
2773| [56512] Apache Continuum up to 1.4.0 cross site scripting
2774| [4285] Apache Tomcat 5.x JVM getLocale denial of service
2775| [4284] Apache Tomcat 5.x HTML Manager Infinite Loop cross site scripting
2776| [4283] Apache Tomcat 5.x ServletContect privilege escalation
2777| [56441] Apache Tomcat up to 7.0.6 denial of service
2778| [56300] Apache CouchDB up to 1.0.1 Web Administration Interface cross site scripting
2779| [55967] Apache Subversion up to 1.6.4 rev_hunt.c denial of service
2780| [55966] Apache Subversion up to 1.6.4 mod_dav_svn repos.c walk denial of service
2781| [55095] Apache Axis2 up to 1.6 Default Password memory corruption
2782| [55631] Apache Archiva up to 1.3.1 User Account cross site request forgery
2783| [55556] Apache Tomcat up to 6.0.29 Default Configuration information disclosure
2784| [55553] Apache Tomcat up to 7.0.4 sessionsList.jsp cross site scripting
2785| [55162] Apache MyFaces up to 2.0.0 Authentication Code unknown vulnerability
2786| [54881] Apache Subversion up to 1.6.12 mod_dav_svn authz.c privilege escalation
2787| [54879] Apache APR-util up to 0.9.14 mod_reqtimeout apr_brigade_split_line denial of service
2788| [54693] Apache Traffic Server DNS Cache unknown vulnerability
2789| [54416] Apache CouchDB up to 0.11.0 cross site request forgery
2790| [54394] Apache CXF up to 2.2.8 Memory Consumption denial of service
2791| [54261] Apache Tomcat jsp/cal/cal2.jsp cross site scripting
2792| [54166] Apache HTTP Server up to 2.2.12 mod_cache Crash denial of service
2793| [54385] Apache Struts up to 2.1.8.1 ParameterInterceptor unknown vulnerability
2794| [54012] Apache Tomcat up to 6.0.10 denial of service
2795| [53763] Apache Axis2 1.3/1.4/1.4.1/1.5/1.5.1 Memory Consumption denial of service
2796| [53368] Apache MyFaces 1.1.7/1.2.8 cross site scripting
2797| [53397] Apache axis2 1.4.1/1.5.1 Administration Console cross site scripting
2798| [52894] Apache Tomcat up to 6.0.7 information disclosure
2799| [52960] Apache ActiveMQ up to 5.4-snapshot information disclosure
2800| [52843] Apache HTTP Server mod_auth_shadow unknown vulnerability
2801| [52786] Apache Open For Business Project up to 09.04 cross site scripting
2802| [52587] Apache ActiveMQ up to 5.3.0 cross site request forgery
2803| [52586] Apache ActiveMQ up to 5.3.0 cross site scripting
2804| [52584] Apache CouchDB up to 0.10.1 information disclosure
2805| [51757] Apache HTTP Server 2.0.44 cross site scripting
2806| [51756] Apache HTTP Server 2.0.44 spoofing
2807| [51717] Apache HTTP Server up to 1.3.3 mod_proxy ap_proxy_send_fb memory corruption
2808| [51690] Apache Tomcat up to 6.0 directory traversal
2809| [51689] Apache Tomcat up to 6.0 information disclosure
2810| [51688] Apache Tomcat up to 6.0 directory traversal
2811| [50886] HP Operations Manager 8.10 on Windows File Upload org.apache.catalina.manager.HTMLManagerServlet memory corruption
2812| [50802] Apache Tomcat up to 3.3 Default Password weak authentication
2813| [50626] Apache Solr 1.0.0 cross site scripting
2814| [49857] Apache HTTP Server mod_proxy_ftp cross site scripting
2815| [49856] Apache HTTP Server 2.2.13 mod_proxy_ftp ap_proxy_ftp_handler denial of service
2816| [49348] Apache Xerces-C++ 2.7.0 Stack-Based denial of service
2817| [86789] Apache Portable Runtime memory/unix/apr_pools.c unknown vulnerability
2818| [49283] Apache APR-util up to 1.3.8 apr-util misc/apr_rmm.c apr_rmm_realloc memory corruption
2819| [48952] Apache HTTP Server up to 1.3.6 mod_deflate denial of service
2820| [48626] Apache Tomcat up to 4.1.23 Access Restriction directory traversal
2821| [48431] Apache Tomcat up to 4.1.23 j_security_check cross site scripting
2822| [48430] Apache Tomcat up to 4.1.23 mod_jk denial of service
2823| [47801] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site request forgery
2824| [47800] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site scripting
2825| [47799] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console directory traversal
2826| [47648] Apache Tiles 2.1.0/2.1.1 cross site scripting
2827| [47640] Apache Struts 2.0.6/2.0.8/2.0.9/2.0.11/2.1 cross site scripting
2828| [47638] Apache Tomcat up to 4.1.23 mod_jk information disclosure
2829| [47636] Apache Struts 2.0.9 xip_client.html cross site scripting
2830| [47593] Apache Mod Perl 1 perl-status Apache::Status cross site scripting
2831| [47637] Apache Struts 1.0.2/1.1/1.2.4/1.2.7/1.2.8 cross site scripting
2832| [47239] Apache Struts up to 2.1.2 Beta struts directory traversal
2833| [47214] Apachefriends xampp 1.6.8 spoofing
2834| [47213] Apachefriends xampp 1.6.8 htaccess cross site request forgery
2835| [47162] Apachefriends XAMPP 1.4.4 weak authentication
2836| [47065] Apache Tomcat 4.1.23 cross site scripting
2837| [46834] Apache Tomcat up to 5.5.20 cross site scripting
2838| [46004] Apache Jackrabbit 1.4/1.5.0 search.jsp cross site scripting
2839| [49205] Apache Roller 2.3/3.0/3.1/4.0 Search cross site scripting
2840| [86625] Apache Struts directory traversal
2841| [44461] Apache Tomcat up to 5.5.0 information disclosure
2842| [44389] Apache Xerces-C++ XML Parser Memory Consumption denial of service
2843| [44352] Apache Friends XAMPP 1.6.8 adodb.php cross site scripting
2844| [43663] Apache Tomcat up to 6.0.16 directory traversal
2845| [43612] Apache Friends XAMPP 1.6.7 iart.php cross site scripting
2846| [43556] Apache HTTP Server up to 2.1.8 mod_proxy_ftp proxy_ftp.c cross site scripting
2847| [43516] Apache Tomcat up to 4.1.20 directory traversal
2848| [43509] Apache Tomcat up to 6.0.13 cross site scripting
2849| [42637] Apache Tomcat up to 6.0.16 cross site scripting
2850| [42325] Apache HTTP Server up to 2.1.8 Error Page cross site scripting
2851| [41838] Apache-SSL 1.3.34 1.57 expandcert privilege escalation
2852| [41091] Apache Software Foundation Mod Jk up to 2.0.1 mod_jk2 Stack-based memory corruption
2853| [40924] Apache Tomcat up to 6.0.15 information disclosure
2854| [40923] Apache Tomcat up to 6.0.15 unknown vulnerability
2855| [40922] Apache Tomcat up to 6.0 information disclosure
2856| [40710] Apache HTTP Server up to 2.0.61 mod_negotiation cross site scripting
2857| [40709] Apache HTTP Server up to 2.0.53 mod_negotiation cross site scripting
2858| [40656] Apache Tomcat 5.5.20 information disclosure
2859| [40503] Apache HTTP Server mod_proxy_ftp cross site scripting
2860| [40502] Apache HTTP Server up to 2.2.5 mod_proxy_balancer memory corruption
2861| [40501] Apache HTTP Server 2.2.6 mod_proxy_balancer cross site request forgery
2862| [40398] Apache HTTP Server up to 2.2 mod_proxy_balancer cross site scripting
2863| [40397] Apache HTTP Server up to 2.2 mod_proxy_balancer balancer_handler denial of service
2864| [40234] Apache Tomcat up to 6.0.15 directory traversal
2865| [40221] Apache HTTP Server 2.2.6 information disclosure
2866| [40027] David Castro Apache Authcas 0.4 sql injection
2867| [3495] Apache OpenOffice up to 2.3 Database Document Processor unknown vulnerability
2868| [3489] Apache HTTP Server 2.x HTTP Header cross site scripting
2869| [3414] Apache Tomcat WebDAV Stored privilege escalation
2870| [39489] Apache Jakarta Slide up to 2.1 directory traversal
2871| [39540] Apache Geronimo 2.0/2.0.1/2.0.2/2.1 unknown vulnerability
2872| [3310] Apache OpenOffice 1.1.3/2.0.4/2.2.1 TIFF Image Parser Heap-based memory corruption
2873| [38768] Apache HTTP Server up to 2.1.7 mod_autoindex.c cross site scripting
2874| [38952] Apache Geronimo 2.0.1/2.1 unknown vulnerability
2875| [38658] Apache Tomcat 4.1.31 cal2.jsp cross site request forgery
2876| [38524] Apache Geronimo 2.0 unknown vulnerability
2877| [3256] Apache Tomcat up to 6.0.13 cross site scripting
2878| [38331] Apache Tomcat 4.1.24 information disclosure
2879| [38330] Apache Tomcat 4.1.24 information disclosure
2880| [38185] Apache Tomcat 3.3/3.3.1/3.3.1a/3.3.2 Error Message CookieExample cross site scripting
2881| [37967] Apache Tomcat up to 4.1.36 Error Message sendmail.jsp cross site scripting
2882| [37647] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 Authorization unknown vulnerability
2883| [37646] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 unknown vulnerability
2884| [3141] Apache Tomcat up to 4.1.31 Accept-Language Header cross site scripting
2885| [3133] Apache Tomcat up to 6.0 HTTP cross site scripting
2886| [37292] Apache Tomcat up to 5.5.1 cross site scripting
2887| [3130] Apache OpenOffice 2.2.1 RTF Document Heap-based memory corruption
2888| [36981] Apache Tomcat JK Web Server Connector up to 1.2.22 mod_jk directory traversal
2889| [36892] Apache Tomcat up to 4.0.0 hello.jsp cross site scripting
2890| [37320] Apache MyFaces Tomahawk up to 1.1.4 cross site scripting
2891| [36697] Apache Tomcat up to 5.5.17 implicit-objects.jsp cross site scripting
2892| [36491] Apache Axis 1.0 Installation javaioFileNotFoundException information disclosure
2893| [36400] Apache Tomcat 5.5.15 mod_jk cross site scripting
2894| [36698] Apache Tomcat up to 4.0.0 cal2.jsp cross site scripting
2895| [36224] XAMPP Apache Distribution up to 1.6.0a adodb.php connect memory corruption
2896| [36225] XAMPP Apache Distribution 1.6.0a sql injection
2897| [2997] Apache httpd/Tomcat 5.5/6.0 directory traversal
2898| [35896] Apache Apache Test up to 1.29 mod_perl denial of service
2899| [35653] Avaya S8300 Cm 3.1.2 Apache Tomcat unknown vulnerability
2900| [35402] Apache Tomcat JK Web Server Connector 1.2.19 mod_jk.so map_uri_to_worker memory corruption
2901| [35067] Apache Stats up to 0.0.2 extract unknown vulnerability
2902| [35025] Apache Stats up to 0.0.3 extract unknown vulnerability
2903| [34252] Apache HTTP Server denial of service
2904| [2795] Apache OpenOffice 2.0.4 WMF/EMF File Heap-based memory corruption
2905| [33877] Apache Opentaps 0.9.3 cross site scripting
2906| [33876] Apache Open For Business Project unknown vulnerability
2907| [33875] Apache Open For Business Project cross site scripting
2908| [2703] Apache Jakarta Tomcat up to 5.x der_get_oid memory corruption
2909| [2611] Apache HTTP Server up to 1.0.1 set_var Format String
2910|
2911| MITRE CVE - https://cve.mitre.org:
2912| [CVE-2013-4156] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.
2913| [CVE-2013-4131] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
2914| [CVE-2013-3239] phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.
2915| [CVE-2013-3060] The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
2916| [CVE-2013-2765] The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
2917| [CVE-2013-2251] Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
2918| [CVE-2013-2249] mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
2919| [CVE-2013-2248] Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
2920| [CVE-2013-2189] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.
2921| [CVE-2013-2135] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
2922| [CVE-2013-2134] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
2923| [CVE-2013-2115] Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
2924| [CVE-2013-2071] java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
2925| [CVE-2013-2067] java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
2926| [CVE-2013-1966] Apache Struts 2 before 2.3.14.1 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
2927| [CVE-2013-1965] Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.1, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
2928| [CVE-2013-1896] mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
2929| [CVE-2013-1884] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
2930| [CVE-2013-1879] Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."
2931| [CVE-2013-1862] mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
2932| [CVE-2013-1849] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
2933| [CVE-2013-1847] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
2934| [CVE-2013-1846] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL.
2935| [CVE-2013-1845] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file or directory.
2936| [CVE-2013-1814] The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
2937| [CVE-2013-1777] The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not property implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
2938| [CVE-2013-1768] The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
2939| [CVE-2013-1088] Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
2940| [CVE-2013-1048] The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
2941| [CVE-2013-0966] The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
2942| [CVE-2013-0942] Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2943| [CVE-2013-0941] EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
2944| [CVE-2013-0253] The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
2945| [CVE-2013-0248] The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
2946| [CVE-2013-0239] Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
2947| [CVE-2012-6573] Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.
2948| [CVE-2012-6551] The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
2949| [CVE-2012-6092] Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
2950| [CVE-2012-5887] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.
2951| [CVE-2012-5886] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
2952| [CVE-2012-5885] The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
2953| [CVE-2012-5786] The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF, possibly 2.6.0, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
2954| [CVE-2012-5785] Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
2955| [CVE-2012-5784] Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
2956| [CVE-2012-5783] Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
2957| [CVE-2012-5633] The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
2958| [CVE-2012-5616] Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.
2959| [CVE-2012-5568] Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
2960| [CVE-2012-5351] Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
2961| [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
2962| [CVE-2012-4557] The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
2963| [CVE-2012-4556] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query.
2964| [CVE-2012-4555] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors.
2965| [CVE-2012-4534] org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
2966| [CVE-2012-4528] The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
2967| [CVE-2012-4501] Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
2968| [CVE-2012-4460] The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an out-of-bounds read, but it might not trigger a crash.
2969| [CVE-2012-4459] Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.
2970| [CVE-2012-4458] The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the client-properties map in a connection.start-ok message.
2971| [CVE-2012-4446] The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
2972| [CVE-2012-4431] org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
2973| [CVE-2012-4418] Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
2974| [CVE-2012-4387] Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
2975| [CVE-2012-4386] The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
2976| [CVE-2012-4360] Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2977| [CVE-2012-4063] The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via unspecified vectors.
2978| [CVE-2012-4001] The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.
2979| [CVE-2012-3908] Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
2980| [CVE-2012-3546] org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
2981| [CVE-2012-3544] Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
2982| [CVE-2012-3526] The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.
2983| [CVE-2012-3513] munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
2984| [CVE-2012-3506] Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
2985| [CVE-2012-3502] The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
2986| [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
2987| [CVE-2012-3467] Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
2988| [CVE-2012-3451] Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
2989| [CVE-2012-3446] Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
2990| [CVE-2012-3376] DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
2991| [CVE-2012-3373] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
2992| [CVE-2012-3126] Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Products Suite 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Apache Tomcat Agent.
2993| [CVE-2012-3123] Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.
2994| [CVE-2012-2760] mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
2995| [CVE-2012-2733] java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
2996| [CVE-2012-2687] Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
2997| [CVE-2012-2381] Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
2998| [CVE-2012-2380] Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.
2999| [CVE-2012-2379] Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
3000| [CVE-2012-2378] Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
3001| [CVE-2012-2329] Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.
3002| [CVE-2012-2145] Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.
3003| [CVE-2012-2138] The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.
3004| [CVE-2012-2098] Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
3005| [CVE-2012-1574] The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
3006| [CVE-2012-1181] fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.
3007| [CVE-2012-1089] Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
3008| [CVE-2012-1007] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.
3009| [CVE-2012-1006] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
3010| [CVE-2012-0883] envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
3011| [CVE-2012-0840] tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
3012| [CVE-2012-0838] Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
3013| [CVE-2012-0788] The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.
3014| [CVE-2012-0394] ** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
3015| [CVE-2012-0393] The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
3016| [CVE-2012-0392] The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
3017| [CVE-2012-0391] The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
3018| [CVE-2012-0256] Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
3019| [CVE-2012-0216] The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
3020| [CVE-2012-0213] The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
3021| [CVE-2012-0053] protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
3022| [CVE-2012-0047] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
3023| [CVE-2012-0031] scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
3024| [CVE-2012-0022] Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
3025| [CVE-2012-0021] The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
3026| [CVE-2011-5064] DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
3027| [CVE-2011-5063] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
3028| [CVE-2011-5062] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
3029| [CVE-2011-5057] Apache Struts 2.3.1.1 and earlier provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
3030| [CVE-2011-5034] Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
3031| [CVE-2011-4905] Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
3032| [CVE-2011-4858] Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
3033| [CVE-2011-4668] IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
3034| [CVE-2011-4449] actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.
3035| [CVE-2011-4415] The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
3036| [CVE-2011-4317] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
3037| [CVE-2011-3639] The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
3038| [CVE-2011-3620] Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
3039| [CVE-2011-3607] Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.
3040| [CVE-2011-3376] org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
3041| [CVE-2011-3375] Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
3042| [CVE-2011-3368] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
3043| [CVE-2011-3348] The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
3044| [CVE-2011-3192] The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
3045| [CVE-2011-3190] Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
3046| [CVE-2011-2729] native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
3047| [CVE-2011-2712] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
3048| [CVE-2011-2688] SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
3049| [CVE-2011-2526] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.
3050| [CVE-2011-2516] Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
3051| [CVE-2011-2481] Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
3052| [CVE-2011-2329] The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730.
3053| [CVE-2011-2204] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.
3054| [CVE-2011-2088] XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
3055| [CVE-2011-2087] Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
3056| [CVE-2011-1928] The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.
3057| [CVE-2011-1921] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
3058| [CVE-2011-1783] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
3059| [CVE-2011-1772] Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
3060| [CVE-2011-1752] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
3061| [CVE-2011-1610] Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
3062| [CVE-2011-1582] Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
3063| [CVE-2011-1571] Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
3064| [CVE-2011-1570] Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
3065| [CVE-2011-1503] The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.
3066| [CVE-2011-1502] Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
3067| [CVE-2011-1498] Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
3068| [CVE-2011-1475] The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
3069| [CVE-2011-1419] Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
3070| [CVE-2011-1318] Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
3071| [CVE-2011-1184] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
3072| [CVE-2011-1183] Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
3073| [CVE-2011-1176] The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
3074| [CVE-2011-1088] Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
3075| [CVE-2011-1077] Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
3076| [CVE-2011-1026] Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of administrators.
3077| [CVE-2011-0715] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
3078| [CVE-2011-0534] Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
3079| [CVE-2011-0533] Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta
3080| [CVE-2011-0419] Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
3081| [CVE-2011-0013] Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
3082| [CVE-2010-4644] Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
3083| [CVE-2010-4539] The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.
3084| [CVE-2010-4476] The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
3085| [CVE-2010-4455] Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.2 and 11.1.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Apache Plugin.
3086| [CVE-2010-4408] Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.
3087| [CVE-2010-4312] The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
3088| [CVE-2010-4172] Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
3089| [CVE-2010-3872] The fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.6 for the Apache HTTP Server does not use bytewise pointer arithmetic in certain circumstances, which has unspecified impact and attack vectors related to "untrusted FastCGI applications" and a "stack buffer overwrite."
3090| [CVE-2010-3863] Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
3091| [CVE-2010-3854] Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
3092| [CVE-2010-3718] Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
3093| [CVE-2010-3449] Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1
3094| [CVE-2010-3315] authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
3095| [CVE-2010-3083] sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.
3096| [CVE-2010-2952] Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.
3097| [CVE-2010-2791] mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
3098| [CVE-2010-2375] Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
3099| [CVE-2010-2234] Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.
3100| [CVE-2010-2227] Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
3101| [CVE-2010-2103] Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.
3102| [CVE-2010-2086] Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
3103| [CVE-2010-2076] Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
3104| [CVE-2010-2068] mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.
3105| [CVE-2010-2057] shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.
3106| [CVE-2010-1632] Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.
3107| [CVE-2010-1623] Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
3108| [CVE-2010-1587] The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
3109| [CVE-2010-1452] The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
3110| [CVE-2010-1325] Cross-site request forgery (CSRF) vulnerability in the apache2-slms package in SUSE Lifecycle Management Server (SLMS) 1.0 on SUSE Linux Enterprise (SLE) 11 allows remote attackers to hijack the authentication of unspecified victims via vectors related to improper parameter quoting. NOTE: some sources report that this is a vulnerability in a product named "Apache SLMS," but that is incorrect.
3111| [CVE-2010-1244] Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
3112| [CVE-2010-1157] Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.
3113| [CVE-2010-1151] Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.
3114| [CVE-2010-0684] Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
3115| [CVE-2010-0434] The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
3116| [CVE-2010-0432] Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewprofile (aka partymgr/control/login), (3) the start parameter to myportal/control/showPortalPage, (4) an invalid URI beginning with /facility/control/ReceiveReturn (aka /crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the contentId parameter (aka the entityName variable) to ecommerce/control/ViewBlogArticle, (6) the entityName parameter to webtools/control/FindGeneric, or the (7) subject or (8) content parameter to an unspecified component under ecommerce/control/contactus.
3117| [CVE-2010-0425] modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
3118| [CVE-2010-0408] The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
3119| [CVE-2010-0390] Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.
3120| [CVE-2010-0219] Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
3121| [CVE-2010-0010] Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
3122| [CVE-2010-0009] Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.
3123| [CVE-2009-5120] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a Project Woodstock service on this port.
3124| [CVE-2009-5119] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted session data.
3125| [CVE-2009-5006] The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.
3126| [CVE-2009-5005] The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.
3127| [CVE-2009-4355] Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
3128| [CVE-2009-4269] The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
3129| [CVE-2009-3923] The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
3130| [CVE-2009-3890] Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.
3131| [CVE-2009-3843] HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
3132| [CVE-2009-3821] Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
3133| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
3134| [CVE-2009-3548] The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
3135| [CVE-2009-3250] The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.
3136| [CVE-2009-3095] The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
3137| [CVE-2009-3094] The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
3138| [CVE-2009-2902] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
3139| [CVE-2009-2901] The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
3140| [CVE-2009-2823] The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.
3141| [CVE-2009-2699] The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
3142| [CVE-2009-2696] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.
3143| [CVE-2009-2693] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
3144| [CVE-2009-2625] XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
3145| [CVE-2009-2412] Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR
3146| [CVE-2009-2299] The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.
3147| [CVE-2009-1956] Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
3148| [CVE-2009-1955] The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
3149| [CVE-2009-1903] The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
3150| [CVE-2009-1891] The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
3151| [CVE-2009-1890] The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
3152| [CVE-2009-1885] Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.
3153| [CVE-2009-1462] The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.
3154| [CVE-2009-1275] Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
3155| [CVE-2009-1195] The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
3156| [CVE-2009-1191] mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
3157| [CVE-2009-1012] Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.
3158| [CVE-2009-0918] Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.
3159| [CVE-2009-0796] Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.
3160| [CVE-2009-0783] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
3161| [CVE-2009-0781] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
3162| [CVE-2009-0754] PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.
3163| [CVE-2009-0580] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.
3164| [CVE-2009-0486] Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
3165| [CVE-2009-0039] Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.
3166| [CVE-2009-0038] Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring
3167| [CVE-2009-0033] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.
3168| [CVE-2009-0026] Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
3169| [CVE-2009-0023] The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
3170| [CVE-2008-6879] Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
3171| [CVE-2008-6755] ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.
3172| [CVE-2008-6722] Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.
3173| [CVE-2008-6682] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
3174| [CVE-2008-6505] Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.
3175| [CVE-2008-6504] ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.
3176| [CVE-2008-5696] Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
3177| [CVE-2008-5676] Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."
3178| [CVE-2008-5519] The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.
3179| [CVE-2008-5518] Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet)
3180| [CVE-2008-5515] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.
3181| [CVE-2008-5457] Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
3182| [CVE-2008-4308] The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
3183| [CVE-2008-4008] Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.
3184| [CVE-2008-3666] Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured
3185| [CVE-2008-3271] Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
3186| [CVE-2008-3257] Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
3187| [CVE-2008-2939] Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
3188| [CVE-2008-2938] Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
3189| [CVE-2008-2742] Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.
3190| [CVE-2008-2717] TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
3191| [CVE-2008-2579] Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.
3192| [CVE-2008-2384] SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
3193| [CVE-2008-2370] Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
3194| [CVE-2008-2364] The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
3195| [CVE-2008-2168] Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
3196| [CVE-2008-2025] Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
3197| [CVE-2008-1947] Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
3198| [CVE-2008-1734] Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.
3199| [CVE-2008-1678] Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
3200| [CVE-2008-1232] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.
3201| [CVE-2008-0869] Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.
3202| [CVE-2008-0732] The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.
3203| [CVE-2008-0555] The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.
3204| [CVE-2008-0457] Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
3205| [CVE-2008-0456] CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
3206| [CVE-2008-0455] Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
3207| [CVE-2008-0128] The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
3208| [CVE-2008-0005] mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
3209| [CVE-2008-0002] Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
3210| [CVE-2007-6750] The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
3211| [CVE-2007-6726] Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
3212| [CVE-2007-6514] Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
3213| [CVE-2007-6423] ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
3214| [CVE-2007-6422] The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
3215| [CVE-2007-6421] Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
3216| [CVE-2007-6420] Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
3217| [CVE-2007-6388] Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
3218| [CVE-2007-6361] Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
3219| [CVE-2007-6342] SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.
3220| [CVE-2007-6286] Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
3221| [CVE-2007-6258] Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.
3222| [CVE-2007-6231] Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_includepath parameter to (1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php, or (5) libchart-1.1/libchart.php in include/. NOTE: access to include/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
3223| [CVE-2007-6203] Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
3224| [CVE-2007-5797] SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
3225| [CVE-2007-5731] Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.
3226| [CVE-2007-5461] Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
3227| [CVE-2007-5342] The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
3228| [CVE-2007-5333] Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
3229| [CVE-2007-5156] Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
3230| [CVE-2007-5085] Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
3231| [CVE-2007-5000] Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
3232| [CVE-2007-4724] Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.
3233| [CVE-2007-4723] Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
3234| [CVE-2007-4641] Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.
3235| [CVE-2007-4556] Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.
3236| [CVE-2007-4548] The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
3237| [CVE-2007-4465] Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
3238| [CVE-2007-3847] The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
3239| [CVE-2007-3571] The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.
3240| [CVE-2007-3386] Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
3241| [CVE-2007-3385] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
3242| [CVE-2007-3384] Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.
3243| [CVE-2007-3383] Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.
3244| [CVE-2007-3382] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
3245| [CVE-2007-3304] Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
3246| [CVE-2007-3303] Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
3247| [CVE-2007-3101] Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.
3248| [CVE-2007-2450] Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.
3249| [CVE-2007-2449] Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the '
3250| [CVE-2007-2353] Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
3251| [CVE-2007-2025] Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.
3252| [CVE-2007-1863] cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
3253| [CVE-2007-1862] The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
3254| [CVE-2007-1860] mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.
3255| [CVE-2007-1858] The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
3256| [CVE-2007-1842] Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.
3257| [CVE-2007-1801] Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.
3258| [CVE-2007-1743] suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
3259| [CVE-2007-1742] suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
3260| [CVE-2007-1741] Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
3261| [CVE-2007-1720] Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.
3262| [CVE-2007-1636] Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.
3263| [CVE-2007-1633] Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.
3264| [CVE-2007-1577] Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
3265| [CVE-2007-1539] Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.
3266| [CVE-2007-1524] Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.
3267| [CVE-2007-1491] Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.
3268| [CVE-2007-1358] Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
3269| [CVE-2007-1349] PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
3270| [CVE-2007-0975] Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.
3271| [CVE-2007-0930] Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.
3272| [CVE-2007-0792] The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
3273| [CVE-2007-0774] Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
3274| [CVE-2007-0637] Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.
3275| [CVE-2007-0451] Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
3276| [CVE-2007-0450] Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
3277| [CVE-2007-0419] The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).
3278| [CVE-2007-0173] Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
3279| [CVE-2007-0098] Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
3280| [CVE-2007-0086] ** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.
3281| [CVE-2006-7217] Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.
3282| [CVE-2006-7216] Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.
3283| [CVE-2006-7197] The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.
3284| [CVE-2006-7196] Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
3285| [CVE-2006-7195] Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
3286| [CVE-2006-7098] The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
3287| [CVE-2006-6869] Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
3288| [CVE-2006-6675] Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecifeid parameters in Welcome web-app.
3289| [CVE-2006-6613] Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive information via a .. (dot dot) in the pa_lang[include_file] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
3290| [CVE-2006-6589] Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.
3291| [CVE-2006-6588] The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
3292| [CVE-2006-6587] Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.
3293| [CVE-2006-6445] Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
3294| [CVE-2006-6071] TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.
3295| [CVE-2006-6047] Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
3296| [CVE-2006-5894] Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
3297| [CVE-2006-5752] Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
3298| [CVE-2006-5733] Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
3299| [CVE-2006-5263] Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apache HTTP Server log file that apparently contains PHP code.
3300| [CVE-2006-4994] Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted "Program Files" pathname.
3301| [CVE-2006-4636] Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.
3302| [CVE-2006-4625] PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
3303| [CVE-2006-4558] DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
3304| [CVE-2006-4191] Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
3305| [CVE-2006-4154] Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
3306| [CVE-2006-4110] Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
3307| [CVE-2006-4004] Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
3308| [CVE-2006-3918] http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
3309| [CVE-2006-3835] Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (
3310| [CVE-2006-3747] Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
3311| [CVE-2006-3362] Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
3312| [CVE-2006-3102] Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of time under the webroot in the temp/articles directory.
3313| [CVE-2006-3070] write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.
3314| [CVE-2006-2831] Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
3315| [CVE-2006-2806] The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.
3316| [CVE-2006-2743] Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
3317| [CVE-2006-2514] Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
3318| [CVE-2006-2330] PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
3319| [CVE-2006-1777] Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache error_log file, which is then included by doc/index.php.
3320| [CVE-2006-1564] Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.
3321| [CVE-2006-1548] Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
3322| [CVE-2006-1547] ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
3323| [CVE-2006-1546] Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
3324| [CVE-2006-1393] Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
3325| [CVE-2006-1346] Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.
3326| [CVE-2006-1292] Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
3327| [CVE-2006-1243] Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
3328| [CVE-2006-1095] Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
3329| [CVE-2006-1079] htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
3330| [CVE-2006-1078] Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
3331| [CVE-2006-0743] Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
3332| [CVE-2006-0254] Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.
3333| [CVE-2006-0150] Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
3334| [CVE-2006-0144] The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.
3335| [CVE-2006-0042] Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.
3336| [CVE-2005-4857] eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a "memory addressing error".
3337| [CVE-2005-4849] Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information.
3338| [CVE-2005-4836] The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
3339| [CVE-2005-4814] Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.
3340| [CVE-2005-4703] Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
3341| [CVE-2005-3745] Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
3342| [CVE-2005-3630] Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.
3343| [CVE-2005-3510] Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
3344| [CVE-2005-3392] Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.
3345| [CVE-2005-3357] mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
3346| [CVE-2005-3352] Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
3347| [CVE-2005-3319] The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.
3348| [CVE-2005-3164] The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
3349| [CVE-2005-2970] Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
3350| [CVE-2005-2963] The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.
3351| [CVE-2005-2728] The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
3352| [CVE-2005-2660] apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.
3353| [CVE-2005-2088] The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
3354| [CVE-2005-1754] ** DISPUTED ** JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
3355| [CVE-2005-1753] ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
3356| [CVE-2005-1344] Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
3357| [CVE-2005-1268] Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
3358| [CVE-2005-1266] Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
3359| [CVE-2005-0808] Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
3360| [CVE-2005-0182] The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.
3361| [CVE-2005-0108] Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.
3362| [CVE-2004-2734] webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
3363| [CVE-2004-2680] mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
3364| [CVE-2004-2650] Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
3365| [CVE-2004-2343] ** DISPUTED ** Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument.
3366| [CVE-2004-2336] Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.
3367| [CVE-2004-2115] Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.
3368| [CVE-2004-1834] mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
3369| [CVE-2004-1765] Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.
3370| [CVE-2004-1545] UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
3371| [CVE-2004-1438] The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
3372| [CVE-2004-1405] MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
3373| [CVE-2004-1404] Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
3374| [CVE-2004-1387] The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
3375| [CVE-2004-1084] Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
3376| [CVE-2004-1083] Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
3377| [CVE-2004-1082] mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
3378| [CVE-2004-0942] Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
3379| [CVE-2004-0940] Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
3380| [CVE-2004-0885] The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
3381| [CVE-2004-0811] Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
3382| [CVE-2004-0809] The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
3383| [CVE-2004-0786] The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
3384| [CVE-2004-0751] The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
3385| [CVE-2004-0748] mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
3386| [CVE-2004-0747] Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
3387| [CVE-2004-0700] Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
3388| [CVE-2004-0646] Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
3389| [CVE-2004-0529] The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.
3390| [CVE-2004-0493] The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
3391| [CVE-2004-0492] Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
3392| [CVE-2004-0490] cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.
3393| [CVE-2004-0488] Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
3394| [CVE-2004-0263] PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
3395| [CVE-2004-0174] Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
3396| [CVE-2004-0173] Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
3397| [CVE-2004-0113] Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
3398| [CVE-2004-0009] Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.
3399| [CVE-2003-1581] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
3400| [CVE-2003-1580] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
3401| [CVE-2003-1573] The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."
3402| [CVE-2003-1521] Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
3403| [CVE-2003-1516] The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
3404| [CVE-2003-1502] mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.
3405| [CVE-2003-1418] Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child proccess IDs (PID).
3406| [CVE-2003-1307] ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."
3407| [CVE-2003-1172] Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
3408| [CVE-2003-1171] Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.
3409| [CVE-2003-1138] The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
3410| [CVE-2003-1054] mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.
3411| [CVE-2003-0993] mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
3412| [CVE-2003-0987] mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
3413| [CVE-2003-0866] The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
3414| [CVE-2003-0844] mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.
3415| [CVE-2003-0843] Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.
3416| [CVE-2003-0789] mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
3417| [CVE-2003-0771] Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.
3418| [CVE-2003-0658] Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
3419| [CVE-2003-0542] Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
3420| [CVE-2003-0460] The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
3421| [CVE-2003-0254] Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
3422| [CVE-2003-0253] The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
3423| [CVE-2003-0249] ** DISPUTED ** PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."
3424| [CVE-2003-0245] Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
3425| [CVE-2003-0192] Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
3426| [CVE-2003-0189] The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
3427| [CVE-2003-0134] Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.
3428| [CVE-2003-0132] A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.
3429| [CVE-2003-0083] Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
3430| [CVE-2003-0020] Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
3431| [CVE-2003-0017] Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.
3432| [CVE-2003-0016] Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
3433| [CVE-2002-2310] ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
3434| [CVE-2002-2309] php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
3435| [CVE-2002-2272] Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
3436| [CVE-2002-2103] Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
3437| [CVE-2002-2029] PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
3438| [CVE-2002-2012] Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
3439| [CVE-2002-2009] Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
3440| [CVE-2002-2008] Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.
3441| [CVE-2002-2007] The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
3442| [CVE-2002-2006] The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
3443| [CVE-2002-1895] The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
3444| [CVE-2002-1850] mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
3445| [CVE-2002-1793] HTTP Server mod_ssl module running on HP-UX 11.04 with Virtualvault OS (VVOS) 4.5 through 4.6 closes the connection when the Apache server times out during an SSL request, which may allow attackers to cause a denial of service.
3446| [CVE-2002-1658] Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
3447| [CVE-2002-1635] The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin.
3448| [CVE-2002-1593] mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.
3449| [CVE-2002-1592] The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.
3450| [CVE-2002-1567] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
3451| [CVE-2002-1394] Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
3452| [CVE-2002-1233] A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
3453| [CVE-2002-1157] Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
3454| [CVE-2002-1156] Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
3455| [CVE-2002-1148] The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
3456| [CVE-2002-0935] Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
3457| [CVE-2002-0843] Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
3458| [CVE-2002-0840] Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
3459| [CVE-2002-0839] The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
3460| [CVE-2002-0682] Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
3461| [CVE-2002-0661] Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
3462| [CVE-2002-0658] OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.
3463| [CVE-2002-0654] Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
3464| [CVE-2002-0653] Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
3465| [CVE-2002-0513] The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.
3466| [CVE-2002-0493] Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
3467| [CVE-2002-0392] Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
3468| [CVE-2002-0259] InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.
3469| [CVE-2002-0249] PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
3470| [CVE-2002-0240] PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
3471| [CVE-2002-0082] The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
3472| [CVE-2002-0061] Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
3473| [CVE-2001-1556] The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
3474| [CVE-2001-1534] mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
3475| [CVE-2001-1510] Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.
3476| [CVE-2001-1449] The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
3477| [CVE-2001-1385] The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
3478| [CVE-2001-1342] Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
3479| [CVE-2001-1217] Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
3480| [CVE-2001-1216] Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
3481| [CVE-2001-1072] Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
3482| [CVE-2001-1013] Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
3483| [CVE-2001-0925] The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
3484| [CVE-2001-0829] A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
3485| [CVE-2001-0766] Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
3486| [CVE-2001-0731] Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
3487| [CVE-2001-0730] split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
3488| [CVE-2001-0729] Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
3489| [CVE-2001-0590] Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
3490| [CVE-2001-0131] htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
3491| [CVE-2001-0108] PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
3492| [CVE-2001-0042] PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
3493| [CVE-2000-1247] The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
3494| [CVE-2000-1210] Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
3495| [CVE-2000-1206] Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
3496| [CVE-2000-1205] Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.
3497| [CVE-2000-1204] Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
3498| [CVE-2000-1168] IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
3499| [CVE-2000-1016] The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
3500| [CVE-2000-0913] mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
3501| [CVE-2000-0883] The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.
3502| [CVE-2000-0869] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method.
3503| [CVE-2000-0868] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
3504| [CVE-2000-0791] Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.
3505| [CVE-2000-0760] The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
3506| [CVE-2000-0759] Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
3507| [CVE-2000-0628] The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.
3508| [CVE-2000-0505] The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
3509| [CVE-1999-1412] A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
3510| [CVE-1999-1293] mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
3511| [CVE-1999-1237] Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
3512| [CVE-1999-1199] Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
3513| [CVE-1999-1053] guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
3514| [CVE-1999-0926] Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
3515| [CVE-1999-0678] A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
3516| [CVE-1999-0448] IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
3517| [CVE-1999-0289] The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
3518| [CVE-1999-0236] ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
3519| [CVE-1999-0107] Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
3520| [CVE-1999-0071] Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
3521|
3522| SecurityFocus - https://www.securityfocus.com/bid/:
3523| [104554] Apache HBase CVE-2018-8025 Security Bypass Vulnerability
3524| [104465] Apache Geode CVE-2017-15695 Remote Code Execution Vulnerability
3525| [104418] Apache Storm CVE-2018-8008 Arbitrary File Write Vulnerability
3526| [104399] Apache Storm CVE-2018-1332 User Impersonation Vulnerability
3527| [104348] Apache UIMA CVE-2017-15691 XML External Entity Injection Vulnerability
3528| [104313] Apache NiFi XML External Entity Injection and Denial of Service Vulnerability
3529| [104259] Apache Geode CVE-2017-12622 Authorization Bypass Vulnerability
3530| [104257] Apache Sling XSS Protection API CVE-2017-15717 Cross Site Scripting Vulnerability
3531| [104253] Apache ZooKeeper CVE-2018-8012 Security Bypass Vulnerability
3532| [104252] Apache Batik CVE-2018-8013 Information Disclosure Vulnerability
3533| [104239] Apache Solr CVE-2018-8010 XML External Entity Multiple Information Disclosure Vulnerabilities
3534| [104215] Apache ORC CVE-2018-8015 Denial of Service Vulnerability
3535| [104203] Apache Tomcat CVE-2018-8014 Security Bypass Vulnerability
3536| [104161] Apache Ambari CVE-2018-8003 Directory Traversal Vulnerability
3537| [104140] Apache Derby CVE-2018-1313 Security Bypass Vulnerability
3538| [104135] Apache Tika CVE-2018-1338 Denial of Service Vulnerability
3539| [104008] Apache Fineract CVE-2018-1291 SQL Injection Vulnerability
3540| [104007] Apache Fineract CVE-2018-1292 SQL Injection Vulnerability
3541| [104005] Apache Fineract CVE-2018-1289 SQL Injection Vulnerability
3542| [104001] Apache Tika CVE-2018-1335 Remote Command Injection Vulnerability
3543| [103975] Apache Fineract CVE-2018-1290 SQL Injection Vulnerability
3544| [103974] Apache Solr CVE-2018-1308 XML External Entity Injection Vulnerability
3545| [103772] Apache Traffic Server CVE-2017-7671 Denial of Service Vulnerability
3546| [103770] Apache Traffic Server CVE-2017-5660 Security Bypass Vulnerability
3547| [103751] Apache Hive CVE-2018-1282 SQL Injection Vulnerability
3548| [103750] Apache Hive CVE-2018-1284 Security Bypass Vulnerability
3549| [103692] Apache Ignite CVE-2018-1295 Arbitrary Code Execution Vulnerability
3550| [103528] Apache HTTP Server CVE-2018-1302 Denial of Service Vulnerability
3551| [103525] Apache HTTP Server CVE-2017-15715 Remote Security Bypass Vulnerability
3552| [103524] Apache HTTP Server CVE-2018-1312 Remote Security Bypass Vulnerability
3553| [103522] Apache HTTP Server CVE-2018-1303 Denial of Service Vulnerability
3554| [103520] Apache HTTP Server CVE-2018-1283 Remote Security Vulnerability
3555| [103516] Apache Struts CVE-2018-1327 Denial of Service Vulnerability
3556| [103515] Apache HTTP Server CVE-2018-1301 Denial of Service Vulnerability
3557| [103512] Apache HTTP Server CVE-2017-15710 Denial of Service Vulnerability
3558| [103508] Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
3559| [103507] Apache Syncope CVE-2018-1322 Multiple Information Disclosure Vulnerabilities
3560| [103490] Apache Commons Compress CVE-2018-1324 Multiple Denial Of Service Vulnerabilities
3561| [103434] APACHE Allura CVE-2018-1319 HTTP Response Splitting Vulnerability
3562| [103389] Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
3563| [103222] Apache CloudStack CVE-2013-4317 Information Disclosure Vulnerability
3564| [103219] Apache Xerces-C CVE-2017-12627 Null Pointer Dereference Denial of Service Vulnerability
3565| [103206] Apache Geode CVE-2017-15693 Remote Code Execution Vulnerability
3566| [103205] Apache Geode CVE-2017-15692 Remote Code Execution Vulnerability
3567| [103170] Apache Tomcat CVE-2018-1304 Security Bypass Vulnerability
3568| [103144] Apache Tomcat CVE-2018-1305 Security Bypass Vulnerability
3569| [103102] Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
3570| [103098] Apache Karaf CVE-2016-8750 LDAP Injection Vulnerability
3571| [103069] Apache Tomcat CVE-2017-15706 Remote Security Weakness
3572| [103068] Apache JMeter CVE-2018-1287 Security Bypass Vulnerability
3573| [103067] Apache Qpid Dispatch Router 'router_core/connections.c' Denial of Service Vulnerability
3574| [103036] Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
3575| [103025] Apache Thrift CVE-2016-5397 Remote Command Injection Vulnerability
3576| [102879] Apache POI CVE-2017-12626 Multiple Denial of Service Vulnerabilities
3577| [102842] Apache NiFi CVE-2017-12632 Host Header Injection Vulnerability
3578| [102815] Apache NiFi CVE-2017-15697 Multiple Cross Site Scripting Vulnerabilities
3579| [102488] Apache Geode CVE-2017-9795 Remote Code Execution Vulnerability
3580| [102229] Apache Sling CVE-2017-15700 Information Disclosure Vulnerability
3581| [102226] Apache Drill CVE-2017-12630 Cross Site Scripting Vulnerability
3582| [102154] Multiple Apache Products CVE-2017-15708 Remote Code Execution Vulnerability
3583| [102127] Apache CXF Fediz CVE-2017-12631 Multiple Cross Site Request Forgery Vulnerabilities
3584| [102041] Apache Qpid Broker-J CVE-2017-15701 Denial of Service Vulnerability
3585| [102040] Apache Qpid Broker CVE-2017-15702 Security Weakness
3586| [102021] Apache Struts CVE-2017-15707 Denial of Service Vulnerability
3587| [101980] EMC RSA Authentication Agent for Web: Apache Web Server Authentication Bypass Vulnerability
3588| [101876] Apache Camel CVE-2017-12634 Deserialization Remote Code Execution Vulnerability
3589| [101874] Apache Camel CVE-2017-12633 Deserialization Remote Code Execution Vulnerability
3590| [101872] Apache Karaf CVE-2014-0219 Local Denial of Service Vulnerability
3591| [101868] Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
3592| [101859] Apache CXF CVE-2017-12624 Denial of Service Vulnerability
3593| [101844] Apache Sling Servlets Post CVE-2017-11296 Cross Site Scripting Vulnerability
3594| [101686] Apache Hive CVE-2017-12625 Information Disclosure Vulnerability
3595| [101644] Apache Wicket CVE-2012-5636 Cross Site Scripting Vulnerability
3596| [101631] Apache Traffic Server CVE-2015-3249 Multiple Remote Code Execution Vulnerabilities
3597| [101630] Apache Traffic Server CVE-2014-3624 Access Bypass Vulnerability
3598| [101625] Apache jUDDI CVE-2009-1197 Security Bypass Vulnerability
3599| [101623] Apache jUDDI CVE-2009-1198 Cross Site Scripting Vulnerability
3600| [101620] Apache Subversion 'libsvn_fs_fs/fs_fs.c' Denial of Service Vulnerability
3601| [101585] Apache OpenOffice Multiple Remote Code Execution Vulnerabilities
3602| [101577] Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
3603| [101575] Apache Wicket CVE-2014-0043 Information Disclosure Vulnerability
3604| [101570] Apache Geode CVE-2017-9797 Information Disclosure Vulnerability
3605| [101562] Apache Derby CVE-2010-2232 Arbitrary File Overwrite Vulnerability
3606| [101560] Apache Portable Runtime Utility CVE-2017-12613 Multiple Information Disclosure Vulnerabilities
3607| [101558] Apache Portable Runtime Utility Local Out-of-Bounds Read Denial of Service Vulnerability
3608| [101532] Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
3609| [101516] Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
3610| [101261] Apache Solr/Lucene CVE-2017-12629 Information Disclosure and Remote Code Execution Vulnerabilities
3611| [101230] Apache Roller CVE-2014-0030 XML External Entity Injection Vulnerability
3612| [101173] Apache IMPALA CVE-2017-9792 Information Disclosure Vulnerability
3613| [101052] Apache Commons Jelly CVE-2017-12621 Security Bypass Vulnerability
3614| [101027] Apache Mesos CVE-2017-7687 Denial of Service Vulnerability
3615| [101023] Apache Mesos CVE-2017-9790 Denial of Service Vulnerability
3616| [100954] Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
3617| [100946] Apache Wicket CVE-2014-7808 Cross Site Request Forgery Vulnerability
3618| [100901] Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability
3619| [100897] Apache Tomcat CVE-2017-12616 Information Disclosure Vulnerability
3620| [100880] Apache Directory LDAP API CVE-2015-3250 Unspecified Information Disclosure Vulnerability
3621| [100872] Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
3622| [100870] Apache Solr CVE-2017-9803 Remote Privilege Escalation Vulnerability
3623| [100859] puppetlabs-apache CVE-2017-2299 Information Disclosure Vulnerability
3624| [100829] Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
3625| [100823] Apache Spark CVE-2017-12612 Deserialization Remote Code Execution Vulnerability
3626| [100612] Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
3627| [100611] Apache Struts CVE-2017-9793 Denial of Service Vulnerability
3628| [100609] Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
3629| [100587] Apache Atlas CVE-2017-3155 Cross Frame Scripting Vulnerability
3630| [100581] Apache Atlas CVE-2017-3154 Information Disclosure Vulnerability
3631| [100578] Apache Atlas CVE-2017-3153 Cross Site Scripting Vulnerability
3632| [100577] Apache Atlas CVE-2017-3152 Cross Site Scripting Vulnerability
3633| [100547] Apache Atlas CVE-2017-3151 HTML Injection Vulnerability
3634| [100536] Apache Atlas CVE-2017-3150 Cross Site Scripting Vulnerability
3635| [100449] Apache Pony Mail CVE-2016-4460 Authentication Bypass Vulnerability
3636| [100447] Apache2Triad Multiple Security Vulnerabilities
3637| [100284] Apache Sling Servlets Post CVE-2017-9802 Cross Site Scripting Vulnerability
3638| [100280] Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
3639| [100259] Apache Subversion CVE-2017-9800 Remote Command Execution Vulnerability
3640| [100256] Apache Tomcat CVE-2017-7675 Directory Traversal Vulnerability
3641| [100235] Apache Storm CVE-2017-9799 Remote Code Execution Vulnerability
3642| [100082] Apache Commons Email CVE-2017-9801 SMTP Header Injection Vulnerability
3643| [99873] Apache Sling XSS Protection API CVE-2016-6798 XML External Entity Injection Vulnerability
3644| [99870] Apache Sling API CVE-2016-5394 Cross Site Scripting Vulnerability
3645| [99603] Apache Spark CVE-2017-7678 Cross Site Scripting Vulnerability
3646| [99592] Apache OpenMeetings CVE-2017-7685 Security Bypass Vulnerability
3647| [99587] Apache OpenMeetings CVE-2017-7673 Security Bypass Vulnerability
3648| [99586] Apache OpenMeetings CVE-2017-7688 Security Bypass Vulnerability
3649| [99584] Apache OpenMeetings CVE-2017-7684 Denial of Service Vulnerability
3650| [99577] Apache OpenMeetings CVE-2017-7663 Cross Site Scripting Vulnerability
3651| [99576] Apache OpenMeetings CVE-2017-7664 XML External Entity Injection Vulnerability
3652| [99569] Apache HTTP Server CVE-2017-9788 Memory Corruption Vulnerability
3653| [99568] Apache HTTP Server CVE-2017-9789 Denial of Service Vulnerability
3654| [99563] Apache Struts CVE-2017-7672 Denial of Service Vulnerability
3655| [99562] Apache Struts Spring AOP Functionality Denial of Service Vulnerability
3656| [99509] Apache Impala CVE-2017-5652 Information Disclosure Vulnerability
3657| [99508] Apache IMPALA CVE-2017-5640 Authentication Bypass Vulnerability
3658| [99486] Apache Traffic Control CVE-2017-7670 Denial of Service Vulnerability
3659| [99485] Apache Solr CVE-2017-7660 Security Bypass Vulnerability
3660| [99484] Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
3661| [99292] Apache Ignite CVE-2017-7686 Information Disclosure Vulnerability
3662| [99170] Apache HTTP Server CVE-2017-7679 Buffer Overflow Vulnerability
3663| [99137] Apache HTTP Server CVE-2017-7668 Denial of Service Vulnerability
3664| [99135] Apache HTTP Server CVE-2017-3167 Authentication Bypass Vulnerability
3665| [99134] Apache HTTP Server CVE-2017-3169 Denial of Service Vulnerability
3666| [99132] Apache HTTP Server CVE-2017-7659 Denial of Service Vulnerability
3667| [99112] Apache Thrift CVE-2015-3254 Denial of Service Vulnerability
3668| [99067] Apache Ranger CVE-2016-8751 HTML Injection Vulnerability
3669| [99018] Apache NiFi CVE-2017-7667 Cross Frame Scripting Vulnerability
3670| [99009] Apache NiFi CVE-2017-7665 Cross Site Scripting Vulnerability
3671| [98961] Apache Ranger CVE-2017-7677 Security Bypass Vulnerability
3672| [98958] Apache Ranger CVE-2017-7676 Security Bypass Vulnerability
3673| [98888] Apache Tomcat CVE-2017-5664 Security Bypass Vulnerability
3674| [98814] Apache Zookeeper CVE-2017-5637 Denial of Service Vulnerability
3675| [98795] Apache Hadoop CVE-2017-7669 Remote Privilege Escalation Vulnerability
3676| [98739] Apache Knox CVE-2017-5646 User Impersonation Vulnerability
3677| [98669] Apache Hive CVE-2016-3083 Security Bypass Vulnerability
3678| [98646] Apache Atlas CVE-2016-8752 Information Disclosure Vulnerability
3679| [98570] Apache Archiva CVE-2017-5657 Multiple Cross-Site Request Forgery Vulnerabilities
3680| [98489] Apache CXF Fediz CVE-2017-7661 Multiple Cross Site Request Forgery Vulnerabilities
3681| [98485] Apache CXF Fediz CVE-2017-7662 Cross Site Request Forgery Vulnerability
3682| [98466] Apache Ambari CVE-2017-5655 Insecure Temporary File Handling Vulnerability
3683| [98365] Apache Cordova For Android CVE-2016-6799 Information Disclosure Vulnerability
3684| [98025] Apache Hadoop CVE-2017-3161 Cross Site Scripting Vulnerability
3685| [98017] Apache Hadoop CVE-2017-3162 Input Validation Vulnerability
3686| [97971] Apache CXF CVE-2017-5656 Information Disclosure Vulnerability
3687| [97968] Apache CXF CVE-2017-5653 Spoofing Vulnerability
3688| [97967] Apache ActiveMQ CVE-2015-7559 Denial of Service Vulnerability
3689| [97949] Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
3690| [97948] Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
3691| [97947] Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
3692| [97945] Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
3693| [97702] Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
3694| [97582] Apache CXF CVE-2016-6812 Cross Site Scripting Vulnerability
3695| [97579] Apache CXF JAX-RS CVE-2016-8739 XML External Entity Injection Vulnerability
3696| [97544] Apache Tomcat CVE-2017-5651 Information Disclosure Vulnerability
3697| [97531] Apache Tomcat CVE-2017-5650 Denial of Service Vulnerability
3698| [97530] Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
3699| [97509] Apache Ignite CVE-2016-6805 Information Disclosure and XML External Entity Injection Vulnerabilities
3700| [97383] Apache Flex BlazeDS CVE-2017-5641 Remote Code Execution Vulnerability
3701| [97378] Apache Geode CVE-2017-5649 Information Disclosure Vulnerability
3702| [97229] Apache Ambari CVE-2016-4976 Local Information Disclosure Vulnerability
3703| [97226] Apache Camel CVE-2017-5643 Server Side Request Forgery Security Bypass Vulnerability
3704| [97184] Apache Ambari CVE-2016-6807 Remote Command Execution Vulnerability
3705| [97179] Apache Camel CVE-2016-8749 Java Deserialization Multiple Remote Code Execution Vulnerabilities
3706| [96983] Apache POI CVE-2017-5644 Denial Of Service Vulnerability
3707| [96895] Apache Tomcat CVE-2016-8747 Information Disclosure Vulnerability
3708| [96731] Apache NiFi CVE-2017-5636 Remote Code Injection Vulnerability
3709| [96730] Apache NiFi CVE-2017-5635 Security Bypass Vulnerability
3710| [96729] Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
3711| [96540] IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
3712| [96398] Apache CXF CVE-2017-3156 Information Disclosure Vulnerability
3713| [96321] Apache Camel CVE-2017-3159 Remote Code Execution Vulnerability
3714| [96293] Apache Tomcat 'http11/AbstractInputBuffer.java' Denial of Service Vulnerability
3715| [96228] Apache Brooklyn Cross Site Request Forgery and Multiple Cross Site Scripting Vulnerabilities
3716| [95998] Apache Ranger CVE-2016-8746 Security Bypass Vulnerability
3717| [95929] Apache Groovy CVE-2016-6497 Information Disclosure Vulnerability
3718| [95838] Apache Cordova For Android CVE-2017-3160 Man in the Middle Security Bypass Vulnerability
3719| [95675] Apache Struts Remote Code Execution Vulnerability
3720| [95621] Apache NiFi CVE-2106-8748 Cross Site Scripting Vulnerability
3721| [95429] Apache Groovy CVE-2016-6814 Remote Code Execution Vulnerability
3722| [95335] Apache Hadoop CVE-2016-3086 Information Disclosure Vulnerability
3723| [95168] Apache Wicket CVE-2016-6793 Denial of Service Vulnerability
3724| [95136] Apache Qpid Broker for Java CVE-2016-8741 Remote Information Disclosure Vulnerability
3725| [95078] Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
3726| [95077] Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
3727| [95076] Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
3728| [95020] Apache Tika CVE-2015-3271 Remote Information Disclosure Vulnerability
3729| [94950] Apache Hadoop CVE-2016-5001 Local Information Disclosure Vulnerability
3730| [94882] Apache ActiveMQ CVE-2016-6810 HTML Injection Vulnerability
3731| [94828] Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
3732| [94766] Apache CouchDB CVE-2016-8742 Local Privilege Escalation Vulnerability
3733| [94657] Apache Struts CVE-2016-8738 Denial of Service Vulnerability
3734| [94650] Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
3735| [94588] Apache Subversion CVE-2016-8734 XML External Entity Denial of Service Vulnerability
3736| [94513] Apache Karaf CVE-2016-8648 Remote Code Execution Vulnerability
3737| [94463] Apache Tomcat CVE-2016-8735 Remote Code Execution Vulnerability
3738| [94462] Apache Tomcat CVE-2016-6817 Denial of Service Vulnerability
3739| [94461] Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
3740| [94418] Apache OpenOffice CVE-2016-6803 Local Privilege Escalation Vulnerability
3741| [94247] Apache Tika CVE-2016-6809 Remote Code Execution Vulnerability
3742| [94221] Apache Ranger CVE-2016-6815 Local Privilege Escalation Vulnerability
3743| [94145] Apache OpenMeetings CVE-2016-8736 Remote Code Execution Vulnerability
3744| [93945] Apache CloudStack CVE-2016-6813 Authorization Bypass Vulnerability
3745| [93944] Apache Tomcat Security Manager CVE-2016-6796 Security Bypass Vulnerability
3746| [93943] Apache Tomcat CVE-2016-6794 Security Bypass Vulnerability
3747| [93942] Apache Tomcat Security Manager CVE-2016-5018 Security Bypass Vulnerability
3748| [93940] Apache Tomcat CVE-2016-6797 Security Bypass Vulnerability
3749| [93939] Apache Tomcat CVE-2016-0762 Information Disclosure Vulnerability
3750| [93774] Apache OpenOffice CVE-2016-6804 DLL Loading Remote Code Execution Vulnerability
3751| [93773] Apache Struts CVE-2016-6795 Directory Traversal Vulnerability
3752| [93478] Apache Tomcat CVE-2016-6325 Local Privilege Escalation Vulnerability
3753| [93472] Apache Tomcat CVE-2016-5425 Insecure File Permissions Vulnerability
3754| [93429] Apache Tomcat JK Connector CVE-2016-6808 Remote Buffer Overflow Vulnerability
3755| [93263] Apache Tomcat CVE-2016-1240 Local Privilege Escalation Vulnerability
3756| [93236] Apache MyFaces Trinidad CVE-2016-5019 Remote Code Execution Vulnerability
3757| [93142] Apache ActiveMQ Artemis CVE-2016-4978 Remote Code Execution Vulnerability
3758| [93132] Apache Derby CVE-2015-1832 XML External Entity Information Disclosure Vulnerability
3759| [93044] Apache Zookeeper CVE-2016-5017 Buffer Overflow Vulnerability
3760| [92966] Apache Jackrabbit CVE-2016-6801 Cross-Site Request Forgery Vulnerability
3761| [92947] Apache Shiro CVE-2016-6802 Remote Security Bypass Vulnerability
3762| [92905] Apache CXF Fediz CVE-2016-4464 Security Bypass Vulnerability
3763| [92577] Apache Ranger CVE-2016-5395 HTML Injection Vulnerability
3764| [92331] Apache HTTP Server CVE-2016-1546 Remote Denial of Service Vulnerability
3765| [92328] Apache Hive CVE-2016-0760 Multiple Remote Code Execution Vulnerabilities
3766| [92320] Apache APR-util and httpd CVE-2016-6312 Denial of Service Vulnerability
3767| [92100] Apache POI CVE-2016-5000 XML External Entity Injection Vulnerability
3768| [92079] Apache OpenOffice CVE-2016-1513 Remote Code Execution Vulnerability
3769| [91818] Apache Tomcat CVE-2016-5388 Security Bypass Vulnerability
3770| [91816] Apache HTTP Server CVE-2016-5387 Security Bypass Vulnerability
3771| [91788] Apache Qpid Proton CVE-2016-4467 Certificate Verification Security Bypass Vulnerability
3772| [91738] Apache XML-RPC CVE-2016-5003 Remote Code Execution Vulnerability
3773| [91736] Apache XML-RPC Multiple Security Vulnerabilities
3774| [91707] Apache Archiva CVE-2016-5005 HTML Injection Vulnerability
3775| [91703] Apache Archiva CVE-2016-4469 Multiple Cross-Site Request Forgery Vulnerabilities
3776| [91566] Apache HTTP Server CVE-2016-4979 Authentication Bypass Vulnerability
3777| [91537] Apache QPID CVE-2016-4974 Deserialization Security Bypass Vulnerability
3778| [91501] Apache Xerces-C CVE-2016-4463 Stack Buffer Overflow Vulnerability
3779| [91453] Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
3780| [91284] Apache Struts CVE-2016-4431 Security Bypass Vulnerability
3781| [91282] Apache Struts CVE-2016-4433 Security Bypass Vulnerability
3782| [91281] Apache Struts CVE-2016-4430 Cross-Site Request Forgery Vulnerability
3783| [91280] Apache Struts CVE-2016-4436 Security Bypass Vulnerability
3784| [91278] Apache Struts CVE-2016-4465 Denial of Service Vulnerability
3785| [91277] Apache Struts Incomplete Fix Remote Code Execution Vulnerability
3786| [91275] Apache Struts CVE-2016-4438 Remote Code Execution Vulnerability
3787| [91217] Apache Continuum 'saveInstallation.action' Command Execution Vulnerability
3788| [91141] Apache CloudStack CVE-2016-3085 Authentication Bypass Vulnerability
3789| [91068] Apache Struts CVE-2016-1181 Remote Code Execution Vulnerability
3790| [91067] Apache Struts CVE-2016-1182 Security Bypass Vulnerability
3791| [91024] Apache Shiro CVE-2016-4437 Information Disclosure Vulnerability
3792| [90988] Apache Ranger CVE-2016-2174 SQL Injection Vulnerability
3793| [90961] Apache Struts CVE-2016-3093 Denial of Service Vulnerability
3794| [90960] Apache Struts CVE-2016-3087 Remote Code Execution Vulnerability
3795| [90921] Apache Qpid CVE-2016-4432 Authentication Bypass Vulnerability
3796| [90920] Apache Qpid CVE-2016-3094 Denial of Service Vulnerability
3797| [90902] Apache PDFBox CVE-2016-2175 XML External Entity Injection Vulnerability
3798| [90897] Apache Tika CVE-2016-4434 XML External Entity Injection Vulnerability
3799| [90827] Apache ActiveMQ CVE-2016-3088 Multiple Arbitrary File Upload Vulnerabilities
3800| [90755] Apache Ambari CVE-2016-0707 Multiple Local Information Disclosure Vulnerabilities
3801| [90482] Apache CVE-2004-1387 Local Security Vulnerability
3802| [89762] Apache CVE-2001-1556 Remote Security Vulnerability
3803| [89417] Apache Subversion CVE-2016-2167 Authentication Bypass Vulnerability
3804| [89326] RETIRED: Apache Subversion CVE-2016-2167 Security Bypass Vulnerability
3805| [89320] Apache Subversion CVE-2016-2168 Remote Denial of Service Vulnerability
3806| [88826] Apache Struts CVE-2016-3082 Remote Code Execution Vulnerability
3807| [88797] Apache Cordova For iOS CVE-2015-5208 Arbitrary Code Execution Vulnerability
3808| [88764] Apache Cordova iOS CVE-2015-5207 Multiple Security Bypass Vulnerabilities
3809| [88701] Apache CVE-2001-1449 Remote Security Vulnerability
3810| [88635] Apache CVE-2000-1204 Remote Security Vulnerability
3811| [88590] Apache WWW server CVE-1999-1199 Denial-Of-Service Vulnerability
3812| [88496] Apache CVE-2000-1206 Remote Security Vulnerability
3813| [87828] Apache CVE-1999-1237 Remote Security Vulnerability
3814| [87784] Apache CVE-1999-1293 Denial-Of-Service Vulnerability
3815| [87327] Apache Struts CVE-2016-3081 Remote Code Execution Vulnerability
3816| [86622] Apache Stats CVE-2007-0975 Remote Security Vulnerability
3817| [86399] Apache CVE-2007-1743 Local Security Vulnerability
3818| [86397] Apache CVE-2007-1742 Local Security Vulnerability
3819| [86311] Apache Struts CVE-2016-4003 Cross Site Scripting Vulnerability
3820| [86174] Apache Wicket CVE-2015-5347 Cross Site Scripting Vulnerability
3821| [85971] Apache OFBiz CVE-2016-2170 Java Deserialization Remote Code Execution Vulnerability
3822| [85967] Apache OFBiz CVE-2015-3268 HTML Injection Vulnerability
3823| [85759] Apache Jetspeed CVE-2016-2171 Unauthorized Access Vulnerability
3824| [85758] Apache Jetspeed CVE-2016-0712 Cross Site Scripting Vulnerability
3825| [85756] Apache Jetspeed CVE-2016-0710 Multiple SQL Injection Vulnerabilities
3826| [85755] Apache Jetspeed CVE-2016-0711 Mulitple HTML Injection Vulnerabilities
3827| [85754] Apache Jetspeed CVE-2016-0709 Directory Traversal Vulnerability
3828| [85730] Apache Subversion CVE-2015-5343 Integer Overflow Vulnerability
3829| [85691] Apache Ranger CVE-2016-0735 Security Bypass Vulnerability
3830| [85578] Apache ActiveMQ CVE-2010-1244 Cross-Site Request Forgery Vulnerability
3831| [85554] Apache OpenMeetings CVE-2016-2164 Multiple Information Disclosure Vulnerabilities
3832| [85553] Apache OpenMeetings CVE-2016-0783 Information Disclosure Vulnerability
3833| [85552] Apache OpenMeetings CVE-2016-2163 HTML Injection Vulnerability
3834| [85550] Apache OpenMeetings CVE-2016-0784 Directory Traversal Vulnerability
3835| [85386] Apache Hadoop CVE-2015-7430 Local Privilege Escalation Vulnerability
3836| [85377] Apache Qpid Proton Python API CVE-2016-2166 Man in the Middle Security Bypass Vulnerability
3837| [85205] Apache Solr CVE-2015-8796 Cross Site Scripting Vulnerability
3838| [85203] Apache Solr CVE-2015-8795 Mulitple HTML Injection Vulnerabilities
3839| [85163] Apache Geronimo CVE-2008-0732 Local Security Vulnerability
3840| [85131] Apache Struts 'TextParseUtil.translateVariables()' Method Remote Code Execution Vulnerability
3841| [85070] Apache Struts CVE-2016-2162 Cross Site Scripting Vulnerability
3842| [85066] Apache Struts CVE-2016-0785 Remote Code Execution Vulnerability
3843| [84422] Apache TomEE CVE-2016-0779 Unspecified Security Vulnerability
3844| [84321] Apache ActiveMQ CVE-2016-0734 Clickjacking Vulnerability
3845| [84316] Apache ActiveMQ CVE-2016-0782 Multiple Cross Site Scripting Vulnerabilities
3846| [83910] Apache Wicket CVE-2015-7520 Cross Site Scripting Vulnerability
3847| [83423] Apache Xerces-C CVE-2016-0729 Buffer Overflow Vulnerability
3848| [83330] Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability
3849| [83329] Apache Tomcat CVE-2015-5174 Directory Traversal Vulnerability
3850| [83328] Apache Tomcat CVE-2015-5345 Directory Traversal Vulnerability
3851| [83327] Apache Tomcat Security Manager CVE-2016-0714 Remote Code Execution Vulnerability
3852| [83326] Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
3853| [83324] Apache Tomcat Security Manager CVE-2016-0706 Information Disclosure Vulnerability
3854| [83323] Apache Tomcat CVE-2015-5346 Session Fixation Vulnerability
3855| [83259] Apache Hadoop CVE-2015-1776 Information Disclosure Vulnerability
3856| [83243] Apache Solr CVE-2015-8797 Cross Site Scripting Vulnerability
3857| [83119] Apache Sling CVE-2016-0956 Information Disclosure Vulnerability
3858| [83002] Apache CVE-2000-1205 Cross-Site Scripting Vulnerability
3859| [82871] Apache Ranger Authentication Bypass and Security Bypass Vulnerabilities
3860| [82800] Apache CloudStack CVE-2015-3251 Information Disclosure Vulnerability
3861| [82798] Apache CloudStack CVE-2015-3252 Authentication Bypass Vulnerability
3862| [82732] Apache Gallery CVE-2003-0771 Local Security Vulnerability
3863| [82676] Apache CVE-2003-1581 Cross-Site Scripting Vulnerability
3864| [82550] Apache Struts CVE-2015-5209 Security Bypass Vulnerability
3865| [82300] Apache Subversion CVE-2015-5259 Integer Overflow Vulnerability
3866| [82260] Apache Camel CVE-2015-5344 Remote Code Execution Vulnerability
3867| [82234] Apache Hive CVE-2015-7521 Security Bypass Vulnerability
3868| [82082] Apache CVE-1999-0289 Remote Security Vulnerability
3869| [81821] Apache Distribution for Solaris CVE-2007-2080 SQL-Injection Vulnerability
3870| [80696] Apache Camel CVE-2015-5348 Information Disclosure Vulnerability
3871| [80525] Apache CVE-2003-1580 Remote Security Vulnerability
3872| [80354] Drupal Apache Solr Search Module Access Bypass Vulnerability
3873| [80193] Apache CVE-1999-0107 Denial-Of-Service Vulnerability
3874| [79812] Apache Directory Studio CVE-2015-5349 Command Injection Vulnerability
3875| [79744] Apache HBase CVE-2015-1836 Unauthorized Access Vulnerability
3876| [79204] Apache TomEE 'EjbObjectInputStream' Remote Code Execution Vulnerability
3877| [77679] Apache Cordova For Android CVE-2015-8320 Weak Randomization Security Bypass Vulnerability
3878| [77677] Apache Cordova For Android CVE-2015-5256 Security Bypass Vulnerability
3879| [77591] Apache CXF SAML SSO Processing CVE-2015-5253 Security Bypass Vulnerability
3880| [77521] Apache Commons Collections 'InvokerTransformer.java' Remote Code Execution Vulnerability
3881| [77110] Apache HttpComponents HttpClient CVE-2015-5262 Denial of Service Vulnerability
3882| [77086] Apache Ambari CVE-2015-1775 Server Side Request Forgery Security Bypass Vulnerability
3883| [77085] Apache Ambari CVE-2015-3270 Remote Privilege Escalation Vulnerability
3884| [77082] Apache Ambari 'targetURI' Parameter Open Redirection Vulnerability
3885| [77059] Apache Ambari CVE-2015-3186 Cross Site Scripting Vulnerability
3886| [76933] Apache James Server Unspecified Command Execution Vulnerability
3887| [76832] Apache cordova-plugin-file-transfer CVE-2015-5204 HTTP Header Injection Vulnerability
3888| [76625] Apache Struts CVE-2015-5169 Cross Site Scripting Vulnerability
3889| [76624] Apache Struts CVE-2015-2992 Cross Site Scripting Vulnerability
3890| [76522] Apache Tapestry CVE-2014-1972 Security Bypass Vulnerability
3891| [76486] Apache CXF Fediz CVE-2015-5175 Denial of Service Vulnerability
3892| [76452] Apache ActiveMQ CVE-2015-1830 Directory Traversal Vulnerability
3893| [76446] Apache Subversion 'libsvn_fs_fs/tree.c' Denial of Service Vulnerability
3894| [76274] Apache Subversion CVE-2015-3184 Information Disclosure Vulnerability
3895| [76273] Apache Subversion CVE-2015-3187 Information Disclosure Vulnerability
3896| [76272] Apache ActiveMQ CVE-2014-3576 Denial of Service Vulnerability
3897| [76221] Apache Ranger CVE-2015-0266 Access Bypass Vulnerability
3898| [76208] Apache Ranger CVE-2015-0265 JavaScript Code Injection Vulnerability
3899| [76025] Apache ActiveMQ Artemis CVE-2015-3208 XML External Entity Information Disclosure Vulnerability
3900| [75965] Apache HTTP Server CVE-2015-3185 Security Bypass Vulnerability
3901| [75964] Apache HTTP Server CVE-2015-0253 Remote Denial of Service Vulnerability
3902| [75963] Apache HTTP Server CVE-2015-3183 Security Vulnerability
3903| [75940] Apache Struts CVE-2015-1831 Security Bypass Vulnerability
3904| [75919] Apache Groovy CVE-2015-3253 Remote Code Execution Vulnerability
3905| [75338] Apache Storm CVE-2015-3188 Remote Code Execution Vulnerability
3906| [75275] Drupal Apache Solr Real-Time Module Access Bypass Vulnerability
3907| [74866] Apache Cordova For Android CVE-2015-1835 Security Bypass Vulnerability
3908| [74839] Apache Sling API and Sling Servlets CVE-2015-2944 Cross Site Scripting Vulnerability
3909| [74761] Apache Jackrabbit CVE-2015-1833 XML External Entity Information Disclosure Vulnerability
3910| [74686] Apache Ambari '/var/lib/ambari-server/ambari-env.sh' Local Privilege Escalation Vulnerability
3911| [74665] Apache Tomcat CVE-2014-7810 Security Bypass Vulnerability
3912| [74475] Apache Tomcat CVE-2014-0230 Denial of Service Vulnerability
3913| [74423] Apache Struts CVE-2015-0899 Security Bypass Vulnerability
3914| [74338] Apache OpenOffice HWP Filter Memory Corruption Vulnerability
3915| [74265] Apache Tomcat 'mod_jk' CVE-2014-8111 Information Disclosure Vulnerability
3916| [74260] Apache Subversion CVE-2015-0248 Multiple Denial of Service Vulnerabilities
3917| [74259] Apache Subversion 'deadprops.c' Security Bypass Vulnerability
3918| [74204] PHP 'sapi/apache2handler/sapi_apache2.c' Remote Code Execution Vulnerability
3919| [74158] Apache HTTP Server 'protocol.c' Remote Denial of Service Vulnerability
3920| [73954] Apache Flex 'asdoc/templates/index.html' Cross Site Scripting Vulnerability
3921| [73851] Apache2 CVE-2012-0216 Cross-Site Scripting Vulnerability
3922| [73478] Apache Cassandra CVE-2015-0225 Remote Code Execution Vulnerability
3923| [73041] Apache HTTP Server 'mod_lua' Module Denial of Service Vulnerability
3924| [73040] Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
3925| [72809] Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
3926| [72717] Apache Tomcat CVE-2014-0227 Chunk Request Remote Denial Of Service Vulnerability
3927| [72557] Apache WSS4J CVE-2015-0227 Security Bypass Vulnerability
3928| [72553] Apache WSS4J CVE-2015-0226 Information Disclosure Vulnerability
3929| [72513] Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
3930| [72511] Apache ActiveMQ CVE-2014-8110 Multiple Cross Site Scripting Vulnerabilities
3931| [72510] Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
3932| [72508] Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
3933| [72319] Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
3934| [72317] Apache Qpid CVE-2015-0224 Incomplete Fix Multiple Denial of Service Vulnerabilities
3935| [72115] Apache Santuario 'XML Signature Verification' Security Bypass Vulnerability
3936| [72053] Apache HTTP Server 'mod_remoteip.c' IP Address Spoofing Vulnerability
3937| [72030] Apache Qpid CVE-2015-0203 Multiple Denial of Service Vulnerabilities
3938| [71879] Apache Traffic Server 'HttpTransact.cc' Denial of Service Vulnerability
3939| [71726] Apache Subversion CVE-2014-3580 Remote Denial of Service Vulnerability
3940| [71725] Apache Subversion CVE-2014-8108 Remote Denial of Service Vulnerability
3941| [71657] Apache HTTP Server 'mod_proxy_fcgi' Module Denial of Service Vulnerability
3942| [71656] Apache HTTP Server 'mod_cache' Module Denial of Service Vulnerability
3943| [71548] Apache Struts CVE-2014-7809 Security Bypass Vulnerability
3944| [71466] Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
3945| [71353] Apache HTTP Server 'LuaAuthzProvider' Authorization Bypass Vulnerability
3946| [71004] Apache Qpid CVE-2014-3629 XML External Entity Injection Vulnerability
3947| [70970] Apache Traffic Server Cross Site Scripting Vulnerability
3948| [70738] Apache CXF CVE-2014-3584 Denial of Service Vulnerability
3949| [70736] Apache CXF SAML SubjectConfirmation Security Bypass Vulnerability
3950| [69728] Apache Tomcat CVE-2013-4444 Arbitrary File Upload Vulnerability
3951| [69648] Apache POI CVE-2014-3574 Denial Of Service Vulnerability
3952| [69647] Apache POI OpenXML parser CVE-2014-3529 XML External Entity Information Disclosure Vulnerability
3953| [69351] Apache OpenOffice Calc CVE-2014-3524 Command Injection Vulnerability
3954| [69295] Apache Axis Incomplete Fix CVE-2014-3596 SSL Certificate Validation Security Bypass Vulnerability
3955| [69286] Apache OFBiz CVE-2014-0232 Multiple Cross Site Scripting Vulnerabilities
3956| [69258] Apache HttpComponents Incomplete Fix CVE-2014-3577 SSL Validation Security Bypass Vulnerability
3957| [69257] Apache HttpComponents Incomplete Fix SSL Certificate Validation Security Bypass Vulnerability
3958| [69248] Apache HTTP Server CVE-2013-4352 Remote Denial of Service Vulnerability
3959| [69237] Apache Subversion CVE-2014-3522 SSL Certificate Validation Information Disclosure Vulnerability
3960| [69173] Apache Traffic Server CVE-2014-3525 Unspecified Security Vulnerability
3961| [69046] Apache Cordova For Android CVE-2014-3502 Information Disclosure Vulnerability
3962| [69041] Apache Cordova For Android CVE-2014-3501 Security Bypass Vulnerability
3963| [69038] Apache Cordova For Android CVE-2014-3500 Security Bypass Vulnerability
3964| [68995] Apache Subversion CVE-2014-3528 Insecure Authentication Weakness
3965| [68966] Apache Subversion 'irkerbridge.py' Local Privilege Escalation Vulnerability
3966| [68965] Apache Subversion 'svnwcsub.py' Local Privilege Escalation Vulnerability
3967| [68863] Apache HTTP Server 'mod_cache' Module Remote Denial of Service Vulnerability
3968| [68747] Apache HTTP Server CVE-2014-3523 Remote Denial of Service Vulnerability
3969| [68745] Apache HTTP Server CVE-2014-0118 Remote Denial of Service Vulnerability
3970| [68742] Apache HTTP Server CVE-2014-0231 Remote Denial of Service Vulnerability
3971| [68740] Apache HTTP Server CVE-2014-0117 Remote Denial of Service Vulnerability
3972| [68678] Apache HTTP Server 'mod_status' CVE-2014-0226 Remote Code Execution Vulnerability
3973| [68445] Apache CXF UsernameToken Information Disclosure Vulnerability
3974| [68441] Apache CXF SAML Tokens Validation Security Bypass Vulnerability
3975| [68431] Apache Syncope CVE-2014-3503 Insecure Password Generation Weakness
3976| [68229] Apache Harmony PRNG Entropy Weakness
3977| [68111] Apache 'mod_wsgi' Module Privilege Escalation Vulnerability
3978| [68072] Apache Tomcat CVE-2014-0186 Remote Denial of Service Vulnerability
3979| [68039] Apache Hive CVE-2014-0228 Security Bypass Vulnerability
3980| [67673] Apache Tomcat CVE-2014-0095 AJP Request Remote Denial Of Service Vulnerability
3981| [67671] Apache Tomcat CVE-2014-0075 Chunk Request Remote Denial Of Service Vulnerability
3982| [67669] Apache Tomcat CVE-2014-0119 XML External Entity Information Disclosure Vulnerability
3983| [67668] Apache Tomcat CVE-2014-0099 Request Processing Information Disclosure Vulnerability
3984| [67667] Apache Tomcat CVE-2014-0096 XML External Entity Information Disclosure Vulnerability
3985| [67534] Apache 'mod_wsgi' Module CVE-2014-0242 Information Disclosure Vulnerability
3986| [67532] Apache 'mod_wsgi' Module Local Privilege Escalation Vulnerability
3987| [67530] Apache Solr Search Template Cross Site Scripting Vulnerability
3988| [67236] Apache CXF CVE-2014-0109 Remote Denial of Service Vulnerability
3989| [67232] Apache CXF CVE-2014-0110 Denial of Service Vulnerability
3990| [67121] Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
3991| [67081] Apache Struts 'getClass()' Method Security Bypass Vulnerability
3992| [67064] Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
3993| [67013] Apache Zookeeper CVE-2014-0085 Local Information Disclosure Vulnerability
3994| [66998] Apache Archiva CVE-2013-2187 Unspecified Cross Site Scripting Vulnerability
3995| [66991] Apache Archiva CVE-2013-2187 HTML Injection Vulnerability
3996| [66927] Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
3997| [66474] Apache CouchDB Universally Unique IDentifier (UUID) Remote Denial of Service Vulnerability
3998| [66397] Apache Xalan-Java Library CVE-2014-0107 Security Bypass Vulnerability
3999| [66303] Apache HTTP Server Multiple Denial of Service Vulnerabilities
4000| [66041] RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
4001| [65999] Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability
4002| [65967] Apache Cordova File-Transfer Unspecified Security Vulnerability
4003| [65959] Apache Cordova InAppBrowser Remote Privilege Escalation Vulnerability
4004| [65935] Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
4005| [65902] Apache Camel CVE-2014-0003 Remote Code Execution Vulnerability
4006| [65901] Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
4007| [65773] Apache Tomcat CVE-2013-4286 Security Bypass Vulnerability
4008| [65769] Apache Tomcat CVE-2014-0033 Session Fixation Vulnerability
4009| [65768] Apache Tomcat CVE-2013-4590 XML External Entity Information Disclosure Vulnerability
4010| [65767] Apache Tomcat CVE-2013-4322 Incomplete Fix Denial of Service Vulnerability
4011| [65615] Apache ActiveMQ 'refresh' Parameter Cross Site Scripting Vulnerability
4012| [65434] Apache Subversion 'mod_dav_svn' Module SVNListParentPath Denial of Service Vulnerability
4013| [65431] Apache Wicket CVE-2013-2055 Information Disclosure Vulnerability
4014| [65400] Apache Commons FileUpload CVE-2014-0050 Denial Of Service Vulnerability
4015| [64782] Apache CloudStack Virtual Router Component Security Bypass Vulnerability
4016| [64780] Apache CloudStack Unauthorized Access Vulnerability
4017| [64617] Apache Libcloud Digital Ocean API Local Information Disclosure Vulnerability
4018| [64437] Apache Santuario XML Security For JAVA XML Signature Denial of Service Vulnerability
4019| [64427] Apache Solr Multiple XML External Entity Injection Vulnerabilities
4020| [64009] Apache Solr CVE-2013-6408 XML External Entity Injection Vulnerability
4021| [64008] Apache Solr CVE-2013-6407 XML External Entity Injection Vulnerability
4022| [63981] Apache Subversion 'mod_dav_svn' Module Denial of Service Vulnerability
4023| [63966] Apache Subversion CVE-2013-4505 Security Bypass Vulnerability
4024| [63963] Apache Roller CVE-2013-4171 Cross Site Scripting Vulnerability
4025| [63935] Apache Solr 'SolrResourceLoader' Directory Traversal Vulnerability
4026| [63928] Apache Roller CVE-2013-4212 OGNL Expression Injection Remote Code Execution Vulnerability
4027| [63515] Apache Tomcat Manager Component CVE-2013-6357 Cross Site Request Forgery Vulnerability
4028| [63403] Apache Struts Multiple Cross Site Scripting Vulnerabilities
4029| [63400] Apache 'mod_pagespeed' Module Unspecified Cross Site Scripting Vulnerability
4030| [63260] Apache Shindig CVE-2013-4295 XML External Entity Information Disclosure Vulnerability
4031| [63241] Apache Sling 'AbstractAuthenticationFormServlet' Open Redirection Vulnerability
4032| [63174] Apache Commons FileUpload 'DiskFileItem' Class Null Byte Arbitrary File Write Vulnerability
4033| [62939] Apache 'mod_fcgid' Module CVE-2013-4365 Heap Buffer Overflow Vulnerability
4034| [62903] Apache Sling 'deepGetOrCreateNode()' Function Denial Of Service Vulnerability
4035| [62706] Apache Camel CVE-2013-4330 Information Disclosure Vulnerability
4036| [62677] Apache 'mod_accounting' Module CVE-2013-5697 SQL Injection Vulnerability
4037| [62674] TYPO3 Apache Solr Unspecified Cross Site Scripting and PHP Code Execution Vulnerabilities
4038| [62587] Apache Struts CVE-2013-4316 Remote Code Execution Vulnerability
4039| [62584] Apache Struts CVE-2013-4310 Security Bypass Vulnerability
4040| [62266] Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
4041| [61984] Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
4042| [61981] Apache HBase RPC Authentication Man In The Middle Security Bypass Vulnerability
4043| [61638] Apache CloudStack CVE-2013-2136 Multiple Cross Site Scripting Vulnerabilities
4044| [61454] Apache Subversion CVE-2013-4131 Denial Of Service Vulnerability
4045| [61379] Apache HTTP Server CVE-2013-2249 Unspecified Remote Security Vulnerability
4046| [61370] Apache OFBiz CVE-2013-2317 'View Log' Cross Site Scripting Vulnerability
4047| [61369] Apache OFBiz Nested Expression Remote Code Execution Vulnerability
4048| [61196] Apache Struts CVE-2013-2248 Multiple Open Redirection Vulnerabilities
4049| [61189] Apache Struts CVE-2013-2251 Multiple Remote Command Execution Vulnerabilities
4050| [61129] Apache HTTP Server CVE-2013-1896 Remote Denial of Service Vulnerability
4051| [61030] Apache CXF CVE-2013-2160 Multiple Remote Denial of Service Vulnerabilities
4052| [60875] Apache Geronimo RMI Classloader Security Bypass Vulnerability
4053| [60846] Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
4054| [60817] Apache Santuario XML Security for C++ CVE-2013-2210 Heap Buffer Overflow Vulnerability
4055| [60800] Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
4056| [60599] Apache Santuario XML Security for C++ CVE-2013-2156 Remote Heap Buffer Overflow Vulnerability
4057| [60595] Apache Santuario XML Security for C++ XML Signature CVE-2013-2155 Denial of Service Vulnerability
4058| [60594] Apache Santuario XML Security for C++ CVE-2013-2154 Stack Buffer Overflow Vulnerability
4059| [60592] Apache Santuario XML Security for C++ XML Signature CVE-2013-2153 Security Bypass Vulnerability
4060| [60534] Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
4061| [60346] Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
4062| [60345] Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
4063| [60267] Apache Subversion CVE-2013-1968 Remote Denial of Service Vulnerability
4064| [60265] Apache Subversion CVE-2013-2088 Command Injection Vulnerability
4065| [60264] Apache Subversion CVE-2013-2112 Remote Denial of Service Vulnerability
4066| [60187] Apache Tomcat DIGEST Authentication CVE-2013-2051 Incomplete Fix Security Weakness
4067| [60186] Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
4068| [60167] Apache Struts 'includeParams' CVE-2013-2115 Incomplete Fix Security Bypass Vulnerability
4069| [60166] Apache Struts 'includeParams' CVE-2013-1966 Security Bypass Vulnerability
4070| [60082] Apache Struts 'ParameterInterceptor' Class OGNL CVE-2013-1965 Security Bypass Vulnerability
4071| [59826] Apache HTTP Server Terminal Escape Sequence in Logs Command Injection Vulnerability
4072| [59799] Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
4073| [59798] Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
4074| [59797] Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
4075| [59670] Apache VCL Multiple Input Validation Vulnerabilities
4076| [59464] Apache CloudStack CVE-2013-2758 Hash Information Disclosure Vulnerability
4077| [59463] Apache CloudStack CVE-2013-2756 Authentication Bypass Vulnerability
4078| [59402] Apache ActiveMQ CVE-2013-3060 Information Disclosure and Denial of Service Vulnerability
4079| [59401] Apache ActiveMQ CVE-2012-6551 Denial of Service Vulnerability
4080| [59400] Apache ActiveMQ CVE-2012-6092 Multiple Cross Site Scripting Vulnerabilities
4081| [58898] Apache Subversion CVE-2013-1884 Remote Denial of Service Vulnerability
4082| [58897] Apache Subversion 'mod_dav_svn/lock.c' Remote Denial of Service Vulnerability
4083| [58895] Apache Subversion 'mod_dav_svn' Remote Denial of Service Vulnerability
4084| [58455] Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
4085| [58379] Apache Qpid CVE-2012-4446 Authentication Bypass Vulnerability
4086| [58378] Apache Qpid CVE-2012-4460 Denial of Service Vulnerability
4087| [58376] Apache Qpid CVE-2012-4458 Denial of Service Vulnerability
4088| [58337] Apache Qpid CVE-2012-4459 Denial of Service Vulnerability
4089| [58326] Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
4090| [58325] Debian Apache HTTP Server CVE-2013-1048 Symlink Attack Local Privilege Escalation Vulnerability
4091| [58323] Apache Subversion 'svn_fs_file_length()' Remote Denial of Service Vulnerability
4092| [58165] Apache HTTP Server Multiple Cross Site Scripting Vulnerabilities
4093| [58136] Apache Maven CVE-2013-0253 SSL Certificate Validation Security Bypass Vulnerability
4094| [58124] Apache Tomcat 'log/logdir' Directory Insecure File Permissions Vulnerability
4095| [58073] Apache Commons HttpClient CVE-2012-5783 SSL Certificate Validation Security Bypass Vulnerability
4096| [57876] Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
4097| [57874] Apache CXF CVE-2012-5633 Security Bypass Vulnerability
4098| [57463] Apache OFBiz CVE-2013-0177 Multiple Cross Site Scripting Vulnerabilities
4099| [57425] Apache CXF CVE-2012-5786 SSL Certificate Validation Security Bypass Vulnerability
4100| [57321] Apache CouchDB CVE-2012-5650 Cross Site Scripting Vulnerability
4101| [57314] Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
4102| [57267] Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
4103| [57259] Apache CloudStack CVE-2012-5616 Local Information Disclosure Vulnerability
4104| [56814] Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
4105| [56813] Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
4106| [56812] Apache Tomcat CVE-2012-3546 Security Bypass Vulnerability
4107| [56753] Apache Apache HTTP Server 'mod_proxy_ajp Module Denial Of Service Vulnerability
4108| [56686] Apache Tomcat CVE-2012-5568 Denial of Service Vulnerability
4109| [56408] Apache Axis and Axis2/Java SSL Certificate Validation Security Bypass Vulnerability
4110| [56403] Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
4111| [56402] Apache Tomcat CVE-2012-2733 Denial of Service Vulnerability
4112| [56171] Apache OFBiz CVE-2012-3506 Unspecified Security Vulnerability
4113| [55876] Apache CloudStack CVE-2012-4501 Security Bypass Vulnerability
4114| [55628] Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
4115| [55608] Apache Qpid (qpidd) Denial of Service Vulnerability
4116| [55536] Apache 'mod_pagespeed' Module Cross Site Scripting and Security Bypass Vulnerabilities
4117| [55508] Apache Axis2 XML Signature Wrapping Security Vulnerability
4118| [55445] Apache Wicket CVE-2012-3373 Cross Site Scripting Vulnerability
4119| [55346] Apache Struts Cross Site Request Forgery and Denial of Service Vulnerabilities
4120| [55290] Drupal Apache Solr Autocomplete Module Cross Site Scripting Vulnerability
4121| [55165] Apache Struts2 Skill Name Remote Code Execution Vulnerability
4122| [55154] Apache 'mod-rpaf' Module Denial of Service Vulnerability
4123| [55131] Apache HTTP Server HTML-Injection And Information Disclosure Vulnerabilities
4124| [54954] Apache QPID NullAuthenticator Authentication Bypass Vulnerability
4125| [54798] Apache Libcloud Man In The Middle Vulnerability
4126| [54358] Apache Hadoop CVE-2012-3376 Information Disclosure Vulnerability
4127| [54341] Apache Sling CVE-2012-2138 Denial Of Service Vulnerability
4128| [54268] Apache Hadoop Symlink Attack Local Privilege Escalation Vulnerability
4129| [54189] Apache Roller Cross Site Request Forgery Vulnerability
4130| [54187] Apache Roller CVE-2012-2381 Cross Site Scripting Vulnerability
4131| [53880] Apache CXF Child Policies Security Bypass Vulnerability
4132| [53877] Apache CXF Elements Validation Security Bypass Vulnerability
4133| [53676] Apache Commons Compress and Apache Ant CVE-2012-2098 Denial Of Service Vulnerability
4134| [53487] Apache POI CVE-2012-0213 Denial Of Service Vulnerability
4135| [53455] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability
4136| [53305] Apache Qpid CVE-2011-3620 Unauthorized Access Security Bypass Vulnerability
4137| [53046] Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
4138| [53025] Apache OFBiz Unspecified Remote Code Execution Vulnerability
4139| [53023] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
4140| [52939] Apache Hadoop CVE-2012-1574 Unspecified User Impersonation Vulnerability
4141| [52702] Apache Struts2 'XSLTResult.java' Remote Arbitrary File Upload Vulnerability
4142| [52696] Apache Traffic Server HTTP Host Header Handling Heap Based Buffer Overflow Vulnerability
4143| [52680] Apache Wicket 'pageMapName' Parameter Cross Site Scripting Vulnerability
4144| [52679] Apache Wicket Hidden Files Information Disclosure Vulnerability
4145| [52565] Apache 'mod_fcgid' Module Denial Of Service Vulnerability
4146| [52146] TYPO3 Apache Solr Extension Unspecified Cross Site Scripting Vulnerability
4147| [51939] Apache MyFaces 'ln' Parameter Information Disclosure Vulnerability
4148| [51917] Apache APR Hash Collision Denial Of Service Vulnerability
4149| [51902] Apache Struts Multiple HTML Injection Vulnerabilities
4150| [51900] Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
4151| [51886] Apache CXF UsernameToken Policy Validation Security Bypass Vulnerability
4152| [51869] Apache HTTP Server CVE-2011-3639 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
4153| [51706] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
4154| [51705] Apache HTTP Server CVE-2012-0021 mod_log_config Denial Of Service Vulnerability
4155| [51628] Apache Struts 'ParameterInterceptor' Class OGNL (CVE-2011-3923) Security Bypass Vulnerability
4156| [51447] Apache Tomcat Parameter Handling Denial of Service Vulnerability
4157| [51442] Apache Tomcat Request Object Security Bypass Vulnerability
4158| [51407] Apache HTTP Server Scoreboard Local Security Bypass Vulnerability
4159| [51257] Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
4160| [51238] Apache Geronimo Hash Collision Denial Of Service Vulnerability
4161| [51200] Apache Tomcat Hash Collision Denial Of Service Vulnerability
4162| [50940] Apache Struts Session Tampering Security Bypass Vulnerability
4163| [50912] RETIRED: Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
4164| [50904] Apache ActiveMQ Failover Mechanism Remote Denial Of Service Vulnerability
4165| [50848] Apache MyFaces EL Expression Evaluation Security Bypass Vulnerability
4166| [50802] Apache HTTP Server 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
4167| [50639] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
4168| [50603] Apache Tomcat Manager Application Security Bypass Vulnerability
4169| [50494] Apache HTTP Server 'ap_pregsub()' Function Local Privilege Escalation Vulnerability
4170| [49957] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
4171| [49762] Apache Tomcat HTTP DIGEST Authentication Multiple Security Weaknesses
4172| [49728] Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
4173| [49616] Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
4174| [49470] Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
4175| [49353] Apache Tomcat AJP Protocol Security Bypass Vulnerability
4176| [49303] Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability
4177| [49290] Apache Wicket Cross Site Scripting Vulnerability
4178| [49147] Apache Tomcat CVE-2011-2481 Information Disclosure Vulnerability
4179| [49143] Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
4180| [48667] Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability
4181| [48653] Apache 'mod_authnz_external' Module SQL Injection Vulnerability
4182| [48611] Apache XML Security for C++ Signature Key Parsing Denial of Service Vulnerability
4183| [48456] Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability
4184| [48015] Apache Archiva Multiple Cross Site Request Forgery Vulnerabilities
4185| [48011] Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
4186| [47929] Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
4187| [47890] Apache Struts 'javatemplates' Plugin Multiple Cross Site Scripting Vulnerabilities
4188| [47886] Apache Tomcat SecurityConstraints Security Bypass Vulnerability
4189| [47820] Apache APR 'apr_fnmatch()' Denial of Service Vulnerability
4190| [47784] Apache Struts XWork 's:submit' HTML Tag Cross Site Scripting Vulnerability
4191| [47199] Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
4192| [47196] Apache Tomcat Login Constraints Security Bypass Vulnerability
4193| [46974] Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
4194| [46953] Apache MPM-ITK Module Security Weakness
4195| [46734] Subversion 'mod_dav_svn' Apache Server NULL Pointer Dereference Denial Of Service Vulnerability
4196| [46685] Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
4197| [46311] Apache Continuum and Archiva Cross Site Scripting Vulnerability
4198| [46177] Apache Tomcat SecurityManager Security Bypass Vulnerability
4199| [46174] Apache Tomcat HTML Manager Interface HTML Injection Vulnerability
4200| [46166] Apache Tomcat JVM Denial of Service Vulnerability
4201| [46164] Apache Tomcat NIO Connector Denial of Service Vulnerability
4202| [46066] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
4203| [45655] Apache Subversion Server Component Multiple Remote Denial Of Service Vulnerabilities
4204| [45123] Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Vulnerability
4205| [45095] Apache Archiva Cross Site Request Forgery Vulnerability
4206| [45015] Apache Tomcat 'sort' and 'orderBy' Parameters Cross Site Scripting Vulnerabilities
4207| [44900] Apache 'mod_fcgid' Module Unspecified Stack Buffer Overflow Vulnerability
4208| [44616] Apache Shiro Directory Traversal Vulnerability
4209| [44355] Apache MyFaces Encrypted View State Oracle Padding Security Vulnerability
4210| [44068] Apache::AuthenHook Local Information Disclosure Vulnerability
4211| [43862] Apache QPID SSL Connection Denial of Service Vulnerability
4212| [43673] Apache APR-util 'apr_brigade_split_line()' Denial of Service Vulnerability
4213| [43637] Apache XML-RPC SAX Parser Information Disclosure Vulnerability
4214| [43111] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
4215| [42637] Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
4216| [42501] Apache CouchDB Cross Site Request Forgery Vulnerability
4217| [42492] Apache CXF XML DTD Processing Security Vulnerability
4218| [42121] Apache SLMS Insufficient Quoting Cross Site Request Forgery Vulnerability
4219| [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
4220| [41963] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
4221| [41544] Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities
4222| [41076] Apache Axis2 '/axis2/axis2-admin' Session Fixation Vulnerability
4223| [40976] Apache Axis2 Document Type Declaration Processing Security Vulnerability
4224| [40827] Apache 'mod_proxy_http' Timeout Handling Information Disclosure Vulnerability
4225| [40343] Apache Axis2 'xsd' Parameter Directory Traversal Vulnerability
4226| [40327] Apache Axis2 'engagingglobally' Cross-Site Scripting Vulnerability
4227| [39771] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
4228| [39636] Apache ActiveMQ Source Code Information Disclosure Vulnerability
4229| [39635] Apache Tomcat Authentication Header Realm Name Information Disclosure Vulnerability
4230| [39538] Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
4231| [39489] Apache OFBiz Multiple Cross Site Scripting and HTML Injection Vulnerabilities
4232| [39119] Apache ActiveMQ 'createDestination.action' HTML Injection Vulnerability
4233| [38580] Apache Subrequest Handling Information Disclosure Vulnerability
4234| [38494] Apache 'mod_isapi' Memory Corruption Vulnerability
4235| [38491] Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
4236| [37966] Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability
4237| [37945] Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability
4238| [37944] Apache Tomcat WAR File Directory Traversal Vulnerability
4239| [37942] Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability
4240| [37149] Apache Tomcat 404 Error Page Cross Site Scripting Vulnerability
4241| [37027] RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
4242| [36990] Apache HTTP TRACE Cross Site Scripting Vulnerability
4243| [36954] Apache Tomcat Windows Installer Insecure Password Vulnerability
4244| [36889] TYPO3 Apache Solr Search Extension Unspecified Cross Site Scripting Vulnerability
4245| [36596] Apache HTTP Server Solaris Event Port Pollset Support Remote Denial Of Service Vulnerability
4246| [36260] Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
4247| [36254] Apache mod_proxy_ftp Remote Command Injection Vulnerability
4248| [35949] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
4249| [35840] Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
4250| [35623] Apache 'mod_deflate' Remote Denial Of Service Vulnerability
4251| [35565] Apache 'mod_proxy' Remote Denial Of Service Vulnerability
4252| [35416] Apache Tomcat XML Parser Information Disclosure Vulnerability
4253| [35263] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
4254| [35253] Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
4255| [35251] Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
4256| [35221] Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
4257| [35196] Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness
4258| [35193] Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability
4259| [35115] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
4260| [34686] Apache Struts Multiple Cross Site Scripting Vulnerabilities
4261| [34663] Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
4262| [34657] Apache Tiles Cross Site Scripting And Information Disclosure Vulnerabilities
4263| [34562] Apache Geronimo Application Server Multiple Remote Vulnerabilities
4264| [34552] Apache ActiveMQ Web Console Multiple Unspecified HTML Injection Vulnerabilities
4265| [34412] Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability
4266| [34399] Apache Struts Unspecified Cross Site Scripting Vulnerability
4267| [34383] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
4268| [33913] Apache Tomcat POST Data Information Disclosure Vulnerability
4269| [33360] Apache Jackrabbit 'q' Parameter Multiple Cross Site Scripting Vulnerabilities
4270| [33110] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
4271| [32657] Novell NetWare ApacheAdmin Security Bypass Vulnerability
4272| [31805] Apache HTTP Server OS Fingerprinting Unspecified Security Vulnerability
4273| [31761] Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
4274| [31698] Apache Tomcat 'RemoteFilterValve' Security Bypass Vulnerability
4275| [31165] Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
4276| [30560] Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability
4277| [30496] Apache Tomcat 'HttpServletResponse.sendError()' Cross Site Scripting Vulnerability
4278| [30494] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
4279| [29653] Apache 'mod_proxy_http' Interim Response Denial of Service Vulnerability
4280| [29502] Apache Tomcat Host Manager Cross Site Scripting Vulnerability
4281| [28576] Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
4282| [28484] Apache Tomcat Requests Containing MS-DOS Device Names Information Disclosure Vulnerability
4283| [28483] Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
4284| [28482] Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
4285| [28481] Apache Tomcat Cross-Site Scripting Vulnerability
4286| [28477] Apache Tomcat AJP Connector Information Disclosure Vulnerability
4287| [27752] Apache mod_jk2 Host Header Multiple Stack Based Buffer Overflow Vulnerabilities
4288| [27706] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
4289| [27703] Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
4290| [27409] Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
4291| [27365] Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
4292| [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
4293| [27236] Apache 'mod_proxy_balancer' Multiple Vulnerabilities
4294| [27234] Apache 'mod_proxy_ftp' Undefined Charset UTF-7 Cross-Site Scripting Vulnerability
4295| [27006] Apache Tomcat JULI Logging Component Default Security Policy Vulnerability
4296| [26939] Apache HTTP Server Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
4297| [26838] Apache mod_imagemap and mod_imap Cross-Site Scripting Vulnerability
4298| [26762] Apache::AuthCAS Cookie SQL Injection Vulnerability
4299| [26663] Apache HTTP Server 413 Error HTTP Request Method Cross-Site Scripting Weakness
4300| [26287] Apache Geronimo SQLLoginModule Authentication Bypass Vulnerability
4301| [26070] Apache Tomcat WebDav Remote Information Disclosure Vulnerability
4302| [25804] Apache Geronimo Management EJB Security Bypass Vulnerability
4303| [25653] Apache Mod_AutoIndex.C Undefined Charset Cross-Site Scripting Vulnerability
4304| [25531] Apache Tomcat Cal2.JSP Cross-Site Scripting Vulnerability
4305| [25489] Apache HTTP Server Mod_Proxy Denial of Service Vulnerability
4306| [25316] Apache Tomcat Multiple Remote Information Disclosure Vulnerabilities
4307| [25314] Apache Tomcat Host Manager Servlet Cross Site Scripting Vulnerability
4308| [25174] Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
4309| [24999] Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
4310| [24759] MySQLDumper Apache Access Control Authentication Bypass Vulnerability
4311| [24649] Apache HTTP Server Mod_Cache Denial of Service Vulnerability
4312| [24645] Apache HTTP Server Mod_Status Cross-Site Scripting Vulnerability
4313| [24553] Apache Mod_Mem_Cache Information Disclosure Vulnerability
4314| [24524] Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
4315| [24480] Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
4316| [24476] Apache Tomcat JSP Example Web Applications Cross Site Scripting Vulnerability
4317| [24475] Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
4318| [24215] Apache HTTP Server Worker Process Multiple Denial of Service Vulnerabilities
4319| [24147] Apache Tomcat JK Connector Double Encoding Security Bypass Vulnerability
4320| [24058] Apache Tomcat Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
4321| [23687] Apache AXIS Non-Existent WSDL Path Information Disclosure Vulnerability
4322| [23438] Apache HTTPD suEXEC Local Multiple Privilege Escalation Weaknesses
4323| [22960] Apache HTTP Server Tomcat Directory Traversal Vulnerability
4324| [22849] Apache mod_python Output Filter Mode Information Disclosure Vulnerability
4325| [22791] Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability
4326| [22732] Debian Apache Root Shell Local Privilege Escalation Vulnerabilities
4327| [22388] Apache Stats Extract Function Multiple Input Validation Vulnerabilities
4328| [21865] Apache And Microsoft IIS Range Denial of Service Vulnerability
4329| [21214] Apache Mod_Auth_Kerb Off-By-One Denial of Service Vulnerability
4330| [20527] Apache Mod_TCL Remote Format String Vulnerability
4331| [19661] Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
4332| [19447] Apache CGI Script Source Code Information Disclosure Vulnerability
4333| [19204] Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
4334| [19106] Apache Tomcat Information Disclosure Vulnerability
4335| [18138] Apache James SMTP Denial Of Service Vulnerability
4336| [17342] Apache Struts Multiple Remote Vulnerabilities
4337| [17095] Apache Log4Net Denial Of Service Vulnerability
4338| [16916] Apache mod_python FileSession Code Execution Vulnerability
4339| [16710] Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
4340| [16260] Apache Geronimo Multiple Input Validation Vulnerabilities
4341| [16153] Apache mod_auth_pgsql Multiple Format String Vulnerabilities
4342| [16152] Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
4343| [15834] Apache 'mod_imap' Referer Cross-Site Scripting Vulnerability
4344| [15765] Apache James Spooler Memory Leak Denial Of Service Vulnerability
4345| [15762] Apache MPM Worker.C Denial Of Service Vulnerability
4346| [15512] Apache Struts Error Response Cross-Site Scripting Vulnerability
4347| [15413] PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
4348| [15325] Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
4349| [15224] Apache Mod_Auth_Shadow Authentication Bypass Vulnerability
4350| [15177] PHP Apache 2 Local Denial of Service Vulnerability
4351| [14982] ApacheTop Insecure Temporary File Creation Vulnerability
4352| [14721] Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
4353| [14660] Apache CGI Byterange Request Denial of Service Vulnerability
4354| [14366] Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
4355| [14106] Apache HTTP Request Smuggling Vulnerability
4356| [13778] Apache HTPasswd Password Command Line Argument Buffer Overflow Vulnerability
4357| [13777] Apache HTPasswd User Command Line Argument Buffer Overflow Vulnerability
4358| [13756] Apache Tomcat Java Security Manager Bypass Vulnerability
4359| [13537] Apache HTDigest Realm Command Line Argument Buffer Overflow Vulnerability
4360| [12877] Apache mod_ssl ssl_io_filter_cleanup Remote Denial Of Service Vulnerability
4361| [12795] Apache Tomcat Remote Malformed Request Denial Of Service Vulnerability
4362| [12619] Apache Software Foundation Batik Squiggle Browser Access Validation Vulnerability
4363| [12519] Apache mod_python Module Publisher Handler Information Disclosure Vulnerability
4364| [12308] Apache Utilities Insecure Temporary File Creation Vulnerability
4365| [12217] Apache mod_auth_radius Malformed RADIUS Server Reply Integer Overflow Vulnerability
4366| [12181] Mod_DOSEvasive Apache Module Local Insecure Temporary File Creation Vulnerability
4367| [11803] Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
4368| [11471] Apache mod_include Local Buffer Overflow Vulnerability
4369| [11360] Apache mod_ssl SSLCipherSuite Restriction Bypass Vulnerability
4370| [11239] Apache Satisfy Directive Access Control Bypass Vulnerability
4371| [11187] Apache Web Server Remote IPv6 Buffer Overflow Vulnerability
4372| [11185] Apache Mod_DAV LOCK Denial Of Service Vulnerability
4373| [11182] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
4374| [11154] Apache mod_ssl Remote Denial of Service Vulnerability
4375| [11094] Apache mod_ssl Denial Of Service Vulnerability
4376| [10789] Apache mod_userdir Module Information Disclosure Vulnerability
4377| [10736] Apache 'mod_ssl' Log Function Format String Vulnerability
4378| [10619] Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
4379| [10508] Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow Vulnerability
4380| [10478] ClueCentral Apache Suexec Patch Security Weakness
4381| [10355] Apache 'mod_ssl' 'ssl_util_uuencode_binary()' Stack Buffer Overflow Vulnerability
4382| [10212] Apache mod_auth Malformed Password Potential Memory Corruption Vulnerability
4383| [9933] Apache mod_disk_cache Module Client Authentication Credential Storage Weakness
4384| [9930] Apache Error and Access Logs Escape Sequence Injection Vulnerability
4385| [9921] Apache Connection Blocking Denial Of Service Vulnerability
4386| [9885] Apache Mod_Security Module SecFilterScanPost Off-By-One Buffer Overflow Vulnerability
4387| [9874] Apache HTAccess LIMIT Directive Bypass Configuration Error Weakness
4388| [9829] Apache Mod_Access Access Control Rule Bypass Vulnerability
4389| [9826] Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
4390| [9733] Apache Cygwin Directory Traversal Vulnerability
4391| [9599] Apache mod_php Global Variables Information Disclosure Weakness
4392| [9590] Apache-SSL Client Certificate Forging Vulnerability
4393| [9571] Apache mod_digest Client-Supplied Nonce Verification Vulnerability
4394| [9471] Apache mod_perl Module File Descriptor Leakage Vulnerability
4395| [9404] Mod-Auth-Shadow Apache Module Expired User Credential Weakness
4396| [9302] Apache mod_php Module File Descriptor Leakage Vulnerability
4397| [9129] Apache mod_python Module Malformed Query Denial of Service Vulnerability
4398| [8926] Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
4399| [8919] Apache Mod_Security Module Heap Corruption Vulnerability
4400| [8911] Apache Web Server Multiple Module Local Buffer Overflow Vulnerability
4401| [8898] Red Hat Apache Directory Index Default Configuration Error
4402| [8883] Apache Cocoon Directory Traversal Vulnerability
4403| [8824] Apache Tomcat Non-HTTP Request Denial Of Service Vulnerability
4404| [8822] Apache Mod_Throttle Module Local Shared Memory Corruption Vulnerability
4405| [8725] Apache2 MOD_CGI STDERR Denial Of Service Vulnerability
4406| [8707] Apache htpasswd Password Entropy Weakness
4407| [8561] Apache::Gallery Insecure Local File Storage Privilege Escalation Vulnerability
4408| [8287] Mod_Mylo Apache Module REQSTR Buffer Overflow Vulnerability
4409| [8226] Apache HTTP Server Multiple Vulnerabilities
4410| [8138] Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
4411| [8137] Apache Web Server Prefork MPM Denial Of Service Vulnerability
4412| [8136] Macromedia Apache Web Server Encoded Space Source Disclosure Vulnerability
4413| [8135] Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
4414| [8134] Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness
4415| [7768] Apache Tomcat Insecure Directory Permissions Vulnerability
4416| [7725] Apache Basic Authentication Module Valid User Login Denial Of Service Vulnerability
4417| [7723] Apache APR_PSPrintf Memory Corruption Vulnerability
4418| [7448] Apache Mod_Auth_Any Remote Command Execution Vulnerability
4419| [7375] Apache Mod_Access_Referer NULL Pointer Dereference Denial of Service Vulnerability
4420| [7332] Apache Web Server OS2 Filestat Denial Of Service Vulnerability
4421| [7255] Apache Web Server File Descriptor Leakage Vulnerability
4422| [7254] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
4423| [6943] Apache Web Server MIME Boundary Information Disclosure Vulnerability
4424| [6939] Apache Web Server ETag Header Information Disclosure Weakness
4425| [6722] Apache Tomcat Web.XML File Contents Disclosure Vulnerability
4426| [6721] Apache Tomcat Null Byte Directory/File Disclosure Vulnerability
4427| [6720] Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
4428| [6662] Apache Web Server MS-DOS Device Name Denial Of Service Vulnerability
4429| [6661] Apache Web Server Default Script Mapping Bypass Vulnerability
4430| [6660] Apache Web Server Illegal Character HTTP Request File Disclosure Vulnerability
4431| [6659] Apache Web Server MS-DOS Device Name Arbitrary Code Execution Vulnerability
4432| [6562] Apache Tomcat Invoker Servlet File Disclosure Vulnerability
4433| [6320] Apache/Tomcat Mod_JK Chunked Encoding Denial Of Service Vulnerability
4434| [6117] Apache mod_php File Descriptor Leakage Vulnerability
4435| [6065] Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
4436| [5996] Apache AB.C Web Benchmarking Buffer Overflow Vulnerability
4437| [5995] Apache AB.C Web Benchmarking Read_Connection() Buffer Overflow Vulnerability
4438| [5993] Multiple Apache HTDigest Buffer Overflow Vulnerabilities
4439| [5992] Apache HTDigest Insecure Temporary File Vulnerability
4440| [5991] Apache HTDigest Arbitrary Command Execution Vulnerability
4441| [5990] Apache HTPasswd Insecure Temporary File Vulnerability
4442| [5981] Multiple Apache HTDigest and HTPassWD Component Vulnerabilites
4443| [5884] Apache Web Server Scoreboard Memory Segment Overwriting SIGUSR1 Sending Vulnerability
4444| [5847] Apache Server Side Include Cross Site Scripting Vulnerability
4445| [5838] Apache Tomcat 3.2 Directory Disclosure Vulnerability
4446| [5816] Apache 2 mod_dav Denial Of Service Vulnerability
4447| [5791] HP VirtualVault Apache mod_ssl Denial Of Service Vulnerability
4448| [5787] Apache Oversized STDERR Buffer Denial Of Service Vulnerability
4449| [5786] Apache Tomcat DefaultServlet File Disclosure Vulnerability
4450| [5542] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
4451| [5486] Apache 2.0 CGI Path Disclosure Vulnerability
4452| [5485] Apache 2.0 Path Disclosure Vulnerability
4453| [5434] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
4454| [5256] Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
4455| [5194] Apache Tomcat DOS Device Name Cross Site Scripting Vulnerability
4456| [5193] Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
4457| [5067] Apache Tomcat Null Character Malformed Request Denial Of Service Vulnerability
4458| [5054] Apache Tomcat Web Root Path Disclosure Vulnerability
4459| [5033] Apache Chunked-Encoding Memory Corruption Vulnerability
4460| [4995] Apache Tomcat JSP Engine Denial of Service Vulnerability
4461| [4878] Apache Tomcat RealPath.JSP Malformed Request Information Disclosure Vulnerability
4462| [4877] Apache Tomcat Example Files Web Root Path Disclosure Vulnerability
4463| [4876] Apache Tomcat Source.JSP Malformed Request Information Disclosure Vulnerability
4464| [4575] Apache Tomcat Servlet Path Disclosure Vulnerability
4465| [4557] Apache Tomcat System Path Information Disclosure Vulnerability
4466| [4437] Apache Error Message Cross-Site Scripting Vulnerability
4467| [4431] Apache PrintEnv/Test_CGI Script Injection Vulnerability
4468| [4358] Apache Double-Reverse Lookup Log Entry Spoofing Vulnerability
4469| [4335] Apache Win32 Batch File Remote Command Execution Vulnerability
4470| [4292] Oracle 9iAS Apache PL/SQL Module Web Administration Access Vulnerability
4471| [4189] Apache mod_ssl/Apache-SSL Buffer Overflow Vulnerability
4472| [4057] Apache 2 for Windows OPTIONS request Path Disclosure Vulnerability
4473| [4056] Apache 2 for Windows php.exe Path Disclosure Vulnerability
4474| [4037] Oracle 9iAS Apache PL/SQL Module Denial of Service Vulnerability
4475| [4032] Oracle 9iAS Apache PL/SQL Module Multiple Buffer Overflows Vulnerability
4476| [3796] Apache HTTP Request Unexpected Behavior Vulnerability
4477| [3790] Apache Non-Existent Log Directory Denial Of Service Vulnerability
4478| [3786] Apache Win32 PHP.EXE Remote File Disclosure Vulnerability
4479| [3727] Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
4480| [3726] Oracle 9I Application Server PL/SQL Apache Module Buffer Overflow Vulnerability
4481| [3596] Apache Split-Logfile File Append Vulnerability
4482| [3521] Apache mod_usertrack Predictable ID Generation Vulnerability
4483| [3335] Red Hat Linux Apache Remote Username Enumeration Vulnerability
4484| [3316] MacOS X Client Apache Directory Contents Disclosure Vulnerability
4485| [3256] Apache mod_auth_oracle Remote SQL Query Manipulation Vulnerability
4486| [3255] Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
4487| [3254] Apache AuthPG Remote SQL Query Manipulation Vulnerability
4488| [3253] Apache mod_auth_pgsql_sys Remote SQL Query Manipulation Vulnerability
4489| [3251] Apache mod_auth_pgsql Remote SQL Query Manipulation Vulnerability
4490| [3176] Apache Mod ReWrite Rules Bypassing Image Linking Vulnerability
4491| [3169] Apache Server Address Disclosure Vulnerability
4492| [3009] Apache Possible Directory Index Disclosure Vulnerability
4493| [2982] Apache Tomcat Cross-Site Scripting Vulnerability
4494| [2852] MacOS X Client Apache File Protection Bypass Vulnerability
4495| [2740] Apache Web Server HTTP Request Denial of Service Vulnerability
4496| [2518] Apache Tomcat 3.0 Directory Traversal Vulnerability
4497| [2503] Apache Artificially Long Slash Path Directory Listing Vulnerability
4498| [2300] NCSA/Apache httpd ScriptAlias Source Retrieval Vulnerability
4499| [2216] Apache Web Server DoS Vulnerability
4500| [2182] Apache /tmp File Race Vulnerability
4501| [2171] Oracle Apache+WebDB Documented Backdoor Vulnerability
4502| [2060] Apache Web Server with Php 3 File Disclosure Vulnerability
4503| [1821] Apache mod_cookies Buffer Overflow Vulnerability
4504| [1728] Apache Rewrite Module Arbitrary File Disclosure Vulnerability
4505| [1658] SuSE Apache CGI Source Code Viewing Vulnerability
4506| [1656] SuSE Apache WebDAV Directory Listings Vulnerability
4507| [1575] Trustix Apache-SSL RPM Permissions Vulnerability
4508| [1548] Apache Jakarta-Tomcat /admin Context Vulnerability
4509| [1532] Apache Tomcat Snoop Servlet Information Disclosure Vulnerability
4510| [1531] Apache Tomcat 3.1 Path Revealing Vulnerability
4511| [1457] Apache::ASP source.asp Example Script Vulnerability
4512| [1284] Apache HTTP Server (win32) Root Directory Access Vulnerability
4513| [1083] Cobalt Raq Apache .htaccess Disclosure Vulnerability
4514|
4515| IBM X-Force - https://exchange.xforce.ibmcloud.com:
4516| [86258] Apache CloudStack text fields cross-site scripting
4517| [85983] Apache Subversion mod_dav_svn module denial of service
4518| [85875] Apache OFBiz UEL code execution
4519| [85874] Apache OFBiz Webtools View Log screen cross-site scripting
4520| [85871] Apache HTTP Server mod_session_dbd unspecified
4521| [85756] Apache Struts OGNL expression command execution
4522| [85755] Apache Struts DefaultActionMapper class open redirect
4523| [85586] Apache ActiveMQ CVE-2013-1879 cross-site scripting
4524| [85574] Apache HTTP Server mod_dav denial of service
4525| [85573] Apache Struts Showcase App OGNL code execution
4526| [85496] Apache CXF denial of service
4527| [85423] Apache Geronimo RMI classloader code execution
4528| [85326] Apache Santuario XML Security for C++ buffer overflow
4529| [85323] Apache Santuario XML Security for Java spoofing
4530| [85319] Apache Qpid Python client SSL spoofing
4531| [85019] Apache Santuario XML Security for C++ CVE-2013-2156 buffer overflow
4532| [85018] Apache Santuario XML Security for C++ CVE-2013-2155 denial of service
4533| [85017] Apache Santuario XML Security for C++ CVE-2013-2154 buffer overflow
4534| [85016] Apache Santuario XML Security for C++ CVE-2013-2153 spoofing
4535| [84952] Apache Tomcat CVE-2012-3544 denial of service
4536| [84763] Apache Struts CVE-2013-2135 security bypass
4537| [84762] Apache Struts CVE-2013-2134 security bypass
4538| [84719] Apache Subversion CVE-2013-2088 command execution
4539| [84718] Apache Subversion CVE-2013-2112 denial of service
4540| [84717] Apache Subversion CVE-2013-1968 denial of service
4541| [84577] Apache Tomcat security bypass
4542| [84576] Apache Tomcat symlink
4543| [84543] Apache Struts CVE-2013-2115 security bypass
4544| [84542] Apache Struts CVE-2013-1966 security bypass
4545| [84154] Apache Tomcat session hijacking
4546| [84144] Apache Tomcat denial of service
4547| [84143] Apache Tomcat information disclosure
4548| [84111] Apache HTTP Server command execution
4549| [84043] Apache Virtual Computing Lab cross-site scripting
4550| [84042] Apache Virtual Computing Lab cross-site scripting
4551| [83782] Apache CloudStack information disclosure
4552| [83781] Apache CloudStack security bypass
4553| [83720] Apache ActiveMQ cross-site scripting
4554| [83719] Apache ActiveMQ denial of service
4555| [83718] Apache ActiveMQ denial of service
4556| [83263] Apache Subversion denial of service
4557| [83262] Apache Subversion denial of service
4558| [83261] Apache Subversion denial of service
4559| [83259] Apache Subversion denial of service
4560| [83035] Apache mod_ruid2 security bypass
4561| [82852] Apache Qpid federation_tag security bypass
4562| [82851] Apache Qpid qpid::framing::Buffer denial of service
4563| [82758] Apache Rave User RPC API information disclosure
4564| [82663] Apache Subversion svn_fs_file_length() denial of service
4565| [82642] Apache Qpid qpid::framing::Buffer::checkAvailable() denial of service
4566| [82641] Apache Qpid AMQP denial of service
4567| [82626] Apache HTTP Server on Debian GNU/Linux Debian apache2ctl symlink
4568| [82618] Apache Commons FileUpload symlink
4569| [82360] Apache HTTP Server manager interface cross-site scripting
4570| [82359] Apache HTTP Server hostnames cross-site scripting
4571| [82338] Apache Tomcat log/logdir information disclosure
4572| [82328] Apache Maven and Apache Maven Wagon SSL spoofing
4573| [82268] Apache OpenJPA deserialization command execution
4574| [81981] Apache CXF UsernameTokens security bypass
4575| [81980] Apache CXF WS-Security security bypass
4576| [81398] Apache OFBiz cross-site scripting
4577| [81240] Apache CouchDB directory traversal
4578| [81226] Apache CouchDB JSONP code execution
4579| [81225] Apache CouchDB Futon user interface cross-site scripting
4580| [81211] Apache Axis2/C SSL spoofing
4581| [81167] Apache CloudStack DeployVM information disclosure
4582| [81166] Apache CloudStack AddHost API information disclosure
4583| [81165] Apache CloudStack createSSHKeyPair API information disclosure
4584| [80518] Apache Tomcat cross-site request forgery security bypass
4585| [80517] Apache Tomcat FormAuthenticator security bypass
4586| [80516] Apache Tomcat NIO denial of service
4587| [80408] Apache Tomcat replay-countermeasure security bypass
4588| [80407] Apache Tomcat HTTP Digest Access Authentication security bypass
4589| [80317] Apache Tomcat slowloris denial of service
4590| [79984] Apache Commons HttpClient SSL spoofing
4591| [79983] Apache CXF SSL spoofing
4592| [79830] Apache Axis2/Java SSL spoofing
4593| [79829] Apache Axis SSL spoofing
4594| [79809] Apache Tomcat DIGEST security bypass
4595| [79806] Apache Tomcat parseHeaders() denial of service
4596| [79540] Apache OFBiz unspecified
4597| [79487] Apache Axis2 SAML security bypass
4598| [79212] Apache Cloudstack code execution
4599| [78734] Apache CXF SOAP Action security bypass
4600| [78730] Apache Qpid broker denial of service
4601| [78617] Eucalyptus Apache Santuario (XML Security for Java) denial of service
4602| [78563] Apache mod_pagespeed module unspecified cross-site scripting
4603| [78562] Apache mod_pagespeed module security bypass
4604| [78454] Apache Axis2 security bypass
4605| [78452] Websense Web Security and Web Filter Apache Tomcat information disclosure
4606| [78451] Websense Web Security and Web Filter Apache Tomcat cross-site scripting
4607| [78321] Apache Wicket unspecified cross-site scripting
4608| [78183] Apache Struts parameters denial of service
4609| [78182] Apache Struts cross-site request forgery
4610| [78153] Apache Solr Autocomplete module for Drupal autocomplete results cross-site scripting
4611| [77987] mod_rpaf module for Apache denial of service
4612| [77958] Apache Struts skill name code execution
4613| [77914] Apache HTTP Server mod_negotiation module cross-site scripting
4614| [77913] Apache HTTP Server mod_proxy_ajp information disclosure
4615| [77568] Apache Qpid broker security bypass
4616| [77421] Apache Libcloud spoofing
4617| [77059] Oracle Solaris Cluster Apache Tomcat Agent unspecified
4618| [77046] Oracle Solaris Apache HTTP Server information disclosure
4619| [76837] Apache Hadoop information disclosure
4620| [76802] Apache Sling CopyFrom denial of service
4621| [76692] Apache Hadoop symlink
4622| [76535] Apache Roller console cross-site request forgery
4623| [76534] Apache Roller weblog cross-site scripting
4624| [76152] Apache CXF elements security bypass
4625| [76151] Apache CXF child policies security bypass
4626| [75983] MapServer for Windows Apache file include
4627| [75857] Apache Commons Compress and Apache Ant bzip2 denial of service
4628| [75558] Apache POI denial of service
4629| [75545] PHP apache_request_headers() buffer overflow
4630| [75302] Apache Qpid SASL security bypass
4631| [75211] Debian GNU/Linux apache 2 cross-site scripting
4632| [74901] Apache HTTP Server LD_LIBRARY_PATH privilege escalation
4633| [74871] Apache OFBiz FlexibleStringExpander code execution
4634| [74870] Apache OFBiz multiple cross-site scripting
4635| [74750] Apache Hadoop unspecified spoofing
4636| [74319] Apache Struts XSLTResult.java file upload
4637| [74313] Apache Traffic Server header buffer overflow
4638| [74276] Apache Wicket directory traversal
4639| [74273] Apache Wicket unspecified cross-site scripting
4640| [74181] Apache HTTP Server mod_fcgid module denial of service
4641| [73690] Apache Struts OGNL code execution
4642| [73432] Apache Solr extension for TYPO3 unspecified cross-site scripting
4643| [73100] Apache MyFaces in directory traversal
4644| [73096] Apache APR hash denial of service
4645| [73052] Apache Struts name cross-site scripting
4646| [73030] Apache CXF UsernameToken security bypass
4647| [72888] Apache Struts lastName cross-site scripting
4648| [72758] Apache HTTP Server httpOnly information disclosure
4649| [72757] Apache HTTP Server MPM denial of service
4650| [72585] Apache Struts ParameterInterceptor security bypass
4651| [72438] Apache Tomcat Digest security bypass
4652| [72437] Apache Tomcat Digest security bypass
4653| [72436] Apache Tomcat DIGEST security bypass
4654| [72425] Apache Tomcat parameter denial of service
4655| [72422] Apache Tomcat request object information disclosure
4656| [72377] Apache HTTP Server scoreboard security bypass
4657| [72345] Apache HTTP Server HTTP request denial of service
4658| [72229] Apache Struts ExceptionDelegator command execution
4659| [72089] Apache Struts ParameterInterceptor directory traversal
4660| [72088] Apache Struts CookieInterceptor command execution
4661| [72047] Apache Geronimo hash denial of service
4662| [72016] Apache Tomcat hash denial of service
4663| [71711] Apache Struts OGNL expression code execution
4664| [71654] Apache Struts interfaces security bypass
4665| [71620] Apache ActiveMQ failover denial of service
4666| [71617] Apache HTTP Server mod_proxy module information disclosure
4667| [71508] Apache MyFaces EL security bypass
4668| [71445] Apache HTTP Server mod_proxy security bypass
4669| [71203] Apache Tomcat servlets privilege escalation
4670| [71181] Apache HTTP Server ap_pregsub() denial of service
4671| [71093] Apache HTTP Server ap_pregsub() buffer overflow
4672| [70336] Apache HTTP Server mod_proxy information disclosure
4673| [69804] Apache HTTP Server mod_proxy_ajp denial of service
4674| [69472] Apache Tomcat AJP security bypass
4675| [69396] Apache HTTP Server ByteRange filter denial of service
4676| [69394] Apache Wicket multi window support cross-site scripting
4677| [69176] Apache Tomcat XML information disclosure
4678| [69161] Apache Tomcat jsvc information disclosure
4679| [68799] mod_authnz_external module for Apache mysql-auth.pl SQL injection
4680| [68541] Apache Tomcat sendfile information disclosure
4681| [68420] Apache XML Security denial of service
4682| [68238] Apache Tomcat JMX information disclosure
4683| [67860] Apache Rampart/C rampart_timestamp_token_validate security bypass
4684| [67804] Apache Subversion control rules information disclosure
4685| [67803] Apache Subversion control rules denial of service
4686| [67802] Apache Subversion baselined denial of service
4687| [67672] Apache Archiva multiple cross-site scripting
4688| [67671] Apache Archiva multiple cross-site request forgery
4689| [67564] Apache APR apr_fnmatch() denial of service
4690| [67532] IBM WebSphere Application Server org.apache.jasper.runtime.JspWriterImpl.response denial of service
4691| [67515] Apache Tomcat annotations security bypass
4692| [67480] Apache Struts s:submit information disclosure
4693| [67414] Apache APR apr_fnmatch() denial of service
4694| [67356] Apache Struts javatemplates cross-site scripting
4695| [67354] Apache Struts Xwork cross-site scripting
4696| [66676] Apache Tomcat HTTP BIO information disclosure
4697| [66675] Apache Tomcat web.xml security bypass
4698| [66640] Apache HttpComponents HttpClient Proxy-Authorization information disclosure
4699| [66241] Apache HttpComponents information disclosure
4700| [66154] Apache Tomcat ServletSecurity security bypass
4701| [65971] Apache Tomcat ServletSecurity security bypass
4702| [65876] Apache Subversion mod_dav_svn denial of service
4703| [65343] Apache Continuum unspecified cross-site scripting
4704| [65162] Apache Tomcat NIO connector denial of service
4705| [65161] Apache Tomcat javax.servlet.ServletRequest.getLocale() denial of service
4706| [65160] Apache Tomcat HTML Manager interface cross-site scripting
4707| [65159] Apache Tomcat ServletContect security bypass
4708| [65050] Apache CouchDB web-based administration UI cross-site scripting
4709| [64773] Oracle HTTP Server Apache Plugin unauthorized access
4710| [64473] Apache Subversion blame -g denial of service
4711| [64472] Apache Subversion walk() denial of service
4712| [64407] Apache Axis2 CVE-2010-0219 code execution
4713| [63926] Apache Archiva password privilege escalation
4714| [63785] Apache CouchDB LD_LIBRARY_PATH privilege escalation
4715| [63493] Apache Archiva credentials cross-site request forgery
4716| [63477] Apache Tomcat HttpOnly session hijacking
4717| [63422] Apache Tomcat sessionsList.jsp cross-site scripting
4718| [63303] Apache mod_fcgid module fcgid_header_bucket_read() buffer overflow
4719| [62959] Apache Shiro filters security bypass
4720| [62790] Apache Perl cgi module denial of service
4721| [62576] Apache Qpid exchange denial of service
4722| [62575] Apache Qpid AMQP denial of service
4723| [62354] Apache Qpid SSL denial of service
4724| [62235] Apache APR-util apr_brigade_split_line() denial of service
4725| [62181] Apache XML-RPC SAX Parser information disclosure
4726| [61721] Apache Traffic Server cache poisoning
4727| [61202] Apache Derby BUILTIN authentication functionality information disclosure
4728| [61186] Apache CouchDB Futon cross-site request forgery
4729| [61169] Apache CXF DTD denial of service
4730| [61070] Apache Jackrabbit search.jsp SQL injection
4731| [61006] Apache SLMS Quoting cross-site request forgery
4732| [60962] Apache Tomcat time cross-site scripting
4733| [60883] Apache mod_proxy_http information disclosure
4734| [60671] Apache HTTP Server mod_cache and mod_dav denial of service
4735| [60264] Apache Tomcat Transfer-Encoding denial of service
4736| [59746] Apache Axis2 axis2/axis2-admin page session hijacking
4737| [59588] Apache Axis2/Java XML DTD (Document Type Declaration) data denial of service
4738| [59413] Apache mod_proxy_http timeout information disclosure
4739| [59058] Apache MyFaces unencrypted view state cross-site scripting
4740| [58827] Apache Axis2 xsd file include
4741| [58790] Apache Axis2 modules cross-site scripting
4742| [58299] Apache ActiveMQ queueBrowse cross-site scripting
4743| [58169] Apache Tomcat Web Application Manager / Host Manager cross-site request forgery
4744| [58056] Apache ActiveMQ .jsp source code disclosure
4745| [58055] Apache Tomcat realm name information disclosure
4746| [58046] Apache HTTP Server mod_auth_shadow security bypass
4747| [57841] Apache Open For Business Project (OFBiz) subject cross-site scripting
4748| [57840] Apache Open For Business Project (OFBiz) multiple parameters cross-site scripting
4749| [57429] Apache CouchDB algorithms information disclosure
4750| [57398] Apache ActiveMQ Web console cross-site request forgery
4751| [57397] Apache ActiveMQ createDestination.action cross-site scripting
4752| [56653] Apache HTTP Server DNS spoofing
4753| [56652] Apache HTTP Server DNS cross-site scripting
4754| [56625] Apache HTTP Server request header information disclosure
4755| [56624] Apache HTTP Server mod_isapi orphaned callback pointer code execution
4756| [56623] Apache HTTP Server mod_proxy_ajp denial of service
4757| [55941] mod_proxy module for Apache ap_proxy_send_fb() buffer overflow
4758| [55857] Apache Tomcat WAR files directory traversal
4759| [55856] Apache Tomcat autoDeploy attribute security bypass
4760| [55855] Apache Tomcat WAR directory traversal
4761| [55210] Intuit component for Joomla! Apache information disclosure
4762| [54533] Apache Tomcat 404 error page cross-site scripting
4763| [54182] Apache Tomcat admin default password
4764| [53878] Apache Solr Search (solr) extension for TYPO3 unspecified cross-site scripting
4765| [53666] Apache HTTP Server Solaris pollset support denial of service
4766| [53650] Apache HTTP Server HTTP basic-auth module security bypass
4767| [53124] mod_proxy_ftp module for Apache HTTP header security bypass
4768| [53041] mod_proxy_ftp module for Apache denial of service
4769| [52540] Apache Portable Runtime and Apache Portable Utility library multiple buffer overflow
4770| [51953] Apache Tomcat Path Disclosure
4771| [51952] Apache Tomcat Path Traversal
4772| [51951] Apache stronghold-status Information Disclosure
4773| [51950] Apache stronghold-info Information Disclosure
4774| [51949] Apache PHP Source Code Disclosure
4775| [51948] Apache Multiviews Attack
4776| [51946] Apache JServ Environment Status Information Disclosure
4777| [51945] Apache error_log Information Disclosure
4778| [51944] Apache Default Installation Page Pattern Found
4779| [51943] Apache AXIS XML Parser echoheaders.jws Sample Web Service Denial of Service
4780| [51942] Apache AXIS XML External Entity File Retrieval
4781| [51941] Apache AXIS Sample Servlet Information Leak
4782| [51940] Apache access_log Information Disclosure
4783| [51626] Apache mod_deflate denial of service
4784| [51532] mod_proxy module for the Apache HTTP Server stream_reqbody_cl denial of service
4785| [51365] Apache Tomcat RequestDispatcher security bypass
4786| [51273] Apache HTTP Server Incomplete Request denial of service
4787| [51195] Apache Tomcat XML information disclosure
4788| [50994] Apache APR-util xml/apr_xml.c denial of service
4789| [50993] Apache APR-util apr_brigade_vprintf denial of service
4790| [50964] Apache APR-util apr_strmatch_precompile() denial of service
4791| [50930] Apache Tomcat j_security_check information disclosure
4792| [50928] Apache Tomcat AJP denial of service
4793| [50884] Apache HTTP Server XML ENTITY denial of service
4794| [50808] Apache HTTP Server AllowOverride privilege escalation
4795| [50108] Apache Struts s:a tag and s:url tag cross-site scripting
4796| [50059] Apache mod_proxy_ajp information disclosure
4797| [49951] Apache Tiles Expression Language (EL) expressions cross-site scripting
4798| [49925] Apache Geronimo Web Administrative Console cross-site request forgery
4799| [49924] Apache Geronimo console/portal/Server/Monitoring cross-site scripting
4800| [49921] Apache ActiveMQ Web interface cross-site scripting
4801| [49898] Apache Geronimo Services/Repository directory traversal
4802| [49725] Apache Tomcat mod_jk module information disclosure
4803| [49715] Apache mod_perl Apache::Status and Apache2::Status modules cross-site scripting
4804| [49712] Apache Struts unspecified cross-site scripting
4805| [49213] Apache Tomcat cal2.jsp cross-site scripting
4806| [48934] Apache Tomcat POST doRead method information disclosure
4807| [48211] Apache Tomcat header HTTP request smuggling
4808| [48163] libapache2-mod-auth-mysql module for Debian multibyte encoding SQL injection
4809| [48110] Apache Jackrabbit search.jsp and swr.jsp cross-site scripting
4810| [47709] Apache Roller "
4811| [47104] Novell Netware ApacheAdmin console security bypass
4812| [47086] Apache HTTP Server OS fingerprinting unspecified
4813| [46329] Apache Struts FilterDispatcher and DefaultStaticContentLoader class directory traversal
4814| [45791] Apache Tomcat RemoteFilterValve security bypass
4815| [44435] Oracle WebLogic Apache Connector buffer overflow
4816| [44411] Apache Tomcat allowLinking UTF-8 directory traversal
4817| [44223] Apache HTTP Server mod_proxy_ftp cross-site scripting
4818| [44156] Apache Tomcat RequestDispatcher directory traversal
4819| [44155] Apache Tomcat HttpServletResponse.sendError() cross-site scripting
4820| [43885] Oracle WebLogic Server Apache Connector buffer overflow
4821| [42987] Apache HTTP Server mod_proxy module denial of service
4822| [42915] Apache Tomcat JSP files path disclosure
4823| [42914] Apache Tomcat MS-DOS path disclosure
4824| [42892] Apache Tomcat unspecified unauthorized access
4825| [42816] Apache Tomcat Host Manager cross-site scripting
4826| [42303] Apache 403 error cross-site scripting
4827| [41618] Apache-SSL ExpandCert() authentication bypass
4828| [40761] Apache Derby RDBNAM parameter and DatabaseMetaData.getURL information disclosure
4829| [40736] Apache Tomcat HTTP/1.1 connector information disclosure
4830| [40614] Apache mod_jk2 HTTP Host header buffer overflow
4831| [40562] Apache Geronimo init information disclosure
4832| [40478] Novell Web Manager webadmin-apache.conf security bypass
4833| [40411] Apache Tomcat exception handling information disclosure
4834| [40409] Apache Tomcat native (APR based) connector weak security
4835| [40403] Apache Tomcat quotes and %5C cookie information disclosure
4836| [40388] Sun Java Plug-In org.apache.crimson.tree.XmlDocument security bypass
4837| [39893] Apache HTTP Server mod_negotiation HTTP response splitting
4838| [39867] Apache HTTP Server mod_negotiation cross-site scripting
4839| [39804] Apache Tomcat SingleSignOn information disclosure
4840| [39615] Apache HTTP Server mod_proxy_ftp.c UTF-7 cross-site scripting
4841| [39612] Apache HTTP Server mod_proxy_balancer buffer overflow
4842| [39608] Apache HTTP Server balancer manager cross-site request forgery
4843| [39476] Apache mod_proxy_balancer balancer_handler function denial of service
4844| [39474] Apache HTTP Server mod_proxy_balancer cross-site scripting
4845| [39472] Apache HTTP Server mod_status cross-site scripting
4846| [39201] Apache Tomcat JULI logging weak security
4847| [39158] Apache HTTP Server Windows SMB shares information disclosure
4848| [39001] Apache HTTP Server mod_imap and mod_imagemap module cross-site scripting
4849| [38951] Apache::AuthCAS Perl module cookie SQL injection
4850| [38800] Apache HTTP Server 413 error page cross-site scripting
4851| [38211] Apache Geronimo SQLLoginModule authentication bypass
4852| [37243] Apache Tomcat WebDAV directory traversal
4853| [37178] RHSA update for Apache HTTP Server mod_status module cross-site scripting not installed
4854| [37177] RHSA update for Apache HTTP Server Apache child process denial of service not installed
4855| [37119] RHSA update for Apache mod_auth_kerb off-by-one buffer overflow not installed
4856| [37100] RHSA update for Apache and IBM HTTP Server Expect header cross-site scripting not installed
4857| [36782] Apache Geronimo MEJB unauthorized access
4858| [36586] Apache HTTP Server UTF-7 cross-site scripting
4859| [36468] Apache Geronimo LoginModule security bypass
4860| [36467] Apache Tomcat functions.jsp cross-site scripting
4861| [36402] Apache Tomcat calendar cross-site request forgery
4862| [36354] Apache HTTP Server mod_proxy module denial of service
4863| [36352] Apache HTTP Server ap_proxy_date_canon() denial of service
4864| [36336] Apache Derby lock table privilege escalation
4865| [36335] Apache Derby schema privilege escalation
4866| [36006] Apache Tomcat "
4867| [36001] Apache Tomcat Host Manager Servlet alias cross-site scripting
4868| [35999] Apache Tomcat \"
4869| [35795] Apache Tomcat CookieExample cross-site scripting
4870| [35536] Apache Tomcat SendMailServlet example cross-site scripting
4871| [35384] Apache HTTP Server mod_cache module denial of service
4872| [35097] Apache HTTP Server mod_status module cross-site scripting
4873| [35095] Apache HTTP Server Prefork MPM module denial of service
4874| [34984] Apache HTTP Server recall_headers information disclosure
4875| [34966] Apache HTTP Server MPM content spoofing
4876| [34965] Apache HTTP Server MPM information disclosure
4877| [34963] Apache HTTP Server MPM multiple denial of service
4878| [34872] Apache MyFaces Tomahawk autoscroll parameter cross-site scripting
4879| [34869] Apache Tomcat JSP example Web application cross-site scripting
4880| [34868] Apache Tomcat Manager and Host Manager cross-site scripting
4881| [34496] Apache Tomcat JK Connector security bypass
4882| [34377] Apache Tomcat hello.jsp cross-site scripting
4883| [34212] Apache Tomcat SSL configuration security bypass
4884| [34210] Apache Tomcat Accept-Language cross-site scripting
4885| [34209] Apache Tomcat calendar application cross-site scripting
4886| [34207] Apache Tomcat implicit-objects.jsp cross-site scripting
4887| [34167] Apache Axis WSDL file path disclosure
4888| [34068] Apache Tomcat AJP connector information disclosure
4889| [33584] Apache HTTP Server suEXEC privilege escalation
4890| [32988] Apache Tomcat proxy module directory traversal
4891| [32794] Apache Tomcat JK Web Server Connector map_uri_to_worker() buffer overflow
4892| [32708] Debian Apache tty privilege escalation
4893| [32441] ApacheStats extract() PHP call unspecified
4894| [32128] Apache Tomcat default account
4895| [31680] Apache Tomcat RequestParamExample cross-site scripting
4896| [31649] Apache Tomcat Sample Servlet TroubleShooter detected
4897| [31557] BEA WebLogic Server and WebLogic Express Apache proxy plug-in denial of service
4898| [31236] Apache HTTP Server htpasswd.c strcpy buffer overflow
4899| [30456] Apache mod_auth_kerb off-by-one buffer overflow
4900| [29550] Apache mod_tcl set_var() format string
4901| [28620] Apache and IBM HTTP Server Expect header cross-site scripting
4902| [28357] Apache HTTP Server mod_alias script source information disclosure
4903| [28063] Apache mod_rewrite off-by-one buffer overflow
4904| [27902] Apache Tomcat URL information disclosure
4905| [26786] Apache James SMTP server denial of service
4906| [25680] libapache2 /tmp/svn file upload
4907| [25614] Apache Struts lookupMap cross-site scripting
4908| [25613] Apache Struts ActionForm denial of service
4909| [25612] Apache Struts isCancelled() security bypass
4910| [24965] Apache mod_python FileSession command execution
4911| [24716] Apache James spooler memory leak denial of service
4912| [24159] Apache Geronimo Web-Access-Log Viewer cross-site scripting
4913| [24158] Apache Geronimo jsp-examples cross-site scripting
4914| [24030] Apache auth_ldap module multiple format strings
4915| [24008] Apache mod_ssl custom error message denial of service
4916| [24003] Apache mod_auth_pgsql module multiple syslog format strings
4917| [23612] Apache mod_imap referer field cross-site scripting
4918| [23173] Apache Struts error message cross-site scripting
4919| [22942] Apache Tomcat directory listing denial of service
4920| [22858] Apache Multi-Processing Module code allows denial of service
4921| [22602] RHSA-2005:582 updates for Apache httpd not installed
4922| [22520] Apache mod-auth-shadow "
4923| [22466] ApacheTop symlink
4924| [22109] Apache HTTP Server ssl_engine_kernel client certificate validation
4925| [22006] Apache HTTP Server byte-range filter denial of service
4926| [21567] Apache mod_ssl off-by-one buffer overflow
4927| [21195] Apache HTTP Server header HTTP request smuggling
4928| [20383] Apache HTTP Server htdigest buffer overflow
4929| [19681] Apache Tomcat AJP12 request denial of service
4930| [18993] Apache HTTP server check_forensic symlink attack
4931| [18790] Apache Tomcat Manager cross-site scripting
4932| [18349] Apache HTTP server Apple HFS+ filesystem obtain information
4933| [18348] Apache HTTP server Apple HFS+ filesystem .DS_Store and .ht file disclosure
4934| [18347] Apache HTTP server Apple Mac OS X Server mod_digest_apple module could allow an attacker to replay responses
4935| [17961] Apache Web server ServerTokens has not been set
4936| [17930] Apache HTTP Server HTTP GET request denial of service
4937| [17785] Apache mod_include module buffer overflow
4938| [17671] Apache HTTP Server SSLCipherSuite bypass restrictions
4939| [17473] Apache HTTP Server Satisfy directive allows access to resources
4940| [17413] Apache htpasswd buffer overflow
4941| [17384] Apache HTTP Server environment variable configuration file buffer overflow
4942| [17382] Apache HTTP Server IPv6 apr_util denial of service
4943| [17366] Apache HTTP Server mod_dav module LOCK denial of service
4944| [17273] Apache HTTP Server speculative mode denial of service
4945| [17200] Apache HTTP Server mod_ssl denial of service
4946| [16890] Apache HTTP Server server-info request has been detected
4947| [16889] Apache HTTP Server server-status request has been detected
4948| [16705] Apache mod_ssl format string attack
4949| [16524] Apache HTTP Server ap_get_mime_headers_core denial of service
4950| [16387] Apache HTTP Server mod_proxy Content-Length buffer overflow
4951| [16230] Apache HTTP Server PHP denial of service
4952| [16214] Apache mod_ssl ssl_util_uuencode_binary buffer overflow
4953| [15958] Apache HTTP Server authentication modules memory corruption
4954| [15547] Apache HTTP Server mod_disk_cache local information disclosure
4955| [15540] Apache HTTP Server socket starvation denial of service
4956| [15467] Novell GroupWise WebAccess using Apache Web server allows viewing of files on the server
4957| [15422] Apache HTTP Server mod_access information disclosure
4958| [15419] Apache HTTP Server mod_ssl plain HTTP request denial of service
4959| [15293] Apache for Cygwin "
4960| [15065] Apache-SSL has a default password
4961| [15041] Apache HTTP Server mod_digest module could allow an attacker to replay responses
4962| [15015] Apache httpd server httpd.conf could allow a local user to bypass restrictions
4963| [14751] Apache Mod_python output filter information disclosure
4964| [14125] Apache HTTP Server mod_userdir module information disclosure
4965| [14075] Apache HTTP Server mod_php file descriptor leak
4966| [13703] Apache HTTP Server account
4967| [13689] Apache HTTP Server configuration allows symlinks
4968| [13688] Apache HTTP Server configuration allows SSI
4969| [13687] Apache HTTP Server Server: header value
4970| [13685] Apache HTTP Server ServerTokens value
4971| [13684] Apache HTTP Server ServerSignature value
4972| [13672] Apache HTTP Server config allows directory autoindexing
4973| [13671] Apache HTTP Server default content
4974| [13670] Apache HTTP Server config file directive references outside content root
4975| [13668] Apache HTTP Server httpd not running in chroot environment
4976| [13666] Apache HTTP Server CGI directory contains possible command interpreter or compiler
4977| [13664] Apache HTTP Server config file contains ScriptAlias entry
4978| [13663] Apache HTTP Server CGI support modules loaded
4979| [13661] Apache HTTP Server config file contains AddHandler entry
4980| [13660] Apache HTTP Server 500 error page not CGI script
4981| [13659] Apache HTTP Server 413 error page not CGI script
4982| [13658] Apache HTTP Server 403 error page not CGI script
4983| [13657] Apache HTTP Server 401 error page not CGI script
4984| [13552] Apache HTTP Server mod_cgid module information disclosure
4985| [13550] Apache GET request directory traversal
4986| [13516] Apache Cocoon XMLForm and JXForm could allow execution of code
4987| [13499] Apache Cocoon directory traversal allows downloading of boot.ini file
4988| [13429] Apache Tomcat non-HTTP request denial of service
4989| [13400] Apache HTTP server mod_alias and mod_rewrite buffer overflow
4990| [13295] Apache weak password encryption
4991| [13254] Apache Tomcat .jsp cross-site scripting
4992| [13125] Apache::Gallery Inline::C could allow arbitrary code execution
4993| [13086] Apache Jakarta Tomcat mod_jk format string allows remote access
4994| [12681] Apache HTTP Server mod_proxy could allow mail relaying
4995| [12662] Apache HTTP Server rotatelogs denial of service
4996| [12554] Apache Tomcat stores password in plain text
4997| [12553] Apache HTTP Server redirects and subrequests denial of service
4998| [12552] Apache HTTP Server FTP proxy server denial of service
4999| [12551] Apache HTTP Server prefork MPM denial of service
5000| [12550] Apache HTTP Server weaker than expected encryption
5001| [12549] Apache HTTP Server type-map file denial of service
5002| [12206] Apache Tomcat /opt/tomcat directory insecure permissions
5003| [12102] Apache Jakarta Tomcat MS-DOS device name request denial of service
5004| [12091] Apache HTTP Server apr_password_validate denial of service
5005| [12090] Apache HTTP Server apr_psprintf code execution
5006| [11804] Apache HTTP Server mod_access_referer denial of service
5007| [11750] Apache HTTP Server could leak sensitive file descriptors
5008| [11730] Apache HTTP Server error log and access log terminal escape sequence injection
5009| [11703] Apache long slash path allows directory listing
5010| [11695] Apache HTTP Server LF (Line Feed) denial of service
5011| [11694] Apache HTTP Server filestat.c denial of service
5012| [11438] Apache HTTP Server MIME message boundaries information disclosure
5013| [11412] Apache HTTP Server error log terminal escape sequence injection
5014| [11196] Apache Tomcat examples and ROOT Web applications cross-site scripting
5015| [11195] Apache Tomcat web.xml could be used to read files
5016| [11194] Apache Tomcat URL appended with a null character could list directories
5017| [11139] Apache HTTP Server mass virtual hosting with mod_rewrite or mod_vhost_alias could allow an attacker to obtain files
5018| [11126] Apache HTTP Server illegal character file disclosure
5019| [11125] Apache HTTP Server DOS device name HTTP POST code execution
5020| [11124] Apache HTTP Server DOS device name denial of service
5021| [11088] Apache HTTP Server mod_vhost_alias CGI source disclosure
5022| [10938] Apache HTTP Server printenv test CGI cross-site scripting
5023| [10771] Apache Tomcat mod_jk module multiple HTTP GET request buffer overflow
5024| [10575] Apache mod_php module could allow an attacker to take over the httpd process
5025| [10499] Apache HTTP Server WebDAV HTTP POST view source
5026| [10457] Apache HTTP Server mod_ssl "
5027| [10415] Apache HTTP Server htdigest insecure system() call could allow command execution
5028| [10414] Apache HTTP Server htdigest multiple buffer overflows
5029| [10413] Apache HTTP Server htdigest temporary file race condition
5030| [10412] Apache HTTP Server htpasswd temporary file race condition
5031| [10376] Apache Tomcat invoker servlet used in conjunction with the default servlet reveals source code
5032| [10348] Apache Tomcat HTTP GET request DOS device reference could cause a denial of service
5033| [10281] Apache HTTP Server ab.c ApacheBench long response buffer overflow
5034| [10280] Apache HTTP Server shared memory scorecard overwrite
5035| [10263] Apache Tomcat mod_jk or mod_jserv connector directory disclosure
5036| [10241] Apache HTTP Server Host: header cross-site scripting
5037| [10230] Slapper worm variants A, B, and C target OpenSSL/Apache systems
5038| [10208] Apache HTTP Server mod_dav denial of service
5039| [10206] HP VVOS Apache mod_ssl denial of service
5040| [10200] Apache HTTP Server stderr denial of service
5041| [10175] Apache Tomcat org.apache.catalina.servlets.DefaultServlet reveals source code
5042| [10169] Slapper worm variant (Slapper.C) targets OpenSSL/Apache systems
5043| [10154] Slapper worm variant (Slapper.B) targets OpenSSL/Apache systems
5044| [10098] Slapper worm targets OpenSSL/Apache systems
5045| [9876] Apache HTTP Server cgi/cgid request could disclose the path to a requested script
5046| [9875] Apache HTTP Server .var file request could disclose installation path
5047| [9863] Apache Tomcat web.xml file could allow a remote attacker to bypass restrictions
5048| [9808] Apache HTTP Server non-Unix version URL encoded directory traversal
5049| [9623] Apache HTTP Server ap_log_rerror() path disclosure
5050| [9520] Apache Tomcat /servlet/ mapping cross-site scripting
5051| [9415] Apache HTTP Server mod_ssl .htaccess off-by-one buffer overflow
5052| [9396] Apache Tomcat null character to threads denial of service
5053| [9394] Apache Tomcat HTTP request for LPT9 reveals Web root path
5054| [9249] Apache HTTP Server chunked encoding heap buffer overflow
5055| [9208] Apache Tomcat sample file requests could reveal directory listing and path to Web root directory
5056| [8932] Apache Tomcat example class information disclosure
5057| [8633] Apache HTTP Server with mod_rewrite could allow an attacker to bypass directives
5058| [8629] Apache HTTP Server double-reverse DNS lookup spoofing
5059| [8589] Apache HTTP Server for Windows DOS batch file remote command execution
5060| [8457] Oracle9i Application Server Apache PL/SQL HTTP Location header buffer overflow
5061| [8455] Oracle9i Application Server default installation could allow an attacker to access certain Apache Services
5062| [8400] Apache HTTP Server mod_frontpage buffer overflows
5063| [8326] Apache HTTP Server multiple MIME headers (sioux) denial of service
5064| [8308] Apache "
5065| [8275] Apache HTTP Server with Multiviews enabled could disclose directory contents
5066| [8119] Apache and PHP OPTIONS request reveals "
5067| [8054] Apache is running on the system
5068| [8029] Mandrake Linux default Apache configuration could allow an attacker to browse files and directories
5069| [8027] Mandrake Linux default Apache configuration has remote management interface enabled
5070| [8026] Mandrake Linux Apache sample programs could disclose sensitive information about the server
5071| [7836] Apache HTTP Server log directory denial of service
5072| [7815] Apache for Windows "
5073| [7810] Apache HTTP request could result in unexpected behavior
5074| [7599] Apache Tomcat reveals installation path
5075| [7494] Apache "
5076| [7419] Apache Web Server could allow remote attackers to overwrite .log files
5077| [7363] Apache Web Server hidden HTTP requests
5078| [7249] Apache mod_proxy denial of service
5079| [7129] Linux with Apache Web server could allow an attacker to determine if a specified username exists
5080| [7103] Apple Mac OS X used with Apache Web server could disclose directory contents
5081| [7059] Apache "
5082| [7057] Apache "
5083| [7056] Apache "
5084| [7055] Apache "
5085| [7054] Apache "
5086| [6997] Apache Jakarta Tomcat error message may reveal information
5087| [6971] Apache Jakarta Tomcat may reveal JSP source code with missing HTTP protocol specification
5088| [6970] Apache crafted HTTP request could reveal the internal IP address
5089| [6921] Apache long slash path allows directory listing
5090| [6687] Apple Mac OS X used with Apache Web server could allow arbitrary file disclosure
5091| [6527] Apache Web Server for Windows and OS2 denial of service
5092| [6316] Apache Jakarta Tomcat may reveal JSP source code
5093| [6305] Apache Jakarta Tomcat directory traversal
5094| [5926] Linux Apache symbolic link
5095| [5659] Apache Web server discloses files when used with php script
5096| [5310] Apache mod_rewrite allows attacker to view arbitrary files
5097| [5204] Apache WebDAV directory listings
5098| [5197] Apache Web server reveals CGI script source code
5099| [5160] Apache Jakarta Tomcat default installation
5100| [5099] Trustix Secure Linux installs Apache with world writable access
5101| [4968] Apache Jakarta Tomcat snoop servlet gives out information which could be used in attack
5102| [4967] Apache Jakarta Tomcat 404 error reveals the pathname of the requested file
5103| [4931] Apache source.asp example file allows users to write to files
5104| [4575] IBM HTTP Server running Apache allows users to directory listing and file retrieval
5105| [4205] Apache Jakarta Tomcat delivers file contents
5106| [2084] Apache on Debian by default serves the /usr/doc directory
5107| [1630] MessageMedia UnityMail and Apache Web server MIME header flood denial of service
5108| [697] Apache HTTP server beck exploit
5109| [331] Apache cookies buffer overflow
5110|
5111| Exploit-DB - https://www.exploit-db.com:
5112| [31130] Apache Tomcat <= 6.0.15 Cookie Quote Handling Remote Information Disclosure Vulnerability
5113| [31052] Apache <= 2.2.6 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
5114| [30901] Apache HTTP Server 2.2.6 Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
5115| [30835] Apache HTTP Server <= 2.2.4 413 Error HTTP Request Method Cross-Site Scripting Weakness
5116| [30563] Apache Tomcat <= 5.5.15 Cal2.JSP Cross-Site Scripting Vulnerability
5117| [30496] Apache Tomcat <= 6.0.13 Cookie Handling Quote Delimiter Session ID Disclosure
5118| [30495] Apache Tomcat <= 6.0.13 Host Manager Servlet Cross Site Scripting Vulnerability
5119| [30191] Apache MyFaces Tomahawk JSF Framework 1.1.5 Autoscroll Parameter Cross Site Scripting Vulnerability
5120| [30189] Apache Tomcat <= 6.0.13 JSP Example Web Applications Cross Site Scripting Vulnerability
5121| [30052] Apache Tomcat 6.0.10 Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
5122| [29930] Apache AXIS 1.0 Non-Existent WSDL Path Information Disclosure Vulnerability
5123| [29859] Apache Roller OGNL Injection
5124| [29739] Apache HTTP Server Tomcat 5.x/6.0.x Directory Traversal Vulnerability
5125| [29435] Apache Tomcat 5.5.25 - CSRF Vulnerabilities
5126| [29316] Apache + PHP 5.x - Remote Code Execution (Multithreaded Scanner) (2)
5127| [29290] Apache / PHP 5.x Remote Code Execution Exploit
5128| [28713] Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object RCE
5129| [28424] Apache 2.x HTTP Server Arbitrary HTTP Request Headers Security Weakness
5130| [28365] Apache 2.2.2 CGI Script Source Code Information Disclosure Vulnerability
5131| [28254] Apache Tomcat 5 Information Disclosure Vulnerability
5132| [27915] Apache James 2.2 SMTP Denial of Service Vulnerability
5133| [27397] Apache suEXEC Privilege Elevation / Information Disclosure
5134| [27135] Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
5135| [27096] Apache Geronimo 1.0 Error Page XSS
5136| [27095] Apache Tomcat / Geronimo 1.0 Sample Script cal2.jsp time Parameter XSS
5137| [26710] Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4 - Denial of Service
5138| [26542] Apache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability
5139| [25986] Plesk Apache Zeroday Remote Exploit
5140| [25980] Apache Struts includeParams Remote Code Execution
5141| [25625] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (2)
5142| [25624] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (1)
5143| [24874] Apache Struts ParametersInterceptor Remote Code Execution
5144| [24744] Apache Rave 0.11 - 0.20 - User Information Disclosure
5145| [24694] Apache 1.3.x mod_include Local Buffer Overflow Vulnerability
5146| [24590] Apache 2.0.x mod_ssl Remote Denial of Service Vulnerability
5147| [23751] Apache Cygwin 1.3.x/2.0.x Directory Traversal Vulnerability
5148| [23581] Apache 2.0.4x mod_perl Module File Descriptor Leakage Vulnerability
5149| [23482] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (2)
5150| [23481] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (1)
5151| [23296] Red Hat Apache 2.0.40 Directory Index Default Configuration Error
5152| [23282] apache cocoon 2.14/2.2 - Directory Traversal vulnerability
5153| [23245] Apache Tomcat 4.0.x Non-HTTP Request Denial of Service Vulnerability
5154| [23119] Apache::Gallery 0.4/0.5/0.6 Insecure Local File Storage Privilege Escalation Vulnerability
5155| [22505] Apache Mod_Access_Referer 1.0.2 NULL Pointer Dereference Denial of Service Vulnerability
5156| [22205] Apache Tomcat 3.x Null Byte Directory/File Disclosure Vulnerability
5157| [22191] Apache Web Server 2.0.x MS-DOS Device Name Denial of Service Vulnerability
5158| [22068] Apache 1.3.x,Tomcat 4.0.x/4.1.x Mod_JK Chunked Encoding Denial of Service Vulnerability
5159| [21885] Apache 1.3/2.0.x Server Side Include Cross Site Scripting Vulnerability
5160| [21882] Apache Tomcat 3.2 Directory Disclosure Vulnerability
5161| [21854] Apache 2.0.39/40 Oversized STDERR Buffer Denial of Service Vulnerability
5162| [21853] Apache Tomcat 3/4 DefaultServlet File Disclosure Vulnerability
5163| [21734] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
5164| [21719] Apache 2.0 Path Disclosure Vulnerability
5165| [21697] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
5166| [21605] Apache Tomcat 4.0.3 DoS Device Name Cross Site Scripting Vulnerability
5167| [21604] Apache Tomcat 4.0.3 Servlet Mapping Cross Site Scripting Vulnerability
5168| [21560] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (2)
5169| [21559] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (1)
5170| [21534] Apache Tomcat 3/4 JSP Engine Denial of Service Vulnerability
5171| [21492] Apache Tomcat 3.2.3/3.2.4 RealPath.JSP Malformed Request Information Disclosure
5172| [21491] Apache Tomcat 3.2.3/3.2.4 Example Files Web Root Path Disclosure
5173| [21490] Apache Tomcat 3.2.3/3.2.4 Source.JSP Malformed Request Information Disclosure
5174| [21412] Apache Tomcat 4.0/4.1 Servlet Path Disclosure Vulnerability
5175| [21350] Apache Win32 1.3.x/2.0.x Batch File Remote Command Execution Vulnerability
5176| [21204] Apache 1.3.20 Win32 PHP.EXE Remote File Disclosure Vulnerability
5177| [21112] Red Hat Linux 7.0 Apache Remote Username Enumeration Vulnerability
5178| [21067] Apache 1.0/1.2/1.3 Server Address Disclosure Vulnerability
5179| [21002] Apache 1.3 Possible Directory Index Disclosure Vulnerability
5180| [20911] Apache 1.3.14 Mac File Protection Bypass Vulnerability
5181| [20716] apache tomcat 3.0 - Directory Traversal vulnerability
5182| [20695] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (4)
5183| [20694] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (3)
5184| [20693] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (2)
5185| [20692] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (1)
5186| [20595] NCSA 1.3/1.4.x/1.5,Apache httpd 0.8.11/0.8.14 ScriptAlias Source Retrieval Vulnerability
5187| [20558] Apache 1.2 Web Server DoS Vulnerability
5188| [20466] Apache 1.3 Web Server with Php 3 File Disclosure Vulnerability
5189| [20435] Apache 0.8.x/1.0.x,NCSA httpd 1.x test-cgi Directory Listing Vulnerability
5190| [20272] Apache 1.2.5/1.3.1,UnityMail 2.0 MIME Header DoS Vulnerability
5191| [20210] Apache 1.3.12 WebDAV Directory Listings Vulnerability
5192| [20131] Apache Tomcat 3.1 Path Revealing Vulnerability
5193| [19975] Apache 1.3.6/1.3.9/1.3.11/1.3.12/1.3.20 Root Directory Access Vulnerability
5194| [19828] Cobalt RaQ 2.0/3.0 Apache .htaccess Disclosure Vulnerability
5195| [19536] Apache <= 1.1,NCSA httpd <= 1.5.2,Netscape Server 1.12/1.1/2.0 a nph-test-cgi Vulnerability
5196| [19231] PHP apache_request_headers Function Buffer Overflow
5197| [18984] Apache Struts <= 2.2.1.1 - Remote Command Execution
5198| [18897] Oracle Weblogic Apache Connector POST Request Buffer Overflow
5199| [18619] Apache Tomcat Remote Exploit (PUT Request) and Account Scanner
5200| [18452] Apache Struts Multiple Persistent Cross-Site Scripting Vulnerabilities
5201| [18442] Apache httpOnly Cookie Disclosure
5202| [18329] Apache Struts2 <= 2.3.1 - Multiple Vulnerabilities
5203| [18221] Apache HTTP Server Denial of Service
5204| [17969] Apache mod_proxy Reverse Proxy Exposure Vulnerability PoC
5205| [17696] Apache httpd Remote Denial of Service (memory exhaustion)
5206| [17691] Apache Struts < 2.2.0 - Remote Command Execution
5207| [16798] Apache mod_jk 1.2.20 Buffer Overflow
5208| [16782] Apache Win32 Chunked Encoding
5209| [16752] Apache module mod_rewrite LDAP protocol Buffer Overflow
5210| [16317] Apache Tomcat Manager Application Deployer Authenticated Code Execution
5211| [15710] Apache Archiva 1.0 - 1.3.1 CSRF Vulnerability
5212| [15319] Apache 2.2 (Windows) Local Denial of Service
5213| [14617] Apache JackRabbit 2.0.0 webapp XPath Injection
5214| [14489] Apache Tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
5215| [12721] Apache Axis2 1.4.1 - Local File Inclusion Vulnerability
5216| [12689] Authenticated Cross-Site Scripting Vulnerability (XSS) within Apache Axis2 administration console
5217| [12343] Apache Tomcat 5.5.0 to 5.5.29 & 6.0.0 to 6.0.26 - Information Disclosure Vulnerability
5218| [12330] Apache OFBiz - Multiple XSS
5219| [12264] Apache OFBiz - FULLADMIN Creator PoC Payload
5220| [12263] Apache OFBiz - SQL Remote Execution PoC Payload
5221| [11662] Apache Spamassassin Milter Plugin Remote Root Command Execution
5222| [11650] Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit
5223| [10811] Joomla.Tutorials GHDB: Apache directory listing Download Vulnerability
5224| [10292] Apache Tomcat 3.2.1 - 404 Error Page Cross Site Scripting Vulnerability
5225| [9995] Apache Tomcat Form Authentication Username Enumeration Weakness
5226| [9994] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
5227| [9993] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
5228| [8842] Apache mod_dav / svn Remote Denial of Service Exploit
5229| [8458] Apache Geronimo <= 2.1.3 - Multiple Directory Traversal Vulnerabilities
5230| [7264] Apache Tomcat runtime.getRuntime().exec() Privilege Escalation (win)
5231| [6229] apache tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
5232| [6100] Apache mod_jk 1.2.19 Remote Buffer Overflow Exploit (win32)
5233| [6089] Bea Weblogic Apache Connector Code Exec / Denial of Service Exploit
5234| [5386] Apache Tomcat Connector jk2-2.0.2 (mod_jk2) Remote Overflow Exploit
5235| [5330] Apache 2.0 mod_jk2 2.0.2 - Remote Buffer Overflow Exploit (win32)
5236| [4552] Apache Tomcat (webdav) Remote File Disclosure Exploit (ssl support)
5237| [4530] Apache Tomcat (webdav) Remote File Disclosure Exploit
5238| [4162] Apache Tomcat Connector (mod_jk) Remote Exploit (exec-shield)
5239| [4093] Apache mod_jk 1.2.19/1.2.20 Remote Buffer Overflow Exploit
5240| [3996] Apache 2.0.58 mod_rewrite Remote Overflow Exploit (win2k3)
5241| [3680] Apache Mod_Rewrite Off-by-one Remote Overflow Exploit (win32)
5242| [3384] Ubuntu/Debian Apache 1.3.33/1.3.34 (CGI TTY) Local Root Exploit
5243| [2237] Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
5244| [2061] Apache Tomcat < 5.5.17 Remote Directory Listing Vulnerability
5245| [1056] Apache <= 2.0.49 Arbitrary Long HTTP Headers Denial of Service
5246| [855] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit
5247| [764] Apache OpenSSL - Remote Exploit (Multiple Targets) (OpenFuckV2.c)
5248| [587] Apache <= 1.3.31 mod_include Local Buffer Overflow Exploit
5249| [466] htpasswd Apache 1.3.31 - Local Exploit
5250| [371] Apache HTTPd Arbitrary Long HTTP Headers DoS (c version)
5251| [360] Apache HTTPd Arbitrary Long HTTP Headers DoS
5252| [132] Apache 1.3.x - 2.0.48 - mod_userdir Remote Users Disclosure Exploit
5253| [126] Apache mod_gzip (with debug_mode) <= 1.2.26.1a Remote Exploit
5254| [67] Apache 1.3.x mod_mylo Remote Code Execution Exploit
5255| [38] Apache <= 2.0.45 APR Remote Exploit -Apache-Knacker.pl
5256| [34] Webfroot Shoutbox < 2.32 (Apache) Remote Exploit
5257| [11] Apache <= 2.0.44 Linux Remote Denial of Service Exploit
5258| [9] Apache HTTP Server 2.x Memory Leak Exploit
5259|
5260| OpenVAS (Nessus) - http://www.openvas.org:
5261| [902924] Apache Struts2 Showcase Skill Name Remote Code Execution Vulnerability
5262| [902837] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability (Windows)
5263| [902830] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
5264| [902664] Apache Traffic Server HTTP Host Header Denial of Service Vulnerability
5265| [901203] Apache httpd Web Server Range Header Denial of Service Vulnerability
5266| [901110] Apache ActiveMQ Source Code Information Disclosure Vulnerability
5267| [901105] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
5268| [900842] Apache 'mod_proxy_ftp' Module Command Injection Vulnerability (Linux)
5269| [900841] Apache 'mod_proxy_ftp' Module Denial Of Service Vulnerability (Linux)
5270| [900573] Apache APR-Utils XML Parser Denial of Service Vulnerability
5271| [900572] Apache APR-Utils Multiple Denial of Service Vulnerabilities
5272| [900571] Apache APR-Utils Version Detection
5273| [900499] Apache mod_proxy_ajp Information Disclosure Vulnerability
5274| [900496] Apache Tiles Multiple XSS Vulnerability
5275| [900493] Apache Tiles Version Detection
5276| [900107] Apache mod_proxy_ftp Wildcard Characters XSS Vulnerability
5277| [900021] Apache Tomcat Cross-Site Scripting and Security Bypass Vulnerabilities
5278| [880086] CentOS Update for apache CESA-2008:0004-01 centos2 i386
5279| [870175] RedHat Update for apache RHSA-2008:0004-01
5280| [864591] Fedora Update for apache-poi FEDORA-2012-10835
5281| [864383] Fedora Update for apache-commons-compress FEDORA-2012-8428
5282| [864280] Fedora Update for apache-commons-compress FEDORA-2012-8465
5283| [864250] Fedora Update for apache-poi FEDORA-2012-7683
5284| [864249] Fedora Update for apache-poi FEDORA-2012-7686
5285| [863993] Fedora Update for apache-commons-daemon FEDORA-2011-10880
5286| [863466] Fedora Update for apache-commons-daemon FEDORA-2011-10936
5287| [855821] Solaris Update for Apache 1.3 122912-19
5288| [855812] Solaris Update for Apache 1.3 122911-19
5289| [855737] Solaris Update for Apache 1.3 122911-17
5290| [855731] Solaris Update for Apache 1.3 122912-17
5291| [855695] Solaris Update for Apache 1.3 122911-16
5292| [855645] Solaris Update for Apache 1.3 122912-16
5293| [855587] Solaris Update for kernel update and Apache 108529-29
5294| [855566] Solaris Update for Apache 116973-07
5295| [855531] Solaris Update for Apache 116974-07
5296| [855524] Solaris Update for Apache 2 120544-14
5297| [855494] Solaris Update for Apache 1.3 122911-15
5298| [855478] Solaris Update for Apache Security 114145-11
5299| [855472] Solaris Update for Apache Security 113146-12
5300| [855179] Solaris Update for Apache 1.3 122912-15
5301| [855147] Solaris Update for kernel update and Apache 108528-29
5302| [855077] Solaris Update for Apache 2 120543-14
5303| [850196] SuSE Update for apache2 openSUSE-SU-2012:0314-1 (apache2)
5304| [850088] SuSE Update for apache2 SUSE-SA:2007:061
5305| [850009] SuSE Update for apache2,apache SUSE-SA:2008:021
5306| [841209] Ubuntu Update for apache2 USN-1627-1
5307| [840900] Ubuntu Update for apache2 USN-1368-1
5308| [840798] Ubuntu Update for apache2 USN-1259-1
5309| [840734] Ubuntu Update for apache2 USN-1199-1
5310| [840542] Ubuntu Update for apache2 vulnerabilities USN-1021-1
5311| [840504] Ubuntu Update for apache2 vulnerability USN-990-2
5312| [840399] Ubuntu Update for apache2 vulnerabilities USN-908-1
5313| [840304] Ubuntu Update for apache2 vulnerabilities USN-575-1
5314| [840118] Ubuntu Update for libapache2-mod-perl2 vulnerability USN-488-1
5315| [840092] Ubuntu Update for apache2 vulnerabilities USN-499-1
5316| [840039] Ubuntu Update for libapache2-mod-python vulnerability USN-430-1
5317| [835253] HP-UX Update for Apache Web Server HPSBUX02645
5318| [835247] HP-UX Update for Apache-based Web Server HPSBUX02612
5319| [835243] HP-UX Update for Apache Running Tomcat Servlet Engine HPSBUX02579
5320| [835236] HP-UX Update for Apache with PHP HPSBUX02543
5321| [835233] HP-UX Update for Apache-based Web Server HPSBUX02531
5322| [835224] HP-UX Update for Apache-based Web Server HPSBUX02465
5323| [835200] HP-UX Update for Apache Web Server Suite HPSBUX02431
5324| [835190] HP-UX Update for Apache Web Server Suite HPSBUX02401
5325| [835188] HP-UX Update for Apache HPSBUX02308
5326| [835181] HP-UX Update for Apache With PHP HPSBUX02332
5327| [835180] HP-UX Update for Apache with PHP HPSBUX02342
5328| [835172] HP-UX Update for Apache HPSBUX02365
5329| [835168] HP-UX Update for Apache HPSBUX02313
5330| [835148] HP-UX Update for Apache HPSBUX01064
5331| [835139] HP-UX Update for Apache with PHP HPSBUX01090
5332| [835131] HP-UX Update for Apache HPSBUX00256
5333| [835119] HP-UX Update for Apache Remote Execution of Arbitrary Code HPSBUX02186
5334| [835104] HP-UX Update for Apache HPSBUX00224
5335| [835103] HP-UX Update for Apache mod_cgid HPSBUX00301
5336| [835101] HP-UX Update for Apache HPSBUX01232
5337| [835080] HP-UX Update for Apache HPSBUX02273
5338| [835078] HP-UX Update for ApacheStrong HPSBUX00255
5339| [835044] HP-UX Update for Apache HPSBUX01019
5340| [835040] HP-UX Update for Apache PHP HPSBUX00207
5341| [835025] HP-UX Update for Apache HPSBUX00197
5342| [835023] HP-UX Update for Apache HPSBUX01022
5343| [835022] HP-UX Update for Apache HPSBUX02292
5344| [835005] HP-UX Update for Apache HPSBUX02262
5345| [831759] Mandriva Update for apache-mod_security MDVSA-2012:182 (apache-mod_security)
5346| [831737] Mandriva Update for apache MDVSA-2012:154-1 (apache)
5347| [831534] Mandriva Update for apache MDVSA-2012:012 (apache)
5348| [831523] Mandriva Update for apache MDVSA-2012:003 (apache)
5349| [831491] Mandriva Update for apache MDVSA-2011:168 (apache)
5350| [831460] Mandriva Update for apache MDVSA-2011:144 (apache)
5351| [831449] Mandriva Update for apache MDVSA-2011:130 (apache)
5352| [831357] Mandriva Update for apache MDVSA-2011:057 (apache)
5353| [831132] Mandriva Update for apache MDVSA-2010:153 (apache)
5354| [831131] Mandriva Update for apache MDVSA-2010:152 (apache)
5355| [830989] Mandriva Update for apache-mod_auth_shadow MDVSA-2010:081 (apache-mod_auth_shadow)
5356| [830931] Mandriva Update for apache MDVSA-2010:057 (apache)
5357| [830926] Mandriva Update for apache MDVSA-2010:053 (apache)
5358| [830918] Mandriva Update for apache-mod_security MDVSA-2010:050 (apache-mod_security)
5359| [830799] Mandriva Update for apache-conf MDVSA-2009:300-2 (apache-conf)
5360| [830797] Mandriva Update for apache-conf MDVSA-2009:300-1 (apache-conf)
5361| [830791] Mandriva Update for apache-conf MDVA-2010:011 (apache-conf)
5362| [830652] Mandriva Update for apache MDVSA-2008:195 (apache)
5363| [830621] Mandriva Update for apache-conf MDVA-2008:129 (apache-conf)
5364| [830581] Mandriva Update for apache MDVSA-2008:016 (apache)
5365| [830294] Mandriva Update for apache MDKSA-2007:140 (apache)
5366| [830196] Mandriva Update for apache MDKSA-2007:235 (apache)
5367| [830112] Mandriva Update for apache MDKSA-2007:127 (apache)
5368| [830109] Mandriva Update for apache-mod_perl MDKSA-2007:083 (apache-mod_perl)
5369| [802425] Apache Struts2 Showcase Arbitrary Java Method Execution vulnerability
5370| [802423] Apache Struts CookBook/Examples Multiple Cross-Site Scripting Vulnerabilities
5371| [802422] Apache Struts Showcase Multiple Persistence Cross-Site Scripting Vulnerabilities
5372| [802415] Apache Tomcat Multiple Security Bypass Vulnerabilities (Win)
5373| [802385] Apache Tomcat Request Object Security Bypass Vulnerability (Win)
5374| [802384] Apache Tomcat Parameter Handling Denial of Service Vulnerability (Win)
5375| [802378] Apache Tomcat Hash Collision Denial Of Service Vulnerability
5376| [801942] Apache Archiva Multiple Vulnerabilities
5377| [801940] Apache Struts2 'XWork' Information Disclosure Vulnerability
5378| [801663] Apache Struts2/XWork Remote Command Execution Vulnerability
5379| [801521] Apache APR-util 'buckets/apr_brigade.c' Denial Of Service Vulnerability
5380| [801284] Apache Derby Information Disclosure Vulnerability
5381| [801203] Apache ActiveMQ Persistent Cross-Site Scripting Vulnerability
5382| [800837] Apache 'mod_deflate' Denial Of Service Vulnerability - July09
5383| [800827] Apache 'mod_proxy_http.c' Denial Of Service Vulnerability
5384| [800680] Apache APR Version Detection
5385| [800679] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
5386| [800678] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
5387| [800677] Apache Roller Version Detection
5388| [800279] Apache mod_jk Module Version Detection
5389| [800278] Apache Struts Cross Site Scripting Vulnerability
5390| [800277] Apache Tomcat mod_jk Information Disclosure Vulnerability
5391| [800276] Apache Struts Version Detection
5392| [800271] Apache Struts Directory Traversal Vulnerability
5393| [800024] Apache Tomcat RemoteFilterValve Security Bypass Vulnerability
5394| [103333] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
5395| [103293] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
5396| [103122] Apache Web Server ETag Header Information Disclosure Weakness
5397| [103074] Apache Continuum Cross Site Scripting Vulnerability
5398| [103073] Apache Continuum Detection
5399| [103053] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
5400| [101023] Apache Open For Business Weak Password security check
5401| [101020] Apache Open For Business HTML injection vulnerability
5402| [101019] Apache Open For Business service detection
5403| [100924] Apache Archiva Cross Site Request Forgery Vulnerability
5404| [100923] Apache Archiva Detection
5405| [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
5406| [100814] Apache Axis2 Document Type Declaration Processing Security Vulnerability
5407| [100813] Apache Axis2 Detection
5408| [100797] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
5409| [100795] Apache Derby Detection
5410| [100762] Apache CouchDB Cross Site Request Forgery Vulnerability
5411| [100725] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
5412| [100613] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
5413| [100514] Apache Multiple Security Vulnerabilities
5414| [100211] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
5415| [100172] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
5416| [100171] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
5417| [100130] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
5418| [72626] Debian Security Advisory DSA 2579-1 (apache2)
5419| [72612] FreeBSD Ports: apache22
5420| [71551] Gentoo Security Advisory GLSA 201206-25 (apache)
5421| [71550] Gentoo Security Advisory GLSA 201206-24 (apache tomcat)
5422| [71512] FreeBSD Ports: apache
5423| [71485] Debian Security Advisory DSA 2506-1 (libapache-mod-security)
5424| [71256] Debian Security Advisory DSA 2452-1 (apache2)
5425| [71238] Debian Security Advisory DSA 2436-1 (libapache2-mod-fcgid)
5426| [70737] FreeBSD Ports: apache
5427| [70724] Debian Security Advisory DSA 2405-1 (apache2)
5428| [70600] FreeBSD Ports: apache
5429| [70253] FreeBSD Ports: apache, apache-event, apache-itk, apache-peruser, apache-worker
5430| [70235] Debian Security Advisory DSA 2298-2 (apache2)
5431| [70233] Debian Security Advisory DSA 2298-1 (apache2)
5432| [69988] Debian Security Advisory DSA 2279-1 (libapache2-mod-authnz-external)
5433| [69338] Debian Security Advisory DSA 2202-1 (apache2)
5434| [67868] FreeBSD Ports: apache
5435| [66816] FreeBSD Ports: apache
5436| [66553] Mandriva Security Advisory MDVSA-2009:189-1 (apache-mod_auth_mysql)
5437| [66414] Mandriva Security Advisory MDVSA-2009:323 (apache)
5438| [66106] SuSE Security Advisory SUSE-SA:2009:050 (apache2,libapr1)
5439| [66081] SLES11: Security update for Apache 2
5440| [66074] SLES10: Security update for Apache 2
5441| [66070] SLES9: Security update for Apache 2
5442| [65998] SLES10: Security update for apache2-mod_python
5443| [65893] SLES10: Security update for Apache 2
5444| [65888] SLES10: Security update for Apache 2
5445| [65575] SLES9: Security update for apache2,apache2-prefork,apache2-worker
5446| [65510] SLES9: Security update for Apache 2
5447| [65472] SLES9: Security update for Apache
5448| [65467] SLES9: Security update for Apache
5449| [65450] SLES9: Security update for apache2
5450| [65390] SLES9: Security update for Apache2
5451| [65363] SLES9: Security update for Apache2
5452| [65309] SLES9: Security update for Apache and mod_ssl
5453| [65296] SLES9: Security update for webdav apache module
5454| [65283] SLES9: Security update for Apache2
5455| [65249] SLES9: Security update for Apache 2
5456| [65230] SLES9: Security update for Apache 2
5457| [65228] SLES9: Security update for Apache 2
5458| [65212] SLES9: Security update for apache2-mod_python
5459| [65209] SLES9: Security update for apache2-worker
5460| [65207] SLES9: Security update for Apache 2
5461| [65168] SLES9: Security update for apache2-mod_python
5462| [65142] SLES9: Security update for Apache2
5463| [65136] SLES9: Security update for Apache 2
5464| [65132] SLES9: Security update for apache
5465| [65131] SLES9: Security update for Apache 2 oes/CORE
5466| [65113] SLES9: Security update for apache2
5467| [65072] SLES9: Security update for apache and mod_ssl
5468| [65017] SLES9: Security update for Apache 2
5469| [64950] Mandrake Security Advisory MDVSA-2009:240 (apache)
5470| [64783] FreeBSD Ports: apache
5471| [64774] Ubuntu USN-802-2 (apache2)
5472| [64653] Ubuntu USN-813-2 (apache2)
5473| [64559] Debian Security Advisory DSA 1834-2 (apache2)
5474| [64532] Mandrake Security Advisory MDVSA-2009:189 (apache-mod_auth_mysql)
5475| [64527] Mandrake Security Advisory MDVSA-2009:184 (apache-mod_security)
5476| [64526] Mandrake Security Advisory MDVSA-2009:183 (apache-mod_security)
5477| [64500] Mandrake Security Advisory MDVSA-2009:168 (apache)
5478| [64443] Ubuntu USN-802-1 (apache2)
5479| [64426] Gentoo Security Advisory GLSA 200907-04 (apache)
5480| [64423] Debian Security Advisory DSA 1834-1 (apache2)
5481| [64391] Mandrake Security Advisory MDVSA-2009:149 (apache)
5482| [64377] Mandrake Security Advisory MDVSA-2009:124-1 (apache)
5483| [64251] Debian Security Advisory DSA 1816-1 (apache2)
5484| [64201] Ubuntu USN-787-1 (apache2)
5485| [64140] Mandrake Security Advisory MDVSA-2009:124 (apache)
5486| [64136] Mandrake Security Advisory MDVSA-2009:102 (apache)
5487| [63565] FreeBSD Ports: apache
5488| [63562] Ubuntu USN-731-1 (apache2)
5489| [61381] Gentoo Security Advisory GLSA 200807-06 (apache)
5490| [61185] FreeBSD Ports: apache
5491| [60582] Gentoo Security Advisory GLSA 200803-19 (apache)
5492| [60387] Slackware Advisory SSA:2008-045-02 apache
5493| [58826] FreeBSD Ports: apache-tomcat
5494| [58825] FreeBSD Ports: apache-tomcat
5495| [58804] FreeBSD Ports: apache
5496| [58745] Gentoo Security Advisory GLSA 200711-06 (apache)
5497| [58360] Debian Security Advisory DSA 1312-1 (libapache-mod-jk)
5498| [57851] Gentoo Security Advisory GLSA 200608-01 (apache)
5499| [57788] Debian Security Advisory DSA 1247-1 (libapache-mod-auth-kerb)
5500| [57335] Debian Security Advisory DSA 1167-1 (apache)
5501| [57201] Debian Security Advisory DSA 1131-1 (apache)
5502| [57200] Debian Security Advisory DSA 1132-1 (apache2)
5503| [57168] Slackware Advisory SSA:2006-209-01 Apache httpd
5504| [57145] FreeBSD Ports: apache
5505| [56731] Slackware Advisory SSA:2006-129-01 Apache httpd
5506| [56729] Slackware Advisory SSA:2006-130-01 Apache httpd redux
5507| [56246] Gentoo Security Advisory GLSA 200602-03 (Apache)
5508| [56212] Debian Security Advisory DSA 952-1 (libapache-auth-ldap)
5509| [56115] Debian Security Advisory DSA 935-1 (libapache2-mod-auth-pgsql)
5510| [56067] FreeBSD Ports: apache
5511| [55803] Slackware Advisory SSA:2005-310-04 apache
5512| [55519] Debian Security Advisory DSA 839-1 (apachetop)
5513| [55392] Gentoo Security Advisory GLSA 200509-12 (Apache)
5514| [55355] FreeBSD Ports: apache
5515| [55284] Debian Security Advisory DSA 807-1 (libapache-mod-ssl)
5516| [55261] Debian Security Advisory DSA 805-1 (apache2)
5517| [55259] Debian Security Advisory DSA 803-1 (apache)
5518| [55129] Gentoo Security Advisory GLSA 200508-15 (apache)
5519| [54739] Gentoo Security Advisory GLSA 200411-18 (apache)
5520| [54724] Gentoo Security Advisory GLSA 200411-03 (apache)
5521| [54712] Gentoo Security Advisory GLSA 200410-21 (apache)
5522| [54689] Gentoo Security Advisory GLSA 200409-33 (net=www/apache)
5523| [54677] Gentoo Security Advisory GLSA 200409-21 (apache)
5524| [54610] Gentoo Security Advisory GLSA 200407-03 (Apache)
5525| [54601] Gentoo Security Advisory GLSA 200406-16 (Apache)
5526| [54590] Gentoo Security Advisory GLSA 200406-05 (Apache)
5527| [54582] Gentoo Security Advisory GLSA 200405-22 (Apache)
5528| [54529] Gentoo Security Advisory GLSA 200403-04 (Apache)
5529| [54499] Gentoo Security Advisory GLSA 200310-04 (Apache)
5530| [54498] Gentoo Security Advisory GLSA 200310-03 (Apache)
5531| [54439] FreeBSD Ports: apache
5532| [53931] Slackware Advisory SSA:2004-133-01 apache
5533| [53903] Slackware Advisory SSA:2004-299-01 apache, mod_ssl, php
5534| [53902] Slackware Advisory SSA:2004-305-01 apache+mod_ssl
5535| [53878] Slackware Advisory SSA:2003-308-01 apache security update
5536| [53851] Debian Security Advisory DSA 135-1 (libapache-mod-ssl)
5537| [53849] Debian Security Advisory DSA 132-1 (apache-ssl)
5538| [53848] Debian Security Advisory DSA 131-1 (apache)
5539| [53784] Debian Security Advisory DSA 021-1 (apache)
5540| [53738] Debian Security Advisory DSA 195-1 (apache-perl)
5541| [53737] Debian Security Advisory DSA 188-1 (apache-ssl)
5542| [53735] Debian Security Advisory DSA 187-1 (apache)
5543| [53703] Debian Security Advisory DSA 532-1 (libapache-mod-ssl)
5544| [53577] Debian Security Advisory DSA 120-1 (libapache-mod-ssl, apache-ssl)
5545| [53568] Debian Security Advisory DSA 067-1 (apache,apache-ssl)
5546| [53519] Debian Security Advisory DSA 689-1 (libapache-mod-python)
5547| [53433] Debian Security Advisory DSA 181-1 (libapache-mod-ssl)
5548| [53282] Debian Security Advisory DSA 594-1 (apache)
5549| [53248] Debian Security Advisory DSA 558-1 (libapache-mod-dav)
5550| [53224] Debian Security Advisory DSA 532-2 (libapache-mod-ssl)
5551| [53215] Debian Security Advisory DSA 525-1 (apache)
5552| [53151] Debian Security Advisory DSA 452-1 (libapache-mod-python)
5553| [52529] FreeBSD Ports: apache+ssl
5554| [52501] FreeBSD Ports: apache
5555| [52461] FreeBSD Ports: apache
5556| [52390] FreeBSD Ports: apache
5557| [52389] FreeBSD Ports: apache
5558| [52388] FreeBSD Ports: apache
5559| [52383] FreeBSD Ports: apache
5560| [52339] FreeBSD Ports: apache+mod_ssl
5561| [52331] FreeBSD Ports: apache
5562| [52329] FreeBSD Ports: ru-apache+mod_ssl
5563| [52314] FreeBSD Ports: apache
5564| [52310] FreeBSD Ports: apache
5565| [15588] Detect Apache HTTPS
5566| [15555] Apache mod_proxy content-length buffer overflow
5567| [15554] Apache mod_include priviledge escalation
5568| [14771] Apache <= 1.3.33 htpasswd local overflow
5569| [14177] Apache mod_access rule bypass
5570| [13644] Apache mod_rootme Backdoor
5571| [12293] Apache Input Header Folding and mod_ssl ssl_io_filter_cleanup DoS Vulnerabilities
5572| [12280] Apache Connection Blocking Denial of Service
5573| [12239] Apache Error Log Escape Sequence Injection
5574| [12123] Apache Tomcat source.jsp malformed request information disclosure
5575| [12085] Apache Tomcat servlet/JSP container default files
5576| [11438] Apache Tomcat Directory Listing and File disclosure
5577| [11204] Apache Tomcat Default Accounts
5578| [11092] Apache 2.0.39 Win32 directory traversal
5579| [11046] Apache Tomcat TroubleShooter Servlet Installed
5580| [11042] Apache Tomcat DOS Device Name XSS
5581| [11041] Apache Tomcat /servlet Cross Site Scripting
5582| [10938] Apache Remote Command Execution via .bat files
5583| [10839] PHP.EXE / Apache Win32 Arbitrary File Reading Vulnerability
5584| [10773] MacOS X Finder reveals contents of Apache Web files
5585| [10766] Apache UserDir Sensitive Information Disclosure
5586| [10756] MacOS X Finder reveals contents of Apache Web directories
5587| [10752] Apache Auth Module SQL Insertion Attack
5588| [10704] Apache Directory Listing
5589| [10678] Apache /server-info accessible
5590| [10677] Apache /server-status accessible
5591| [10440] Check for Apache Multiple / vulnerability
5592|
5593| SecurityTracker - https://www.securitytracker.com:
5594| [1028865] Apache Struts Bugs Permit Remote Code Execution and URL Redirection Attacks
5595| [1028864] Apache Struts Wildcard Matching and Expression Evaluation Bugs Let Remote Users Execute Arbitrary Code
5596| [1028824] Apache mod_dav_svn URI Processing Flaw Lets Remote Users Deny Service
5597| [1028823] Apache Unspecified Flaw in mod_session_dbd Has Unspecified Impact
5598| [1028724] (HP Issues Fix for HP-UX) Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
5599| [1028722] (Red Hat Issues Fix for JBoss) Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
5600| [1028693] (Red Hat Issues Fix) Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
5601| [1028622] Apache Struts 'includeParams' Bugs Permit Remote Command Execution and Cross-Site Scripting Attacks
5602| [1028621] Apache Subversion Bugs Let Remote Authenticated Users Execute Arbitrary Commands and Deny Service
5603| [1028540] Apache mod_rewrite Input Validation Flaw Lets Remote Users Execute Arbitrary Commands
5604| [1028534] Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
5605| [1028533] Apache Tomcat Lack of Chunked Transfer Encoding Extension Size Limit Lets Remote Users Deny Service
5606| [1028532] Apache Tomcat AsyncListeners Bug May Disclose Information from One Request to Another User
5607| [1028515] Apache VCL Input Validation Flaw Lets Remote Authenticated Users Gain Elevated Privileges
5608| [1028457] Apache ActiveMQ Bugs Let Remote Users Conduct Cross-Site Scripting Attacks, Deny Service, and Obtain Potentially Sensitive Information
5609| [1028287] Apache CXF WSS4JInInterceptor Grants Service Access to Remote Users
5610| [1028286] Apache CXF WS-Security UsernameToken Processing Flaw Lets Remote Users Bypass Authentication
5611| [1028252] Apache Commons FileUpload Unsafe Temporary File Lets Local Users Gain Elevated Privileges
5612| [1028207] Apache Input Validation Bugs Permit Cross-Site Scripting Attacks
5613| [1027836] Apache Tomcat Connection Processing Bug Lets Remote Users Deny Service
5614| [1027834] Apache Tomcat Bug Lets Remote Users Bypass Cross-Site Request Forgery Prevention Filter
5615| [1027833] Apache Tomcat Bug Lets Remote Users Bypass Security Constraints
5616| [1027729] Apache Tomcat Header Processing Bug Lets Remote Users Deny Service
5617| [1027728] Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
5618| [1027554] Apache CXF Lets Remote Authenticated Users Execute Unauthorized SOAP Actions
5619| [1027508] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
5620| [1027421] Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
5621| [1027096] Apache Commons Compress BZip2CompressorOutputStream() Sorting Algorithm Lets Remote or Local Users Deny Service
5622| [1026932] Apache LD_LIBRARY_PATH Processing Lets Local Users Gain Elevated Privileges
5623| [1026928] Apache OFBiz Unspecified Flaw Lets Remote Users Execute Arbitrary Code
5624| [1026927] Apache OFBiz Input Validation Flaws Permit Cross-Site Scripting Attacks
5625| [1026847] Apache Traffic Server Host Header Processing Flaw Lets Remote Users Deny Service
5626| [1026846] Apache Wicket Discloses Hidden Application Files to Remote Users
5627| [1026839] Apache Wicket Input Validation Flaw in 'wicket:pageMapName' Parameter Permits Cross-Site Scripting Attacks
5628| [1026616] Apache Bugs Let Remote Users Deny Service and Obtain Cookie Data
5629| [1026575] Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
5630| [1026484] Apache Struts Bug Lets Remote Users Overwrite Files and Execute Arbitrary Code
5631| [1026477] Apache Tomcat Hash Table Collision Bug Lets Remote Users Deny Service
5632| [1026402] Apache Struts Conversion Error Lets Remote Users Inject Arbitrary Commands
5633| [1026353] Apache mod_proxy/mod_rewrite Bug Lets Remote Users Access Internal Servers
5634| [1026295] Apache Tomcat Lets Untrusted Web Applications Gain Elevated Privileges
5635| [1026267] Apache .htaccess File Integer Overflow Lets Local Users Execute Arbitrary Code
5636| [1026144] Apache mod_proxy Pattern Matching Bug Lets Remote Users Access Internal Servers
5637| [1026095] Apache Tomcat HTTP DIGEST Authentication Weaknesses Let Remote Users Conduct Bypass Attacks
5638| [1026054] Apache mod_proxy_ajp HTTP Processing Error Lets Remote Users Deny Service
5639| [1025993] Apache Tomcat AJP Protocol Processing Bug Lets Remote Users Bypass Authentication or Obtain Information
5640| [1025976] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
5641| [1025960] Apache httpd Byterange Filter Processing Error Lets Remote Users Deny Service
5642| [1025925] Apache Tomcat Commons Daemon jsvc Lets Local Users Gain Elevated Privileges
5643| [1025924] Apache Tomcat XML Validation Flaw Lets Applications Obtain Potentially Sensitive Information
5644| [1025788] Apache Tomcat Lets Malicious Applications Obtain Information and Deny Service
5645| [1025755] Apache Santuario Buffer Overflow Lets Remote Users Deny Service
5646| [1025712] Apache Tomcat Discloses Passwords to Local Users in Certain Cases
5647| [1025577] Apache Archiva Input Validation Hole Permits Cross-Site Scripting Attacks
5648| [1025576] Apache Archiva Request Validation Flaw Permits Cross-Site Request Forgery Attacks
5649| [1025527] Apache APR Library apr_fnmatch() Flaw Lets Remote Users Execute Arbitrary Code
5650| [1025303] Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
5651| [1025215] Apache Tomcat May Ignore @ServletSecurity Annotation Protections
5652| [1025066] Apache Continuum Input Validation Flaw Permits Cross-Site Request Forgery Attacks
5653| [1025065] Apache Continuum Input Validation Hole Permits Cross-Site Scripting Attacks
5654| [1025027] Apache Tomcat maxHttpHeaderSize Parsing Error Lets Remote Users Deny Service
5655| [1025026] Apache Tomcat Manager Input Validation Hole Permits Cross-Site Scripting Attacks
5656| [1025025] Apache Tomcat Security Manager Lets Local Users Bypass File Permissions
5657| [1024764] Apache Tomcat Manager Input Validation Hole in 'sessionList.jsp' Permits Cross-Site Scripting Attacks
5658| [1024417] Apache Traffic Server Insufficient Randomization Lets Remote Users Poison the DNS Cache
5659| [1024332] Apache mod_cache and mod_dav Request Processing Flaw Lets Remote Users Deny Service
5660| [1024180] Apache Tomcat 'Transfer-Encoding' Header Processing Flaw Lets Remote Users Deny Service and Obtain Potentially Sensitive Information
5661| [1024096] Apache mod_proxy_http May Return Results for a Different Request
5662| [1023942] Apache mod_proxy_ajp Error Condition Lets Remote Users Deny Service
5663| [1023941] Apache ap_read_request() Memory Error May Let Remote Users Access Potentially Sensitive Information
5664| [1023778] Apache ActiveMQ Input Validation Flaw Permits Cross-Site Scripting Attacks
5665| [1023701] Apache mod_isapi Error Processing Flaw May Let Remote Users Deny Service
5666| [1023533] Apache mod_proxy Integer Overflow May Let Remote Users Execute Arbitrary Code
5667| [1022988] Apache Solaris Support Code Bug Lets Remote Users Deny Service
5668| [1022529] Apache mod_deflate Connection State Bug Lets Remote Users Deny Service
5669| [1022509] Apache mod_proxy stream_reqbody_cl() Infinite Loop Lets Remote Users Deny Service
5670| [1022296] Apache IncludesNoExec Options Restrictions Can Be Bypass By Local Users
5671| [1022264] Apache mod_proxy_ajp Bug May Disclose Another User's Response Data
5672| [1022001] Apache Tomcat mod_jk May Disclose Responses to the Wrong User
5673| [1021988] mod_perl Input Validation Flaw in Apache::Status and Apache2::Status Permits Cross-Site Scripting Attacks
5674| [1021350] NetWare Bug Lets Remote Users Access the ApacheAdmin Console
5675| [1020635] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
5676| [1020520] Oracle WebLogic Apache Connector Lets Remote Users Execute Arbitrary Code
5677| [1020267] Apache mod_proxy Interim Response Process Bug Lets Remote Users Deny Service
5678| [1019784] Apache-SSL Certificate Processing Bug May Let Remote Users View Portions of Kernel Memory
5679| [1019256] Apache mod_negotiation Input Validation Hole Permits Cross-Site Scripting Attacks
5680| [1019194] Apache Input Validation Hole in Mod_AutoIndex When the Character Set is Undefined May Permit Cross-Site Scripting Attacks
5681| [1019185] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
5682| [1019154] Apache Input Validation Hole in mod_status Permits Cross-Site Scripting Attacks
5683| [1019093] Apache Input Validation Hole in mod_imap Permits Cross-Site Scripting Attacks
5684| [1019030] Apache Input Validation Hole in Default HTTP 413 Error Page Permits Cross-Site Scripting Attacks
5685| [1018633] Apache mod_proxy Bug Lets Remote Users Deny Service
5686| [1018304] Apache HTTPD scoreboard Protection Flaw Lets Local Users Terminate Arbitrary Processes
5687| [1018303] Apache HTTPD mod_cache May Let Remote Users Deny Service
5688| [1018302] Apache mod_status Input Validation Hole Permits Cross-Site Scripting Attacks
5689| [1018269] Apache Tomcat Input Validation Hole in Processing Accept-Language Header Permits Cross-Site Scripting Attacks
5690| [1017904] Apache suEXEC Bugs May Let Local Users Gain Elevated Privileges
5691| [1017719] Apache Tomcat JK Web Server Connector Buffer Overflow in map_uri_to_worker() Lets Remote Users Execute Arbitrary Code
5692| [1017062] Apache mod_tcl Format String Bug in set_var() Function May Let Remote Users Execute Arbitrary Code
5693| [1016601] Apache mod_rewrite Off-by-one Error Lets Remote Users Execute Arbitrary Code
5694| [1016576] Apache Tomcat Discloses Directory Listings to Remote Users
5695| [1015447] Apache mod_ssl Null Pointer Dereference May Let Remote Users Deny Service
5696| [1015344] Apache mod_imap Input Validation Flaw in Referer Field Lets Remote Users Conduct Cross-Site Scripting Attacks
5697| [1015093] Apache Memory Leak in MPM 'worker.c' Code May Let Remote Users Deny Service
5698| [1014996] ApacheTop Unsafe Temporary File May Let Local Users Gain Elevated Privileges
5699| [1014833] Apache ssl_hook_Access() Function May Fail to Verify Client Certificates
5700| [1014826] Apache Memory Leak in 'byterange filter' Lets Remote Users Deny Service
5701| [1014575] Apache mod_ssl Off-by-one Buffer Overflow in Processing CRLs May Let Remote Users Deny Service
5702| [1014323] Apache Chunked Transfer-Encoding and Content-Length Processing Lets Remote Users Smuggle HTTP Requests
5703| [1013156] Apache mod_python Publisher Handler Discloses Information to Remote Users
5704| [1012829] Apache mod_auth_radius radcpy() Integer Overflow Lets Remote Users Deny Service in Certain Cases
5705| [1012416] Apache on Apple OS X Lets Remote Users Bypass Apache File Handlers and Directly Access Files
5706| [1012415] Apache on Apple HFS+ Filesystems May Disclose '.DS_Store' Files to Remote Users
5707| [1012414] Apache mod_digest_apple Lets Remote Users Replay Authentication Credentials
5708| [1012083] Apache Web Server Error in Processing Requests With Many Space Characters Lets Remote Users Deny Service
5709| [1011783] Apache mod_include Buffer Overflow Lets Local Users Execute Arbitrary Code
5710| [1011557] Apache mod_ssl SSLCipherSuite Directive Can By Bypassed in Certain Cases
5711| [1011385] Apache Satsify Directive Error May Let Remote Users Access Restricted Resources
5712| [1011340] Apache SSL Connection Abort State Error Lets Remote Users Deny Service
5713| [1011303] Apache ap_resolve_env() Buffer Overflow in Reading Configuration Files May Let Local Users Gain Elevated Privileges
5714| [1011299] Apache IPv6 Address Parsing Flaw May Let Remote Users Deny Service
5715| [1011248] Apache mod_dav LOCK Method Error May Let Remote Users Deny Service
5716| [1011213] Apache mod_ssl Can Be Crashed By Remote Users When Reverse Proxying SSL Connections
5717| [1010674] Apache Can Be Crashed By PHP Code Invoking Nested Remote Sockets
5718| [1010599] Apache httpd Header Line Memory Allocation Lets Remote Users Crash the Server
5719| [1010462] Apache mod_proxy Buffer Overflow May Let Remote Users Execute Arbitrary Code
5720| [1010322] Apache mod_ssl Stack Overflow in ssl_util_uuencode_binary() May Let Remote Users Execute Arbitrary Code
5721| [1010270] cPanel Apache mod_phpsuexec Options Let Local Users Gain Elevated Privileges
5722| [1009934] Apache Web Server Has Buffer Overflow in ebcdic2ascii() on Older Processor Architectures
5723| [1009516] Apache mod_survey HTML Report Format Lets Remote Users Conduct Cross-Site Scripting Attacks
5724| [1009509] Apache mod_disk_cache Stores Authentication Credentials on Disk
5725| [1009495] Apache Web Server Socket Starvation Flaw May Let Remote Users Deny Service
5726| [1009417] GroupWise WebAccess With Apache on NetWare Has Configuration Flaw That May Grant Web Access to Remote Users
5727| [1009338] Apache mod_access Parsing Flaw May Fail to Enforce Allow/Deny Rules
5728| [1009337] Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon
5729| [1009182] Apache for Cygwin '..%5C' Input Validation Flaw Discloses Files to Remote Users
5730| [1008973] PHP May Apply Incorrect php_admin_* Settings To Requests for Apache Virtual Hosts
5731| [1008967] Apache-SSL 'SSLFakeBasicAuth' Lets Remote Users Forge Client Certificates to Be Authenticated
5732| [1008920] Apache mod_digest May Validate Replayed Client Responses
5733| [1008828] Apache mod_python String Processing Bug Still Lets Remote Users Crash the Web Server
5734| [1008822] Apache mod_perl File Descriptor Leak May Let Local Users Hijack the http and https Services
5735| [1008675] mod_auth_shadow Apache Module Authenticates Expired Passwords
5736| [1008559] Apache mod_php File Descriptor Leak May Let Local Users Hijack the https Service
5737| [1008335] Apache mod_python String Processing Bug Lets Remote Users Crash the Web Server
5738| [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
5739| [1008030] Apache mod_rewrite Contains a Buffer Overflow
5740| [1008029] Apache mod_alias Contains a Buffer Overflow
5741| [1008028] Apache mod_cgid May Disclose CGI Output to Another Client
5742| [1007995] Apache Cocoon Forms May Let Remote Users Execute Arbitrary Java Code on the System
5743| [1007993] Apache Cocoon 'view-source' Sample Script Discloses Files to Remote Users
5744| [1007823] Apache Web Server mod_cgi Error May Let Malicious CGI Scripts Crash the Web Service
5745| [1007664] Apache::Gallery Unsafe Temporary Files May Let Local Users Gain Apache Web Server Privileges
5746| [1007557] Apache Web Server Does Not Filter Terminal Escape Sequences From Log Files
5747| [1007230] Apache HTTP Server 'rotatelogs' Bug on Win32 and OS/2 May Cause the Logging to Stop
5748| [1007146] Apache HTTP Server FTP Proxy Bug May Cause Denial of Service Conditions
5749| [1007145] Apache 'accept()' Errors May Cause Denial of Service Conditions
5750| [1007144] Apache Web Server 'type-map' File Error Permits Local Denial of Service Attacks
5751| [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
5752| [1006864] Apache Web Server Can Be Crashed By Remote Users Via mod_dav Flaws and Also Via Basic Authentication
5753| [1006709] Apache mod_survey Input Validation Flaw Lets Remote Users Fill Up Disk Space
5754| [1006614] Apache mod_ntlm Buffer Overflow and Format String Flaw Let Remote Users Execute Arbitary Code
5755| [1006591] Apache mod_access_referer Module Null Pointer Dereference May Faciliate Denial of Service Attacks
5756| [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
5757| [1006021] Apache Tomcat Server URL Parsing Error May Disclose Otherwise Inaccessible Web Directory Listings and Files to Remote Users
5758| [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
5759| [1005962] Apache Web Server Path Parsing Flaw May Allow Remote Users to Execute Code in Certain Configurations
5760| [1005848] Apache 'printenv' Script Input Validation Bugs in Older Versions May Let Remote Users Conduct Cross-Site Scripting Attacks
5761| [1005765] Apache mod_jk Module Processing Bug When Used With Tomcat May Disclose Information to Remote Users or Crash
5762| [1005548] Apache mod_php Module May Allow Local Users to Gain Control of the Web Port
5763| [1005499] Apache Web Server (2.0.42) May Disclose CGI Source Code to Remote Users When Used With WebDAV
5764| [1005410] Apache Tomcat Java Servlet Engine Can Be Crashed Via Multiple Requests for DOS Device Names
5765| [1005351] Apache Web Server (1.3.x) Shared Memory Scoreboard Bug Lets Certain Local Users Issue Signals With Root Privileges
5766| [1005331] Apache Web Server (2.x) SSI Server Signature Filtering Hole Lets Remote Users Conduct Cross-Site Scripting Attacks
5767| [1005290] Apache Tomcat Java Server Default Servlet Returns JSP Source Code to Remote Users
5768| [1005285] Apache Web Server 'mod_dav' Has Null Pointer Bug That May Allow Remote Users to Cause Denial of Service Conditions
5769| [1005010] Apache Web Server (2.0) Has Unspecified Flaw That Allows Remote Users to Obtain Sensitive Data and Cause Denial of Service Conditions
5770| [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
5771| [1004745] Apache Tomcat Java Server Allows Cross-Site Scripting Attacks
5772| [1004636] Apache mod_ssl 'Off-by-One' Bug May Let Local Users Crash the Web Server or Possibly Execute Arbitrary Code
5773| [1004602] Apache Tomcat Java Server for Windows Can Be Crashed By Remote Users Sending Malicious Requests to Hang All Available Working Threads
5774| [1004586] Apache Tomcat Java Server May Disclose the Installation Path to Remote Users
5775| [1004555] Apache Web Server Chunked Encoding Flaw May Let Remote Users Execute Arbitrary Code on the Server
5776| [1004209] Apache 'mod_python' Python Language Interpreter Bug in Publisher Handler May Allow Remote Users to Modify Files on the System
5777| [1003874] Apache Web Server for Windows Has Batch File Processing Hole That Lets Remote Users Execute Commands on the System
5778| [1003767] 'mod_frontpage' Module for Apache Web Server Has Buffer Overlow in 'fpexec.c' That Allows Remote Users to Execute Arbitrary Code on the System with Root Privileges
5779| [1003723] Apache-SSL for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
5780| [1003664] 'mod_ssl' Security Package for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
5781| [1003602] GNUJSP Java Server Pages Implementation Discloses Web Files and Source Code to Remote Users and Bypasses Apache Access Control Restrictions
5782| [1003465] PHP for Apache Web Server May Disclose Installation Path Information to Remote Users Making 'OPTIONS' Requests
5783| [1003451] Oracle Application Server PL/SQL Module for Apache Has Buffer Overflows That Allow Remote Users to Execute Arbitrary Code and Gain Access to the Server
5784| [1003131] Apache Web Server in Virtual Hosting Mode Can Be Crashed By a Local User Removing a Log Directory
5785| [1003104] PHP.EXE Windows CGI for Apache Web Server May Let Remote Users View Files on the Server Due to Configuration Error
5786| [1003008] Apache 'mod_bf' Module Lets Remote Users Execute Arbitrary Code
5787| [1002629] Apache suEXEC Wrapper Fails to Observe Minimum Group ID Security Settings in Certain Situations
5788| [1002542] Apache Web Server Virtual Hosting Split-Logfile Function Lets Remote Users Write Log Entries to Arbitrary Files on the System
5789| [1002400] Apache mod_gzip Module Has Buffer Overflow That Can Be Exploited By Local Users to Gain Elevated Privileges
5790| [1002303] Several 3rd Party Apache Authentication Modules Allow Remote Users to Execute Arbitrary Code to Gain Access to the System or Execute Stored Procedures to Obtain Arbitrary Database Information
5791| [1002188] Apache Web Server Discloses Internal IP Addresses to Remote Users in Certain Configurations
5792| [1001989] Apache Web Server May Disclose Directory Contents Even If an Index.html File is Present in the Directory
5793| [1001719] Apache Web Server on Mac OS X Client Fails to Enforce File and Directory Access Protections, Giving Remote Users Access to Restricted Pages
5794| [1001572] Apache Web Server on Microsoft Windows Platforms Allows Remote Users to Crash the Web Server
5795| [1001304] Apache Web Server for Windows Lets Remote Users Crash the Web Server Application
5796| [1001083] Apache Web Server May Display Directory Index Listings Even if Directory Listings Are Disabled
5797|
5798| OSVDB - http://www.osvdb.org:
5799| [96078] Apache CloudStack Infrastructure Menu Setup Network Multiple Field XSS
5800| [96077] Apache CloudStack Global Settings Multiple Field XSS
5801| [96076] Apache CloudStack Instances Menu Display Name Field XSS
5802| [96075] Apache CloudStack Instances Menu Add Instances Network Name Field XSS
5803| [96074] Apache CloudStack Instances Menu Add Instances Review Step Multiple Field XSS
5804| [96031] Apache HTTP Server suEXEC Symlink Arbitrary File Access
5805| [95888] Apache Archiva Single / Double Quote Character Handling XSS Weakness
5806| [95885] Apache Subversion mod_dav_svn Module Crafted HTTP Request Handling Remote DoS
5807| [95706] Apache OpenOffice.org (OOo) OOXML Document File XML Element Handling Memory Corruption
5808| [95704] Apache OpenOffice.org (OOo) DOC File PLCF Data Handling Memory Corruption
5809| [95603] Apache Continuum web/util/GenerateRecipentNotifier.java recipient Parameter XSS
5810| [95602] Apache Continuum web/action/notifier/JabberProjectNotifierEditAction-jabberProjectNotifierSave-validation.xml Multiple Parameter XSS
5811| [95601] Apache Continuum web/action/notifier/JabberGroupNotifierEditAction-jabberProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
5812| [95600] Apache Continuum web/action/ScheduleAction-saveSchedule-validation.xml Multiple Parameter XSS
5813| [95599] Apache Continuumweb/action/BuildDefinitionAction-saveBuildDefinition-validation.xml Multiple Parameter XSS
5814| [95598] Apache Continuum web/action/AddProjectAction-addProject-validation.xml Multiple Parameter XSS
5815| [95597] Apache Continuum web/action/ProjectEditAction-projectSave-validation.xml Multiple Parameter XSS
5816| [95596] Apache Continuum web/action/notifier/IrcGroupNotifierEditAction-ircProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
5817| [95595] Apache Continuum web/action/notifier/IrcProjectNotifierEditAction-ircProjectNotifierSave-validation.xml Multiple Parameter XSS
5818| [95594] Apache Continuum web/action/ProjectGroupAction.java Multiple Parameter XSS
5819| [95593] Apache Continuum web/action/AddProjectGroupAction.java Multiple Parameter XSS
5820| [95592] Apache Continuum web/action/AddProjectAction.java Multiple Parameter XSS
5821| [95523] Apache OFBiz Webtools Application View Log Screen Unspecified XSS
5822| [95522] Apache OFBiz Nested Expression Evaluation Arbitrary UEL Function Execution
5823| [95521] Apache HTTP Server mod_session_dbd Session Saving Unspecified Issue
5824| [95498] Apache HTTP Server mod_dav.c Crafted MERGE Request Remote DoS
5825| [95406] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Arbitrary Site Redirect
5826| [95405] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Remote Code Execution
5827| [95011] Apache CXF XML Parser SOAP Message Handling CPU Resource Exhaustion Remote DoS
5828| [94705] Apache Geronimo RMI Classloader Exposure Serialized Object Handling Remote Code Execution
5829| [94651] Apache Santuario (XML Security for C++) XML Signature CanonicalizationMethod Parameter Spoofing Weakness
5830| [94636] Apache Continuum workingCopy.action userDirectory Traversal Arbitrary File Access
5831| [94635] Apache Maven SCM SvnCommandlineUtils Process Listing Local Password Disclosure
5832| [94632] Apache Maven Wagon SSH (wagon-ssh) Host Verification Failure MitM Weakness
5833| [94625] Apache Santuario (XML Security for C++) XML Signature Reference Crafted XPointer Expression Handling Heap Buffer Overflow
5834| [94618] Apache Archiva /archiva/security/useredit.action username Parameter XSS
5835| [94617] Apache Archiva /archiva/security/roleedit.action name Parameter XSS
5836| [94616] Apache Archiva /archiva/security/userlist!show.action roleName Parameter XSS
5837| [94615] Apache Archiva /archiva/deleteArtifact!doDelete.action groupId Parameter XSS
5838| [94614] Apache Archiva /archiva/admin/addLegacyArtifactPath!commit.action legacyArtifactPath.path Parameter XSS
5839| [94613] Apache Archiva /archiva/admin/addRepository.action Multiple Parameter XSS
5840| [94612] Apache Archiva /archiva/admin/editAppearance.action Multiple Parameter XSS
5841| [94611] Apache Archiva /archiva/admin/addLegacyArtifactPath.action Multiple Parameter XSS
5842| [94610] Apache Archiva /archiva/admin/addNetworkProxy.action Multiple Parameter XSS
5843| [94403] Apache Santuario (XML Security for C++) InclusiveNamespace PrefixList Processing Heap Overflow
5844| [94402] Apache Santuario (XML Security for C++) HMAC-based XML Signature Processing DoS
5845| [94401] Apache Santuario (XML Security for C++) XPointer Evaluation Stack Overflow
5846| [94400] Apache Santuario (XML Security for C++) HMAC-Based XML Signature Reference Element Validation Spoofing Weakness
5847| [94279] Apache Qpid CA Certificate Validation Bypass
5848| [94275] Apache Solr JettySolrRunner.java Can Not Find Error Message XSS
5849| [94233] Apache OpenJPA Object Deserialization Arbitrary Executable Creation
5850| [94042] Apache Axis JAX-WS Java Unspecified Exposure
5851| [93969] Apache Struts OGNL Expression Handling Double Evaluation Error Remote Command Execution
5852| [93796] Apache Subversion Filename Handling FSFS Repository Corruption Remote DoS
5853| [93795] Apache Subversion svnserve Server Aborted Connection Message Handling Remote DoS
5854| [93794] Apache Subversion contrib/hook-scripts/check-mime-type.pl svnlook Hyphenated argv Argument Handling Remote DoS
5855| [93793] Apache Subversion contrib/hook-scripts/svn-keyword-check.pl Filename Handling Remote Command Execution
5856| [93646] Apache Struts Crafted Parameter Arbitrary OGNL Code Execution
5857| [93645] Apache Struts URL / Anchor Tag includeParams Attribute Remote Command Execution
5858| [93636] Apache Pig Multiple Physical Operator Memory Exhaustion Remote Remote DoS
5859| [93635] Apache Wink DTD (Document Type Definition) Expansion Data Parsing Information Disclosure
5860| [93605] RT Apache::Session::File Session Replay Reuse Information Disclosure
5861| [93599] Apache Derby SYSCS_UTIL.SYSCS_SET_DATABASE_PROPERTY Boot Password Manipulation Re-encryption Failure Password Corruption
5862| [93555] Apache Commons Codec Invalid Base32 String Information Tunneling Weakness
5863| [93554] Apache HBase bulkLoadHFiles() Method ACL Bypass
5864| [93543] JBoss Enterprise Application Platform org.apache.catalina.connector.Response.encodeURL() Method MitM jsessionid Disclosure
5865| [93542] Apache ManifoldCF (Connectors Framework) org.apache.manifoldcf.crawler.ExportConfiguration Class Configuration Export Password Disclosure
5866| [93541] Apache Solr json.wrf Callback XSS
5867| [93524] Apache Hadoop GetSecurityDescriptorControl() Function Absolute Security Descriptor Handling NULL Descriptor Weakness
5868| [93521] Apache jUDDI Security API Token Session Persistence Weakness
5869| [93520] Apache CloudStack Default SSL Key Weakness
5870| [93519] Apache Shindig /ifr Cross-site Arbitrary Gadget Invocation
5871| [93518] Apache Solr /admin/analysis.jsp name Parameter XSS
5872| [93517] Apache CloudStack setup-cloud-management /etc/sudoers Modification Local Privilege Escalation
5873| [93516] Apache CXF UsernameTokenInterceptor Nonce Caching Replay Weakness
5874| [93515] Apache HBase table.jsp name Parameter XSS
5875| [93514] Apache CloudStack Management Server Unauthenticated Remote JMX Connection Default Setting Weakness
5876| [93463] Apache Struts EL / OGNL Interpretation Unspecified Remote Code Execution
5877| [93462] Apache CXF WS-SecurityPolicy AlgorithmSuite Arbitrary Ciphertext Decryption Weakness
5878| [93401] Apache Hadoop core-site.xml Permission Weakness Local Alfredo Secret Disclosure
5879| [93400] Apache Hadoop Map/Reduce Job Log Directory Symlink Arbitrary File Mode Manipulation
5880| [93397] Apache Wicket Referrer HTTP Header Session ID Disclosure
5881| [93366] Apache HTTP Server modules/mappers/mod_rewrite.c do_rewritelog() Function Log File Terminal Escape Sequence Filtering Remote Command Execution
5882| [93254] Apache Tomcat AsyncListener Method Cross-session Information Disclosure
5883| [93253] Apache Tomcat Chunked Transfer Encoding Data Saturation Remote DoS
5884| [93252] Apache Tomcat FORM Authenticator Session Fixation
5885| [93172] Apache Camel camel/endpoints/ Endpoint XSS
5886| [93171] Apache Sling HtmlResponse Error Message XSS
5887| [93170] Apache Directory DelegatingAuthenticator MitM Spoofing Weakness
5888| [93169] Apache Wave AuthenticationServlet.java Session Fixation Weakness
5889| [93168] Apache Click ErrorReport.java id Parameter XSS
5890| [93167] Apache ActiveMQ JMSXUserId Spoofing Weakness
5891| [93166] Apache CXF Crafted Message Element Count Handling System Resource Exhaustion Remote DoS
5892| [93165] Apache CXF Crafted Message Element Level Handling System Resource Exhaustion Remote DoS
5893| [93164] Apache Harmony DatagramSocket Class connect Method CheckAccept() IP Blacklist Bypass
5894| [93163] Apache Hadoop Map/Reduce Daemon Symlink Arbitrary File Overwrite
5895| [93162] Apache VelocityStruts struts/ErrorsTool.getMsgs Error Message XSS
5896| [93161] Apache CouchDB Rewriter VM Atom Table Memory Exhaustion Remote DoS
5897| [93158] Apache Wicket BookmarkablePageLink Feature XSS CSRF
5898| [93157] Apache Struts UrlHelper.java s:url includeParams Functionality XSS
5899| [93156] Apache Tapestry Calendar Component datefield.js datefield Parameter XSS
5900| [93155] Apache Struts fielderror.ftl fielderror Parameter Error Message XSS
5901| [93154] Apache JSPWiki Edit.jsp createPages WikiPermission Bypass
5902| [93153] Apache PDFBox PDFXrefStreamParser Missing Element Handling PDF Parsing DoS
5903| [93152] Apache Hadoop HttpServer.java Multiple Function XSS
5904| [93151] Apache Shiro Search Filter userName Parameter LDAP Code Injection Weakness
5905| [93150] Apache Harmony java.net.SocketPermission Class boolean equals Function checkConnect() Weakness Host Name Retrieval
5906| [93149] Apache Harmony java.security.Provider Class void load Function checkSecurityAccess() Weakness
5907| [93148] Apache Harmony java.security.ProtectionDomain Class java.lang.String.toString() Function checkPermission() Weakness
5908| [93147] Apache Harmony java.net.URLConnection openConnection Function checkConnect Weakness Proxy Connection Permission Bypass
5909| [93146] Apache Harmony java.net.ServerSocket Class void implAccept Function checkAccept() Weakness SerSocket Subclass Creation
5910| [93145] Apache Qpid JMS Client Detached Session Frame Handling NULL Pointer Dereference Remote DoS
5911| [93144] Apache Solr Admin Command Execution CSRF
5912| [93009] Apache VCL XMLRPC API Unspecified Function Remote Privilege Escalation
5913| [93008] Apache VCL Web GUI Unspecified Remote Privilege Escalation
5914| [92997] Apache Commons Codec org.apache.commons.codec.net.URLCodec Fields Missing 'final' Thread-safety Unspecified Issue
5915| [92976] Apache ActiveMQ scheduled.jsp crontab Command XSS
5916| [92947] Apache Commons Codec org.apache.commons.codec.language.Soundex.US_ENGLISH_MAPPING Missing MS_PKGPROTECT Field Manipulation Unspecified Issue
5917| [92749] Apache CloudStack Predictable Hash Virtual Machine Console Console Access URL Generation
5918| [92748] Apache CloudStack VM Console Access Restriction Bypass
5919| [92709] Apache ActiveMQ Web Console Unauthenticated Remote Access
5920| [92708] Apache ActiveMQ Sample Web Application Broker Resource Consumption Remote DoS
5921| [92707] Apache ActiveMQ webapp/websocket/chat.js Subscribe Message XSS
5922| [92706] Apache ActiveMQ Debug Log Rendering XSS
5923| [92705] Apache ActiveMQ PortfolioPublishServlet.java refresh Parameter XSS
5924| [92270] Apache Tomcat Unspecified CSRF
5925| [92094] Apache Subversion mod_dav_svn Module Nonexistent URL Lock Request Handling NULL Pointer Dereference Remote DoS
5926| [92093] Apache Subversion mod_dav_svn Module Activity URL PROPFIND Request Handling NULL Pointer Dereference Remote DoS
5927| [92092] Apache Subversion mod_dav_svn Module Log REPORT Request Handling NULL Pointer Dereference Remote DoS
5928| [92091] Apache Subversion mod_dav_svn Module Node Property Handling Resource Exhaustion Remote DoS
5929| [92090] Apache Subversion mod_dav_svn Module Activity URL Lock Request Handling NULL Pointer Dereference Remote DoS
5930| [91774] Apache Commons Codec Unspecified Non-private Field Manipulation Weakness
5931| [91628] mod_ruid2 for Apache HTTP Server fchdir() Inherited File Descriptor chroot Restriction Bypass
5932| [91328] Apache Wicket $up$ Traversal Arbitrary File Access
5933| [91295] Apple Mac OS X Apache Unicode Character URI Handling Authentication Bypass
5934| [91235] Apache Rave /app/api/rpc/users/get User Object Hashed Password Remote Disclosure
5935| [91185] Munin Default Apache Configuration Permission Weakness Remote Information Disclosure
5936| [91173] Apache Wicket WebApplicationPath Constructor Bypass /WEB-INF/ Directory File Access
5937| [91172] Apache Wicket PackageResourceGuard File Extension Filter Bypass
5938| [91025] Apache Qpid qpid::framing::Buffer Class Multiple Method Out-of-bounds Access Remote DoS
5939| [91024] Apache Qpid federation_tag Attribute Handling Federated Interbroker Link Access Restriction Bypass
5940| [91023] Apache Qpid AMQP Type Decoder Exposure Array Size Value Handling Memory Consumption Remote DoS
5941| [91022] Apache Qpid qpid/cpp/include/qpid/framing/Buffer.h qpid::framing::Buffer::checkAvailable() Function Integer Overflow
5942| [90986] Apache Jena ARQ INSERT DATA Request Handling Overflow
5943| [90907] Apache Subversion mod_dav_svn / libsvn_fs svn_fs_file_length() Function MKACTIVITY / PROPFIND Option Request Handling Remote DoS
5944| [90906] Apache Commons FileUpload /tmp Storage Symlink Arbitrary File Overwrite
5945| [90864] Apache Batik 1xx Redirect Script Origin Restriction Bypass
5946| [90858] Apache Ant Malformed TAR File Handling Infinite Loop DoS
5947| [90852] Apache HTTP Server for Debian apachectl /var/lock Permission Weakness Symlink Directory Permission Manipulation
5948| [90804] Apache Commons CLI Path Subversion Local Privilege Escalation
5949| [90802] Apache Avro Recursive Schema Handling Infinite Recursion DoS
5950| [90592] Apache Batik ApplicationSecurityEnforcer.java Multiple Method Security Restriction Bypass
5951| [90591] Apache Batik XML External Entity (XXE) Data Parsing Arbitrary File Disclosure
5952| [90565] Apache Tomcat Log Directory Permission Weakness Local Information Disclosure
5953| [90564] Apache Maven / Maven Wagon SSL Certificate Validation MitM Spoofing Weakness
5954| [90557] Apache HTTP Server mod_proxy_balancer balancer-manager Interface Multiple Parameter XSS
5955| [90556] Apache HTTP Server Multiple Module Multiple Parameter XSS
5956| [90276] Apache Axis2 axis2.xml Plaintext Password Local Disclosure
5957| [90249] Apache Axiom ClassLoader XMLInputFactory / XMLOutputFactory Construction Unspecified Issue
5958| [90235] Apache Commons HttpClient Certificate Wildcard Matching Weakness
5959| [90079] Apache CXF WSS4JInInterceptor URIMappingInterceptor WS-Security SOAP Service Access Restriction Bypass
5960| [90078] Apache CXF WS-SecurityPolicy Enabled Plaintext UsernameTokens Handling Authentication Bypass
5961| [89453] Apache Open For Business Project (OFBiz) Screenlet.title Widget Attribute XSS
5962| [89452] Apache Open For Business Project (OFBiz) Image.alt Widget Attribute XSS
5963| [89294] Apache CouchDB Futon UI Browser-based Test Suite Query Parameter XSS
5964| [89293] Apache CouchDB Unspecified Traversal Arbitrary File Access
5965| [89275] Apache HTTP Server mod_proxy_ajp Module Expensive Request Parsing Remote DoS
5966| [89267] Apache CouchDB JSONP Callback Handling Unspecified XSS
5967| [89146] Apache CloudStack Master Server log4j.conf SSH Private Key / Plaintext Password Disclosure
5968| [88603] Apache OpenOffice.org (OOo) Unspecified Information Disclosure
5969| [88602] Apache OpenOffice.org (OOo) Unspecified Manifest-processing Issue
5970| [88601] Apache OpenOffice.org (OOo) Unspecified PowerPoint File Handling Issue
5971| [88285] Apache Tomcat Partial HTTP Request Saturation Remote DoS
5972| [88095] Apache Tomcat NIO Connector Terminated Connection Infinte Loop DoS
5973| [88094] Apache Tomcat FORM Authentication Crafted j_security_check Request Security Constraint Bypass
5974| [88093] Apache Tomcat Null Session Requst CSRF Prevention Filter Bypass
5975| [88043] IBM Tivoli Netcool/Reporter Apache CGI Unspecified Remote Command Execution
5976| [87580] Apache Tomcat DIGEST Authentication Session State Caching Authentication Bypass Weakness
5977| [87579] Apache Tomcat DIGEST Authentication Stale Nonce Verification Authentication Bypass Weakness
5978| [87477] Apache Tomcat Project Woodstock Service Error Page UTF-7 XSS Weakness
5979| [87227] Apache Tomcat InternalNioInputBuffer.java parseHeaders() Function Request Header Size Parsing Remote DoS
5980| [87223] Apache Tomcat DIGEST Authentication replay-countermeasure Functionality cnonce / cn Verification Authentication Bypass Weakness
5981| [87160] Apache Commons HttpClient X.509 Certificate Domain Name Matching MiTM Weakness
5982| [87159] Apache CXF X.509 Certificate Domain Name Matching MiTM Weakness
5983| [87150] Apache Axis / Axis2 X.509 Certificate Domain Name Matching MiTM Weakness
5984| [86902] Apache HTTP Server 3xx Redirect Internal IP Address Remote Disclosure
5985| [86901] Apache Tomcat Error Message Path Disclosure
5986| [86684] Apache CloudStack Unauthorized Arbitrary API Call Invocation
5987| [86556] Apache Open For Business Project (OFBiz) Unspecified Issue
5988| [86503] Visual Tools VS home/apache/DiskManager/cron/init_diskmgr Local Command Execution
5989| [86401] Apache ActiveMQ ResourceHandler Traversal Arbitrary File Access
5990| [86225] Apache Axis2 XML Signature Wrapping (XSW) Authentication Bypass
5991| [86206] Apache Axis2 Crafted SAML Assertion Signature Exclusion Attack Authentication Bypass
5992| [85722] Apache CXF SOAP Request Parsing Access Restriction Bypass
5993| [85704] Apache Qpid Incoming Client Connection Saturation Remote DoS
5994| [85474] Eucalyptus Apache Santuario (XML Security for Java) Library XML Signature Transform Handling DoS
5995| [85430] Apache mod_pagespeed Module Unspecified XSS
5996| [85429] Apache mod_pagespeed Module Hostname Verification Cross-host Resource Disclosure
5997| [85249] Apache Wicket Unspecified XSS
5998| [85236] Apache Hadoop conf/hadoop-env.sh Temporary File Symlink Arbitrary File Manipulation
5999| [85090] Apache HTTP Server mod_proxy_ajp.c mod_proxy_ajp Module Proxy Functionality Cross-client Information Disclosure
6000| [85089] Apache HTTP Server mod_proxy_http.c mod_proxy_http Module Cross-client Information Disclosure
6001| [85062] Apache Solr Autocomplete Module for Drupal Autocomplete Results XSS
6002| [85010] Apache Struts Token Handling Mechanism Token Name Configuration Parameter CSRF Weakness
6003| [85009] Apache Struts Request Parameter OGNL Expression Parsing Remote DoS
6004| [84911] libapache2-mod-rpaf X-Forward-For HTTP Header Parsing Remote DoS
6005| [84823] Apache HTTP Server Multiple Module Back End Server Error Handling HTTP Request Parsing Remote Information Disclosure
6006| [84818] Apache HTTP Server mod_negotiation Module mod_negotiation.c make_variant_list Function XSS
6007| [84562] Apache Qpid Broker Authentication Mechanism AMQP Client Shadow Connection NullAuthenticator Request Parsing Authentication Bypass
6008| [84458] Apache Libcloud SSL Certificate Validation MitM Spoofing Weakness
6009| [84279] PHP on Apache php_default_post_reader POST Request Handling Overflow DoS
6010| [84278] PHP w/ Apache PDO::ATTR_DEFAULT_FETCH_MODE / PDO::FETCH_CLASS DoS
6011| [84231] Apache Hadoop DataNodes Client BlockTokens Arbitrary Block Access
6012| [83943] Oracle Solaris Cluster Apache Tomcat Agent Subcomponent Unspecified Local Privilege Escalation
6013| [83939] Oracle Solaris Apache HTTP Server Subcomponent Unspecified Remote Information Disclosure
6014| [83685] svnauthcheck Apache HTTP Configuration File Permission Revocation Weakness
6015| [83682] Apache Sling POST Servlet @CopyFrom Operation HTTP Request Parsing Infinite Loop Remote DoS
6016| [83339] Apache Roller Blogger Roll Unspecified XSS
6017| [83270] Apache Roller Unspecified Admin Action CSRF
6018| [82782] Apache CXF WS-SecurityPolicy 1.1 SupportingToken Policy Bypass
6019| [82781] Apache CXF WS-SecurityPolicy Supporting Token Children Specification Token Signing Verification Weakness
6020| [82611] cPanel Apache Piped Log Configuration Log Message Formatting Traversal Arbitrary File Creation
6021| [82436] MapServer for Windows Bundled Apache / PHP Configuration Local File Inclusion
6022| [82215] PHP sapi/cgi/cgi_main.c apache_request_headers Function HTTP Header Handling Remote Overflow
6023| [82161] Apache Commons Compress bzip2 File Compression BZip2CompressorOutputStream Class File Handling Remote DoS
6024| [81965] Apache Batik Squiggle SVG Browser JAR File Arbitrary Code Execution
6025| [81790] Apache POI src/org/apache/poi/hwpf/model/UnhandledDataStructure.java UnhandledDataStructure() constructor Length Attribute CDF / CFBF File Handling Remote DoS
6026| [81660] Apache Qpid Credential Checking Cluster Authentication Bypass
6027| [81511] Apache for Debian /usr/share/doc HTTP Request Parsing Local Script Execution
6028| [81359] Apache HTTP Server LD_LIBRARY_PATH Variable Local Privilege Escalation
6029| [81349] Apache Open For Business Project (OFBiz) Webslinger Component Unspecified XSS
6030| [81348] Apache Open For Business Project (OFBiz) Content IDs / Map-Keys Unspecified XSS
6031| [81347] Apache Open For Business Project (OFBiz) Parameter Arrays Unspecified XSS
6032| [81346] Apache Open For Business Project (OFBiz) checkoutProcess.js getServerError() Function Unspecified XSS
6033| [81196] Apache Open For Business Project (OFBiz) FlexibleStringExpander Nested Script String Parsing Remote Code Execution
6034| [80981] Apache Hadoop Kerberos/MapReduce Security Feature User Impersonation Weakness
6035| [80571] Apache Traffic Server Host HTTP Header Parsing Remote Overflow
6036| [80547] Apache Struts XSLTResult.java File Upload Arbitrary Command Execution
6037| [80360] AskApache Password Protector Plugin for WordPress Error Page $_SERVER Superglobal XSS
6038| [80349] Apache HTTP Server mod_fcgid Module fcgid_spawn_ctl.c FcgidMaxProcessesPerClass Virtual Host Directive HTTP Request Parsing Remote DoS
6039| [80301] Apache Wicket /resources/ Absolute Path Arbitrary File Access
6040| [80300] Apache Wicket wicket:pageMapName Parameter XSS
6041| [79478] Apache Solr Extension for TYPO3 Unspecified XSS
6042| [79002] Apache MyFaces javax.faces.resource In Parameter Traversal Arbitrary File Access
6043| [78994] Apache Struts struts-examples/upload/upload-submit.do name Parameter XSS
6044| [78993] Apache Struts struts-cookbook/processDyna.do message Parameter XSS
6045| [78992] Apache Struts struts-cookbook/processSimple.do message Parameter XSS
6046| [78991] Apache Struts struts2-rest-showcase/orders clientName Parameter XSS
6047| [78990] Apache Struts struts2-showcase/person/editPerson.action Multiple Parameter XSS
6048| [78932] Apache APR Hash Collision Form Parameter Parsing Remote DoS
6049| [78903] Apache CXF SOAP Request Parsing WS-Security UsernameToken Policy Bypass
6050| [78600] Apache Tomcat HTTP DIGEST Authentication DigestAuthenticator.java Catalina Weakness Security Bypass
6051| [78599] Apache Tomcat HTTP DIGEST Authentication Realm Value Parsing Security Bypass
6052| [78598] Apache Tomcat HTTP DIGEST Authentication qop Value Parsing Security Bypass
6053| [78573] Apache Tomcat Parameter Saturation CPU Consumption Remote DoS
6054| [78556] Apache HTTP Server Status Code 400 Default Error Response httpOnly Cookie Disclosure
6055| [78555] Apache HTTP Server Threaded MPM %{cookiename}C Log Format String Cookie Handling Remote DoS
6056| [78501] Apache Struts ParameterInterceptor Class OGNL Expression Parsing Remote Command Execution
6057| [78331] Apache Tomcat Request Object Recycling Information Disclosure
6058| [78293] Apache HTTP Server Scoreboard Invalid Free Operation Local Security Bypass
6059| [78277] Apache Struts ExceptionDelegator Component Parameter Parsing Remote Code Execution
6060| [78276] Apache Struts DebuggingInterceptor Component Developer Mode Unspecified Remote Command Execution
6061| [78113] Apache Tomcat Hash Collision Form Parameter Parsing Remote DoS
6062| [78112] Apache Geronimo Hash Collision Form Parameter Parsing Remote DoS
6063| [78109] Apache Struts ParameterInterceptor Traversal Arbitrary File Overwrite
6064| [78108] Apache Struts CookieInterceptor Cookie Name Handling Remote Command Execution
6065| [77593] Apache Struts Conversion Error OGNL Expression Injection
6066| [77496] Apache ActiveMQ Failover Mechanism Openwire Request Parsing Remote DoS
6067| [77444] Apache HTTP Server mod_proxy Mdule Web Request HTTP/0.9 Protocol URL Parsing Proxy Remote Security Bypass
6068| [77374] Apache MyFaces Java Bean includeViewParameters Parsing EL Expression Security Weakness
6069| [77310] Apache HTTP Server mod_proxy Reverse Proxy Mode Security Bypass Weakness (2011-4317)
6070| [77234] Apache HTTP Server on cygwin Encoded Traversal Arbitrary File Access
6071| [77012] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Memory Consumption DoS
6072| [76944] Apache Tomcat Manager Application Servlets Access Restriction Bypass
6073| [76744] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Overflow
6074| [76189] Apache Tomcat HTTP DIGEST Authentication Weakness
6075| [76079] Apache HTTP Server mod_proxy Mdule Web Request URL Parsing Proxy Remote Security Bypass (2011-3368)
6076| [76072] Apache JServ jserv.conf jserv-status Handler jserv/ URI Request Parsing Local Information Disclosure
6077| [75807] Apache HTTP Server Incomplete Header Connection Saturation Remote DoS
6078| [75647] Apache HTTP Server mod_proxy_ajp Module mod_proxy_balancer HTTP Request Remote DoS
6079| [75376] Apache Libcloud SSL Certificate Validation MitM Server Spoofing Weakness
6080| [74853] Domain Technologie Control /etc/apache2/apache2.conf File Permissions Weakness dtcdaemons User Password Disclosure
6081| [74818] Apache Tomcat AJP Message Injection Authentication Bypass
6082| [74725] Apache Wicket Multi Window Support Unspecified XSS
6083| [74721] Apache HTTP Server ByteRange Filter Memory Exhaustion Remote DoS
6084| [74541] Apache Commons Daemon Jsvc Permissions Weakness Arbitrary File Access
6085| [74535] Apache Tomcat XML Parser Cross-application Multiple File Manipulation
6086| [74447] Apache Struts XWork Nonexistent Method s:submit Element Internal Java Class Remote Path Disclosure
6087| [74262] Apache HTTP Server Multi-Processing Module itk.c Configuration Merger mpm-itk root UID / GID Remote Privilege Escalation
6088| [74120] Apache HTTP Server mod_authnz_external mysql/mysql-auth.pl user Field SQL Injection
6089| [73920] Oracle Secure Backup /apache/htdocts/php/common.php username Parameter Remote Code Execution
6090| [73798] Apache Tomcat sendfile Request Start / Endpoint Parsing Local DoS
6091| [73797] Apache Tomcat sendfile Request Attribute Validation Weakness Local Access Restriction Bypass
6092| [73776] Apache Tomcat HTTP BIO Connector HTTP Pipelining Cross-user Remote Response Access
6093| [73644] Apache XML Security Signature Key Parsing Overflow DoS
6094| [73600] Apache Struts javatemplates Plugin Component Handlers .action URI Multiple Parameter XSS
6095| [73462] Apache Rampart/C util/rampart_timestamp_token.c rampart_timestamp_token_validate Function Expired Token Remote Access Restriction Bypass
6096| [73429] Apache Tomcat JMX MemoryUserDatabase Local Password Disclosure
6097| [73384] Apache HTTP Server mod_rewrite PCRE Resource Exhaustion DoS
6098| [73383] Apache HTTP Server Portable Runtime (APR) Library apr_fnmatch() Infinite Loop Remote DoS
6099| [73378] IBM WebSphere Application Server (WAS) JavaServer Pages org.apache.jasper.runtime.JspWriterImpl.response JSP Page Application Restart Remote DoS
6100| [73247] Apache Subversion mod_dav_svn File Permission Weakness Information Disclosure
6101| [73246] Apache Subversion mod_dav_svn Path-based Access Control Rule Handling Remote DoS
6102| [73245] Apache Subversion mod_dav_svn Baselined Resource Request Handling Remote DoS
6103| [73154] Apache Archiva Multiple Unspecified CSRF
6104| [73153] Apache Archiva /archiva/admin/deleteNetworkProxy!confirm.action proxyid Parameter XSS
6105| [72407] Apache Tomcat @ServletSecurity Initial Load Annotation Security Constraint Bypass Information Disclosure
6106| [72238] Apache Struts Action / Method Names <
6107| [71647] Apache HttpComponents HttpClient Proxy-Authorization Credentials Remote Disclosure
6108| [71558] Apache Tomcat SecurityManager ServletContext Attribute Traversal Arbitrary File Manipulation
6109| [71557] Apache Tomcat HTML Manager Multiple XSS
6110| [71075] Apache Archiva User Management Page XSS
6111| [71027] Apache Tomcat @ServletSecurity Annotation Security Constraint Bypass Information Disclosure
6112| [70925] Apache Continuum Project Pages Unspecified XSS (2011-0533)
6113| [70924] Apache Continuum Multiple Admin Function CSRF
6114| [70809] Apache Tomcat NIO HTTP Connector Request Line Processing DoS
6115| [70734] Apache CouchDB Request / Cookie Handling Unspecified XSS
6116| [70585] Oracle Fusion Middleware Oracle HTTP Server Apache Plugin Unspecified Remote Issue
6117| [70333] Apache Subversion rev_hunt.c blame Command Multiple Memory Leak Remote DoS
6118| [70332] Apache Subversion Apache HTTP Server mod_dav_svn repos.c walk FunctionSVNParentPath Collection Remote DoS
6119| [69659] Apache Archiva Admin Authentication Weakness Privilege Escalation
6120| [69520] Apache Archiva Administrator Credential Manipulation CSRF
6121| [69512] Apache Tomcat Set-Cookie Header HTTPOnly Flag Session Hijacking Weakness
6122| [69456] Apache Tomcat Manager manager/html/sessions Multiple Parameter XSS
6123| [69275] Apache mod_fcgid Module fcgid_bucket.c fcgid_header_bucket_read() Function Remote Overflow
6124| [69067] Apache Shiro URI Path Security Traversal Information Disclosure
6125| [68815] Apache MyFaces shared/util/StateUtils.java View State MAC Weakness Cryptographic Padding Remote View State Modification
6126| [68670] Apache Qpid C++ Broker Component broker/SessionAdapter.cpp SessionAdapter::ExchangeHandlerImpl::checkAlternate Function Exchange Alternate Remote DoS
6127| [68669] Apache Qpid cluster/Cluster.cpp Cluster::deliveredEvent Function Invalid AMQP Data Remote DoS
6128| [68662] Apache Axis2 dswsbobje.war Module Admin Account Default Password
6129| [68531] Apache Qpid qpidd sys/ssl/SslSocket.cpp Incomplete SSL Handshake Remote DoS
6130| [68327] Apache APR-util buckets/apr_brigade.c apr_brigade_split_line() Function Memory Consumption DoS
6131| [68314] Apache XML-RPC SAX Parser External Entity Information Disclosure
6132| [67964] Apache Traffic Server Transaction ID / Source Port Randomization Weakness DNS Cache Poisoning
6133| [67846] SUSE Lifecycle Management Server on SUSE Linux Enterprise apache2-slms Parameter Quoting CSRF
6134| [67294] Apache CXF XML SOAP Message Crafted Document Type Declaration Remote DoS
6135| [67240] Apache CouchDB Installation Page Direct Request Arbitrary JavaScript Code Execution CSRF
6136| [67205] Apache Derby BUILTIN Authentication Password Hash Generation Algorithm SHA-1 Transformation Password Substitution
6137| [66745] Apache HTTP Server Multiple Modules Pathless Request Remote DoS
6138| [66319] Apache Tomcat Crafted Transfer-Encoding Header Handling Buffer Recycling Remote DoS
6139| [66280] Apache Struts XWork ParameterInterceptor Server-Side Object Remote Code Execution
6140| [66226] Apache Axis2 Admin Interface Cookie Session Fixation
6141| [65697] Apache Axis2 / Java SOAP Message DTD Rejection Weakness Arbitrary File Access
6142| [65654] Apache HTTP Server mod_proxy_http mod_proxy_http.c Timeout Detection Weakness HTTP Request Response Disclosure
6143| [65429] Apache MyFaces Unencrypted ViewState Serialized View Object Manipulation Arbitrary Expression Language (EL) Statement Execution
6144| [65054] Apache ActiveMQ Jetty Error Handler XSS
6145| [64844] Apache Axis2/Java axis2/axis2-admin/engagingglobally modules Parameter XSS
6146| [64522] Apache Open For Business Project (OFBiz) ecommerce/control/contactus Multiple Parameter XSS
6147| [64521] Apache Open For Business Project (OFBiz) Web Tools Section entityName Parameter XSS
6148| [64520] Apache Open For Business Project (OFBiz) ecommerce/control/ViewBlogArticle contentId Parameter XSS
6149| [64519] Apache Open For Business Project (OFBiz) Control Servlet URI XSS
6150| [64518] Apache Open For Business Project (OFBiz) Show Portal Page Section start Parameter XSS
6151| [64517] Apache Open For Business Project (OFBiz) View Profile Section partyId Parameter XSS
6152| [64516] Apache Open For Business Project (OFBiz) Export Product Listing Section productStoreId Parameter XSS
6153| [64307] Apache Tomcat Web Application Manager/Host Manager CSRF
6154| [64056] mod_auth_shadow for Apache HTTP Server wait() Function Authentication Bypass
6155| [64023] Apache Tomcat WWW-Authenticate Header Local Host Information Disclosure
6156| [64020] Apache ActiveMQ Jetty ResourceHandler Crafted Request JSP File Source Disclosure
6157| [63895] Apache HTTP Server mod_headers Unspecified Issue
6158| [63368] Apache ActiveMQ createDestination.action JMSDestination Parameter CSRF
6159| [63367] Apache ActiveMQ createDestination.action JMSDestination Parameter XSS
6160| [63350] Apache CouchDB Hash Verification Algorithm Predictable Execution Time Weakness
6161| [63140] Apache Thrift Service Malformed Data Remote DoS
6162| [62676] Apache HTTP Server mod_proxy_ajp Module Crafted Request Remote DoS
6163| [62675] Apache HTTP Server Multi-Processing Module (MPM) Subrequest Header Handling Cross-thread Information Disclosure
6164| [62674] Apache HTTP Server mod_isapi Module Unloading Crafted Request Remote DoS
6165| [62231] Apache HTTP Server Logging Format Weakness Crafted DNS Response IP Address Spoofing
6166| [62230] Apache HTTP Server Crafted DNS Response Inverse Lookup Log Corruption XSS
6167| [62054] Apache Tomcat WAR Filename Traversal Work-directory File Deletion
6168| [62053] Apache Tomcat Autodeployment Process appBase File HTTP Request Authentication Bypass
6169| [62052] Apache Tomcat WAR File Traversal Arbitrary File Overwrite
6170| [62009] Apache HTTP Server src/modules/proxy/proxy_util.c mod_proxy ap_proxy_send_fb() Function Overflow
6171| [61379] Apache River Outrigger Entry Storage Saturation Memory Exhaustion DoS
6172| [61378] Apache Hadoop Map/Reduce JobTracker Memory Consumption DoS
6173| [61377] Apache Commons Modeler Multiple Mutable Static Fields Weakness
6174| [61376] Apache Rampart wsse:security Tag Signature Value Checking Weakness
6175| [60687] Apache C++ Standard Library (STDCXX) strxfrm() Function Overflow
6176| [60680] Apache Hadoop JobHistory Job Name Manipulation Weakness
6177| [60679] Apache ODE DeploymentWebService OMElement zipPart CRLF Injection
6178| [60678] Apache Roller Comment Email Notification Manipulation DoS
6179| [60677] Apache CouchDB Unspecified Document Handling Remote DoS
6180| [60428] Sun Java Plug-in org.apache.crimson.tree.XmlDocument Class reateXmlDocument Method Floppy Drive Access Bypass
6181| [60413] mod_throttle for Apache Shared Memory File Manipulation Local Privilege Escalation
6182| [60412] Sun Java Plug-in org.apache.xalan.processor.XSLProcessorVersion Class Unsigned Applet Variable Sharing Privilege Escalation
6183| [60396] Apache HTTP Server on OpenBSD Multipart MIME Boundary Remote Information Disclosure
6184| [60395] Apache HTTP Server on OpenBSD ETag HTTP Header Remote Information Disclosure
6185| [60232] PHP on Apache php.exe Direct Request Remote DoS
6186| [60176] Apache Tomcat Windows Installer Admin Default Password
6187| [60016] Apache HTTP Server on HP Secure OS for Linux HTTP Request Handling Unspecified Issue
6188| [59979] Apache HTTP Server on Apple Mac OS X HTTP TRACE Method Unspecified Client XSS
6189| [59969] Apache HTTP Server mod_ssl SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection
6190| [59944] Apache Hadoop jobhistory.jsp XSS
6191| [59374] Apache Solr Search Extension for TYPO3 Unspecified XSS
6192| [59022] Apache Shindig ConcatProxyServlet HTTP Header Response Splitting
6193| [59021] Apache Cocoon X-Cocoon-Version Header Remote Information Disclosure
6194| [59020] Apache Tapestry HTTPS Session Cookie Secure Flag Weakness
6195| [59019] Apache mod_python Cookie Salting Weakness
6196| [59018] Apache Harmony Error Message Handling Overflow
6197| [59013] Apache Derby SYSCS_EXPORT_TABLE Arbitrary File Overwrite
6198| [59012] Apache Derby Driver Auto-loading Non-deterministic Startup Weakness
6199| [59011] Apache JSPWiki Page Attachment Change Note Function XSS
6200| [59010] Apache Solr get-file.jsp XSS
6201| [59009] Apache Solr action.jsp XSS
6202| [59008] Apache Solr analysis.jsp XSS
6203| [59007] Apache Solr schema.jsp Multiple Parameter XSS
6204| [59006] Apache Beehive select / checkbox Tag XSS
6205| [59005] Apache Beehive jpfScopeID Global Parameter XSS
6206| [59004] Apache Beehive Error Message XSS
6207| [59003] Apache HttpClient POST Request Handling Memory Consumption DoS
6208| [59002] Apache Jetspeed default-page.psml URI XSS
6209| [59001] Apache Axis2 xsd Parameter Traversal Arbitrary File Disclosure
6210| [59000] Apache CXF Unsigned Message Policy Bypass
6211| [58999] Apache WSS4J CallbackHandler Plaintext Password Validation Weakness
6212| [58998] Apache OpenJPA persistence.xml Cleartext Password Local Disclosure
6213| [58997] Apache OpenEJB openejb.xml Cleartext Password Local Disclosure
6214| [58996] Apache Hadoop Map/Reduce LinuxTaskController File Group Ownership Weakness
6215| [58995] Apache Hadoop Map/Reduce Task Ownership Weakness
6216| [58994] Apache Hadoop Map/Reduce DistributedCache Localized File Permission Weakness
6217| [58993] Apache Hadoop browseBlock.jsp XSS
6218| [58991] Apache Hadoop browseDirectory.jsp XSS
6219| [58990] Apache Hadoop Map/Reduce HTTP TaskTrackers User Data Remote Disclosure
6220| [58989] Apache Hadoop Sqoop Process Listing Local Cleartext Password Disclosure
6221| [58988] Apache Hadoop Chukwa HICC Portal Unspecified XSS
6222| [58987] Apache Hadoop Map/Reduce TaskTracker User File Permission Weakness
6223| [58986] Apache Qpid Encrypted Message Handling Remote Overflow DoS
6224| [58985] Apache Qpid Process Listing Local Cleartext Password Disclosure
6225| [58984] Apache Jackrabbit Content Repository (JCR) Default Account Privilege Access Weakness
6226| [58983] Apache Jackrabbit Content Repository (JCR) NamespaceRegistry API Registration Method Race Condition
6227| [58982] Apache Synapse Proxy Service Security Policy Mismatch Weakness
6228| [58981] Apache Geronimo TomcatGeronimoRealm Security Context Persistence Weakness
6229| [58980] Apache Geronimo LDAP Realm Configuration Restart Reversion Weakness
6230| [58979] Apache MyFaces Tomahawk ExtensionsPhaseListener HTML Injection Information Disclosure
6231| [58978] Apache MyFaces Trinidad LocaleInfoScriptlet XSS
6232| [58977] Apache Open For Business Project (OFBiz) Multiple Default Accounts
6233| [58976] Apache Open For Business Project (OFBiz) URI passThru Parameter XSS
6234| [58975] Apache Open For Business Project (OFBiz) PARTYMGR_CREATE/UPDATE Permission Arbitrary User Password Modification
6235| [58974] Apache Sling /apps Script User Session Management Access Weakness
6236| [58973] Apache Tuscany Crafted SOAP Request Access Restriction Bypass
6237| [58931] Apache Geronimo Cookie Parameters Validation Weakness
6238| [58930] Apache Xalan-C++ XPath Handling Remote DoS
6239| [58879] Apache Portable Runtime (APR-util) poll/unix/port.c Event Port Backend Pollset Feature Remote DoS
6240| [58837] Apache Commons Net FTPSClient CipherSuites / Protocols Mutable Object Unspecified Data Security Issue
6241| [58813] Apache MyFaces Trinidad tr:table / HTML Comment Handling DoS
6242| [58812] Apache Open For Business Project (OFBiz) JSESSIONID Session Hijacking Weakness
6243| [58811] Apache Open For Business Project (OFBiz) /catalog/control/EditProductConfigItem configItemId Parameter XSS
6244| [58810] Apache Open For Business Project (OFBiz) /catalog/control/EditProdCatalo prodCatalogId Parameter XSS
6245| [58809] Apache Open For Business Project (OFBiz) /partymgr/control/viewprofile partyId Parameter XSS
6246| [58808] Apache Open For Business Project (OFBiz) /catalog/control/createProduct internalName Parameter XSS
6247| [58807] Apache Open For Business Project (OFBiz) Multiple Unspecified CSRF
6248| [58806] Apache FtpServer MINA Logging Filter Cleartext Credential Local Disclosure
6249| [58805] Apache Derby Unauthenticated Database / Admin Access
6250| [58804] Apache Wicket Header Contribution Unspecified Issue
6251| [58803] Apache Wicket Session Fixation
6252| [58802] Apache Directory Server (ApacheDS) userPassword Attribute Search Password Disclosure
6253| [58801] Apache ActiveMQ Stomp Client Credential Validation Bypass
6254| [58800] Apache Tapestry (context)/servicestatus Internal Service Information Disclosure
6255| [58799] Apache Tapestry Logging Cleartext Password Disclosure
6256| [58798] Apache Jetspeed pipeline Parameter pipeline-map Policy Bypass
6257| [58797] Apache Jetspeed Password Policy Multiple Weaknesses
6258| [58796] Apache Jetspeed Unsalted Password Storage Weakness
6259| [58795] Apache Rampart Crafted SOAP Header Authentication Bypass
6260| [58794] Apache Roller Admin Protocol (RAP) Malformed Header Authentication Bypass
6261| [58793] Apache Hadoop Map/Reduce mapred.system.dir Permission Weakness Job Manipulation
6262| [58792] Apache Shindig gadgets.rpc iframe RPC Call Validation Weakness
6263| [58791] Apache Synapse synapse.properties Cleartext Credential Local Disclosure
6264| [58790] Apache WSS4J SOAP Message UsernameToken Remote Password Disclosure
6265| [58789] Apache WSS4J SOAP Header Malformed UsernameToken Authentication Bypass
6266| [58776] Apache JSPWiki PreviewContent.jsp Edited Text XSS
6267| [58775] Apache JSPWiki preview.jsp action Parameter XSS
6268| [58774] Apache JSPWiki Edit.jsp Multiple Parameter XSS
6269| [58773] Apache JSPWiki Accept-Language Header Multiple Script language Parameter XSS
6270| [58772] Apache JSPWiki EditorManager.java editor Parameter XSS
6271| [58771] Apache JSPWiki GroupContent.jsp Multiple Parameter XSS
6272| [58770] Apache JSPWiki Group.jsp group Parameter XSS
6273| [58769] Apache JSPWiki Database Connection Termination DoS Weakness
6274| [58768] Apache JSPWiki Attachment Servlet nextpage Parameter Arbitrary Site Redirect
6275| [58766] Apache JSPWiki /admin/SecurityConfig.jsp Direct Request Information Disclosure
6276| [58765] Apache JSPWiki Spam Filter UniqueID RNG Weakness
6277| [58764] Apache JSPWiki Edit.jsp Multiple Parameter XSS
6278| [58763] Apache JSPWiki Include Tag Multiple Script XSS
6279| [58762] Apache JSPWiki Multiple .java Tags pageContext Parameter XSS
6280| [58761] Apache JSPWiki Wiki.jsp skin Parameter XSS
6281| [58760] Apache Commons VFS Exception Error Message Cleartext Credential Disclosure
6282| [58759] Apache Jackrabbit Content Repository (JCR) UUID System.currentTimeMillis() RNG Weakness
6283| [58758] Apache River GrantPermission Policy Manipulation Privilege Escalation
6284| [58757] Apache WS-Commons Java2 StaXUtils Multiple Unspecified Minor Issues
6285| [58756] Apache WSS4J WSHandler Client Certificate Signature Validation Weakness
6286| [58755] Apache Harmony DRLVM Non-public Class Member Access
6287| [58754] Apache Harmony File.createTempFile() Temporary File Creation Prediction Weakness
6288| [58751] Apache Geronimo GeronimoIdentityResolver Subject Handling Multiple Issues
6289| [58750] Apache MyFaces Trinidad Generated HTML Information Disclosure
6290| [58749] Apache MyFaces Trinidad Database Access Error Message Information Disclosure
6291| [58748] Apache MyFaces Trinidad Image Resource Loader Traversal Arbitrary Image Access
6292| [58747] Apache MyFaces Trinidad Error Message User Entered Data Disclosure Weakness
6293| [58746] Apache Axis2 JAX-WS Java2 WSDL4J Unspecified Issue
6294| [58744] Apache Wicket Crafted File Upload Disk Space Exhaustion DoS
6295| [58743] Apache Wicket wicket.util.crypt.SunJceCrypt Encryption Reversion Weakness
6296| [58742] Apache Rampart PolicyBasedValiadtor HttpsToken Endpoint Connection Weakness
6297| [58741] Apache Rampart WSSecSignature / WSSecEncryptedKey KeyIdentifierType Validation Weakness
6298| [58740] Apache Rampart TransportBinding Message Payload Cleartext Disclosure
6299| [58739] Apache Open For Business Project (OFBiz) Unsalted Password Storage Weakness
6300| [58738] Apache Open For Business Project (OFBiz) orderId Parameter Arbitrary Order Access
6301| [58737] Apache mod_python w/ mod_python.publisher index.py Underscore Prefixed Variable Disclosure
6302| [58735] Apache Open For Business Project (OFBiz) /ecommerce/control/keywordsearch SEARCH_STRING Parameter XSS
6303| [58734] Apache Torque Log File Cleartext Credential Local Disclosure
6304| [58733] Apache Axis2 doGet Implementation Authentication Bypass Service State Manipulation
6305| [58732] Apache MyFaces UIInput.validate() Null Value Validation Bypass Weakness
6306| [58731] Apache MyFaces /faces/* Prefix Mapping Authentication Bypass
6307| [58725] Apache Tapestry Basic String ACL Bypass Weakness
6308| [58724] Apache Roller Logout Functionality Failure Session Persistence
6309| [58723] Apache Roller User Profile / Admin Page Cleartext Password Disclosure
6310| [58722] Apache Derby Connection URL Encryption Method Reversion Weakness
6311| [58721] Apache Geronimo on Tomcat Security-constraint Resource ACL Bypass
6312| [58720] Apache Geronimo Explicit Servlet Mapping Access Bypass Weakness
6313| [58719] Apache Geronimo Keystore Unprivileged Service Disable DoS
6314| [58718] Apache Geronimo Deployment Plans Remote Password Disclosure
6315| [58717] Apache Jetspeed Portlet Application Edit Access Restriction Bypass
6316| [58716] Apache Jetspeed PSML Management Cached Constraint Authentication Weakness
6317| [58707] Apache WSS4J Crafted PasswordDigest Request Authentication Bypass
6318| [58706] Apache HttpClient Pre-emptive Authorization Remote Credential Disclosure
6319| [58705] Apache Directory Server (ApacheDS) User Passwords Cleartext Disclosure
6320| [58704] Apache Directory Server (ApacheDS) Non-existent User LDAP Bind Remote DoS
6321| [58703] Apache Geronimo Debug Console Unauthenticated Remote Information Disclosure
6322| [58702] Apache Directory Server (ApacheDS) Persistent LDAP Anonymous Bind Weakness
6323| [58701] Apache Jetspeed User Admin Portlet Unpassworded Account Creation Weakness
6324| [58700] Apache MyFaces /faces/* Path Handling Remote Overflow DoS
6325| [58699] Apache MyFaces Disable Property Client Side Manipulation Privilege Escalation
6326| [58698] Apache Roller Remember Me Functionality Cleartext Password Disclosure
6327| [58697] Apache XalanJ2 org.apache.xalan.xsltc.runtime.CallFunction Class Unspecified Issue
6328| [58696] Apache Tapestry Encoded Traversal Arbitrary File Access
6329| [58695] Apache Jetspeed Unauthenticated PSML Tags / Admin Folder Access
6330| [58694] Apache Geronimo Deploy Tool Process List Local Credential Disclosure
6331| [58693] Apache Derby service.properties File Encryption Key Information Disclosure
6332| [58692] Apache Geronimo Default Security Realm Login Brute Force Weakness
6333| [58689] Apache Roller Retrieve Last 5 Post Feature Unauthorized Blog Post Manipulation
6334| [58688] Apache Xalan-Java (XalanJ2) Static Variables Multiple Unspecified Issues
6335| [58687] Apache Axis Invalid wsdl Request XSS
6336| [58686] Apache Cocoon Temporary File Creation Unspecified Race Condition
6337| [58685] Apache Velocity Template Designer Privileged Code Execution
6338| [58684] Apache Jetspeed controls.Customize Action Security Check Bypass
6339| [58675] Apache Open For Business Project (OFBiz) eCommerce/ordermgr Multiple Field XSS
6340| [58674] Apache Open For Business Project (OFBiz) ecommerce/control/login Multiple Field XSS
6341| [58673] Apache Open For Business Project (OFBiz) ecommerce/control/viewprofile Multiple Field XSS
6342| [58672] Apache Open For Business Project (OFBiz) POS Input Panel Cleartext Password Disclosure
6343| [58671] Apache Axis2 JMS Signed Message Crafted WS-Security Header Security Bypass
6344| [58670] Apache Jetspeed JetspeedTool.getPortletFromRegistry Portlet Security Validation Failure
6345| [58669] Apache Jetspeed LDAP Cleartext Passwords Disclosure
6346| [58668] Apache Axis External Entity (XXE) Data Parsing Privilege Escalation
6347| [58667] Apache Roller Database Cleartext Passwords Disclosure
6348| [58666] Apache Xerces-C++ UTF-8 Transcoder Overlong Code Handling Unspecified Issue
6349| [58665] Apache Jetspeed Turbine: Cross-user Privileged Action Execution
6350| [58664] Apache Jetspeed EditAccount.vm Password Modification Weakness
6351| [58663] Apache Jetspeed Role Parameter Arbitrary Portlet Disclosure
6352| [58662] Apache Axis JWS Page Generated .class File Direct Request Information Disclosure
6353| [58661] Apache Jetspeed user-form.vm Password Reset Cleartext Disclosure
6354| [58660] Apache WSS4J checkReceiverResults Function Crafted SOAP Request Authentication Bypass
6355| [58658] Apache Rampart Crafted SOAP Request Security Verification Bypass
6356| [57882] Apache HTTP Server mod_proxy_ftp Authorization HTTP Header Arbitrary FTP Command Injection
6357| [57851] Apache HTTP Server mod_proxy_ftp EPSV Command NULL Dereference Remote DoS
6358| [56984] Apache Xerces2 Java Malformed XML Input DoS
6359| [56903] Apache ODE (Orchestration Director Engine) Process Deployment Web Service Traversal Arbitrary File Manipulation
6360| [56859] Apache Xerces-C++ Multiple Sub-project XML Nested DTD Structures Parsing Recursion Error DoS
6361| [56766] Apache Portable Runtime (APR-util) memory/unix/apr_pools.c Relocatable Memory Block Aligning Overflow
6362| [56765] Apache Portable Runtime (APR-util) misc/apr_rmm.c Multiple Function Overflows
6363| [56517] Apache HTTP Server File Descriptor Leak Arbitrary Local File Append
6364| [56443] PTK Unspecified Apache Sub-process Arbitrary Command Execution
6365| [56414] Apache Tiles Duplicate Expression Language (EL) Expression Evaluation XSS
6366| [55814] mod_NTLM for Apache HTTP Server ap_log_rerror() Function Remote Format String
6367| [55813] mod_NTLM for Apache HTTP Server log() Function Remote Overflow
6368| [55782] Apache HTTP Server mod_deflate Module Aborted Connection DoS
6369| [55553] Apache HTTP Server mod_proxy Module mod_proxy_http.c stream_reqbody_cl Function CPU Consumption DoS
6370| [55059] Apache APR-util strmatch/apr_strmatch.c apr_strmatch_precompile Function Crafted Input Remote DoS
6371| [55058] Apache APR-util apr_brigade_vprintf Function Crafted Input Off-by-one Remote DoS
6372| [55057] Apache APR-util xml/apr_xml.c apr_xml_* Interface Expat XML Parser Crafted XML Document Remote DoS
6373| [55056] Apache Tomcat Cross-application TLD File Manipulation
6374| [55055] Apache Tomcat Illegal URL Encoded Password Request Username Enumeration
6375| [55054] Apache Tomcat Java AJP Connector mod_jk Load Balancing Worker Malformed Header Remote DoS
6376| [55053] Apache Tomcat Crafted Request Security Restraint Bypass Arbitrary Content Access
6377| [54733] Apache HTTP Server AllowOverride Directive .htaccess Options Bypass
6378| [54713] razorCMS Security Manager apache User Account Unspecified File Permission Weakness Issue
6379| [54589] Apache Jserv Nonexistent JSP Request XSS
6380| [54122] Apache Struts s:a / s:url Tag href Element XSS
6381| [54093] Apache ActiveMQ Web Console JMS Message XSS
6382| [53932] Apache Geronimo Multiple Admin Function CSRF
6383| [53931] Apache Geronimo /console/portal/Server/Monitoring Multiple Parameter XSS
6384| [53930] Apache Geronimo /console/portal/ URI XSS
6385| [53929] Apache Geronimo on Windows Security/Keystores Portlet Traversal Arbitrary File Upload
6386| [53928] Apache Geronimo on Windows Embedded DB/DB Manager Portlet Traversal Arbitrary File Upload
6387| [53927] Apache Geronimo on Windows Services/Repository Portlet Traversal Arbitrary File Upload
6388| [53921] Apache HTTP Server mod_proxy_ajp Cross Thread/Session Information Disclosure
6389| [53766] Oracle BEA WebLogic Server Plug-ins for Apache Certificate Handling Remote Overflow
6390| [53574] PHP on Apache .htaccess mbstring.func_overload Setting Cross Hosted Site Behavior Modification
6391| [53381] Apache Tomcat JK Connector Content-Length Header Cross-user Information Disclosure
6392| [53380] Apache Struts Unspecified XSS
6393| [53289] Apache mod_perl Apache::Status /perl-status Unspecified XSS
6394| [53186] Apache HTTP Server htpasswd Predictable Salt Weakness
6395| [52899] Apache Tomcat Examples Web Application Calendar Application jsp/cal/cal2.jsp time Parameter XSS
6396| [52407] Apache Tomcat doRead Method POST Content Information Disclosure
6397| [51923] Apache HTTP Server mod-auth-mysql Module mod_auth_mysql.c Multibyte Character Encoding SQL Injection
6398| [51613] Apache HTTP Server Third-party Module Child Process File Descriptor Leak
6399| [51612] Apache HTTP Server Internal Redirect Handling Infinite Loop DoS
6400| [51468] Apache Jackrabbit Content Repository (JCR) swr.jsp q Parameter XSS
6401| [51467] Apache Jackrabbit Content Repository (JCR) search.jsp q Parameter XSS
6402| [51151] Apache Roller Search Function q Parameter XSS
6403| [50482] PHP with Apache php_value Order Unspecified Issue
6404| [50475] Novell NetWare ApacheAdmin Console Unauthenticated Access
6405| [49734] Apache Struts DefaultStaticContentLoader Class Traversal Arbitrary File Access
6406| [49733] Apache Struts FilterDispatcher Class Traversal Arbitrary File Access
6407| [49283] Oracle BEA WebLogic Server Plugins for Apache Remote Transfer-Encoding Overflow
6408| [49062] Apache Tomcat Cross-thread Concurrent Request Variable Overwrite Information Disclosure
6409| [48847] ModSecurity (mod_security) Transformation Caching Unspecified Apache DoS
6410| [48788] Apache Xerces-C++ XML Schema maxOccurs Value XML File Handling DoS
6411| [47474] Apache HTTP Server mod_proxy_ftp Directory Component Wildcard Character XSS
6412| [47464] Apache Tomcat allowLinking / UTF-8 Traversal Arbitrary File Access
6413| [47463] Apache Tomcat RequestDispatcher Traversal Arbitrary File Access
6414| [47462] Apache Tomcat HttpServletResponse.sendError Method Message Argument XSS
6415| [47096] Oracle Weblogic Apache Connector POST Request Overflow
6416| [46382] Frontend Filemanager (air_filemanager) Extension for TYPO3 on Apache Unspecified Arbitrary Code Execution
6417| [46285] TYPO3 on Apache Crafted Filename Upload Arbitrary Command Execution
6418| [46085] Apache HTTP Server mod_proxy ap_proxy_http_process_response() Function Interim Response Forwarding Remote DoS
6419| [45905] Apache Tomcat Host Manager host-manager/html/add name Parameter XSS
6420| [45879] Ragnarok Online Control Panel on Apache Crafted Traversal Authentication Bypass
6421| [45742] Apache HTTP Server on Novell Unspecified Request Directive Internal IP Disclosure
6422| [45740] Apache Derby DropSchemaNode Bind Phase Arbitrary Scheme Statement Dropping
6423| [45599] Apache Derby Lock Table Statement Privilege Requirement Bypass Arbitrary Table Lock
6424| [45585] Apache Derby ACCSEC Command RDBNAM Parameter Cleartext Credential Disclosure
6425| [45584] Apache Derby DatabaseMetaData.getURL Function Cleartext Credential Disclosure
6426| [45420] Apache HTTP Server 403 Error Page UTF-7 Encoded XSS
6427| [44728] PHP Toolkit on Gentoo Linux Interpretation Conflict Apache HTTP Server Local DoS
6428| [44618] Oracle JSP Apache/Jserv Path Translation Traversal Arbitrary JSP File Execution
6429| [44159] Apache HTTP Server Remote Virtual Host Name Disclosure
6430| [43997] Apache-SSL ExpandCert() Function Certificate Handling Arbitrary Environment Variables Manipulation
6431| [43994] suPHP for Apache (mod_suphp) Directory Symlink Local Privilege Escalation
6432| [43993] suPHP for Apache (mod_suphp) Owner Mode Race Condition Symlink Local Privilege Escalation
6433| [43663] Apache HTTP Server Mixed Platform AddType Directive Crafted Request PHP Source Disclosure
6434| [43658] AuthCAS Module (AuthCAS.pm) for Apache HTTP Server SESSION_COOKIE_NAME SQL Injection
6435| [43452] Apache Tomcat HTTP Request Smuggling
6436| [43309] Apache Geronimo LoginModule Login Method Bypass
6437| [43290] Apache JSPWiki Entry Page Attachment Unrestricted File Upload
6438| [43259] Apache HTTP Server on Windows mod_proxy_balancer URL Handling Remote Memory Corruption
6439| [43224] Apache Geronimo on SuSE Linux init Script Symlink Unspecified File/Directory Access
6440| [43189] Apache mod_jk2 Host Header Multiple Fields Remote Overflow
6441| [42937] Apache HTTP Server mod_proxy_balancer balancer-manager Unspecified CSRF
6442| [42341] MOD_PLSQL for Apache Unspecified URL SQL Injection
6443| [42340] MOD_PLSQL for Apache CGI Environment Handling Unspecified Overflow
6444| [42214] Apache HTTP Server mod_proxy_ftp UTF-7 Encoded XSS
6445| [42091] Apache Maven Site Plugin Installation Permission Weakness
6446| [42089] Apache Maven .m2/settings.xml Cleartext Password Disclosure
6447| [42088] Apache Maven Defined Repo Process Listing Password Disclosure
6448| [42087] Apache Maven Site Plugin SSH Deployment Permission Setting Weakness
6449| [42036] Apache HTTP Server MS-DOS Device Request Host OS Disclosure
6450| [41891] BEA WebLogic Apache Beehive NetUI Page Flow Unspecified XSS
6451| [41436] Apache Tomcat Native APR Connector Duplicate Request Issue
6452| [41435] Apache Tomcat %5C Cookie Handling Session ID Disclosure
6453| [41434] Apache Tomcat Exception Handling Subsequent Request Information Disclosure
6454| [41400] LimeSurvey save.php Apache Log File PHP Code Injection
6455| [41029] Apache Tomcat Calendar Examples Application cal2.jsp Multiple Parameter CSRF
6456| [41019] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload XSS
6457| [41018] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload CRLF
6458| [40853] Apache Tomcat SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) JSESSIONIDSSO Cookie Security Weakness
6459| [40264] Apache HTTP Server mod_proxy_balancer balancer_handler Function bb Variable Remote DoS
6460| [40263] Apache HTTP Server mod_proxy_balancer balancer-manager Multiple Parameter XSS
6461| [40262] Apache HTTP Server mod_status refresh XSS
6462| [39833] Apache Tomcat JULI Logging Component catalina.policy Security Bypass
6463| [39251] Coppermine Photo Gallery on Apache Multiple File Extension Upload Arbitrary Code Execution
6464| [39166] Apache Tomcat on Windows caseSensitive Attribute Mixed Case Request JSP Source Disclosure
6465| [39134] Apache mod_imagemap Module Imagemap Unspecified XSS
6466| [39133] Apache mod_imap Module Imagemap File Unspecified XSS
6467| [39035] Apache Tomcat examples/servlet/CookieExample Multiple Parameter XSS
6468| [39003] Apache HTTP Server HTTP Method Header Request Entity Too Large XSS
6469| [39000] Apache Tomcat SendMailServlet sendmail.jsp mailfrom Parameter XSS
6470| [38939] Apache HTTP Server Prefork MPM Module Array Modification Local DoS
6471| [38673] Apache Jakarta Slide WebDAV SYSTEM Request Traversal Arbitrary File Access
6472| [38662] Apache Geronimo SQLLoginModule Nonexistent User Authentication Bypass
6473| [38661] Apache Geronimo MEJB Unspecified Authentication Bypass
6474| [38641] Apache HTTP Server mod_mem_cache recall_headers Function Information Disclosure
6475| [38640] Apache HTTP Server suexec Document Root Unauthorized Operations
6476| [38639] Apache HTTP Server suexec Multiple Symlink Privilege Escalation
6477| [38636] Apache HTTP Server mod_autoindex.c P Variable UTF-7 Charset XSS
6478| [38513] BEA WebLogic Server Proxy Plug-in for Apache Protocol Error Handling Remote DoS
6479| [38187] Apache Geronimo / Tomcat WebDAV XML SYSTEM Tag Arbitrary File Access
6480| [37079] Apache HTTP Server mod_cache cache_util.c Malformed Cache-Control Header DoS
6481| [37071] Apache Tomcat Cookie Handling Session ID Disclosure
6482| [37070] Apache Tomcat Cookie Handling Quote Delimiter Session ID Disclosure
6483| [37052] Apache HTTP Server mod_status mod_status.c Unspecified XSS
6484| [37051] Apache HTTP Server mod_proxy modules/proxy/proxy_util.c Crafted Header Remote DoS
6485| [37050] Apache HTTP Server Prefork MPM Module Crafted Code Sequence Local DoS
6486| [36417] Apache Tomcat Host Manager Servlet html/add Action aliases Parameter XSS
6487| [36377] Apache MyFaces Tomahawk JSF Application autoscroll Multiple Script XSS
6488| [36080] Apache Tomcat JSP Examples Crafted URI XSS
6489| [36079] Apache Tomcat Manager Uploaded Filename XSS
6490| [34888] Apache Tomcat Example Calendar Application cal2.jsp time Parameter XSS
6491| [34887] Apache Tomcat implicit-objects.jsp Crafted Header XSS
6492| [34885] Apache Tomcat on IIS Servlet Engine MS-DOS Device Request DoS
6493| [34884] Apache Tomcat on Windows Nonexistent Resource Request Path Disclosure
6494| [34883] Apache Tomcat Crafted JSP File Request Path Disclosure
6495| [34882] Apache Tomcat Default SSL Ciphersuite Configuration Weakness
6496| [34881] Apache Tomcat Malformed Accept-Language Header XSS
6497| [34880] Apache Tomcat HTTP/1.1 Connector NULL Byte Request JSP Source Disclosure
6498| [34879] Apache Tomcat examples/jsp2/jspx/textRotate.jspx XSS
6499| [34878] Apache Tomcat examples/jsp2/el/implicit-objects.jsp XSS
6500| [34877] Apache Tomcat JK Web Server Connector (mod_jk) Double Encoded Traversal Arbitrary File Access
6501| [34876] Apache HTTP Server ScriptAlias CGI Source Disclosure
6502| [34875] Apache Tomcat appdev/sample/web/hello.jsp Multiple Parameter XSS
6503| [34874] Apache Tomcat AJP Connector mod_jk ajp_process_callback Remote Memory Disclosure
6504| [34873] Apache Stats Variable Extraction _REQUEST Ssuperglobal Array Overwrite
6505| [34872] Apache HTTP Server suexec User/Group Combination Weakness Local Privilege Escalation
6506| [34769] Apache Tomcat w/ Proxy Module Double Encoded Traversal Arbitrary File Access
6507| [34541] mod_perl for Apache HTTP Server RegistryCooker.pm PATH_INFO Crafted URI Remote DoS
6508| [34540] mod_perl for Apache HTTP Server PerlRun.pm PATH_INFO Crafted URI Remote DoS
6509| [34398] Apache Tomcat mod_jk Invalid Chunked Encoded Body Information Disclosure
6510| [34154] Apache Axis Nonexistent Java Web Service Path Disclosure
6511| [33855] Apache Tomcat JK Web Server Connector mod_jk.so Long URI Worker Map Remote Overflow
6512| [33816] Apache HTTP Server on Debian Linux TTY Local Privilege Escalation
6513| [33456] Apache HTTP Server Crafted TCP Connection Range Header DoS
6514| [33346] Avaya Multiple Products Apache Tomcat Port Weakness
6515| [32979] Apache Java Mail Enterprise Server (JAMES) Phoenix/MX4J Interface Arbitrary User Creation
6516| [32978] Apache Java Mail Enterprise Server (JAMES) POP3Server Log File Plaintext Password Disclosure
6517| [32724] Apache mod_python _filter_read Freed Memory Disclosure
6518| [32723] Apache Tomcat semicolon Crafted Filename Request Forced Directory Listing
6519| [32396] Apache Open For Business Project (OFBiz) Ecommerce Component Forum Implementation Message Body XSS
6520| [32395] Apache Open For Business Project (OFBiz) Ecommerce Component Form Field Manipulation Privilege Escalation
6521| [30354] Linux Subversion libapache2-svn Search Path Subversion Local Privilege Escalation
6522| [29603] PHP ini_restore() Apache httpd.conf Options Bypass
6523| [29536] Apache Tcl mod_tcl set_var Function Remote Format String
6524| [28919] Apache Roller Weblogger Blog Comment Multiple Field XSS
6525| [28130] PHP with Apache Mixed Case Method Limit Directive Bypass
6526| [27913] Apache HTTP Server on Windows mod_alias URL Validation Canonicalization CGI Source Disclosure
6527| [27588] Apache HTTP Server mod_rewrite LDAP Protocol URL Handling Overflow
6528| [27487] Apache HTTP Server Crafted Expect Header Cross Domain HTML Injection
6529| [26935] FCKeditor on Apache connector.php Crafted File Extension Arbitrary File Upload
6530| [26572] Apache Java Mail Enterprise Server (JAMES) MAIL Command Overflow DoS
6531| [25909] Drupal on Apache files Directory File Upload Arbitrary Code Execution
6532| [24825] Oracle ModPL/SQL for Apache Unspecified Remote HTTP Issue
6533| [24365] Apache Struts Multiple Function Error Message XSS
6534| [24364] Apache Struts getMultipartRequestHandler() Function Crafted Request DoS
6535| [24363] Apache Struts org.apache.struts.taglib.html.Constants.CANCEL Validation Bypass
6536| [24103] Pubcookie Apache mod_pubcookie Unspecified XSS
6537| [23906] Apache mod_python for Apache HTTP Server FileSession Privileged Local Command Execution
6538| [23905] Apache Log4net LocalSyslogAppender Format String Memory Corruption DoS
6539| [23198] Apache WSS4J Library SOAP Signature Verification Bypass
6540| [23124] Generic Apache Request Library (libapreq) apreq_parse_* Functions Remote DoS
6541| [22652] mod_php for Apache HTTP Server Crafted import_request_variables Function DoS
6542| [22475] PHP w/ Apache PDO::FETCH_CLASS __set() Function DoS
6543| [22473] PHP w/ Apache2 Crafted PDOStatement DoS
6544| [22459] Apache Geronimo Error Page XSS
6545| [22458] Apache Tomcat / Geronimo Sample Script cal2.jsp time Parameter XSS
6546| [22301] auth_ldap for Apache HTTP Server auth_ldap_log_reason() Function Remote Format String
6547| [22261] Apache HTTP Server mod_ssl ssl_hook_Access Error Handling DoS
6548| [22259] mod_auth_pgsql for Apache HTTP Server Log Function Format String
6549| [21736] Apache Java Mail Enterprise Server (JAMES) Spooler retrieve Function DoS
6550| [21705] Apache HTTP Server mod_imap Image Map Referer XSS
6551| [21021] Apache Struts Error Message XSS
6552| [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
6553| [20491] PHP mod_php apache2handler SAPI Crafted .htaccess DoS
6554| [20462] Apache HTTP Server worker.c MPM Memory Exhaustion DoS
6555| [20439] Apache Tomcat Directory Listing Saturation DoS
6556| [20373] Apache Tomcat on HP Secure OS for Linux Unspecified Servlet Access Issue
6557| [20285] Apache HTTP Server Log File Control Character Injection
6558| [20242] Apache HTTP Server mod_usertrack Predictable Session ID Generation
6559| [20209] Brainf*ck Module (mod_bf) for Apache HTTP Server Local Overflow
6560| [20033] Apache Tomcat MS-DOS Device Request Error Message Path Disclosure
6561| [19883] apachetop atop.debug Symlink Arbitrary File Overwrite
6562| [19863] mod_auth_shadow for Apache HTTP Server require group Authentication Bypass
6563| [19855] Apache HTTP Server ErrorDocument Directive .htaccess Bypass
6564| [19821] Apache Tomcat Malformed Post Request Information Disclosure
6565| [19769] Apache HTTP Server Double-reverse DNS Lookup Spoofing
6566| [19188] Apache HTTP Server mod_ssl SSLVerifyClient Per-location Context Restriction Bypass
6567| [19137] Apache HTTP Server on Red Hat Linux Double Slash GET Request Forced Directory Listing
6568| [19136] Apache on Mandrake Linux Arbitrary Directory Forced Listing
6569| [18977] Apache HTTP Server Crafted HTTP Range Header DoS
6570| [18389] Ragnarok Online Control Panel Apache Authentication Bypass
6571| [18286] Apache HTTP Server mod_ssl ssl_callback_SSLVerify_CRL( ) Function Overflow
6572| [18233] Apache HTTP Server htdigest user Variable Overfow
6573| [17738] Apache HTTP Server HTTP Request Smuggling
6574| [16586] Apache HTTP Server Win32 GET Overflow DoS
6575| [15889] Apache HTTP Server mod_cgid Threaded MPM CGI Output Misdirection
6576| [14896] mod_dav for Apache HTTP Server Remote Null Dereference Child Process Termination
6577| [14879] Apache HTTP Server ap_log_rerror Function Error Message Path Disclosure
6578| [14770] Apache Tomcat AJP12 Protocol Malformed Packet Remote DoS
6579| [14597] Apache Tomcat IntegerOverflow.jsp Test JSP Script Path Disclosure
6580| [14596] Apache Tomcat pageSession.jsp Test JSP Script Path Disclosure
6581| [14595] Apache Tomcat pageLanguage.jsp Test JSP Script Path Disclosure
6582| [14594] Apache Tomcat pageIsThreadSafe.jsp Test JSP Script Path Disclosure
6583| [14593] Apache Tomcat pageIsErrorPage.jsp Test JSP Script Path Disclosure
6584| [14592] Apache Tomcat pageInvalid.jsp Test JSP Script Path Disclosure
6585| [14591] Apache Tomcat pageExtends.jsp Test JSP Script Path Disclosure
6586| [14590] Apache Tomcat pageDouble.jsp Test JSP Script Path Disclosure
6587| [14589] Apache Tomcat pageAutoFlush.jsp Test JSP Script Path Disclosure
6588| [14588] Apache Tomcat extends2.jsp Test JSP Script Path Disclosure
6589| [14587] Apache Tomcat extends1.jsp Test JSP Script Path Disclosure
6590| [14586] Apache Tomcat comments.jsp Test JSP Script Path Disclosure
6591| [14585] Apache Tomcat buffer4.jsp Test JSP Script Path Disclosure
6592| [14584] Apache Tomcat buffer3.jsp Test JSP Script Path Disclosure
6593| [14583] Apache Tomcat buffer2.jsp Test JSP Script Path Disclosure
6594| [14582] Apache Tomcat buffer1.jsp Test JSP Script Path Disclosure
6595| [14581] Apache Tomcat pageImport2.jsp Test JSP Script Path Disclosure
6596| [14580] Apache Tomcat pageInfo.jsp Test JSP Script Path Disclosure
6597| [14410] mod_frontpage for Apache HTTP Server fpexec Remote Overflow
6598| [14044] Apache Batik Squiggle Browser with Rhino Scripting Engine Unspecified File System Access
6599| [13737] mod_access_referer for Apache HTTP Server Malformed Referer DoS
6600| [13711] Apache mod_python publisher.py Traversal Arbitrary Object Information Disclosure
6601| [13640] mod_auth_any for Apache HTTP Server on Red Hat Linux Metacharacter Command Execution
6602| [13304] Apache Tomcat realPath.jsp Path Disclosure
6603| [13303] Apache Tomcat source.jsp Arbitrary Directory Listing
6604| [13087] Apache HTTP Server mod_log_forensic check_forensic Symlink Arbitrary File Creation / Overwrite
6605| [12849] mod_auth_radius for Apache HTTP Server radcpy() Function Overflow DoS
6606| [12848] Apache HTTP Server htdigest realm Variable Overflow
6607| [12721] Apache Tomcat examples/jsp2/el/functions.jsp XSS
6608| [12720] mod_dosevasive for Apache HTTP Server Symlink Arbitrary File Create/Overwrite
6609| [12558] Apache HTTP Server IPv6 FTP Proxy Socket Failure DoS
6610| [12557] Apache HTTP Server prefork MPM accept Error DoS
6611| [12233] Apache Tomcat MS-DOS Device Name Request DoS
6612| [12232] Apache Tomcat with JDK Arbitrary Directory/Source Disclosure
6613| [12231] Apache Tomcat web.xml Arbitrary File Access
6614| [12193] Apache HTTP Server on Mac OS X File Handler Bypass
6615| [12192] Apache HTTP Server on Mac OS X Unauthorized .ht and .DS_Store File Access
6616| [12178] Apache Jakarta Lucene results.jsp XSS
6617| [12176] mod_digest_apple for Apache HTTP Server on Mac OS X Authentication Replay
6618| [11391] Apache HTTP Server Header Parsing Space Saturation DoS
6619| [11003] Apache HTTP Server mod_include get_tag() Function Local Overflow
6620| [10976] mod_mylo for Apache HTTP Server mylo_log Logging Function HTTP GET Overflow
6621| [10637] Apache HTTP Server mod_ssl SSLCipherSuite Access Restriction Bypass
6622| [10546] Macromedia JRun4 mod_jrun Apache Module Remote Overflow
6623| [10471] Apache Xerces-C++ XML Parser DoS
6624| [10218] Apache HTTP Server Satisfy Directive Access Control Bypass
6625| [10068] Apache HTTP Server htpasswd Local Overflow
6626| [10049] mod_cplusplus For Apache HTTP Server Unspecified Overflow
6627| [9994] Apache HTTP Server apr-util IPV6 Parsing DoS
6628| [9991] Apache HTTP Server ap_resolve_env Environment Variable Local Overflow
6629| [9948] mod_dav for Apache HTTP Server LOCK Request DoS
6630| [9742] Apache HTTP Server mod_ssl char_buffer_read Function Reverse Proxy DoS
6631| [9718] Apache HTTP Server Win32 Single Dot Append Arbitrary File Access
6632| [9717] Apache HTTP Server mod_cookies Cookie Overflow
6633| [9716] Apache::Gallery Gallery.pm Inline::C Predictable Filename Code Execution
6634| [9715] Apache HTTP Server rotatelogs Control Characters Over Pipe DoS
6635| [9714] Apache Authentication Module Threaded MPM DoS
6636| [9713] Apache HTTP Server on OS2 filestat.c Device Name Request DoS
6637| [9712] Apache HTTP Server Multiple Linefeed Request Memory Consumption DoS
6638| [9711] Apache HTTP Server Access Log Terminal Escape Sequence Injection
6639| [9710] Apache HTTP Server on Windows Illegal Character Default Script Mapping Bypass
6640| [9709] Apache HTTP Server on Windows MS-DOS Device Name HTTP Post Code Execution
6641| [9708] Apache HTTP Server on Windows MS-DOS Device Name DoS
6642| [9707] Apache HTTP Server Duplicate MIME Header Saturation DoS
6643| [9706] Apache Web Server Multiple MIME Header Saturation Remote DoS
6644| [9705] Apache Tomcat Invoker/Default Servlet Source Disclosure
6645| [9702] Apache HTTP Server CGI/WebDAV HTTP POST Request Source Disclosure
6646| [9701] Apache HTTP Server for Windows Multiple Slash Forced Directory Listing
6647| [9700] Apache HTTP Server mod_autoindex Multiple Slash Request Forced Directory Listing
6648| [9699] Apache HTTP Server mod_dir Multiple Slash Request Forced Directory Listing
6649| [9698] Apache HTTP Server mod_negotiation Multiple Slash Request Forced Directory Listing
6650| [9697] Apache HTTP Server htdigest Local Symlink Arbitrary File Overwrite
6651| [9696] Apache HTTP Server htpasswd Local Symlink Arbitrary File Overwrite
6652| [9695] Apache Tomcat SnoopServlet Servlet Information Disclosure
6653| [9694] PHP3 on Apache HTTP Server Encoded Traversal Arbitrary File Access
6654| [9693] mod_auth_pgsql_sys for Apache HTTP Server User Name SQL Injection
6655| [9692] Apache HTTP Server mod_vhost_alias Mass Virtual Hosting Arbitrary File Access
6656| [9691] Apache HTTP Server mod_rewrite Mass Virtual Hosting Arbitrary File Access
6657| [9690] Apache HTTP Server mod_vhost_alias CGI Program Source Disclosure
6658| [9689] Trustix httpsd for Apache-SSL Permission Weakness Privilege Escalation
6659| [9688] Apache HTTP Server mod_proxy Malformed FTP Command DoS
6660| [9687] Apache::AuthenSmb smbval SMB Authentication Library Multiple Overflows
6661| [9686] Apache::AuthenSmb smbvalid SMB Authentication Library Multiple Overflows
6662| [9523] Apache HTTP Server mod_ssl Aborted Connection DoS
6663| [9459] Oracle PL/SQL (mod_plsql) Apache Module Help Page Request Remote Overflow
6664| [9208] Apache Tomcat .jsp Encoded Newline XSS
6665| [9204] Apache Tomcat ROOT Application XSS
6666| [9203] Apache Tomcat examples Application XSS
6667| [9068] Apache HTTP Server mod_userdir User Account Information Disclosure
6668| [8773] Apache Tomcat Catalina org.apache.catalina.servlets.DefaultServlet Source Code Disclosure
6669| [8772] Apache Tomcat Catalina org.apache.catalina.connector.http DoS
6670| [7943] Apache HTTP Server mod_ssl sslkeys File Disclosure
6671| [7942] Apache HTTP Server mod_ssl Default Pass Phrase
6672| [7941] Apache HTTP Server mod_ssl Encrypted Private Key File Descriptor Leak
6673| [7935] Apache HTTP Server mod_ssl ssl_gcache Race Conditions
6674| [7934] Apache HTTP Server mod_ssl SSLSessionCache File Content Disclosure
6675| [7933] Apache HTTP Server mod_ssl SSLMutex File Content Disclosure
6676| [7932] Apache HTTP Server mod_ssl mkcert.sh File Creation Permission Weakness
6677| [7931] Apache HTTP Server mod_ssl X.509 Client Certificate Authentication Bypass
6678| [7930] Apache HTTP Server mod_ssl ssl_expr_eval_func_file() Overflow
6679| [7929] Apache HTTP Server mod_ssl ssl_engine_log.c mod_proxy Hook Function Remote Format String
6680| [7611] Apache HTTP Server mod_alias Local Overflow
6681| [7394] Apache Tomcat mod_jk Invalid Transfer-Encoding Chunked Field DoS
6682| [7203] Apache Tomcat source.jsp Traversal Arbitrary File Access
6683| [7039] Apache HTTP Server on Mac OS X HFS+ File System Access Bypass
6684| [6882] Apache mod_python Malformed Query String Variant DoS
6685| [6839] Apache HTTP Server mod_proxy Content-Length Overflow
6686| [6630] Apache Tomcat Java Server Pages (JSP) Engine WPrinterJob() DoS
6687| [6472] Apache HTTP Server mod_ssl ssl_util_uuencode_binary Remote Overflow
6688| [5821] Apache HTTP Server Multiple / GET Remote Overflow DoS
6689| [5580] Apache Tomcat Servlet Malformed URL JSP Source Disclosure
6690| [5552] Apache HTTP Server split-logfile Arbitrary .log File Overwrite
6691| [5526] Apache Tomcat Long .JSP URI Path Disclosure
6692| [5278] Apache Tomcat web.xml Restriction Bypass
6693| [5051] Apache Tomcat Null Character DoS
6694| [4973] Apache Tomcat servlet Mapping XSS
6695| [4650] mod_gzip for Apache HTTP Server Debug Mode Printf Stack Overflow
6696| [4649] mod_gzip for Apache HTTP Server Debug Mode Format String Overflow
6697| [4648] mod_gzip for Apache HTTP Server Debug Mode Race Condition
6698| [4568] mod_survey For Apache ENV Tags SQL Injection
6699| [4553] Apache HTTP Server ApacheBench Overflow DoS
6700| [4552] Apache HTTP Server Shared Memory Scoreboard DoS
6701| [4446] Apache HTTP Server mod_disk_cache Stores Credentials
6702| [4383] Apache HTTP Server Socket Race Condition DoS
6703| [4382] Apache HTTP Server Log Entry Terminal Escape Sequence Injection
6704| [4340] Apache Portable Runtime (APR) apr_psprintf DoS
6705| [4232] Apache Cocoon DatabaseAuthenticatorAction SQL Injection
6706| [4231] Apache Cocoon Error Page Server Path Disclosure
6707| [4182] Apache HTTP Server mod_ssl Plain HTTP Request DoS
6708| [4181] Apache HTTP Server mod_access IP Address Netmask Rule Bypass
6709| [4075] Apache HTTP Sever on Windows .var File Request Path Disclosure
6710| [4037] Apache HTTP Server on Cygwin Encoded GET Request Arbitrary File Access
6711| [3877] Apache-SSL SSLVerifyClient SSLFakeBasicAuth Client Certificate Forgery
6712| [3819] Apache HTTP Server mod_digest Cross Realm Credential Replay
6713| [3322] mod_php for Apache HTTP Server Process Hijack
6714| [3215] mod_php for Apache HTTP Server File Descriptor Leakage
6715| [2885] Apache mod_python Malformed Query String DoS
6716| [2749] Apache Cocoon view-source Sample File Traversal Arbitrary File Access
6717| [2733] Apache HTTP Server mod_rewrite Local Overflow
6718| [2672] Apache HTTP Server mod_ssl SSLCipherSuite Ciphersuite Downgrade Weakness
6719| [2613] Apache HTTP Server mod_cgi stderr Output Handling Local DoS
6720| [2149] Apache::Gallery Privilege Escalation
6721| [2107] Apache HTTP Server mod_ssl Host: Header XSS
6722| [1926] Apache HTTP Server mod_rewrite Crafted URI Rule Bypass
6723| [1833] Apache HTTP Server Multiple Slash GET Request DoS
6724| [1577] Apache HTTP Server mod_rewrite RewriteRule Expansion Arbitrary File Access
6725| [872] Apache Tomcat Multiple Default Accounts
6726| [862] Apache HTTP Server SSI Error Page XSS
6727| [859] Apache HTTP Server Win32 Crafted Traversal Arbitrary File Access
6728| [849] Apache Tomcat TroubleShooter Servlet Information Disclosure
6729| [845] Apache Tomcat MSDOS Device XSS
6730| [844] Apache Tomcat Java Servlet Error Page XSS
6731| [842] Apache HTTP Server mod_ssl ssl_compat_directive Function Overflow
6732| [838] Apache HTTP Server Chunked Encoding Remote Overflow
6733| [827] PHP4 for Apache on Windows php.exe Malformed Request Path Disclosure
6734| [775] Apache mod_python Module Importing Privilege Function Execution
6735| [769] Apache HTTP Server Win32 DOS Batch File Arbitrary Command Execution
6736| [756] Apache HTTP Server mod_ssl i2d_SSL_SESSION Function SSL Client Certificate Overflow
6737| [701] Apache HTTP Server Win32 ScriptAlias php.exe Arbitrary File Access
6738| [674] Apache Tomcat Nonexistent File Error Message Path Disclosure
6739| [637] Apache HTTP Server UserDir Directive Username Enumeration
6740| [623] mod_auth_pgsql for Apache HTTP Server User Name SQL Injection
6741| [582] Apache HTTP Server Multiviews Feature Arbitrary Directory Listing
6742| [562] Apache HTTP Server mod_info /server-info Information Disclosure
6743| [561] Apache Web Servers mod_status /server-status Information Disclosure
6744| [417] Apache HTTP Server on SuSE Linux /doc/packages Remote Information Disclosure
6745| [410] mod_perl for Apache HTTP Server /perl/ Directory Listing
6746| [404] Apache HTTP Server on SuSE Linux WebDAV PROPFIND Arbitrary Directory Listing
6747| [402] Apache HTTP Server on SuSE Linux cgi-bin-sdb Request Script Source Disclosure
6748| [379] Apache ASP module Apache::ASP source.asp Example File Arbitrary File Creation
6749| [377] Apache Tomcat Snoop Servlet Remote Information Disclosure
6750| [376] Apache Tomcat contextAdmin Arbitrary File Access
6751| [342] Apache HTTP Server for Windows Multiple Forward Slash Directory Listing
6752| [222] Apache HTTP Server test-cgi Arbitrary File Access
6753| [143] Apache HTTP Server printenv.pl Multiple Method CGI XSS
6754| [48] Apache HTTP Server on Debian /usr/doc Directory Information Disclosure
6755|_
6756Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
6757Aggressive OS guesses: Crestron XPanel control system (87%), Vodavi XTS-IP PBX (87%), HP P2000 G3 NAS device (86%), ASUS RT-N56U WAP (Linux 3.4) (86%), Linux 3.16 (86%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (85%), Sun Solaris 9 or 10, or OpenSolaris 2009.06 snv_111b (85%)
6758No exact OS matches for host (test conditions non-ideal).
6759Uptime guess: 28.791 days (since Sat Dec 21 09:35:25 2019)
6760Network Distance: 25 hops
6761TCP Sequence Prediction: Difficulty=172 (Good luck!)
6762IP ID Sequence Generation: Incremental
6763
6764TRACEROUTE (using port 80/tcp)
6765HOP RTT ADDRESS
67661 100.20 ms 10.253.204.1
67672 100.25 ms 104.245.145.177
67683 100.28 ms te0-0-2-1.225.nr11.b010988-1.yyz02.atlas.cogentco.com (38.104.156.9)
67694 100.30 ms te0-0-0-1.agr13.yyz02.atlas.cogentco.com (154.24.54.37)
67705 100.28 ms te0-9-0-9.ccr31.yyz02.atlas.cogentco.com (154.54.43.141)
67716 100.33 ms be2993.ccr21.cle04.atlas.cogentco.com (154.54.31.225)
67727 100.35 ms be2717.ccr41.ord01.atlas.cogentco.com (154.54.6.221)
67738 100.38 ms be2831.ccr21.mci01.atlas.cogentco.com (154.54.42.165)
67749 100.40 ms be3035.ccr21.den01.atlas.cogentco.com (154.54.5.89)
677510 100.45 ms be3037.ccr21.slc01.atlas.cogentco.com (154.54.41.145)
677611 131.25 ms be3109.ccr21.sfo01.atlas.cogentco.com (154.54.44.137)
677712 131.24 ms be3669.ccr41.sjc03.atlas.cogentco.com (154.54.43.10)
677813 101.08 ms 38.88.224.178
677914 131.27 ms 111.87.3.117
678015 242.76 ms 106.187.13.9
678116 242.79 ms 27.85.224.170
678217 242.85 ms 125.29.26.58
678318 203.04 ms 133.208.191.11
678419 242.78 ms 133.208.55.50
678520 242.80 ms unused-133-130-015-097.interq.or.jp (133.130.15.97)
678621 201.74 ms unused-133-130-013-018.interq.or.jp (133.130.13.18)
678722 245.10 ms g-o-p-2w-a18-1-e-1-10.interq.or.jp (157.7.40.130)
678823 245.01 ms unused-157-007-038-082.interq.or.jp (157.7.38.82)
678924 ...
679025 201.28 ms www18.gmoserver.jp (133.130.64.112)
6791
6792NSE: Script Post-scanning.
6793Initiating NSE at 04:34
6794Completed NSE at 04:34, 0.00s elapsed
6795Initiating NSE at 04:34
6796Completed NSE at 04:34, 0.00s elapsed
6797#######################################################################################################################################
6798Starting Nmap 7.80 ( https://nmap.org ) at 2020-01-19 04:34 EST
6799NSE: Loaded 162 scripts for scanning.
6800NSE: Script Pre-scanning.
6801Initiating NSE at 04:34
6802Completed NSE at 04:34, 0.00s elapsed
6803Initiating NSE at 04:34
6804Completed NSE at 04:34, 0.00s elapsed
6805Initiating Parallel DNS resolution of 1 host. at 04:34
6806Completed Parallel DNS resolution of 1 host. at 04:34, 0.02s elapsed
6807Initiating SYN Stealth Scan at 04:34
6808Scanning www18.gmoserver.jp (133.130.64.112) [1 port]
6809Discovered open port 443/tcp on 133.130.64.112
6810Completed SYN Stealth Scan at 04:34, 0.23s elapsed (1 total ports)
6811Initiating Service scan at 04:34
6812Scanning 1 service on www18.gmoserver.jp (133.130.64.112)
6813Completed Service scan at 04:34, 13.38s elapsed (1 service on 1 host)
6814Initiating OS detection (try #1) against www18.gmoserver.jp (133.130.64.112)
6815Retrying OS detection (try #2) against www18.gmoserver.jp (133.130.64.112)
6816Initiating Traceroute at 04:35
6817Completed Traceroute at 04:35, 3.32s elapsed
6818Initiating Parallel DNS resolution of 24 hosts. at 04:35
6819Completed Parallel DNS resolution of 24 hosts. at 04:35, 0.91s elapsed
6820NSE: Script scanning 133.130.64.112.
6821Initiating NSE at 04:35
6822Completed NSE at 04:36, 90.52s elapsed
6823Initiating NSE at 04:36
6824Completed NSE at 04:36, 2.23s elapsed
6825Nmap scan report for www18.gmoserver.jp (133.130.64.112)
6826Host is up (0.24s latency).
6827
6828PORT STATE SERVICE VERSION
6829443/tcp open ssl/http Apache httpd
6830| http-brute:
6831|_ Path "/" does not require authentication
6832|_http-chrono: Request times for /; avg: 1046.40ms; min: 999.14ms; max: 1130.25ms
6833|_http-csrf: Couldn't find any CSRF vulnerabilities.
6834|_http-date: Sun, 19 Jan 2020 09:35:23 GMT; -5s from local time.
6835|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
6836|_http-dombased-xss: Couldn't find any DOM based XSS.
6837| http-errors:
6838| Spidering limited to: maxpagecount=40; withinhost=www18.gmoserver.jp
6839| Found the following error pages:
6840|
6841| Error Code: 404
6842|_ https://www18.gmoserver.jp:443/
6843|_http-feed: Couldn't find any feeds.
6844|_http-fetch: Please enter the complete path of the directory to save data in.
6845| http-headers:
6846| Date: Sun, 19 Jan 2020 09:35:29 GMT
6847| Server: Apache
6848| Last-Modified: Wed, 02 Aug 2017 08:47:14 GMT
6849| Accept-Ranges: bytes
6850| Content-Length: 1242
6851| Connection: close
6852| Content-Type: text/html
6853|
6854|_ (Request type: GET)
6855|_http-jsonp-detection: Couldn't find any JSONP endpoints.
6856|_http-mobileversion-checker: No mobile version detected.
6857| http-security-headers:
6858| Strict_Transport_Security:
6859|_ HSTS not configured in HTTPS Server
6860|_http-server-header: Apache
6861| http-sitemap-generator:
6862| Directory structure:
6863| Longest directory structure:
6864| Depth: 0
6865| Dir: /
6866| Total files found (by extension):
6867|_
6868|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
6869|_http-title: 403 Forbidden
6870|_http-traceroute: ERROR: Script execution failed (use -d to debug)
6871| http-vhosts:
6872|_127 names had status 403
6873|_http-vuln-cve2014-3704: ERROR: Script execution failed (use -d to debug)
6874|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
6875|_http-xssed: No previously reported XSS vuln.
6876| vulscan: VulDB - https://vuldb.com:
6877| [141649] Apache OFBiz up to 16.11.05 Form Widget Freemarker Markup Code Execution
6878| [141648] Apache OFBiz up to 16.11.05 Application Stored cross site scripting
6879| [140386] Apache Commons Beanutils 1.9.2 BeanIntrospector unknown vulnerability
6880| [139708] Apache Ranger up to 1.2.0 Policy Import cross site scripting
6881| [139540] cPanel up to 60.0.24 Apache HTTP Server Key information disclosure
6882| [139386] Apache Tike up to 1.21 RecursiveParserWrapper Stack-based memory corruption
6883| [139385] Apache Tika 1.19/1.20/1.21 SAXParsers Hang denial of service
6884| [139384] Apache Tika up to 1.21 RecursiveParserWrapper ZIP File denial of service
6885| [139261] Apache Solr 8.2.0 DataImportHandler Parameter unknown vulnerability
6886| [139259] cPanel up to 68.0.26 WHM Apache Includes Editor information disclosure
6887| [139256] cPanel up to 68.0.26 WHM Apache Configuration Include Editor cross site scripting
6888| [139239] cPanel up to 70.0.22 Apache HTTP Server Log information disclosure
6889| [139141] Apache ActiveMQ Client up to 5.15.4 ActiveMQConnection.java ActiveMQConnection denial of service
6890| [139130] cPanel up to 73.x Apache HTTP Server Injection privilege escalation
6891| [138914] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 VM sql injection
6892| [138913] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Block Argument privilege escalation
6893| [138912] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Cookie sql injection
6894| [138816] Apache Storm up to 1.2.2 Logviewer Daemon Log information disclosure
6895| [138815] Apache Storm up to 1.2.2 UI Daemon Deserialization privilege escalation
6896| [138164] Oracle 2.7.0.1 Apache Log4j unknown vulnerability
6897| [138155] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Tomcat unknown vulnerability
6898| [138151] Oracle Transportation Management 6.3.7 Apache Tomcat unknown vulnerability
6899| [138149] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Commons FileUpload unknown vulnerability
6900| [138131] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Tomcat unknown vulnerability
6901| [138129] Oracle Retail Xstore Point of Service 7.0/7.1 Apache HTTP Server denial of service
6902| [138123] Oracle Retail Order Management System 5.0 Apache Struts 1 unknown vulnerability
6903| [138122] Oracle Retail Order Broker 5.2/15.0 Apache Tomcat unknown vulnerability
6904| [138121] Oracle Retail Order Broker 5.2/15.0 Apache CXF unknown vulnerability
6905| [138112] Oracle Retail Integration Bus 15.0/16.0 Apache Commons FileUpload unknown vulnerability
6906| [138111] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Commons FileUpload unknown vulnerability
6907| [138103] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56/8.57 Apache WSS4J information disclosure
6908| [138053] Oracle JD Edwards EnterpriseOne Tools 9.2 Apache Log4j unknown vulnerability
6909| [138036] Oracle Insurance Rules Palette 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
6910| [138035] Oracle Insurance Policy Administration J2EE 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
6911| [138034] Oracle Insurance Calculation Engine 9.7/10.0/10.1/10.2 Apache Commons FileUpload unknown vulnerability
6912| [138028] Oracle Identity Manager 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
6913| [138020] Oracle BI Publisher 11.1.1.9.0 Apache Tomcat unknown vulnerability
6914| [138019] Oracle BI Publisher (formerly XML Publisher) 11.1.1.9.0 Apache Tomcat unknown vulnerability
6915| [138017] Oracle Outside In Technology 8.5.4 Apache Commons FileUpload unknown vulnerability
6916| [138013] Oracle Outside In Technology 8.5.4 Apache Tomcat unknown vulnerability
6917| [138012] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
6918| [138009] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
6919| [138008] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Struts 1 denial of service
6920| [138007] Oracle WebCenter Sites 12.2.1.3.0 Apache Tomcat denial of service
6921| [138006] Oracle Enterprise Repository 12.1.3.0.0 Apache CXF denial of service
6922| [138000] Oracle WebCenter Sites 12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
6923| [137999] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
6924| [137995] Oracle Hospitality Simphony 18.2.1 Apache WSS4J information disclosure
6925| [137987] Oracle FLEXCUBE Universal Banking up to 12.0.3/12.4.0/14.2.0 Apache Log4j unknown vulnerability
6926| [137981] Oracle Insurance IFRS 17 Analyzer 8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
6927| [137980] Oracle Insurance Data Foundation 8.0.4/8.0.5/8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
6928| [137979] Oracle 8.0.8 Apache Commons FileUpload unknown vulnerability
6929| [137973] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Batik unknown vulnerability
6930| [137970] Oracle Financial Services Profitability Management 8.0.4/8.0.5/8.0.6/8.0.7 Apache ActiveMQ unknown vulnerability
6931| [137967] Oracle up to 8.0.7 Apache httpd unknown vulnerability
6932| [137966] Oracle 8.0.7/8.0.8 Apache Groovy unknown vulnerability
6933| [137965] Oracle Financial Services Liquidity Risk Management 8.0.1/8.0.2/8.0.4/8.0.5/8.0.6 Apache Commons FileUpload unknown vulnerability
6934| [137964] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Log4j unknown vulnerability
6935| [137933] Oracle Banking Platform up to 2.7.1 Apache Tika unknown vulnerability
6936| [137926] Oracle Enterprise Manager for Fusion Middleware 13.2/13.3 Apache Commons FileUpload information disclosure
6937| [137924] Oracle Enterprise Manager Base Platform 12.1.0.5.0/13.2.0.0.0/13.3.0.0.0 Apache Commons FileUpload unknown vulnerability
6938| [137914] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
6939| [137913] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
6940| [137911] Oracle E-Business Suite up to 12.2.8 Apache HTTP Server unknown vulnerability
6941| [137910] Oracle E-Business Suite up to 12.2.8 Apache CXF information disclosure
6942| [137909] Oracle E-Business Suite up to 12.2.8 Apache Commons FileUpload unknown vulnerability
6943| [137905] Oracle Primavera Gateway 15.2/16.2/17.12/18.8 Apache Tika denial of service
6944| [137901] Oracle Primavera Unifier up to 18.8 Apache HTTP Server unknown vulnerability
6945| [137895] Oracle Instant Messaging Server 10.0.1.2.0 Apache Tika information disclosure
6946| [137894] Oracle EAGLE (Software) 46.5/46.6/46.7 Apache Tomcat information disclosure
6947| [137892] Oracle Online Mediation Controller 6.1 Apache Batik denial of service
6948| [137891] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Tomcat unknown vulnerability
6949| [137885] Oracle Diameter Signaling Router (DSR) 8.0/8.1/8.2 Apache cxf unknown vulnerability
6950| [137882] Oracle Unified 8.0.0.2.0 Apache Commons FileUpload unknown vulnerability
6951| [137881] Oracle Online Mediation Controller 6.1 Apache Commons FileUpload unknown vulnerability
6952| [137880] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Log4j unknown vulnerability
6953| [137879] Oracle Convergence 3.0.2 Apache Commons FileUpload unknown vulnerability
6954| [137876] Oracle Application Session Controller 3.7.1/3.8.0 Apache Commons FileUpload unknown vulnerability
6955| [137829] Apache Roller 5.2.3 Math Comment Authenticator Reflected cross site scripting
6956| [137736] Apache Kafka 0.11.0.0/2.1.0 ACL Validation Request privilege escalation
6957| [136858] MakerBot Replicator 5G Printer Apache HTTP Server information disclosure
6958| [136849] Analogic Poste.io 2.1.6 on Apache RoundCube logs/ information disclosure
6959| [136822] Apache Tomcat up to 8.5.40/9.0.19 Incomplete Fix CVE-2019-0199 Resource Exhaustion denial of service
6960| [136808] Apache Geode up to 1.8.0 Secure Mode privilege escalation
6961| [136646] Apache Allura up to 1.10.x Dropdown Selector Stored cross site scripting
6962| [136374] Apache HTTP Server up to 2.4.38 Slash Regular Expression unknown vulnerability
6963| [136373] Apache HTTP Server 2.4.34/2.4.35/2.4.36/2.4.37/2.4.38 HTTP2 Request Crash denial of service
6964| [136372] Apache HTTP Server up to 2.4.38 HTTP2 Request unknown vulnerability
6965| [136370] Apache Fineract up to 1.2.x sql injection
6966| [136369] Apache Fineract up to 1.2.x sql injection
6967| [135731] Apache Hadoop up to 2.8.4/2.9.1/3.1.0 yarn privilege escalation
6968| [135664] Apache Tomcat up to 7.0.93/8.5.39/9.0.0.17 SSI printenv Command cross site scripting
6969| [135663] Apache Camel up to 2.23.x JSON-lib Library XML Data XML External Entity
6970| [135661] Apache Roller up to 5.2.1/5.2.0 XML-RPC Interface XML File Server-Side Request Forgery
6971| [135402] Apache Zookeeper up to 3.4.13/3.5.0-alpha to 3.5.4-beta getACL() information disclosure
6972| [135270] Apache JSPWiki up to 2.11.0.M3 Plugin Link cross site scripting
6973| [135269] Apache JSPWiki up to 2.11.0.M3 InterWiki Link cross site scripting
6974| [135268] Apache JSPWiki up to 2.11.0.M3 Attachment cross site scripting
6975| [134527] Apache Karaf up to 4.2.4 Config Service directory traversal
6976| [134416] Apache Sanselan 0.97-incubator Loop denial of service
6977| [134415] Apache Sanselan 0.97-incubator Hang denial of service
6978| [134291] Apache Axis up to 1.7.8 Server-Side Request Forgery
6979| [134290] Apache UIMA DUCC up to 2.2.2 cross site scripting
6980| [134248] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
6981| [134247] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
6982| [134246] Apache Camel up to 2.19/2.21.3/2.22.2/2.23.0 directory traversal
6983| [134138] Apache Pluto 3.0.0/3.0.1 Chat Room Demo Portlet cross site scripting
6984| [133992] Apache Qpid Proton up to 0.27.0 Certificate Validation Man-in-the-Middle weak authentication
6985| [133977] Apache Zeppelin up to 0.7.x Stored cross site scripting
6986| [133976] Apache Zeppelin up to 0.7.x Cron Scheduler privilege escalation
6987| [133975] Apache Zeppelin up to 0.7.2 Session Fixation weak authentication
6988| [133444] Apache PDFbox 2.0.14 XML Parser XML External Entity
6989| [133573] Oracle FLEXCUBE Private Banking 2.0.0.0/2.2.0.1/12.0.1.0/12.0.3.0/12.1.0.0 Apache ActiveMQ unknown vulnerability
6990| [133407] Apache Tomcat up to 7.0.93/8.5.39/9.0.17 on Windows JRE Command Line Argument Code Execution
6991| [133315] Apache Airflow up to 1.10.2 HTTP Endpoint cross site request forgery
6992| [133314] Apache Airflow up to 1.10.2 Metadata Database cross site scripting
6993| [133290] Apache Tomcat up to 8.5.37/9.0.14 HTTP2 Stream Execution denial of service
6994| [133112] Apache HTTP Server up to 2.4.38 mod_auth_digest race condition privilege escalation
6995| [133111] Apache HTTP Server 2.4.37/2.4.38 mod_ssl Bypass privilege escalation
6996| [133092] Airsonic 10.2.1 org.apache.commons.lang.RandomStringUtils RecoverController.java java.util.Random weak authentication
6997| [132568] Apache JSPWiki up to 2.11.0.M2 URL User information disclosure
6998| [132567] Apache JSPWiki up to 2.11.0.M2 URL cross site scripting
6999| [132566] Apache ActiveMQ up to 5.15.8 MQTT Frame Memory denial of service
7000| [132565] Apache HBase up to 2.1.3 REST Server Request privilege escalation
7001| [132183] Apache Mesos up to pre-1.4.x Docker Image Code Execution
7002| [131988] Apache Karaf up to 4.2.2 kar Deployer directory traversal
7003| [131859] Apache Hadoop up to 2.9.1 privilege escalation
7004| [131479] Apache Solr up to 7.6 HTTP GET Request Server-Side Request Forgery
7005| [131446] Apache Solr up to 5.0.5/6.6.5 Config API HTTP POST Request Code Execution
7006| [131385] Apache Qpid Broker-J up to 6.x/7.0.6/7.1.0 AMQP Command Crash denial of service
7007| [131315] Apache Mesos up to pre-1.4.x Mesos Masters Rendering JSON Payload Recursion denial of service
7008| [131236] Apache Airflow up to 1.10.1 Metadata Database cross site scripting
7009| [130755] Apache JSPWiki up to 2.10.5 URL cross site scripting
7010| [130629] Apache Guacamole Cookie Flag weak encryption
7011| [130628] Apache Hadoop up to 3.0.0 HDFS information disclosure
7012| [130529] Apache Subversion 1.10.0/1.10.1/1.10.2/1.10.3/1.11.0 mod_dav_svn Directory Crash denial of service
7013| [130353] Apache Open Office up to 4.1.5 Document Loader String memory corruption
7014| [130341] Apache HTTP Server 2.4.37 mod_ssl Loop denial of service
7015| [130330] Apache HTTP Server up to 2.4.37 mod_session Expired privilege escalation
7016| [130329] Apache HTTP Server 2.4.37 mod_http2 Slowloris denial of service
7017| [130212] Apache Airflow up to 1.10.0 LDAP Auth Backend Certificate weak authentication
7018| [130123] Apache Airflow up to 1.8.2 information disclosure
7019| [130122] Apache Airflow up to 1.8.2 command injection cross site request forgery
7020| [130121] Apache Airflow up to 1.8.2 Webserver Object Code Execution
7021| [129717] Oracle Secure Global Desktop 5.4 Apache HTTP Server denial of service
7022| [129688] Oracle Tape Library ACSLS 8.4 Apache Log4j unknown vulnerability
7023| [129673] Oracle Retail Returns Management 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
7024| [129672] Oracle Retail Central Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
7025| [129671] Oracle Retail Back Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
7026| [129574] Oracle Outside In Technology 8.5.3/8.5.4 Apache Tomcat denial of service
7027| [129573] Oracle WebLogic Server 10.3.6.0 Apache HTTP Server denial of service
7028| [129563] Oracle Enterprise Repository 12.1.3.0.0 Apache Log4j unknown vulnerability
7029| [129555] Oracle Outside In Technology 8.5.3 Apache Batik denial of service
7030| [129551] Oracle Outside In Technology 8.5.3/8.5.4 Apache Commons FileUpload denial of service
7031| [129542] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
7032| [129538] Oracle SOA Suite 12.1.3.0.0/12.2.1.3.0 Apache Batik unknown vulnerability
7033| [129519] Oracle Enterprise Manager Ops Center 12.2.2/12.3.3 Apache ActiveMQ unknown vulnerability
7034| [129508] Oracle Applications Manager up to 12.2.8 Apache Derby unknown vulnerability
7035| [129507] Oracle Mobile Field Service up to 12.2.8 Apache Log4j unknown vulnerability
7036| [129505] Oracle Email Center up to 12.2.8 Apache Log4j unknown vulnerability
7037| [129504] Oracle CRM Technical Foundation up to 12.2.8 Apache Commons FileUpload unknown vulnerability
7038| [129499] Oracle Partner Management up to 12.2.8 Apache Log4j unknown vulnerability
7039| [129498] Oracle Marketing up to 12.2.8 Apache Commons FileUpload unknown vulnerability
7040| [129480] Oracle Communications WebRTC Session Controller up to 7.1 Apache Batik unknown vulnerability
7041| [129479] Oracle Communications Diameter Signaling Router up to 8.2 Apache Batik unknown vulnerability
7042| [129474] Oracle Communications Diameter Signaling Router up to 8.2 Apache HTTP Server information disclosure
7043| [129472] Oracle Communications WebRTC Session Controller up to 7.1 Apache Struts 1 unknown vulnerability
7044| [129470] Oracle Communications Converged Application Server up to 7.0.0.0 Apache Struts 1 unknown vulnerability
7045| [129463] Oracle Communications WebRTC Session Controller up to 7.1 Apache Log4j unknown vulnerability
7046| [129461] Oracle Communications Services Gatekeeper up to 6.1.0.3.x Apache Commons Collections Fileupload unknown vulnerability
7047| [129460] Oracle Communications Service Broker 6.0 Apache Log4j unknown vulnerability
7048| [129459] Oracle Communications Policy Management up to 12.4 Apache Struts 2 unknown vulnerability
7049| [129458] Oracle Communications Online Mediation Controller 6.1 Apache Log4j unknown vulnerability
7050| [129457] Oracle Communications Diameter Signaling Router up to 8.2 Apache Commons Fileupload unknown vulnerability
7051| [129456] Oracle Communications Converged Application Server 6.1 Apache Log4j unknown vulnerability
7052| [128714] Apache Thrift Java Client Library up to 0.11.0 SASL Negotiation org.apache.thrift.transport.TSaslTransport unknown vulnerability
7053| [128713] Apache Thrift Node.js Static Web Server up to 0.11.0 directory traversal
7054| [128709] Apache Karaf up to 4.1.6/4.2.1 Features Deployer XMLInputFactory XML External Entity
7055| [128575] Apache NetBeans 9.0 Proxy Auto-Config Code Execution
7056| [128369] Apache Tika 1.8-1.19.1 SQLite3Parser Loop sql injection
7057| [128111] Apache NiFi 1.8.0 Template Upload Man-in-the-Middle cross site request forgery
7058| [128110] Apache NiFi 1.8.0 Cluster Request privilege escalation
7059| [128109] Apache NiFi 1.8.0 Error Page message-page.jsp Request Header cross site scripting
7060| [128108] Apache NiFi up to 1.7.x X-Frame-Options Header privilege escalation
7061| [128102] Apache Oozie up to 5.0.0 Workflow XML Impersonation spoofing
7062| [127994] WordPress up to 5.0.0 on Apache httpd MIME Restriction cross site scripting
7063| [127981] Apache OFBiz 16.11.01/16.11.02/16.11.03/16.11.04 HTTP Engine httpService GET Request privilege escalation
7064| [127161] Apache Hadoop 2.7.4/2.7.5/2.7.6 Incomplete Fix CVE-2016-6811 privilege escalation
7065| [127040] Loadbalancer.org Enterprise VA MAX up to 8.3.2 Apache HTTP Server Log cross site scripting
7066| [127007] Apache Spark Request Code Execution
7067| [126791] Apache Hadoop up to 0.23.11/2.7.6/2.8.4/2.9.1/3.0.2 ZIP File unknown vulnerability
7068| [126767] Apache Qpid Proton-J Transport 0.3 Certificate Verification Man-in-the-Middle weak authentication
7069| [126896] Apache Commons FileUpload 1.3.3 on LDAP Manager DiskFileItem File privilege escalation
7070| [126574] Apache Hive up to 2.3.3/3.1.0 Query privilege escalation
7071| [126573] Apache Hive up to 2.3.3/3.1.0 HiveServer2 privilege escalation
7072| [126564] Apache Superset up to 0.22 Pickle Library load Code Execution
7073| [126488] Apache Syncope up to 2.0.10/2.1.1 BPMN Definition xxe privilege escalation
7074| [126487] Apache Syncope up to 2.0.10/2.1.1 cross site scripting
7075| [126346] Apache Tomcat Path privilege escalation
7076| [125922] Apache Impala up to 3.0.0 ALTER privilege escalation
7077| [125921] Apache Impala up to 3.0.0 Queue Injection privilege escalation
7078| [125647] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Install (Apache Tomcat) information disclosure
7079| [125617] Oracle Retail Returns Management 14.1 Apache Batik unknown vulnerability
7080| [125616] Oracle Retail Point-of-Service 13.4/14.0/14.1 Apache Batik unknown vulnerability
7081| [125614] Oracle Retail Central Office 14.1 Apache Batik unknown vulnerability
7082| [125613] Oracle Retail Back Office 13.3/13.4/14/14.1 Apache Batik unknown vulnerability
7083| [125599] Oracle Retail Open Commerce Platform 5.3.0/6.0.0/6.0.1 Apache Log4j unknown vulnerability
7084| [125569] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56 Apache HTTP Server information disclosure
7085| [125494] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat information disclosure
7086| [125447] Oracle Business Intelligence Enterprise Edition 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Batik unknown vulnerability
7087| [125428] Oracle Identity Management Suite 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
7088| [125427] Oracle Identity Analytics 11.1.1.5.8 Apache Log4j unknown vulnerability
7089| [125424] Oracle API Gateway 11.1.2.4.0 Apache Log4j unknown vulnerability
7090| [125423] Oracle BI Publisher 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Log4j unknown vulnerability
7091| [125383] Oracle up to 10.2.0 Apache Trinidad unknown vulnerability
7092| [125379] Oracle up to 10.1.x Apache Struts 1 cross site scripting
7093| [125377] Oracle up to 10.2.0 Apache Commons Collections unknown vulnerability
7094| [125376] Oracle Communications Application Session Controller up to 3.7.0 Apache Commons Collections unknown vulnerability
7095| [125375] Oracle Communications User Data Repository up to 12.1.x Apache Xerces memory corruption
7096| [125248] Apache ActiveMQ up to 5.15.5 Web-based Administration Console queue.jsp Parameter cross site scripting
7097| [125133] Apache Tika up to 1.19 XML Parser reset() denial of service
7098| [124877] Apache PDFbox up to 2.0.11 PDF File denial of service
7099| [124876] Apache Ranger up to 1.1.x UnixAuthenticationService Stack-based memory corruption
7100| [124791] Apache Tomcat up to 7.0.90/8.5.33/9.0.11 URL Open Redirect
7101| [124787] Apache Pony Mail 0.7/0.8/0.9 Statistics Generator Timestamp Data information disclosure
7102| [124447] Apache HTTP Server up to 2.4.34 SETTINGS Frame denial of service
7103| [124346] Apache Mesos pre-1.4.2/1.5.0/1.5.1/1.6.0 on Executor HTTP API String Comparison validation JSON Web Token information disclosure
7104| [124286] Apache Tika up to 1.18 IptcAnpaParser Loop denial of service
7105| [124242] Apache Tika up to 0.18 C:/evil.bat" Directory unknown vulnerability
7106| [124241] Apache Tika up to 0.18 XML Parser Entity Expansion denial of service
7107| [124191] Apache Karaf up to 3.0.8/4.0.8/4.1.0 WebConsole .../gogo/ weak authentication
7108| [124190] Apache Karaf up to 4.1.x sshd privilege escalation
7109| [124152] Apache Camel Mail up to 2.22.0 Path directory traversal
7110| [124143] Apache SpamAssassin up to 3.4.1 PDFInfo Plugin Code Execution
7111| [124134] Apache SpamAssassin up to 3.4.1 Scan Engine HTML::Parser Email denial of service
7112| [124095] PHP up to 5.6.37/7.0.31/7.1.21/7.2.9 Apache2 sapi_apache2.c php_handler cross site scripting
7113| [124024] Apache Mesos 1.4.x/1.5.0 libprocess JSON Payload denial of service
7114| [123814] Apache ActiveMQ Client up to 5.15.5 TLS Hostname Verification Man-in-the-Middle weak authentication
7115| [123393] Apache Traffic Server up to 6.2.2/7.1.3 ESI Plugin Config privilege escalation
7116| [123392] Apache Traffic Server 6.2.2 TLS Handshake Segmentation Fault denial of service
7117| [123391] Apache Traffic Server up to 6.2.2/7.1.3 Range Request Performance denial of service
7118| [123390] Apache Traffic Server up to 6.2.2/7.1.3 Request HTTP Smuggling privilege escalation
7119| [123369] Apache Traffic Server up to 6.2.2/7.1.3 ACL remap.config Request denial of service
7120| [123197] Apache Sentry up to 2.0.0 privilege escalation
7121| [123145] Apache Struts up to 2.3.34/2.5.16 Namespace Code Execution
7122| [123144] Apache Cayenne up to 4.1.M1 CayenneModeler XML File File Transfer privilege escalation
7123| [122981] Apache Commons Compress 1.7 ZipArchiveInputStream ZIP Archive denial of service
7124| [122889] Apache HTTP Server up to 2.2.31/2.4.23 mod_userdir HTTP Response Splitting privilege escalation
7125| [122800] Apache Spark 1.3.0 REST API weak authentication
7126| [122642] Apache Airflow up to 1.8.x 404 Page Reflected cross site scripting
7127| [122568] Apache Tomcat up to 8.5.31/9.0.9 Connection Reuse weak authentication
7128| [122567] Apache Axis 1.0./1.1/1.2/1.3/1.4 cross site scripting
7129| [122556] Apache Tomcat up to 7.0.86/8.0.51/8.5.30/9.0.7 UTF-8 Decoder Loop denial of service
7130| [122531] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.9 WebSocket Client unknown vulnerability
7131| [122456] Apache Camel up to 2.20.3/2.21.0 XSD Validator XML External Entity
7132| [122455] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Revoked Certificate weak authentication
7133| [122454] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Responder Revoked Certificate weak authentication
7134| [122214] Apache Kafka up to 0.9.0.1/0.10.2.1/0.11.0.2/1.0.0 Broker Request Data Loss denial of service
7135| [122202] Apache Kafka up to 0.10.2.1/0.11.0.1 SASL Impersonation spoofing
7136| [122101] Docker Skeleton Runtime for Apache OpenWhisk Docker Action dockerskeleton:1.3.0 privilege escalation
7137| [122100] PHP Runtime for Apache OpenWhisk Docker Action action-php-v7.2:1.0.0 privilege escalation
7138| [122012] Apache Ignite up to 2.5 Serialization privilege escalation
7139| [121911] Apache Ambari up to 2.5.x/2.6.2 Log Message Credentials information disclosure
7140| [121910] Apache HTTP Server 2.4.33 mod_md HTTP Requests denial of service
7141| [121854] Oracle Tape Library ACSLS up to ACSLS 8.4.0-2 Apache Commons Collections unknown vulnerability
7142| [121752] Oracle Insurance Policy Administration 10.0/10.1/10.2/11.0 Apache Log4j unknown vulnerability
7143| [121370] Apache Spark up to 2.1.2/2.2.1/2.3.0 URL cross site scripting
7144| [121354] Apache CouchDB HTTP API Code Execution
7145| [121144] Apache LDAP API up to 1.0.1 SSL Filter information disclosure
7146| [121143] Apache Storm up to 0.10.2/1.0.6/1.1.2/1.2.1 Cluster privilege escalation
7147| [120436] Apache CXF Fediz up to 1.4.3 Application Plugin unknown vulnerability
7148| [120310] Apache PDFbox up to 1.8.14/2.0.10 AFMParser Loop denial of service
7149| [120168] Apache CXF weak authentication
7150| [120080] Apache Cassandra up to 3.11.1 JMX/RMI Interface RMI Request privilege escalation
7151| [120043] Apache HBase up to 1.2.6.0/1.3.2.0/1.4.4/2.0.0 Thrift 1 API Server weak authentication
7152| [119723] Apache Qpid Broker-J 7.0.0/7.0.1/7.0.2/7.0.3/7.0.4 AMQP Messages Crash denial of service
7153| [122569] Apache HTTP Server up to 2.4.33 HTTP2 Request denial of service
7154| [119486] Apache Geode up to 1.4.0 Security Manager Code Execution
7155| [119306] Apache MXNet Network Interface privilege escalation
7156| [118999] Apache Storm up to 1.0.6/1.1.2/1.2.1 Archive directory traversal
7157| [118996] Apache Storm up to 1.0.6/1.1.2/1.2.1 Daemon spoofing
7158| [118644] Apple macOS up to 10.13.5 apache_mod_php unknown vulnerability
7159| [118200] Apache Batik up to 1.9 Deserialization unknown vulnerability
7160| [118143] Apache NiFi activemq-client Library Deserialization denial of service
7161| [118142] Apache NiFi 1.6.0 SplitXML xxe privilege escalation
7162| [118051] Apache Zookeeper up to 3.4.9/3.5.3-beta weak authentication
7163| [117997] Apache ORC up to 1.4.3 ORC File Recursion denial of service
7164| [117825] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.8 CORS Filter privilege escalation
7165| [117405] Apache Derby up to 10.14.1.0 Network Server Network Packet privilege escalation
7166| [117347] Apache Ambari up to 2.6.1 HTTP Request directory traversal
7167| [117265] LibreOffice/Apache Office Writer SMB Connection XML Document information disclosure
7168| [117143] Apache uimaj/uima-as/uimaFIT/uimaDUCC XML XXE information disclosure
7169| [117117] Apache Tika up to 1.17 ChmParser Loop denial of service
7170| [117116] Apache Tika up to 1.17 BPGParser Loop denial of service
7171| [117115] Apache Tika up to 1.17 tika-server command injection
7172| [116929] Apache Fineract getReportType Parameter privilege escalation
7173| [116928] Apache Fineract REST Endpoint Parameter privilege escalation
7174| [116927] Apache Fineract MakercheckersApiResource Parameter sql injection
7175| [116926] Apache Fineract REST Parameter privilege escalation
7176| [116574] Apache wicket-jquery-ui up to 6.29.0/7.10.1/8.0.0-M9.1 WYSIWYG Editor privilege escalation
7177| [116622] Oracle Enterprise Manager for MySQL Database 12.1.0.4 EM Plugin: General (Apache Tomcat) unknown vulnerability
7178| [115931] Apache Solr up to 6.6.2/7.2.1 XML Data Parameter XML External Entity
7179| [115883] Apache Hive up to 2.3.2 privilege escalation
7180| [115882] Apache Hive up to 2.3.2 xpath_short information disclosure
7181| [115881] Apache DriverHive JDBC Driver up to 2.3.2 Escape Argument Bypass privilege escalation
7182| [115518] Apache Ignite 2.3 Deserialization privilege escalation
7183| [115260] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache cross site scripting
7184| [115259] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache Cookie Stack-based memory corruption
7185| [115500] CA Workload Control Center up to r11.4 SP5 Apache MyFaces Component Code Execution
7186| [115121] Apache Struts REST Plugin up to 2.5.15 Xstream XML Data denial of service
7187| [115061] Apache HTTP Server up to 2.4.29 HTTP Digest Authentication Challenge HTTP Requests Replay privilege escalation
7188| [115060] Apache HTTP Server up to 2.4.29 mod_cache_socache Request Header Crash denial of service
7189| [115059] Apache HTTP Server up to 2.4.29 HTTP2 NULL Pointer Dereference denial of service
7190| [115058] Apache HTTP Server up to 2.4.29 HTTP Header Crash denial of service
7191| [115057] Apache HTTP Server up to 2.4.29 mod_session Variable Name Cache privilege escalation
7192| [115039] Apache HTTP Server up to 2.4.29 FilesMatch File Upload privilege escalation
7193| [115038] Apache HTTP Server up to 2.0.65/2.2.34/2.4.29 mod_authnz_ldap Crash denial of service
7194| [114817] Apache Syncope up to 1.2.10/2.0.7 Search Parameter information disclosure
7195| [114816] Apache Syncope up to 1.2.10/2.0.7 XSLT Code Execution
7196| [114717] Apache Commons 1.11/1.12/1.13/1.14/1.15 ZIP Archive ZipFile/ZipArchiveInputStream denial of service
7197| [114661] Apache Allura up to 1.8.0 HTTP Response Splitting privilege escalation
7198| [114400] Apache Tomcat JK ISAPI Connector up to 1.2.42 IIS/ISAPI privilege escalation
7199| [114258] Apache HTTP Server up to 2.4.22 mod_cluster Segmentation Fault denial of service
7200| [114086] Apache ODE 1.3.3 ODE Process Deployment Web Service directory traversal
7201| [113955] Apache Xerces-C up to 3.2.0 XML Parser NULL Pointer Dereference denial of service
7202| [113945] Apache Tomcat up to 7.0.84/8.0.49/8.5.27/9.0.4 URL Pattern Empty String privilege escalation
7203| [113944] Apache OpenMeetings up to 3.x/4.0.1 CRUD Operation denial of service
7204| [113905] Apache Traffic Server up to 5.2.x/5.3.2/6.2.0/7.0.0 TLS Handshake Core Dump denial of service
7205| [113904] Apache Traffic Server up to 6.2.0 Host Header privilege escalation
7206| [113895] Apache Geode up to 1.3.x Code Execution
7207| [113894] Apache Geode up to 1.3.x TcpServer Code Execution
7208| [113888] Apache James Hupa WebMail 0.0.2 cross site scripting
7209| [113813] Apache Geode Cluster up to 1.3.x Secure Mode privilege escalation
7210| [113747] Apache Tomcat Servlets privilege escalation
7211| [113647] Apache Qpid up to 0.30 qpidd Broker AMQP Message Crash denial of service
7212| [113645] Apache VCL up to 2.1/2.2.1/2.3.1 Web GUI/XMLRPC API privilege escalation
7213| [113560] Apache jUDDI Console 3.0.0 Log Entries spoofing
7214| [113571] Apache Oozie up to 4.3.0/5.0.0-beta1 XML Data XML File privilege escalation
7215| [113569] Apache Karaf up to 4.0.7 LDAPLoginModule LDAP injection denial of service
7216| [113273] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
7217| [113198] Apache Qpid Dispatch Router 0.7.0/0.8.0 AMQP denial of service
7218| [113186] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
7219| [113145] Apache Thrift up to 0.9.3 Go Client Library privilege escalation
7220| [113106] Apache jUDDI up to 3.3.3 XML Data WADL2Java/WSDL2Java XML Document privilege escalation
7221| [113105] Apache Qpid Broker-J 7.0.0 AMQP Crash denial of service
7222| [112885] Apache Allura up to 1.8.0 File information disclosure
7223| [112856] Apache CloudStack up to 4.8.1.0/4.9.0.0 API weak authentication
7224| [112855] Apache CloudStack 4.1.0/4.1.1 API information disclosure
7225| [112678] Apache Tomcat up to 7.0.82/8.0.47/8.5.23/9.0.1 Bug Fix 61201 privilege escalation
7226| [112677] Apache Tomcat Native Connector up to 1.1.34/1.2.14 OCSP Checker Client weak authentication
7227| [112625] Apache POI up to 3.16 Loop denial of service
7228| [112448] Apache NiFi up to 1.3.x Deserialization privilege escalation
7229| [112396] Apache Hadoop 2.7.3/2.7.4 YARN NodeManager Credentials information disclosure
7230| [112339] Apache NiFi 1.5.0 Header privilege escalation
7231| [112330] Apache NiFi 1.5.0 Header HTTP Request privilege escalation
7232| [112314] NetGain Enterprise Manager 7.2.730 Build 1034 org.apache.jsp.u.jsp.tools.exec_jsp Servlet Parameter privilege escalation
7233| [112253] Apache Hadoop up to 0.23.x/2.7.4/2.8.2 MapReduce Job History Server Configuration File privilege escalation
7234| [112171] Oracle Secure Global Desktop 5.3 Apache Log4j privilege escalation
7235| [112164] Oracle Agile PLM 9.3.5/9.3.6 Apache Tomcat unknown vulnerability
7236| [112161] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Tomcat privilege escalation
7237| [112158] Oracle Autovue for Agile Product Lifecycle Management 21.0.0/21.0.1 Apache Log4j privilege escalation
7238| [112156] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Log4j privilege escalation
7239| [112155] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Apache Log4j privilege escalation
7240| [112137] Oracle MICROS Relate CRM Software 10.8.x/11.4.x/15.0.x, Apache Tomcat unknown vulnerability
7241| [112136] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat privilege escalation
7242| [112133] Oracle Retail Workforce Management 1.60.7/1.64.0 Apache Log4j privilege escalation
7243| [112129] Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 Apache Log4j privilege escalation
7244| [112114] Oracle 9.1 Apache Log4j privilege escalation
7245| [112113] Oracle 9.1 Apache Log4j privilege escalation
7246| [112045] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat privilege escalation
7247| [112038] Oracle Health Sciences Empirica Inspections 1.0.1.1 Apache Tomcat information disclosure
7248| [112019] Oracle Endeca Information Discovery Integrator 3.1.0/3.2.0 Apache Tomcat privilege escalation
7249| [112017] Oracle WebCenter Portal 11.1.1.9.0/12.2.1.2.0/12.2.1.3.0 Apache Struts 1 cross site scripting
7250| [112011] Oracle Identity Manager 11.1.2.3.0 Apache Commons Collections privilege escalation
7251| [111950] Oracle Database 12.2.0.1 Apache Tomcat information disclosure
7252| [111703] Apache Sling XSS Protection API 1.0.4 URL Encoding cross site scripting
7253| [111556] Apache Geode up to 1.2.x Secure Mode Parameter OQL privilege escalation
7254| [111555] Apache Geode up to 1.2.x Secure Mode OQL privilege escalation
7255| [111540] Apache Geode up to 1.2.x Secure Mode information disclosure
7256| [111519] Apache Sling JCR ContentLoader 2.1.4 xmlreader directory traversal
7257| [111338] Apache DeltaSpike-JSF 1.8.0 cross site scripting
7258| [111330] Apache OFBiz 16.11.01/16.11.02/16.11.03 BIRT Plugin cross site scripting
7259| [110789] Apache Sling up to 1.4.0 Authentication Service Credentials information disclosure
7260| [110785] Apache Drill up to 1.11.0 Query Page unknown vulnerability
7261| [110701] Apache Fineract Query Parameter sql injection
7262| [110484] Apache Synapse up to 3.0.0 Apache Commons Collections Serialized Object Code Injection privilege escalation
7263| [110426] Adobe Experience Manager 6.0/6.1/6.2/6.3 Apache Sling Servlets Post cross site scripting
7264| [110141] Apache Struts up to 2.5.14 REST Plugin denial of service
7265| [110140] Apache Qpid Broker-J up to 0.32 privilege escalation
7266| [110139] Apache Qpid Broker-J up to 6.1.4 AMQP Frame denial of service
7267| [110106] Apache CXF Fediz Spring cross site request forgery
7268| [109766] Apache OpenOffice up to 4.1.3 DOC File Parser WW8Fonts memory corruption
7269| [109750] Apache OpenOffice up to 4.1.3 DOC File Parser ImportOldFormatStyles memory corruption
7270| [109749] Apache OpenOffice up to 4.1.3 PPT File Parser PPTStyleSheet memory corruption
7271| [109606] October CMS Build 412 Apache Configuration File Upload privilege escalation
7272| [109419] Apache Camel up to 2.19.3/2.20.0 camel-castor Java Object Deserialization privilege escalation
7273| [109418] Apache Camel up to 2.19.3/2.20.0 camel-hessian Java Object Deserialization privilege escalation
7274| [109400] Apache CouchDB up to 1.6.x/2.1.0 Database Server Shell privilege escalation
7275| [109399] Apache CouchDB up to 1.6.x/2.1.0 JSON Parser Shell privilege escalation
7276| [109398] Apache CXF 3.1.14/3.2.1 JAX-WS/JAX-RS Attachment denial of service
7277| [108872] Apache Hive up to 2.1.1/2.2.0/2.3.0 Policy Enforcement privilege escalation
7278| [108939] Apple macOS up to 10.13.1 apache unknown vulnerability
7279| [108938] Apple macOS up to 10.13.1 apache denial of service
7280| [108937] Apple macOS up to 10.13.1 apache unknown vulnerability
7281| [108936] Apple macOS up to 10.13.1 apache unknown vulnerability
7282| [108935] Apple macOS up to 10.13.1 apache denial of service
7283| [108934] Apple macOS up to 10.13.1 apache unknown vulnerability
7284| [108933] Apple macOS up to 10.13.1 apache unknown vulnerability
7285| [108932] Apple macOS up to 10.13.1 apache unknown vulnerability
7286| [108931] Apple macOS up to 10.13.1 apache denial of service
7287| [108930] Apple macOS up to 10.13.1 apache unknown vulnerability
7288| [108929] Apple macOS up to 10.13.1 apache denial of service
7289| [108928] Apple macOS up to 10.13.1 apache unknown vulnerability
7290| [108797] Apache Struts up to 2.3.19 TextParseUtiltranslateVariables OGNL Expression privilege escalation
7291| [108795] Apache Traffic Server up to 5.3.0 HTTP2 set_dynamic_table_size memory corruption
7292| [108794] Apache WSS4J up to 1.6.16/2.0.1 Incomplete Fix Leak information disclosure
7293| [108793] Apache Qpid up to 0.30 qpidd Crash denial of service
7294| [108792] Apache Traffic Server up to 5.1.0 Access Restriction privilege escalation
7295| [108791] Apache Wicket up to 1.5.11/6.16.x/7.0.0-M2 Session information disclosure
7296| [108790] Apache Storm 0.9.0.1 Log Viewer directory traversal
7297| [108789] Apache Cordova In-App-Browser Standalone Plugin up to 0.3.1 on iOS CDVInAppBrowser privilege escalation
7298| [108788] Apache Cordova File-Transfer Standalone Plugin up to 0.4.1 on iOS ios/CDVFileTransfer.m spoofing
7299| [108787] Apache HttpClient up to 4.3.0 HttpClientBuilder.java unknown vulnerability
7300| [108786] Apache Wicket up to 1.4.21/1.5.9/6.3.x script Tag cross site scripting
7301| [108783] Apache Hadoop up to 0.23.3/1.0.3/2.0.1 Kerberos Security Feature Key weak encryption
7302| [108782] Apache Xerces2 XML Service denial of service
7303| [108781] Apache jUDDI up to 1.x happyjuddi.jsp Parameter cross site scripting
7304| [108780] Apache jUDDI up to 1.x Log File uddiget.jsp spoofing
7305| [108709] Apache Cordova Android up to 3.7.1/4.0.1 intent URL privilege escalation
7306| [108708] Apache ActiveMQ up to 5.10.0 XML Data XML External Entity
7307| [108707] Apache ActiveMQ up to 1.7.0 XML Data XML External Entity
7308| [108629] Apache OFBiz up to 10.04.01 privilege escalation
7309| [108543] Apache Derby 10.1.2.1/10.2.2.0/10.3.1.4/10.4.1.3 Export File privilege escalation
7310| [108312] Apache HTTP Server on RHEL IP Address Filter privilege escalation
7311| [108297] Apache NiFi up to 0.7.1/1.1.1 Proxy Chain Username Deserialization privilege escalation
7312| [108296] Apache NiFi up to 0.7.1/1.1.1 Cluster Request privilege escalation
7313| [108250] Oracle Secure Global Desktop 5.3 Apache HTTP Server memory corruption
7314| [108245] Oracle Transportation Management up to 6.3.7 Apache Tomcat unknown vulnerability
7315| [108244] Oracle Transportation Management 6.4.1/6.4.2 Apache Commons FileUpload denial of service
7316| [108243] Oracle Agile Engineering Data Management 6.1.3/6.2.0 Apache Commons Collections memory corruption
7317| [108222] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Batik denial of service
7318| [108219] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat unknown vulnerability
7319| [108217] Oracle Retail Store Inventory Management 13.2.9/14.0.4/14.1.3/15.0.1/16.0.1 Apache Groovy unknown vulnerability
7320| [108216] Oracle Retail Convenience and Fuel POS Software 2.1.132 Apache Groovy unknown vulnerability
7321| [108169] Oracle MySQL Enterprise Monitor up to 3.2.8.2223/3.3.4.3247/3.4.2.4181 Apache Tomcat unknown vulnerability
7322| [108113] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Batik denial of service
7323| [108107] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat unknown vulnerability
7324| [108102] Oracle Healthcare Master Person Index 4.x Apache Groovy unknown vulnerability
7325| [108085] Oracle Identity Manager 11.1.2.3.0 Apache Struts 1 memory corruption
7326| [108083] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
7327| [108080] Oracle GlassFish Server 3.1.2 Apache Commons FileUpload denial of service
7328| [108066] Oracle Management Pack for GoldenGate 11.2.1.0.12 Apache Tomcat memory corruption
7329| [108062] Oracle BI Publisher 11.1.1.7.0/12.2.1.1.0/12.2.1.2.0 Apache ActiveMQ memory corruption
7330| [108060] Oracle Enterprise Manager Ops Center 12.2.2/12.3.2 Apache Groovy unknown vulnerability
7331| [108033] Oracle Primavera Unifier 9.13/9.14/10.x/15.x/16.x, Apache Groovy unknown vulnerability
7332| [108013] Oracle Communications WebRTC Session Controller 7.0/7.1/7.2 Apache Groovy unknown vulnerability
7333| [108011] Oracle Communications Services Gatekeeper 5.1/6.0 Apache Trinidad unknown vulnerability
7334| [107904] Apache Struts up to 2.3.28 Double OGNL Evaluation privilege escalation
7335| [107860] Apache Solr up to 7.0 Apache Lucene RunExecutableListener XML External Entity
7336| [107834] Apache Ranger up to 0.6.1 Change Password privilege escalation
7337| [107639] Apache NiFi 1.4.0 XML External Entity
7338| [107606] Apache ZooKeper up to 3.4.9/3.5.2 Command CPU Exhaustion denial of service
7339| [107597] Apache Roller up to 5.0.2 XML-RPC Protocol Support XML External Entity
7340| [107429] Apache Impala up to 2.9.x Kudu Table privilege escalation
7341| [107411] Apache Tomcat up to 7.0.81/8.0.46/8.5.22/9.0.0 JSP File File Upload privilege escalation
7342| [107385] Apache Geode up to 1.2.0 Secure Mode privilege escalation
7343| [107339] Apache OpenNLP up to 1.5.3/1.6.0/1.7.2/1.8.1 XML Data XML External Entity
7344| [107333] Apache Wicket up to 8.0.0-M1 CSRF Prevention HTTP Header privilege escalation
7345| [107323] Apache Wicket 1.5.10/6.13.0 Class Request information disclosure
7346| [107310] Apache Geode up to 1.2.0 Command Line Utility Query privilege escalation
7347| [107276] ArcSight ESM/ArcSight ESM Express up to 6.9.1c Patch 3/6.11.0 Apache Tomcat Version information disclosure
7348| [107266] Apache Tika up to 1.12 XML Parser XML External Entity
7349| [107262] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
7350| [107258] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
7351| [107197] Apache Xerces Jelly Parser XML File XML External Entity
7352| [107193] ZTE NR8950 Apache Commons Collections RMI Request Deserialization privilege escalation
7353| [107084] Apache Struts up to 2.3.19 cross site scripting
7354| [106877] Apache Struts up to 2.0.33/2.5.10 Freemarker Tag privilege escalation
7355| [106875] Apache Struts up to 2.5.5 URL Validator denial of service
7356| [106874] Apache Struts up to 2.3.30 Convention Plugin directory traversal
7357| [106847] Apache Tomcat up to 7.0.80 VirtualDirContext Source information disclosure
7358| [106846] Apache Tomcat up to 7.0.79 on Windows HTTP PUT Method Parameter File Upload privilege escalation
7359| [106777] Apache HTTP Server up to 2.2.34/2.4.27 Limit Directive ap_limit_section HTTP Request information disclosure
7360| [106739] puppetlabs-apache up to 1.11.0/2.0.x weak authentication
7361| [106720] Apache Wicket up to 1.5.12/6.18.x/7.0.0-M4 CryptoMapper privilege escalation
7362| [106586] Apache Brooklyn up to 0.9.x REST Server cross site scripting
7363| [106562] Apache Spark up to 2.1.1 Launcher API Deserialization privilege escalation
7364| [106559] Apache Brooklyn up to 0.9.x SnakeYAML YAML Data Java privilege escalation
7365| [106558] Apache Brooklyn up to 0.9.x REST Server cross site request forgery
7366| [106556] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
7367| [106555] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
7368| [106171] Apache Directory LDAP API up to 1.0.0-M30 Timing unknown vulnerability
7369| [106167] Apache Struts up to 2.5.12 REST Plugin XML Data privilege escalation
7370| [106166] Apache Struts up to 2.3.33/2.5.12 REST Plugin denial of service
7371| [106165] Apache Struts up to 2.3.33/2.5.12 URLValidator Regex CPU Exhaustion denial of service
7372| [106115] Apache Hadoop up to 2.6.4/2.7.2 YARN NodeManager Password information disclosure
7373| [106012] Apache Solr up to 5.5.3/6.4.0 Replication directory traversal
7374| [105980] Apache Engine 16.11.01 Parameter Reflected unknown vulnerability
7375| [105962] Apache Atlas 0.6.0/0.7.0 Frame cross site scripting
7376| [105961] Apache Atlas 0.6.0/0.7.0 Stack Trace information disclosure
7377| [105960] Apache Atlas 0.6.0/0.7.0 Search Reflected cross site scripting
7378| [105959] Apache Atlas 0.6.0/0.7.0 edit Tag DOM cross site scripting
7379| [105958] Apache Atlas 0.6.0/0.7.0 edit Tag Stored cross site scripting
7380| [105957] Apache Atlas 0.6.0/0.7.0 Cookie privilege escalation
7381| [105905] Apache Atlas 0.6.0/0.7.0/0.7.1 /js privilege escalation
7382| [105878] Apache Struts up to 2.3.24.0 privilege escalation
7383| [105682] Apache2Triad 1.5.4 phpsftpd/users.php Parameter cross site scripting
7384| [105681] Apache2Triad 1.5.4 phpsftpd/users.php Request cross site request forgery
7385| [105680] Apache2Triad 1.5.4 Parameter Session Fixation weak authentication
7386| [105643] Apache Pony Mail up to 0.8b weak authentication
7387| [105288] Apache Sling up to 2.3.21 Sling.evalString() String cross site scripting
7388| [105219] Apache Tomcat up to 8.5.15/9.0.0.M21 HTTP2 Bypass directory traversal
7389| [105218] Apache Tomcat up to 7.0.78/8.0.44/8.5.15/9.0.0.M21 CORS Filter Cache Poisoning privilege escalation
7390| [105215] Apache CXF up to 3.0.12/3.1.9 OAuth2 Hawk/JOSE MAC Validation Timing unknown vulnerability
7391| [105206] Apache CXF up to 3.0.11/3.1.8 JAX-RS Module XML External Entity
7392| [105205] Apache CXF up to 3.0.11/3.1.8 HTTP Transport Module Parameter cross site scripting
7393| [105202] Apache Storm 1.0.0/1.0.1/1.0.2/1.0.3/1.1.0 Worker privilege escalation
7394| [104987] Apache Xerces-C++ XML Service CPU Exhaustion denial of service
7395| [104986] Apache CXF 2.4.5/2.5.1 WS-SP UsernameToken Policy SOAP Request weak authentication
7396| [104985] Apache MyFaces Core up to 2.1.4 EL Expression Parameter Injection information disclosure
7397| [104983] Apache Wink up to 1.1.1 XML Document xxe privilege escalation
7398| [104981] Apache Commons Email 1.0/1.1/1.2/1.3/1.4 Subject Linebreak SMTP privilege escalation
7399| [104591] MEDHOST Document Management System Apache Solr Default Credentials weak authentication
7400| [104062] Oracle MySQL Enterprise Monitor up to 3.3.3.1199 Apache Tomcat unknown vulnerability
7401| [104061] Oracle MySQL Enterprise Monitor up to 3.2.7.1204/3.3.3.1199 Apache Tomcat unknown vulnerability
7402| [104060] Oracle MySQL Enterprise Monitor up to 3.1.5.7958/3.2.5.1141/3.3.2.1162 Apache Struts 2 unknown vulnerability
7403| [103995] Oracle 8.3/8.4/15.1/15.2 Apache Trinidad unknown vulnerability
7404| [103993] Oracle Policy Automation up to 12.2.3 Apache Commons FileUplaod denial of service
7405| [103916] Oracle Banking Platform 2.3/2.4/2.4.1/2.5 Apache Commons FileUpload denial of service
7406| [103906] Oracle Communications BRM 11.2.0.0.0 Apache Commons Collections privilege escalation
7407| [103904] Oracle Communications BRM 11.2.0.0.0/11.3.0.0.0 Apache Groovy memory corruption
7408| [103866] Oracle Transportation Management 6.1/6.2 Apache Webserver unknown vulnerability
7409| [103816] Oracle BI Publisher 11.1.1.9.0/12.2.1.1.0/12.2.1.2.0 Apache Commons Fileupload denial of service
7410| [103797] Oracle Tuxedo System and Applications Monitor Apache Commons Collections privilege escalation
7411| [103792] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Commons Fileupload privilege escalation
7412| [103791] Oracle Endeca Server 7.6.0.0/7.6.1.0 Apache Commons Collections privilege escalation
7413| [103788] Oracle Enterprise Repository 11.1.1.7.0/12.1.3.0.0 Apache ActiveMQ memory corruption
7414| [103787] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Groovy memory corruption
7415| [103763] Apache Sling up to 1.0.11 XSS Protection API XSS.getValidXML() Application XML External Entity
7416| [103762] Apache Sling up to 1.0.12 XSS Protection API XSSAPI.encodeForJSString() Script Tag cross site scripting
7417| [103693] Apache OpenMeetings 1.0.0 HTTP Method privilege escalation
7418| [103692] Apache OpenMeetings 1.0.0 Tomcat Error information disclosure
7419| [103691] Apache OpenMeetings 3.2.0 Parameter privilege escalation
7420| [103690] Apache OpenMeetings 1.0.0 sql injection
7421| [103689] Apache OpenMeetings 1.0.0 crossdomain.xml privilege escalation
7422| [103688] Apache OpenMeetings 1.0.0 weak encryption
7423| [103687] Apache OpenMeetings 1.0.0 cross site request forgery
7424| [103556] Apache Roller 5.1.0/5.1.1 Weblog Page Template VTL privilege escalation
7425| [103554] Apache OpenMeetings 1.0.0 Password Update unknown vulnerability
7426| [103553] Apache OpenMeetings 1.0.0 File Upload privilege escalation
7427| [103552] Apache OpenMeetings 3.2.0 Chat cross site scripting
7428| [103551] Apache OpenMeetings 3.1.0 XML unknown vulnerability
7429| [103521] Apache HTTP Server 2.4.26 HTTP2 Free memory corruption
7430| [103520] Apache HTTP Server up to 2.2.33/2.4.26 mod_auth_digest Authorization Header memory corruption
7431| [103519] Apache Struts up to 2.5.11/2.3.32 Spring AOP denial of service
7432| [103518] Apache Struts up to 2.5.11 URLValidator directory traversal
7433| [103492] Apache Spark up to 2.1.x Web UI Reflected cross site scripting
7434| [103401] Apache Struts 2.3.x Struts 1 Plugin ActionMessage privilege escalation
7435| [103399] Apache Traffic Control Traffic Router TCP Connection Slowloris denial of service
7436| [103387] Apache Impala up to 2.8.0 StatestoreSubscriber weak encryption
7437| [103386] Apache Impala up to 2.7.x/2.8.0 Kerberos weak authentication
7438| [103352] Apache Solr Node weak authentication
7439| [102897] Apache Ignite up to 2.0 Update Notifier information disclosure
7440| [102878] Code42 CrashPlan 5.4.x RMI Server org.apache.commons.ssl.rmi.DateRMI privilege escalation
7441| [102698] Apache HTTP Server up to 2.2.32/2.4.25 mod_mime Content-Type memory corruption
7442| [102697] Apache HTTP Server 2.2.24/2.2.32 HTTP Strict Parsing ap_find_token Request Header memory corruption
7443| [102690] Apache HTTP Server up to 2.2.32/2.4.25 mod_ssl ap_hook_process_connection() denial of service
7444| [102689] Apache HTTP Server up to 2.2.32/2.4.25 ap_get_basic_auth_pw weak authentication
7445| [102622] Apache Thrift up to 0.9.2 Client Libraries skip denial of service
7446| [102538] Apache Ranger up to 0.7.0 Authorizer unknown vulnerability
7447| [102537] Apache Ranger up to 0.7.0 Wildcard Character unknown vulnerability
7448| [102536] Apache Ranger up to 0.6 Stored cross site scripting
7449| [102535] Apache Ranger up to 0.6.2 Policy Engine unknown vulnerability
7450| [102255] Apache NiFi up to 0.7.3/1.2.x Response Header privilege escalation
7451| [102254] Apache NiFi up to 0.7.3/1.2.x UI cross site scripting
7452| [102070] Apache CXF Fediz up to 1.1.2/1.2.0 Application Plugin denial of service
7453| [102020] Apache Tomcat up to 9.0.0.M1 Java Servlet HTTP Method unknown vulnerability
7454| [101858] Apache Hive up to 1.2.1/2.0.0 Client weak authentication
7455| [101802] Apache KNOX up to 0.11.0 WebHDFS privilege escalation
7456| [101928] HPE Aruba ClearPass Apache Tomcat information disclosure
7457| [101524] Apache Archiva up to 1.x/2.2.1 REST Endpoint cross site request forgery
7458| [101513] Apache jUDDI 3.1./3.1.2/3.1.3/3.1.4 Logout Open Redirect
7459| [101430] Apache CXF Fediz up to 1.3.1 OIDC Service cross site request forgery
7460| [101429] Apache CXF Fediz up to 1.2.3/1.3.1 Plugins cross site request forgery
7461| [100619] Apache Hadoop up to 2.6.x HDFS Servlet unknown vulnerability
7462| [100618] Apache Hadoop up to 2.7.0 HDFS Web UI cross site scripting
7463| [100621] Adobe ColdFusion 10/11/2016 Apache BlazeDS Library Deserialization privilege escalation
7464| [100205] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Apache Commons FileUpload denial of service
7465| [100191] Oracle Secure Global Desktop 4.71/5.2/5.3 Web Server (Apache HTTP Server) information disclosure
7466| [100162] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Commons Collections privilege escalation
7467| [100160] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Trinidad unknown vulnerability
7468| [99969] Oracle WebCenter Sites 11.1.1.8.0 Apache Tomcat memory corruption
7469| [99937] Apache Batik up to 1.8 privilege escalation
7470| [99936] Apache FOP up to 2.1 privilege escalation
7471| [99935] Apache CXF up to 3.0.12/3.1.10 STSClient Cache information disclosure
7472| [99934] Apache CXF up to 3.0.12/3.1.10 JAX-RS XML Security Streaming Client spoofing
7473| [99930] Apache Traffic Server up to 6.2.0 denial of service
7474| [99929] Apache Log4j up to 2.8.1 Socket Server Deserialization privilege escalation
7475| [99925] Apache Traffic Server 6.0.0/6.1.0/6.2.0 HPACK Bomb denial of service
7476| [99738] Ping Identity OpenID Connect Authentication Module up to 2.13 on Apache Mod_auth_openidc.c spoofing
7477| [117569] Apache Hadoop up to 2.7.3 privilege escalation
7478| [99591] Apache TomEE up to 1.7.3/7.0.0-M2 EjbObjectInputStream Serialized Object privilege escalation
7479| [99370] Apache Ignite up to 1.8 update-notifier Document XML External Entity
7480| [99299] Apache Geode up to 1.1.0 Pulse OQL Query privilege escalation
7481| [99572] Apache Tomcat up to 7.0.75/8.0.41/8.5.11/9.0.0.M17 Application Listener privilege escalation
7482| [99570] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP Connector Cache information disclosure
7483| [99569] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP/2 GOAWAY Frame Resource Exhaustion denial of service
7484| [99568] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 Pipelined Request information disclosure
7485| [99048] Apache Ambari up to 2.3.x REST API Shell Metacharacter privilege escalation
7486| [99014] Apache Camel Jackson/JacksonXML privilege escalation
7487| [98610] Apple macOS up to 10.12.3 apache_mod_php memory corruption
7488| [98609] Apple macOS up to 10.12.3 apache_mod_php denial of service
7489| [98608] Apple macOS up to 10.12.3 apache_mod_php memory corruption
7490| [98607] Apple macOS up to 10.12.3 apache_mod_php denial of service
7491| [98606] Apple macOS up to 10.12.3 apache_mod_php denial of service
7492| [98605] Apple macOS up to 10.12.3 Apache denial of service
7493| [98604] Apple macOS up to 10.12.3 Apache denial of service
7494| [98603] Apple macOS up to 10.12.3 Apache denial of service
7495| [98602] Apple macOS up to 10.12.3 Apache denial of service
7496| [98601] Apple macOS up to 10.12.3 Apache denial of service
7497| [98517] Apache POI up to 3.14 OOXML File XXE denial of service
7498| [98405] Apache Hadoop up to 0.23.10 privilege escalation
7499| [98199] Apache Camel Validation XML External Entity
7500| [97892] Apache Tomcat up to 9.0.0.M15 Reverse-Proxy Http11InputBuffer.java information disclosure
7501| [97617] Apache Camel camel-snakeyaml Deserialization privilege escalation
7502| [97602] Apache Camel camel-jackson/camel-jacksonxml CamelJacksonUnmarshalType privilege escalation
7503| [97732] Apache Struts up to 2.3.31/2.5.10 Jakarta Multipart Parser Content-Type privilege escalation
7504| [97466] mod_auth_openidc up to 2.1.5 on Apache weak authentication
7505| [97455] mod_auth_openidc up to 2.1.4 on Apache weak authentication
7506| [97081] Apache Tomcat HTTPS Request denial of service
7507| [97162] EMC OpenText Documentum D2 BeanShell/Apache Commons privilege escalation
7508| [96949] Hanwha Techwin Smart Security Manager up to 1.5 Redis/Apache Felix Gogo privilege escalation
7509| [96314] Apache Cordova up to 6.1.1 on Android weak authentication
7510| [95945] Apple macOS up to 10.12.2 apache_mod_php denial of service
7511| [95944] Apple macOS up to 10.12.2 apache_mod_php denial of service
7512| [95943] Apple macOS up to 10.12.2 apache_mod_php memory corruption
7513| [95666] Oracle FLEXCUBE Direct Banking 12.0.0/12.0.1/12.0.2/12.0.3 Apache Commons Collections privilege escalation
7514| [95455] Apache NiFi up to 1.0.0/1.1.0 Connection Details Dialogue cross site scripting
7515| [95311] Apache Storm UI Daemon privilege escalation
7516| [95291] ZoneMinder 1.30.0 Apache httpd privilege escalation
7517| [94800] Apache Wicket up to 1.5.16/6.24.x Deserialize DiskFileItem denial of service
7518| [94705] Apache Qpid Broker for Java up to 6.1.0 SCRAM-SHA-1/SCRAM-SHA-256 User information disclosure
7519| [94627] Apache HTTP Server up to 2.4.24 mod_auth_digest Crash denial of service
7520| [94626] Apache HTTP Server up to 2.4.24 mod_session_crypto Padding weak encryption
7521| [94625] Apache HTTP Server up to 2.4.24 Response Split privilege escalation
7522| [94540] Apache Tika 1.9 tika-server File information disclosure
7523| [94600] Apache ActiveMQ up to 5.14.1 Administration Console cross site scripting
7524| [94348] Apple macOS up to 10.12.1 apache_mod_php denial of service
7525| [94347] Apple macOS up to 10.12.1 apache_mod_php denial of service
7526| [94346] Apple macOS up to 10.12.1 apache_mod_php denial of service
7527| [94345] Apple macOS up to 10.12.1 apache_mod_php denial of service
7528| [94344] Apple macOS up to 10.12.1 apache_mod_php denial of service
7529| [94343] Apple macOS up to 10.12.1 apache_mod_php memory corruption
7530| [94342] Apple macOS up to 10.12.1 apache_mod_php memory corruption
7531| [94128] Apache Tomcat up to 9.0.0.M13 Error information disclosure
7532| [93958] Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c denial of service
7533| [93874] Apache Subversion up to 1.8.16/1.9.4 mod_dontdothat XXE denial of service
7534| [93855] Apache Hadoop up to 2.6.4/2.7.2 HDFS Service privilege escalation
7535| [93609] Apache OpenMeetings 3.1.0 RMI Registry privilege escalation
7536| [93555] Apache Tika 1.6-1.13 jmatio MATLAB File privilege escalation
7537| [93799] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
7538| [93798] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
7539| [93797] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 HTTP Split privilege escalation
7540| [93796] Apache Tomcat up to 8.5.6/9.0.0.M11 HTTP/2 Header Parser denial of service
7541| [93532] Apache Commons Collections Library Java privilege escalation
7542| [93210] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 ResourceLinkFactory privilege escalation
7543| [93209] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Realm Authentication User information disclosure
7544| [93208] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 System Property Replacement information disclosure
7545| [93207] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Utility Method privilege escalation
7546| [93206] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Configuration privilege escalation
7547| [93098] Apache Commons FileUpload privilege escalation
7548| [92987] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Commons Collection memory corruption
7549| [92986] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Tomcat memory corruption
7550| [92982] Oracle Insurance IStream 4.3.2 Apache Commons Collections memory corruption
7551| [92981] Oracle Financial Services Lending and Leasing 14.1.0/14.2.0 Apache Commons Collections memory corruption
7552| [92979] Oracle up to 8.0.3 Apache Commons Collections memory corruption
7553| [92977] Oracle FLEXCUBE Universal Banking up to 12.2.0 Apache Commons Collections memory corruption
7554| [92976] Oracle FLEXCUBE Universal Banking 12.87.1/12.87.2 Apache Commons Collections memory corruption
7555| [92975] Oracle FLEXCUBE Private Banking up to 12.1.0 Apache Commons Collections memory corruption
7556| [92974] Oracle FLEXCUBE Investor Servicing 12.0.1 Apache Commons Collections memory corruption
7557| [92973] Oracle 12.0.0/12.1.0 Apache Commons Collections memory corruption
7558| [92972] Oracle FLEXCUBE Core Banking 11.5.0.0.0/11.6.0.0.0 Apache Commons Collections memory corruption
7559| [92962] Oracle Agile PLM 9.3.4/9.3.5 Apache Commons Collections memory corruption
7560| [92909] Oracle Agile PLM 9.3.4/9.3.5 Apache Tomcat unknown vulnerability
7561| [92786] Oracle Banking Digital Experience 15.1 Apache Commons Collections information disclosure
7562| [92549] Apache Tomcat on Red Hat privilege escalation
7563| [92509] Apache Tomcat JK ISAPI Connector up to 1.2.41 jk_uri_worker_map.c memory corruption
7564| [92314] Apache MyFaces Trinidad up to 1.0.13/1.2.15/2.0.1/2.1.1 CoreResponseStateManager memory corruption
7565| [92313] Apache Struts2 up to 2.3.28/2.5.0 Action Name Cleanup cross site request forgery
7566| [92299] Apache Derby up to 10.12.1.0 SqlXmlUtil XML External Entity
7567| [92217] Apache ActiveMQ Artemis up to 1.3.x Broker/REST GetObject privilege escalation
7568| [92174] Apache Ranger up to 0.6.0 Policy cross site scripting
7569| [91831] Apache Jackrabbit up to 2.13.2 HTTP Header cross site request forgery
7570| [91825] Apache Zookeeper up to 3.4.8/3.5.2 C CLI Shell memory corruption
7571| [91818] Apache CXF Fediz up to 1.2.2/1.3.0 Application Plugin privilege escalation
7572| [92056] Apple macOS up to 10.11 apache_mod_php memory corruption
7573| [92055] Apple macOS up to 10.11 apache_mod_php memory corruption
7574| [92054] Apple macOS up to 10.11 apache_mod_php denial of service
7575| [92053] Apple macOS up to 10.11 apache_mod_php denial of service
7576| [92052] Apple macOS up to 10.11 apache_mod_php denial of service
7577| [92051] Apple macOS up to 10.11 apache_mod_php memory corruption
7578| [92050] Apple macOS up to 10.11 apache_mod_php denial of service
7579| [92049] Apple macOS up to 10.11 apache_mod_php memory corruption
7580| [92048] Apple macOS up to 10.11 apache_mod_php denial of service
7581| [92047] Apple macOS up to 10.11 apache_mod_php memory corruption
7582| [92046] Apple macOS up to 10.11 apache_mod_php memory corruption
7583| [92045] Apple macOS up to 10.11 apache_mod_php memory corruption
7584| [92044] Apple macOS up to 10.11 apache_mod_php memory corruption
7585| [92043] Apple macOS up to 10.11 apache_mod_php denial of service
7586| [92042] Apple macOS up to 10.11 apache_mod_php memory corruption
7587| [92041] Apple macOS up to 10.11 apache_mod_php memory corruption
7588| [92040] Apple macOS up to 10.11 Apache Proxy privilege escalation
7589| [91785] Apache Shiro up to 1.3.1 Servlet Filter privilege escalation
7590| [90879] Apache OpenMeetings up to 3.1.1 SWF Panel cross site scripting
7591| [90878] Apache Sentry up to 1.6.x Blacklist Filter reflect/reflect2/java_method privilege escalation
7592| [90610] Apache POI up to 3.13 XLSX2CSV Example OpenXML Document XML External Entity
7593| [90584] Apache ActiveMQ up to 5.11.3/5.12.2/5.13/1 Administration Web Console privilege escalation
7594| [90385] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site scripting
7595| [90384] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site request forgery
7596| [90383] Apache OpenOffice up to 4.1.2 Impress File memory corruption
7597| [89670] Apache Tomcat up to 8.5.4 CGI Servlet Environment Variable Open Redirect
7598| [89669] Apache HTTP Server up to 2.4.23 RFC 3875 Namespace Conflict Environment Variable Open Redirect
7599| [89726] Apple Mac OS X up to 10.11.5 apache_mod_php memory corruption
7600| [89484] Apache Qpid up to 0.13.0 on Windows Proton Library Certificate weak authentication
7601| [89473] HPE iMC PLAT/EAD/APM/iMC NTA/iMC BIMS/iMC UAM_TAM up to 7.2 Apache Commons Collections Library Command privilege escalation
7602| [90263] Apache Archiva Header denial of service
7603| [90262] Apache Archiva Deserialize privilege escalation
7604| [90261] Apache Archiva XML DTD Connection privilege escalation
7605| [88827] Apache Xerces-C++ up to 3.1.3 DTD Stack-Based memory corruption
7606| [88747] Apache HTTP Server 2.4.17/2.4.18 mod_http2 denial of service
7607| [88608] Apache Struts up to 2.3.28.1/2.5.0 URLValidator Null Value denial of service
7608| [88607] Apache Struts up to 2.3.28.1 REST Plugin Expression privilege escalation
7609| [88606] Apache Struts up to 2.3.28.1 Restriction privilege escalation
7610| [88605] Apache Struts up to 2.3.28.1 Restriction privilege escalation
7611| [88604] Apache Struts up to 2.3.28.1 Token Validator cross site request forgery
7612| [88603] Apache Commons FileUpload up to 1.3.1 MultipartStream denial of service
7613| [88602] Apache Struts up to 1.3.10 ActionServlet.java cross site scripting
7614| [88601] Apache Struts up to 1.3.10 Multithreading ActionServlet.java memory corruption
7615| [88600] Apache Struts up to 1.3.10 MultiPageValidator privilege escalation
7616| [89005] Apache Qpid AMQP JMS Client getObject privilege escalation
7617| [87888] Apache Ranger up to 0.5.2 Policy Admin Tool eventTime sql injection
7618| [87835] Apache CloudStack up to 4.5.2.0/4.6.2.0/4.7.1.0/4.8.0.0 SAML-based Authentication privilege escalation
7619| [87806] HPE Discovery and Dependency Mapping Inventory up to 9.32 update 3 Apache Commons Collections Library privilege escalation
7620| [87805] HPE Universal CMDB up to 10.21 Apache Commons Collections Library privilege escalation
7621| [87768] Apache Shiro up to 1.2.4 Cipher Key privilege escalation
7622| [87765] Apache James Server 2.3.2 Command privilege escalation
7623| [88667] Apache HTTP Server up to 2.4.20 mod_http2 Certificate weak authentication
7624| [87718] Apache Struts up to 2.3.24.1 OGNL Caching denial of service
7625| [87717] Apache Struts up to 2.3.28 REST Plugin privilege escalation
7626| [87706] Apache Qpid Java up to 6.0.2 AMQP privilege escalation
7627| [87703] Apache Qbid Java up to 6.0.2 PlainSaslServer.java denial of service
7628| [87702] Apache ActiveMQ up to 5.13.x Fileserver Web Application Upload privilege escalation
7629| [87700] Apache PDFbox up to 1.8.11/2.0.0 XML Parser PDF Document XML External Entity
7630| [87679] HP Release Control 9.13/9.20/9.21 Apache Commons Collections Library Java Object privilege escalation
7631| [87540] Apache Ambari up to 2.2.0 File Browser View information disclosure
7632| [87433] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
7633| [87432] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
7634| [87431] Apple Mac OS X up to 10.11.4 apache_mod_php Format String
7635| [87430] Apple Mac OS X up to 10.11.4 apache_mod_php denial of service
7636| [87429] Apple Mac OS X up to 10.11.4 apache_mod_php information disclosure
7637| [87428] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
7638| [87427] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
7639| [87389] Apache Xerces C++ up to 3.1.3 XML Document DTDScanner.cpp memory corruption
7640| [87172] Adobe ColdFusion 11 Update 7/2016/up to 10 Update 18 Apache Commons Collections Library privilege escalation
7641| [87121] Apache Cordova iOS up to 3.x Plugin privilege escalation
7642| [87120] Apache Cordova iOS up to 3.x URL Whitelist privilege escalation
7643| [83806] HPE Network Node Manager i up to 10.01 Apache Commons Collections Library privilege escalation
7644| [83077] Apache Subversion up to 1.8.15/1.9.3 mod_authz_svn mod_authz_svn.c denial of service
7645| [83076] Apache Subversion up to 1.8.15/1.9.3 svnserve svnserve/cyrus_auth.c privilege escalation
7646| [82790] Apache Struts 2.0.0/2.3.24/2.3.28 Dynamic Method privilege escalation
7647| [82789] Apache Struts 2.0.0/2.3.24/2.3.28 XSLTResult privilege escalation
7648| [82725] HPE P9000 Command View up to 7.x/8.4.0 Apache Commons Collections Library privilege escalation
7649| [82444] Apache Camel up to 2.14.x/2.15.4/2.16.0 HTTP Request privilege escalation
7650| [82389] Apache Subversion up to 1.7.x/1.8.14/1.9.2 mod_dav_svn util.c memory corruption
7651| [82280] Apache Struts up to 1.7 JRE URLDecoder cross site scripting
7652| [82260] Apache OFBiz up to 12.04.05/13.07.02 Java Object privilege escalation
7653| [82259] Apache Qpid Proton up to 0.12.0 proton.reactor.Connector weak encryption
7654| [82250] Apache Ranger up to 0.5.0 Admin UI weak authentication
7655| [82214] Apache Wicket up to 1.5.14/6.21.x/7.1.x Input Element cross site scripting
7656| [82213] Apache Wicket up to 1.5.14/6.21.x/7.1.x ModalWindow Title getWindowOpenJavaScript cross site scripting
7657| [82212] Apache Ranger up to 0.5.0 Policy Admin Tool privilege escalation
7658| [82211] Apache OFBiz up to 12.04.06/13.07.02 ModelFormField.java DisplayEntityField.getDescription cross site scripting
7659| [82082] Apache JetSpeed up to 2.3.0 User Manager Service privilege escalation
7660| [82081] Apache OpenMeetings up to 3.1.0 SOAP API information disclosure
7661| [82080] Apache OpenMeetings up to 3.1.0 Event cross site scripting
7662| [82078] Apache OpenMeetings up to 3.1.0 Import/Export System Backup ZIP Archive directory traversal
7663| [82077] Apache OpenMeetings up to 3.1.0 Password Reset sendHashByUser privilege escalation
7664| [82076] Apache Ranger up to 0.5.1 privilege escalation
7665| [82075] Apache JetSpeed up to 2.3.0 Portal cross site scripting
7666| [82074] Apache JetSpeed up to 2.3.0 cross site scripting
7667| [82073] Apache JetSpeed up to 2.3.0 User Manager Service sql injection
7668| [82072] Apache JetSpeed up to 2.3.0 Portal Site Manager ZIP Archive directory traversal
7669| [82058] Apache LDAP Studio/Directory Studio up to 2.0.0-M9 CSV Export privilege escalation
7670| [82053] Apache Ranger up to 0.4.x Policy Admin Tool privilege escalation
7671| [82052] Apache Ranger up to 0.4.x Policy Admin Tool HTTP Request cross site scripting
7672| [81696] Apache ActiveMQ up to 5.13.1 HTTP Header privilege escalation
7673| [81695] Apache Xerces-C up to 3.1.2 internal/XMLReader.cpp memory corruption
7674| [81622] HPE Asset Manager 9.40/9.41/9.50 Apache Commons Collections Library Java Object privilege escalation
7675| [81406] HPE Service Manager up to 9.35 P3/9.41 P1 Apache Commons Collections Library Command privilege escalation
7676| [81405] HPE Operations Orchestration up to 10.50 Apache Commons Collections Library Command privilege escalation
7677| [81427] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
7678| [81426] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
7679| [81372] Apache Struts up to 2.3.24.1 I18NInterceptor cross site scripting
7680| [81371] Apache Struts up to 2.3.24.1 Double OGNL Evaluation privilege escalation
7681| [81370] Apache Struts up to 2.3.24.1 Java URLDecoder cross site scripting
7682| [81084] Apache Tomcat 6.0/7.0/8.0/9.0 ServletContext directory traversal
7683| [81083] Apache Tomcat 7.0/8.0/9.0 Index Page cross site request forgery
7684| [81082] Apache Tomcat 7.0/8.0/9.0 ResourceLinkFactory.setGlobalContext privilege escalation
7685| [81081] Apache Tomcat 6.0/7.0/8.0/9.0 Error information disclosure
7686| [81080] Apache Tomcat 6.0/7.0/8.0/9.0 Session Persistence privilege escalation
7687| [81079] Apache Tomcat 6.0/7.0/8.0/9.0 StatusManagerServlet information disclosure
7688| [81078] Apache Tomcat 7.0/8.0/9.0 Session privilege escalation
7689| [80970] Apache Solr up to 5.3.0 Admin UI plugins.js cross site scripting
7690| [80969] Apache Solr up to 5.2 Schema schema-browser.js cross site scripting
7691| [80968] Apache Solr up to 5.0 analysis.js cross site scripting
7692| [80940] HP Continuous Delivery Automation 1.30 Apache Commons Collections Library privilege escalation
7693| [80823] Apache CloudStack up to 4.5.1 KVM Virtual Machine Migration privilege escalation
7694| [80822] Apache CloudStack up to 4.5.1 API Call information disclosure
7695| [80778] Apache Camel up to 2.15.4/2.16.0 camel-xstream privilege escalation
7696| [80750] HPE Operations Manager 8.x/9.0 on Windows Apache Commons Collections Library privilege escalation
7697| [80724] Apache Hive up to 1.2.1 Authorization Framework privilege escalation
7698| [80577] Oracle Secure Global Desktop 4.63/4.71/5.2 Apache HTTP Server denial of service
7699| [80165] Intel McAfee ePolicy Orchestrator up to 4.6.9/5.0.3/5.3.1 Apache Commons Collections Library privilege escalation
7700| [80116] Apache Subversion up to 1.9.2 svn Protocol libsvn_ra_svn/marshal.c read_string memory corruption
7701| [80115] Apache ActiveMQ up to 5.12.x Broker Service privilege escalation
7702| [80036] IBM Cognos Business Intelligence Apache Commons Collections Library InvokerTransformer privilege escalation
7703| [79873] VMware vCenter Operations/vRealize Orchestrator Apache Commons Collections Library Serialized Java Object privilege escalation
7704| [79840] Apache Cordova File Transfer Plugin up to 1.2.x on Android unknown vulnerability
7705| [79839] Apache TomEE Serialized Java Stream EjbObjectInputStream privilege escalation
7706| [79791] Cisco Products Apache Commons Collections Library privilege escalation
7707| [79539] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
7708| [79538] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
7709| [79294] Apache Cordova-Android up to 3.6 BridgeSecret Random Generator weak encryption
7710| [79291] Apache Cordova-Android up to 4.0 Javascript Whitelist privilege escalation
7711| [79244] Apache CXF up to 2.7.17/3.0.7/3.1.2 SAML Web SSO Module SAML Response weak authentication
7712| [79243] Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0 WLS Security com.bea.core.apache.commons.collections.jar privilege escalation
7713| [78989] Apache Ambari up to 2.1.1 Open Redirect
7714| [78988] Apache Ambari up to 2.0.1/2.1.0 Password privilege escalation
7715| [78987] Apache Ambari up to 2.0.x cross site scripting
7716| [78986] Apache Ambari up to 2.0.x Proxy Endpoint api/v1/proxy privilege escalation
7717| [78780] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
7718| [78779] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
7719| [78778] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
7720| [78777] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
7721| [78776] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
7722| [78775] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
7723| [78774] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
7724| [78297] Apache Commons Components HttpClient up to 4.3.5 HTTPS Timeout denial of service
7725| [77406] Apache Flex BlazeDS AMF Message XML External Entity
7726| [77429] Apache ActiveMQ up to 5.10.0 LDAPLoginModule privilege escalation
7727| [77399] Apache ActiveMQ up to 5.10.0 LDAPLoginModule weak authentication
7728| [77375] Apache Tapestry up to 5.3.5 Client-Side Object Storage privilege escalation
7729| [77331] Apache ActiveMQ up to 5.11.1 on Windows Fileserver Upload/Download directory traversal
7730| [77299] Apache Solr Real-Time Module up to 7.x-1.1 Index Content information disclosure
7731| [77247] Apache ActiveMQ up to 5.10 TransportConnection.java processControlCommand denial of service
7732| [77083] Apache Groovy up to 2.4.3 MethodClosure.java MethodClosure memory corruption
7733| [76953] Apache Subversion 1.7.0/1.8.0/1.8.10 svn_repos_trace_node_locations information disclosure
7734| [76952] Apache Subversion 1.7.0/1.8.0/1.8.10 mod_authz_svn anonymous/authenticated information disclosure
7735| [76567] Apache Struts 2.3.20 unknown vulnerability
7736| [76733] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 ap_some_auth_required unknown vulnerability
7737| [76732] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 Request apr_brigade_flatten privilege escalation
7738| [76731] Apache HTTP Server 2.4.12 ErrorDocument 400 Crash denial of service
7739| [75690] Apache Camel up to 2.13.3/2.14.1 XPathBuilder.java XML External Entity
7740| [75689] Apache Camel up to 2.13.3/2.14.1 XML Converter Setup XmlConverter.java SAXSource privilege escalation
7741| [75668] Apache Sling API/Sling Servlets Post up to 2.2.1 HtmlResponse cross site scripting
7742| [75601] Apache Jackrabbit up to 2.10.0 WebDAV Request XML External Entity
7743| [75420] Apache Tomcat up to 6.0.43/7.0.58/8.0.16 Security Manager privilege escalation
7744| [75145] Apache OpenOffice up to 4.1.1 HWP Filter Crash denial of service
7745| [75032] Apache Tomcat Connectors up to 1.2.40 mod_jk privilege escalation
7746| [75135] PHP 5.4/5.5 HTTP Request sapi_apache2.c apache2handler privilege escalation
7747| [74793] Apache Tomcat File Upload denial of service
7748| [74708] Apple MacOS X up to 10.10.2 Apache denial of service
7749| [74707] Apple MacOS X up to 10.10.2 Apache denial of service
7750| [74706] Apple MacOS X up to 10.10.2 Apache memory corruption
7751| [74705] Apple MacOS X up to 10.10.2 Apache denial of service
7752| [74704] Apple MacOS X up to 10.10.2 Apache denial of service
7753| [74703] Apple MacOS X up to 10.10.2 Apache denial of service
7754| [74702] Apple MacOS X up to 10.10.2 Apache denial of service
7755| [74701] Apple MacOS X up to 10.10.2 Apache cross site request forgery
7756| [74700] Apple MacOS X up to 10.10.2 Apache unknown vulnerability
7757| [74661] Apache Flex up to 4.14.0 asdoc index.html cross site scripting
7758| [74609] Apache Cassandra up to 1.2.19/2.0.13/2.1.3 JMX/RMI Interface privilege escalation
7759| [74469] Apache Xerces-C up to 7.0 internal/XMLReader.cpp denial of service
7760| [74468] Apache Batik up to 1.6 denial of service
7761| [74414] Apache Mod-gnutls up to 0.5.1 Authentication spoofing
7762| [74371] Apache Standard Taglibs up to 1.2.0 memory corruption
7763| [74367] Apache HTTP Server up to 2.4.12 mod_lua lua_request.c wsupgrade denial of service
7764| [74174] Apache WSS4J up to 2.0.0 privilege escalation
7765| [74172] Apache ActiveMQ up to 5.5.0 Administration Console cross site scripting
7766| [69092] Apache Tomcat up to 6.0.42/7.0.54/8.0.8 HTTP Request Smuggling privilege escalation
7767| [73831] Apache Qpid up to 0.30 Access Restriction unknown vulnerability
7768| [73731] Apache XML Security unknown vulnerability
7769| [68660] Oracle BI Publisher 10.1.3.4.2/11.1.1.7 Apache Tomcat cross site scripting
7770| [73659] Apache CloudStack up to 4.3.0 Stack-Based unknown vulnerability
7771| [73593] Apache Traffic Server up to 5.1.0 denial of service
7772| [73511] Apache POI up to 3.10 Deadlock denial of service
7773| [73510] Apache Solr up to 4.3.0 cross site scripting
7774| [68447] Apache Subversion up to 1.7.18/1.8.10 mod_dav_svn Crash denial of service
7775| [68446] Apache Subversion up to 1.7.18/1.8.10 REPORT Request Crash denial of service
7776| [73173] Apache CloudStack Stack-Based unknown vulnerability
7777| [68357] Apache Struts up to 2.3.16.3 Random Number Generator cross site request forgery
7778| [73106] Apache Hadoop up to 2.4.0 Symlink privilege escalation
7779| [68575] Apache HTTP Server up to 2.4.10 LuaAuthzProvider mod_lua.c privilege escalation
7780| [72890] Apache Qpid 0.30 unknown vulnerability
7781| [72887] Apache Hive 0.13.0 File Permission privilege escalation
7782| [72878] Apache Cordova 3.5.0 cross site request forgery
7783| [72877] Apache Cordova 3.5.0 cross site request forgery
7784| [72876] Apache Cordova 3.5.0 cross site request forgery
7785| [68435] Apache HTTP Server 2.4.10 mod_proxy_fcgi.c handle_headers denial of service
7786| [68065] Apache CXF up to 3.0.1 JAX-RS SAML denial of service
7787| [68064] Apache CXF up to 3.0.0 SAML Token denial of service
7788| [67913] Oracle Retail Markdown Optimization 12.0/13.0/13.1/13.2/13.4 Apache commons-beanutils-1.8.0.jar memory corruption
7789| [67912] Oracle Retail Invoice Matching up to 14.0 Apache commons-beanutils-1.8.0.jar memory corruption
7790| [67911] Oracle Retail Clearance Optimization Engine 13.3/13.4/14.0 Apache commons-beanutils-1.8.0.jar memory corruption
7791| [67910] Oracle Retail Allocation up to 13.2 Apache commons-beanutils-1.8.0.jar memory corruption
7792| [71835] Apache Shiro 1.0.0/1.1.0/1.2.0/1.2.1/1.2.2 unknown vulnerability
7793| [71633] Apachefriends XAMPP 1.8.1 cross site scripting
7794| [71629] Apache Axis2/C spoofing
7795| [67633] Apple Mac OS X up to 10.9.4 apache_mod_php ext/standard/dns.c dns_get_record memory corruption
7796| [67631] Apple Mac OS X up to 10.9.4 apache_mod_php Symlink memory corruption
7797| [67630] Apple Mac OS X up to 10.9.4 apache_mod_php cdf_read_property_info denial of service
7798| [67629] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_count_chain denial of service
7799| [67628] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_check_stream_offset denial of service
7800| [67627] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c mconvert memory corruption
7801| [67626] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c denial of service
7802| [67625] Apple Mac OS X up to 10.9.4 apache_mod_php Crash denial of service
7803| [67624] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_property_info denial of service
7804| [67623] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_unpack_summary_info denial of service
7805| [67622] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_short_sector denial of service
7806| [67620] Apple Mac OS X up to 10.9.4 apache_mod_php magic/Magdir/commands denial of service
7807| [67790] Apache HTTP Server mod_cache NULL Pointer Dereference denial of service
7808| [67522] Apache Tomcat up to 7.0.39 JSP Upload privilege escalation
7809| [70809] Apache POI up to 3.11 Crash denial of service
7810| [70808] Apache POI up to 3.10 unknown vulnerability
7811| [70806] Apache Commons-httpclient 4.2/4.2.1/4.2.2 spoofing
7812| [70749] Apache Axis up to 1.4 getCN spoofing
7813| [70701] Apache Traffic Server up to 3.3.5 denial of service
7814| [70700] Apache OFBiz up to 12.04.03 cross site scripting
7815| [67402] Apache OpenOffice 4.0.0/4.0.1/4.1.0 Calc privilege escalation
7816| [67401] Apache OpenOffice up to 4.1.0 OLE Object information disclosure
7817| [70661] Apache Subversion up to 1.6.17 denial of service
7818| [70660] Apache Subversion up to 1.6.17 spoofing
7819| [70659] Apache Subversion up to 1.6.17 spoofing
7820| [67183] Apache HTTP Server up to 2.4.9 mod_proxy denial of service
7821| [67180] Apache HTTP Server up to 2.4.9 WinNT MPM Memory Leak denial of service
7822| [67185] Apache HTTP Server up to 2.4.9 mod_status Heap-Based memory corruption
7823| [67184] Apache HTTP Server 2.4.5/2.4.6 mod_cache NULL Pointer Dereference denial of service
7824| [67182] Apache HTTP Server up to 2.4.9 mod_deflate Memory Consumption denial of service
7825| [67181] Apache HTTP Server up to 2.4.9 mod_cgid denial of service
7826| [70338] Apache Syncope up to 1.1.7 unknown vulnerability
7827| [70295] Apache CXF up to 2.7.9 Cleartext information disclosure
7828| [70106] Apache Open For Business Project up to 10.04.0 getServerError cross site scripting
7829| [70105] Apache MyFaces up to 2.1.5 JavaServer Faces directory traversal
7830| [69846] Apache HBase up to 0.94.8 information disclosure
7831| [69783] Apache CouchDB up to 1.2.0 memory corruption
7832| [13383] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 XML Parser privilege escalation
7833| [13300] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi setuid privilege escalation
7834| [13299] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi Content-Type Header information disclosure
7835| [13164] Apache CXF up to 2.6.13/2.7.10 SOAP OutgoingChainInterceptor.java Invalid Content denial of service
7836| [13163] Apache CXF up to 2.6.13/2.7.10 SOAP HTML Content denial of service
7837| [13158] Apache Struts up to 2.3.16.2 ParametersInterceptor getClass privilege escalation
7838| [69515] Apache Struts up to 2.3.15.0 CookieInterceptor memory corruption
7839| [13086] Apache Struts up to 1.3.10 Class Loader privilege escalation
7840| [13067] Apache Struts up to 2.3.16.1 Class Loader privilege escalation
7841| [69431] Apache Archiva up to 1.3.6 cross site scripting
7842| [69385] Apache Syncope up to 1.1.6 unknown vulnerability
7843| [69338] Apache Xalan-Java up to 2.7.1 system-property unknown vulnerability
7844| [12742] Trustwave ModSecurity up to 2.7.5 Chunk Extension apache2/modsecurity.c modsecurity_tx_init privilege escalation
7845| [12741] Trustwave ModSecurity up to 2.7.6 Chunked HTTP Transfer apache2/modsecurity.c modsecurity_tx_init Trailing Header privilege escalation
7846| [13387] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Content-Length Header privilege escalation
7847| [13386] Apache Tomcat Security Manager up to 6.0.39/7.0.53/8.0.5 XSLT privilege escalation
7848| [13385] Apache Tomcat 8.0.0/8.0.1/8.0.3 AJP Request Zero Length denial of service
7849| [13384] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Chunked HTTP Request denial of service
7850| [12748] Apache CouchDB 1.5.0 UUIDS /_uuids denial of service
7851| [66739] Apache Camel up to 2.12.2 unknown vulnerability
7852| [66738] Apache Camel up to 2.12.2 unknown vulnerability
7853| [12667] Apache HTTP Server 2.4.7 mod_log_config.c log_cookie denial of service
7854| [66695] Apache CouchDB up to 1.2.0 cross site scripting
7855| [66694] Apache CouchDB up to 1.2.0 Partition partition2 directory traversal
7856| [66689] Apache HTTP Server up to 2.0.33 mod_dav dav_xml_get_cdata denial of service
7857| [12518] Apache Tomcat up to 6.0.38/7.0.49/8.0.0-RC9 HTTP Header denial of service
7858| [66498] Apache expressions up to 3.3.0 Whitelist unknown vulnerability
7859| [12781] Apache Struts up to 2.3.8 ParametersInterceptor getClass denial of service
7860| [12439] Apache Tomcat 6.0.33 XML XXE information disclosure
7861| [12438] Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37 coyoteadapter.java disableURLRewriting privilege escalation
7862| [66356] Apache Wicket up to 6.8.0 information disclosure
7863| [12209] Apache Tomcat 7.0.0/7.0.50/8.0.0-RC1/8.0.1 Content-Type Header for Multi-Part Request Infinite Loop denial of service
7864| [66322] Apache ActiveMQ up to 5.8.0 cross site scripting
7865| [12291] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
7866| [66255] Apache Open For Business Project up to 10.04.3 cross site scripting
7867| [66200] Apache Hadoop up to 2.0.5 Security Feature information disclosure
7868| [66072] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
7869| [66068] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
7870| [11928] Oracle Secure Global Desktop up to 4.71 Apache Tomcat unknown vulnerability
7871| [11924] Oracle Secure Global Desktop up to 4.63 Apache Tomcat denial of service
7872| [11922] Oracle Secure Global Desktop up to 4.63 Apache Tomcat unknown vulnerability
7873| [66049] Apache XML Security for Java up to 1.4.6 Memory Consumption denial of service
7874| [12199] Apache Subversion up to 1.8.5 mod_dav_svn/repos.c get_resource denial of service
7875| [65946] askapache Firefox Adsense up to 3.0 askapache-firefox-adsense.php cross site request forgery
7876| [65668] Apache Solr 4.0.0 Updater denial of service
7877| [65665] Apache Solr up to 4.3.0 denial of service
7878| [65664] Apache Solr 3.6.0/3.6.1/3.6.2/4.0.0 Updater denial of service
7879| [65663] Apache Solr up to 4.5.1 ResourceLoader directory traversal
7880| [65658] Apache roller 4.0/4.0.1/5.0/5.0.1 unknown vulnerability
7881| [65657] Apache Roller 4.0/4.0.1/5.0/5.0.1 cross site scripting
7882| [11325] Apache Subversion 1.7.13 mod_dontdothat Bypass denial of service
7883| [11324] Apache Subversion up to 1.8.4 mod_dav_svn denial of service
7884| [11098] Apache Tomcat 5.5.25 HTTP Request cross site request forgery
7885| [65410] Apache Struts 2.3.15.3 cross site scripting
7886| [65386] Apache Solr up to 2.2.1 on TYPO3 cross site scripting
7887| [65385] Apache Solr up to 2.2.1 on TYPO3 unknown vulnerability
7888| [11044] Apache Struts 2.3.15.3 showConfig.action cross site scripting
7889| [11043] Apache Struts 2.3.15.3 actionNames.action cross site scripting
7890| [11018] cPanel WHM up to 11.40.0.11 Apache mod_userdir Tweak Interface privilege escalation
7891| [65342] Apache Sling 1.0.2/1.0.4/1.0.6/1.1.0/1.1.2 Auth Core cross site scripting
7892| [65340] Apache Shindig 2.5.0 information disclosure
7893| [65316] Apache Mod Fcgid up to 2.3.7 mod_fcgid fcgid_bucket.c fcgid_header_bucket_read memory corruption
7894| [65313] Apache Sling 2.2.0/2.3.0 AbstractCreateOperation.java deepGetOrCreateNode denial of service
7895| [10826] Apache Struts 2 File privilege escalation
7896| [65204] Apache Camel up to 2.10.1 unknown vulnerability
7897| [10460] Apache Struts 2.0.0/2.3.15.1 Action Mapping Mechanism Bypass privilege escalation
7898| [10459] Apache Struts 2.0.0/2.3.15 Dynamic Method Invocation unknown vulnerability
7899| [10160] Apache Subversion 1.8.0/1.8.1/1.8.2 svnwcsub.py handle_options race condition
7900| [10159] Apache Subversion up to 1.8.2 svnserve write_pid_file race condition
7901| [10158] Apache Subversion 1.8.0/1.8.1/1.8.2 daemonize.py daemon::daemonize race condition
7902| [10157] Apache Subversion up to 1.8.1 FSFS Repository Symlink privilege escalation
7903| [64808] Fail2ban up to 0.8.9 apache-auth.conf denial of service
7904| [64760] Best Practical RT up to 4.0.12 Apache::Session::File information disclosure
7905| [64722] Apache XML Security for C++ Heap-based memory corruption
7906| [64719] Apache XML Security for C++ Heap-based memory corruption
7907| [64718] Apache XML Security for C++ verify denial of service
7908| [64717] Apache XML Security for C++ getURIBaseTXFM memory corruption
7909| [64716] Apache XML Security for C++ spoofing
7910| [64701] Apache CXF up to 2.7.3 XML Parser Memory Consumption denial of service
7911| [64700] Apache CloudStack up to 4.1.0 Stack-Based cross site scripting
7912| [64667] Apache Open For Business Project up to 10.04.04 unknown vulnerability
7913| [64666] Apache Open For Business Project up to 10.04.04 cross site scripting
7914| [9891] Apache HTTP Server 2.2.22 suEXEC Feature .htaccess information disclosure
7915| [64509] Apache ActiveMQ up to 5.8.0 scheduled.jsp cross site scripting
7916| [9826] Apache Subversion up to 1.8.0 mod_dav_svn denial of service
7917| [9683] Apache HTTP Server 2.4.5 mod_session_dbd denial of service
7918| [64485] Apache Struts up to 2.2.3.0 privilege escalation
7919| [9568] Apache Struts up to 2.3.15 DefaultActionMapper cross site request forgery
7920| [9567] Apache Struts up to 2.3.15 DefaultActionMapper memory corruption
7921| [64467] Apache Geronimo 3.0 memory corruption
7922| [64466] Apache OpenJPA up to 2.2.1 Serialization memory corruption
7923| [64457] Apache Struts up to 2.2.3.0 cross site scripting
7924| [64326] Alejandro Garza Apachesolr Autocomplete up to 7.x-1.1 cross site scripting
7925| [9184] Apache Qpid up to 0.20 SSL misconfiguration
7926| [8935] Apache Subversion up to 1.7.9 FSFS Format Repository denial of service
7927| [8934] Apache Subversion up to 1.7.9 Svnserve Server denial of service
7928| [8933] Apache Subversion up to 1.6.21 check-mime-type.pl svnlook memory corruption
7929| [8932] Apache Subversion up to 1.6.21 svn-keyword-check.pl svnlook changed memory corruption
7930| [9022] Apache Struts up to 2.3.14.2 OGNL Expression memory corruption
7931| [8873] Apache Struts 2.3.14 privilege escalation
7932| [8872] Apache Struts 2.3.14 privilege escalation
7933| [8746] Apache HTTP Server Log File Terminal Escape Sequence Filtering mod_rewrite.c do_rewritelog privilege escalation
7934| [8666] Apache Tomcat up to 7.0.32 AsyncListener information disclosure
7935| [8665] Apache Tomcat up to 7.0.29 Chunked Transfer Encoding Extension Size denial of service
7936| [8664] Apache Tomcat up to 7.0.32 FORM Authentication weak authentication
7937| [64075] Apache Subversion up to 1.7.7 mod_dav_svn Crash denial of service
7938| [64074] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
7939| [64073] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
7940| [64072] Apache Subversion up to 1.7.7 mod_dav_svn NULL Pointer Dereference denial of service
7941| [64071] Apache Subversion up to 1.7.8 mod_dav_svn Memory Consumption denial of service
7942| [8768] Apache Struts up to 2.3.14 on Mac EL and OGNL Interpreter memory corruption
7943| [64006] Apache ActiveMQ up to 5.7.0 denial of service
7944| [64005] Apache ActiveMQ up to 5.7.0 Default Configuration denial of service
7945| [64004] Apache ActiveMQ up to 5.7.0 PortfolioPublishServlet.java cross site scripting
7946| [8427] Apache Tomcat Session Transaction weak authentication
7947| [63960] Apache Maven 3.0.4 Default Configuration spoofing
7948| [63751] Apache qpid up to 0.20 qpid::framing::Buffer denial of service
7949| [63750] Apache qpid up to 0.20 checkAvailable denial of service
7950| [63749] Apache Qpid up to 0.20 Memory Consumption denial of service
7951| [63748] Apache Qpid up to 0.20 Default Configuration denial of service
7952| [63747] Apache Rave up to 0.20 User Account information disclosure
7953| [7889] Apache Subversion up to 1.6.17 mod_dav_svn/svn_fs_file_length() denial of service
7954| [63646] Apache HTTP Server up to 2.2.23/2.4.3 mod_proxy_balancer.c balancer_handler cross site scripting
7955| [7688] Apache CXF up to 2.7.1 WSS4JInterceptor Bypass weak authentication
7956| [7687] Apache CXF up to 2.7.2 Token weak authentication
7957| [63334] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
7958| [63299] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
7959| [7202] Apache HTTP Server 2.4.2 on Oracle Solaris ld_library_path cross site scripting
7960| [7075] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector NioEndpoint.java denial of service
7961| [7074] Apache Tomcat up to 6.0.35/7.0.29 FORM Authentication RealmBase.java weak authentication
7962| [7073] Apache Tomcat up to 6.0.35/7.0.31 CSRF Prevention Filter cross site request forgery
7963| [63090] Apache Tomcat up to 4.1.24 denial of service
7964| [63089] Apache HTTP Server up to 2.2.13 mod_proxy_ajp denial of service
7965| [62933] Apache Tomcat up to 5.5.0 Access Restriction unknown vulnerability
7966| [62929] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector Memory Consumption denial of service
7967| [62833] Apache CXF -/2.6.0 spoofing
7968| [62832] Apache Axis2 up to 1.6.2 spoofing
7969| [62831] Apache Axis up to 1.4 Java Message Service spoofing
7970| [62830] Apache Commons-httpclient 3.0 Payments spoofing
7971| [62826] Apache Libcloud up to 0.11.0 spoofing
7972| [62757] Apache Open For Business Project up to 10.04.0 unknown vulnerability
7973| [8830] Red Hat JBoss Enterprise Application Platform 6.0.1 org.apache.catalina.connector.Response.encodeURL information disclosure
7974| [62661] Apache Axis2 unknown vulnerability
7975| [62658] Apache Axis2 unknown vulnerability
7976| [62467] Apache Qpid up to 0.17 denial of service
7977| [62417] Apache CXF 2.4.7/2.4.8/2.5.3/2.5.4/2.6.1 spoofing
7978| [6301] Apache HTTP Server mod_pagespeed cross site scripting
7979| [6300] Apache HTTP Server mod_pagespeed Hostname information disclosure
7980| [6123] Apache Wicket up to 1.5.7 Ajax Link cross site scripting
7981| [62035] Apache Struts up to 2.3.4 denial of service
7982| [61916] Apache QPID 0.5/0.6/0.14/0.16 unknown vulnerability
7983| [6998] Apache Tomcat 5.5.35/6.0.35/7.0.28 DIGEST Authentication Session State Caching privilege escalation
7984| [6997] Apache Tomcat 5.5.35/6.0.35/7.0.28 HTTP Digest Authentication Implementation privilege escalation
7985| [6092] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_ajp.c information disclosure
7986| [6090] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_http.c information disclosure
7987| [61507] Apache POI up to 3.8 UnhandledDataStructure denial of service
7988| [6070] Apache Struts up to 2.3.4 Token Name Configuration Parameter privilege escalation
7989| [6069] Apache Struts up to 2.3.4 Request Parameter OGNL Expression denial of service
7990| [5764] Oracle Solaris 10 Apache HTTP Server information disclosure
7991| [5700] Oracle Secure Backup 10.3.0.3/10.4.0.1 Apache denial of service
7992| [61255] Apache Hadoop 2.0.0 Kerberos unknown vulnerability
7993| [61229] Apache Sling up to 2.1.1 denial of service
7994| [61152] Apache Commons-compress 1.0/1.1/1.2/1.3/1.4 denial of service
7995| [61094] Apache Roller up to 5.0 cross site scripting
7996| [61093] Apache Roller up to 5.0 cross site request forgery
7997| [61005] Apache OpenOffice 3.3/3.4 unknown vulnerability
7998| [9673] Apache HTTP Server up to 2.4.4 mod_dav mod_dav.c Request denial of service
7999| [5436] Apache OpenOffice 3.3/3.4 WPXContentListener.cpp _closeTableRow File memory corruption
8000| [5435] Apache OpenOffice 3.3/3.4 vclmi.dll File memory corruption
8001| [60730] PHP 5.4.0/5.4.1/5.4.2 apache_request_headers memory corruption
8002| [60708] Apache Qpid 0.12 unknown vulnerability
8003| [5032] Apache Hadoop up to 0.20.205.0/1.0.1/0.23.1 Kerberos/MapReduce Security Feature privilege escalation
8004| [4949] Apache Struts File Upload XSLTResult.java XSLT File privilege escalation
8005| [4955] Apache Traffic Server 3.0.3/3.1.2 HTTP Header Parser memory corruption
8006| [4882] Apache Wicket up to 1.5.4 directory traversal
8007| [4881] Apache Wicket up to 1.4.19 cross site scripting
8008| [4884] Apache HTTP Server up to 2.3.6 mod_fcgid fcgid_spawn_ctl.c FcgidMaxProcessesPerClass HTTP Requests denial of service
8009| [60352] Apache Struts up to 2.2.3 memory corruption
8010| [60153] Apache Portable Runtime up to 1.4.3 denial of service
8011| [4598] Apache Struts 1.3.10 upload-submit.do cross site scripting
8012| [4597] Apache Struts 1.3.10 processSimple.do cross site scripting
8013| [4596] Apache Struts 2.0.14/2.2.3 struts2-rest-showcase/orders cross site scripting
8014| [4595] Apache Struts 2.0.14/2.2.3 struts2-showcase/person/editPerson.action cross site scripting
8015| [4583] Apache HTTP Server up to 2.2.21 Threaded MPM denial of service
8016| [4582] Apache HTTP Server up to 2.2.21 protocol.c information disclosure
8017| [4571] Apache Struts up to 2.3.1.2 privilege escalation
8018| [4557] Apache Tomcat up to 7.0.21 Caching/Recycling information disclosure
8019| [59934] Apache Tomcat up to 6.0.9 DigestAuthenticator.java unknown vulnerability
8020| [59933] Apache Tomcat up to 6.0.9 Access Restriction unknown vulnerability
8021| [59932] Apache Tomcat up to 6.0.9 unknown vulnerability
8022| [59931] Apache Tomcat up to 6.0.9 Access Restriction information disclosure
8023| [59902] Apache Struts up to 2.2.3 Interfaces unknown vulnerability
8024| [4528] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
8025| [4527] Apache Struts up to 2.2.3 ExceptionDelegator cross site scripting
8026| [59888] Apache Tomcat up to 6.0.6 denial of service
8027| [59886] Apache ActiveMQ up to 5.5.1 Crash denial of service
8028| [4513] Apache Struts up to 2.3.1 ParameterInterceptor directory traversal
8029| [4512] Apache Struts up to 2.2.3 CookieInterceptor privilege escalation
8030| [59850] Apache Geronimo up to 2.2.1 denial of service
8031| [59825] Apache HTTP Server up to 2.1.7 mod_reqtimeout denial of service
8032| [59556] Apache HTTP Server up to 2.0.53 mod_proxy information disclosure
8033| [58467] Apache libcloud 0.2.0/0.3.0/0.3.1/0.4.0 Access Restriction spoofing
8034| [58413] Apache Tomcat up to 6.0.10 spoofing
8035| [58381] Apache Wicket up to 1.4.17 cross site scripting
8036| [58296] Apache Tomcat up to 7.0.19 unknown vulnerability
8037| [57888] Apache HttpClient 4.0/4.0.1/4.1 Authorization information disclosure
8038| [57587] Apache Subversion up to 1.6.16 mod_dav_svn information disclosure
8039| [57585] Apache Subversion up to 1.6.16 mod_dav_svn Memory Consumption denial of service
8040| [57584] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
8041| [57577] Apache Rampart-C 1.3.0 Access Restriction rampart_timestamp_token_validate privilege escalation
8042| [57568] Apache Archiva up to 1.3.4 cross site scripting
8043| [57567] Apache Archiva up to 1.3.4 cross site request forgery
8044| [57481] Apache Tomcat 7.0.12/7.0.13 Access Restriction unknown vulnerability
8045| [4355] Apache HTTP Server APR apr_fnmatch denial of service
8046| [57435] Apache Struts up to 2.2.1.1 FileHandler.java cross site scripting
8047| [57425] Apache Struts up to 2.2.1.1 cross site scripting
8048| [4352] Apache HTTP Server 2.2.x APR apr_fnmatch denial of service
8049| [57025] Apache Tomcat up to 7.0.11 information disclosure
8050| [57024] Apache Tomcat 7.0.11 Access Restriction information disclosure
8051| [56774] IBM WebSphere Application Server up to 7.0.0.14 org.apache.jasper.runtime.JspWriterImpl.response denial of service
8052| [56824] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
8053| [56832] Apache Tomcat up to 7.0.10 Access Restriction information disclosure
8054| [56830] Apache Tomcat up to 7.0.9 Access Restriction privilege escalation
8055| [12440] Apache Tomcat 6.0.33 Malicious Request cross site scripting
8056| [56512] Apache Continuum up to 1.4.0 cross site scripting
8057| [4285] Apache Tomcat 5.x JVM getLocale denial of service
8058| [4284] Apache Tomcat 5.x HTML Manager Infinite Loop cross site scripting
8059| [4283] Apache Tomcat 5.x ServletContect privilege escalation
8060| [56441] Apache Tomcat up to 7.0.6 denial of service
8061| [56300] Apache CouchDB up to 1.0.1 Web Administration Interface cross site scripting
8062| [55967] Apache Subversion up to 1.6.4 rev_hunt.c denial of service
8063| [55966] Apache Subversion up to 1.6.4 mod_dav_svn repos.c walk denial of service
8064| [55095] Apache Axis2 up to 1.6 Default Password memory corruption
8065| [55631] Apache Archiva up to 1.3.1 User Account cross site request forgery
8066| [55556] Apache Tomcat up to 6.0.29 Default Configuration information disclosure
8067| [55553] Apache Tomcat up to 7.0.4 sessionsList.jsp cross site scripting
8068| [55162] Apache MyFaces up to 2.0.0 Authentication Code unknown vulnerability
8069| [54881] Apache Subversion up to 1.6.12 mod_dav_svn authz.c privilege escalation
8070| [54879] Apache APR-util up to 0.9.14 mod_reqtimeout apr_brigade_split_line denial of service
8071| [54693] Apache Traffic Server DNS Cache unknown vulnerability
8072| [54416] Apache CouchDB up to 0.11.0 cross site request forgery
8073| [54394] Apache CXF up to 2.2.8 Memory Consumption denial of service
8074| [54261] Apache Tomcat jsp/cal/cal2.jsp cross site scripting
8075| [54166] Apache HTTP Server up to 2.2.12 mod_cache Crash denial of service
8076| [54385] Apache Struts up to 2.1.8.1 ParameterInterceptor unknown vulnerability
8077| [54012] Apache Tomcat up to 6.0.10 denial of service
8078| [53763] Apache Axis2 1.3/1.4/1.4.1/1.5/1.5.1 Memory Consumption denial of service
8079| [53368] Apache MyFaces 1.1.7/1.2.8 cross site scripting
8080| [53397] Apache axis2 1.4.1/1.5.1 Administration Console cross site scripting
8081| [52894] Apache Tomcat up to 6.0.7 information disclosure
8082| [52960] Apache ActiveMQ up to 5.4-snapshot information disclosure
8083| [52843] Apache HTTP Server mod_auth_shadow unknown vulnerability
8084| [52786] Apache Open For Business Project up to 09.04 cross site scripting
8085| [52587] Apache ActiveMQ up to 5.3.0 cross site request forgery
8086| [52586] Apache ActiveMQ up to 5.3.0 cross site scripting
8087| [52584] Apache CouchDB up to 0.10.1 information disclosure
8088| [51757] Apache HTTP Server 2.0.44 cross site scripting
8089| [51756] Apache HTTP Server 2.0.44 spoofing
8090| [51717] Apache HTTP Server up to 1.3.3 mod_proxy ap_proxy_send_fb memory corruption
8091| [51690] Apache Tomcat up to 6.0 directory traversal
8092| [51689] Apache Tomcat up to 6.0 information disclosure
8093| [51688] Apache Tomcat up to 6.0 directory traversal
8094| [50886] HP Operations Manager 8.10 on Windows File Upload org.apache.catalina.manager.HTMLManagerServlet memory corruption
8095| [50802] Apache Tomcat up to 3.3 Default Password weak authentication
8096| [50626] Apache Solr 1.0.0 cross site scripting
8097| [49857] Apache HTTP Server mod_proxy_ftp cross site scripting
8098| [49856] Apache HTTP Server 2.2.13 mod_proxy_ftp ap_proxy_ftp_handler denial of service
8099| [49348] Apache Xerces-C++ 2.7.0 Stack-Based denial of service
8100| [86789] Apache Portable Runtime memory/unix/apr_pools.c unknown vulnerability
8101| [49283] Apache APR-util up to 1.3.8 apr-util misc/apr_rmm.c apr_rmm_realloc memory corruption
8102| [48952] Apache HTTP Server up to 1.3.6 mod_deflate denial of service
8103| [48626] Apache Tomcat up to 4.1.23 Access Restriction directory traversal
8104| [48431] Apache Tomcat up to 4.1.23 j_security_check cross site scripting
8105| [48430] Apache Tomcat up to 4.1.23 mod_jk denial of service
8106| [47801] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site request forgery
8107| [47800] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site scripting
8108| [47799] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console directory traversal
8109| [47648] Apache Tiles 2.1.0/2.1.1 cross site scripting
8110| [47640] Apache Struts 2.0.6/2.0.8/2.0.9/2.0.11/2.1 cross site scripting
8111| [47638] Apache Tomcat up to 4.1.23 mod_jk information disclosure
8112| [47636] Apache Struts 2.0.9 xip_client.html cross site scripting
8113| [47593] Apache Mod Perl 1 perl-status Apache::Status cross site scripting
8114| [47637] Apache Struts 1.0.2/1.1/1.2.4/1.2.7/1.2.8 cross site scripting
8115| [47239] Apache Struts up to 2.1.2 Beta struts directory traversal
8116| [47214] Apachefriends xampp 1.6.8 spoofing
8117| [47213] Apachefriends xampp 1.6.8 htaccess cross site request forgery
8118| [47162] Apachefriends XAMPP 1.4.4 weak authentication
8119| [47065] Apache Tomcat 4.1.23 cross site scripting
8120| [46834] Apache Tomcat up to 5.5.20 cross site scripting
8121| [46004] Apache Jackrabbit 1.4/1.5.0 search.jsp cross site scripting
8122| [49205] Apache Roller 2.3/3.0/3.1/4.0 Search cross site scripting
8123| [86625] Apache Struts directory traversal
8124| [44461] Apache Tomcat up to 5.5.0 information disclosure
8125| [44389] Apache Xerces-C++ XML Parser Memory Consumption denial of service
8126| [44352] Apache Friends XAMPP 1.6.8 adodb.php cross site scripting
8127| [43663] Apache Tomcat up to 6.0.16 directory traversal
8128| [43612] Apache Friends XAMPP 1.6.7 iart.php cross site scripting
8129| [43556] Apache HTTP Server up to 2.1.8 mod_proxy_ftp proxy_ftp.c cross site scripting
8130| [43516] Apache Tomcat up to 4.1.20 directory traversal
8131| [43509] Apache Tomcat up to 6.0.13 cross site scripting
8132| [42637] Apache Tomcat up to 6.0.16 cross site scripting
8133| [42325] Apache HTTP Server up to 2.1.8 Error Page cross site scripting
8134| [41838] Apache-SSL 1.3.34 1.57 expandcert privilege escalation
8135| [41091] Apache Software Foundation Mod Jk up to 2.0.1 mod_jk2 Stack-based memory corruption
8136| [40924] Apache Tomcat up to 6.0.15 information disclosure
8137| [40923] Apache Tomcat up to 6.0.15 unknown vulnerability
8138| [40922] Apache Tomcat up to 6.0 information disclosure
8139| [40710] Apache HTTP Server up to 2.0.61 mod_negotiation cross site scripting
8140| [40709] Apache HTTP Server up to 2.0.53 mod_negotiation cross site scripting
8141| [40656] Apache Tomcat 5.5.20 information disclosure
8142| [40503] Apache HTTP Server mod_proxy_ftp cross site scripting
8143| [40502] Apache HTTP Server up to 2.2.5 mod_proxy_balancer memory corruption
8144| [40501] Apache HTTP Server 2.2.6 mod_proxy_balancer cross site request forgery
8145| [40398] Apache HTTP Server up to 2.2 mod_proxy_balancer cross site scripting
8146| [40397] Apache HTTP Server up to 2.2 mod_proxy_balancer balancer_handler denial of service
8147| [40234] Apache Tomcat up to 6.0.15 directory traversal
8148| [40221] Apache HTTP Server 2.2.6 information disclosure
8149| [40027] David Castro Apache Authcas 0.4 sql injection
8150| [3495] Apache OpenOffice up to 2.3 Database Document Processor unknown vulnerability
8151| [3489] Apache HTTP Server 2.x HTTP Header cross site scripting
8152| [3414] Apache Tomcat WebDAV Stored privilege escalation
8153| [39489] Apache Jakarta Slide up to 2.1 directory traversal
8154| [39540] Apache Geronimo 2.0/2.0.1/2.0.2/2.1 unknown vulnerability
8155| [3310] Apache OpenOffice 1.1.3/2.0.4/2.2.1 TIFF Image Parser Heap-based memory corruption
8156| [38768] Apache HTTP Server up to 2.1.7 mod_autoindex.c cross site scripting
8157| [38952] Apache Geronimo 2.0.1/2.1 unknown vulnerability
8158| [38658] Apache Tomcat 4.1.31 cal2.jsp cross site request forgery
8159| [38524] Apache Geronimo 2.0 unknown vulnerability
8160| [3256] Apache Tomcat up to 6.0.13 cross site scripting
8161| [38331] Apache Tomcat 4.1.24 information disclosure
8162| [38330] Apache Tomcat 4.1.24 information disclosure
8163| [38185] Apache Tomcat 3.3/3.3.1/3.3.1a/3.3.2 Error Message CookieExample cross site scripting
8164| [37967] Apache Tomcat up to 4.1.36 Error Message sendmail.jsp cross site scripting
8165| [37647] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 Authorization unknown vulnerability
8166| [37646] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 unknown vulnerability
8167| [3141] Apache Tomcat up to 4.1.31 Accept-Language Header cross site scripting
8168| [3133] Apache Tomcat up to 6.0 HTTP cross site scripting
8169| [37292] Apache Tomcat up to 5.5.1 cross site scripting
8170| [3130] Apache OpenOffice 2.2.1 RTF Document Heap-based memory corruption
8171| [36981] Apache Tomcat JK Web Server Connector up to 1.2.22 mod_jk directory traversal
8172| [36892] Apache Tomcat up to 4.0.0 hello.jsp cross site scripting
8173| [37320] Apache MyFaces Tomahawk up to 1.1.4 cross site scripting
8174| [36697] Apache Tomcat up to 5.5.17 implicit-objects.jsp cross site scripting
8175| [36491] Apache Axis 1.0 Installation javaioFileNotFoundException information disclosure
8176| [36400] Apache Tomcat 5.5.15 mod_jk cross site scripting
8177| [36698] Apache Tomcat up to 4.0.0 cal2.jsp cross site scripting
8178| [36224] XAMPP Apache Distribution up to 1.6.0a adodb.php connect memory corruption
8179| [36225] XAMPP Apache Distribution 1.6.0a sql injection
8180| [2997] Apache httpd/Tomcat 5.5/6.0 directory traversal
8181| [35896] Apache Apache Test up to 1.29 mod_perl denial of service
8182| [35653] Avaya S8300 Cm 3.1.2 Apache Tomcat unknown vulnerability
8183| [35402] Apache Tomcat JK Web Server Connector 1.2.19 mod_jk.so map_uri_to_worker memory corruption
8184| [35067] Apache Stats up to 0.0.2 extract unknown vulnerability
8185| [35025] Apache Stats up to 0.0.3 extract unknown vulnerability
8186| [34252] Apache HTTP Server denial of service
8187| [2795] Apache OpenOffice 2.0.4 WMF/EMF File Heap-based memory corruption
8188| [33877] Apache Opentaps 0.9.3 cross site scripting
8189| [33876] Apache Open For Business Project unknown vulnerability
8190| [33875] Apache Open For Business Project cross site scripting
8191| [2703] Apache Jakarta Tomcat up to 5.x der_get_oid memory corruption
8192| [2611] Apache HTTP Server up to 1.0.1 set_var Format String
8193|
8194| MITRE CVE - https://cve.mitre.org:
8195| [CVE-2013-4156] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.
8196| [CVE-2013-4131] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
8197| [CVE-2013-3239] phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.
8198| [CVE-2013-3060] The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
8199| [CVE-2013-2765] The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
8200| [CVE-2013-2251] Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
8201| [CVE-2013-2249] mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
8202| [CVE-2013-2248] Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
8203| [CVE-2013-2189] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.
8204| [CVE-2013-2135] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
8205| [CVE-2013-2134] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
8206| [CVE-2013-2115] Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
8207| [CVE-2013-2071] java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
8208| [CVE-2013-2067] java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
8209| [CVE-2013-1966] Apache Struts 2 before 2.3.14.1 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
8210| [CVE-2013-1965] Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.1, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
8211| [CVE-2013-1896] mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
8212| [CVE-2013-1884] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
8213| [CVE-2013-1879] Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."
8214| [CVE-2013-1862] mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
8215| [CVE-2013-1849] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
8216| [CVE-2013-1847] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
8217| [CVE-2013-1846] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL.
8218| [CVE-2013-1845] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file or directory.
8219| [CVE-2013-1814] The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
8220| [CVE-2013-1777] The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not property implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
8221| [CVE-2013-1768] The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
8222| [CVE-2013-1088] Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
8223| [CVE-2013-1048] The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
8224| [CVE-2013-0966] The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
8225| [CVE-2013-0942] Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8226| [CVE-2013-0941] EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
8227| [CVE-2013-0253] The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
8228| [CVE-2013-0248] The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
8229| [CVE-2013-0239] Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
8230| [CVE-2012-6573] Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.
8231| [CVE-2012-6551] The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
8232| [CVE-2012-6092] Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
8233| [CVE-2012-5887] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.
8234| [CVE-2012-5886] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
8235| [CVE-2012-5885] The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
8236| [CVE-2012-5786] The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF, possibly 2.6.0, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
8237| [CVE-2012-5785] Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
8238| [CVE-2012-5784] Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
8239| [CVE-2012-5783] Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
8240| [CVE-2012-5633] The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
8241| [CVE-2012-5616] Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.
8242| [CVE-2012-5568] Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
8243| [CVE-2012-5351] Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
8244| [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
8245| [CVE-2012-4557] The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
8246| [CVE-2012-4556] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query.
8247| [CVE-2012-4555] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors.
8248| [CVE-2012-4534] org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
8249| [CVE-2012-4528] The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
8250| [CVE-2012-4501] Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
8251| [CVE-2012-4460] The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an out-of-bounds read, but it might not trigger a crash.
8252| [CVE-2012-4459] Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.
8253| [CVE-2012-4458] The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the client-properties map in a connection.start-ok message.
8254| [CVE-2012-4446] The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
8255| [CVE-2012-4431] org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
8256| [CVE-2012-4418] Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
8257| [CVE-2012-4387] Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
8258| [CVE-2012-4386] The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
8259| [CVE-2012-4360] Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8260| [CVE-2012-4063] The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via unspecified vectors.
8261| [CVE-2012-4001] The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.
8262| [CVE-2012-3908] Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
8263| [CVE-2012-3546] org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
8264| [CVE-2012-3544] Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
8265| [CVE-2012-3526] The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.
8266| [CVE-2012-3513] munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
8267| [CVE-2012-3506] Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
8268| [CVE-2012-3502] The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
8269| [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
8270| [CVE-2012-3467] Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
8271| [CVE-2012-3451] Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
8272| [CVE-2012-3446] Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
8273| [CVE-2012-3376] DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
8274| [CVE-2012-3373] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
8275| [CVE-2012-3126] Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Products Suite 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Apache Tomcat Agent.
8276| [CVE-2012-3123] Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.
8277| [CVE-2012-2760] mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
8278| [CVE-2012-2733] java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
8279| [CVE-2012-2687] Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
8280| [CVE-2012-2381] Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
8281| [CVE-2012-2380] Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.
8282| [CVE-2012-2379] Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
8283| [CVE-2012-2378] Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
8284| [CVE-2012-2329] Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.
8285| [CVE-2012-2145] Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.
8286| [CVE-2012-2138] The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.
8287| [CVE-2012-2098] Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
8288| [CVE-2012-1574] The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
8289| [CVE-2012-1181] fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.
8290| [CVE-2012-1089] Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
8291| [CVE-2012-1007] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.
8292| [CVE-2012-1006] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
8293| [CVE-2012-0883] envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
8294| [CVE-2012-0840] tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
8295| [CVE-2012-0838] Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
8296| [CVE-2012-0788] The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.
8297| [CVE-2012-0394] ** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
8298| [CVE-2012-0393] The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
8299| [CVE-2012-0392] The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
8300| [CVE-2012-0391] The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
8301| [CVE-2012-0256] Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
8302| [CVE-2012-0216] The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
8303| [CVE-2012-0213] The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
8304| [CVE-2012-0053] protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
8305| [CVE-2012-0047] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
8306| [CVE-2012-0031] scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
8307| [CVE-2012-0022] Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
8308| [CVE-2012-0021] The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
8309| [CVE-2011-5064] DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
8310| [CVE-2011-5063] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
8311| [CVE-2011-5062] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
8312| [CVE-2011-5057] Apache Struts 2.3.1.1 and earlier provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
8313| [CVE-2011-5034] Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
8314| [CVE-2011-4905] Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
8315| [CVE-2011-4858] Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
8316| [CVE-2011-4668] IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
8317| [CVE-2011-4449] actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.
8318| [CVE-2011-4415] The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
8319| [CVE-2011-4317] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
8320| [CVE-2011-3639] The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
8321| [CVE-2011-3620] Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
8322| [CVE-2011-3607] Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.
8323| [CVE-2011-3376] org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
8324| [CVE-2011-3375] Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
8325| [CVE-2011-3368] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
8326| [CVE-2011-3348] The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
8327| [CVE-2011-3192] The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
8328| [CVE-2011-3190] Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
8329| [CVE-2011-2729] native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
8330| [CVE-2011-2712] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
8331| [CVE-2011-2688] SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
8332| [CVE-2011-2526] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.
8333| [CVE-2011-2516] Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
8334| [CVE-2011-2481] Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
8335| [CVE-2011-2329] The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730.
8336| [CVE-2011-2204] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.
8337| [CVE-2011-2088] XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
8338| [CVE-2011-2087] Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
8339| [CVE-2011-1928] The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.
8340| [CVE-2011-1921] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
8341| [CVE-2011-1783] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
8342| [CVE-2011-1772] Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
8343| [CVE-2011-1752] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
8344| [CVE-2011-1610] Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
8345| [CVE-2011-1582] Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
8346| [CVE-2011-1571] Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
8347| [CVE-2011-1570] Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
8348| [CVE-2011-1503] The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.
8349| [CVE-2011-1502] Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
8350| [CVE-2011-1498] Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
8351| [CVE-2011-1475] The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
8352| [CVE-2011-1419] Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
8353| [CVE-2011-1318] Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
8354| [CVE-2011-1184] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
8355| [CVE-2011-1183] Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
8356| [CVE-2011-1176] The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
8357| [CVE-2011-1088] Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
8358| [CVE-2011-1077] Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8359| [CVE-2011-1026] Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of administrators.
8360| [CVE-2011-0715] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
8361| [CVE-2011-0534] Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
8362| [CVE-2011-0533] Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta
8363| [CVE-2011-0419] Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
8364| [CVE-2011-0013] Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
8365| [CVE-2010-4644] Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
8366| [CVE-2010-4539] The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.
8367| [CVE-2010-4476] The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
8368| [CVE-2010-4455] Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.2 and 11.1.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Apache Plugin.
8369| [CVE-2010-4408] Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.
8370| [CVE-2010-4312] The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
8371| [CVE-2010-4172] Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
8372| [CVE-2010-3872] The fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.6 for the Apache HTTP Server does not use bytewise pointer arithmetic in certain circumstances, which has unspecified impact and attack vectors related to "untrusted FastCGI applications" and a "stack buffer overwrite."
8373| [CVE-2010-3863] Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
8374| [CVE-2010-3854] Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8375| [CVE-2010-3718] Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
8376| [CVE-2010-3449] Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1
8377| [CVE-2010-3315] authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
8378| [CVE-2010-3083] sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.
8379| [CVE-2010-2952] Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.
8380| [CVE-2010-2791] mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
8381| [CVE-2010-2375] Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
8382| [CVE-2010-2234] Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.
8383| [CVE-2010-2227] Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
8384| [CVE-2010-2103] Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.
8385| [CVE-2010-2086] Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
8386| [CVE-2010-2076] Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
8387| [CVE-2010-2068] mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.
8388| [CVE-2010-2057] shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.
8389| [CVE-2010-1632] Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.
8390| [CVE-2010-1623] Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
8391| [CVE-2010-1587] The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
8392| [CVE-2010-1452] The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
8393| [CVE-2010-1325] Cross-site request forgery (CSRF) vulnerability in the apache2-slms package in SUSE Lifecycle Management Server (SLMS) 1.0 on SUSE Linux Enterprise (SLE) 11 allows remote attackers to hijack the authentication of unspecified victims via vectors related to improper parameter quoting. NOTE: some sources report that this is a vulnerability in a product named "Apache SLMS," but that is incorrect.
8394| [CVE-2010-1244] Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
8395| [CVE-2010-1157] Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.
8396| [CVE-2010-1151] Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.
8397| [CVE-2010-0684] Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
8398| [CVE-2010-0434] The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
8399| [CVE-2010-0432] Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewprofile (aka partymgr/control/login), (3) the start parameter to myportal/control/showPortalPage, (4) an invalid URI beginning with /facility/control/ReceiveReturn (aka /crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the contentId parameter (aka the entityName variable) to ecommerce/control/ViewBlogArticle, (6) the entityName parameter to webtools/control/FindGeneric, or the (7) subject or (8) content parameter to an unspecified component under ecommerce/control/contactus.
8400| [CVE-2010-0425] modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
8401| [CVE-2010-0408] The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
8402| [CVE-2010-0390] Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.
8403| [CVE-2010-0219] Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
8404| [CVE-2010-0010] Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
8405| [CVE-2010-0009] Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.
8406| [CVE-2009-5120] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a Project Woodstock service on this port.
8407| [CVE-2009-5119] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted session data.
8408| [CVE-2009-5006] The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.
8409| [CVE-2009-5005] The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.
8410| [CVE-2009-4355] Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
8411| [CVE-2009-4269] The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
8412| [CVE-2009-3923] The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
8413| [CVE-2009-3890] Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.
8414| [CVE-2009-3843] HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
8415| [CVE-2009-3821] Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8416| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
8417| [CVE-2009-3548] The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
8418| [CVE-2009-3250] The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.
8419| [CVE-2009-3095] The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
8420| [CVE-2009-3094] The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
8421| [CVE-2009-2902] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
8422| [CVE-2009-2901] The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
8423| [CVE-2009-2823] The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.
8424| [CVE-2009-2699] The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
8425| [CVE-2009-2696] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.
8426| [CVE-2009-2693] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
8427| [CVE-2009-2625] XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
8428| [CVE-2009-2412] Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR
8429| [CVE-2009-2299] The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.
8430| [CVE-2009-1956] Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
8431| [CVE-2009-1955] The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
8432| [CVE-2009-1903] The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
8433| [CVE-2009-1891] The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
8434| [CVE-2009-1890] The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
8435| [CVE-2009-1885] Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.
8436| [CVE-2009-1462] The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.
8437| [CVE-2009-1275] Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
8438| [CVE-2009-1195] The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
8439| [CVE-2009-1191] mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
8440| [CVE-2009-1012] Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.
8441| [CVE-2009-0918] Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.
8442| [CVE-2009-0796] Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.
8443| [CVE-2009-0783] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
8444| [CVE-2009-0781] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
8445| [CVE-2009-0754] PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.
8446| [CVE-2009-0580] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.
8447| [CVE-2009-0486] Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
8448| [CVE-2009-0039] Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.
8449| [CVE-2009-0038] Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring
8450| [CVE-2009-0033] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.
8451| [CVE-2009-0026] Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
8452| [CVE-2009-0023] The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
8453| [CVE-2008-6879] Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
8454| [CVE-2008-6755] ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.
8455| [CVE-2008-6722] Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.
8456| [CVE-2008-6682] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
8457| [CVE-2008-6505] Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.
8458| [CVE-2008-6504] ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.
8459| [CVE-2008-5696] Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
8460| [CVE-2008-5676] Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."
8461| [CVE-2008-5519] The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.
8462| [CVE-2008-5518] Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet)
8463| [CVE-2008-5515] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.
8464| [CVE-2008-5457] Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
8465| [CVE-2008-4308] The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
8466| [CVE-2008-4008] Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.
8467| [CVE-2008-3666] Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured
8468| [CVE-2008-3271] Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
8469| [CVE-2008-3257] Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
8470| [CVE-2008-2939] Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
8471| [CVE-2008-2938] Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
8472| [CVE-2008-2742] Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.
8473| [CVE-2008-2717] TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
8474| [CVE-2008-2579] Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.
8475| [CVE-2008-2384] SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
8476| [CVE-2008-2370] Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
8477| [CVE-2008-2364] The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
8478| [CVE-2008-2168] Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
8479| [CVE-2008-2025] Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
8480| [CVE-2008-1947] Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
8481| [CVE-2008-1734] Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.
8482| [CVE-2008-1678] Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
8483| [CVE-2008-1232] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.
8484| [CVE-2008-0869] Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.
8485| [CVE-2008-0732] The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.
8486| [CVE-2008-0555] The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.
8487| [CVE-2008-0457] Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
8488| [CVE-2008-0456] CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
8489| [CVE-2008-0455] Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
8490| [CVE-2008-0128] The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
8491| [CVE-2008-0005] mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
8492| [CVE-2008-0002] Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
8493| [CVE-2007-6750] The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
8494| [CVE-2007-6726] Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
8495| [CVE-2007-6514] Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
8496| [CVE-2007-6423] ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
8497| [CVE-2007-6422] The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
8498| [CVE-2007-6421] Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
8499| [CVE-2007-6420] Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
8500| [CVE-2007-6388] Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8501| [CVE-2007-6361] Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
8502| [CVE-2007-6342] SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.
8503| [CVE-2007-6286] Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
8504| [CVE-2007-6258] Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.
8505| [CVE-2007-6231] Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_includepath parameter to (1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php, or (5) libchart-1.1/libchart.php in include/. NOTE: access to include/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
8506| [CVE-2007-6203] Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
8507| [CVE-2007-5797] SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
8508| [CVE-2007-5731] Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.
8509| [CVE-2007-5461] Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
8510| [CVE-2007-5342] The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
8511| [CVE-2007-5333] Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
8512| [CVE-2007-5156] Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
8513| [CVE-2007-5085] Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
8514| [CVE-2007-5000] Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8515| [CVE-2007-4724] Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.
8516| [CVE-2007-4723] Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
8517| [CVE-2007-4641] Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.
8518| [CVE-2007-4556] Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.
8519| [CVE-2007-4548] The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
8520| [CVE-2007-4465] Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
8521| [CVE-2007-3847] The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
8522| [CVE-2007-3571] The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.
8523| [CVE-2007-3386] Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
8524| [CVE-2007-3385] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
8525| [CVE-2007-3384] Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.
8526| [CVE-2007-3383] Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.
8527| [CVE-2007-3382] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
8528| [CVE-2007-3304] Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
8529| [CVE-2007-3303] Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
8530| [CVE-2007-3101] Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.
8531| [CVE-2007-2450] Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.
8532| [CVE-2007-2449] Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the '
8533| [CVE-2007-2353] Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
8534| [CVE-2007-2025] Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.
8535| [CVE-2007-1863] cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
8536| [CVE-2007-1862] The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
8537| [CVE-2007-1860] mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.
8538| [CVE-2007-1858] The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
8539| [CVE-2007-1842] Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.
8540| [CVE-2007-1801] Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.
8541| [CVE-2007-1743] suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
8542| [CVE-2007-1742] suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
8543| [CVE-2007-1741] Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
8544| [CVE-2007-1720] Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.
8545| [CVE-2007-1636] Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.
8546| [CVE-2007-1633] Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.
8547| [CVE-2007-1577] Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
8548| [CVE-2007-1539] Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.
8549| [CVE-2007-1524] Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.
8550| [CVE-2007-1491] Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.
8551| [CVE-2007-1358] Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
8552| [CVE-2007-1349] PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
8553| [CVE-2007-0975] Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.
8554| [CVE-2007-0930] Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.
8555| [CVE-2007-0792] The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
8556| [CVE-2007-0774] Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
8557| [CVE-2007-0637] Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.
8558| [CVE-2007-0451] Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
8559| [CVE-2007-0450] Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
8560| [CVE-2007-0419] The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).
8561| [CVE-2007-0173] Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
8562| [CVE-2007-0098] Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
8563| [CVE-2007-0086] ** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.
8564| [CVE-2006-7217] Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.
8565| [CVE-2006-7216] Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.
8566| [CVE-2006-7197] The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.
8567| [CVE-2006-7196] Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
8568| [CVE-2006-7195] Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
8569| [CVE-2006-7098] The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
8570| [CVE-2006-6869] Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
8571| [CVE-2006-6675] Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecifeid parameters in Welcome web-app.
8572| [CVE-2006-6613] Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive information via a .. (dot dot) in the pa_lang[include_file] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
8573| [CVE-2006-6589] Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.
8574| [CVE-2006-6588] The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
8575| [CVE-2006-6587] Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.
8576| [CVE-2006-6445] Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
8577| [CVE-2006-6071] TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.
8578| [CVE-2006-6047] Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
8579| [CVE-2006-5894] Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
8580| [CVE-2006-5752] Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
8581| [CVE-2006-5733] Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
8582| [CVE-2006-5263] Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apache HTTP Server log file that apparently contains PHP code.
8583| [CVE-2006-4994] Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted "Program Files" pathname.
8584| [CVE-2006-4636] Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.
8585| [CVE-2006-4625] PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
8586| [CVE-2006-4558] DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
8587| [CVE-2006-4191] Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
8588| [CVE-2006-4154] Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
8589| [CVE-2006-4110] Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
8590| [CVE-2006-4004] Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
8591| [CVE-2006-3918] http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
8592| [CVE-2006-3835] Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (
8593| [CVE-2006-3747] Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
8594| [CVE-2006-3362] Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
8595| [CVE-2006-3102] Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of time under the webroot in the temp/articles directory.
8596| [CVE-2006-3070] write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.
8597| [CVE-2006-2831] Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
8598| [CVE-2006-2806] The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.
8599| [CVE-2006-2743] Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
8600| [CVE-2006-2514] Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
8601| [CVE-2006-2330] PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
8602| [CVE-2006-1777] Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache error_log file, which is then included by doc/index.php.
8603| [CVE-2006-1564] Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.
8604| [CVE-2006-1548] Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
8605| [CVE-2006-1547] ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
8606| [CVE-2006-1546] Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
8607| [CVE-2006-1393] Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
8608| [CVE-2006-1346] Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.
8609| [CVE-2006-1292] Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
8610| [CVE-2006-1243] Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
8611| [CVE-2006-1095] Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
8612| [CVE-2006-1079] htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
8613| [CVE-2006-1078] Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
8614| [CVE-2006-0743] Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
8615| [CVE-2006-0254] Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.
8616| [CVE-2006-0150] Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
8617| [CVE-2006-0144] The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.
8618| [CVE-2006-0042] Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.
8619| [CVE-2005-4857] eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a "memory addressing error".
8620| [CVE-2005-4849] Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information.
8621| [CVE-2005-4836] The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
8622| [CVE-2005-4814] Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.
8623| [CVE-2005-4703] Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
8624| [CVE-2005-3745] Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
8625| [CVE-2005-3630] Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.
8626| [CVE-2005-3510] Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
8627| [CVE-2005-3392] Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.
8628| [CVE-2005-3357] mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
8629| [CVE-2005-3352] Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
8630| [CVE-2005-3319] The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.
8631| [CVE-2005-3164] The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
8632| [CVE-2005-2970] Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
8633| [CVE-2005-2963] The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.
8634| [CVE-2005-2728] The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
8635| [CVE-2005-2660] apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.
8636| [CVE-2005-2088] The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
8637| [CVE-2005-1754] ** DISPUTED ** JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
8638| [CVE-2005-1753] ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
8639| [CVE-2005-1344] Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
8640| [CVE-2005-1268] Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
8641| [CVE-2005-1266] Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
8642| [CVE-2005-0808] Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
8643| [CVE-2005-0182] The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.
8644| [CVE-2005-0108] Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.
8645| [CVE-2004-2734] webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
8646| [CVE-2004-2680] mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
8647| [CVE-2004-2650] Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
8648| [CVE-2004-2343] ** DISPUTED ** Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument.
8649| [CVE-2004-2336] Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.
8650| [CVE-2004-2115] Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.
8651| [CVE-2004-1834] mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
8652| [CVE-2004-1765] Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.
8653| [CVE-2004-1545] UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
8654| [CVE-2004-1438] The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
8655| [CVE-2004-1405] MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
8656| [CVE-2004-1404] Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
8657| [CVE-2004-1387] The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
8658| [CVE-2004-1084] Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
8659| [CVE-2004-1083] Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
8660| [CVE-2004-1082] mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
8661| [CVE-2004-0942] Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
8662| [CVE-2004-0940] Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
8663| [CVE-2004-0885] The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
8664| [CVE-2004-0811] Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
8665| [CVE-2004-0809] The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
8666| [CVE-2004-0786] The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
8667| [CVE-2004-0751] The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
8668| [CVE-2004-0748] mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
8669| [CVE-2004-0747] Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
8670| [CVE-2004-0700] Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
8671| [CVE-2004-0646] Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
8672| [CVE-2004-0529] The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.
8673| [CVE-2004-0493] The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
8674| [CVE-2004-0492] Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
8675| [CVE-2004-0490] cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.
8676| [CVE-2004-0488] Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
8677| [CVE-2004-0263] PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
8678| [CVE-2004-0174] Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
8679| [CVE-2004-0173] Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
8680| [CVE-2004-0113] Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
8681| [CVE-2004-0009] Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.
8682| [CVE-2003-1581] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
8683| [CVE-2003-1580] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
8684| [CVE-2003-1573] The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."
8685| [CVE-2003-1521] Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
8686| [CVE-2003-1516] The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
8687| [CVE-2003-1502] mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.
8688| [CVE-2003-1418] Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child proccess IDs (PID).
8689| [CVE-2003-1307] ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."
8690| [CVE-2003-1172] Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
8691| [CVE-2003-1171] Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.
8692| [CVE-2003-1138] The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
8693| [CVE-2003-1054] mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.
8694| [CVE-2003-0993] mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
8695| [CVE-2003-0987] mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
8696| [CVE-2003-0866] The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
8697| [CVE-2003-0844] mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.
8698| [CVE-2003-0843] Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.
8699| [CVE-2003-0789] mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
8700| [CVE-2003-0771] Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.
8701| [CVE-2003-0658] Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
8702| [CVE-2003-0542] Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
8703| [CVE-2003-0460] The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
8704| [CVE-2003-0254] Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
8705| [CVE-2003-0253] The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
8706| [CVE-2003-0249] ** DISPUTED ** PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."
8707| [CVE-2003-0245] Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
8708| [CVE-2003-0192] Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
8709| [CVE-2003-0189] The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
8710| [CVE-2003-0134] Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.
8711| [CVE-2003-0132] A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.
8712| [CVE-2003-0083] Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
8713| [CVE-2003-0020] Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
8714| [CVE-2003-0017] Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.
8715| [CVE-2003-0016] Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
8716| [CVE-2002-2310] ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
8717| [CVE-2002-2309] php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
8718| [CVE-2002-2272] Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
8719| [CVE-2002-2103] Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
8720| [CVE-2002-2029] PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
8721| [CVE-2002-2012] Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
8722| [CVE-2002-2009] Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
8723| [CVE-2002-2008] Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.
8724| [CVE-2002-2007] The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
8725| [CVE-2002-2006] The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
8726| [CVE-2002-1895] The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
8727| [CVE-2002-1850] mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
8728| [CVE-2002-1793] HTTP Server mod_ssl module running on HP-UX 11.04 with Virtualvault OS (VVOS) 4.5 through 4.6 closes the connection when the Apache server times out during an SSL request, which may allow attackers to cause a denial of service.
8729| [CVE-2002-1658] Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
8730| [CVE-2002-1635] The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin.
8731| [CVE-2002-1593] mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.
8732| [CVE-2002-1592] The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.
8733| [CVE-2002-1567] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
8734| [CVE-2002-1394] Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
8735| [CVE-2002-1233] A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
8736| [CVE-2002-1157] Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
8737| [CVE-2002-1156] Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
8738| [CVE-2002-1148] The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
8739| [CVE-2002-0935] Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
8740| [CVE-2002-0843] Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
8741| [CVE-2002-0840] Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
8742| [CVE-2002-0839] The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
8743| [CVE-2002-0682] Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
8744| [CVE-2002-0661] Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
8745| [CVE-2002-0658] OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.
8746| [CVE-2002-0654] Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
8747| [CVE-2002-0653] Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
8748| [CVE-2002-0513] The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.
8749| [CVE-2002-0493] Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
8750| [CVE-2002-0392] Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
8751| [CVE-2002-0259] InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.
8752| [CVE-2002-0249] PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
8753| [CVE-2002-0240] PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
8754| [CVE-2002-0082] The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
8755| [CVE-2002-0061] Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
8756| [CVE-2001-1556] The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
8757| [CVE-2001-1534] mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
8758| [CVE-2001-1510] Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.
8759| [CVE-2001-1449] The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
8760| [CVE-2001-1385] The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
8761| [CVE-2001-1342] Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
8762| [CVE-2001-1217] Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
8763| [CVE-2001-1216] Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
8764| [CVE-2001-1072] Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
8765| [CVE-2001-1013] Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
8766| [CVE-2001-0925] The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
8767| [CVE-2001-0829] A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
8768| [CVE-2001-0766] Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
8769| [CVE-2001-0731] Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
8770| [CVE-2001-0730] split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
8771| [CVE-2001-0729] Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
8772| [CVE-2001-0590] Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
8773| [CVE-2001-0131] htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
8774| [CVE-2001-0108] PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
8775| [CVE-2001-0042] PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
8776| [CVE-2000-1247] The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
8777| [CVE-2000-1210] Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
8778| [CVE-2000-1206] Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
8779| [CVE-2000-1205] Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.
8780| [CVE-2000-1204] Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
8781| [CVE-2000-1168] IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
8782| [CVE-2000-1016] The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
8783| [CVE-2000-0913] mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
8784| [CVE-2000-0883] The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.
8785| [CVE-2000-0869] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method.
8786| [CVE-2000-0868] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
8787| [CVE-2000-0791] Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.
8788| [CVE-2000-0760] The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
8789| [CVE-2000-0759] Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
8790| [CVE-2000-0628] The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.
8791| [CVE-2000-0505] The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
8792| [CVE-1999-1412] A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
8793| [CVE-1999-1293] mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
8794| [CVE-1999-1237] Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
8795| [CVE-1999-1199] Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
8796| [CVE-1999-1053] guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
8797| [CVE-1999-0926] Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
8798| [CVE-1999-0678] A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
8799| [CVE-1999-0448] IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
8800| [CVE-1999-0289] The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
8801| [CVE-1999-0236] ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
8802| [CVE-1999-0107] Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
8803| [CVE-1999-0071] Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
8804|
8805| SecurityFocus - https://www.securityfocus.com/bid/:
8806| [104554] Apache HBase CVE-2018-8025 Security Bypass Vulnerability
8807| [104465] Apache Geode CVE-2017-15695 Remote Code Execution Vulnerability
8808| [104418] Apache Storm CVE-2018-8008 Arbitrary File Write Vulnerability
8809| [104399] Apache Storm CVE-2018-1332 User Impersonation Vulnerability
8810| [104348] Apache UIMA CVE-2017-15691 XML External Entity Injection Vulnerability
8811| [104313] Apache NiFi XML External Entity Injection and Denial of Service Vulnerability
8812| [104259] Apache Geode CVE-2017-12622 Authorization Bypass Vulnerability
8813| [104257] Apache Sling XSS Protection API CVE-2017-15717 Cross Site Scripting Vulnerability
8814| [104253] Apache ZooKeeper CVE-2018-8012 Security Bypass Vulnerability
8815| [104252] Apache Batik CVE-2018-8013 Information Disclosure Vulnerability
8816| [104239] Apache Solr CVE-2018-8010 XML External Entity Multiple Information Disclosure Vulnerabilities
8817| [104215] Apache ORC CVE-2018-8015 Denial of Service Vulnerability
8818| [104203] Apache Tomcat CVE-2018-8014 Security Bypass Vulnerability
8819| [104161] Apache Ambari CVE-2018-8003 Directory Traversal Vulnerability
8820| [104140] Apache Derby CVE-2018-1313 Security Bypass Vulnerability
8821| [104135] Apache Tika CVE-2018-1338 Denial of Service Vulnerability
8822| [104008] Apache Fineract CVE-2018-1291 SQL Injection Vulnerability
8823| [104007] Apache Fineract CVE-2018-1292 SQL Injection Vulnerability
8824| [104005] Apache Fineract CVE-2018-1289 SQL Injection Vulnerability
8825| [104001] Apache Tika CVE-2018-1335 Remote Command Injection Vulnerability
8826| [103975] Apache Fineract CVE-2018-1290 SQL Injection Vulnerability
8827| [103974] Apache Solr CVE-2018-1308 XML External Entity Injection Vulnerability
8828| [103772] Apache Traffic Server CVE-2017-7671 Denial of Service Vulnerability
8829| [103770] Apache Traffic Server CVE-2017-5660 Security Bypass Vulnerability
8830| [103751] Apache Hive CVE-2018-1282 SQL Injection Vulnerability
8831| [103750] Apache Hive CVE-2018-1284 Security Bypass Vulnerability
8832| [103692] Apache Ignite CVE-2018-1295 Arbitrary Code Execution Vulnerability
8833| [103528] Apache HTTP Server CVE-2018-1302 Denial of Service Vulnerability
8834| [103525] Apache HTTP Server CVE-2017-15715 Remote Security Bypass Vulnerability
8835| [103524] Apache HTTP Server CVE-2018-1312 Remote Security Bypass Vulnerability
8836| [103522] Apache HTTP Server CVE-2018-1303 Denial of Service Vulnerability
8837| [103520] Apache HTTP Server CVE-2018-1283 Remote Security Vulnerability
8838| [103516] Apache Struts CVE-2018-1327 Denial of Service Vulnerability
8839| [103515] Apache HTTP Server CVE-2018-1301 Denial of Service Vulnerability
8840| [103512] Apache HTTP Server CVE-2017-15710 Denial of Service Vulnerability
8841| [103508] Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
8842| [103507] Apache Syncope CVE-2018-1322 Multiple Information Disclosure Vulnerabilities
8843| [103490] Apache Commons Compress CVE-2018-1324 Multiple Denial Of Service Vulnerabilities
8844| [103434] APACHE Allura CVE-2018-1319 HTTP Response Splitting Vulnerability
8845| [103389] Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
8846| [103222] Apache CloudStack CVE-2013-4317 Information Disclosure Vulnerability
8847| [103219] Apache Xerces-C CVE-2017-12627 Null Pointer Dereference Denial of Service Vulnerability
8848| [103206] Apache Geode CVE-2017-15693 Remote Code Execution Vulnerability
8849| [103205] Apache Geode CVE-2017-15692 Remote Code Execution Vulnerability
8850| [103170] Apache Tomcat CVE-2018-1304 Security Bypass Vulnerability
8851| [103144] Apache Tomcat CVE-2018-1305 Security Bypass Vulnerability
8852| [103102] Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
8853| [103098] Apache Karaf CVE-2016-8750 LDAP Injection Vulnerability
8854| [103069] Apache Tomcat CVE-2017-15706 Remote Security Weakness
8855| [103068] Apache JMeter CVE-2018-1287 Security Bypass Vulnerability
8856| [103067] Apache Qpid Dispatch Router 'router_core/connections.c' Denial of Service Vulnerability
8857| [103036] Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
8858| [103025] Apache Thrift CVE-2016-5397 Remote Command Injection Vulnerability
8859| [102879] Apache POI CVE-2017-12626 Multiple Denial of Service Vulnerabilities
8860| [102842] Apache NiFi CVE-2017-12632 Host Header Injection Vulnerability
8861| [102815] Apache NiFi CVE-2017-15697 Multiple Cross Site Scripting Vulnerabilities
8862| [102488] Apache Geode CVE-2017-9795 Remote Code Execution Vulnerability
8863| [102229] Apache Sling CVE-2017-15700 Information Disclosure Vulnerability
8864| [102226] Apache Drill CVE-2017-12630 Cross Site Scripting Vulnerability
8865| [102154] Multiple Apache Products CVE-2017-15708 Remote Code Execution Vulnerability
8866| [102127] Apache CXF Fediz CVE-2017-12631 Multiple Cross Site Request Forgery Vulnerabilities
8867| [102041] Apache Qpid Broker-J CVE-2017-15701 Denial of Service Vulnerability
8868| [102040] Apache Qpid Broker CVE-2017-15702 Security Weakness
8869| [102021] Apache Struts CVE-2017-15707 Denial of Service Vulnerability
8870| [101980] EMC RSA Authentication Agent for Web: Apache Web Server Authentication Bypass Vulnerability
8871| [101876] Apache Camel CVE-2017-12634 Deserialization Remote Code Execution Vulnerability
8872| [101874] Apache Camel CVE-2017-12633 Deserialization Remote Code Execution Vulnerability
8873| [101872] Apache Karaf CVE-2014-0219 Local Denial of Service Vulnerability
8874| [101868] Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
8875| [101859] Apache CXF CVE-2017-12624 Denial of Service Vulnerability
8876| [101844] Apache Sling Servlets Post CVE-2017-11296 Cross Site Scripting Vulnerability
8877| [101686] Apache Hive CVE-2017-12625 Information Disclosure Vulnerability
8878| [101644] Apache Wicket CVE-2012-5636 Cross Site Scripting Vulnerability
8879| [101631] Apache Traffic Server CVE-2015-3249 Multiple Remote Code Execution Vulnerabilities
8880| [101630] Apache Traffic Server CVE-2014-3624 Access Bypass Vulnerability
8881| [101625] Apache jUDDI CVE-2009-1197 Security Bypass Vulnerability
8882| [101623] Apache jUDDI CVE-2009-1198 Cross Site Scripting Vulnerability
8883| [101620] Apache Subversion 'libsvn_fs_fs/fs_fs.c' Denial of Service Vulnerability
8884| [101585] Apache OpenOffice Multiple Remote Code Execution Vulnerabilities
8885| [101577] Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
8886| [101575] Apache Wicket CVE-2014-0043 Information Disclosure Vulnerability
8887| [101570] Apache Geode CVE-2017-9797 Information Disclosure Vulnerability
8888| [101562] Apache Derby CVE-2010-2232 Arbitrary File Overwrite Vulnerability
8889| [101560] Apache Portable Runtime Utility CVE-2017-12613 Multiple Information Disclosure Vulnerabilities
8890| [101558] Apache Portable Runtime Utility Local Out-of-Bounds Read Denial of Service Vulnerability
8891| [101532] Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
8892| [101516] Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
8893| [101261] Apache Solr/Lucene CVE-2017-12629 Information Disclosure and Remote Code Execution Vulnerabilities
8894| [101230] Apache Roller CVE-2014-0030 XML External Entity Injection Vulnerability
8895| [101173] Apache IMPALA CVE-2017-9792 Information Disclosure Vulnerability
8896| [101052] Apache Commons Jelly CVE-2017-12621 Security Bypass Vulnerability
8897| [101027] Apache Mesos CVE-2017-7687 Denial of Service Vulnerability
8898| [101023] Apache Mesos CVE-2017-9790 Denial of Service Vulnerability
8899| [100954] Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
8900| [100946] Apache Wicket CVE-2014-7808 Cross Site Request Forgery Vulnerability
8901| [100901] Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability
8902| [100897] Apache Tomcat CVE-2017-12616 Information Disclosure Vulnerability
8903| [100880] Apache Directory LDAP API CVE-2015-3250 Unspecified Information Disclosure Vulnerability
8904| [100872] Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
8905| [100870] Apache Solr CVE-2017-9803 Remote Privilege Escalation Vulnerability
8906| [100859] puppetlabs-apache CVE-2017-2299 Information Disclosure Vulnerability
8907| [100829] Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
8908| [100823] Apache Spark CVE-2017-12612 Deserialization Remote Code Execution Vulnerability
8909| [100612] Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
8910| [100611] Apache Struts CVE-2017-9793 Denial of Service Vulnerability
8911| [100609] Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
8912| [100587] Apache Atlas CVE-2017-3155 Cross Frame Scripting Vulnerability
8913| [100581] Apache Atlas CVE-2017-3154 Information Disclosure Vulnerability
8914| [100578] Apache Atlas CVE-2017-3153 Cross Site Scripting Vulnerability
8915| [100577] Apache Atlas CVE-2017-3152 Cross Site Scripting Vulnerability
8916| [100547] Apache Atlas CVE-2017-3151 HTML Injection Vulnerability
8917| [100536] Apache Atlas CVE-2017-3150 Cross Site Scripting Vulnerability
8918| [100449] Apache Pony Mail CVE-2016-4460 Authentication Bypass Vulnerability
8919| [100447] Apache2Triad Multiple Security Vulnerabilities
8920| [100284] Apache Sling Servlets Post CVE-2017-9802 Cross Site Scripting Vulnerability
8921| [100280] Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
8922| [100259] Apache Subversion CVE-2017-9800 Remote Command Execution Vulnerability
8923| [100256] Apache Tomcat CVE-2017-7675 Directory Traversal Vulnerability
8924| [100235] Apache Storm CVE-2017-9799 Remote Code Execution Vulnerability
8925| [100082] Apache Commons Email CVE-2017-9801 SMTP Header Injection Vulnerability
8926| [99873] Apache Sling XSS Protection API CVE-2016-6798 XML External Entity Injection Vulnerability
8927| [99870] Apache Sling API CVE-2016-5394 Cross Site Scripting Vulnerability
8928| [99603] Apache Spark CVE-2017-7678 Cross Site Scripting Vulnerability
8929| [99592] Apache OpenMeetings CVE-2017-7685 Security Bypass Vulnerability
8930| [99587] Apache OpenMeetings CVE-2017-7673 Security Bypass Vulnerability
8931| [99586] Apache OpenMeetings CVE-2017-7688 Security Bypass Vulnerability
8932| [99584] Apache OpenMeetings CVE-2017-7684 Denial of Service Vulnerability
8933| [99577] Apache OpenMeetings CVE-2017-7663 Cross Site Scripting Vulnerability
8934| [99576] Apache OpenMeetings CVE-2017-7664 XML External Entity Injection Vulnerability
8935| [99569] Apache HTTP Server CVE-2017-9788 Memory Corruption Vulnerability
8936| [99568] Apache HTTP Server CVE-2017-9789 Denial of Service Vulnerability
8937| [99563] Apache Struts CVE-2017-7672 Denial of Service Vulnerability
8938| [99562] Apache Struts Spring AOP Functionality Denial of Service Vulnerability
8939| [99509] Apache Impala CVE-2017-5652 Information Disclosure Vulnerability
8940| [99508] Apache IMPALA CVE-2017-5640 Authentication Bypass Vulnerability
8941| [99486] Apache Traffic Control CVE-2017-7670 Denial of Service Vulnerability
8942| [99485] Apache Solr CVE-2017-7660 Security Bypass Vulnerability
8943| [99484] Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
8944| [99292] Apache Ignite CVE-2017-7686 Information Disclosure Vulnerability
8945| [99170] Apache HTTP Server CVE-2017-7679 Buffer Overflow Vulnerability
8946| [99137] Apache HTTP Server CVE-2017-7668 Denial of Service Vulnerability
8947| [99135] Apache HTTP Server CVE-2017-3167 Authentication Bypass Vulnerability
8948| [99134] Apache HTTP Server CVE-2017-3169 Denial of Service Vulnerability
8949| [99132] Apache HTTP Server CVE-2017-7659 Denial of Service Vulnerability
8950| [99112] Apache Thrift CVE-2015-3254 Denial of Service Vulnerability
8951| [99067] Apache Ranger CVE-2016-8751 HTML Injection Vulnerability
8952| [99018] Apache NiFi CVE-2017-7667 Cross Frame Scripting Vulnerability
8953| [99009] Apache NiFi CVE-2017-7665 Cross Site Scripting Vulnerability
8954| [98961] Apache Ranger CVE-2017-7677 Security Bypass Vulnerability
8955| [98958] Apache Ranger CVE-2017-7676 Security Bypass Vulnerability
8956| [98888] Apache Tomcat CVE-2017-5664 Security Bypass Vulnerability
8957| [98814] Apache Zookeeper CVE-2017-5637 Denial of Service Vulnerability
8958| [98795] Apache Hadoop CVE-2017-7669 Remote Privilege Escalation Vulnerability
8959| [98739] Apache Knox CVE-2017-5646 User Impersonation Vulnerability
8960| [98669] Apache Hive CVE-2016-3083 Security Bypass Vulnerability
8961| [98646] Apache Atlas CVE-2016-8752 Information Disclosure Vulnerability
8962| [98570] Apache Archiva CVE-2017-5657 Multiple Cross-Site Request Forgery Vulnerabilities
8963| [98489] Apache CXF Fediz CVE-2017-7661 Multiple Cross Site Request Forgery Vulnerabilities
8964| [98485] Apache CXF Fediz CVE-2017-7662 Cross Site Request Forgery Vulnerability
8965| [98466] Apache Ambari CVE-2017-5655 Insecure Temporary File Handling Vulnerability
8966| [98365] Apache Cordova For Android CVE-2016-6799 Information Disclosure Vulnerability
8967| [98025] Apache Hadoop CVE-2017-3161 Cross Site Scripting Vulnerability
8968| [98017] Apache Hadoop CVE-2017-3162 Input Validation Vulnerability
8969| [97971] Apache CXF CVE-2017-5656 Information Disclosure Vulnerability
8970| [97968] Apache CXF CVE-2017-5653 Spoofing Vulnerability
8971| [97967] Apache ActiveMQ CVE-2015-7559 Denial of Service Vulnerability
8972| [97949] Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
8973| [97948] Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
8974| [97947] Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
8975| [97945] Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
8976| [97702] Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
8977| [97582] Apache CXF CVE-2016-6812 Cross Site Scripting Vulnerability
8978| [97579] Apache CXF JAX-RS CVE-2016-8739 XML External Entity Injection Vulnerability
8979| [97544] Apache Tomcat CVE-2017-5651 Information Disclosure Vulnerability
8980| [97531] Apache Tomcat CVE-2017-5650 Denial of Service Vulnerability
8981| [97530] Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
8982| [97509] Apache Ignite CVE-2016-6805 Information Disclosure and XML External Entity Injection Vulnerabilities
8983| [97383] Apache Flex BlazeDS CVE-2017-5641 Remote Code Execution Vulnerability
8984| [97378] Apache Geode CVE-2017-5649 Information Disclosure Vulnerability
8985| [97229] Apache Ambari CVE-2016-4976 Local Information Disclosure Vulnerability
8986| [97226] Apache Camel CVE-2017-5643 Server Side Request Forgery Security Bypass Vulnerability
8987| [97184] Apache Ambari CVE-2016-6807 Remote Command Execution Vulnerability
8988| [97179] Apache Camel CVE-2016-8749 Java Deserialization Multiple Remote Code Execution Vulnerabilities
8989| [96983] Apache POI CVE-2017-5644 Denial Of Service Vulnerability
8990| [96895] Apache Tomcat CVE-2016-8747 Information Disclosure Vulnerability
8991| [96731] Apache NiFi CVE-2017-5636 Remote Code Injection Vulnerability
8992| [96730] Apache NiFi CVE-2017-5635 Security Bypass Vulnerability
8993| [96729] Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
8994| [96540] IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
8995| [96398] Apache CXF CVE-2017-3156 Information Disclosure Vulnerability
8996| [96321] Apache Camel CVE-2017-3159 Remote Code Execution Vulnerability
8997| [96293] Apache Tomcat 'http11/AbstractInputBuffer.java' Denial of Service Vulnerability
8998| [96228] Apache Brooklyn Cross Site Request Forgery and Multiple Cross Site Scripting Vulnerabilities
8999| [95998] Apache Ranger CVE-2016-8746 Security Bypass Vulnerability
9000| [95929] Apache Groovy CVE-2016-6497 Information Disclosure Vulnerability
9001| [95838] Apache Cordova For Android CVE-2017-3160 Man in the Middle Security Bypass Vulnerability
9002| [95675] Apache Struts Remote Code Execution Vulnerability
9003| [95621] Apache NiFi CVE-2106-8748 Cross Site Scripting Vulnerability
9004| [95429] Apache Groovy CVE-2016-6814 Remote Code Execution Vulnerability
9005| [95335] Apache Hadoop CVE-2016-3086 Information Disclosure Vulnerability
9006| [95168] Apache Wicket CVE-2016-6793 Denial of Service Vulnerability
9007| [95136] Apache Qpid Broker for Java CVE-2016-8741 Remote Information Disclosure Vulnerability
9008| [95078] Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
9009| [95077] Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
9010| [95076] Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
9011| [95020] Apache Tika CVE-2015-3271 Remote Information Disclosure Vulnerability
9012| [94950] Apache Hadoop CVE-2016-5001 Local Information Disclosure Vulnerability
9013| [94882] Apache ActiveMQ CVE-2016-6810 HTML Injection Vulnerability
9014| [94828] Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
9015| [94766] Apache CouchDB CVE-2016-8742 Local Privilege Escalation Vulnerability
9016| [94657] Apache Struts CVE-2016-8738 Denial of Service Vulnerability
9017| [94650] Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
9018| [94588] Apache Subversion CVE-2016-8734 XML External Entity Denial of Service Vulnerability
9019| [94513] Apache Karaf CVE-2016-8648 Remote Code Execution Vulnerability
9020| [94463] Apache Tomcat CVE-2016-8735 Remote Code Execution Vulnerability
9021| [94462] Apache Tomcat CVE-2016-6817 Denial of Service Vulnerability
9022| [94461] Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
9023| [94418] Apache OpenOffice CVE-2016-6803 Local Privilege Escalation Vulnerability
9024| [94247] Apache Tika CVE-2016-6809 Remote Code Execution Vulnerability
9025| [94221] Apache Ranger CVE-2016-6815 Local Privilege Escalation Vulnerability
9026| [94145] Apache OpenMeetings CVE-2016-8736 Remote Code Execution Vulnerability
9027| [93945] Apache CloudStack CVE-2016-6813 Authorization Bypass Vulnerability
9028| [93944] Apache Tomcat Security Manager CVE-2016-6796 Security Bypass Vulnerability
9029| [93943] Apache Tomcat CVE-2016-6794 Security Bypass Vulnerability
9030| [93942] Apache Tomcat Security Manager CVE-2016-5018 Security Bypass Vulnerability
9031| [93940] Apache Tomcat CVE-2016-6797 Security Bypass Vulnerability
9032| [93939] Apache Tomcat CVE-2016-0762 Information Disclosure Vulnerability
9033| [93774] Apache OpenOffice CVE-2016-6804 DLL Loading Remote Code Execution Vulnerability
9034| [93773] Apache Struts CVE-2016-6795 Directory Traversal Vulnerability
9035| [93478] Apache Tomcat CVE-2016-6325 Local Privilege Escalation Vulnerability
9036| [93472] Apache Tomcat CVE-2016-5425 Insecure File Permissions Vulnerability
9037| [93429] Apache Tomcat JK Connector CVE-2016-6808 Remote Buffer Overflow Vulnerability
9038| [93263] Apache Tomcat CVE-2016-1240 Local Privilege Escalation Vulnerability
9039| [93236] Apache MyFaces Trinidad CVE-2016-5019 Remote Code Execution Vulnerability
9040| [93142] Apache ActiveMQ Artemis CVE-2016-4978 Remote Code Execution Vulnerability
9041| [93132] Apache Derby CVE-2015-1832 XML External Entity Information Disclosure Vulnerability
9042| [93044] Apache Zookeeper CVE-2016-5017 Buffer Overflow Vulnerability
9043| [92966] Apache Jackrabbit CVE-2016-6801 Cross-Site Request Forgery Vulnerability
9044| [92947] Apache Shiro CVE-2016-6802 Remote Security Bypass Vulnerability
9045| [92905] Apache CXF Fediz CVE-2016-4464 Security Bypass Vulnerability
9046| [92577] Apache Ranger CVE-2016-5395 HTML Injection Vulnerability
9047| [92331] Apache HTTP Server CVE-2016-1546 Remote Denial of Service Vulnerability
9048| [92328] Apache Hive CVE-2016-0760 Multiple Remote Code Execution Vulnerabilities
9049| [92320] Apache APR-util and httpd CVE-2016-6312 Denial of Service Vulnerability
9050| [92100] Apache POI CVE-2016-5000 XML External Entity Injection Vulnerability
9051| [92079] Apache OpenOffice CVE-2016-1513 Remote Code Execution Vulnerability
9052| [91818] Apache Tomcat CVE-2016-5388 Security Bypass Vulnerability
9053| [91816] Apache HTTP Server CVE-2016-5387 Security Bypass Vulnerability
9054| [91788] Apache Qpid Proton CVE-2016-4467 Certificate Verification Security Bypass Vulnerability
9055| [91738] Apache XML-RPC CVE-2016-5003 Remote Code Execution Vulnerability
9056| [91736] Apache XML-RPC Multiple Security Vulnerabilities
9057| [91707] Apache Archiva CVE-2016-5005 HTML Injection Vulnerability
9058| [91703] Apache Archiva CVE-2016-4469 Multiple Cross-Site Request Forgery Vulnerabilities
9059| [91566] Apache HTTP Server CVE-2016-4979 Authentication Bypass Vulnerability
9060| [91537] Apache QPID CVE-2016-4974 Deserialization Security Bypass Vulnerability
9061| [91501] Apache Xerces-C CVE-2016-4463 Stack Buffer Overflow Vulnerability
9062| [91453] Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
9063| [91284] Apache Struts CVE-2016-4431 Security Bypass Vulnerability
9064| [91282] Apache Struts CVE-2016-4433 Security Bypass Vulnerability
9065| [91281] Apache Struts CVE-2016-4430 Cross-Site Request Forgery Vulnerability
9066| [91280] Apache Struts CVE-2016-4436 Security Bypass Vulnerability
9067| [91278] Apache Struts CVE-2016-4465 Denial of Service Vulnerability
9068| [91277] Apache Struts Incomplete Fix Remote Code Execution Vulnerability
9069| [91275] Apache Struts CVE-2016-4438 Remote Code Execution Vulnerability
9070| [91217] Apache Continuum 'saveInstallation.action' Command Execution Vulnerability
9071| [91141] Apache CloudStack CVE-2016-3085 Authentication Bypass Vulnerability
9072| [91068] Apache Struts CVE-2016-1181 Remote Code Execution Vulnerability
9073| [91067] Apache Struts CVE-2016-1182 Security Bypass Vulnerability
9074| [91024] Apache Shiro CVE-2016-4437 Information Disclosure Vulnerability
9075| [90988] Apache Ranger CVE-2016-2174 SQL Injection Vulnerability
9076| [90961] Apache Struts CVE-2016-3093 Denial of Service Vulnerability
9077| [90960] Apache Struts CVE-2016-3087 Remote Code Execution Vulnerability
9078| [90921] Apache Qpid CVE-2016-4432 Authentication Bypass Vulnerability
9079| [90920] Apache Qpid CVE-2016-3094 Denial of Service Vulnerability
9080| [90902] Apache PDFBox CVE-2016-2175 XML External Entity Injection Vulnerability
9081| [90897] Apache Tika CVE-2016-4434 XML External Entity Injection Vulnerability
9082| [90827] Apache ActiveMQ CVE-2016-3088 Multiple Arbitrary File Upload Vulnerabilities
9083| [90755] Apache Ambari CVE-2016-0707 Multiple Local Information Disclosure Vulnerabilities
9084| [90482] Apache CVE-2004-1387 Local Security Vulnerability
9085| [89762] Apache CVE-2001-1556 Remote Security Vulnerability
9086| [89417] Apache Subversion CVE-2016-2167 Authentication Bypass Vulnerability
9087| [89326] RETIRED: Apache Subversion CVE-2016-2167 Security Bypass Vulnerability
9088| [89320] Apache Subversion CVE-2016-2168 Remote Denial of Service Vulnerability
9089| [88826] Apache Struts CVE-2016-3082 Remote Code Execution Vulnerability
9090| [88797] Apache Cordova For iOS CVE-2015-5208 Arbitrary Code Execution Vulnerability
9091| [88764] Apache Cordova iOS CVE-2015-5207 Multiple Security Bypass Vulnerabilities
9092| [88701] Apache CVE-2001-1449 Remote Security Vulnerability
9093| [88635] Apache CVE-2000-1204 Remote Security Vulnerability
9094| [88590] Apache WWW server CVE-1999-1199 Denial-Of-Service Vulnerability
9095| [88496] Apache CVE-2000-1206 Remote Security Vulnerability
9096| [87828] Apache CVE-1999-1237 Remote Security Vulnerability
9097| [87784] Apache CVE-1999-1293 Denial-Of-Service Vulnerability
9098| [87327] Apache Struts CVE-2016-3081 Remote Code Execution Vulnerability
9099| [86622] Apache Stats CVE-2007-0975 Remote Security Vulnerability
9100| [86399] Apache CVE-2007-1743 Local Security Vulnerability
9101| [86397] Apache CVE-2007-1742 Local Security Vulnerability
9102| [86311] Apache Struts CVE-2016-4003 Cross Site Scripting Vulnerability
9103| [86174] Apache Wicket CVE-2015-5347 Cross Site Scripting Vulnerability
9104| [85971] Apache OFBiz CVE-2016-2170 Java Deserialization Remote Code Execution Vulnerability
9105| [85967] Apache OFBiz CVE-2015-3268 HTML Injection Vulnerability
9106| [85759] Apache Jetspeed CVE-2016-2171 Unauthorized Access Vulnerability
9107| [85758] Apache Jetspeed CVE-2016-0712 Cross Site Scripting Vulnerability
9108| [85756] Apache Jetspeed CVE-2016-0710 Multiple SQL Injection Vulnerabilities
9109| [85755] Apache Jetspeed CVE-2016-0711 Mulitple HTML Injection Vulnerabilities
9110| [85754] Apache Jetspeed CVE-2016-0709 Directory Traversal Vulnerability
9111| [85730] Apache Subversion CVE-2015-5343 Integer Overflow Vulnerability
9112| [85691] Apache Ranger CVE-2016-0735 Security Bypass Vulnerability
9113| [85578] Apache ActiveMQ CVE-2010-1244 Cross-Site Request Forgery Vulnerability
9114| [85554] Apache OpenMeetings CVE-2016-2164 Multiple Information Disclosure Vulnerabilities
9115| [85553] Apache OpenMeetings CVE-2016-0783 Information Disclosure Vulnerability
9116| [85552] Apache OpenMeetings CVE-2016-2163 HTML Injection Vulnerability
9117| [85550] Apache OpenMeetings CVE-2016-0784 Directory Traversal Vulnerability
9118| [85386] Apache Hadoop CVE-2015-7430 Local Privilege Escalation Vulnerability
9119| [85377] Apache Qpid Proton Python API CVE-2016-2166 Man in the Middle Security Bypass Vulnerability
9120| [85205] Apache Solr CVE-2015-8796 Cross Site Scripting Vulnerability
9121| [85203] Apache Solr CVE-2015-8795 Mulitple HTML Injection Vulnerabilities
9122| [85163] Apache Geronimo CVE-2008-0732 Local Security Vulnerability
9123| [85131] Apache Struts 'TextParseUtil.translateVariables()' Method Remote Code Execution Vulnerability
9124| [85070] Apache Struts CVE-2016-2162 Cross Site Scripting Vulnerability
9125| [85066] Apache Struts CVE-2016-0785 Remote Code Execution Vulnerability
9126| [84422] Apache TomEE CVE-2016-0779 Unspecified Security Vulnerability
9127| [84321] Apache ActiveMQ CVE-2016-0734 Clickjacking Vulnerability
9128| [84316] Apache ActiveMQ CVE-2016-0782 Multiple Cross Site Scripting Vulnerabilities
9129| [83910] Apache Wicket CVE-2015-7520 Cross Site Scripting Vulnerability
9130| [83423] Apache Xerces-C CVE-2016-0729 Buffer Overflow Vulnerability
9131| [83330] Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability
9132| [83329] Apache Tomcat CVE-2015-5174 Directory Traversal Vulnerability
9133| [83328] Apache Tomcat CVE-2015-5345 Directory Traversal Vulnerability
9134| [83327] Apache Tomcat Security Manager CVE-2016-0714 Remote Code Execution Vulnerability
9135| [83326] Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
9136| [83324] Apache Tomcat Security Manager CVE-2016-0706 Information Disclosure Vulnerability
9137| [83323] Apache Tomcat CVE-2015-5346 Session Fixation Vulnerability
9138| [83259] Apache Hadoop CVE-2015-1776 Information Disclosure Vulnerability
9139| [83243] Apache Solr CVE-2015-8797 Cross Site Scripting Vulnerability
9140| [83119] Apache Sling CVE-2016-0956 Information Disclosure Vulnerability
9141| [83002] Apache CVE-2000-1205 Cross-Site Scripting Vulnerability
9142| [82871] Apache Ranger Authentication Bypass and Security Bypass Vulnerabilities
9143| [82800] Apache CloudStack CVE-2015-3251 Information Disclosure Vulnerability
9144| [82798] Apache CloudStack CVE-2015-3252 Authentication Bypass Vulnerability
9145| [82732] Apache Gallery CVE-2003-0771 Local Security Vulnerability
9146| [82676] Apache CVE-2003-1581 Cross-Site Scripting Vulnerability
9147| [82550] Apache Struts CVE-2015-5209 Security Bypass Vulnerability
9148| [82300] Apache Subversion CVE-2015-5259 Integer Overflow Vulnerability
9149| [82260] Apache Camel CVE-2015-5344 Remote Code Execution Vulnerability
9150| [82234] Apache Hive CVE-2015-7521 Security Bypass Vulnerability
9151| [82082] Apache CVE-1999-0289 Remote Security Vulnerability
9152| [81821] Apache Distribution for Solaris CVE-2007-2080 SQL-Injection Vulnerability
9153| [80696] Apache Camel CVE-2015-5348 Information Disclosure Vulnerability
9154| [80525] Apache CVE-2003-1580 Remote Security Vulnerability
9155| [80354] Drupal Apache Solr Search Module Access Bypass Vulnerability
9156| [80193] Apache CVE-1999-0107 Denial-Of-Service Vulnerability
9157| [79812] Apache Directory Studio CVE-2015-5349 Command Injection Vulnerability
9158| [79744] Apache HBase CVE-2015-1836 Unauthorized Access Vulnerability
9159| [79204] Apache TomEE 'EjbObjectInputStream' Remote Code Execution Vulnerability
9160| [77679] Apache Cordova For Android CVE-2015-8320 Weak Randomization Security Bypass Vulnerability
9161| [77677] Apache Cordova For Android CVE-2015-5256 Security Bypass Vulnerability
9162| [77591] Apache CXF SAML SSO Processing CVE-2015-5253 Security Bypass Vulnerability
9163| [77521] Apache Commons Collections 'InvokerTransformer.java' Remote Code Execution Vulnerability
9164| [77110] Apache HttpComponents HttpClient CVE-2015-5262 Denial of Service Vulnerability
9165| [77086] Apache Ambari CVE-2015-1775 Server Side Request Forgery Security Bypass Vulnerability
9166| [77085] Apache Ambari CVE-2015-3270 Remote Privilege Escalation Vulnerability
9167| [77082] Apache Ambari 'targetURI' Parameter Open Redirection Vulnerability
9168| [77059] Apache Ambari CVE-2015-3186 Cross Site Scripting Vulnerability
9169| [76933] Apache James Server Unspecified Command Execution Vulnerability
9170| [76832] Apache cordova-plugin-file-transfer CVE-2015-5204 HTTP Header Injection Vulnerability
9171| [76625] Apache Struts CVE-2015-5169 Cross Site Scripting Vulnerability
9172| [76624] Apache Struts CVE-2015-2992 Cross Site Scripting Vulnerability
9173| [76522] Apache Tapestry CVE-2014-1972 Security Bypass Vulnerability
9174| [76486] Apache CXF Fediz CVE-2015-5175 Denial of Service Vulnerability
9175| [76452] Apache ActiveMQ CVE-2015-1830 Directory Traversal Vulnerability
9176| [76446] Apache Subversion 'libsvn_fs_fs/tree.c' Denial of Service Vulnerability
9177| [76274] Apache Subversion CVE-2015-3184 Information Disclosure Vulnerability
9178| [76273] Apache Subversion CVE-2015-3187 Information Disclosure Vulnerability
9179| [76272] Apache ActiveMQ CVE-2014-3576 Denial of Service Vulnerability
9180| [76221] Apache Ranger CVE-2015-0266 Access Bypass Vulnerability
9181| [76208] Apache Ranger CVE-2015-0265 JavaScript Code Injection Vulnerability
9182| [76025] Apache ActiveMQ Artemis CVE-2015-3208 XML External Entity Information Disclosure Vulnerability
9183| [75965] Apache HTTP Server CVE-2015-3185 Security Bypass Vulnerability
9184| [75964] Apache HTTP Server CVE-2015-0253 Remote Denial of Service Vulnerability
9185| [75963] Apache HTTP Server CVE-2015-3183 Security Vulnerability
9186| [75940] Apache Struts CVE-2015-1831 Security Bypass Vulnerability
9187| [75919] Apache Groovy CVE-2015-3253 Remote Code Execution Vulnerability
9188| [75338] Apache Storm CVE-2015-3188 Remote Code Execution Vulnerability
9189| [75275] Drupal Apache Solr Real-Time Module Access Bypass Vulnerability
9190| [74866] Apache Cordova For Android CVE-2015-1835 Security Bypass Vulnerability
9191| [74839] Apache Sling API and Sling Servlets CVE-2015-2944 Cross Site Scripting Vulnerability
9192| [74761] Apache Jackrabbit CVE-2015-1833 XML External Entity Information Disclosure Vulnerability
9193| [74686] Apache Ambari '/var/lib/ambari-server/ambari-env.sh' Local Privilege Escalation Vulnerability
9194| [74665] Apache Tomcat CVE-2014-7810 Security Bypass Vulnerability
9195| [74475] Apache Tomcat CVE-2014-0230 Denial of Service Vulnerability
9196| [74423] Apache Struts CVE-2015-0899 Security Bypass Vulnerability
9197| [74338] Apache OpenOffice HWP Filter Memory Corruption Vulnerability
9198| [74265] Apache Tomcat 'mod_jk' CVE-2014-8111 Information Disclosure Vulnerability
9199| [74260] Apache Subversion CVE-2015-0248 Multiple Denial of Service Vulnerabilities
9200| [74259] Apache Subversion 'deadprops.c' Security Bypass Vulnerability
9201| [74204] PHP 'sapi/apache2handler/sapi_apache2.c' Remote Code Execution Vulnerability
9202| [74158] Apache HTTP Server 'protocol.c' Remote Denial of Service Vulnerability
9203| [73954] Apache Flex 'asdoc/templates/index.html' Cross Site Scripting Vulnerability
9204| [73851] Apache2 CVE-2012-0216 Cross-Site Scripting Vulnerability
9205| [73478] Apache Cassandra CVE-2015-0225 Remote Code Execution Vulnerability
9206| [73041] Apache HTTP Server 'mod_lua' Module Denial of Service Vulnerability
9207| [73040] Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
9208| [72809] Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
9209| [72717] Apache Tomcat CVE-2014-0227 Chunk Request Remote Denial Of Service Vulnerability
9210| [72557] Apache WSS4J CVE-2015-0227 Security Bypass Vulnerability
9211| [72553] Apache WSS4J CVE-2015-0226 Information Disclosure Vulnerability
9212| [72513] Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
9213| [72511] Apache ActiveMQ CVE-2014-8110 Multiple Cross Site Scripting Vulnerabilities
9214| [72510] Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
9215| [72508] Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
9216| [72319] Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
9217| [72317] Apache Qpid CVE-2015-0224 Incomplete Fix Multiple Denial of Service Vulnerabilities
9218| [72115] Apache Santuario 'XML Signature Verification' Security Bypass Vulnerability
9219| [72053] Apache HTTP Server 'mod_remoteip.c' IP Address Spoofing Vulnerability
9220| [72030] Apache Qpid CVE-2015-0203 Multiple Denial of Service Vulnerabilities
9221| [71879] Apache Traffic Server 'HttpTransact.cc' Denial of Service Vulnerability
9222| [71726] Apache Subversion CVE-2014-3580 Remote Denial of Service Vulnerability
9223| [71725] Apache Subversion CVE-2014-8108 Remote Denial of Service Vulnerability
9224| [71657] Apache HTTP Server 'mod_proxy_fcgi' Module Denial of Service Vulnerability
9225| [71656] Apache HTTP Server 'mod_cache' Module Denial of Service Vulnerability
9226| [71548] Apache Struts CVE-2014-7809 Security Bypass Vulnerability
9227| [71466] Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
9228| [71353] Apache HTTP Server 'LuaAuthzProvider' Authorization Bypass Vulnerability
9229| [71004] Apache Qpid CVE-2014-3629 XML External Entity Injection Vulnerability
9230| [70970] Apache Traffic Server Cross Site Scripting Vulnerability
9231| [70738] Apache CXF CVE-2014-3584 Denial of Service Vulnerability
9232| [70736] Apache CXF SAML SubjectConfirmation Security Bypass Vulnerability
9233| [69728] Apache Tomcat CVE-2013-4444 Arbitrary File Upload Vulnerability
9234| [69648] Apache POI CVE-2014-3574 Denial Of Service Vulnerability
9235| [69647] Apache POI OpenXML parser CVE-2014-3529 XML External Entity Information Disclosure Vulnerability
9236| [69351] Apache OpenOffice Calc CVE-2014-3524 Command Injection Vulnerability
9237| [69295] Apache Axis Incomplete Fix CVE-2014-3596 SSL Certificate Validation Security Bypass Vulnerability
9238| [69286] Apache OFBiz CVE-2014-0232 Multiple Cross Site Scripting Vulnerabilities
9239| [69258] Apache HttpComponents Incomplete Fix CVE-2014-3577 SSL Validation Security Bypass Vulnerability
9240| [69257] Apache HttpComponents Incomplete Fix SSL Certificate Validation Security Bypass Vulnerability
9241| [69248] Apache HTTP Server CVE-2013-4352 Remote Denial of Service Vulnerability
9242| [69237] Apache Subversion CVE-2014-3522 SSL Certificate Validation Information Disclosure Vulnerability
9243| [69173] Apache Traffic Server CVE-2014-3525 Unspecified Security Vulnerability
9244| [69046] Apache Cordova For Android CVE-2014-3502 Information Disclosure Vulnerability
9245| [69041] Apache Cordova For Android CVE-2014-3501 Security Bypass Vulnerability
9246| [69038] Apache Cordova For Android CVE-2014-3500 Security Bypass Vulnerability
9247| [68995] Apache Subversion CVE-2014-3528 Insecure Authentication Weakness
9248| [68966] Apache Subversion 'irkerbridge.py' Local Privilege Escalation Vulnerability
9249| [68965] Apache Subversion 'svnwcsub.py' Local Privilege Escalation Vulnerability
9250| [68863] Apache HTTP Server 'mod_cache' Module Remote Denial of Service Vulnerability
9251| [68747] Apache HTTP Server CVE-2014-3523 Remote Denial of Service Vulnerability
9252| [68745] Apache HTTP Server CVE-2014-0118 Remote Denial of Service Vulnerability
9253| [68742] Apache HTTP Server CVE-2014-0231 Remote Denial of Service Vulnerability
9254| [68740] Apache HTTP Server CVE-2014-0117 Remote Denial of Service Vulnerability
9255| [68678] Apache HTTP Server 'mod_status' CVE-2014-0226 Remote Code Execution Vulnerability
9256| [68445] Apache CXF UsernameToken Information Disclosure Vulnerability
9257| [68441] Apache CXF SAML Tokens Validation Security Bypass Vulnerability
9258| [68431] Apache Syncope CVE-2014-3503 Insecure Password Generation Weakness
9259| [68229] Apache Harmony PRNG Entropy Weakness
9260| [68111] Apache 'mod_wsgi' Module Privilege Escalation Vulnerability
9261| [68072] Apache Tomcat CVE-2014-0186 Remote Denial of Service Vulnerability
9262| [68039] Apache Hive CVE-2014-0228 Security Bypass Vulnerability
9263| [67673] Apache Tomcat CVE-2014-0095 AJP Request Remote Denial Of Service Vulnerability
9264| [67671] Apache Tomcat CVE-2014-0075 Chunk Request Remote Denial Of Service Vulnerability
9265| [67669] Apache Tomcat CVE-2014-0119 XML External Entity Information Disclosure Vulnerability
9266| [67668] Apache Tomcat CVE-2014-0099 Request Processing Information Disclosure Vulnerability
9267| [67667] Apache Tomcat CVE-2014-0096 XML External Entity Information Disclosure Vulnerability
9268| [67534] Apache 'mod_wsgi' Module CVE-2014-0242 Information Disclosure Vulnerability
9269| [67532] Apache 'mod_wsgi' Module Local Privilege Escalation Vulnerability
9270| [67530] Apache Solr Search Template Cross Site Scripting Vulnerability
9271| [67236] Apache CXF CVE-2014-0109 Remote Denial of Service Vulnerability
9272| [67232] Apache CXF CVE-2014-0110 Denial of Service Vulnerability
9273| [67121] Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
9274| [67081] Apache Struts 'getClass()' Method Security Bypass Vulnerability
9275| [67064] Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
9276| [67013] Apache Zookeeper CVE-2014-0085 Local Information Disclosure Vulnerability
9277| [66998] Apache Archiva CVE-2013-2187 Unspecified Cross Site Scripting Vulnerability
9278| [66991] Apache Archiva CVE-2013-2187 HTML Injection Vulnerability
9279| [66927] Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
9280| [66474] Apache CouchDB Universally Unique IDentifier (UUID) Remote Denial of Service Vulnerability
9281| [66397] Apache Xalan-Java Library CVE-2014-0107 Security Bypass Vulnerability
9282| [66303] Apache HTTP Server Multiple Denial of Service Vulnerabilities
9283| [66041] RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
9284| [65999] Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability
9285| [65967] Apache Cordova File-Transfer Unspecified Security Vulnerability
9286| [65959] Apache Cordova InAppBrowser Remote Privilege Escalation Vulnerability
9287| [65935] Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
9288| [65902] Apache Camel CVE-2014-0003 Remote Code Execution Vulnerability
9289| [65901] Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
9290| [65773] Apache Tomcat CVE-2013-4286 Security Bypass Vulnerability
9291| [65769] Apache Tomcat CVE-2014-0033 Session Fixation Vulnerability
9292| [65768] Apache Tomcat CVE-2013-4590 XML External Entity Information Disclosure Vulnerability
9293| [65767] Apache Tomcat CVE-2013-4322 Incomplete Fix Denial of Service Vulnerability
9294| [65615] Apache ActiveMQ 'refresh' Parameter Cross Site Scripting Vulnerability
9295| [65434] Apache Subversion 'mod_dav_svn' Module SVNListParentPath Denial of Service Vulnerability
9296| [65431] Apache Wicket CVE-2013-2055 Information Disclosure Vulnerability
9297| [65400] Apache Commons FileUpload CVE-2014-0050 Denial Of Service Vulnerability
9298| [64782] Apache CloudStack Virtual Router Component Security Bypass Vulnerability
9299| [64780] Apache CloudStack Unauthorized Access Vulnerability
9300| [64617] Apache Libcloud Digital Ocean API Local Information Disclosure Vulnerability
9301| [64437] Apache Santuario XML Security For JAVA XML Signature Denial of Service Vulnerability
9302| [64427] Apache Solr Multiple XML External Entity Injection Vulnerabilities
9303| [64009] Apache Solr CVE-2013-6408 XML External Entity Injection Vulnerability
9304| [64008] Apache Solr CVE-2013-6407 XML External Entity Injection Vulnerability
9305| [63981] Apache Subversion 'mod_dav_svn' Module Denial of Service Vulnerability
9306| [63966] Apache Subversion CVE-2013-4505 Security Bypass Vulnerability
9307| [63963] Apache Roller CVE-2013-4171 Cross Site Scripting Vulnerability
9308| [63935] Apache Solr 'SolrResourceLoader' Directory Traversal Vulnerability
9309| [63928] Apache Roller CVE-2013-4212 OGNL Expression Injection Remote Code Execution Vulnerability
9310| [63515] Apache Tomcat Manager Component CVE-2013-6357 Cross Site Request Forgery Vulnerability
9311| [63403] Apache Struts Multiple Cross Site Scripting Vulnerabilities
9312| [63400] Apache 'mod_pagespeed' Module Unspecified Cross Site Scripting Vulnerability
9313| [63260] Apache Shindig CVE-2013-4295 XML External Entity Information Disclosure Vulnerability
9314| [63241] Apache Sling 'AbstractAuthenticationFormServlet' Open Redirection Vulnerability
9315| [63174] Apache Commons FileUpload 'DiskFileItem' Class Null Byte Arbitrary File Write Vulnerability
9316| [62939] Apache 'mod_fcgid' Module CVE-2013-4365 Heap Buffer Overflow Vulnerability
9317| [62903] Apache Sling 'deepGetOrCreateNode()' Function Denial Of Service Vulnerability
9318| [62706] Apache Camel CVE-2013-4330 Information Disclosure Vulnerability
9319| [62677] Apache 'mod_accounting' Module CVE-2013-5697 SQL Injection Vulnerability
9320| [62674] TYPO3 Apache Solr Unspecified Cross Site Scripting and PHP Code Execution Vulnerabilities
9321| [62587] Apache Struts CVE-2013-4316 Remote Code Execution Vulnerability
9322| [62584] Apache Struts CVE-2013-4310 Security Bypass Vulnerability
9323| [62266] Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
9324| [61984] Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
9325| [61981] Apache HBase RPC Authentication Man In The Middle Security Bypass Vulnerability
9326| [61638] Apache CloudStack CVE-2013-2136 Multiple Cross Site Scripting Vulnerabilities
9327| [61454] Apache Subversion CVE-2013-4131 Denial Of Service Vulnerability
9328| [61379] Apache HTTP Server CVE-2013-2249 Unspecified Remote Security Vulnerability
9329| [61370] Apache OFBiz CVE-2013-2317 'View Log' Cross Site Scripting Vulnerability
9330| [61369] Apache OFBiz Nested Expression Remote Code Execution Vulnerability
9331| [61196] Apache Struts CVE-2013-2248 Multiple Open Redirection Vulnerabilities
9332| [61189] Apache Struts CVE-2013-2251 Multiple Remote Command Execution Vulnerabilities
9333| [61129] Apache HTTP Server CVE-2013-1896 Remote Denial of Service Vulnerability
9334| [61030] Apache CXF CVE-2013-2160 Multiple Remote Denial of Service Vulnerabilities
9335| [60875] Apache Geronimo RMI Classloader Security Bypass Vulnerability
9336| [60846] Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
9337| [60817] Apache Santuario XML Security for C++ CVE-2013-2210 Heap Buffer Overflow Vulnerability
9338| [60800] Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
9339| [60599] Apache Santuario XML Security for C++ CVE-2013-2156 Remote Heap Buffer Overflow Vulnerability
9340| [60595] Apache Santuario XML Security for C++ XML Signature CVE-2013-2155 Denial of Service Vulnerability
9341| [60594] Apache Santuario XML Security for C++ CVE-2013-2154 Stack Buffer Overflow Vulnerability
9342| [60592] Apache Santuario XML Security for C++ XML Signature CVE-2013-2153 Security Bypass Vulnerability
9343| [60534] Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
9344| [60346] Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
9345| [60345] Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
9346| [60267] Apache Subversion CVE-2013-1968 Remote Denial of Service Vulnerability
9347| [60265] Apache Subversion CVE-2013-2088 Command Injection Vulnerability
9348| [60264] Apache Subversion CVE-2013-2112 Remote Denial of Service Vulnerability
9349| [60187] Apache Tomcat DIGEST Authentication CVE-2013-2051 Incomplete Fix Security Weakness
9350| [60186] Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
9351| [60167] Apache Struts 'includeParams' CVE-2013-2115 Incomplete Fix Security Bypass Vulnerability
9352| [60166] Apache Struts 'includeParams' CVE-2013-1966 Security Bypass Vulnerability
9353| [60082] Apache Struts 'ParameterInterceptor' Class OGNL CVE-2013-1965 Security Bypass Vulnerability
9354| [59826] Apache HTTP Server Terminal Escape Sequence in Logs Command Injection Vulnerability
9355| [59799] Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
9356| [59798] Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
9357| [59797] Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
9358| [59670] Apache VCL Multiple Input Validation Vulnerabilities
9359| [59464] Apache CloudStack CVE-2013-2758 Hash Information Disclosure Vulnerability
9360| [59463] Apache CloudStack CVE-2013-2756 Authentication Bypass Vulnerability
9361| [59402] Apache ActiveMQ CVE-2013-3060 Information Disclosure and Denial of Service Vulnerability
9362| [59401] Apache ActiveMQ CVE-2012-6551 Denial of Service Vulnerability
9363| [59400] Apache ActiveMQ CVE-2012-6092 Multiple Cross Site Scripting Vulnerabilities
9364| [58898] Apache Subversion CVE-2013-1884 Remote Denial of Service Vulnerability
9365| [58897] Apache Subversion 'mod_dav_svn/lock.c' Remote Denial of Service Vulnerability
9366| [58895] Apache Subversion 'mod_dav_svn' Remote Denial of Service Vulnerability
9367| [58455] Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
9368| [58379] Apache Qpid CVE-2012-4446 Authentication Bypass Vulnerability
9369| [58378] Apache Qpid CVE-2012-4460 Denial of Service Vulnerability
9370| [58376] Apache Qpid CVE-2012-4458 Denial of Service Vulnerability
9371| [58337] Apache Qpid CVE-2012-4459 Denial of Service Vulnerability
9372| [58326] Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
9373| [58325] Debian Apache HTTP Server CVE-2013-1048 Symlink Attack Local Privilege Escalation Vulnerability
9374| [58323] Apache Subversion 'svn_fs_file_length()' Remote Denial of Service Vulnerability
9375| [58165] Apache HTTP Server Multiple Cross Site Scripting Vulnerabilities
9376| [58136] Apache Maven CVE-2013-0253 SSL Certificate Validation Security Bypass Vulnerability
9377| [58124] Apache Tomcat 'log/logdir' Directory Insecure File Permissions Vulnerability
9378| [58073] Apache Commons HttpClient CVE-2012-5783 SSL Certificate Validation Security Bypass Vulnerability
9379| [57876] Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
9380| [57874] Apache CXF CVE-2012-5633 Security Bypass Vulnerability
9381| [57463] Apache OFBiz CVE-2013-0177 Multiple Cross Site Scripting Vulnerabilities
9382| [57425] Apache CXF CVE-2012-5786 SSL Certificate Validation Security Bypass Vulnerability
9383| [57321] Apache CouchDB CVE-2012-5650 Cross Site Scripting Vulnerability
9384| [57314] Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
9385| [57267] Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
9386| [57259] Apache CloudStack CVE-2012-5616 Local Information Disclosure Vulnerability
9387| [56814] Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
9388| [56813] Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
9389| [56812] Apache Tomcat CVE-2012-3546 Security Bypass Vulnerability
9390| [56753] Apache Apache HTTP Server 'mod_proxy_ajp Module Denial Of Service Vulnerability
9391| [56686] Apache Tomcat CVE-2012-5568 Denial of Service Vulnerability
9392| [56408] Apache Axis and Axis2/Java SSL Certificate Validation Security Bypass Vulnerability
9393| [56403] Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
9394| [56402] Apache Tomcat CVE-2012-2733 Denial of Service Vulnerability
9395| [56171] Apache OFBiz CVE-2012-3506 Unspecified Security Vulnerability
9396| [55876] Apache CloudStack CVE-2012-4501 Security Bypass Vulnerability
9397| [55628] Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
9398| [55608] Apache Qpid (qpidd) Denial of Service Vulnerability
9399| [55536] Apache 'mod_pagespeed' Module Cross Site Scripting and Security Bypass Vulnerabilities
9400| [55508] Apache Axis2 XML Signature Wrapping Security Vulnerability
9401| [55445] Apache Wicket CVE-2012-3373 Cross Site Scripting Vulnerability
9402| [55346] Apache Struts Cross Site Request Forgery and Denial of Service Vulnerabilities
9403| [55290] Drupal Apache Solr Autocomplete Module Cross Site Scripting Vulnerability
9404| [55165] Apache Struts2 Skill Name Remote Code Execution Vulnerability
9405| [55154] Apache 'mod-rpaf' Module Denial of Service Vulnerability
9406| [55131] Apache HTTP Server HTML-Injection And Information Disclosure Vulnerabilities
9407| [54954] Apache QPID NullAuthenticator Authentication Bypass Vulnerability
9408| [54798] Apache Libcloud Man In The Middle Vulnerability
9409| [54358] Apache Hadoop CVE-2012-3376 Information Disclosure Vulnerability
9410| [54341] Apache Sling CVE-2012-2138 Denial Of Service Vulnerability
9411| [54268] Apache Hadoop Symlink Attack Local Privilege Escalation Vulnerability
9412| [54189] Apache Roller Cross Site Request Forgery Vulnerability
9413| [54187] Apache Roller CVE-2012-2381 Cross Site Scripting Vulnerability
9414| [53880] Apache CXF Child Policies Security Bypass Vulnerability
9415| [53877] Apache CXF Elements Validation Security Bypass Vulnerability
9416| [53676] Apache Commons Compress and Apache Ant CVE-2012-2098 Denial Of Service Vulnerability
9417| [53487] Apache POI CVE-2012-0213 Denial Of Service Vulnerability
9418| [53455] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability
9419| [53305] Apache Qpid CVE-2011-3620 Unauthorized Access Security Bypass Vulnerability
9420| [53046] Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
9421| [53025] Apache OFBiz Unspecified Remote Code Execution Vulnerability
9422| [53023] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
9423| [52939] Apache Hadoop CVE-2012-1574 Unspecified User Impersonation Vulnerability
9424| [52702] Apache Struts2 'XSLTResult.java' Remote Arbitrary File Upload Vulnerability
9425| [52696] Apache Traffic Server HTTP Host Header Handling Heap Based Buffer Overflow Vulnerability
9426| [52680] Apache Wicket 'pageMapName' Parameter Cross Site Scripting Vulnerability
9427| [52679] Apache Wicket Hidden Files Information Disclosure Vulnerability
9428| [52565] Apache 'mod_fcgid' Module Denial Of Service Vulnerability
9429| [52146] TYPO3 Apache Solr Extension Unspecified Cross Site Scripting Vulnerability
9430| [51939] Apache MyFaces 'ln' Parameter Information Disclosure Vulnerability
9431| [51917] Apache APR Hash Collision Denial Of Service Vulnerability
9432| [51902] Apache Struts Multiple HTML Injection Vulnerabilities
9433| [51900] Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
9434| [51886] Apache CXF UsernameToken Policy Validation Security Bypass Vulnerability
9435| [51869] Apache HTTP Server CVE-2011-3639 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
9436| [51706] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
9437| [51705] Apache HTTP Server CVE-2012-0021 mod_log_config Denial Of Service Vulnerability
9438| [51628] Apache Struts 'ParameterInterceptor' Class OGNL (CVE-2011-3923) Security Bypass Vulnerability
9439| [51447] Apache Tomcat Parameter Handling Denial of Service Vulnerability
9440| [51442] Apache Tomcat Request Object Security Bypass Vulnerability
9441| [51407] Apache HTTP Server Scoreboard Local Security Bypass Vulnerability
9442| [51257] Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
9443| [51238] Apache Geronimo Hash Collision Denial Of Service Vulnerability
9444| [51200] Apache Tomcat Hash Collision Denial Of Service Vulnerability
9445| [50940] Apache Struts Session Tampering Security Bypass Vulnerability
9446| [50912] RETIRED: Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
9447| [50904] Apache ActiveMQ Failover Mechanism Remote Denial Of Service Vulnerability
9448| [50848] Apache MyFaces EL Expression Evaluation Security Bypass Vulnerability
9449| [50802] Apache HTTP Server 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
9450| [50639] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
9451| [50603] Apache Tomcat Manager Application Security Bypass Vulnerability
9452| [50494] Apache HTTP Server 'ap_pregsub()' Function Local Privilege Escalation Vulnerability
9453| [49957] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
9454| [49762] Apache Tomcat HTTP DIGEST Authentication Multiple Security Weaknesses
9455| [49728] Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
9456| [49616] Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
9457| [49470] Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
9458| [49353] Apache Tomcat AJP Protocol Security Bypass Vulnerability
9459| [49303] Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability
9460| [49290] Apache Wicket Cross Site Scripting Vulnerability
9461| [49147] Apache Tomcat CVE-2011-2481 Information Disclosure Vulnerability
9462| [49143] Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
9463| [48667] Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability
9464| [48653] Apache 'mod_authnz_external' Module SQL Injection Vulnerability
9465| [48611] Apache XML Security for C++ Signature Key Parsing Denial of Service Vulnerability
9466| [48456] Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability
9467| [48015] Apache Archiva Multiple Cross Site Request Forgery Vulnerabilities
9468| [48011] Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
9469| [47929] Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
9470| [47890] Apache Struts 'javatemplates' Plugin Multiple Cross Site Scripting Vulnerabilities
9471| [47886] Apache Tomcat SecurityConstraints Security Bypass Vulnerability
9472| [47820] Apache APR 'apr_fnmatch()' Denial of Service Vulnerability
9473| [47784] Apache Struts XWork 's:submit' HTML Tag Cross Site Scripting Vulnerability
9474| [47199] Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
9475| [47196] Apache Tomcat Login Constraints Security Bypass Vulnerability
9476| [46974] Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
9477| [46953] Apache MPM-ITK Module Security Weakness
9478| [46734] Subversion 'mod_dav_svn' Apache Server NULL Pointer Dereference Denial Of Service Vulnerability
9479| [46685] Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
9480| [46311] Apache Continuum and Archiva Cross Site Scripting Vulnerability
9481| [46177] Apache Tomcat SecurityManager Security Bypass Vulnerability
9482| [46174] Apache Tomcat HTML Manager Interface HTML Injection Vulnerability
9483| [46166] Apache Tomcat JVM Denial of Service Vulnerability
9484| [46164] Apache Tomcat NIO Connector Denial of Service Vulnerability
9485| [46066] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
9486| [45655] Apache Subversion Server Component Multiple Remote Denial Of Service Vulnerabilities
9487| [45123] Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Vulnerability
9488| [45095] Apache Archiva Cross Site Request Forgery Vulnerability
9489| [45015] Apache Tomcat 'sort' and 'orderBy' Parameters Cross Site Scripting Vulnerabilities
9490| [44900] Apache 'mod_fcgid' Module Unspecified Stack Buffer Overflow Vulnerability
9491| [44616] Apache Shiro Directory Traversal Vulnerability
9492| [44355] Apache MyFaces Encrypted View State Oracle Padding Security Vulnerability
9493| [44068] Apache::AuthenHook Local Information Disclosure Vulnerability
9494| [43862] Apache QPID SSL Connection Denial of Service Vulnerability
9495| [43673] Apache APR-util 'apr_brigade_split_line()' Denial of Service Vulnerability
9496| [43637] Apache XML-RPC SAX Parser Information Disclosure Vulnerability
9497| [43111] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
9498| [42637] Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
9499| [42501] Apache CouchDB Cross Site Request Forgery Vulnerability
9500| [42492] Apache CXF XML DTD Processing Security Vulnerability
9501| [42121] Apache SLMS Insufficient Quoting Cross Site Request Forgery Vulnerability
9502| [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
9503| [41963] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
9504| [41544] Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities
9505| [41076] Apache Axis2 '/axis2/axis2-admin' Session Fixation Vulnerability
9506| [40976] Apache Axis2 Document Type Declaration Processing Security Vulnerability
9507| [40827] Apache 'mod_proxy_http' Timeout Handling Information Disclosure Vulnerability
9508| [40343] Apache Axis2 'xsd' Parameter Directory Traversal Vulnerability
9509| [40327] Apache Axis2 'engagingglobally' Cross-Site Scripting Vulnerability
9510| [39771] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
9511| [39636] Apache ActiveMQ Source Code Information Disclosure Vulnerability
9512| [39635] Apache Tomcat Authentication Header Realm Name Information Disclosure Vulnerability
9513| [39538] Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
9514| [39489] Apache OFBiz Multiple Cross Site Scripting and HTML Injection Vulnerabilities
9515| [39119] Apache ActiveMQ 'createDestination.action' HTML Injection Vulnerability
9516| [38580] Apache Subrequest Handling Information Disclosure Vulnerability
9517| [38494] Apache 'mod_isapi' Memory Corruption Vulnerability
9518| [38491] Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
9519| [37966] Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability
9520| [37945] Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability
9521| [37944] Apache Tomcat WAR File Directory Traversal Vulnerability
9522| [37942] Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability
9523| [37149] Apache Tomcat 404 Error Page Cross Site Scripting Vulnerability
9524| [37027] RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
9525| [36990] Apache HTTP TRACE Cross Site Scripting Vulnerability
9526| [36954] Apache Tomcat Windows Installer Insecure Password Vulnerability
9527| [36889] TYPO3 Apache Solr Search Extension Unspecified Cross Site Scripting Vulnerability
9528| [36596] Apache HTTP Server Solaris Event Port Pollset Support Remote Denial Of Service Vulnerability
9529| [36260] Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
9530| [36254] Apache mod_proxy_ftp Remote Command Injection Vulnerability
9531| [35949] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
9532| [35840] Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
9533| [35623] Apache 'mod_deflate' Remote Denial Of Service Vulnerability
9534| [35565] Apache 'mod_proxy' Remote Denial Of Service Vulnerability
9535| [35416] Apache Tomcat XML Parser Information Disclosure Vulnerability
9536| [35263] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
9537| [35253] Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
9538| [35251] Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
9539| [35221] Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
9540| [35196] Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness
9541| [35193] Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability
9542| [35115] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
9543| [34686] Apache Struts Multiple Cross Site Scripting Vulnerabilities
9544| [34663] Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
9545| [34657] Apache Tiles Cross Site Scripting And Information Disclosure Vulnerabilities
9546| [34562] Apache Geronimo Application Server Multiple Remote Vulnerabilities
9547| [34552] Apache ActiveMQ Web Console Multiple Unspecified HTML Injection Vulnerabilities
9548| [34412] Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability
9549| [34399] Apache Struts Unspecified Cross Site Scripting Vulnerability
9550| [34383] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
9551| [33913] Apache Tomcat POST Data Information Disclosure Vulnerability
9552| [33360] Apache Jackrabbit 'q' Parameter Multiple Cross Site Scripting Vulnerabilities
9553| [33110] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
9554| [32657] Novell NetWare ApacheAdmin Security Bypass Vulnerability
9555| [31805] Apache HTTP Server OS Fingerprinting Unspecified Security Vulnerability
9556| [31761] Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
9557| [31698] Apache Tomcat 'RemoteFilterValve' Security Bypass Vulnerability
9558| [31165] Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
9559| [30560] Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability
9560| [30496] Apache Tomcat 'HttpServletResponse.sendError()' Cross Site Scripting Vulnerability
9561| [30494] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
9562| [29653] Apache 'mod_proxy_http' Interim Response Denial of Service Vulnerability
9563| [29502] Apache Tomcat Host Manager Cross Site Scripting Vulnerability
9564| [28576] Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
9565| [28484] Apache Tomcat Requests Containing MS-DOS Device Names Information Disclosure Vulnerability
9566| [28483] Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
9567| [28482] Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
9568| [28481] Apache Tomcat Cross-Site Scripting Vulnerability
9569| [28477] Apache Tomcat AJP Connector Information Disclosure Vulnerability
9570| [27752] Apache mod_jk2 Host Header Multiple Stack Based Buffer Overflow Vulnerabilities
9571| [27706] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
9572| [27703] Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
9573| [27409] Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
9574| [27365] Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
9575| [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
9576| [27236] Apache 'mod_proxy_balancer' Multiple Vulnerabilities
9577| [27234] Apache 'mod_proxy_ftp' Undefined Charset UTF-7 Cross-Site Scripting Vulnerability
9578| [27006] Apache Tomcat JULI Logging Component Default Security Policy Vulnerability
9579| [26939] Apache HTTP Server Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
9580| [26838] Apache mod_imagemap and mod_imap Cross-Site Scripting Vulnerability
9581| [26762] Apache::AuthCAS Cookie SQL Injection Vulnerability
9582| [26663] Apache HTTP Server 413 Error HTTP Request Method Cross-Site Scripting Weakness
9583| [26287] Apache Geronimo SQLLoginModule Authentication Bypass Vulnerability
9584| [26070] Apache Tomcat WebDav Remote Information Disclosure Vulnerability
9585| [25804] Apache Geronimo Management EJB Security Bypass Vulnerability
9586| [25653] Apache Mod_AutoIndex.C Undefined Charset Cross-Site Scripting Vulnerability
9587| [25531] Apache Tomcat Cal2.JSP Cross-Site Scripting Vulnerability
9588| [25489] Apache HTTP Server Mod_Proxy Denial of Service Vulnerability
9589| [25316] Apache Tomcat Multiple Remote Information Disclosure Vulnerabilities
9590| [25314] Apache Tomcat Host Manager Servlet Cross Site Scripting Vulnerability
9591| [25174] Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
9592| [24999] Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
9593| [24759] MySQLDumper Apache Access Control Authentication Bypass Vulnerability
9594| [24649] Apache HTTP Server Mod_Cache Denial of Service Vulnerability
9595| [24645] Apache HTTP Server Mod_Status Cross-Site Scripting Vulnerability
9596| [24553] Apache Mod_Mem_Cache Information Disclosure Vulnerability
9597| [24524] Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
9598| [24480] Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
9599| [24476] Apache Tomcat JSP Example Web Applications Cross Site Scripting Vulnerability
9600| [24475] Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
9601| [24215] Apache HTTP Server Worker Process Multiple Denial of Service Vulnerabilities
9602| [24147] Apache Tomcat JK Connector Double Encoding Security Bypass Vulnerability
9603| [24058] Apache Tomcat Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
9604| [23687] Apache AXIS Non-Existent WSDL Path Information Disclosure Vulnerability
9605| [23438] Apache HTTPD suEXEC Local Multiple Privilege Escalation Weaknesses
9606| [22960] Apache HTTP Server Tomcat Directory Traversal Vulnerability
9607| [22849] Apache mod_python Output Filter Mode Information Disclosure Vulnerability
9608| [22791] Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability
9609| [22732] Debian Apache Root Shell Local Privilege Escalation Vulnerabilities
9610| [22388] Apache Stats Extract Function Multiple Input Validation Vulnerabilities
9611| [21865] Apache And Microsoft IIS Range Denial of Service Vulnerability
9612| [21214] Apache Mod_Auth_Kerb Off-By-One Denial of Service Vulnerability
9613| [20527] Apache Mod_TCL Remote Format String Vulnerability
9614| [19661] Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
9615| [19447] Apache CGI Script Source Code Information Disclosure Vulnerability
9616| [19204] Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
9617| [19106] Apache Tomcat Information Disclosure Vulnerability
9618| [18138] Apache James SMTP Denial Of Service Vulnerability
9619| [17342] Apache Struts Multiple Remote Vulnerabilities
9620| [17095] Apache Log4Net Denial Of Service Vulnerability
9621| [16916] Apache mod_python FileSession Code Execution Vulnerability
9622| [16710] Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
9623| [16260] Apache Geronimo Multiple Input Validation Vulnerabilities
9624| [16153] Apache mod_auth_pgsql Multiple Format String Vulnerabilities
9625| [16152] Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
9626| [15834] Apache 'mod_imap' Referer Cross-Site Scripting Vulnerability
9627| [15765] Apache James Spooler Memory Leak Denial Of Service Vulnerability
9628| [15762] Apache MPM Worker.C Denial Of Service Vulnerability
9629| [15512] Apache Struts Error Response Cross-Site Scripting Vulnerability
9630| [15413] PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
9631| [15325] Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
9632| [15224] Apache Mod_Auth_Shadow Authentication Bypass Vulnerability
9633| [15177] PHP Apache 2 Local Denial of Service Vulnerability
9634| [14982] ApacheTop Insecure Temporary File Creation Vulnerability
9635| [14721] Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
9636| [14660] Apache CGI Byterange Request Denial of Service Vulnerability
9637| [14366] Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
9638| [14106] Apache HTTP Request Smuggling Vulnerability
9639| [13778] Apache HTPasswd Password Command Line Argument Buffer Overflow Vulnerability
9640| [13777] Apache HTPasswd User Command Line Argument Buffer Overflow Vulnerability
9641| [13756] Apache Tomcat Java Security Manager Bypass Vulnerability
9642| [13537] Apache HTDigest Realm Command Line Argument Buffer Overflow Vulnerability
9643| [12877] Apache mod_ssl ssl_io_filter_cleanup Remote Denial Of Service Vulnerability
9644| [12795] Apache Tomcat Remote Malformed Request Denial Of Service Vulnerability
9645| [12619] Apache Software Foundation Batik Squiggle Browser Access Validation Vulnerability
9646| [12519] Apache mod_python Module Publisher Handler Information Disclosure Vulnerability
9647| [12308] Apache Utilities Insecure Temporary File Creation Vulnerability
9648| [12217] Apache mod_auth_radius Malformed RADIUS Server Reply Integer Overflow Vulnerability
9649| [12181] Mod_DOSEvasive Apache Module Local Insecure Temporary File Creation Vulnerability
9650| [11803] Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
9651| [11471] Apache mod_include Local Buffer Overflow Vulnerability
9652| [11360] Apache mod_ssl SSLCipherSuite Restriction Bypass Vulnerability
9653| [11239] Apache Satisfy Directive Access Control Bypass Vulnerability
9654| [11187] Apache Web Server Remote IPv6 Buffer Overflow Vulnerability
9655| [11185] Apache Mod_DAV LOCK Denial Of Service Vulnerability
9656| [11182] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
9657| [11154] Apache mod_ssl Remote Denial of Service Vulnerability
9658| [11094] Apache mod_ssl Denial Of Service Vulnerability
9659| [10789] Apache mod_userdir Module Information Disclosure Vulnerability
9660| [10736] Apache 'mod_ssl' Log Function Format String Vulnerability
9661| [10619] Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
9662| [10508] Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow Vulnerability
9663| [10478] ClueCentral Apache Suexec Patch Security Weakness
9664| [10355] Apache 'mod_ssl' 'ssl_util_uuencode_binary()' Stack Buffer Overflow Vulnerability
9665| [10212] Apache mod_auth Malformed Password Potential Memory Corruption Vulnerability
9666| [9933] Apache mod_disk_cache Module Client Authentication Credential Storage Weakness
9667| [9930] Apache Error and Access Logs Escape Sequence Injection Vulnerability
9668| [9921] Apache Connection Blocking Denial Of Service Vulnerability
9669| [9885] Apache Mod_Security Module SecFilterScanPost Off-By-One Buffer Overflow Vulnerability
9670| [9874] Apache HTAccess LIMIT Directive Bypass Configuration Error Weakness
9671| [9829] Apache Mod_Access Access Control Rule Bypass Vulnerability
9672| [9826] Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
9673| [9733] Apache Cygwin Directory Traversal Vulnerability
9674| [9599] Apache mod_php Global Variables Information Disclosure Weakness
9675| [9590] Apache-SSL Client Certificate Forging Vulnerability
9676| [9571] Apache mod_digest Client-Supplied Nonce Verification Vulnerability
9677| [9471] Apache mod_perl Module File Descriptor Leakage Vulnerability
9678| [9404] Mod-Auth-Shadow Apache Module Expired User Credential Weakness
9679| [9302] Apache mod_php Module File Descriptor Leakage Vulnerability
9680| [9129] Apache mod_python Module Malformed Query Denial of Service Vulnerability
9681| [8926] Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
9682| [8919] Apache Mod_Security Module Heap Corruption Vulnerability
9683| [8911] Apache Web Server Multiple Module Local Buffer Overflow Vulnerability
9684| [8898] Red Hat Apache Directory Index Default Configuration Error
9685| [8883] Apache Cocoon Directory Traversal Vulnerability
9686| [8824] Apache Tomcat Non-HTTP Request Denial Of Service Vulnerability
9687| [8822] Apache Mod_Throttle Module Local Shared Memory Corruption Vulnerability
9688| [8725] Apache2 MOD_CGI STDERR Denial Of Service Vulnerability
9689| [8707] Apache htpasswd Password Entropy Weakness
9690| [8561] Apache::Gallery Insecure Local File Storage Privilege Escalation Vulnerability
9691| [8287] Mod_Mylo Apache Module REQSTR Buffer Overflow Vulnerability
9692| [8226] Apache HTTP Server Multiple Vulnerabilities
9693| [8138] Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
9694| [8137] Apache Web Server Prefork MPM Denial Of Service Vulnerability
9695| [8136] Macromedia Apache Web Server Encoded Space Source Disclosure Vulnerability
9696| [8135] Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
9697| [8134] Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness
9698| [7768] Apache Tomcat Insecure Directory Permissions Vulnerability
9699| [7725] Apache Basic Authentication Module Valid User Login Denial Of Service Vulnerability
9700| [7723] Apache APR_PSPrintf Memory Corruption Vulnerability
9701| [7448] Apache Mod_Auth_Any Remote Command Execution Vulnerability
9702| [7375] Apache Mod_Access_Referer NULL Pointer Dereference Denial of Service Vulnerability
9703| [7332] Apache Web Server OS2 Filestat Denial Of Service Vulnerability
9704| [7255] Apache Web Server File Descriptor Leakage Vulnerability
9705| [7254] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
9706| [6943] Apache Web Server MIME Boundary Information Disclosure Vulnerability
9707| [6939] Apache Web Server ETag Header Information Disclosure Weakness
9708| [6722] Apache Tomcat Web.XML File Contents Disclosure Vulnerability
9709| [6721] Apache Tomcat Null Byte Directory/File Disclosure Vulnerability
9710| [6720] Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
9711| [6662] Apache Web Server MS-DOS Device Name Denial Of Service Vulnerability
9712| [6661] Apache Web Server Default Script Mapping Bypass Vulnerability
9713| [6660] Apache Web Server Illegal Character HTTP Request File Disclosure Vulnerability
9714| [6659] Apache Web Server MS-DOS Device Name Arbitrary Code Execution Vulnerability
9715| [6562] Apache Tomcat Invoker Servlet File Disclosure Vulnerability
9716| [6320] Apache/Tomcat Mod_JK Chunked Encoding Denial Of Service Vulnerability
9717| [6117] Apache mod_php File Descriptor Leakage Vulnerability
9718| [6065] Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
9719| [5996] Apache AB.C Web Benchmarking Buffer Overflow Vulnerability
9720| [5995] Apache AB.C Web Benchmarking Read_Connection() Buffer Overflow Vulnerability
9721| [5993] Multiple Apache HTDigest Buffer Overflow Vulnerabilities
9722| [5992] Apache HTDigest Insecure Temporary File Vulnerability
9723| [5991] Apache HTDigest Arbitrary Command Execution Vulnerability
9724| [5990] Apache HTPasswd Insecure Temporary File Vulnerability
9725| [5981] Multiple Apache HTDigest and HTPassWD Component Vulnerabilites
9726| [5884] Apache Web Server Scoreboard Memory Segment Overwriting SIGUSR1 Sending Vulnerability
9727| [5847] Apache Server Side Include Cross Site Scripting Vulnerability
9728| [5838] Apache Tomcat 3.2 Directory Disclosure Vulnerability
9729| [5816] Apache 2 mod_dav Denial Of Service Vulnerability
9730| [5791] HP VirtualVault Apache mod_ssl Denial Of Service Vulnerability
9731| [5787] Apache Oversized STDERR Buffer Denial Of Service Vulnerability
9732| [5786] Apache Tomcat DefaultServlet File Disclosure Vulnerability
9733| [5542] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
9734| [5486] Apache 2.0 CGI Path Disclosure Vulnerability
9735| [5485] Apache 2.0 Path Disclosure Vulnerability
9736| [5434] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
9737| [5256] Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
9738| [5194] Apache Tomcat DOS Device Name Cross Site Scripting Vulnerability
9739| [5193] Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
9740| [5067] Apache Tomcat Null Character Malformed Request Denial Of Service Vulnerability
9741| [5054] Apache Tomcat Web Root Path Disclosure Vulnerability
9742| [5033] Apache Chunked-Encoding Memory Corruption Vulnerability
9743| [4995] Apache Tomcat JSP Engine Denial of Service Vulnerability
9744| [4878] Apache Tomcat RealPath.JSP Malformed Request Information Disclosure Vulnerability
9745| [4877] Apache Tomcat Example Files Web Root Path Disclosure Vulnerability
9746| [4876] Apache Tomcat Source.JSP Malformed Request Information Disclosure Vulnerability
9747| [4575] Apache Tomcat Servlet Path Disclosure Vulnerability
9748| [4557] Apache Tomcat System Path Information Disclosure Vulnerability
9749| [4437] Apache Error Message Cross-Site Scripting Vulnerability
9750| [4431] Apache PrintEnv/Test_CGI Script Injection Vulnerability
9751| [4358] Apache Double-Reverse Lookup Log Entry Spoofing Vulnerability
9752| [4335] Apache Win32 Batch File Remote Command Execution Vulnerability
9753| [4292] Oracle 9iAS Apache PL/SQL Module Web Administration Access Vulnerability
9754| [4189] Apache mod_ssl/Apache-SSL Buffer Overflow Vulnerability
9755| [4057] Apache 2 for Windows OPTIONS request Path Disclosure Vulnerability
9756| [4056] Apache 2 for Windows php.exe Path Disclosure Vulnerability
9757| [4037] Oracle 9iAS Apache PL/SQL Module Denial of Service Vulnerability
9758| [4032] Oracle 9iAS Apache PL/SQL Module Multiple Buffer Overflows Vulnerability
9759| [3796] Apache HTTP Request Unexpected Behavior Vulnerability
9760| [3790] Apache Non-Existent Log Directory Denial Of Service Vulnerability
9761| [3786] Apache Win32 PHP.EXE Remote File Disclosure Vulnerability
9762| [3727] Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
9763| [3726] Oracle 9I Application Server PL/SQL Apache Module Buffer Overflow Vulnerability
9764| [3596] Apache Split-Logfile File Append Vulnerability
9765| [3521] Apache mod_usertrack Predictable ID Generation Vulnerability
9766| [3335] Red Hat Linux Apache Remote Username Enumeration Vulnerability
9767| [3316] MacOS X Client Apache Directory Contents Disclosure Vulnerability
9768| [3256] Apache mod_auth_oracle Remote SQL Query Manipulation Vulnerability
9769| [3255] Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
9770| [3254] Apache AuthPG Remote SQL Query Manipulation Vulnerability
9771| [3253] Apache mod_auth_pgsql_sys Remote SQL Query Manipulation Vulnerability
9772| [3251] Apache mod_auth_pgsql Remote SQL Query Manipulation Vulnerability
9773| [3176] Apache Mod ReWrite Rules Bypassing Image Linking Vulnerability
9774| [3169] Apache Server Address Disclosure Vulnerability
9775| [3009] Apache Possible Directory Index Disclosure Vulnerability
9776| [2982] Apache Tomcat Cross-Site Scripting Vulnerability
9777| [2852] MacOS X Client Apache File Protection Bypass Vulnerability
9778| [2740] Apache Web Server HTTP Request Denial of Service Vulnerability
9779| [2518] Apache Tomcat 3.0 Directory Traversal Vulnerability
9780| [2503] Apache Artificially Long Slash Path Directory Listing Vulnerability
9781| [2300] NCSA/Apache httpd ScriptAlias Source Retrieval Vulnerability
9782| [2216] Apache Web Server DoS Vulnerability
9783| [2182] Apache /tmp File Race Vulnerability
9784| [2171] Oracle Apache+WebDB Documented Backdoor Vulnerability
9785| [2060] Apache Web Server with Php 3 File Disclosure Vulnerability
9786| [1821] Apache mod_cookies Buffer Overflow Vulnerability
9787| [1728] Apache Rewrite Module Arbitrary File Disclosure Vulnerability
9788| [1658] SuSE Apache CGI Source Code Viewing Vulnerability
9789| [1656] SuSE Apache WebDAV Directory Listings Vulnerability
9790| [1575] Trustix Apache-SSL RPM Permissions Vulnerability
9791| [1548] Apache Jakarta-Tomcat /admin Context Vulnerability
9792| [1532] Apache Tomcat Snoop Servlet Information Disclosure Vulnerability
9793| [1531] Apache Tomcat 3.1 Path Revealing Vulnerability
9794| [1457] Apache::ASP source.asp Example Script Vulnerability
9795| [1284] Apache HTTP Server (win32) Root Directory Access Vulnerability
9796| [1083] Cobalt Raq Apache .htaccess Disclosure Vulnerability
9797|
9798| IBM X-Force - https://exchange.xforce.ibmcloud.com:
9799| [86258] Apache CloudStack text fields cross-site scripting
9800| [85983] Apache Subversion mod_dav_svn module denial of service
9801| [85875] Apache OFBiz UEL code execution
9802| [85874] Apache OFBiz Webtools View Log screen cross-site scripting
9803| [85871] Apache HTTP Server mod_session_dbd unspecified
9804| [85756] Apache Struts OGNL expression command execution
9805| [85755] Apache Struts DefaultActionMapper class open redirect
9806| [85586] Apache ActiveMQ CVE-2013-1879 cross-site scripting
9807| [85574] Apache HTTP Server mod_dav denial of service
9808| [85573] Apache Struts Showcase App OGNL code execution
9809| [85496] Apache CXF denial of service
9810| [85423] Apache Geronimo RMI classloader code execution
9811| [85326] Apache Santuario XML Security for C++ buffer overflow
9812| [85323] Apache Santuario XML Security for Java spoofing
9813| [85319] Apache Qpid Python client SSL spoofing
9814| [85019] Apache Santuario XML Security for C++ CVE-2013-2156 buffer overflow
9815| [85018] Apache Santuario XML Security for C++ CVE-2013-2155 denial of service
9816| [85017] Apache Santuario XML Security for C++ CVE-2013-2154 buffer overflow
9817| [85016] Apache Santuario XML Security for C++ CVE-2013-2153 spoofing
9818| [84952] Apache Tomcat CVE-2012-3544 denial of service
9819| [84763] Apache Struts CVE-2013-2135 security bypass
9820| [84762] Apache Struts CVE-2013-2134 security bypass
9821| [84719] Apache Subversion CVE-2013-2088 command execution
9822| [84718] Apache Subversion CVE-2013-2112 denial of service
9823| [84717] Apache Subversion CVE-2013-1968 denial of service
9824| [84577] Apache Tomcat security bypass
9825| [84576] Apache Tomcat symlink
9826| [84543] Apache Struts CVE-2013-2115 security bypass
9827| [84542] Apache Struts CVE-2013-1966 security bypass
9828| [84154] Apache Tomcat session hijacking
9829| [84144] Apache Tomcat denial of service
9830| [84143] Apache Tomcat information disclosure
9831| [84111] Apache HTTP Server command execution
9832| [84043] Apache Virtual Computing Lab cross-site scripting
9833| [84042] Apache Virtual Computing Lab cross-site scripting
9834| [83782] Apache CloudStack information disclosure
9835| [83781] Apache CloudStack security bypass
9836| [83720] Apache ActiveMQ cross-site scripting
9837| [83719] Apache ActiveMQ denial of service
9838| [83718] Apache ActiveMQ denial of service
9839| [83263] Apache Subversion denial of service
9840| [83262] Apache Subversion denial of service
9841| [83261] Apache Subversion denial of service
9842| [83259] Apache Subversion denial of service
9843| [83035] Apache mod_ruid2 security bypass
9844| [82852] Apache Qpid federation_tag security bypass
9845| [82851] Apache Qpid qpid::framing::Buffer denial of service
9846| [82758] Apache Rave User RPC API information disclosure
9847| [82663] Apache Subversion svn_fs_file_length() denial of service
9848| [82642] Apache Qpid qpid::framing::Buffer::checkAvailable() denial of service
9849| [82641] Apache Qpid AMQP denial of service
9850| [82626] Apache HTTP Server on Debian GNU/Linux Debian apache2ctl symlink
9851| [82618] Apache Commons FileUpload symlink
9852| [82360] Apache HTTP Server manager interface cross-site scripting
9853| [82359] Apache HTTP Server hostnames cross-site scripting
9854| [82338] Apache Tomcat log/logdir information disclosure
9855| [82328] Apache Maven and Apache Maven Wagon SSL spoofing
9856| [82268] Apache OpenJPA deserialization command execution
9857| [81981] Apache CXF UsernameTokens security bypass
9858| [81980] Apache CXF WS-Security security bypass
9859| [81398] Apache OFBiz cross-site scripting
9860| [81240] Apache CouchDB directory traversal
9861| [81226] Apache CouchDB JSONP code execution
9862| [81225] Apache CouchDB Futon user interface cross-site scripting
9863| [81211] Apache Axis2/C SSL spoofing
9864| [81167] Apache CloudStack DeployVM information disclosure
9865| [81166] Apache CloudStack AddHost API information disclosure
9866| [81165] Apache CloudStack createSSHKeyPair API information disclosure
9867| [80518] Apache Tomcat cross-site request forgery security bypass
9868| [80517] Apache Tomcat FormAuthenticator security bypass
9869| [80516] Apache Tomcat NIO denial of service
9870| [80408] Apache Tomcat replay-countermeasure security bypass
9871| [80407] Apache Tomcat HTTP Digest Access Authentication security bypass
9872| [80317] Apache Tomcat slowloris denial of service
9873| [79984] Apache Commons HttpClient SSL spoofing
9874| [79983] Apache CXF SSL spoofing
9875| [79830] Apache Axis2/Java SSL spoofing
9876| [79829] Apache Axis SSL spoofing
9877| [79809] Apache Tomcat DIGEST security bypass
9878| [79806] Apache Tomcat parseHeaders() denial of service
9879| [79540] Apache OFBiz unspecified
9880| [79487] Apache Axis2 SAML security bypass
9881| [79212] Apache Cloudstack code execution
9882| [78734] Apache CXF SOAP Action security bypass
9883| [78730] Apache Qpid broker denial of service
9884| [78617] Eucalyptus Apache Santuario (XML Security for Java) denial of service
9885| [78563] Apache mod_pagespeed module unspecified cross-site scripting
9886| [78562] Apache mod_pagespeed module security bypass
9887| [78454] Apache Axis2 security bypass
9888| [78452] Websense Web Security and Web Filter Apache Tomcat information disclosure
9889| [78451] Websense Web Security and Web Filter Apache Tomcat cross-site scripting
9890| [78321] Apache Wicket unspecified cross-site scripting
9891| [78183] Apache Struts parameters denial of service
9892| [78182] Apache Struts cross-site request forgery
9893| [78153] Apache Solr Autocomplete module for Drupal autocomplete results cross-site scripting
9894| [77987] mod_rpaf module for Apache denial of service
9895| [77958] Apache Struts skill name code execution
9896| [77914] Apache HTTP Server mod_negotiation module cross-site scripting
9897| [77913] Apache HTTP Server mod_proxy_ajp information disclosure
9898| [77568] Apache Qpid broker security bypass
9899| [77421] Apache Libcloud spoofing
9900| [77059] Oracle Solaris Cluster Apache Tomcat Agent unspecified
9901| [77046] Oracle Solaris Apache HTTP Server information disclosure
9902| [76837] Apache Hadoop information disclosure
9903| [76802] Apache Sling CopyFrom denial of service
9904| [76692] Apache Hadoop symlink
9905| [76535] Apache Roller console cross-site request forgery
9906| [76534] Apache Roller weblog cross-site scripting
9907| [76152] Apache CXF elements security bypass
9908| [76151] Apache CXF child policies security bypass
9909| [75983] MapServer for Windows Apache file include
9910| [75857] Apache Commons Compress and Apache Ant bzip2 denial of service
9911| [75558] Apache POI denial of service
9912| [75545] PHP apache_request_headers() buffer overflow
9913| [75302] Apache Qpid SASL security bypass
9914| [75211] Debian GNU/Linux apache 2 cross-site scripting
9915| [74901] Apache HTTP Server LD_LIBRARY_PATH privilege escalation
9916| [74871] Apache OFBiz FlexibleStringExpander code execution
9917| [74870] Apache OFBiz multiple cross-site scripting
9918| [74750] Apache Hadoop unspecified spoofing
9919| [74319] Apache Struts XSLTResult.java file upload
9920| [74313] Apache Traffic Server header buffer overflow
9921| [74276] Apache Wicket directory traversal
9922| [74273] Apache Wicket unspecified cross-site scripting
9923| [74181] Apache HTTP Server mod_fcgid module denial of service
9924| [73690] Apache Struts OGNL code execution
9925| [73432] Apache Solr extension for TYPO3 unspecified cross-site scripting
9926| [73100] Apache MyFaces in directory traversal
9927| [73096] Apache APR hash denial of service
9928| [73052] Apache Struts name cross-site scripting
9929| [73030] Apache CXF UsernameToken security bypass
9930| [72888] Apache Struts lastName cross-site scripting
9931| [72758] Apache HTTP Server httpOnly information disclosure
9932| [72757] Apache HTTP Server MPM denial of service
9933| [72585] Apache Struts ParameterInterceptor security bypass
9934| [72438] Apache Tomcat Digest security bypass
9935| [72437] Apache Tomcat Digest security bypass
9936| [72436] Apache Tomcat DIGEST security bypass
9937| [72425] Apache Tomcat parameter denial of service
9938| [72422] Apache Tomcat request object information disclosure
9939| [72377] Apache HTTP Server scoreboard security bypass
9940| [72345] Apache HTTP Server HTTP request denial of service
9941| [72229] Apache Struts ExceptionDelegator command execution
9942| [72089] Apache Struts ParameterInterceptor directory traversal
9943| [72088] Apache Struts CookieInterceptor command execution
9944| [72047] Apache Geronimo hash denial of service
9945| [72016] Apache Tomcat hash denial of service
9946| [71711] Apache Struts OGNL expression code execution
9947| [71654] Apache Struts interfaces security bypass
9948| [71620] Apache ActiveMQ failover denial of service
9949| [71617] Apache HTTP Server mod_proxy module information disclosure
9950| [71508] Apache MyFaces EL security bypass
9951| [71445] Apache HTTP Server mod_proxy security bypass
9952| [71203] Apache Tomcat servlets privilege escalation
9953| [71181] Apache HTTP Server ap_pregsub() denial of service
9954| [71093] Apache HTTP Server ap_pregsub() buffer overflow
9955| [70336] Apache HTTP Server mod_proxy information disclosure
9956| [69804] Apache HTTP Server mod_proxy_ajp denial of service
9957| [69472] Apache Tomcat AJP security bypass
9958| [69396] Apache HTTP Server ByteRange filter denial of service
9959| [69394] Apache Wicket multi window support cross-site scripting
9960| [69176] Apache Tomcat XML information disclosure
9961| [69161] Apache Tomcat jsvc information disclosure
9962| [68799] mod_authnz_external module for Apache mysql-auth.pl SQL injection
9963| [68541] Apache Tomcat sendfile information disclosure
9964| [68420] Apache XML Security denial of service
9965| [68238] Apache Tomcat JMX information disclosure
9966| [67860] Apache Rampart/C rampart_timestamp_token_validate security bypass
9967| [67804] Apache Subversion control rules information disclosure
9968| [67803] Apache Subversion control rules denial of service
9969| [67802] Apache Subversion baselined denial of service
9970| [67672] Apache Archiva multiple cross-site scripting
9971| [67671] Apache Archiva multiple cross-site request forgery
9972| [67564] Apache APR apr_fnmatch() denial of service
9973| [67532] IBM WebSphere Application Server org.apache.jasper.runtime.JspWriterImpl.response denial of service
9974| [67515] Apache Tomcat annotations security bypass
9975| [67480] Apache Struts s:submit information disclosure
9976| [67414] Apache APR apr_fnmatch() denial of service
9977| [67356] Apache Struts javatemplates cross-site scripting
9978| [67354] Apache Struts Xwork cross-site scripting
9979| [66676] Apache Tomcat HTTP BIO information disclosure
9980| [66675] Apache Tomcat web.xml security bypass
9981| [66640] Apache HttpComponents HttpClient Proxy-Authorization information disclosure
9982| [66241] Apache HttpComponents information disclosure
9983| [66154] Apache Tomcat ServletSecurity security bypass
9984| [65971] Apache Tomcat ServletSecurity security bypass
9985| [65876] Apache Subversion mod_dav_svn denial of service
9986| [65343] Apache Continuum unspecified cross-site scripting
9987| [65162] Apache Tomcat NIO connector denial of service
9988| [65161] Apache Tomcat javax.servlet.ServletRequest.getLocale() denial of service
9989| [65160] Apache Tomcat HTML Manager interface cross-site scripting
9990| [65159] Apache Tomcat ServletContect security bypass
9991| [65050] Apache CouchDB web-based administration UI cross-site scripting
9992| [64773] Oracle HTTP Server Apache Plugin unauthorized access
9993| [64473] Apache Subversion blame -g denial of service
9994| [64472] Apache Subversion walk() denial of service
9995| [64407] Apache Axis2 CVE-2010-0219 code execution
9996| [63926] Apache Archiva password privilege escalation
9997| [63785] Apache CouchDB LD_LIBRARY_PATH privilege escalation
9998| [63493] Apache Archiva credentials cross-site request forgery
9999| [63477] Apache Tomcat HttpOnly session hijacking
10000| [63422] Apache Tomcat sessionsList.jsp cross-site scripting
10001| [63303] Apache mod_fcgid module fcgid_header_bucket_read() buffer overflow
10002| [62959] Apache Shiro filters security bypass
10003| [62790] Apache Perl cgi module denial of service
10004| [62576] Apache Qpid exchange denial of service
10005| [62575] Apache Qpid AMQP denial of service
10006| [62354] Apache Qpid SSL denial of service
10007| [62235] Apache APR-util apr_brigade_split_line() denial of service
10008| [62181] Apache XML-RPC SAX Parser information disclosure
10009| [61721] Apache Traffic Server cache poisoning
10010| [61202] Apache Derby BUILTIN authentication functionality information disclosure
10011| [61186] Apache CouchDB Futon cross-site request forgery
10012| [61169] Apache CXF DTD denial of service
10013| [61070] Apache Jackrabbit search.jsp SQL injection
10014| [61006] Apache SLMS Quoting cross-site request forgery
10015| [60962] Apache Tomcat time cross-site scripting
10016| [60883] Apache mod_proxy_http information disclosure
10017| [60671] Apache HTTP Server mod_cache and mod_dav denial of service
10018| [60264] Apache Tomcat Transfer-Encoding denial of service
10019| [59746] Apache Axis2 axis2/axis2-admin page session hijacking
10020| [59588] Apache Axis2/Java XML DTD (Document Type Declaration) data denial of service
10021| [59413] Apache mod_proxy_http timeout information disclosure
10022| [59058] Apache MyFaces unencrypted view state cross-site scripting
10023| [58827] Apache Axis2 xsd file include
10024| [58790] Apache Axis2 modules cross-site scripting
10025| [58299] Apache ActiveMQ queueBrowse cross-site scripting
10026| [58169] Apache Tomcat Web Application Manager / Host Manager cross-site request forgery
10027| [58056] Apache ActiveMQ .jsp source code disclosure
10028| [58055] Apache Tomcat realm name information disclosure
10029| [58046] Apache HTTP Server mod_auth_shadow security bypass
10030| [57841] Apache Open For Business Project (OFBiz) subject cross-site scripting
10031| [57840] Apache Open For Business Project (OFBiz) multiple parameters cross-site scripting
10032| [57429] Apache CouchDB algorithms information disclosure
10033| [57398] Apache ActiveMQ Web console cross-site request forgery
10034| [57397] Apache ActiveMQ createDestination.action cross-site scripting
10035| [56653] Apache HTTP Server DNS spoofing
10036| [56652] Apache HTTP Server DNS cross-site scripting
10037| [56625] Apache HTTP Server request header information disclosure
10038| [56624] Apache HTTP Server mod_isapi orphaned callback pointer code execution
10039| [56623] Apache HTTP Server mod_proxy_ajp denial of service
10040| [55941] mod_proxy module for Apache ap_proxy_send_fb() buffer overflow
10041| [55857] Apache Tomcat WAR files directory traversal
10042| [55856] Apache Tomcat autoDeploy attribute security bypass
10043| [55855] Apache Tomcat WAR directory traversal
10044| [55210] Intuit component for Joomla! Apache information disclosure
10045| [54533] Apache Tomcat 404 error page cross-site scripting
10046| [54182] Apache Tomcat admin default password
10047| [53878] Apache Solr Search (solr) extension for TYPO3 unspecified cross-site scripting
10048| [53666] Apache HTTP Server Solaris pollset support denial of service
10049| [53650] Apache HTTP Server HTTP basic-auth module security bypass
10050| [53124] mod_proxy_ftp module for Apache HTTP header security bypass
10051| [53041] mod_proxy_ftp module for Apache denial of service
10052| [52540] Apache Portable Runtime and Apache Portable Utility library multiple buffer overflow
10053| [51953] Apache Tomcat Path Disclosure
10054| [51952] Apache Tomcat Path Traversal
10055| [51951] Apache stronghold-status Information Disclosure
10056| [51950] Apache stronghold-info Information Disclosure
10057| [51949] Apache PHP Source Code Disclosure
10058| [51948] Apache Multiviews Attack
10059| [51946] Apache JServ Environment Status Information Disclosure
10060| [51945] Apache error_log Information Disclosure
10061| [51944] Apache Default Installation Page Pattern Found
10062| [51943] Apache AXIS XML Parser echoheaders.jws Sample Web Service Denial of Service
10063| [51942] Apache AXIS XML External Entity File Retrieval
10064| [51941] Apache AXIS Sample Servlet Information Leak
10065| [51940] Apache access_log Information Disclosure
10066| [51626] Apache mod_deflate denial of service
10067| [51532] mod_proxy module for the Apache HTTP Server stream_reqbody_cl denial of service
10068| [51365] Apache Tomcat RequestDispatcher security bypass
10069| [51273] Apache HTTP Server Incomplete Request denial of service
10070| [51195] Apache Tomcat XML information disclosure
10071| [50994] Apache APR-util xml/apr_xml.c denial of service
10072| [50993] Apache APR-util apr_brigade_vprintf denial of service
10073| [50964] Apache APR-util apr_strmatch_precompile() denial of service
10074| [50930] Apache Tomcat j_security_check information disclosure
10075| [50928] Apache Tomcat AJP denial of service
10076| [50884] Apache HTTP Server XML ENTITY denial of service
10077| [50808] Apache HTTP Server AllowOverride privilege escalation
10078| [50108] Apache Struts s:a tag and s:url tag cross-site scripting
10079| [50059] Apache mod_proxy_ajp information disclosure
10080| [49951] Apache Tiles Expression Language (EL) expressions cross-site scripting
10081| [49925] Apache Geronimo Web Administrative Console cross-site request forgery
10082| [49924] Apache Geronimo console/portal/Server/Monitoring cross-site scripting
10083| [49921] Apache ActiveMQ Web interface cross-site scripting
10084| [49898] Apache Geronimo Services/Repository directory traversal
10085| [49725] Apache Tomcat mod_jk module information disclosure
10086| [49715] Apache mod_perl Apache::Status and Apache2::Status modules cross-site scripting
10087| [49712] Apache Struts unspecified cross-site scripting
10088| [49213] Apache Tomcat cal2.jsp cross-site scripting
10089| [48934] Apache Tomcat POST doRead method information disclosure
10090| [48211] Apache Tomcat header HTTP request smuggling
10091| [48163] libapache2-mod-auth-mysql module for Debian multibyte encoding SQL injection
10092| [48110] Apache Jackrabbit search.jsp and swr.jsp cross-site scripting
10093| [47709] Apache Roller "
10094| [47104] Novell Netware ApacheAdmin console security bypass
10095| [47086] Apache HTTP Server OS fingerprinting unspecified
10096| [46329] Apache Struts FilterDispatcher and DefaultStaticContentLoader class directory traversal
10097| [45791] Apache Tomcat RemoteFilterValve security bypass
10098| [44435] Oracle WebLogic Apache Connector buffer overflow
10099| [44411] Apache Tomcat allowLinking UTF-8 directory traversal
10100| [44223] Apache HTTP Server mod_proxy_ftp cross-site scripting
10101| [44156] Apache Tomcat RequestDispatcher directory traversal
10102| [44155] Apache Tomcat HttpServletResponse.sendError() cross-site scripting
10103| [43885] Oracle WebLogic Server Apache Connector buffer overflow
10104| [42987] Apache HTTP Server mod_proxy module denial of service
10105| [42915] Apache Tomcat JSP files path disclosure
10106| [42914] Apache Tomcat MS-DOS path disclosure
10107| [42892] Apache Tomcat unspecified unauthorized access
10108| [42816] Apache Tomcat Host Manager cross-site scripting
10109| [42303] Apache 403 error cross-site scripting
10110| [41618] Apache-SSL ExpandCert() authentication bypass
10111| [40761] Apache Derby RDBNAM parameter and DatabaseMetaData.getURL information disclosure
10112| [40736] Apache Tomcat HTTP/1.1 connector information disclosure
10113| [40614] Apache mod_jk2 HTTP Host header buffer overflow
10114| [40562] Apache Geronimo init information disclosure
10115| [40478] Novell Web Manager webadmin-apache.conf security bypass
10116| [40411] Apache Tomcat exception handling information disclosure
10117| [40409] Apache Tomcat native (APR based) connector weak security
10118| [40403] Apache Tomcat quotes and %5C cookie information disclosure
10119| [40388] Sun Java Plug-In org.apache.crimson.tree.XmlDocument security bypass
10120| [39893] Apache HTTP Server mod_negotiation HTTP response splitting
10121| [39867] Apache HTTP Server mod_negotiation cross-site scripting
10122| [39804] Apache Tomcat SingleSignOn information disclosure
10123| [39615] Apache HTTP Server mod_proxy_ftp.c UTF-7 cross-site scripting
10124| [39612] Apache HTTP Server mod_proxy_balancer buffer overflow
10125| [39608] Apache HTTP Server balancer manager cross-site request forgery
10126| [39476] Apache mod_proxy_balancer balancer_handler function denial of service
10127| [39474] Apache HTTP Server mod_proxy_balancer cross-site scripting
10128| [39472] Apache HTTP Server mod_status cross-site scripting
10129| [39201] Apache Tomcat JULI logging weak security
10130| [39158] Apache HTTP Server Windows SMB shares information disclosure
10131| [39001] Apache HTTP Server mod_imap and mod_imagemap module cross-site scripting
10132| [38951] Apache::AuthCAS Perl module cookie SQL injection
10133| [38800] Apache HTTP Server 413 error page cross-site scripting
10134| [38211] Apache Geronimo SQLLoginModule authentication bypass
10135| [37243] Apache Tomcat WebDAV directory traversal
10136| [37178] RHSA update for Apache HTTP Server mod_status module cross-site scripting not installed
10137| [37177] RHSA update for Apache HTTP Server Apache child process denial of service not installed
10138| [37119] RHSA update for Apache mod_auth_kerb off-by-one buffer overflow not installed
10139| [37100] RHSA update for Apache and IBM HTTP Server Expect header cross-site scripting not installed
10140| [36782] Apache Geronimo MEJB unauthorized access
10141| [36586] Apache HTTP Server UTF-7 cross-site scripting
10142| [36468] Apache Geronimo LoginModule security bypass
10143| [36467] Apache Tomcat functions.jsp cross-site scripting
10144| [36402] Apache Tomcat calendar cross-site request forgery
10145| [36354] Apache HTTP Server mod_proxy module denial of service
10146| [36352] Apache HTTP Server ap_proxy_date_canon() denial of service
10147| [36336] Apache Derby lock table privilege escalation
10148| [36335] Apache Derby schema privilege escalation
10149| [36006] Apache Tomcat "
10150| [36001] Apache Tomcat Host Manager Servlet alias cross-site scripting
10151| [35999] Apache Tomcat \"
10152| [35795] Apache Tomcat CookieExample cross-site scripting
10153| [35536] Apache Tomcat SendMailServlet example cross-site scripting
10154| [35384] Apache HTTP Server mod_cache module denial of service
10155| [35097] Apache HTTP Server mod_status module cross-site scripting
10156| [35095] Apache HTTP Server Prefork MPM module denial of service
10157| [34984] Apache HTTP Server recall_headers information disclosure
10158| [34966] Apache HTTP Server MPM content spoofing
10159| [34965] Apache HTTP Server MPM information disclosure
10160| [34963] Apache HTTP Server MPM multiple denial of service
10161| [34872] Apache MyFaces Tomahawk autoscroll parameter cross-site scripting
10162| [34869] Apache Tomcat JSP example Web application cross-site scripting
10163| [34868] Apache Tomcat Manager and Host Manager cross-site scripting
10164| [34496] Apache Tomcat JK Connector security bypass
10165| [34377] Apache Tomcat hello.jsp cross-site scripting
10166| [34212] Apache Tomcat SSL configuration security bypass
10167| [34210] Apache Tomcat Accept-Language cross-site scripting
10168| [34209] Apache Tomcat calendar application cross-site scripting
10169| [34207] Apache Tomcat implicit-objects.jsp cross-site scripting
10170| [34167] Apache Axis WSDL file path disclosure
10171| [34068] Apache Tomcat AJP connector information disclosure
10172| [33584] Apache HTTP Server suEXEC privilege escalation
10173| [32988] Apache Tomcat proxy module directory traversal
10174| [32794] Apache Tomcat JK Web Server Connector map_uri_to_worker() buffer overflow
10175| [32708] Debian Apache tty privilege escalation
10176| [32441] ApacheStats extract() PHP call unspecified
10177| [32128] Apache Tomcat default account
10178| [31680] Apache Tomcat RequestParamExample cross-site scripting
10179| [31649] Apache Tomcat Sample Servlet TroubleShooter detected
10180| [31557] BEA WebLogic Server and WebLogic Express Apache proxy plug-in denial of service
10181| [31236] Apache HTTP Server htpasswd.c strcpy buffer overflow
10182| [30456] Apache mod_auth_kerb off-by-one buffer overflow
10183| [29550] Apache mod_tcl set_var() format string
10184| [28620] Apache and IBM HTTP Server Expect header cross-site scripting
10185| [28357] Apache HTTP Server mod_alias script source information disclosure
10186| [28063] Apache mod_rewrite off-by-one buffer overflow
10187| [27902] Apache Tomcat URL information disclosure
10188| [26786] Apache James SMTP server denial of service
10189| [25680] libapache2 /tmp/svn file upload
10190| [25614] Apache Struts lookupMap cross-site scripting
10191| [25613] Apache Struts ActionForm denial of service
10192| [25612] Apache Struts isCancelled() security bypass
10193| [24965] Apache mod_python FileSession command execution
10194| [24716] Apache James spooler memory leak denial of service
10195| [24159] Apache Geronimo Web-Access-Log Viewer cross-site scripting
10196| [24158] Apache Geronimo jsp-examples cross-site scripting
10197| [24030] Apache auth_ldap module multiple format strings
10198| [24008] Apache mod_ssl custom error message denial of service
10199| [24003] Apache mod_auth_pgsql module multiple syslog format strings
10200| [23612] Apache mod_imap referer field cross-site scripting
10201| [23173] Apache Struts error message cross-site scripting
10202| [22942] Apache Tomcat directory listing denial of service
10203| [22858] Apache Multi-Processing Module code allows denial of service
10204| [22602] RHSA-2005:582 updates for Apache httpd not installed
10205| [22520] Apache mod-auth-shadow "
10206| [22466] ApacheTop symlink
10207| [22109] Apache HTTP Server ssl_engine_kernel client certificate validation
10208| [22006] Apache HTTP Server byte-range filter denial of service
10209| [21567] Apache mod_ssl off-by-one buffer overflow
10210| [21195] Apache HTTP Server header HTTP request smuggling
10211| [20383] Apache HTTP Server htdigest buffer overflow
10212| [19681] Apache Tomcat AJP12 request denial of service
10213| [18993] Apache HTTP server check_forensic symlink attack
10214| [18790] Apache Tomcat Manager cross-site scripting
10215| [18349] Apache HTTP server Apple HFS+ filesystem obtain information
10216| [18348] Apache HTTP server Apple HFS+ filesystem .DS_Store and .ht file disclosure
10217| [18347] Apache HTTP server Apple Mac OS X Server mod_digest_apple module could allow an attacker to replay responses
10218| [17961] Apache Web server ServerTokens has not been set
10219| [17930] Apache HTTP Server HTTP GET request denial of service
10220| [17785] Apache mod_include module buffer overflow
10221| [17671] Apache HTTP Server SSLCipherSuite bypass restrictions
10222| [17473] Apache HTTP Server Satisfy directive allows access to resources
10223| [17413] Apache htpasswd buffer overflow
10224| [17384] Apache HTTP Server environment variable configuration file buffer overflow
10225| [17382] Apache HTTP Server IPv6 apr_util denial of service
10226| [17366] Apache HTTP Server mod_dav module LOCK denial of service
10227| [17273] Apache HTTP Server speculative mode denial of service
10228| [17200] Apache HTTP Server mod_ssl denial of service
10229| [16890] Apache HTTP Server server-info request has been detected
10230| [16889] Apache HTTP Server server-status request has been detected
10231| [16705] Apache mod_ssl format string attack
10232| [16524] Apache HTTP Server ap_get_mime_headers_core denial of service
10233| [16387] Apache HTTP Server mod_proxy Content-Length buffer overflow
10234| [16230] Apache HTTP Server PHP denial of service
10235| [16214] Apache mod_ssl ssl_util_uuencode_binary buffer overflow
10236| [15958] Apache HTTP Server authentication modules memory corruption
10237| [15547] Apache HTTP Server mod_disk_cache local information disclosure
10238| [15540] Apache HTTP Server socket starvation denial of service
10239| [15467] Novell GroupWise WebAccess using Apache Web server allows viewing of files on the server
10240| [15422] Apache HTTP Server mod_access information disclosure
10241| [15419] Apache HTTP Server mod_ssl plain HTTP request denial of service
10242| [15293] Apache for Cygwin "
10243| [15065] Apache-SSL has a default password
10244| [15041] Apache HTTP Server mod_digest module could allow an attacker to replay responses
10245| [15015] Apache httpd server httpd.conf could allow a local user to bypass restrictions
10246| [14751] Apache Mod_python output filter information disclosure
10247| [14125] Apache HTTP Server mod_userdir module information disclosure
10248| [14075] Apache HTTP Server mod_php file descriptor leak
10249| [13703] Apache HTTP Server account
10250| [13689] Apache HTTP Server configuration allows symlinks
10251| [13688] Apache HTTP Server configuration allows SSI
10252| [13687] Apache HTTP Server Server: header value
10253| [13685] Apache HTTP Server ServerTokens value
10254| [13684] Apache HTTP Server ServerSignature value
10255| [13672] Apache HTTP Server config allows directory autoindexing
10256| [13671] Apache HTTP Server default content
10257| [13670] Apache HTTP Server config file directive references outside content root
10258| [13668] Apache HTTP Server httpd not running in chroot environment
10259| [13666] Apache HTTP Server CGI directory contains possible command interpreter or compiler
10260| [13664] Apache HTTP Server config file contains ScriptAlias entry
10261| [13663] Apache HTTP Server CGI support modules loaded
10262| [13661] Apache HTTP Server config file contains AddHandler entry
10263| [13660] Apache HTTP Server 500 error page not CGI script
10264| [13659] Apache HTTP Server 413 error page not CGI script
10265| [13658] Apache HTTP Server 403 error page not CGI script
10266| [13657] Apache HTTP Server 401 error page not CGI script
10267| [13552] Apache HTTP Server mod_cgid module information disclosure
10268| [13550] Apache GET request directory traversal
10269| [13516] Apache Cocoon XMLForm and JXForm could allow execution of code
10270| [13499] Apache Cocoon directory traversal allows downloading of boot.ini file
10271| [13429] Apache Tomcat non-HTTP request denial of service
10272| [13400] Apache HTTP server mod_alias and mod_rewrite buffer overflow
10273| [13295] Apache weak password encryption
10274| [13254] Apache Tomcat .jsp cross-site scripting
10275| [13125] Apache::Gallery Inline::C could allow arbitrary code execution
10276| [13086] Apache Jakarta Tomcat mod_jk format string allows remote access
10277| [12681] Apache HTTP Server mod_proxy could allow mail relaying
10278| [12662] Apache HTTP Server rotatelogs denial of service
10279| [12554] Apache Tomcat stores password in plain text
10280| [12553] Apache HTTP Server redirects and subrequests denial of service
10281| [12552] Apache HTTP Server FTP proxy server denial of service
10282| [12551] Apache HTTP Server prefork MPM denial of service
10283| [12550] Apache HTTP Server weaker than expected encryption
10284| [12549] Apache HTTP Server type-map file denial of service
10285| [12206] Apache Tomcat /opt/tomcat directory insecure permissions
10286| [12102] Apache Jakarta Tomcat MS-DOS device name request denial of service
10287| [12091] Apache HTTP Server apr_password_validate denial of service
10288| [12090] Apache HTTP Server apr_psprintf code execution
10289| [11804] Apache HTTP Server mod_access_referer denial of service
10290| [11750] Apache HTTP Server could leak sensitive file descriptors
10291| [11730] Apache HTTP Server error log and access log terminal escape sequence injection
10292| [11703] Apache long slash path allows directory listing
10293| [11695] Apache HTTP Server LF (Line Feed) denial of service
10294| [11694] Apache HTTP Server filestat.c denial of service
10295| [11438] Apache HTTP Server MIME message boundaries information disclosure
10296| [11412] Apache HTTP Server error log terminal escape sequence injection
10297| [11196] Apache Tomcat examples and ROOT Web applications cross-site scripting
10298| [11195] Apache Tomcat web.xml could be used to read files
10299| [11194] Apache Tomcat URL appended with a null character could list directories
10300| [11139] Apache HTTP Server mass virtual hosting with mod_rewrite or mod_vhost_alias could allow an attacker to obtain files
10301| [11126] Apache HTTP Server illegal character file disclosure
10302| [11125] Apache HTTP Server DOS device name HTTP POST code execution
10303| [11124] Apache HTTP Server DOS device name denial of service
10304| [11088] Apache HTTP Server mod_vhost_alias CGI source disclosure
10305| [10938] Apache HTTP Server printenv test CGI cross-site scripting
10306| [10771] Apache Tomcat mod_jk module multiple HTTP GET request buffer overflow
10307| [10575] Apache mod_php module could allow an attacker to take over the httpd process
10308| [10499] Apache HTTP Server WebDAV HTTP POST view source
10309| [10457] Apache HTTP Server mod_ssl "
10310| [10415] Apache HTTP Server htdigest insecure system() call could allow command execution
10311| [10414] Apache HTTP Server htdigest multiple buffer overflows
10312| [10413] Apache HTTP Server htdigest temporary file race condition
10313| [10412] Apache HTTP Server htpasswd temporary file race condition
10314| [10376] Apache Tomcat invoker servlet used in conjunction with the default servlet reveals source code
10315| [10348] Apache Tomcat HTTP GET request DOS device reference could cause a denial of service
10316| [10281] Apache HTTP Server ab.c ApacheBench long response buffer overflow
10317| [10280] Apache HTTP Server shared memory scorecard overwrite
10318| [10263] Apache Tomcat mod_jk or mod_jserv connector directory disclosure
10319| [10241] Apache HTTP Server Host: header cross-site scripting
10320| [10230] Slapper worm variants A, B, and C target OpenSSL/Apache systems
10321| [10208] Apache HTTP Server mod_dav denial of service
10322| [10206] HP VVOS Apache mod_ssl denial of service
10323| [10200] Apache HTTP Server stderr denial of service
10324| [10175] Apache Tomcat org.apache.catalina.servlets.DefaultServlet reveals source code
10325| [10169] Slapper worm variant (Slapper.C) targets OpenSSL/Apache systems
10326| [10154] Slapper worm variant (Slapper.B) targets OpenSSL/Apache systems
10327| [10098] Slapper worm targets OpenSSL/Apache systems
10328| [9876] Apache HTTP Server cgi/cgid request could disclose the path to a requested script
10329| [9875] Apache HTTP Server .var file request could disclose installation path
10330| [9863] Apache Tomcat web.xml file could allow a remote attacker to bypass restrictions
10331| [9808] Apache HTTP Server non-Unix version URL encoded directory traversal
10332| [9623] Apache HTTP Server ap_log_rerror() path disclosure
10333| [9520] Apache Tomcat /servlet/ mapping cross-site scripting
10334| [9415] Apache HTTP Server mod_ssl .htaccess off-by-one buffer overflow
10335| [9396] Apache Tomcat null character to threads denial of service
10336| [9394] Apache Tomcat HTTP request for LPT9 reveals Web root path
10337| [9249] Apache HTTP Server chunked encoding heap buffer overflow
10338| [9208] Apache Tomcat sample file requests could reveal directory listing and path to Web root directory
10339| [8932] Apache Tomcat example class information disclosure
10340| [8633] Apache HTTP Server with mod_rewrite could allow an attacker to bypass directives
10341| [8629] Apache HTTP Server double-reverse DNS lookup spoofing
10342| [8589] Apache HTTP Server for Windows DOS batch file remote command execution
10343| [8457] Oracle9i Application Server Apache PL/SQL HTTP Location header buffer overflow
10344| [8455] Oracle9i Application Server default installation could allow an attacker to access certain Apache Services
10345| [8400] Apache HTTP Server mod_frontpage buffer overflows
10346| [8326] Apache HTTP Server multiple MIME headers (sioux) denial of service
10347| [8308] Apache "
10348| [8275] Apache HTTP Server with Multiviews enabled could disclose directory contents
10349| [8119] Apache and PHP OPTIONS request reveals "
10350| [8054] Apache is running on the system
10351| [8029] Mandrake Linux default Apache configuration could allow an attacker to browse files and directories
10352| [8027] Mandrake Linux default Apache configuration has remote management interface enabled
10353| [8026] Mandrake Linux Apache sample programs could disclose sensitive information about the server
10354| [7836] Apache HTTP Server log directory denial of service
10355| [7815] Apache for Windows "
10356| [7810] Apache HTTP request could result in unexpected behavior
10357| [7599] Apache Tomcat reveals installation path
10358| [7494] Apache "
10359| [7419] Apache Web Server could allow remote attackers to overwrite .log files
10360| [7363] Apache Web Server hidden HTTP requests
10361| [7249] Apache mod_proxy denial of service
10362| [7129] Linux with Apache Web server could allow an attacker to determine if a specified username exists
10363| [7103] Apple Mac OS X used with Apache Web server could disclose directory contents
10364| [7059] Apache "
10365| [7057] Apache "
10366| [7056] Apache "
10367| [7055] Apache "
10368| [7054] Apache "
10369| [6997] Apache Jakarta Tomcat error message may reveal information
10370| [6971] Apache Jakarta Tomcat may reveal JSP source code with missing HTTP protocol specification
10371| [6970] Apache crafted HTTP request could reveal the internal IP address
10372| [6921] Apache long slash path allows directory listing
10373| [6687] Apple Mac OS X used with Apache Web server could allow arbitrary file disclosure
10374| [6527] Apache Web Server for Windows and OS2 denial of service
10375| [6316] Apache Jakarta Tomcat may reveal JSP source code
10376| [6305] Apache Jakarta Tomcat directory traversal
10377| [5926] Linux Apache symbolic link
10378| [5659] Apache Web server discloses files when used with php script
10379| [5310] Apache mod_rewrite allows attacker to view arbitrary files
10380| [5204] Apache WebDAV directory listings
10381| [5197] Apache Web server reveals CGI script source code
10382| [5160] Apache Jakarta Tomcat default installation
10383| [5099] Trustix Secure Linux installs Apache with world writable access
10384| [4968] Apache Jakarta Tomcat snoop servlet gives out information which could be used in attack
10385| [4967] Apache Jakarta Tomcat 404 error reveals the pathname of the requested file
10386| [4931] Apache source.asp example file allows users to write to files
10387| [4575] IBM HTTP Server running Apache allows users to directory listing and file retrieval
10388| [4205] Apache Jakarta Tomcat delivers file contents
10389| [2084] Apache on Debian by default serves the /usr/doc directory
10390| [1630] MessageMedia UnityMail and Apache Web server MIME header flood denial of service
10391| [697] Apache HTTP server beck exploit
10392| [331] Apache cookies buffer overflow
10393|
10394| Exploit-DB - https://www.exploit-db.com:
10395| [31130] Apache Tomcat <= 6.0.15 Cookie Quote Handling Remote Information Disclosure Vulnerability
10396| [31052] Apache <= 2.2.6 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
10397| [30901] Apache HTTP Server 2.2.6 Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
10398| [30835] Apache HTTP Server <= 2.2.4 413 Error HTTP Request Method Cross-Site Scripting Weakness
10399| [30563] Apache Tomcat <= 5.5.15 Cal2.JSP Cross-Site Scripting Vulnerability
10400| [30496] Apache Tomcat <= 6.0.13 Cookie Handling Quote Delimiter Session ID Disclosure
10401| [30495] Apache Tomcat <= 6.0.13 Host Manager Servlet Cross Site Scripting Vulnerability
10402| [30191] Apache MyFaces Tomahawk JSF Framework 1.1.5 Autoscroll Parameter Cross Site Scripting Vulnerability
10403| [30189] Apache Tomcat <= 6.0.13 JSP Example Web Applications Cross Site Scripting Vulnerability
10404| [30052] Apache Tomcat 6.0.10 Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
10405| [29930] Apache AXIS 1.0 Non-Existent WSDL Path Information Disclosure Vulnerability
10406| [29859] Apache Roller OGNL Injection
10407| [29739] Apache HTTP Server Tomcat 5.x/6.0.x Directory Traversal Vulnerability
10408| [29435] Apache Tomcat 5.5.25 - CSRF Vulnerabilities
10409| [29316] Apache + PHP 5.x - Remote Code Execution (Multithreaded Scanner) (2)
10410| [29290] Apache / PHP 5.x Remote Code Execution Exploit
10411| [28713] Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object RCE
10412| [28424] Apache 2.x HTTP Server Arbitrary HTTP Request Headers Security Weakness
10413| [28365] Apache 2.2.2 CGI Script Source Code Information Disclosure Vulnerability
10414| [28254] Apache Tomcat 5 Information Disclosure Vulnerability
10415| [27915] Apache James 2.2 SMTP Denial of Service Vulnerability
10416| [27397] Apache suEXEC Privilege Elevation / Information Disclosure
10417| [27135] Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
10418| [27096] Apache Geronimo 1.0 Error Page XSS
10419| [27095] Apache Tomcat / Geronimo 1.0 Sample Script cal2.jsp time Parameter XSS
10420| [26710] Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4 - Denial of Service
10421| [26542] Apache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability
10422| [25986] Plesk Apache Zeroday Remote Exploit
10423| [25980] Apache Struts includeParams Remote Code Execution
10424| [25625] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (2)
10425| [25624] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (1)
10426| [24874] Apache Struts ParametersInterceptor Remote Code Execution
10427| [24744] Apache Rave 0.11 - 0.20 - User Information Disclosure
10428| [24694] Apache 1.3.x mod_include Local Buffer Overflow Vulnerability
10429| [24590] Apache 2.0.x mod_ssl Remote Denial of Service Vulnerability
10430| [23751] Apache Cygwin 1.3.x/2.0.x Directory Traversal Vulnerability
10431| [23581] Apache 2.0.4x mod_perl Module File Descriptor Leakage Vulnerability
10432| [23482] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (2)
10433| [23481] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (1)
10434| [23296] Red Hat Apache 2.0.40 Directory Index Default Configuration Error
10435| [23282] apache cocoon 2.14/2.2 - Directory Traversal vulnerability
10436| [23245] Apache Tomcat 4.0.x Non-HTTP Request Denial of Service Vulnerability
10437| [23119] Apache::Gallery 0.4/0.5/0.6 Insecure Local File Storage Privilege Escalation Vulnerability
10438| [22505] Apache Mod_Access_Referer 1.0.2 NULL Pointer Dereference Denial of Service Vulnerability
10439| [22205] Apache Tomcat 3.x Null Byte Directory/File Disclosure Vulnerability
10440| [22191] Apache Web Server 2.0.x MS-DOS Device Name Denial of Service Vulnerability
10441| [22068] Apache 1.3.x,Tomcat 4.0.x/4.1.x Mod_JK Chunked Encoding Denial of Service Vulnerability
10442| [21885] Apache 1.3/2.0.x Server Side Include Cross Site Scripting Vulnerability
10443| [21882] Apache Tomcat 3.2 Directory Disclosure Vulnerability
10444| [21854] Apache 2.0.39/40 Oversized STDERR Buffer Denial of Service Vulnerability
10445| [21853] Apache Tomcat 3/4 DefaultServlet File Disclosure Vulnerability
10446| [21734] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
10447| [21719] Apache 2.0 Path Disclosure Vulnerability
10448| [21697] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
10449| [21605] Apache Tomcat 4.0.3 DoS Device Name Cross Site Scripting Vulnerability
10450| [21604] Apache Tomcat 4.0.3 Servlet Mapping Cross Site Scripting Vulnerability
10451| [21560] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (2)
10452| [21559] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (1)
10453| [21534] Apache Tomcat 3/4 JSP Engine Denial of Service Vulnerability
10454| [21492] Apache Tomcat 3.2.3/3.2.4 RealPath.JSP Malformed Request Information Disclosure
10455| [21491] Apache Tomcat 3.2.3/3.2.4 Example Files Web Root Path Disclosure
10456| [21490] Apache Tomcat 3.2.3/3.2.4 Source.JSP Malformed Request Information Disclosure
10457| [21412] Apache Tomcat 4.0/4.1 Servlet Path Disclosure Vulnerability
10458| [21350] Apache Win32 1.3.x/2.0.x Batch File Remote Command Execution Vulnerability
10459| [21204] Apache 1.3.20 Win32 PHP.EXE Remote File Disclosure Vulnerability
10460| [21112] Red Hat Linux 7.0 Apache Remote Username Enumeration Vulnerability
10461| [21067] Apache 1.0/1.2/1.3 Server Address Disclosure Vulnerability
10462| [21002] Apache 1.3 Possible Directory Index Disclosure Vulnerability
10463| [20911] Apache 1.3.14 Mac File Protection Bypass Vulnerability
10464| [20716] apache tomcat 3.0 - Directory Traversal vulnerability
10465| [20695] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (4)
10466| [20694] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (3)
10467| [20693] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (2)
10468| [20692] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (1)
10469| [20595] NCSA 1.3/1.4.x/1.5,Apache httpd 0.8.11/0.8.14 ScriptAlias Source Retrieval Vulnerability
10470| [20558] Apache 1.2 Web Server DoS Vulnerability
10471| [20466] Apache 1.3 Web Server with Php 3 File Disclosure Vulnerability
10472| [20435] Apache 0.8.x/1.0.x,NCSA httpd 1.x test-cgi Directory Listing Vulnerability
10473| [20272] Apache 1.2.5/1.3.1,UnityMail 2.0 MIME Header DoS Vulnerability
10474| [20210] Apache 1.3.12 WebDAV Directory Listings Vulnerability
10475| [20131] Apache Tomcat 3.1 Path Revealing Vulnerability
10476| [19975] Apache 1.3.6/1.3.9/1.3.11/1.3.12/1.3.20 Root Directory Access Vulnerability
10477| [19828] Cobalt RaQ 2.0/3.0 Apache .htaccess Disclosure Vulnerability
10478| [19536] Apache <= 1.1,NCSA httpd <= 1.5.2,Netscape Server 1.12/1.1/2.0 a nph-test-cgi Vulnerability
10479| [19231] PHP apache_request_headers Function Buffer Overflow
10480| [18984] Apache Struts <= 2.2.1.1 - Remote Command Execution
10481| [18897] Oracle Weblogic Apache Connector POST Request Buffer Overflow
10482| [18619] Apache Tomcat Remote Exploit (PUT Request) and Account Scanner
10483| [18452] Apache Struts Multiple Persistent Cross-Site Scripting Vulnerabilities
10484| [18442] Apache httpOnly Cookie Disclosure
10485| [18329] Apache Struts2 <= 2.3.1 - Multiple Vulnerabilities
10486| [18221] Apache HTTP Server Denial of Service
10487| [17969] Apache mod_proxy Reverse Proxy Exposure Vulnerability PoC
10488| [17696] Apache httpd Remote Denial of Service (memory exhaustion)
10489| [17691] Apache Struts < 2.2.0 - Remote Command Execution
10490| [16798] Apache mod_jk 1.2.20 Buffer Overflow
10491| [16782] Apache Win32 Chunked Encoding
10492| [16752] Apache module mod_rewrite LDAP protocol Buffer Overflow
10493| [16317] Apache Tomcat Manager Application Deployer Authenticated Code Execution
10494| [15710] Apache Archiva 1.0 - 1.3.1 CSRF Vulnerability
10495| [15319] Apache 2.2 (Windows) Local Denial of Service
10496| [14617] Apache JackRabbit 2.0.0 webapp XPath Injection
10497| [14489] Apache Tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
10498| [12721] Apache Axis2 1.4.1 - Local File Inclusion Vulnerability
10499| [12689] Authenticated Cross-Site Scripting Vulnerability (XSS) within Apache Axis2 administration console
10500| [12343] Apache Tomcat 5.5.0 to 5.5.29 & 6.0.0 to 6.0.26 - Information Disclosure Vulnerability
10501| [12330] Apache OFBiz - Multiple XSS
10502| [12264] Apache OFBiz - FULLADMIN Creator PoC Payload
10503| [12263] Apache OFBiz - SQL Remote Execution PoC Payload
10504| [11662] Apache Spamassassin Milter Plugin Remote Root Command Execution
10505| [11650] Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit
10506| [10811] Joomla.Tutorials GHDB: Apache directory listing Download Vulnerability
10507| [10292] Apache Tomcat 3.2.1 - 404 Error Page Cross Site Scripting Vulnerability
10508| [9995] Apache Tomcat Form Authentication Username Enumeration Weakness
10509| [9994] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
10510| [9993] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
10511| [8842] Apache mod_dav / svn Remote Denial of Service Exploit
10512| [8458] Apache Geronimo <= 2.1.3 - Multiple Directory Traversal Vulnerabilities
10513| [7264] Apache Tomcat runtime.getRuntime().exec() Privilege Escalation (win)
10514| [6229] apache tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
10515| [6100] Apache mod_jk 1.2.19 Remote Buffer Overflow Exploit (win32)
10516| [6089] Bea Weblogic Apache Connector Code Exec / Denial of Service Exploit
10517| [5386] Apache Tomcat Connector jk2-2.0.2 (mod_jk2) Remote Overflow Exploit
10518| [5330] Apache 2.0 mod_jk2 2.0.2 - Remote Buffer Overflow Exploit (win32)
10519| [4552] Apache Tomcat (webdav) Remote File Disclosure Exploit (ssl support)
10520| [4530] Apache Tomcat (webdav) Remote File Disclosure Exploit
10521| [4162] Apache Tomcat Connector (mod_jk) Remote Exploit (exec-shield)
10522| [4093] Apache mod_jk 1.2.19/1.2.20 Remote Buffer Overflow Exploit
10523| [3996] Apache 2.0.58 mod_rewrite Remote Overflow Exploit (win2k3)
10524| [3680] Apache Mod_Rewrite Off-by-one Remote Overflow Exploit (win32)
10525| [3384] Ubuntu/Debian Apache 1.3.33/1.3.34 (CGI TTY) Local Root Exploit
10526| [2237] Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
10527| [2061] Apache Tomcat < 5.5.17 Remote Directory Listing Vulnerability
10528| [1056] Apache <= 2.0.49 Arbitrary Long HTTP Headers Denial of Service
10529| [855] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit
10530| [764] Apache OpenSSL - Remote Exploit (Multiple Targets) (OpenFuckV2.c)
10531| [587] Apache <= 1.3.31 mod_include Local Buffer Overflow Exploit
10532| [466] htpasswd Apache 1.3.31 - Local Exploit
10533| [371] Apache HTTPd Arbitrary Long HTTP Headers DoS (c version)
10534| [360] Apache HTTPd Arbitrary Long HTTP Headers DoS
10535| [132] Apache 1.3.x - 2.0.48 - mod_userdir Remote Users Disclosure Exploit
10536| [126] Apache mod_gzip (with debug_mode) <= 1.2.26.1a Remote Exploit
10537| [67] Apache 1.3.x mod_mylo Remote Code Execution Exploit
10538| [38] Apache <= 2.0.45 APR Remote Exploit -Apache-Knacker.pl
10539| [34] Webfroot Shoutbox < 2.32 (Apache) Remote Exploit
10540| [11] Apache <= 2.0.44 Linux Remote Denial of Service Exploit
10541| [9] Apache HTTP Server 2.x Memory Leak Exploit
10542|
10543| OpenVAS (Nessus) - http://www.openvas.org:
10544| [902924] Apache Struts2 Showcase Skill Name Remote Code Execution Vulnerability
10545| [902837] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability (Windows)
10546| [902830] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
10547| [902664] Apache Traffic Server HTTP Host Header Denial of Service Vulnerability
10548| [901203] Apache httpd Web Server Range Header Denial of Service Vulnerability
10549| [901110] Apache ActiveMQ Source Code Information Disclosure Vulnerability
10550| [901105] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
10551| [900842] Apache 'mod_proxy_ftp' Module Command Injection Vulnerability (Linux)
10552| [900841] Apache 'mod_proxy_ftp' Module Denial Of Service Vulnerability (Linux)
10553| [900573] Apache APR-Utils XML Parser Denial of Service Vulnerability
10554| [900572] Apache APR-Utils Multiple Denial of Service Vulnerabilities
10555| [900571] Apache APR-Utils Version Detection
10556| [900499] Apache mod_proxy_ajp Information Disclosure Vulnerability
10557| [900496] Apache Tiles Multiple XSS Vulnerability
10558| [900493] Apache Tiles Version Detection
10559| [900107] Apache mod_proxy_ftp Wildcard Characters XSS Vulnerability
10560| [900021] Apache Tomcat Cross-Site Scripting and Security Bypass Vulnerabilities
10561| [880086] CentOS Update for apache CESA-2008:0004-01 centos2 i386
10562| [870175] RedHat Update for apache RHSA-2008:0004-01
10563| [864591] Fedora Update for apache-poi FEDORA-2012-10835
10564| [864383] Fedora Update for apache-commons-compress FEDORA-2012-8428
10565| [864280] Fedora Update for apache-commons-compress FEDORA-2012-8465
10566| [864250] Fedora Update for apache-poi FEDORA-2012-7683
10567| [864249] Fedora Update for apache-poi FEDORA-2012-7686
10568| [863993] Fedora Update for apache-commons-daemon FEDORA-2011-10880
10569| [863466] Fedora Update for apache-commons-daemon FEDORA-2011-10936
10570| [855821] Solaris Update for Apache 1.3 122912-19
10571| [855812] Solaris Update for Apache 1.3 122911-19
10572| [855737] Solaris Update for Apache 1.3 122911-17
10573| [855731] Solaris Update for Apache 1.3 122912-17
10574| [855695] Solaris Update for Apache 1.3 122911-16
10575| [855645] Solaris Update for Apache 1.3 122912-16
10576| [855587] Solaris Update for kernel update and Apache 108529-29
10577| [855566] Solaris Update for Apache 116973-07
10578| [855531] Solaris Update for Apache 116974-07
10579| [855524] Solaris Update for Apache 2 120544-14
10580| [855494] Solaris Update for Apache 1.3 122911-15
10581| [855478] Solaris Update for Apache Security 114145-11
10582| [855472] Solaris Update for Apache Security 113146-12
10583| [855179] Solaris Update for Apache 1.3 122912-15
10584| [855147] Solaris Update for kernel update and Apache 108528-29
10585| [855077] Solaris Update for Apache 2 120543-14
10586| [850196] SuSE Update for apache2 openSUSE-SU-2012:0314-1 (apache2)
10587| [850088] SuSE Update for apache2 SUSE-SA:2007:061
10588| [850009] SuSE Update for apache2,apache SUSE-SA:2008:021
10589| [841209] Ubuntu Update for apache2 USN-1627-1
10590| [840900] Ubuntu Update for apache2 USN-1368-1
10591| [840798] Ubuntu Update for apache2 USN-1259-1
10592| [840734] Ubuntu Update for apache2 USN-1199-1
10593| [840542] Ubuntu Update for apache2 vulnerabilities USN-1021-1
10594| [840504] Ubuntu Update for apache2 vulnerability USN-990-2
10595| [840399] Ubuntu Update for apache2 vulnerabilities USN-908-1
10596| [840304] Ubuntu Update for apache2 vulnerabilities USN-575-1
10597| [840118] Ubuntu Update for libapache2-mod-perl2 vulnerability USN-488-1
10598| [840092] Ubuntu Update for apache2 vulnerabilities USN-499-1
10599| [840039] Ubuntu Update for libapache2-mod-python vulnerability USN-430-1
10600| [835253] HP-UX Update for Apache Web Server HPSBUX02645
10601| [835247] HP-UX Update for Apache-based Web Server HPSBUX02612
10602| [835243] HP-UX Update for Apache Running Tomcat Servlet Engine HPSBUX02579
10603| [835236] HP-UX Update for Apache with PHP HPSBUX02543
10604| [835233] HP-UX Update for Apache-based Web Server HPSBUX02531
10605| [835224] HP-UX Update for Apache-based Web Server HPSBUX02465
10606| [835200] HP-UX Update for Apache Web Server Suite HPSBUX02431
10607| [835190] HP-UX Update for Apache Web Server Suite HPSBUX02401
10608| [835188] HP-UX Update for Apache HPSBUX02308
10609| [835181] HP-UX Update for Apache With PHP HPSBUX02332
10610| [835180] HP-UX Update for Apache with PHP HPSBUX02342
10611| [835172] HP-UX Update for Apache HPSBUX02365
10612| [835168] HP-UX Update for Apache HPSBUX02313
10613| [835148] HP-UX Update for Apache HPSBUX01064
10614| [835139] HP-UX Update for Apache with PHP HPSBUX01090
10615| [835131] HP-UX Update for Apache HPSBUX00256
10616| [835119] HP-UX Update for Apache Remote Execution of Arbitrary Code HPSBUX02186
10617| [835104] HP-UX Update for Apache HPSBUX00224
10618| [835103] HP-UX Update for Apache mod_cgid HPSBUX00301
10619| [835101] HP-UX Update for Apache HPSBUX01232
10620| [835080] HP-UX Update for Apache HPSBUX02273
10621| [835078] HP-UX Update for ApacheStrong HPSBUX00255
10622| [835044] HP-UX Update for Apache HPSBUX01019
10623| [835040] HP-UX Update for Apache PHP HPSBUX00207
10624| [835025] HP-UX Update for Apache HPSBUX00197
10625| [835023] HP-UX Update for Apache HPSBUX01022
10626| [835022] HP-UX Update for Apache HPSBUX02292
10627| [835005] HP-UX Update for Apache HPSBUX02262
10628| [831759] Mandriva Update for apache-mod_security MDVSA-2012:182 (apache-mod_security)
10629| [831737] Mandriva Update for apache MDVSA-2012:154-1 (apache)
10630| [831534] Mandriva Update for apache MDVSA-2012:012 (apache)
10631| [831523] Mandriva Update for apache MDVSA-2012:003 (apache)
10632| [831491] Mandriva Update for apache MDVSA-2011:168 (apache)
10633| [831460] Mandriva Update for apache MDVSA-2011:144 (apache)
10634| [831449] Mandriva Update for apache MDVSA-2011:130 (apache)
10635| [831357] Mandriva Update for apache MDVSA-2011:057 (apache)
10636| [831132] Mandriva Update for apache MDVSA-2010:153 (apache)
10637| [831131] Mandriva Update for apache MDVSA-2010:152 (apache)
10638| [830989] Mandriva Update for apache-mod_auth_shadow MDVSA-2010:081 (apache-mod_auth_shadow)
10639| [830931] Mandriva Update for apache MDVSA-2010:057 (apache)
10640| [830926] Mandriva Update for apache MDVSA-2010:053 (apache)
10641| [830918] Mandriva Update for apache-mod_security MDVSA-2010:050 (apache-mod_security)
10642| [830799] Mandriva Update for apache-conf MDVSA-2009:300-2 (apache-conf)
10643| [830797] Mandriva Update for apache-conf MDVSA-2009:300-1 (apache-conf)
10644| [830791] Mandriva Update for apache-conf MDVA-2010:011 (apache-conf)
10645| [830652] Mandriva Update for apache MDVSA-2008:195 (apache)
10646| [830621] Mandriva Update for apache-conf MDVA-2008:129 (apache-conf)
10647| [830581] Mandriva Update for apache MDVSA-2008:016 (apache)
10648| [830294] Mandriva Update for apache MDKSA-2007:140 (apache)
10649| [830196] Mandriva Update for apache MDKSA-2007:235 (apache)
10650| [830112] Mandriva Update for apache MDKSA-2007:127 (apache)
10651| [830109] Mandriva Update for apache-mod_perl MDKSA-2007:083 (apache-mod_perl)
10652| [802425] Apache Struts2 Showcase Arbitrary Java Method Execution vulnerability
10653| [802423] Apache Struts CookBook/Examples Multiple Cross-Site Scripting Vulnerabilities
10654| [802422] Apache Struts Showcase Multiple Persistence Cross-Site Scripting Vulnerabilities
10655| [802415] Apache Tomcat Multiple Security Bypass Vulnerabilities (Win)
10656| [802385] Apache Tomcat Request Object Security Bypass Vulnerability (Win)
10657| [802384] Apache Tomcat Parameter Handling Denial of Service Vulnerability (Win)
10658| [802378] Apache Tomcat Hash Collision Denial Of Service Vulnerability
10659| [801942] Apache Archiva Multiple Vulnerabilities
10660| [801940] Apache Struts2 'XWork' Information Disclosure Vulnerability
10661| [801663] Apache Struts2/XWork Remote Command Execution Vulnerability
10662| [801521] Apache APR-util 'buckets/apr_brigade.c' Denial Of Service Vulnerability
10663| [801284] Apache Derby Information Disclosure Vulnerability
10664| [801203] Apache ActiveMQ Persistent Cross-Site Scripting Vulnerability
10665| [800837] Apache 'mod_deflate' Denial Of Service Vulnerability - July09
10666| [800827] Apache 'mod_proxy_http.c' Denial Of Service Vulnerability
10667| [800680] Apache APR Version Detection
10668| [800679] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
10669| [800678] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
10670| [800677] Apache Roller Version Detection
10671| [800279] Apache mod_jk Module Version Detection
10672| [800278] Apache Struts Cross Site Scripting Vulnerability
10673| [800277] Apache Tomcat mod_jk Information Disclosure Vulnerability
10674| [800276] Apache Struts Version Detection
10675| [800271] Apache Struts Directory Traversal Vulnerability
10676| [800024] Apache Tomcat RemoteFilterValve Security Bypass Vulnerability
10677| [103333] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
10678| [103293] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
10679| [103122] Apache Web Server ETag Header Information Disclosure Weakness
10680| [103074] Apache Continuum Cross Site Scripting Vulnerability
10681| [103073] Apache Continuum Detection
10682| [103053] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
10683| [101023] Apache Open For Business Weak Password security check
10684| [101020] Apache Open For Business HTML injection vulnerability
10685| [101019] Apache Open For Business service detection
10686| [100924] Apache Archiva Cross Site Request Forgery Vulnerability
10687| [100923] Apache Archiva Detection
10688| [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
10689| [100814] Apache Axis2 Document Type Declaration Processing Security Vulnerability
10690| [100813] Apache Axis2 Detection
10691| [100797] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
10692| [100795] Apache Derby Detection
10693| [100762] Apache CouchDB Cross Site Request Forgery Vulnerability
10694| [100725] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
10695| [100613] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
10696| [100514] Apache Multiple Security Vulnerabilities
10697| [100211] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
10698| [100172] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
10699| [100171] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
10700| [100130] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
10701| [72626] Debian Security Advisory DSA 2579-1 (apache2)
10702| [72612] FreeBSD Ports: apache22
10703| [71551] Gentoo Security Advisory GLSA 201206-25 (apache)
10704| [71550] Gentoo Security Advisory GLSA 201206-24 (apache tomcat)
10705| [71512] FreeBSD Ports: apache
10706| [71485] Debian Security Advisory DSA 2506-1 (libapache-mod-security)
10707| [71256] Debian Security Advisory DSA 2452-1 (apache2)
10708| [71238] Debian Security Advisory DSA 2436-1 (libapache2-mod-fcgid)
10709| [70737] FreeBSD Ports: apache
10710| [70724] Debian Security Advisory DSA 2405-1 (apache2)
10711| [70600] FreeBSD Ports: apache
10712| [70253] FreeBSD Ports: apache, apache-event, apache-itk, apache-peruser, apache-worker
10713| [70235] Debian Security Advisory DSA 2298-2 (apache2)
10714| [70233] Debian Security Advisory DSA 2298-1 (apache2)
10715| [69988] Debian Security Advisory DSA 2279-1 (libapache2-mod-authnz-external)
10716| [69338] Debian Security Advisory DSA 2202-1 (apache2)
10717| [67868] FreeBSD Ports: apache
10718| [66816] FreeBSD Ports: apache
10719| [66553] Mandriva Security Advisory MDVSA-2009:189-1 (apache-mod_auth_mysql)
10720| [66414] Mandriva Security Advisory MDVSA-2009:323 (apache)
10721| [66106] SuSE Security Advisory SUSE-SA:2009:050 (apache2,libapr1)
10722| [66081] SLES11: Security update for Apache 2
10723| [66074] SLES10: Security update for Apache 2
10724| [66070] SLES9: Security update for Apache 2
10725| [65998] SLES10: Security update for apache2-mod_python
10726| [65893] SLES10: Security update for Apache 2
10727| [65888] SLES10: Security update for Apache 2
10728| [65575] SLES9: Security update for apache2,apache2-prefork,apache2-worker
10729| [65510] SLES9: Security update for Apache 2
10730| [65472] SLES9: Security update for Apache
10731| [65467] SLES9: Security update for Apache
10732| [65450] SLES9: Security update for apache2
10733| [65390] SLES9: Security update for Apache2
10734| [65363] SLES9: Security update for Apache2
10735| [65309] SLES9: Security update for Apache and mod_ssl
10736| [65296] SLES9: Security update for webdav apache module
10737| [65283] SLES9: Security update for Apache2
10738| [65249] SLES9: Security update for Apache 2
10739| [65230] SLES9: Security update for Apache 2
10740| [65228] SLES9: Security update for Apache 2
10741| [65212] SLES9: Security update for apache2-mod_python
10742| [65209] SLES9: Security update for apache2-worker
10743| [65207] SLES9: Security update for Apache 2
10744| [65168] SLES9: Security update for apache2-mod_python
10745| [65142] SLES9: Security update for Apache2
10746| [65136] SLES9: Security update for Apache 2
10747| [65132] SLES9: Security update for apache
10748| [65131] SLES9: Security update for Apache 2 oes/CORE
10749| [65113] SLES9: Security update for apache2
10750| [65072] SLES9: Security update for apache and mod_ssl
10751| [65017] SLES9: Security update for Apache 2
10752| [64950] Mandrake Security Advisory MDVSA-2009:240 (apache)
10753| [64783] FreeBSD Ports: apache
10754| [64774] Ubuntu USN-802-2 (apache2)
10755| [64653] Ubuntu USN-813-2 (apache2)
10756| [64559] Debian Security Advisory DSA 1834-2 (apache2)
10757| [64532] Mandrake Security Advisory MDVSA-2009:189 (apache-mod_auth_mysql)
10758| [64527] Mandrake Security Advisory MDVSA-2009:184 (apache-mod_security)
10759| [64526] Mandrake Security Advisory MDVSA-2009:183 (apache-mod_security)
10760| [64500] Mandrake Security Advisory MDVSA-2009:168 (apache)
10761| [64443] Ubuntu USN-802-1 (apache2)
10762| [64426] Gentoo Security Advisory GLSA 200907-04 (apache)
10763| [64423] Debian Security Advisory DSA 1834-1 (apache2)
10764| [64391] Mandrake Security Advisory MDVSA-2009:149 (apache)
10765| [64377] Mandrake Security Advisory MDVSA-2009:124-1 (apache)
10766| [64251] Debian Security Advisory DSA 1816-1 (apache2)
10767| [64201] Ubuntu USN-787-1 (apache2)
10768| [64140] Mandrake Security Advisory MDVSA-2009:124 (apache)
10769| [64136] Mandrake Security Advisory MDVSA-2009:102 (apache)
10770| [63565] FreeBSD Ports: apache
10771| [63562] Ubuntu USN-731-1 (apache2)
10772| [61381] Gentoo Security Advisory GLSA 200807-06 (apache)
10773| [61185] FreeBSD Ports: apache
10774| [60582] Gentoo Security Advisory GLSA 200803-19 (apache)
10775| [60387] Slackware Advisory SSA:2008-045-02 apache
10776| [58826] FreeBSD Ports: apache-tomcat
10777| [58825] FreeBSD Ports: apache-tomcat
10778| [58804] FreeBSD Ports: apache
10779| [58745] Gentoo Security Advisory GLSA 200711-06 (apache)
10780| [58360] Debian Security Advisory DSA 1312-1 (libapache-mod-jk)
10781| [57851] Gentoo Security Advisory GLSA 200608-01 (apache)
10782| [57788] Debian Security Advisory DSA 1247-1 (libapache-mod-auth-kerb)
10783| [57335] Debian Security Advisory DSA 1167-1 (apache)
10784| [57201] Debian Security Advisory DSA 1131-1 (apache)
10785| [57200] Debian Security Advisory DSA 1132-1 (apache2)
10786| [57168] Slackware Advisory SSA:2006-209-01 Apache httpd
10787| [57145] FreeBSD Ports: apache
10788| [56731] Slackware Advisory SSA:2006-129-01 Apache httpd
10789| [56729] Slackware Advisory SSA:2006-130-01 Apache httpd redux
10790| [56246] Gentoo Security Advisory GLSA 200602-03 (Apache)
10791| [56212] Debian Security Advisory DSA 952-1 (libapache-auth-ldap)
10792| [56115] Debian Security Advisory DSA 935-1 (libapache2-mod-auth-pgsql)
10793| [56067] FreeBSD Ports: apache
10794| [55803] Slackware Advisory SSA:2005-310-04 apache
10795| [55519] Debian Security Advisory DSA 839-1 (apachetop)
10796| [55392] Gentoo Security Advisory GLSA 200509-12 (Apache)
10797| [55355] FreeBSD Ports: apache
10798| [55284] Debian Security Advisory DSA 807-1 (libapache-mod-ssl)
10799| [55261] Debian Security Advisory DSA 805-1 (apache2)
10800| [55259] Debian Security Advisory DSA 803-1 (apache)
10801| [55129] Gentoo Security Advisory GLSA 200508-15 (apache)
10802| [54739] Gentoo Security Advisory GLSA 200411-18 (apache)
10803| [54724] Gentoo Security Advisory GLSA 200411-03 (apache)
10804| [54712] Gentoo Security Advisory GLSA 200410-21 (apache)
10805| [54689] Gentoo Security Advisory GLSA 200409-33 (net=www/apache)
10806| [54677] Gentoo Security Advisory GLSA 200409-21 (apache)
10807| [54610] Gentoo Security Advisory GLSA 200407-03 (Apache)
10808| [54601] Gentoo Security Advisory GLSA 200406-16 (Apache)
10809| [54590] Gentoo Security Advisory GLSA 200406-05 (Apache)
10810| [54582] Gentoo Security Advisory GLSA 200405-22 (Apache)
10811| [54529] Gentoo Security Advisory GLSA 200403-04 (Apache)
10812| [54499] Gentoo Security Advisory GLSA 200310-04 (Apache)
10813| [54498] Gentoo Security Advisory GLSA 200310-03 (Apache)
10814| [54439] FreeBSD Ports: apache
10815| [53931] Slackware Advisory SSA:2004-133-01 apache
10816| [53903] Slackware Advisory SSA:2004-299-01 apache, mod_ssl, php
10817| [53902] Slackware Advisory SSA:2004-305-01 apache+mod_ssl
10818| [53878] Slackware Advisory SSA:2003-308-01 apache security update
10819| [53851] Debian Security Advisory DSA 135-1 (libapache-mod-ssl)
10820| [53849] Debian Security Advisory DSA 132-1 (apache-ssl)
10821| [53848] Debian Security Advisory DSA 131-1 (apache)
10822| [53784] Debian Security Advisory DSA 021-1 (apache)
10823| [53738] Debian Security Advisory DSA 195-1 (apache-perl)
10824| [53737] Debian Security Advisory DSA 188-1 (apache-ssl)
10825| [53735] Debian Security Advisory DSA 187-1 (apache)
10826| [53703] Debian Security Advisory DSA 532-1 (libapache-mod-ssl)
10827| [53577] Debian Security Advisory DSA 120-1 (libapache-mod-ssl, apache-ssl)
10828| [53568] Debian Security Advisory DSA 067-1 (apache,apache-ssl)
10829| [53519] Debian Security Advisory DSA 689-1 (libapache-mod-python)
10830| [53433] Debian Security Advisory DSA 181-1 (libapache-mod-ssl)
10831| [53282] Debian Security Advisory DSA 594-1 (apache)
10832| [53248] Debian Security Advisory DSA 558-1 (libapache-mod-dav)
10833| [53224] Debian Security Advisory DSA 532-2 (libapache-mod-ssl)
10834| [53215] Debian Security Advisory DSA 525-1 (apache)
10835| [53151] Debian Security Advisory DSA 452-1 (libapache-mod-python)
10836| [52529] FreeBSD Ports: apache+ssl
10837| [52501] FreeBSD Ports: apache
10838| [52461] FreeBSD Ports: apache
10839| [52390] FreeBSD Ports: apache
10840| [52389] FreeBSD Ports: apache
10841| [52388] FreeBSD Ports: apache
10842| [52383] FreeBSD Ports: apache
10843| [52339] FreeBSD Ports: apache+mod_ssl
10844| [52331] FreeBSD Ports: apache
10845| [52329] FreeBSD Ports: ru-apache+mod_ssl
10846| [52314] FreeBSD Ports: apache
10847| [52310] FreeBSD Ports: apache
10848| [15588] Detect Apache HTTPS
10849| [15555] Apache mod_proxy content-length buffer overflow
10850| [15554] Apache mod_include priviledge escalation
10851| [14771] Apache <= 1.3.33 htpasswd local overflow
10852| [14177] Apache mod_access rule bypass
10853| [13644] Apache mod_rootme Backdoor
10854| [12293] Apache Input Header Folding and mod_ssl ssl_io_filter_cleanup DoS Vulnerabilities
10855| [12280] Apache Connection Blocking Denial of Service
10856| [12239] Apache Error Log Escape Sequence Injection
10857| [12123] Apache Tomcat source.jsp malformed request information disclosure
10858| [12085] Apache Tomcat servlet/JSP container default files
10859| [11438] Apache Tomcat Directory Listing and File disclosure
10860| [11204] Apache Tomcat Default Accounts
10861| [11092] Apache 2.0.39 Win32 directory traversal
10862| [11046] Apache Tomcat TroubleShooter Servlet Installed
10863| [11042] Apache Tomcat DOS Device Name XSS
10864| [11041] Apache Tomcat /servlet Cross Site Scripting
10865| [10938] Apache Remote Command Execution via .bat files
10866| [10839] PHP.EXE / Apache Win32 Arbitrary File Reading Vulnerability
10867| [10773] MacOS X Finder reveals contents of Apache Web files
10868| [10766] Apache UserDir Sensitive Information Disclosure
10869| [10756] MacOS X Finder reveals contents of Apache Web directories
10870| [10752] Apache Auth Module SQL Insertion Attack
10871| [10704] Apache Directory Listing
10872| [10678] Apache /server-info accessible
10873| [10677] Apache /server-status accessible
10874| [10440] Check for Apache Multiple / vulnerability
10875|
10876| SecurityTracker - https://www.securitytracker.com:
10877| [1028865] Apache Struts Bugs Permit Remote Code Execution and URL Redirection Attacks
10878| [1028864] Apache Struts Wildcard Matching and Expression Evaluation Bugs Let Remote Users Execute Arbitrary Code
10879| [1028824] Apache mod_dav_svn URI Processing Flaw Lets Remote Users Deny Service
10880| [1028823] Apache Unspecified Flaw in mod_session_dbd Has Unspecified Impact
10881| [1028724] (HP Issues Fix for HP-UX) Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
10882| [1028722] (Red Hat Issues Fix for JBoss) Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
10883| [1028693] (Red Hat Issues Fix) Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
10884| [1028622] Apache Struts 'includeParams' Bugs Permit Remote Command Execution and Cross-Site Scripting Attacks
10885| [1028621] Apache Subversion Bugs Let Remote Authenticated Users Execute Arbitrary Commands and Deny Service
10886| [1028540] Apache mod_rewrite Input Validation Flaw Lets Remote Users Execute Arbitrary Commands
10887| [1028534] Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
10888| [1028533] Apache Tomcat Lack of Chunked Transfer Encoding Extension Size Limit Lets Remote Users Deny Service
10889| [1028532] Apache Tomcat AsyncListeners Bug May Disclose Information from One Request to Another User
10890| [1028515] Apache VCL Input Validation Flaw Lets Remote Authenticated Users Gain Elevated Privileges
10891| [1028457] Apache ActiveMQ Bugs Let Remote Users Conduct Cross-Site Scripting Attacks, Deny Service, and Obtain Potentially Sensitive Information
10892| [1028287] Apache CXF WSS4JInInterceptor Grants Service Access to Remote Users
10893| [1028286] Apache CXF WS-Security UsernameToken Processing Flaw Lets Remote Users Bypass Authentication
10894| [1028252] Apache Commons FileUpload Unsafe Temporary File Lets Local Users Gain Elevated Privileges
10895| [1028207] Apache Input Validation Bugs Permit Cross-Site Scripting Attacks
10896| [1027836] Apache Tomcat Connection Processing Bug Lets Remote Users Deny Service
10897| [1027834] Apache Tomcat Bug Lets Remote Users Bypass Cross-Site Request Forgery Prevention Filter
10898| [1027833] Apache Tomcat Bug Lets Remote Users Bypass Security Constraints
10899| [1027729] Apache Tomcat Header Processing Bug Lets Remote Users Deny Service
10900| [1027728] Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
10901| [1027554] Apache CXF Lets Remote Authenticated Users Execute Unauthorized SOAP Actions
10902| [1027508] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
10903| [1027421] Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
10904| [1027096] Apache Commons Compress BZip2CompressorOutputStream() Sorting Algorithm Lets Remote or Local Users Deny Service
10905| [1026932] Apache LD_LIBRARY_PATH Processing Lets Local Users Gain Elevated Privileges
10906| [1026928] Apache OFBiz Unspecified Flaw Lets Remote Users Execute Arbitrary Code
10907| [1026927] Apache OFBiz Input Validation Flaws Permit Cross-Site Scripting Attacks
10908| [1026847] Apache Traffic Server Host Header Processing Flaw Lets Remote Users Deny Service
10909| [1026846] Apache Wicket Discloses Hidden Application Files to Remote Users
10910| [1026839] Apache Wicket Input Validation Flaw in 'wicket:pageMapName' Parameter Permits Cross-Site Scripting Attacks
10911| [1026616] Apache Bugs Let Remote Users Deny Service and Obtain Cookie Data
10912| [1026575] Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
10913| [1026484] Apache Struts Bug Lets Remote Users Overwrite Files and Execute Arbitrary Code
10914| [1026477] Apache Tomcat Hash Table Collision Bug Lets Remote Users Deny Service
10915| [1026402] Apache Struts Conversion Error Lets Remote Users Inject Arbitrary Commands
10916| [1026353] Apache mod_proxy/mod_rewrite Bug Lets Remote Users Access Internal Servers
10917| [1026295] Apache Tomcat Lets Untrusted Web Applications Gain Elevated Privileges
10918| [1026267] Apache .htaccess File Integer Overflow Lets Local Users Execute Arbitrary Code
10919| [1026144] Apache mod_proxy Pattern Matching Bug Lets Remote Users Access Internal Servers
10920| [1026095] Apache Tomcat HTTP DIGEST Authentication Weaknesses Let Remote Users Conduct Bypass Attacks
10921| [1026054] Apache mod_proxy_ajp HTTP Processing Error Lets Remote Users Deny Service
10922| [1025993] Apache Tomcat AJP Protocol Processing Bug Lets Remote Users Bypass Authentication or Obtain Information
10923| [1025976] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
10924| [1025960] Apache httpd Byterange Filter Processing Error Lets Remote Users Deny Service
10925| [1025925] Apache Tomcat Commons Daemon jsvc Lets Local Users Gain Elevated Privileges
10926| [1025924] Apache Tomcat XML Validation Flaw Lets Applications Obtain Potentially Sensitive Information
10927| [1025788] Apache Tomcat Lets Malicious Applications Obtain Information and Deny Service
10928| [1025755] Apache Santuario Buffer Overflow Lets Remote Users Deny Service
10929| [1025712] Apache Tomcat Discloses Passwords to Local Users in Certain Cases
10930| [1025577] Apache Archiva Input Validation Hole Permits Cross-Site Scripting Attacks
10931| [1025576] Apache Archiva Request Validation Flaw Permits Cross-Site Request Forgery Attacks
10932| [1025527] Apache APR Library apr_fnmatch() Flaw Lets Remote Users Execute Arbitrary Code
10933| [1025303] Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
10934| [1025215] Apache Tomcat May Ignore @ServletSecurity Annotation Protections
10935| [1025066] Apache Continuum Input Validation Flaw Permits Cross-Site Request Forgery Attacks
10936| [1025065] Apache Continuum Input Validation Hole Permits Cross-Site Scripting Attacks
10937| [1025027] Apache Tomcat maxHttpHeaderSize Parsing Error Lets Remote Users Deny Service
10938| [1025026] Apache Tomcat Manager Input Validation Hole Permits Cross-Site Scripting Attacks
10939| [1025025] Apache Tomcat Security Manager Lets Local Users Bypass File Permissions
10940| [1024764] Apache Tomcat Manager Input Validation Hole in 'sessionList.jsp' Permits Cross-Site Scripting Attacks
10941| [1024417] Apache Traffic Server Insufficient Randomization Lets Remote Users Poison the DNS Cache
10942| [1024332] Apache mod_cache and mod_dav Request Processing Flaw Lets Remote Users Deny Service
10943| [1024180] Apache Tomcat 'Transfer-Encoding' Header Processing Flaw Lets Remote Users Deny Service and Obtain Potentially Sensitive Information
10944| [1024096] Apache mod_proxy_http May Return Results for a Different Request
10945| [1023942] Apache mod_proxy_ajp Error Condition Lets Remote Users Deny Service
10946| [1023941] Apache ap_read_request() Memory Error May Let Remote Users Access Potentially Sensitive Information
10947| [1023778] Apache ActiveMQ Input Validation Flaw Permits Cross-Site Scripting Attacks
10948| [1023701] Apache mod_isapi Error Processing Flaw May Let Remote Users Deny Service
10949| [1023533] Apache mod_proxy Integer Overflow May Let Remote Users Execute Arbitrary Code
10950| [1022988] Apache Solaris Support Code Bug Lets Remote Users Deny Service
10951| [1022529] Apache mod_deflate Connection State Bug Lets Remote Users Deny Service
10952| [1022509] Apache mod_proxy stream_reqbody_cl() Infinite Loop Lets Remote Users Deny Service
10953| [1022296] Apache IncludesNoExec Options Restrictions Can Be Bypass By Local Users
10954| [1022264] Apache mod_proxy_ajp Bug May Disclose Another User's Response Data
10955| [1022001] Apache Tomcat mod_jk May Disclose Responses to the Wrong User
10956| [1021988] mod_perl Input Validation Flaw in Apache::Status and Apache2::Status Permits Cross-Site Scripting Attacks
10957| [1021350] NetWare Bug Lets Remote Users Access the ApacheAdmin Console
10958| [1020635] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
10959| [1020520] Oracle WebLogic Apache Connector Lets Remote Users Execute Arbitrary Code
10960| [1020267] Apache mod_proxy Interim Response Process Bug Lets Remote Users Deny Service
10961| [1019784] Apache-SSL Certificate Processing Bug May Let Remote Users View Portions of Kernel Memory
10962| [1019256] Apache mod_negotiation Input Validation Hole Permits Cross-Site Scripting Attacks
10963| [1019194] Apache Input Validation Hole in Mod_AutoIndex When the Character Set is Undefined May Permit Cross-Site Scripting Attacks
10964| [1019185] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
10965| [1019154] Apache Input Validation Hole in mod_status Permits Cross-Site Scripting Attacks
10966| [1019093] Apache Input Validation Hole in mod_imap Permits Cross-Site Scripting Attacks
10967| [1019030] Apache Input Validation Hole in Default HTTP 413 Error Page Permits Cross-Site Scripting Attacks
10968| [1018633] Apache mod_proxy Bug Lets Remote Users Deny Service
10969| [1018304] Apache HTTPD scoreboard Protection Flaw Lets Local Users Terminate Arbitrary Processes
10970| [1018303] Apache HTTPD mod_cache May Let Remote Users Deny Service
10971| [1018302] Apache mod_status Input Validation Hole Permits Cross-Site Scripting Attacks
10972| [1018269] Apache Tomcat Input Validation Hole in Processing Accept-Language Header Permits Cross-Site Scripting Attacks
10973| [1017904] Apache suEXEC Bugs May Let Local Users Gain Elevated Privileges
10974| [1017719] Apache Tomcat JK Web Server Connector Buffer Overflow in map_uri_to_worker() Lets Remote Users Execute Arbitrary Code
10975| [1017062] Apache mod_tcl Format String Bug in set_var() Function May Let Remote Users Execute Arbitrary Code
10976| [1016601] Apache mod_rewrite Off-by-one Error Lets Remote Users Execute Arbitrary Code
10977| [1016576] Apache Tomcat Discloses Directory Listings to Remote Users
10978| [1015447] Apache mod_ssl Null Pointer Dereference May Let Remote Users Deny Service
10979| [1015344] Apache mod_imap Input Validation Flaw in Referer Field Lets Remote Users Conduct Cross-Site Scripting Attacks
10980| [1015093] Apache Memory Leak in MPM 'worker.c' Code May Let Remote Users Deny Service
10981| [1014996] ApacheTop Unsafe Temporary File May Let Local Users Gain Elevated Privileges
10982| [1014833] Apache ssl_hook_Access() Function May Fail to Verify Client Certificates
10983| [1014826] Apache Memory Leak in 'byterange filter' Lets Remote Users Deny Service
10984| [1014575] Apache mod_ssl Off-by-one Buffer Overflow in Processing CRLs May Let Remote Users Deny Service
10985| [1014323] Apache Chunked Transfer-Encoding and Content-Length Processing Lets Remote Users Smuggle HTTP Requests
10986| [1013156] Apache mod_python Publisher Handler Discloses Information to Remote Users
10987| [1012829] Apache mod_auth_radius radcpy() Integer Overflow Lets Remote Users Deny Service in Certain Cases
10988| [1012416] Apache on Apple OS X Lets Remote Users Bypass Apache File Handlers and Directly Access Files
10989| [1012415] Apache on Apple HFS+ Filesystems May Disclose '.DS_Store' Files to Remote Users
10990| [1012414] Apache mod_digest_apple Lets Remote Users Replay Authentication Credentials
10991| [1012083] Apache Web Server Error in Processing Requests With Many Space Characters Lets Remote Users Deny Service
10992| [1011783] Apache mod_include Buffer Overflow Lets Local Users Execute Arbitrary Code
10993| [1011557] Apache mod_ssl SSLCipherSuite Directive Can By Bypassed in Certain Cases
10994| [1011385] Apache Satsify Directive Error May Let Remote Users Access Restricted Resources
10995| [1011340] Apache SSL Connection Abort State Error Lets Remote Users Deny Service
10996| [1011303] Apache ap_resolve_env() Buffer Overflow in Reading Configuration Files May Let Local Users Gain Elevated Privileges
10997| [1011299] Apache IPv6 Address Parsing Flaw May Let Remote Users Deny Service
10998| [1011248] Apache mod_dav LOCK Method Error May Let Remote Users Deny Service
10999| [1011213] Apache mod_ssl Can Be Crashed By Remote Users When Reverse Proxying SSL Connections
11000| [1010674] Apache Can Be Crashed By PHP Code Invoking Nested Remote Sockets
11001| [1010599] Apache httpd Header Line Memory Allocation Lets Remote Users Crash the Server
11002| [1010462] Apache mod_proxy Buffer Overflow May Let Remote Users Execute Arbitrary Code
11003| [1010322] Apache mod_ssl Stack Overflow in ssl_util_uuencode_binary() May Let Remote Users Execute Arbitrary Code
11004| [1010270] cPanel Apache mod_phpsuexec Options Let Local Users Gain Elevated Privileges
11005| [1009934] Apache Web Server Has Buffer Overflow in ebcdic2ascii() on Older Processor Architectures
11006| [1009516] Apache mod_survey HTML Report Format Lets Remote Users Conduct Cross-Site Scripting Attacks
11007| [1009509] Apache mod_disk_cache Stores Authentication Credentials on Disk
11008| [1009495] Apache Web Server Socket Starvation Flaw May Let Remote Users Deny Service
11009| [1009417] GroupWise WebAccess With Apache on NetWare Has Configuration Flaw That May Grant Web Access to Remote Users
11010| [1009338] Apache mod_access Parsing Flaw May Fail to Enforce Allow/Deny Rules
11011| [1009337] Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon
11012| [1009182] Apache for Cygwin '..%5C' Input Validation Flaw Discloses Files to Remote Users
11013| [1008973] PHP May Apply Incorrect php_admin_* Settings To Requests for Apache Virtual Hosts
11014| [1008967] Apache-SSL 'SSLFakeBasicAuth' Lets Remote Users Forge Client Certificates to Be Authenticated
11015| [1008920] Apache mod_digest May Validate Replayed Client Responses
11016| [1008828] Apache mod_python String Processing Bug Still Lets Remote Users Crash the Web Server
11017| [1008822] Apache mod_perl File Descriptor Leak May Let Local Users Hijack the http and https Services
11018| [1008675] mod_auth_shadow Apache Module Authenticates Expired Passwords
11019| [1008559] Apache mod_php File Descriptor Leak May Let Local Users Hijack the https Service
11020| [1008335] Apache mod_python String Processing Bug Lets Remote Users Crash the Web Server
11021| [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
11022| [1008030] Apache mod_rewrite Contains a Buffer Overflow
11023| [1008029] Apache mod_alias Contains a Buffer Overflow
11024| [1008028] Apache mod_cgid May Disclose CGI Output to Another Client
11025| [1007995] Apache Cocoon Forms May Let Remote Users Execute Arbitrary Java Code on the System
11026| [1007993] Apache Cocoon 'view-source' Sample Script Discloses Files to Remote Users
11027| [1007823] Apache Web Server mod_cgi Error May Let Malicious CGI Scripts Crash the Web Service
11028| [1007664] Apache::Gallery Unsafe Temporary Files May Let Local Users Gain Apache Web Server Privileges
11029| [1007557] Apache Web Server Does Not Filter Terminal Escape Sequences From Log Files
11030| [1007230] Apache HTTP Server 'rotatelogs' Bug on Win32 and OS/2 May Cause the Logging to Stop
11031| [1007146] Apache HTTP Server FTP Proxy Bug May Cause Denial of Service Conditions
11032| [1007145] Apache 'accept()' Errors May Cause Denial of Service Conditions
11033| [1007144] Apache Web Server 'type-map' File Error Permits Local Denial of Service Attacks
11034| [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
11035| [1006864] Apache Web Server Can Be Crashed By Remote Users Via mod_dav Flaws and Also Via Basic Authentication
11036| [1006709] Apache mod_survey Input Validation Flaw Lets Remote Users Fill Up Disk Space
11037| [1006614] Apache mod_ntlm Buffer Overflow and Format String Flaw Let Remote Users Execute Arbitary Code
11038| [1006591] Apache mod_access_referer Module Null Pointer Dereference May Faciliate Denial of Service Attacks
11039| [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
11040| [1006021] Apache Tomcat Server URL Parsing Error May Disclose Otherwise Inaccessible Web Directory Listings and Files to Remote Users
11041| [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
11042| [1005962] Apache Web Server Path Parsing Flaw May Allow Remote Users to Execute Code in Certain Configurations
11043| [1005848] Apache 'printenv' Script Input Validation Bugs in Older Versions May Let Remote Users Conduct Cross-Site Scripting Attacks
11044| [1005765] Apache mod_jk Module Processing Bug When Used With Tomcat May Disclose Information to Remote Users or Crash
11045| [1005548] Apache mod_php Module May Allow Local Users to Gain Control of the Web Port
11046| [1005499] Apache Web Server (2.0.42) May Disclose CGI Source Code to Remote Users When Used With WebDAV
11047| [1005410] Apache Tomcat Java Servlet Engine Can Be Crashed Via Multiple Requests for DOS Device Names
11048| [1005351] Apache Web Server (1.3.x) Shared Memory Scoreboard Bug Lets Certain Local Users Issue Signals With Root Privileges
11049| [1005331] Apache Web Server (2.x) SSI Server Signature Filtering Hole Lets Remote Users Conduct Cross-Site Scripting Attacks
11050| [1005290] Apache Tomcat Java Server Default Servlet Returns JSP Source Code to Remote Users
11051| [1005285] Apache Web Server 'mod_dav' Has Null Pointer Bug That May Allow Remote Users to Cause Denial of Service Conditions
11052| [1005010] Apache Web Server (2.0) Has Unspecified Flaw That Allows Remote Users to Obtain Sensitive Data and Cause Denial of Service Conditions
11053| [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
11054| [1004745] Apache Tomcat Java Server Allows Cross-Site Scripting Attacks
11055| [1004636] Apache mod_ssl 'Off-by-One' Bug May Let Local Users Crash the Web Server or Possibly Execute Arbitrary Code
11056| [1004602] Apache Tomcat Java Server for Windows Can Be Crashed By Remote Users Sending Malicious Requests to Hang All Available Working Threads
11057| [1004586] Apache Tomcat Java Server May Disclose the Installation Path to Remote Users
11058| [1004555] Apache Web Server Chunked Encoding Flaw May Let Remote Users Execute Arbitrary Code on the Server
11059| [1004209] Apache 'mod_python' Python Language Interpreter Bug in Publisher Handler May Allow Remote Users to Modify Files on the System
11060| [1003874] Apache Web Server for Windows Has Batch File Processing Hole That Lets Remote Users Execute Commands on the System
11061| [1003767] 'mod_frontpage' Module for Apache Web Server Has Buffer Overlow in 'fpexec.c' That Allows Remote Users to Execute Arbitrary Code on the System with Root Privileges
11062| [1003723] Apache-SSL for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
11063| [1003664] 'mod_ssl' Security Package for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
11064| [1003602] GNUJSP Java Server Pages Implementation Discloses Web Files and Source Code to Remote Users and Bypasses Apache Access Control Restrictions
11065| [1003465] PHP for Apache Web Server May Disclose Installation Path Information to Remote Users Making 'OPTIONS' Requests
11066| [1003451] Oracle Application Server PL/SQL Module for Apache Has Buffer Overflows That Allow Remote Users to Execute Arbitrary Code and Gain Access to the Server
11067| [1003131] Apache Web Server in Virtual Hosting Mode Can Be Crashed By a Local User Removing a Log Directory
11068| [1003104] PHP.EXE Windows CGI for Apache Web Server May Let Remote Users View Files on the Server Due to Configuration Error
11069| [1003008] Apache 'mod_bf' Module Lets Remote Users Execute Arbitrary Code
11070| [1002629] Apache suEXEC Wrapper Fails to Observe Minimum Group ID Security Settings in Certain Situations
11071| [1002542] Apache Web Server Virtual Hosting Split-Logfile Function Lets Remote Users Write Log Entries to Arbitrary Files on the System
11072| [1002400] Apache mod_gzip Module Has Buffer Overflow That Can Be Exploited By Local Users to Gain Elevated Privileges
11073| [1002303] Several 3rd Party Apache Authentication Modules Allow Remote Users to Execute Arbitrary Code to Gain Access to the System or Execute Stored Procedures to Obtain Arbitrary Database Information
11074| [1002188] Apache Web Server Discloses Internal IP Addresses to Remote Users in Certain Configurations
11075| [1001989] Apache Web Server May Disclose Directory Contents Even If an Index.html File is Present in the Directory
11076| [1001719] Apache Web Server on Mac OS X Client Fails to Enforce File and Directory Access Protections, Giving Remote Users Access to Restricted Pages
11077| [1001572] Apache Web Server on Microsoft Windows Platforms Allows Remote Users to Crash the Web Server
11078| [1001304] Apache Web Server for Windows Lets Remote Users Crash the Web Server Application
11079| [1001083] Apache Web Server May Display Directory Index Listings Even if Directory Listings Are Disabled
11080|
11081| OSVDB - http://www.osvdb.org:
11082| [96078] Apache CloudStack Infrastructure Menu Setup Network Multiple Field XSS
11083| [96077] Apache CloudStack Global Settings Multiple Field XSS
11084| [96076] Apache CloudStack Instances Menu Display Name Field XSS
11085| [96075] Apache CloudStack Instances Menu Add Instances Network Name Field XSS
11086| [96074] Apache CloudStack Instances Menu Add Instances Review Step Multiple Field XSS
11087| [96031] Apache HTTP Server suEXEC Symlink Arbitrary File Access
11088| [95888] Apache Archiva Single / Double Quote Character Handling XSS Weakness
11089| [95885] Apache Subversion mod_dav_svn Module Crafted HTTP Request Handling Remote DoS
11090| [95706] Apache OpenOffice.org (OOo) OOXML Document File XML Element Handling Memory Corruption
11091| [95704] Apache OpenOffice.org (OOo) DOC File PLCF Data Handling Memory Corruption
11092| [95603] Apache Continuum web/util/GenerateRecipentNotifier.java recipient Parameter XSS
11093| [95602] Apache Continuum web/action/notifier/JabberProjectNotifierEditAction-jabberProjectNotifierSave-validation.xml Multiple Parameter XSS
11094| [95601] Apache Continuum web/action/notifier/JabberGroupNotifierEditAction-jabberProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
11095| [95600] Apache Continuum web/action/ScheduleAction-saveSchedule-validation.xml Multiple Parameter XSS
11096| [95599] Apache Continuumweb/action/BuildDefinitionAction-saveBuildDefinition-validation.xml Multiple Parameter XSS
11097| [95598] Apache Continuum web/action/AddProjectAction-addProject-validation.xml Multiple Parameter XSS
11098| [95597] Apache Continuum web/action/ProjectEditAction-projectSave-validation.xml Multiple Parameter XSS
11099| [95596] Apache Continuum web/action/notifier/IrcGroupNotifierEditAction-ircProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
11100| [95595] Apache Continuum web/action/notifier/IrcProjectNotifierEditAction-ircProjectNotifierSave-validation.xml Multiple Parameter XSS
11101| [95594] Apache Continuum web/action/ProjectGroupAction.java Multiple Parameter XSS
11102| [95593] Apache Continuum web/action/AddProjectGroupAction.java Multiple Parameter XSS
11103| [95592] Apache Continuum web/action/AddProjectAction.java Multiple Parameter XSS
11104| [95523] Apache OFBiz Webtools Application View Log Screen Unspecified XSS
11105| [95522] Apache OFBiz Nested Expression Evaluation Arbitrary UEL Function Execution
11106| [95521] Apache HTTP Server mod_session_dbd Session Saving Unspecified Issue
11107| [95498] Apache HTTP Server mod_dav.c Crafted MERGE Request Remote DoS
11108| [95406] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Arbitrary Site Redirect
11109| [95405] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Remote Code Execution
11110| [95011] Apache CXF XML Parser SOAP Message Handling CPU Resource Exhaustion Remote DoS
11111| [94705] Apache Geronimo RMI Classloader Exposure Serialized Object Handling Remote Code Execution
11112| [94651] Apache Santuario (XML Security for C++) XML Signature CanonicalizationMethod Parameter Spoofing Weakness
11113| [94636] Apache Continuum workingCopy.action userDirectory Traversal Arbitrary File Access
11114| [94635] Apache Maven SCM SvnCommandlineUtils Process Listing Local Password Disclosure
11115| [94632] Apache Maven Wagon SSH (wagon-ssh) Host Verification Failure MitM Weakness
11116| [94625] Apache Santuario (XML Security for C++) XML Signature Reference Crafted XPointer Expression Handling Heap Buffer Overflow
11117| [94618] Apache Archiva /archiva/security/useredit.action username Parameter XSS
11118| [94617] Apache Archiva /archiva/security/roleedit.action name Parameter XSS
11119| [94616] Apache Archiva /archiva/security/userlist!show.action roleName Parameter XSS
11120| [94615] Apache Archiva /archiva/deleteArtifact!doDelete.action groupId Parameter XSS
11121| [94614] Apache Archiva /archiva/admin/addLegacyArtifactPath!commit.action legacyArtifactPath.path Parameter XSS
11122| [94613] Apache Archiva /archiva/admin/addRepository.action Multiple Parameter XSS
11123| [94612] Apache Archiva /archiva/admin/editAppearance.action Multiple Parameter XSS
11124| [94611] Apache Archiva /archiva/admin/addLegacyArtifactPath.action Multiple Parameter XSS
11125| [94610] Apache Archiva /archiva/admin/addNetworkProxy.action Multiple Parameter XSS
11126| [94403] Apache Santuario (XML Security for C++) InclusiveNamespace PrefixList Processing Heap Overflow
11127| [94402] Apache Santuario (XML Security for C++) HMAC-based XML Signature Processing DoS
11128| [94401] Apache Santuario (XML Security for C++) XPointer Evaluation Stack Overflow
11129| [94400] Apache Santuario (XML Security for C++) HMAC-Based XML Signature Reference Element Validation Spoofing Weakness
11130| [94279] Apache Qpid CA Certificate Validation Bypass
11131| [94275] Apache Solr JettySolrRunner.java Can Not Find Error Message XSS
11132| [94233] Apache OpenJPA Object Deserialization Arbitrary Executable Creation
11133| [94042] Apache Axis JAX-WS Java Unspecified Exposure
11134| [93969] Apache Struts OGNL Expression Handling Double Evaluation Error Remote Command Execution
11135| [93796] Apache Subversion Filename Handling FSFS Repository Corruption Remote DoS
11136| [93795] Apache Subversion svnserve Server Aborted Connection Message Handling Remote DoS
11137| [93794] Apache Subversion contrib/hook-scripts/check-mime-type.pl svnlook Hyphenated argv Argument Handling Remote DoS
11138| [93793] Apache Subversion contrib/hook-scripts/svn-keyword-check.pl Filename Handling Remote Command Execution
11139| [93646] Apache Struts Crafted Parameter Arbitrary OGNL Code Execution
11140| [93645] Apache Struts URL / Anchor Tag includeParams Attribute Remote Command Execution
11141| [93636] Apache Pig Multiple Physical Operator Memory Exhaustion Remote Remote DoS
11142| [93635] Apache Wink DTD (Document Type Definition) Expansion Data Parsing Information Disclosure
11143| [93605] RT Apache::Session::File Session Replay Reuse Information Disclosure
11144| [93599] Apache Derby SYSCS_UTIL.SYSCS_SET_DATABASE_PROPERTY Boot Password Manipulation Re-encryption Failure Password Corruption
11145| [93555] Apache Commons Codec Invalid Base32 String Information Tunneling Weakness
11146| [93554] Apache HBase bulkLoadHFiles() Method ACL Bypass
11147| [93543] JBoss Enterprise Application Platform org.apache.catalina.connector.Response.encodeURL() Method MitM jsessionid Disclosure
11148| [93542] Apache ManifoldCF (Connectors Framework) org.apache.manifoldcf.crawler.ExportConfiguration Class Configuration Export Password Disclosure
11149| [93541] Apache Solr json.wrf Callback XSS
11150| [93524] Apache Hadoop GetSecurityDescriptorControl() Function Absolute Security Descriptor Handling NULL Descriptor Weakness
11151| [93521] Apache jUDDI Security API Token Session Persistence Weakness
11152| [93520] Apache CloudStack Default SSL Key Weakness
11153| [93519] Apache Shindig /ifr Cross-site Arbitrary Gadget Invocation
11154| [93518] Apache Solr /admin/analysis.jsp name Parameter XSS
11155| [93517] Apache CloudStack setup-cloud-management /etc/sudoers Modification Local Privilege Escalation
11156| [93516] Apache CXF UsernameTokenInterceptor Nonce Caching Replay Weakness
11157| [93515] Apache HBase table.jsp name Parameter XSS
11158| [93514] Apache CloudStack Management Server Unauthenticated Remote JMX Connection Default Setting Weakness
11159| [93463] Apache Struts EL / OGNL Interpretation Unspecified Remote Code Execution
11160| [93462] Apache CXF WS-SecurityPolicy AlgorithmSuite Arbitrary Ciphertext Decryption Weakness
11161| [93401] Apache Hadoop core-site.xml Permission Weakness Local Alfredo Secret Disclosure
11162| [93400] Apache Hadoop Map/Reduce Job Log Directory Symlink Arbitrary File Mode Manipulation
11163| [93397] Apache Wicket Referrer HTTP Header Session ID Disclosure
11164| [93366] Apache HTTP Server modules/mappers/mod_rewrite.c do_rewritelog() Function Log File Terminal Escape Sequence Filtering Remote Command Execution
11165| [93254] Apache Tomcat AsyncListener Method Cross-session Information Disclosure
11166| [93253] Apache Tomcat Chunked Transfer Encoding Data Saturation Remote DoS
11167| [93252] Apache Tomcat FORM Authenticator Session Fixation
11168| [93172] Apache Camel camel/endpoints/ Endpoint XSS
11169| [93171] Apache Sling HtmlResponse Error Message XSS
11170| [93170] Apache Directory DelegatingAuthenticator MitM Spoofing Weakness
11171| [93169] Apache Wave AuthenticationServlet.java Session Fixation Weakness
11172| [93168] Apache Click ErrorReport.java id Parameter XSS
11173| [93167] Apache ActiveMQ JMSXUserId Spoofing Weakness
11174| [93166] Apache CXF Crafted Message Element Count Handling System Resource Exhaustion Remote DoS
11175| [93165] Apache CXF Crafted Message Element Level Handling System Resource Exhaustion Remote DoS
11176| [93164] Apache Harmony DatagramSocket Class connect Method CheckAccept() IP Blacklist Bypass
11177| [93163] Apache Hadoop Map/Reduce Daemon Symlink Arbitrary File Overwrite
11178| [93162] Apache VelocityStruts struts/ErrorsTool.getMsgs Error Message XSS
11179| [93161] Apache CouchDB Rewriter VM Atom Table Memory Exhaustion Remote DoS
11180| [93158] Apache Wicket BookmarkablePageLink Feature XSS CSRF
11181| [93157] Apache Struts UrlHelper.java s:url includeParams Functionality XSS
11182| [93156] Apache Tapestry Calendar Component datefield.js datefield Parameter XSS
11183| [93155] Apache Struts fielderror.ftl fielderror Parameter Error Message XSS
11184| [93154] Apache JSPWiki Edit.jsp createPages WikiPermission Bypass
11185| [93153] Apache PDFBox PDFXrefStreamParser Missing Element Handling PDF Parsing DoS
11186| [93152] Apache Hadoop HttpServer.java Multiple Function XSS
11187| [93151] Apache Shiro Search Filter userName Parameter LDAP Code Injection Weakness
11188| [93150] Apache Harmony java.net.SocketPermission Class boolean equals Function checkConnect() Weakness Host Name Retrieval
11189| [93149] Apache Harmony java.security.Provider Class void load Function checkSecurityAccess() Weakness
11190| [93148] Apache Harmony java.security.ProtectionDomain Class java.lang.String.toString() Function checkPermission() Weakness
11191| [93147] Apache Harmony java.net.URLConnection openConnection Function checkConnect Weakness Proxy Connection Permission Bypass
11192| [93146] Apache Harmony java.net.ServerSocket Class void implAccept Function checkAccept() Weakness SerSocket Subclass Creation
11193| [93145] Apache Qpid JMS Client Detached Session Frame Handling NULL Pointer Dereference Remote DoS
11194| [93144] Apache Solr Admin Command Execution CSRF
11195| [93009] Apache VCL XMLRPC API Unspecified Function Remote Privilege Escalation
11196| [93008] Apache VCL Web GUI Unspecified Remote Privilege Escalation
11197| [92997] Apache Commons Codec org.apache.commons.codec.net.URLCodec Fields Missing 'final' Thread-safety Unspecified Issue
11198| [92976] Apache ActiveMQ scheduled.jsp crontab Command XSS
11199| [92947] Apache Commons Codec org.apache.commons.codec.language.Soundex.US_ENGLISH_MAPPING Missing MS_PKGPROTECT Field Manipulation Unspecified Issue
11200| [92749] Apache CloudStack Predictable Hash Virtual Machine Console Console Access URL Generation
11201| [92748] Apache CloudStack VM Console Access Restriction Bypass
11202| [92709] Apache ActiveMQ Web Console Unauthenticated Remote Access
11203| [92708] Apache ActiveMQ Sample Web Application Broker Resource Consumption Remote DoS
11204| [92707] Apache ActiveMQ webapp/websocket/chat.js Subscribe Message XSS
11205| [92706] Apache ActiveMQ Debug Log Rendering XSS
11206| [92705] Apache ActiveMQ PortfolioPublishServlet.java refresh Parameter XSS
11207| [92270] Apache Tomcat Unspecified CSRF
11208| [92094] Apache Subversion mod_dav_svn Module Nonexistent URL Lock Request Handling NULL Pointer Dereference Remote DoS
11209| [92093] Apache Subversion mod_dav_svn Module Activity URL PROPFIND Request Handling NULL Pointer Dereference Remote DoS
11210| [92092] Apache Subversion mod_dav_svn Module Log REPORT Request Handling NULL Pointer Dereference Remote DoS
11211| [92091] Apache Subversion mod_dav_svn Module Node Property Handling Resource Exhaustion Remote DoS
11212| [92090] Apache Subversion mod_dav_svn Module Activity URL Lock Request Handling NULL Pointer Dereference Remote DoS
11213| [91774] Apache Commons Codec Unspecified Non-private Field Manipulation Weakness
11214| [91628] mod_ruid2 for Apache HTTP Server fchdir() Inherited File Descriptor chroot Restriction Bypass
11215| [91328] Apache Wicket $up$ Traversal Arbitrary File Access
11216| [91295] Apple Mac OS X Apache Unicode Character URI Handling Authentication Bypass
11217| [91235] Apache Rave /app/api/rpc/users/get User Object Hashed Password Remote Disclosure
11218| [91185] Munin Default Apache Configuration Permission Weakness Remote Information Disclosure
11219| [91173] Apache Wicket WebApplicationPath Constructor Bypass /WEB-INF/ Directory File Access
11220| [91172] Apache Wicket PackageResourceGuard File Extension Filter Bypass
11221| [91025] Apache Qpid qpid::framing::Buffer Class Multiple Method Out-of-bounds Access Remote DoS
11222| [91024] Apache Qpid federation_tag Attribute Handling Federated Interbroker Link Access Restriction Bypass
11223| [91023] Apache Qpid AMQP Type Decoder Exposure Array Size Value Handling Memory Consumption Remote DoS
11224| [91022] Apache Qpid qpid/cpp/include/qpid/framing/Buffer.h qpid::framing::Buffer::checkAvailable() Function Integer Overflow
11225| [90986] Apache Jena ARQ INSERT DATA Request Handling Overflow
11226| [90907] Apache Subversion mod_dav_svn / libsvn_fs svn_fs_file_length() Function MKACTIVITY / PROPFIND Option Request Handling Remote DoS
11227| [90906] Apache Commons FileUpload /tmp Storage Symlink Arbitrary File Overwrite
11228| [90864] Apache Batik 1xx Redirect Script Origin Restriction Bypass
11229| [90858] Apache Ant Malformed TAR File Handling Infinite Loop DoS
11230| [90852] Apache HTTP Server for Debian apachectl /var/lock Permission Weakness Symlink Directory Permission Manipulation
11231| [90804] Apache Commons CLI Path Subversion Local Privilege Escalation
11232| [90802] Apache Avro Recursive Schema Handling Infinite Recursion DoS
11233| [90592] Apache Batik ApplicationSecurityEnforcer.java Multiple Method Security Restriction Bypass
11234| [90591] Apache Batik XML External Entity (XXE) Data Parsing Arbitrary File Disclosure
11235| [90565] Apache Tomcat Log Directory Permission Weakness Local Information Disclosure
11236| [90564] Apache Maven / Maven Wagon SSL Certificate Validation MitM Spoofing Weakness
11237| [90557] Apache HTTP Server mod_proxy_balancer balancer-manager Interface Multiple Parameter XSS
11238| [90556] Apache HTTP Server Multiple Module Multiple Parameter XSS
11239| [90276] Apache Axis2 axis2.xml Plaintext Password Local Disclosure
11240| [90249] Apache Axiom ClassLoader XMLInputFactory / XMLOutputFactory Construction Unspecified Issue
11241| [90235] Apache Commons HttpClient Certificate Wildcard Matching Weakness
11242| [90079] Apache CXF WSS4JInInterceptor URIMappingInterceptor WS-Security SOAP Service Access Restriction Bypass
11243| [90078] Apache CXF WS-SecurityPolicy Enabled Plaintext UsernameTokens Handling Authentication Bypass
11244| [89453] Apache Open For Business Project (OFBiz) Screenlet.title Widget Attribute XSS
11245| [89452] Apache Open For Business Project (OFBiz) Image.alt Widget Attribute XSS
11246| [89294] Apache CouchDB Futon UI Browser-based Test Suite Query Parameter XSS
11247| [89293] Apache CouchDB Unspecified Traversal Arbitrary File Access
11248| [89275] Apache HTTP Server mod_proxy_ajp Module Expensive Request Parsing Remote DoS
11249| [89267] Apache CouchDB JSONP Callback Handling Unspecified XSS
11250| [89146] Apache CloudStack Master Server log4j.conf SSH Private Key / Plaintext Password Disclosure
11251| [88603] Apache OpenOffice.org (OOo) Unspecified Information Disclosure
11252| [88602] Apache OpenOffice.org (OOo) Unspecified Manifest-processing Issue
11253| [88601] Apache OpenOffice.org (OOo) Unspecified PowerPoint File Handling Issue
11254| [88285] Apache Tomcat Partial HTTP Request Saturation Remote DoS
11255| [88095] Apache Tomcat NIO Connector Terminated Connection Infinte Loop DoS
11256| [88094] Apache Tomcat FORM Authentication Crafted j_security_check Request Security Constraint Bypass
11257| [88093] Apache Tomcat Null Session Requst CSRF Prevention Filter Bypass
11258| [88043] IBM Tivoli Netcool/Reporter Apache CGI Unspecified Remote Command Execution
11259| [87580] Apache Tomcat DIGEST Authentication Session State Caching Authentication Bypass Weakness
11260| [87579] Apache Tomcat DIGEST Authentication Stale Nonce Verification Authentication Bypass Weakness
11261| [87477] Apache Tomcat Project Woodstock Service Error Page UTF-7 XSS Weakness
11262| [87227] Apache Tomcat InternalNioInputBuffer.java parseHeaders() Function Request Header Size Parsing Remote DoS
11263| [87223] Apache Tomcat DIGEST Authentication replay-countermeasure Functionality cnonce / cn Verification Authentication Bypass Weakness
11264| [87160] Apache Commons HttpClient X.509 Certificate Domain Name Matching MiTM Weakness
11265| [87159] Apache CXF X.509 Certificate Domain Name Matching MiTM Weakness
11266| [87150] Apache Axis / Axis2 X.509 Certificate Domain Name Matching MiTM Weakness
11267| [86902] Apache HTTP Server 3xx Redirect Internal IP Address Remote Disclosure
11268| [86901] Apache Tomcat Error Message Path Disclosure
11269| [86684] Apache CloudStack Unauthorized Arbitrary API Call Invocation
11270| [86556] Apache Open For Business Project (OFBiz) Unspecified Issue
11271| [86503] Visual Tools VS home/apache/DiskManager/cron/init_diskmgr Local Command Execution
11272| [86401] Apache ActiveMQ ResourceHandler Traversal Arbitrary File Access
11273| [86225] Apache Axis2 XML Signature Wrapping (XSW) Authentication Bypass
11274| [86206] Apache Axis2 Crafted SAML Assertion Signature Exclusion Attack Authentication Bypass
11275| [85722] Apache CXF SOAP Request Parsing Access Restriction Bypass
11276| [85704] Apache Qpid Incoming Client Connection Saturation Remote DoS
11277| [85474] Eucalyptus Apache Santuario (XML Security for Java) Library XML Signature Transform Handling DoS
11278| [85430] Apache mod_pagespeed Module Unspecified XSS
11279| [85429] Apache mod_pagespeed Module Hostname Verification Cross-host Resource Disclosure
11280| [85249] Apache Wicket Unspecified XSS
11281| [85236] Apache Hadoop conf/hadoop-env.sh Temporary File Symlink Arbitrary File Manipulation
11282| [85090] Apache HTTP Server mod_proxy_ajp.c mod_proxy_ajp Module Proxy Functionality Cross-client Information Disclosure
11283| [85089] Apache HTTP Server mod_proxy_http.c mod_proxy_http Module Cross-client Information Disclosure
11284| [85062] Apache Solr Autocomplete Module for Drupal Autocomplete Results XSS
11285| [85010] Apache Struts Token Handling Mechanism Token Name Configuration Parameter CSRF Weakness
11286| [85009] Apache Struts Request Parameter OGNL Expression Parsing Remote DoS
11287| [84911] libapache2-mod-rpaf X-Forward-For HTTP Header Parsing Remote DoS
11288| [84823] Apache HTTP Server Multiple Module Back End Server Error Handling HTTP Request Parsing Remote Information Disclosure
11289| [84818] Apache HTTP Server mod_negotiation Module mod_negotiation.c make_variant_list Function XSS
11290| [84562] Apache Qpid Broker Authentication Mechanism AMQP Client Shadow Connection NullAuthenticator Request Parsing Authentication Bypass
11291| [84458] Apache Libcloud SSL Certificate Validation MitM Spoofing Weakness
11292| [84279] PHP on Apache php_default_post_reader POST Request Handling Overflow DoS
11293| [84278] PHP w/ Apache PDO::ATTR_DEFAULT_FETCH_MODE / PDO::FETCH_CLASS DoS
11294| [84231] Apache Hadoop DataNodes Client BlockTokens Arbitrary Block Access
11295| [83943] Oracle Solaris Cluster Apache Tomcat Agent Subcomponent Unspecified Local Privilege Escalation
11296| [83939] Oracle Solaris Apache HTTP Server Subcomponent Unspecified Remote Information Disclosure
11297| [83685] svnauthcheck Apache HTTP Configuration File Permission Revocation Weakness
11298| [83682] Apache Sling POST Servlet @CopyFrom Operation HTTP Request Parsing Infinite Loop Remote DoS
11299| [83339] Apache Roller Blogger Roll Unspecified XSS
11300| [83270] Apache Roller Unspecified Admin Action CSRF
11301| [82782] Apache CXF WS-SecurityPolicy 1.1 SupportingToken Policy Bypass
11302| [82781] Apache CXF WS-SecurityPolicy Supporting Token Children Specification Token Signing Verification Weakness
11303| [82611] cPanel Apache Piped Log Configuration Log Message Formatting Traversal Arbitrary File Creation
11304| [82436] MapServer for Windows Bundled Apache / PHP Configuration Local File Inclusion
11305| [82215] PHP sapi/cgi/cgi_main.c apache_request_headers Function HTTP Header Handling Remote Overflow
11306| [82161] Apache Commons Compress bzip2 File Compression BZip2CompressorOutputStream Class File Handling Remote DoS
11307| [81965] Apache Batik Squiggle SVG Browser JAR File Arbitrary Code Execution
11308| [81790] Apache POI src/org/apache/poi/hwpf/model/UnhandledDataStructure.java UnhandledDataStructure() constructor Length Attribute CDF / CFBF File Handling Remote DoS
11309| [81660] Apache Qpid Credential Checking Cluster Authentication Bypass
11310| [81511] Apache for Debian /usr/share/doc HTTP Request Parsing Local Script Execution
11311| [81359] Apache HTTP Server LD_LIBRARY_PATH Variable Local Privilege Escalation
11312| [81349] Apache Open For Business Project (OFBiz) Webslinger Component Unspecified XSS
11313| [81348] Apache Open For Business Project (OFBiz) Content IDs / Map-Keys Unspecified XSS
11314| [81347] Apache Open For Business Project (OFBiz) Parameter Arrays Unspecified XSS
11315| [81346] Apache Open For Business Project (OFBiz) checkoutProcess.js getServerError() Function Unspecified XSS
11316| [81196] Apache Open For Business Project (OFBiz) FlexibleStringExpander Nested Script String Parsing Remote Code Execution
11317| [80981] Apache Hadoop Kerberos/MapReduce Security Feature User Impersonation Weakness
11318| [80571] Apache Traffic Server Host HTTP Header Parsing Remote Overflow
11319| [80547] Apache Struts XSLTResult.java File Upload Arbitrary Command Execution
11320| [80360] AskApache Password Protector Plugin for WordPress Error Page $_SERVER Superglobal XSS
11321| [80349] Apache HTTP Server mod_fcgid Module fcgid_spawn_ctl.c FcgidMaxProcessesPerClass Virtual Host Directive HTTP Request Parsing Remote DoS
11322| [80301] Apache Wicket /resources/ Absolute Path Arbitrary File Access
11323| [80300] Apache Wicket wicket:pageMapName Parameter XSS
11324| [79478] Apache Solr Extension for TYPO3 Unspecified XSS
11325| [79002] Apache MyFaces javax.faces.resource In Parameter Traversal Arbitrary File Access
11326| [78994] Apache Struts struts-examples/upload/upload-submit.do name Parameter XSS
11327| [78993] Apache Struts struts-cookbook/processDyna.do message Parameter XSS
11328| [78992] Apache Struts struts-cookbook/processSimple.do message Parameter XSS
11329| [78991] Apache Struts struts2-rest-showcase/orders clientName Parameter XSS
11330| [78990] Apache Struts struts2-showcase/person/editPerson.action Multiple Parameter XSS
11331| [78932] Apache APR Hash Collision Form Parameter Parsing Remote DoS
11332| [78903] Apache CXF SOAP Request Parsing WS-Security UsernameToken Policy Bypass
11333| [78600] Apache Tomcat HTTP DIGEST Authentication DigestAuthenticator.java Catalina Weakness Security Bypass
11334| [78599] Apache Tomcat HTTP DIGEST Authentication Realm Value Parsing Security Bypass
11335| [78598] Apache Tomcat HTTP DIGEST Authentication qop Value Parsing Security Bypass
11336| [78573] Apache Tomcat Parameter Saturation CPU Consumption Remote DoS
11337| [78556] Apache HTTP Server Status Code 400 Default Error Response httpOnly Cookie Disclosure
11338| [78555] Apache HTTP Server Threaded MPM %{cookiename}C Log Format String Cookie Handling Remote DoS
11339| [78501] Apache Struts ParameterInterceptor Class OGNL Expression Parsing Remote Command Execution
11340| [78331] Apache Tomcat Request Object Recycling Information Disclosure
11341| [78293] Apache HTTP Server Scoreboard Invalid Free Operation Local Security Bypass
11342| [78277] Apache Struts ExceptionDelegator Component Parameter Parsing Remote Code Execution
11343| [78276] Apache Struts DebuggingInterceptor Component Developer Mode Unspecified Remote Command Execution
11344| [78113] Apache Tomcat Hash Collision Form Parameter Parsing Remote DoS
11345| [78112] Apache Geronimo Hash Collision Form Parameter Parsing Remote DoS
11346| [78109] Apache Struts ParameterInterceptor Traversal Arbitrary File Overwrite
11347| [78108] Apache Struts CookieInterceptor Cookie Name Handling Remote Command Execution
11348| [77593] Apache Struts Conversion Error OGNL Expression Injection
11349| [77496] Apache ActiveMQ Failover Mechanism Openwire Request Parsing Remote DoS
11350| [77444] Apache HTTP Server mod_proxy Mdule Web Request HTTP/0.9 Protocol URL Parsing Proxy Remote Security Bypass
11351| [77374] Apache MyFaces Java Bean includeViewParameters Parsing EL Expression Security Weakness
11352| [77310] Apache HTTP Server mod_proxy Reverse Proxy Mode Security Bypass Weakness (2011-4317)
11353| [77234] Apache HTTP Server on cygwin Encoded Traversal Arbitrary File Access
11354| [77012] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Memory Consumption DoS
11355| [76944] Apache Tomcat Manager Application Servlets Access Restriction Bypass
11356| [76744] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Overflow
11357| [76189] Apache Tomcat HTTP DIGEST Authentication Weakness
11358| [76079] Apache HTTP Server mod_proxy Mdule Web Request URL Parsing Proxy Remote Security Bypass (2011-3368)
11359| [76072] Apache JServ jserv.conf jserv-status Handler jserv/ URI Request Parsing Local Information Disclosure
11360| [75807] Apache HTTP Server Incomplete Header Connection Saturation Remote DoS
11361| [75647] Apache HTTP Server mod_proxy_ajp Module mod_proxy_balancer HTTP Request Remote DoS
11362| [75376] Apache Libcloud SSL Certificate Validation MitM Server Spoofing Weakness
11363| [74853] Domain Technologie Control /etc/apache2/apache2.conf File Permissions Weakness dtcdaemons User Password Disclosure
11364| [74818] Apache Tomcat AJP Message Injection Authentication Bypass
11365| [74725] Apache Wicket Multi Window Support Unspecified XSS
11366| [74721] Apache HTTP Server ByteRange Filter Memory Exhaustion Remote DoS
11367| [74541] Apache Commons Daemon Jsvc Permissions Weakness Arbitrary File Access
11368| [74535] Apache Tomcat XML Parser Cross-application Multiple File Manipulation
11369| [74447] Apache Struts XWork Nonexistent Method s:submit Element Internal Java Class Remote Path Disclosure
11370| [74262] Apache HTTP Server Multi-Processing Module itk.c Configuration Merger mpm-itk root UID / GID Remote Privilege Escalation
11371| [74120] Apache HTTP Server mod_authnz_external mysql/mysql-auth.pl user Field SQL Injection
11372| [73920] Oracle Secure Backup /apache/htdocts/php/common.php username Parameter Remote Code Execution
11373| [73798] Apache Tomcat sendfile Request Start / Endpoint Parsing Local DoS
11374| [73797] Apache Tomcat sendfile Request Attribute Validation Weakness Local Access Restriction Bypass
11375| [73776] Apache Tomcat HTTP BIO Connector HTTP Pipelining Cross-user Remote Response Access
11376| [73644] Apache XML Security Signature Key Parsing Overflow DoS
11377| [73600] Apache Struts javatemplates Plugin Component Handlers .action URI Multiple Parameter XSS
11378| [73462] Apache Rampart/C util/rampart_timestamp_token.c rampart_timestamp_token_validate Function Expired Token Remote Access Restriction Bypass
11379| [73429] Apache Tomcat JMX MemoryUserDatabase Local Password Disclosure
11380| [73384] Apache HTTP Server mod_rewrite PCRE Resource Exhaustion DoS
11381| [73383] Apache HTTP Server Portable Runtime (APR) Library apr_fnmatch() Infinite Loop Remote DoS
11382| [73378] IBM WebSphere Application Server (WAS) JavaServer Pages org.apache.jasper.runtime.JspWriterImpl.response JSP Page Application Restart Remote DoS
11383| [73247] Apache Subversion mod_dav_svn File Permission Weakness Information Disclosure
11384| [73246] Apache Subversion mod_dav_svn Path-based Access Control Rule Handling Remote DoS
11385| [73245] Apache Subversion mod_dav_svn Baselined Resource Request Handling Remote DoS
11386| [73154] Apache Archiva Multiple Unspecified CSRF
11387| [73153] Apache Archiva /archiva/admin/deleteNetworkProxy!confirm.action proxyid Parameter XSS
11388| [72407] Apache Tomcat @ServletSecurity Initial Load Annotation Security Constraint Bypass Information Disclosure
11389| [72238] Apache Struts Action / Method Names <
11390| [71647] Apache HttpComponents HttpClient Proxy-Authorization Credentials Remote Disclosure
11391| [71558] Apache Tomcat SecurityManager ServletContext Attribute Traversal Arbitrary File Manipulation
11392| [71557] Apache Tomcat HTML Manager Multiple XSS
11393| [71075] Apache Archiva User Management Page XSS
11394| [71027] Apache Tomcat @ServletSecurity Annotation Security Constraint Bypass Information Disclosure
11395| [70925] Apache Continuum Project Pages Unspecified XSS (2011-0533)
11396| [70924] Apache Continuum Multiple Admin Function CSRF
11397| [70809] Apache Tomcat NIO HTTP Connector Request Line Processing DoS
11398| [70734] Apache CouchDB Request / Cookie Handling Unspecified XSS
11399| [70585] Oracle Fusion Middleware Oracle HTTP Server Apache Plugin Unspecified Remote Issue
11400| [70333] Apache Subversion rev_hunt.c blame Command Multiple Memory Leak Remote DoS
11401| [70332] Apache Subversion Apache HTTP Server mod_dav_svn repos.c walk FunctionSVNParentPath Collection Remote DoS
11402| [69659] Apache Archiva Admin Authentication Weakness Privilege Escalation
11403| [69520] Apache Archiva Administrator Credential Manipulation CSRF
11404| [69512] Apache Tomcat Set-Cookie Header HTTPOnly Flag Session Hijacking Weakness
11405| [69456] Apache Tomcat Manager manager/html/sessions Multiple Parameter XSS
11406| [69275] Apache mod_fcgid Module fcgid_bucket.c fcgid_header_bucket_read() Function Remote Overflow
11407| [69067] Apache Shiro URI Path Security Traversal Information Disclosure
11408| [68815] Apache MyFaces shared/util/StateUtils.java View State MAC Weakness Cryptographic Padding Remote View State Modification
11409| [68670] Apache Qpid C++ Broker Component broker/SessionAdapter.cpp SessionAdapter::ExchangeHandlerImpl::checkAlternate Function Exchange Alternate Remote DoS
11410| [68669] Apache Qpid cluster/Cluster.cpp Cluster::deliveredEvent Function Invalid AMQP Data Remote DoS
11411| [68662] Apache Axis2 dswsbobje.war Module Admin Account Default Password
11412| [68531] Apache Qpid qpidd sys/ssl/SslSocket.cpp Incomplete SSL Handshake Remote DoS
11413| [68327] Apache APR-util buckets/apr_brigade.c apr_brigade_split_line() Function Memory Consumption DoS
11414| [68314] Apache XML-RPC SAX Parser External Entity Information Disclosure
11415| [67964] Apache Traffic Server Transaction ID / Source Port Randomization Weakness DNS Cache Poisoning
11416| [67846] SUSE Lifecycle Management Server on SUSE Linux Enterprise apache2-slms Parameter Quoting CSRF
11417| [67294] Apache CXF XML SOAP Message Crafted Document Type Declaration Remote DoS
11418| [67240] Apache CouchDB Installation Page Direct Request Arbitrary JavaScript Code Execution CSRF
11419| [67205] Apache Derby BUILTIN Authentication Password Hash Generation Algorithm SHA-1 Transformation Password Substitution
11420| [66745] Apache HTTP Server Multiple Modules Pathless Request Remote DoS
11421| [66319] Apache Tomcat Crafted Transfer-Encoding Header Handling Buffer Recycling Remote DoS
11422| [66280] Apache Struts XWork ParameterInterceptor Server-Side Object Remote Code Execution
11423| [66226] Apache Axis2 Admin Interface Cookie Session Fixation
11424| [65697] Apache Axis2 / Java SOAP Message DTD Rejection Weakness Arbitrary File Access
11425| [65654] Apache HTTP Server mod_proxy_http mod_proxy_http.c Timeout Detection Weakness HTTP Request Response Disclosure
11426| [65429] Apache MyFaces Unencrypted ViewState Serialized View Object Manipulation Arbitrary Expression Language (EL) Statement Execution
11427| [65054] Apache ActiveMQ Jetty Error Handler XSS
11428| [64844] Apache Axis2/Java axis2/axis2-admin/engagingglobally modules Parameter XSS
11429| [64522] Apache Open For Business Project (OFBiz) ecommerce/control/contactus Multiple Parameter XSS
11430| [64521] Apache Open For Business Project (OFBiz) Web Tools Section entityName Parameter XSS
11431| [64520] Apache Open For Business Project (OFBiz) ecommerce/control/ViewBlogArticle contentId Parameter XSS
11432| [64519] Apache Open For Business Project (OFBiz) Control Servlet URI XSS
11433| [64518] Apache Open For Business Project (OFBiz) Show Portal Page Section start Parameter XSS
11434| [64517] Apache Open For Business Project (OFBiz) View Profile Section partyId Parameter XSS
11435| [64516] Apache Open For Business Project (OFBiz) Export Product Listing Section productStoreId Parameter XSS
11436| [64307] Apache Tomcat Web Application Manager/Host Manager CSRF
11437| [64056] mod_auth_shadow for Apache HTTP Server wait() Function Authentication Bypass
11438| [64023] Apache Tomcat WWW-Authenticate Header Local Host Information Disclosure
11439| [64020] Apache ActiveMQ Jetty ResourceHandler Crafted Request JSP File Source Disclosure
11440| [63895] Apache HTTP Server mod_headers Unspecified Issue
11441| [63368] Apache ActiveMQ createDestination.action JMSDestination Parameter CSRF
11442| [63367] Apache ActiveMQ createDestination.action JMSDestination Parameter XSS
11443| [63350] Apache CouchDB Hash Verification Algorithm Predictable Execution Time Weakness
11444| [63140] Apache Thrift Service Malformed Data Remote DoS
11445| [62676] Apache HTTP Server mod_proxy_ajp Module Crafted Request Remote DoS
11446| [62675] Apache HTTP Server Multi-Processing Module (MPM) Subrequest Header Handling Cross-thread Information Disclosure
11447| [62674] Apache HTTP Server mod_isapi Module Unloading Crafted Request Remote DoS
11448| [62231] Apache HTTP Server Logging Format Weakness Crafted DNS Response IP Address Spoofing
11449| [62230] Apache HTTP Server Crafted DNS Response Inverse Lookup Log Corruption XSS
11450| [62054] Apache Tomcat WAR Filename Traversal Work-directory File Deletion
11451| [62053] Apache Tomcat Autodeployment Process appBase File HTTP Request Authentication Bypass
11452| [62052] Apache Tomcat WAR File Traversal Arbitrary File Overwrite
11453| [62009] Apache HTTP Server src/modules/proxy/proxy_util.c mod_proxy ap_proxy_send_fb() Function Overflow
11454| [61379] Apache River Outrigger Entry Storage Saturation Memory Exhaustion DoS
11455| [61378] Apache Hadoop Map/Reduce JobTracker Memory Consumption DoS
11456| [61377] Apache Commons Modeler Multiple Mutable Static Fields Weakness
11457| [61376] Apache Rampart wsse:security Tag Signature Value Checking Weakness
11458| [60687] Apache C++ Standard Library (STDCXX) strxfrm() Function Overflow
11459| [60680] Apache Hadoop JobHistory Job Name Manipulation Weakness
11460| [60679] Apache ODE DeploymentWebService OMElement zipPart CRLF Injection
11461| [60678] Apache Roller Comment Email Notification Manipulation DoS
11462| [60677] Apache CouchDB Unspecified Document Handling Remote DoS
11463| [60428] Sun Java Plug-in org.apache.crimson.tree.XmlDocument Class reateXmlDocument Method Floppy Drive Access Bypass
11464| [60413] mod_throttle for Apache Shared Memory File Manipulation Local Privilege Escalation
11465| [60412] Sun Java Plug-in org.apache.xalan.processor.XSLProcessorVersion Class Unsigned Applet Variable Sharing Privilege Escalation
11466| [60396] Apache HTTP Server on OpenBSD Multipart MIME Boundary Remote Information Disclosure
11467| [60395] Apache HTTP Server on OpenBSD ETag HTTP Header Remote Information Disclosure
11468| [60232] PHP on Apache php.exe Direct Request Remote DoS
11469| [60176] Apache Tomcat Windows Installer Admin Default Password
11470| [60016] Apache HTTP Server on HP Secure OS for Linux HTTP Request Handling Unspecified Issue
11471| [59979] Apache HTTP Server on Apple Mac OS X HTTP TRACE Method Unspecified Client XSS
11472| [59969] Apache HTTP Server mod_ssl SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection
11473| [59944] Apache Hadoop jobhistory.jsp XSS
11474| [59374] Apache Solr Search Extension for TYPO3 Unspecified XSS
11475| [59022] Apache Shindig ConcatProxyServlet HTTP Header Response Splitting
11476| [59021] Apache Cocoon X-Cocoon-Version Header Remote Information Disclosure
11477| [59020] Apache Tapestry HTTPS Session Cookie Secure Flag Weakness
11478| [59019] Apache mod_python Cookie Salting Weakness
11479| [59018] Apache Harmony Error Message Handling Overflow
11480| [59013] Apache Derby SYSCS_EXPORT_TABLE Arbitrary File Overwrite
11481| [59012] Apache Derby Driver Auto-loading Non-deterministic Startup Weakness
11482| [59011] Apache JSPWiki Page Attachment Change Note Function XSS
11483| [59010] Apache Solr get-file.jsp XSS
11484| [59009] Apache Solr action.jsp XSS
11485| [59008] Apache Solr analysis.jsp XSS
11486| [59007] Apache Solr schema.jsp Multiple Parameter XSS
11487| [59006] Apache Beehive select / checkbox Tag XSS
11488| [59005] Apache Beehive jpfScopeID Global Parameter XSS
11489| [59004] Apache Beehive Error Message XSS
11490| [59003] Apache HttpClient POST Request Handling Memory Consumption DoS
11491| [59002] Apache Jetspeed default-page.psml URI XSS
11492| [59001] Apache Axis2 xsd Parameter Traversal Arbitrary File Disclosure
11493| [59000] Apache CXF Unsigned Message Policy Bypass
11494| [58999] Apache WSS4J CallbackHandler Plaintext Password Validation Weakness
11495| [58998] Apache OpenJPA persistence.xml Cleartext Password Local Disclosure
11496| [58997] Apache OpenEJB openejb.xml Cleartext Password Local Disclosure
11497| [58996] Apache Hadoop Map/Reduce LinuxTaskController File Group Ownership Weakness
11498| [58995] Apache Hadoop Map/Reduce Task Ownership Weakness
11499| [58994] Apache Hadoop Map/Reduce DistributedCache Localized File Permission Weakness
11500| [58993] Apache Hadoop browseBlock.jsp XSS
11501| [58991] Apache Hadoop browseDirectory.jsp XSS
11502| [58990] Apache Hadoop Map/Reduce HTTP TaskTrackers User Data Remote Disclosure
11503| [58989] Apache Hadoop Sqoop Process Listing Local Cleartext Password Disclosure
11504| [58988] Apache Hadoop Chukwa HICC Portal Unspecified XSS
11505| [58987] Apache Hadoop Map/Reduce TaskTracker User File Permission Weakness
11506| [58986] Apache Qpid Encrypted Message Handling Remote Overflow DoS
11507| [58985] Apache Qpid Process Listing Local Cleartext Password Disclosure
11508| [58984] Apache Jackrabbit Content Repository (JCR) Default Account Privilege Access Weakness
11509| [58983] Apache Jackrabbit Content Repository (JCR) NamespaceRegistry API Registration Method Race Condition
11510| [58982] Apache Synapse Proxy Service Security Policy Mismatch Weakness
11511| [58981] Apache Geronimo TomcatGeronimoRealm Security Context Persistence Weakness
11512| [58980] Apache Geronimo LDAP Realm Configuration Restart Reversion Weakness
11513| [58979] Apache MyFaces Tomahawk ExtensionsPhaseListener HTML Injection Information Disclosure
11514| [58978] Apache MyFaces Trinidad LocaleInfoScriptlet XSS
11515| [58977] Apache Open For Business Project (OFBiz) Multiple Default Accounts
11516| [58976] Apache Open For Business Project (OFBiz) URI passThru Parameter XSS
11517| [58975] Apache Open For Business Project (OFBiz) PARTYMGR_CREATE/UPDATE Permission Arbitrary User Password Modification
11518| [58974] Apache Sling /apps Script User Session Management Access Weakness
11519| [58973] Apache Tuscany Crafted SOAP Request Access Restriction Bypass
11520| [58931] Apache Geronimo Cookie Parameters Validation Weakness
11521| [58930] Apache Xalan-C++ XPath Handling Remote DoS
11522| [58879] Apache Portable Runtime (APR-util) poll/unix/port.c Event Port Backend Pollset Feature Remote DoS
11523| [58837] Apache Commons Net FTPSClient CipherSuites / Protocols Mutable Object Unspecified Data Security Issue
11524| [58813] Apache MyFaces Trinidad tr:table / HTML Comment Handling DoS
11525| [58812] Apache Open For Business Project (OFBiz) JSESSIONID Session Hijacking Weakness
11526| [58811] Apache Open For Business Project (OFBiz) /catalog/control/EditProductConfigItem configItemId Parameter XSS
11527| [58810] Apache Open For Business Project (OFBiz) /catalog/control/EditProdCatalo prodCatalogId Parameter XSS
11528| [58809] Apache Open For Business Project (OFBiz) /partymgr/control/viewprofile partyId Parameter XSS
11529| [58808] Apache Open For Business Project (OFBiz) /catalog/control/createProduct internalName Parameter XSS
11530| [58807] Apache Open For Business Project (OFBiz) Multiple Unspecified CSRF
11531| [58806] Apache FtpServer MINA Logging Filter Cleartext Credential Local Disclosure
11532| [58805] Apache Derby Unauthenticated Database / Admin Access
11533| [58804] Apache Wicket Header Contribution Unspecified Issue
11534| [58803] Apache Wicket Session Fixation
11535| [58802] Apache Directory Server (ApacheDS) userPassword Attribute Search Password Disclosure
11536| [58801] Apache ActiveMQ Stomp Client Credential Validation Bypass
11537| [58800] Apache Tapestry (context)/servicestatus Internal Service Information Disclosure
11538| [58799] Apache Tapestry Logging Cleartext Password Disclosure
11539| [58798] Apache Jetspeed pipeline Parameter pipeline-map Policy Bypass
11540| [58797] Apache Jetspeed Password Policy Multiple Weaknesses
11541| [58796] Apache Jetspeed Unsalted Password Storage Weakness
11542| [58795] Apache Rampart Crafted SOAP Header Authentication Bypass
11543| [58794] Apache Roller Admin Protocol (RAP) Malformed Header Authentication Bypass
11544| [58793] Apache Hadoop Map/Reduce mapred.system.dir Permission Weakness Job Manipulation
11545| [58792] Apache Shindig gadgets.rpc iframe RPC Call Validation Weakness
11546| [58791] Apache Synapse synapse.properties Cleartext Credential Local Disclosure
11547| [58790] Apache WSS4J SOAP Message UsernameToken Remote Password Disclosure
11548| [58789] Apache WSS4J SOAP Header Malformed UsernameToken Authentication Bypass
11549| [58776] Apache JSPWiki PreviewContent.jsp Edited Text XSS
11550| [58775] Apache JSPWiki preview.jsp action Parameter XSS
11551| [58774] Apache JSPWiki Edit.jsp Multiple Parameter XSS
11552| [58773] Apache JSPWiki Accept-Language Header Multiple Script language Parameter XSS
11553| [58772] Apache JSPWiki EditorManager.java editor Parameter XSS
11554| [58771] Apache JSPWiki GroupContent.jsp Multiple Parameter XSS
11555| [58770] Apache JSPWiki Group.jsp group Parameter XSS
11556| [58769] Apache JSPWiki Database Connection Termination DoS Weakness
11557| [58768] Apache JSPWiki Attachment Servlet nextpage Parameter Arbitrary Site Redirect
11558| [58766] Apache JSPWiki /admin/SecurityConfig.jsp Direct Request Information Disclosure
11559| [58765] Apache JSPWiki Spam Filter UniqueID RNG Weakness
11560| [58764] Apache JSPWiki Edit.jsp Multiple Parameter XSS
11561| [58763] Apache JSPWiki Include Tag Multiple Script XSS
11562| [58762] Apache JSPWiki Multiple .java Tags pageContext Parameter XSS
11563| [58761] Apache JSPWiki Wiki.jsp skin Parameter XSS
11564| [58760] Apache Commons VFS Exception Error Message Cleartext Credential Disclosure
11565| [58759] Apache Jackrabbit Content Repository (JCR) UUID System.currentTimeMillis() RNG Weakness
11566| [58758] Apache River GrantPermission Policy Manipulation Privilege Escalation
11567| [58757] Apache WS-Commons Java2 StaXUtils Multiple Unspecified Minor Issues
11568| [58756] Apache WSS4J WSHandler Client Certificate Signature Validation Weakness
11569| [58755] Apache Harmony DRLVM Non-public Class Member Access
11570| [58754] Apache Harmony File.createTempFile() Temporary File Creation Prediction Weakness
11571| [58751] Apache Geronimo GeronimoIdentityResolver Subject Handling Multiple Issues
11572| [58750] Apache MyFaces Trinidad Generated HTML Information Disclosure
11573| [58749] Apache MyFaces Trinidad Database Access Error Message Information Disclosure
11574| [58748] Apache MyFaces Trinidad Image Resource Loader Traversal Arbitrary Image Access
11575| [58747] Apache MyFaces Trinidad Error Message User Entered Data Disclosure Weakness
11576| [58746] Apache Axis2 JAX-WS Java2 WSDL4J Unspecified Issue
11577| [58744] Apache Wicket Crafted File Upload Disk Space Exhaustion DoS
11578| [58743] Apache Wicket wicket.util.crypt.SunJceCrypt Encryption Reversion Weakness
11579| [58742] Apache Rampart PolicyBasedValiadtor HttpsToken Endpoint Connection Weakness
11580| [58741] Apache Rampart WSSecSignature / WSSecEncryptedKey KeyIdentifierType Validation Weakness
11581| [58740] Apache Rampart TransportBinding Message Payload Cleartext Disclosure
11582| [58739] Apache Open For Business Project (OFBiz) Unsalted Password Storage Weakness
11583| [58738] Apache Open For Business Project (OFBiz) orderId Parameter Arbitrary Order Access
11584| [58737] Apache mod_python w/ mod_python.publisher index.py Underscore Prefixed Variable Disclosure
11585| [58735] Apache Open For Business Project (OFBiz) /ecommerce/control/keywordsearch SEARCH_STRING Parameter XSS
11586| [58734] Apache Torque Log File Cleartext Credential Local Disclosure
11587| [58733] Apache Axis2 doGet Implementation Authentication Bypass Service State Manipulation
11588| [58732] Apache MyFaces UIInput.validate() Null Value Validation Bypass Weakness
11589| [58731] Apache MyFaces /faces/* Prefix Mapping Authentication Bypass
11590| [58725] Apache Tapestry Basic String ACL Bypass Weakness
11591| [58724] Apache Roller Logout Functionality Failure Session Persistence
11592| [58723] Apache Roller User Profile / Admin Page Cleartext Password Disclosure
11593| [58722] Apache Derby Connection URL Encryption Method Reversion Weakness
11594| [58721] Apache Geronimo on Tomcat Security-constraint Resource ACL Bypass
11595| [58720] Apache Geronimo Explicit Servlet Mapping Access Bypass Weakness
11596| [58719] Apache Geronimo Keystore Unprivileged Service Disable DoS
11597| [58718] Apache Geronimo Deployment Plans Remote Password Disclosure
11598| [58717] Apache Jetspeed Portlet Application Edit Access Restriction Bypass
11599| [58716] Apache Jetspeed PSML Management Cached Constraint Authentication Weakness
11600| [58707] Apache WSS4J Crafted PasswordDigest Request Authentication Bypass
11601| [58706] Apache HttpClient Pre-emptive Authorization Remote Credential Disclosure
11602| [58705] Apache Directory Server (ApacheDS) User Passwords Cleartext Disclosure
11603| [58704] Apache Directory Server (ApacheDS) Non-existent User LDAP Bind Remote DoS
11604| [58703] Apache Geronimo Debug Console Unauthenticated Remote Information Disclosure
11605| [58702] Apache Directory Server (ApacheDS) Persistent LDAP Anonymous Bind Weakness
11606| [58701] Apache Jetspeed User Admin Portlet Unpassworded Account Creation Weakness
11607| [58700] Apache MyFaces /faces/* Path Handling Remote Overflow DoS
11608| [58699] Apache MyFaces Disable Property Client Side Manipulation Privilege Escalation
11609| [58698] Apache Roller Remember Me Functionality Cleartext Password Disclosure
11610| [58697] Apache XalanJ2 org.apache.xalan.xsltc.runtime.CallFunction Class Unspecified Issue
11611| [58696] Apache Tapestry Encoded Traversal Arbitrary File Access
11612| [58695] Apache Jetspeed Unauthenticated PSML Tags / Admin Folder Access
11613| [58694] Apache Geronimo Deploy Tool Process List Local Credential Disclosure
11614| [58693] Apache Derby service.properties File Encryption Key Information Disclosure
11615| [58692] Apache Geronimo Default Security Realm Login Brute Force Weakness
11616| [58689] Apache Roller Retrieve Last 5 Post Feature Unauthorized Blog Post Manipulation
11617| [58688] Apache Xalan-Java (XalanJ2) Static Variables Multiple Unspecified Issues
11618| [58687] Apache Axis Invalid wsdl Request XSS
11619| [58686] Apache Cocoon Temporary File Creation Unspecified Race Condition
11620| [58685] Apache Velocity Template Designer Privileged Code Execution
11621| [58684] Apache Jetspeed controls.Customize Action Security Check Bypass
11622| [58675] Apache Open For Business Project (OFBiz) eCommerce/ordermgr Multiple Field XSS
11623| [58674] Apache Open For Business Project (OFBiz) ecommerce/control/login Multiple Field XSS
11624| [58673] Apache Open For Business Project (OFBiz) ecommerce/control/viewprofile Multiple Field XSS
11625| [58672] Apache Open For Business Project (OFBiz) POS Input Panel Cleartext Password Disclosure
11626| [58671] Apache Axis2 JMS Signed Message Crafted WS-Security Header Security Bypass
11627| [58670] Apache Jetspeed JetspeedTool.getPortletFromRegistry Portlet Security Validation Failure
11628| [58669] Apache Jetspeed LDAP Cleartext Passwords Disclosure
11629| [58668] Apache Axis External Entity (XXE) Data Parsing Privilege Escalation
11630| [58667] Apache Roller Database Cleartext Passwords Disclosure
11631| [58666] Apache Xerces-C++ UTF-8 Transcoder Overlong Code Handling Unspecified Issue
11632| [58665] Apache Jetspeed Turbine: Cross-user Privileged Action Execution
11633| [58664] Apache Jetspeed EditAccount.vm Password Modification Weakness
11634| [58663] Apache Jetspeed Role Parameter Arbitrary Portlet Disclosure
11635| [58662] Apache Axis JWS Page Generated .class File Direct Request Information Disclosure
11636| [58661] Apache Jetspeed user-form.vm Password Reset Cleartext Disclosure
11637| [58660] Apache WSS4J checkReceiverResults Function Crafted SOAP Request Authentication Bypass
11638| [58658] Apache Rampart Crafted SOAP Request Security Verification Bypass
11639| [57882] Apache HTTP Server mod_proxy_ftp Authorization HTTP Header Arbitrary FTP Command Injection
11640| [57851] Apache HTTP Server mod_proxy_ftp EPSV Command NULL Dereference Remote DoS
11641| [56984] Apache Xerces2 Java Malformed XML Input DoS
11642| [56903] Apache ODE (Orchestration Director Engine) Process Deployment Web Service Traversal Arbitrary File Manipulation
11643| [56859] Apache Xerces-C++ Multiple Sub-project XML Nested DTD Structures Parsing Recursion Error DoS
11644| [56766] Apache Portable Runtime (APR-util) memory/unix/apr_pools.c Relocatable Memory Block Aligning Overflow
11645| [56765] Apache Portable Runtime (APR-util) misc/apr_rmm.c Multiple Function Overflows
11646| [56517] Apache HTTP Server File Descriptor Leak Arbitrary Local File Append
11647| [56443] PTK Unspecified Apache Sub-process Arbitrary Command Execution
11648| [56414] Apache Tiles Duplicate Expression Language (EL) Expression Evaluation XSS
11649| [55814] mod_NTLM for Apache HTTP Server ap_log_rerror() Function Remote Format String
11650| [55813] mod_NTLM for Apache HTTP Server log() Function Remote Overflow
11651| [55782] Apache HTTP Server mod_deflate Module Aborted Connection DoS
11652| [55553] Apache HTTP Server mod_proxy Module mod_proxy_http.c stream_reqbody_cl Function CPU Consumption DoS
11653| [55059] Apache APR-util strmatch/apr_strmatch.c apr_strmatch_precompile Function Crafted Input Remote DoS
11654| [55058] Apache APR-util apr_brigade_vprintf Function Crafted Input Off-by-one Remote DoS
11655| [55057] Apache APR-util xml/apr_xml.c apr_xml_* Interface Expat XML Parser Crafted XML Document Remote DoS
11656| [55056] Apache Tomcat Cross-application TLD File Manipulation
11657| [55055] Apache Tomcat Illegal URL Encoded Password Request Username Enumeration
11658| [55054] Apache Tomcat Java AJP Connector mod_jk Load Balancing Worker Malformed Header Remote DoS
11659| [55053] Apache Tomcat Crafted Request Security Restraint Bypass Arbitrary Content Access
11660| [54733] Apache HTTP Server AllowOverride Directive .htaccess Options Bypass
11661| [54713] razorCMS Security Manager apache User Account Unspecified File Permission Weakness Issue
11662| [54589] Apache Jserv Nonexistent JSP Request XSS
11663| [54122] Apache Struts s:a / s:url Tag href Element XSS
11664| [54093] Apache ActiveMQ Web Console JMS Message XSS
11665| [53932] Apache Geronimo Multiple Admin Function CSRF
11666| [53931] Apache Geronimo /console/portal/Server/Monitoring Multiple Parameter XSS
11667| [53930] Apache Geronimo /console/portal/ URI XSS
11668| [53929] Apache Geronimo on Windows Security/Keystores Portlet Traversal Arbitrary File Upload
11669| [53928] Apache Geronimo on Windows Embedded DB/DB Manager Portlet Traversal Arbitrary File Upload
11670| [53927] Apache Geronimo on Windows Services/Repository Portlet Traversal Arbitrary File Upload
11671| [53921] Apache HTTP Server mod_proxy_ajp Cross Thread/Session Information Disclosure
11672| [53766] Oracle BEA WebLogic Server Plug-ins for Apache Certificate Handling Remote Overflow
11673| [53574] PHP on Apache .htaccess mbstring.func_overload Setting Cross Hosted Site Behavior Modification
11674| [53381] Apache Tomcat JK Connector Content-Length Header Cross-user Information Disclosure
11675| [53380] Apache Struts Unspecified XSS
11676| [53289] Apache mod_perl Apache::Status /perl-status Unspecified XSS
11677| [53186] Apache HTTP Server htpasswd Predictable Salt Weakness
11678| [52899] Apache Tomcat Examples Web Application Calendar Application jsp/cal/cal2.jsp time Parameter XSS
11679| [52407] Apache Tomcat doRead Method POST Content Information Disclosure
11680| [51923] Apache HTTP Server mod-auth-mysql Module mod_auth_mysql.c Multibyte Character Encoding SQL Injection
11681| [51613] Apache HTTP Server Third-party Module Child Process File Descriptor Leak
11682| [51612] Apache HTTP Server Internal Redirect Handling Infinite Loop DoS
11683| [51468] Apache Jackrabbit Content Repository (JCR) swr.jsp q Parameter XSS
11684| [51467] Apache Jackrabbit Content Repository (JCR) search.jsp q Parameter XSS
11685| [51151] Apache Roller Search Function q Parameter XSS
11686| [50482] PHP with Apache php_value Order Unspecified Issue
11687| [50475] Novell NetWare ApacheAdmin Console Unauthenticated Access
11688| [49734] Apache Struts DefaultStaticContentLoader Class Traversal Arbitrary File Access
11689| [49733] Apache Struts FilterDispatcher Class Traversal Arbitrary File Access
11690| [49283] Oracle BEA WebLogic Server Plugins for Apache Remote Transfer-Encoding Overflow
11691| [49062] Apache Tomcat Cross-thread Concurrent Request Variable Overwrite Information Disclosure
11692| [48847] ModSecurity (mod_security) Transformation Caching Unspecified Apache DoS
11693| [48788] Apache Xerces-C++ XML Schema maxOccurs Value XML File Handling DoS
11694| [47474] Apache HTTP Server mod_proxy_ftp Directory Component Wildcard Character XSS
11695| [47464] Apache Tomcat allowLinking / UTF-8 Traversal Arbitrary File Access
11696| [47463] Apache Tomcat RequestDispatcher Traversal Arbitrary File Access
11697| [47462] Apache Tomcat HttpServletResponse.sendError Method Message Argument XSS
11698| [47096] Oracle Weblogic Apache Connector POST Request Overflow
11699| [46382] Frontend Filemanager (air_filemanager) Extension for TYPO3 on Apache Unspecified Arbitrary Code Execution
11700| [46285] TYPO3 on Apache Crafted Filename Upload Arbitrary Command Execution
11701| [46085] Apache HTTP Server mod_proxy ap_proxy_http_process_response() Function Interim Response Forwarding Remote DoS
11702| [45905] Apache Tomcat Host Manager host-manager/html/add name Parameter XSS
11703| [45879] Ragnarok Online Control Panel on Apache Crafted Traversal Authentication Bypass
11704| [45742] Apache HTTP Server on Novell Unspecified Request Directive Internal IP Disclosure
11705| [45740] Apache Derby DropSchemaNode Bind Phase Arbitrary Scheme Statement Dropping
11706| [45599] Apache Derby Lock Table Statement Privilege Requirement Bypass Arbitrary Table Lock
11707| [45585] Apache Derby ACCSEC Command RDBNAM Parameter Cleartext Credential Disclosure
11708| [45584] Apache Derby DatabaseMetaData.getURL Function Cleartext Credential Disclosure
11709| [45420] Apache HTTP Server 403 Error Page UTF-7 Encoded XSS
11710| [44728] PHP Toolkit on Gentoo Linux Interpretation Conflict Apache HTTP Server Local DoS
11711| [44618] Oracle JSP Apache/Jserv Path Translation Traversal Arbitrary JSP File Execution
11712| [44159] Apache HTTP Server Remote Virtual Host Name Disclosure
11713| [43997] Apache-SSL ExpandCert() Function Certificate Handling Arbitrary Environment Variables Manipulation
11714| [43994] suPHP for Apache (mod_suphp) Directory Symlink Local Privilege Escalation
11715| [43993] suPHP for Apache (mod_suphp) Owner Mode Race Condition Symlink Local Privilege Escalation
11716| [43663] Apache HTTP Server Mixed Platform AddType Directive Crafted Request PHP Source Disclosure
11717| [43658] AuthCAS Module (AuthCAS.pm) for Apache HTTP Server SESSION_COOKIE_NAME SQL Injection
11718| [43452] Apache Tomcat HTTP Request Smuggling
11719| [43309] Apache Geronimo LoginModule Login Method Bypass
11720| [43290] Apache JSPWiki Entry Page Attachment Unrestricted File Upload
11721| [43259] Apache HTTP Server on Windows mod_proxy_balancer URL Handling Remote Memory Corruption
11722| [43224] Apache Geronimo on SuSE Linux init Script Symlink Unspecified File/Directory Access
11723| [43189] Apache mod_jk2 Host Header Multiple Fields Remote Overflow
11724| [42937] Apache HTTP Server mod_proxy_balancer balancer-manager Unspecified CSRF
11725| [42341] MOD_PLSQL for Apache Unspecified URL SQL Injection
11726| [42340] MOD_PLSQL for Apache CGI Environment Handling Unspecified Overflow
11727| [42214] Apache HTTP Server mod_proxy_ftp UTF-7 Encoded XSS
11728| [42091] Apache Maven Site Plugin Installation Permission Weakness
11729| [42089] Apache Maven .m2/settings.xml Cleartext Password Disclosure
11730| [42088] Apache Maven Defined Repo Process Listing Password Disclosure
11731| [42087] Apache Maven Site Plugin SSH Deployment Permission Setting Weakness
11732| [42036] Apache HTTP Server MS-DOS Device Request Host OS Disclosure
11733| [41891] BEA WebLogic Apache Beehive NetUI Page Flow Unspecified XSS
11734| [41436] Apache Tomcat Native APR Connector Duplicate Request Issue
11735| [41435] Apache Tomcat %5C Cookie Handling Session ID Disclosure
11736| [41434] Apache Tomcat Exception Handling Subsequent Request Information Disclosure
11737| [41400] LimeSurvey save.php Apache Log File PHP Code Injection
11738| [41029] Apache Tomcat Calendar Examples Application cal2.jsp Multiple Parameter CSRF
11739| [41019] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload XSS
11740| [41018] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload CRLF
11741| [40853] Apache Tomcat SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) JSESSIONIDSSO Cookie Security Weakness
11742| [40264] Apache HTTP Server mod_proxy_balancer balancer_handler Function bb Variable Remote DoS
11743| [40263] Apache HTTP Server mod_proxy_balancer balancer-manager Multiple Parameter XSS
11744| [40262] Apache HTTP Server mod_status refresh XSS
11745| [39833] Apache Tomcat JULI Logging Component catalina.policy Security Bypass
11746| [39251] Coppermine Photo Gallery on Apache Multiple File Extension Upload Arbitrary Code Execution
11747| [39166] Apache Tomcat on Windows caseSensitive Attribute Mixed Case Request JSP Source Disclosure
11748| [39134] Apache mod_imagemap Module Imagemap Unspecified XSS
11749| [39133] Apache mod_imap Module Imagemap File Unspecified XSS
11750| [39035] Apache Tomcat examples/servlet/CookieExample Multiple Parameter XSS
11751| [39003] Apache HTTP Server HTTP Method Header Request Entity Too Large XSS
11752| [39000] Apache Tomcat SendMailServlet sendmail.jsp mailfrom Parameter XSS
11753| [38939] Apache HTTP Server Prefork MPM Module Array Modification Local DoS
11754| [38673] Apache Jakarta Slide WebDAV SYSTEM Request Traversal Arbitrary File Access
11755| [38662] Apache Geronimo SQLLoginModule Nonexistent User Authentication Bypass
11756| [38661] Apache Geronimo MEJB Unspecified Authentication Bypass
11757| [38641] Apache HTTP Server mod_mem_cache recall_headers Function Information Disclosure
11758| [38640] Apache HTTP Server suexec Document Root Unauthorized Operations
11759| [38639] Apache HTTP Server suexec Multiple Symlink Privilege Escalation
11760| [38636] Apache HTTP Server mod_autoindex.c P Variable UTF-7 Charset XSS
11761| [38513] BEA WebLogic Server Proxy Plug-in for Apache Protocol Error Handling Remote DoS
11762| [38187] Apache Geronimo / Tomcat WebDAV XML SYSTEM Tag Arbitrary File Access
11763| [37079] Apache HTTP Server mod_cache cache_util.c Malformed Cache-Control Header DoS
11764| [37071] Apache Tomcat Cookie Handling Session ID Disclosure
11765| [37070] Apache Tomcat Cookie Handling Quote Delimiter Session ID Disclosure
11766| [37052] Apache HTTP Server mod_status mod_status.c Unspecified XSS
11767| [37051] Apache HTTP Server mod_proxy modules/proxy/proxy_util.c Crafted Header Remote DoS
11768| [37050] Apache HTTP Server Prefork MPM Module Crafted Code Sequence Local DoS
11769| [36417] Apache Tomcat Host Manager Servlet html/add Action aliases Parameter XSS
11770| [36377] Apache MyFaces Tomahawk JSF Application autoscroll Multiple Script XSS
11771| [36080] Apache Tomcat JSP Examples Crafted URI XSS
11772| [36079] Apache Tomcat Manager Uploaded Filename XSS
11773| [34888] Apache Tomcat Example Calendar Application cal2.jsp time Parameter XSS
11774| [34887] Apache Tomcat implicit-objects.jsp Crafted Header XSS
11775| [34885] Apache Tomcat on IIS Servlet Engine MS-DOS Device Request DoS
11776| [34884] Apache Tomcat on Windows Nonexistent Resource Request Path Disclosure
11777| [34883] Apache Tomcat Crafted JSP File Request Path Disclosure
11778| [34882] Apache Tomcat Default SSL Ciphersuite Configuration Weakness
11779| [34881] Apache Tomcat Malformed Accept-Language Header XSS
11780| [34880] Apache Tomcat HTTP/1.1 Connector NULL Byte Request JSP Source Disclosure
11781| [34879] Apache Tomcat examples/jsp2/jspx/textRotate.jspx XSS
11782| [34878] Apache Tomcat examples/jsp2/el/implicit-objects.jsp XSS
11783| [34877] Apache Tomcat JK Web Server Connector (mod_jk) Double Encoded Traversal Arbitrary File Access
11784| [34876] Apache HTTP Server ScriptAlias CGI Source Disclosure
11785| [34875] Apache Tomcat appdev/sample/web/hello.jsp Multiple Parameter XSS
11786| [34874] Apache Tomcat AJP Connector mod_jk ajp_process_callback Remote Memory Disclosure
11787| [34873] Apache Stats Variable Extraction _REQUEST Ssuperglobal Array Overwrite
11788| [34872] Apache HTTP Server suexec User/Group Combination Weakness Local Privilege Escalation
11789| [34769] Apache Tomcat w/ Proxy Module Double Encoded Traversal Arbitrary File Access
11790| [34541] mod_perl for Apache HTTP Server RegistryCooker.pm PATH_INFO Crafted URI Remote DoS
11791| [34540] mod_perl for Apache HTTP Server PerlRun.pm PATH_INFO Crafted URI Remote DoS
11792| [34398] Apache Tomcat mod_jk Invalid Chunked Encoded Body Information Disclosure
11793| [34154] Apache Axis Nonexistent Java Web Service Path Disclosure
11794| [33855] Apache Tomcat JK Web Server Connector mod_jk.so Long URI Worker Map Remote Overflow
11795| [33816] Apache HTTP Server on Debian Linux TTY Local Privilege Escalation
11796| [33456] Apache HTTP Server Crafted TCP Connection Range Header DoS
11797| [33346] Avaya Multiple Products Apache Tomcat Port Weakness
11798| [32979] Apache Java Mail Enterprise Server (JAMES) Phoenix/MX4J Interface Arbitrary User Creation
11799| [32978] Apache Java Mail Enterprise Server (JAMES) POP3Server Log File Plaintext Password Disclosure
11800| [32724] Apache mod_python _filter_read Freed Memory Disclosure
11801| [32723] Apache Tomcat semicolon Crafted Filename Request Forced Directory Listing
11802| [32396] Apache Open For Business Project (OFBiz) Ecommerce Component Forum Implementation Message Body XSS
11803| [32395] Apache Open For Business Project (OFBiz) Ecommerce Component Form Field Manipulation Privilege Escalation
11804| [30354] Linux Subversion libapache2-svn Search Path Subversion Local Privilege Escalation
11805| [29603] PHP ini_restore() Apache httpd.conf Options Bypass
11806| [29536] Apache Tcl mod_tcl set_var Function Remote Format String
11807| [28919] Apache Roller Weblogger Blog Comment Multiple Field XSS
11808| [28130] PHP with Apache Mixed Case Method Limit Directive Bypass
11809| [27913] Apache HTTP Server on Windows mod_alias URL Validation Canonicalization CGI Source Disclosure
11810| [27588] Apache HTTP Server mod_rewrite LDAP Protocol URL Handling Overflow
11811| [27487] Apache HTTP Server Crafted Expect Header Cross Domain HTML Injection
11812| [26935] FCKeditor on Apache connector.php Crafted File Extension Arbitrary File Upload
11813| [26572] Apache Java Mail Enterprise Server (JAMES) MAIL Command Overflow DoS
11814| [25909] Drupal on Apache files Directory File Upload Arbitrary Code Execution
11815| [24825] Oracle ModPL/SQL for Apache Unspecified Remote HTTP Issue
11816| [24365] Apache Struts Multiple Function Error Message XSS
11817| [24364] Apache Struts getMultipartRequestHandler() Function Crafted Request DoS
11818| [24363] Apache Struts org.apache.struts.taglib.html.Constants.CANCEL Validation Bypass
11819| [24103] Pubcookie Apache mod_pubcookie Unspecified XSS
11820| [23906] Apache mod_python for Apache HTTP Server FileSession Privileged Local Command Execution
11821| [23905] Apache Log4net LocalSyslogAppender Format String Memory Corruption DoS
11822| [23198] Apache WSS4J Library SOAP Signature Verification Bypass
11823| [23124] Generic Apache Request Library (libapreq) apreq_parse_* Functions Remote DoS
11824| [22652] mod_php for Apache HTTP Server Crafted import_request_variables Function DoS
11825| [22475] PHP w/ Apache PDO::FETCH_CLASS __set() Function DoS
11826| [22473] PHP w/ Apache2 Crafted PDOStatement DoS
11827| [22459] Apache Geronimo Error Page XSS
11828| [22458] Apache Tomcat / Geronimo Sample Script cal2.jsp time Parameter XSS
11829| [22301] auth_ldap for Apache HTTP Server auth_ldap_log_reason() Function Remote Format String
11830| [22261] Apache HTTP Server mod_ssl ssl_hook_Access Error Handling DoS
11831| [22259] mod_auth_pgsql for Apache HTTP Server Log Function Format String
11832| [21736] Apache Java Mail Enterprise Server (JAMES) Spooler retrieve Function DoS
11833| [21705] Apache HTTP Server mod_imap Image Map Referer XSS
11834| [21021] Apache Struts Error Message XSS
11835| [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
11836| [20491] PHP mod_php apache2handler SAPI Crafted .htaccess DoS
11837| [20462] Apache HTTP Server worker.c MPM Memory Exhaustion DoS
11838| [20439] Apache Tomcat Directory Listing Saturation DoS
11839| [20373] Apache Tomcat on HP Secure OS for Linux Unspecified Servlet Access Issue
11840| [20285] Apache HTTP Server Log File Control Character Injection
11841| [20242] Apache HTTP Server mod_usertrack Predictable Session ID Generation
11842| [20209] Brainf*ck Module (mod_bf) for Apache HTTP Server Local Overflow
11843| [20033] Apache Tomcat MS-DOS Device Request Error Message Path Disclosure
11844| [19883] apachetop atop.debug Symlink Arbitrary File Overwrite
11845| [19863] mod_auth_shadow for Apache HTTP Server require group Authentication Bypass
11846| [19855] Apache HTTP Server ErrorDocument Directive .htaccess Bypass
11847| [19821] Apache Tomcat Malformed Post Request Information Disclosure
11848| [19769] Apache HTTP Server Double-reverse DNS Lookup Spoofing
11849| [19188] Apache HTTP Server mod_ssl SSLVerifyClient Per-location Context Restriction Bypass
11850| [19137] Apache HTTP Server on Red Hat Linux Double Slash GET Request Forced Directory Listing
11851| [19136] Apache on Mandrake Linux Arbitrary Directory Forced Listing
11852| [18977] Apache HTTP Server Crafted HTTP Range Header DoS
11853| [18389] Ragnarok Online Control Panel Apache Authentication Bypass
11854| [18286] Apache HTTP Server mod_ssl ssl_callback_SSLVerify_CRL( ) Function Overflow
11855| [18233] Apache HTTP Server htdigest user Variable Overfow
11856| [17738] Apache HTTP Server HTTP Request Smuggling
11857| [16586] Apache HTTP Server Win32 GET Overflow DoS
11858| [15889] Apache HTTP Server mod_cgid Threaded MPM CGI Output Misdirection
11859| [14896] mod_dav for Apache HTTP Server Remote Null Dereference Child Process Termination
11860| [14879] Apache HTTP Server ap_log_rerror Function Error Message Path Disclosure
11861| [14770] Apache Tomcat AJP12 Protocol Malformed Packet Remote DoS
11862| [14597] Apache Tomcat IntegerOverflow.jsp Test JSP Script Path Disclosure
11863| [14596] Apache Tomcat pageSession.jsp Test JSP Script Path Disclosure
11864| [14595] Apache Tomcat pageLanguage.jsp Test JSP Script Path Disclosure
11865| [14594] Apache Tomcat pageIsThreadSafe.jsp Test JSP Script Path Disclosure
11866| [14593] Apache Tomcat pageIsErrorPage.jsp Test JSP Script Path Disclosure
11867| [14592] Apache Tomcat pageInvalid.jsp Test JSP Script Path Disclosure
11868| [14591] Apache Tomcat pageExtends.jsp Test JSP Script Path Disclosure
11869| [14590] Apache Tomcat pageDouble.jsp Test JSP Script Path Disclosure
11870| [14589] Apache Tomcat pageAutoFlush.jsp Test JSP Script Path Disclosure
11871| [14588] Apache Tomcat extends2.jsp Test JSP Script Path Disclosure
11872| [14587] Apache Tomcat extends1.jsp Test JSP Script Path Disclosure
11873| [14586] Apache Tomcat comments.jsp Test JSP Script Path Disclosure
11874| [14585] Apache Tomcat buffer4.jsp Test JSP Script Path Disclosure
11875| [14584] Apache Tomcat buffer3.jsp Test JSP Script Path Disclosure
11876| [14583] Apache Tomcat buffer2.jsp Test JSP Script Path Disclosure
11877| [14582] Apache Tomcat buffer1.jsp Test JSP Script Path Disclosure
11878| [14581] Apache Tomcat pageImport2.jsp Test JSP Script Path Disclosure
11879| [14580] Apache Tomcat pageInfo.jsp Test JSP Script Path Disclosure
11880| [14410] mod_frontpage for Apache HTTP Server fpexec Remote Overflow
11881| [14044] Apache Batik Squiggle Browser with Rhino Scripting Engine Unspecified File System Access
11882| [13737] mod_access_referer for Apache HTTP Server Malformed Referer DoS
11883| [13711] Apache mod_python publisher.py Traversal Arbitrary Object Information Disclosure
11884| [13640] mod_auth_any for Apache HTTP Server on Red Hat Linux Metacharacter Command Execution
11885| [13304] Apache Tomcat realPath.jsp Path Disclosure
11886| [13303] Apache Tomcat source.jsp Arbitrary Directory Listing
11887| [13087] Apache HTTP Server mod_log_forensic check_forensic Symlink Arbitrary File Creation / Overwrite
11888| [12849] mod_auth_radius for Apache HTTP Server radcpy() Function Overflow DoS
11889| [12848] Apache HTTP Server htdigest realm Variable Overflow
11890| [12721] Apache Tomcat examples/jsp2/el/functions.jsp XSS
11891| [12720] mod_dosevasive for Apache HTTP Server Symlink Arbitrary File Create/Overwrite
11892| [12558] Apache HTTP Server IPv6 FTP Proxy Socket Failure DoS
11893| [12557] Apache HTTP Server prefork MPM accept Error DoS
11894| [12233] Apache Tomcat MS-DOS Device Name Request DoS
11895| [12232] Apache Tomcat with JDK Arbitrary Directory/Source Disclosure
11896| [12231] Apache Tomcat web.xml Arbitrary File Access
11897| [12193] Apache HTTP Server on Mac OS X File Handler Bypass
11898| [12192] Apache HTTP Server on Mac OS X Unauthorized .ht and .DS_Store File Access
11899| [12178] Apache Jakarta Lucene results.jsp XSS
11900| [12176] mod_digest_apple for Apache HTTP Server on Mac OS X Authentication Replay
11901| [11391] Apache HTTP Server Header Parsing Space Saturation DoS
11902| [11003] Apache HTTP Server mod_include get_tag() Function Local Overflow
11903| [10976] mod_mylo for Apache HTTP Server mylo_log Logging Function HTTP GET Overflow
11904| [10637] Apache HTTP Server mod_ssl SSLCipherSuite Access Restriction Bypass
11905| [10546] Macromedia JRun4 mod_jrun Apache Module Remote Overflow
11906| [10471] Apache Xerces-C++ XML Parser DoS
11907| [10218] Apache HTTP Server Satisfy Directive Access Control Bypass
11908| [10068] Apache HTTP Server htpasswd Local Overflow
11909| [10049] mod_cplusplus For Apache HTTP Server Unspecified Overflow
11910| [9994] Apache HTTP Server apr-util IPV6 Parsing DoS
11911| [9991] Apache HTTP Server ap_resolve_env Environment Variable Local Overflow
11912| [9948] mod_dav for Apache HTTP Server LOCK Request DoS
11913| [9742] Apache HTTP Server mod_ssl char_buffer_read Function Reverse Proxy DoS
11914| [9718] Apache HTTP Server Win32 Single Dot Append Arbitrary File Access
11915| [9717] Apache HTTP Server mod_cookies Cookie Overflow
11916| [9716] Apache::Gallery Gallery.pm Inline::C Predictable Filename Code Execution
11917| [9715] Apache HTTP Server rotatelogs Control Characters Over Pipe DoS
11918| [9714] Apache Authentication Module Threaded MPM DoS
11919| [9713] Apache HTTP Server on OS2 filestat.c Device Name Request DoS
11920| [9712] Apache HTTP Server Multiple Linefeed Request Memory Consumption DoS
11921| [9711] Apache HTTP Server Access Log Terminal Escape Sequence Injection
11922| [9710] Apache HTTP Server on Windows Illegal Character Default Script Mapping Bypass
11923| [9709] Apache HTTP Server on Windows MS-DOS Device Name HTTP Post Code Execution
11924| [9708] Apache HTTP Server on Windows MS-DOS Device Name DoS
11925| [9707] Apache HTTP Server Duplicate MIME Header Saturation DoS
11926| [9706] Apache Web Server Multiple MIME Header Saturation Remote DoS
11927| [9705] Apache Tomcat Invoker/Default Servlet Source Disclosure
11928| [9702] Apache HTTP Server CGI/WebDAV HTTP POST Request Source Disclosure
11929| [9701] Apache HTTP Server for Windows Multiple Slash Forced Directory Listing
11930| [9700] Apache HTTP Server mod_autoindex Multiple Slash Request Forced Directory Listing
11931| [9699] Apache HTTP Server mod_dir Multiple Slash Request Forced Directory Listing
11932| [9698] Apache HTTP Server mod_negotiation Multiple Slash Request Forced Directory Listing
11933| [9697] Apache HTTP Server htdigest Local Symlink Arbitrary File Overwrite
11934| [9696] Apache HTTP Server htpasswd Local Symlink Arbitrary File Overwrite
11935| [9695] Apache Tomcat SnoopServlet Servlet Information Disclosure
11936| [9694] PHP3 on Apache HTTP Server Encoded Traversal Arbitrary File Access
11937| [9693] mod_auth_pgsql_sys for Apache HTTP Server User Name SQL Injection
11938| [9692] Apache HTTP Server mod_vhost_alias Mass Virtual Hosting Arbitrary File Access
11939| [9691] Apache HTTP Server mod_rewrite Mass Virtual Hosting Arbitrary File Access
11940| [9690] Apache HTTP Server mod_vhost_alias CGI Program Source Disclosure
11941| [9689] Trustix httpsd for Apache-SSL Permission Weakness Privilege Escalation
11942| [9688] Apache HTTP Server mod_proxy Malformed FTP Command DoS
11943| [9687] Apache::AuthenSmb smbval SMB Authentication Library Multiple Overflows
11944| [9686] Apache::AuthenSmb smbvalid SMB Authentication Library Multiple Overflows
11945| [9523] Apache HTTP Server mod_ssl Aborted Connection DoS
11946| [9459] Oracle PL/SQL (mod_plsql) Apache Module Help Page Request Remote Overflow
11947| [9208] Apache Tomcat .jsp Encoded Newline XSS
11948| [9204] Apache Tomcat ROOT Application XSS
11949| [9203] Apache Tomcat examples Application XSS
11950| [9068] Apache HTTP Server mod_userdir User Account Information Disclosure
11951| [8773] Apache Tomcat Catalina org.apache.catalina.servlets.DefaultServlet Source Code Disclosure
11952| [8772] Apache Tomcat Catalina org.apache.catalina.connector.http DoS
11953| [7943] Apache HTTP Server mod_ssl sslkeys File Disclosure
11954| [7942] Apache HTTP Server mod_ssl Default Pass Phrase
11955| [7941] Apache HTTP Server mod_ssl Encrypted Private Key File Descriptor Leak
11956| [7935] Apache HTTP Server mod_ssl ssl_gcache Race Conditions
11957| [7934] Apache HTTP Server mod_ssl SSLSessionCache File Content Disclosure
11958| [7933] Apache HTTP Server mod_ssl SSLMutex File Content Disclosure
11959| [7932] Apache HTTP Server mod_ssl mkcert.sh File Creation Permission Weakness
11960| [7931] Apache HTTP Server mod_ssl X.509 Client Certificate Authentication Bypass
11961| [7930] Apache HTTP Server mod_ssl ssl_expr_eval_func_file() Overflow
11962| [7929] Apache HTTP Server mod_ssl ssl_engine_log.c mod_proxy Hook Function Remote Format String
11963| [7611] Apache HTTP Server mod_alias Local Overflow
11964| [7394] Apache Tomcat mod_jk Invalid Transfer-Encoding Chunked Field DoS
11965| [7203] Apache Tomcat source.jsp Traversal Arbitrary File Access
11966| [7039] Apache HTTP Server on Mac OS X HFS+ File System Access Bypass
11967| [6882] Apache mod_python Malformed Query String Variant DoS
11968| [6839] Apache HTTP Server mod_proxy Content-Length Overflow
11969| [6630] Apache Tomcat Java Server Pages (JSP) Engine WPrinterJob() DoS
11970| [6472] Apache HTTP Server mod_ssl ssl_util_uuencode_binary Remote Overflow
11971| [5821] Apache HTTP Server Multiple / GET Remote Overflow DoS
11972| [5580] Apache Tomcat Servlet Malformed URL JSP Source Disclosure
11973| [5552] Apache HTTP Server split-logfile Arbitrary .log File Overwrite
11974| [5526] Apache Tomcat Long .JSP URI Path Disclosure
11975| [5278] Apache Tomcat web.xml Restriction Bypass
11976| [5051] Apache Tomcat Null Character DoS
11977| [4973] Apache Tomcat servlet Mapping XSS
11978| [4650] mod_gzip for Apache HTTP Server Debug Mode Printf Stack Overflow
11979| [4649] mod_gzip for Apache HTTP Server Debug Mode Format String Overflow
11980| [4648] mod_gzip for Apache HTTP Server Debug Mode Race Condition
11981| [4568] mod_survey For Apache ENV Tags SQL Injection
11982| [4553] Apache HTTP Server ApacheBench Overflow DoS
11983| [4552] Apache HTTP Server Shared Memory Scoreboard DoS
11984| [4446] Apache HTTP Server mod_disk_cache Stores Credentials
11985| [4383] Apache HTTP Server Socket Race Condition DoS
11986| [4382] Apache HTTP Server Log Entry Terminal Escape Sequence Injection
11987| [4340] Apache Portable Runtime (APR) apr_psprintf DoS
11988| [4232] Apache Cocoon DatabaseAuthenticatorAction SQL Injection
11989| [4231] Apache Cocoon Error Page Server Path Disclosure
11990| [4182] Apache HTTP Server mod_ssl Plain HTTP Request DoS
11991| [4181] Apache HTTP Server mod_access IP Address Netmask Rule Bypass
11992| [4075] Apache HTTP Sever on Windows .var File Request Path Disclosure
11993| [4037] Apache HTTP Server on Cygwin Encoded GET Request Arbitrary File Access
11994| [3877] Apache-SSL SSLVerifyClient SSLFakeBasicAuth Client Certificate Forgery
11995| [3819] Apache HTTP Server mod_digest Cross Realm Credential Replay
11996| [3322] mod_php for Apache HTTP Server Process Hijack
11997| [3215] mod_php for Apache HTTP Server File Descriptor Leakage
11998| [2885] Apache mod_python Malformed Query String DoS
11999| [2749] Apache Cocoon view-source Sample File Traversal Arbitrary File Access
12000| [2733] Apache HTTP Server mod_rewrite Local Overflow
12001| [2672] Apache HTTP Server mod_ssl SSLCipherSuite Ciphersuite Downgrade Weakness
12002| [2613] Apache HTTP Server mod_cgi stderr Output Handling Local DoS
12003| [2149] Apache::Gallery Privilege Escalation
12004| [2107] Apache HTTP Server mod_ssl Host: Header XSS
12005| [1926] Apache HTTP Server mod_rewrite Crafted URI Rule Bypass
12006| [1833] Apache HTTP Server Multiple Slash GET Request DoS
12007| [1577] Apache HTTP Server mod_rewrite RewriteRule Expansion Arbitrary File Access
12008| [872] Apache Tomcat Multiple Default Accounts
12009| [862] Apache HTTP Server SSI Error Page XSS
12010| [859] Apache HTTP Server Win32 Crafted Traversal Arbitrary File Access
12011| [849] Apache Tomcat TroubleShooter Servlet Information Disclosure
12012| [845] Apache Tomcat MSDOS Device XSS
12013| [844] Apache Tomcat Java Servlet Error Page XSS
12014| [842] Apache HTTP Server mod_ssl ssl_compat_directive Function Overflow
12015| [838] Apache HTTP Server Chunked Encoding Remote Overflow
12016| [827] PHP4 for Apache on Windows php.exe Malformed Request Path Disclosure
12017| [775] Apache mod_python Module Importing Privilege Function Execution
12018| [769] Apache HTTP Server Win32 DOS Batch File Arbitrary Command Execution
12019| [756] Apache HTTP Server mod_ssl i2d_SSL_SESSION Function SSL Client Certificate Overflow
12020| [701] Apache HTTP Server Win32 ScriptAlias php.exe Arbitrary File Access
12021| [674] Apache Tomcat Nonexistent File Error Message Path Disclosure
12022| [637] Apache HTTP Server UserDir Directive Username Enumeration
12023| [623] mod_auth_pgsql for Apache HTTP Server User Name SQL Injection
12024| [582] Apache HTTP Server Multiviews Feature Arbitrary Directory Listing
12025| [562] Apache HTTP Server mod_info /server-info Information Disclosure
12026| [561] Apache Web Servers mod_status /server-status Information Disclosure
12027| [417] Apache HTTP Server on SuSE Linux /doc/packages Remote Information Disclosure
12028| [410] mod_perl for Apache HTTP Server /perl/ Directory Listing
12029| [404] Apache HTTP Server on SuSE Linux WebDAV PROPFIND Arbitrary Directory Listing
12030| [402] Apache HTTP Server on SuSE Linux cgi-bin-sdb Request Script Source Disclosure
12031| [379] Apache ASP module Apache::ASP source.asp Example File Arbitrary File Creation
12032| [377] Apache Tomcat Snoop Servlet Remote Information Disclosure
12033| [376] Apache Tomcat contextAdmin Arbitrary File Access
12034| [342] Apache HTTP Server for Windows Multiple Forward Slash Directory Listing
12035| [222] Apache HTTP Server test-cgi Arbitrary File Access
12036| [143] Apache HTTP Server printenv.pl Multiple Method CGI XSS
12037| [48] Apache HTTP Server on Debian /usr/doc Directory Information Disclosure
12038|_
12039Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
12040Aggressive OS guesses: Crestron XPanel control system (87%), Vodavi XTS-IP PBX (87%), HP P2000 G3 NAS device (86%), ASUS RT-N56U WAP (Linux 3.4) (86%), Linux 3.16 (86%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (85%), Sun Solaris 10 (85%), Sun Solaris 9 or 10 (85%), Sun Solaris 9 or 10, or OpenSolaris 2009.06 snv_111b (85%)
12041No exact OS matches for host (test conditions non-ideal).
12042Uptime guess: 28.793 days (since Sat Dec 21 09:35:25 2019)
12043Network Distance: 25 hops
12044TCP Sequence Prediction: Difficulty=158 (Good luck!)
12045IP ID Sequence Generation: Incremental
12046
12047TRACEROUTE (using port 443/tcp)
12048HOP RTT ADDRESS
120491 103.76 ms 10.253.204.1
120502 133.53 ms 104.245.145.177
120513 133.60 ms te0-0-2-1.225.nr11.b010988-1.yyz02.atlas.cogentco.com (38.104.156.9)
120524 133.63 ms te0-0-0-1.agr13.yyz02.atlas.cogentco.com (154.24.54.37)
120535 133.60 ms te0-9-0-9.ccr32.yyz02.atlas.cogentco.com (154.54.43.153)
120546 133.66 ms be2994.ccr22.cle04.atlas.cogentco.com (154.54.31.233)
120557 133.70 ms be2718.ccr42.ord01.atlas.cogentco.com (154.54.7.129)
120568 133.76 ms be2832.ccr22.mci01.atlas.cogentco.com (154.54.44.169)
120579 205.50 ms be3036.ccr22.den01.atlas.cogentco.com (154.54.31.89)
1205810 205.59 ms be3038.ccr32.slc01.atlas.cogentco.com (154.54.42.97)
1205911 124.04 ms be3110.ccr22.sfo01.atlas.cogentco.com (154.54.44.141)
1206012 167.68 ms be3670.ccr41.sjc03.atlas.cogentco.com (154.54.43.14)
1206113 137.37 ms 38.88.224.178
1206214 167.56 ms 111.87.3.113
1206315 236.93 ms oteACS001.int-gw.kddi.ne.jp.13.187.106.in-addr.arpa (106.187.13.13)
1206416 267.58 ms 27.85.224.198
1206517 267.63 ms 125.29.26.58
1206618 267.60 ms 133.208.191.11
1206719 226.62 ms 133.208.55.50
1206820 226.62 ms unused-133-130-015-097.interq.or.jp (133.130.15.97)
1206921 235.62 ms unused-133-130-013-018.interq.or.jp (133.130.13.18)
1207022 227.24 ms g-o-p-2w-a18-1-e-1-10.interq.or.jp (157.7.40.130)
1207123 267.05 ms unused-157-007-038-082.interq.or.jp (157.7.38.82)
1207224 ...
1207325 226.48 ms www18.gmoserver.jp (133.130.64.112)
12074
12075NSE: Script Post-scanning.
12076Initiating NSE at 04:36
12077Completed NSE at 04:36, 0.00s elapsed
12078Initiating NSE at 04:36
12079Completed NSE at 04:36, 0.00s elapsed
12080#######################################################################################################################################
12081Version: 1.11.13-static
12082OpenSSL 1.0.2-chacha (1.0.2g-dev)
12083
12084Connected to 133.130.64.112
12085
12086Testing SSL server 133.130.64.112 on port 443 using SNI name 133.130.64.112
12087
12088 TLS Fallback SCSV:
12089Server supports TLS Fallback SCSV
12090
12091 TLS renegotiation:
12092Session renegotiation not supported
12093
12094 TLS Compression:
12095Compression disabled
12096
12097 Heartbleed:
12098TLS 1.2 not vulnerable to heartbleed
12099TLS 1.1 not vulnerable to heartbleed
12100TLS 1.0 not vulnerable to heartbleed
12101
12102 Supported Server Cipher(s):
12103Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384 Curve P-256 DHE 256
12104Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-GCM-SHA256 Curve P-256 DHE 256
12105Accepted TLSv1.2 256 bits DHE-RSA-AES256-GCM-SHA384 DHE 2048 bits
12106Accepted TLSv1.2 128 bits DHE-RSA-AES128-GCM-SHA256 DHE 2048 bits
12107Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA384 Curve P-256 DHE 256
12108Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
12109Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA256 DHE 2048 bits
12110Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA DHE 2048 bits
12111Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA256 Curve P-256 DHE 256
12112Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
12113Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA256 DHE 2048 bits
12114Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA DHE 2048 bits
12115Accepted TLSv1.2 256 bits AES256-GCM-SHA384
12116Accepted TLSv1.2 128 bits AES128-GCM-SHA256
12117Accepted TLSv1.2 256 bits AES256-SHA256
12118Accepted TLSv1.2 256 bits AES256-SHA
12119Accepted TLSv1.2 128 bits AES128-SHA256
12120Accepted TLSv1.2 128 bits AES128-SHA
12121
12122 SSL Certificate:
12123Signature Algorithm: sha256WithRSAEncryption
12124RSA Key Strength: 2048
12125
12126Subject: *.gmoserver.jp
12127Altnames: DNS:*.gmoserver.jp, DNS:gmoserver.jp
12128Issuer: GlobalSign RSA DV SSL CA 2018
12129
12130Not valid before: Dec 20 06:01:34 2019 GMT
12131Not valid after: Feb 14 07:59:06 2022 GMT
12132#######################################################################################################################################
12133Starting Nmap 7.80 ( https://nmap.org ) at 2020-01-19 04:40 EST
12134NSE: Loaded 47 scripts for scanning.
12135NSE: Script Pre-scanning.
12136Initiating NSE at 04:40
12137Completed NSE at 04:40, 0.00s elapsed
12138Initiating NSE at 04:40
12139Completed NSE at 04:40, 0.00s elapsed
12140Initiating Parallel DNS resolution of 1 host. at 04:40
12141Completed Parallel DNS resolution of 1 host. at 04:40, 0.02s elapsed
12142Initiating SYN Stealth Scan at 04:40
12143Scanning www18.gmoserver.jp (133.130.64.112) [65535 ports]
12144Discovered open port 80/tcp on 133.130.64.112
12145Discovered open port 443/tcp on 133.130.64.112
12146SYN Stealth Scan Timing: About 20.74% done; ETC: 04:43 (0:01:58 remaining)
12147SYN Stealth Scan Timing: About 24.39% done; ETC: 04:45 (0:03:09 remaining)
12148SYN Stealth Scan Timing: About 27.48% done; ETC: 04:46 (0:04:00 remaining)
12149SYN Stealth Scan Timing: About 30.73% done; ETC: 04:47 (0:04:33 remaining)
12150SYN Stealth Scan Timing: About 33.96% done; ETC: 04:48 (0:04:54 remaining)
12151SYN Stealth Scan Timing: About 36.08% done; ETC: 04:49 (0:05:21 remaining)
12152SYN Stealth Scan Timing: About 57.66% done; ETC: 04:52 (0:04:54 remaining)
12153SYN Stealth Scan Timing: About 63.85% done; ETC: 04:52 (0:04:19 remaining)
12154SYN Stealth Scan Timing: About 69.57% done; ETC: 04:53 (0:03:41 remaining)
12155SYN Stealth Scan Timing: About 74.87% done; ETC: 04:53 (0:03:04 remaining)
12156SYN Stealth Scan Timing: About 80.56% done; ETC: 04:53 (0:02:26 remaining)
12157SYN Stealth Scan Timing: About 85.77% done; ETC: 04:53 (0:01:47 remaining)
12158SYN Stealth Scan Timing: About 91.01% done; ETC: 04:53 (0:01:09 remaining)
12159Completed SYN Stealth Scan at 04:54, 799.16s elapsed (65535 total ports)
12160Initiating Service scan at 04:54
12161Scanning 2 services on www18.gmoserver.jp (133.130.64.112)
12162Completed Service scan at 04:54, 13.45s elapsed (2 services on 1 host)
12163Initiating OS detection (try #1) against www18.gmoserver.jp (133.130.64.112)
12164Retrying OS detection (try #2) against www18.gmoserver.jp (133.130.64.112)
12165Initiating Traceroute at 04:54
12166Completed Traceroute at 04:54, 3.22s elapsed
12167Initiating Parallel DNS resolution of 24 hosts. at 04:54
12168Completed Parallel DNS resolution of 24 hosts. at 04:54, 0.73s elapsed
12169NSE: Script scanning 133.130.64.112.
12170Initiating NSE at 04:54
12171Completed NSE at 04:54, 6.75s elapsed
12172Initiating NSE at 04:54
12173Completed NSE at 04:54, 2.10s elapsed
12174Nmap scan report for www18.gmoserver.jp (133.130.64.112)
12175Host is up (0.23s latency).
12176Not shown: 65533 closed ports
12177PORT STATE SERVICE VERSION
1217880/tcp open http Apache httpd
12179|_http-server-header: Apache
12180| vulscan: VulDB - https://vuldb.com:
12181| [141649] Apache OFBiz up to 16.11.05 Form Widget Freemarker Markup Code Execution
12182| [141648] Apache OFBiz up to 16.11.05 Application Stored cross site scripting
12183| [140386] Apache Commons Beanutils 1.9.2 BeanIntrospector unknown vulnerability
12184| [139708] Apache Ranger up to 1.2.0 Policy Import cross site scripting
12185| [139540] cPanel up to 60.0.24 Apache HTTP Server Key information disclosure
12186| [139386] Apache Tike up to 1.21 RecursiveParserWrapper Stack-based memory corruption
12187| [139385] Apache Tika 1.19/1.20/1.21 SAXParsers Hang denial of service
12188| [139384] Apache Tika up to 1.21 RecursiveParserWrapper ZIP File denial of service
12189| [139261] Apache Solr 8.2.0 DataImportHandler Parameter unknown vulnerability
12190| [139259] cPanel up to 68.0.26 WHM Apache Includes Editor information disclosure
12191| [139256] cPanel up to 68.0.26 WHM Apache Configuration Include Editor cross site scripting
12192| [139239] cPanel up to 70.0.22 Apache HTTP Server Log information disclosure
12193| [139141] Apache ActiveMQ Client up to 5.15.4 ActiveMQConnection.java ActiveMQConnection denial of service
12194| [139130] cPanel up to 73.x Apache HTTP Server Injection privilege escalation
12195| [138914] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 VM sql injection
12196| [138913] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Block Argument privilege escalation
12197| [138912] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Cookie sql injection
12198| [138816] Apache Storm up to 1.2.2 Logviewer Daemon Log information disclosure
12199| [138815] Apache Storm up to 1.2.2 UI Daemon Deserialization privilege escalation
12200| [138164] Oracle 2.7.0.1 Apache Log4j unknown vulnerability
12201| [138155] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Tomcat unknown vulnerability
12202| [138151] Oracle Transportation Management 6.3.7 Apache Tomcat unknown vulnerability
12203| [138149] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Commons FileUpload unknown vulnerability
12204| [138131] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Tomcat unknown vulnerability
12205| [138129] Oracle Retail Xstore Point of Service 7.0/7.1 Apache HTTP Server denial of service
12206| [138123] Oracle Retail Order Management System 5.0 Apache Struts 1 unknown vulnerability
12207| [138122] Oracle Retail Order Broker 5.2/15.0 Apache Tomcat unknown vulnerability
12208| [138121] Oracle Retail Order Broker 5.2/15.0 Apache CXF unknown vulnerability
12209| [138112] Oracle Retail Integration Bus 15.0/16.0 Apache Commons FileUpload unknown vulnerability
12210| [138111] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Commons FileUpload unknown vulnerability
12211| [138103] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56/8.57 Apache WSS4J information disclosure
12212| [138053] Oracle JD Edwards EnterpriseOne Tools 9.2 Apache Log4j unknown vulnerability
12213| [138036] Oracle Insurance Rules Palette 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
12214| [138035] Oracle Insurance Policy Administration J2EE 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
12215| [138034] Oracle Insurance Calculation Engine 9.7/10.0/10.1/10.2 Apache Commons FileUpload unknown vulnerability
12216| [138028] Oracle Identity Manager 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
12217| [138020] Oracle BI Publisher 11.1.1.9.0 Apache Tomcat unknown vulnerability
12218| [138019] Oracle BI Publisher (formerly XML Publisher) 11.1.1.9.0 Apache Tomcat unknown vulnerability
12219| [138017] Oracle Outside In Technology 8.5.4 Apache Commons FileUpload unknown vulnerability
12220| [138013] Oracle Outside In Technology 8.5.4 Apache Tomcat unknown vulnerability
12221| [138012] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
12222| [138009] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
12223| [138008] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Struts 1 denial of service
12224| [138007] Oracle WebCenter Sites 12.2.1.3.0 Apache Tomcat denial of service
12225| [138006] Oracle Enterprise Repository 12.1.3.0.0 Apache CXF denial of service
12226| [138000] Oracle WebCenter Sites 12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
12227| [137999] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
12228| [137995] Oracle Hospitality Simphony 18.2.1 Apache WSS4J information disclosure
12229| [137987] Oracle FLEXCUBE Universal Banking up to 12.0.3/12.4.0/14.2.0 Apache Log4j unknown vulnerability
12230| [137981] Oracle Insurance IFRS 17 Analyzer 8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
12231| [137980] Oracle Insurance Data Foundation 8.0.4/8.0.5/8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
12232| [137979] Oracle 8.0.8 Apache Commons FileUpload unknown vulnerability
12233| [137973] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Batik unknown vulnerability
12234| [137970] Oracle Financial Services Profitability Management 8.0.4/8.0.5/8.0.6/8.0.7 Apache ActiveMQ unknown vulnerability
12235| [137967] Oracle up to 8.0.7 Apache httpd unknown vulnerability
12236| [137966] Oracle 8.0.7/8.0.8 Apache Groovy unknown vulnerability
12237| [137965] Oracle Financial Services Liquidity Risk Management 8.0.1/8.0.2/8.0.4/8.0.5/8.0.6 Apache Commons FileUpload unknown vulnerability
12238| [137964] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Log4j unknown vulnerability
12239| [137933] Oracle Banking Platform up to 2.7.1 Apache Tika unknown vulnerability
12240| [137926] Oracle Enterprise Manager for Fusion Middleware 13.2/13.3 Apache Commons FileUpload information disclosure
12241| [137924] Oracle Enterprise Manager Base Platform 12.1.0.5.0/13.2.0.0.0/13.3.0.0.0 Apache Commons FileUpload unknown vulnerability
12242| [137914] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
12243| [137913] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
12244| [137911] Oracle E-Business Suite up to 12.2.8 Apache HTTP Server unknown vulnerability
12245| [137910] Oracle E-Business Suite up to 12.2.8 Apache CXF information disclosure
12246| [137909] Oracle E-Business Suite up to 12.2.8 Apache Commons FileUpload unknown vulnerability
12247| [137905] Oracle Primavera Gateway 15.2/16.2/17.12/18.8 Apache Tika denial of service
12248| [137901] Oracle Primavera Unifier up to 18.8 Apache HTTP Server unknown vulnerability
12249| [137895] Oracle Instant Messaging Server 10.0.1.2.0 Apache Tika information disclosure
12250| [137894] Oracle EAGLE (Software) 46.5/46.6/46.7 Apache Tomcat information disclosure
12251| [137892] Oracle Online Mediation Controller 6.1 Apache Batik denial of service
12252| [137891] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Tomcat unknown vulnerability
12253| [137885] Oracle Diameter Signaling Router (DSR) 8.0/8.1/8.2 Apache cxf unknown vulnerability
12254| [137882] Oracle Unified 8.0.0.2.0 Apache Commons FileUpload unknown vulnerability
12255| [137881] Oracle Online Mediation Controller 6.1 Apache Commons FileUpload unknown vulnerability
12256| [137880] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Log4j unknown vulnerability
12257| [137879] Oracle Convergence 3.0.2 Apache Commons FileUpload unknown vulnerability
12258| [137876] Oracle Application Session Controller 3.7.1/3.8.0 Apache Commons FileUpload unknown vulnerability
12259| [137829] Apache Roller 5.2.3 Math Comment Authenticator Reflected cross site scripting
12260| [137736] Apache Kafka 0.11.0.0/2.1.0 ACL Validation Request privilege escalation
12261| [136858] MakerBot Replicator 5G Printer Apache HTTP Server information disclosure
12262| [136849] Analogic Poste.io 2.1.6 on Apache RoundCube logs/ information disclosure
12263| [136822] Apache Tomcat up to 8.5.40/9.0.19 Incomplete Fix CVE-2019-0199 Resource Exhaustion denial of service
12264| [136808] Apache Geode up to 1.8.0 Secure Mode privilege escalation
12265| [136646] Apache Allura up to 1.10.x Dropdown Selector Stored cross site scripting
12266| [136374] Apache HTTP Server up to 2.4.38 Slash Regular Expression unknown vulnerability
12267| [136373] Apache HTTP Server 2.4.34/2.4.35/2.4.36/2.4.37/2.4.38 HTTP2 Request Crash denial of service
12268| [136372] Apache HTTP Server up to 2.4.38 HTTP2 Request unknown vulnerability
12269| [136370] Apache Fineract up to 1.2.x sql injection
12270| [136369] Apache Fineract up to 1.2.x sql injection
12271| [135731] Apache Hadoop up to 2.8.4/2.9.1/3.1.0 yarn privilege escalation
12272| [135664] Apache Tomcat up to 7.0.93/8.5.39/9.0.0.17 SSI printenv Command cross site scripting
12273| [135663] Apache Camel up to 2.23.x JSON-lib Library XML Data XML External Entity
12274| [135661] Apache Roller up to 5.2.1/5.2.0 XML-RPC Interface XML File Server-Side Request Forgery
12275| [135402] Apache Zookeeper up to 3.4.13/3.5.0-alpha to 3.5.4-beta getACL() information disclosure
12276| [135270] Apache JSPWiki up to 2.11.0.M3 Plugin Link cross site scripting
12277| [135269] Apache JSPWiki up to 2.11.0.M3 InterWiki Link cross site scripting
12278| [135268] Apache JSPWiki up to 2.11.0.M3 Attachment cross site scripting
12279| [134527] Apache Karaf up to 4.2.4 Config Service directory traversal
12280| [134416] Apache Sanselan 0.97-incubator Loop denial of service
12281| [134415] Apache Sanselan 0.97-incubator Hang denial of service
12282| [134291] Apache Axis up to 1.7.8 Server-Side Request Forgery
12283| [134290] Apache UIMA DUCC up to 2.2.2 cross site scripting
12284| [134248] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
12285| [134247] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
12286| [134246] Apache Camel up to 2.19/2.21.3/2.22.2/2.23.0 directory traversal
12287| [134138] Apache Pluto 3.0.0/3.0.1 Chat Room Demo Portlet cross site scripting
12288| [133992] Apache Qpid Proton up to 0.27.0 Certificate Validation Man-in-the-Middle weak authentication
12289| [133977] Apache Zeppelin up to 0.7.x Stored cross site scripting
12290| [133976] Apache Zeppelin up to 0.7.x Cron Scheduler privilege escalation
12291| [133975] Apache Zeppelin up to 0.7.2 Session Fixation weak authentication
12292| [133444] Apache PDFbox 2.0.14 XML Parser XML External Entity
12293| [133573] Oracle FLEXCUBE Private Banking 2.0.0.0/2.2.0.1/12.0.1.0/12.0.3.0/12.1.0.0 Apache ActiveMQ unknown vulnerability
12294| [133407] Apache Tomcat up to 7.0.93/8.5.39/9.0.17 on Windows JRE Command Line Argument Code Execution
12295| [133315] Apache Airflow up to 1.10.2 HTTP Endpoint cross site request forgery
12296| [133314] Apache Airflow up to 1.10.2 Metadata Database cross site scripting
12297| [133290] Apache Tomcat up to 8.5.37/9.0.14 HTTP2 Stream Execution denial of service
12298| [133112] Apache HTTP Server up to 2.4.38 mod_auth_digest race condition privilege escalation
12299| [133111] Apache HTTP Server 2.4.37/2.4.38 mod_ssl Bypass privilege escalation
12300| [133092] Airsonic 10.2.1 org.apache.commons.lang.RandomStringUtils RecoverController.java java.util.Random weak authentication
12301| [132568] Apache JSPWiki up to 2.11.0.M2 URL User information disclosure
12302| [132567] Apache JSPWiki up to 2.11.0.M2 URL cross site scripting
12303| [132566] Apache ActiveMQ up to 5.15.8 MQTT Frame Memory denial of service
12304| [132565] Apache HBase up to 2.1.3 REST Server Request privilege escalation
12305| [132183] Apache Mesos up to pre-1.4.x Docker Image Code Execution
12306| [131988] Apache Karaf up to 4.2.2 kar Deployer directory traversal
12307| [131859] Apache Hadoop up to 2.9.1 privilege escalation
12308| [131479] Apache Solr up to 7.6 HTTP GET Request Server-Side Request Forgery
12309| [131446] Apache Solr up to 5.0.5/6.6.5 Config API HTTP POST Request Code Execution
12310| [131385] Apache Qpid Broker-J up to 6.x/7.0.6/7.1.0 AMQP Command Crash denial of service
12311| [131315] Apache Mesos up to pre-1.4.x Mesos Masters Rendering JSON Payload Recursion denial of service
12312| [131236] Apache Airflow up to 1.10.1 Metadata Database cross site scripting
12313| [130755] Apache JSPWiki up to 2.10.5 URL cross site scripting
12314| [130629] Apache Guacamole Cookie Flag weak encryption
12315| [130628] Apache Hadoop up to 3.0.0 HDFS information disclosure
12316| [130529] Apache Subversion 1.10.0/1.10.1/1.10.2/1.10.3/1.11.0 mod_dav_svn Directory Crash denial of service
12317| [130353] Apache Open Office up to 4.1.5 Document Loader String memory corruption
12318| [130341] Apache HTTP Server 2.4.37 mod_ssl Loop denial of service
12319| [130330] Apache HTTP Server up to 2.4.37 mod_session Expired privilege escalation
12320| [130329] Apache HTTP Server 2.4.37 mod_http2 Slowloris denial of service
12321| [130212] Apache Airflow up to 1.10.0 LDAP Auth Backend Certificate weak authentication
12322| [130123] Apache Airflow up to 1.8.2 information disclosure
12323| [130122] Apache Airflow up to 1.8.2 command injection cross site request forgery
12324| [130121] Apache Airflow up to 1.8.2 Webserver Object Code Execution
12325| [129717] Oracle Secure Global Desktop 5.4 Apache HTTP Server denial of service
12326| [129688] Oracle Tape Library ACSLS 8.4 Apache Log4j unknown vulnerability
12327| [129673] Oracle Retail Returns Management 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
12328| [129672] Oracle Retail Central Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
12329| [129671] Oracle Retail Back Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
12330| [129574] Oracle Outside In Technology 8.5.3/8.5.4 Apache Tomcat denial of service
12331| [129573] Oracle WebLogic Server 10.3.6.0 Apache HTTP Server denial of service
12332| [129563] Oracle Enterprise Repository 12.1.3.0.0 Apache Log4j unknown vulnerability
12333| [129555] Oracle Outside In Technology 8.5.3 Apache Batik denial of service
12334| [129551] Oracle Outside In Technology 8.5.3/8.5.4 Apache Commons FileUpload denial of service
12335| [129542] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
12336| [129538] Oracle SOA Suite 12.1.3.0.0/12.2.1.3.0 Apache Batik unknown vulnerability
12337| [129519] Oracle Enterprise Manager Ops Center 12.2.2/12.3.3 Apache ActiveMQ unknown vulnerability
12338| [129508] Oracle Applications Manager up to 12.2.8 Apache Derby unknown vulnerability
12339| [129507] Oracle Mobile Field Service up to 12.2.8 Apache Log4j unknown vulnerability
12340| [129505] Oracle Email Center up to 12.2.8 Apache Log4j unknown vulnerability
12341| [129504] Oracle CRM Technical Foundation up to 12.2.8 Apache Commons FileUpload unknown vulnerability
12342| [129499] Oracle Partner Management up to 12.2.8 Apache Log4j unknown vulnerability
12343| [129498] Oracle Marketing up to 12.2.8 Apache Commons FileUpload unknown vulnerability
12344| [129480] Oracle Communications WebRTC Session Controller up to 7.1 Apache Batik unknown vulnerability
12345| [129479] Oracle Communications Diameter Signaling Router up to 8.2 Apache Batik unknown vulnerability
12346| [129474] Oracle Communications Diameter Signaling Router up to 8.2 Apache HTTP Server information disclosure
12347| [129472] Oracle Communications WebRTC Session Controller up to 7.1 Apache Struts 1 unknown vulnerability
12348| [129470] Oracle Communications Converged Application Server up to 7.0.0.0 Apache Struts 1 unknown vulnerability
12349| [129463] Oracle Communications WebRTC Session Controller up to 7.1 Apache Log4j unknown vulnerability
12350| [129461] Oracle Communications Services Gatekeeper up to 6.1.0.3.x Apache Commons Collections Fileupload unknown vulnerability
12351| [129460] Oracle Communications Service Broker 6.0 Apache Log4j unknown vulnerability
12352| [129459] Oracle Communications Policy Management up to 12.4 Apache Struts 2 unknown vulnerability
12353| [129458] Oracle Communications Online Mediation Controller 6.1 Apache Log4j unknown vulnerability
12354| [129457] Oracle Communications Diameter Signaling Router up to 8.2 Apache Commons Fileupload unknown vulnerability
12355| [129456] Oracle Communications Converged Application Server 6.1 Apache Log4j unknown vulnerability
12356| [128714] Apache Thrift Java Client Library up to 0.11.0 SASL Negotiation org.apache.thrift.transport.TSaslTransport unknown vulnerability
12357| [128713] Apache Thrift Node.js Static Web Server up to 0.11.0 directory traversal
12358| [128709] Apache Karaf up to 4.1.6/4.2.1 Features Deployer XMLInputFactory XML External Entity
12359| [128575] Apache NetBeans 9.0 Proxy Auto-Config Code Execution
12360| [128369] Apache Tika 1.8-1.19.1 SQLite3Parser Loop sql injection
12361| [128111] Apache NiFi 1.8.0 Template Upload Man-in-the-Middle cross site request forgery
12362| [128110] Apache NiFi 1.8.0 Cluster Request privilege escalation
12363| [128109] Apache NiFi 1.8.0 Error Page message-page.jsp Request Header cross site scripting
12364| [128108] Apache NiFi up to 1.7.x X-Frame-Options Header privilege escalation
12365| [128102] Apache Oozie up to 5.0.0 Workflow XML Impersonation spoofing
12366| [127994] WordPress up to 5.0.0 on Apache httpd MIME Restriction cross site scripting
12367| [127981] Apache OFBiz 16.11.01/16.11.02/16.11.03/16.11.04 HTTP Engine httpService GET Request privilege escalation
12368| [127161] Apache Hadoop 2.7.4/2.7.5/2.7.6 Incomplete Fix CVE-2016-6811 privilege escalation
12369| [127040] Loadbalancer.org Enterprise VA MAX up to 8.3.2 Apache HTTP Server Log cross site scripting
12370| [127007] Apache Spark Request Code Execution
12371| [126791] Apache Hadoop up to 0.23.11/2.7.6/2.8.4/2.9.1/3.0.2 ZIP File unknown vulnerability
12372| [126767] Apache Qpid Proton-J Transport 0.3 Certificate Verification Man-in-the-Middle weak authentication
12373| [126896] Apache Commons FileUpload 1.3.3 on LDAP Manager DiskFileItem File privilege escalation
12374| [126574] Apache Hive up to 2.3.3/3.1.0 Query privilege escalation
12375| [126573] Apache Hive up to 2.3.3/3.1.0 HiveServer2 privilege escalation
12376| [126564] Apache Superset up to 0.22 Pickle Library load Code Execution
12377| [126488] Apache Syncope up to 2.0.10/2.1.1 BPMN Definition xxe privilege escalation
12378| [126487] Apache Syncope up to 2.0.10/2.1.1 cross site scripting
12379| [126346] Apache Tomcat Path privilege escalation
12380| [125922] Apache Impala up to 3.0.0 ALTER privilege escalation
12381| [125921] Apache Impala up to 3.0.0 Queue Injection privilege escalation
12382| [125647] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Install (Apache Tomcat) information disclosure
12383| [125617] Oracle Retail Returns Management 14.1 Apache Batik unknown vulnerability
12384| [125616] Oracle Retail Point-of-Service 13.4/14.0/14.1 Apache Batik unknown vulnerability
12385| [125614] Oracle Retail Central Office 14.1 Apache Batik unknown vulnerability
12386| [125613] Oracle Retail Back Office 13.3/13.4/14/14.1 Apache Batik unknown vulnerability
12387| [125599] Oracle Retail Open Commerce Platform 5.3.0/6.0.0/6.0.1 Apache Log4j unknown vulnerability
12388| [125569] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56 Apache HTTP Server information disclosure
12389| [125494] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat information disclosure
12390| [125447] Oracle Business Intelligence Enterprise Edition 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Batik unknown vulnerability
12391| [125428] Oracle Identity Management Suite 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
12392| [125427] Oracle Identity Analytics 11.1.1.5.8 Apache Log4j unknown vulnerability
12393| [125424] Oracle API Gateway 11.1.2.4.0 Apache Log4j unknown vulnerability
12394| [125423] Oracle BI Publisher 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Log4j unknown vulnerability
12395| [125383] Oracle up to 10.2.0 Apache Trinidad unknown vulnerability
12396| [125379] Oracle up to 10.1.x Apache Struts 1 cross site scripting
12397| [125377] Oracle up to 10.2.0 Apache Commons Collections unknown vulnerability
12398| [125376] Oracle Communications Application Session Controller up to 3.7.0 Apache Commons Collections unknown vulnerability
12399| [125375] Oracle Communications User Data Repository up to 12.1.x Apache Xerces memory corruption
12400| [125248] Apache ActiveMQ up to 5.15.5 Web-based Administration Console queue.jsp Parameter cross site scripting
12401| [125133] Apache Tika up to 1.19 XML Parser reset() denial of service
12402| [124877] Apache PDFbox up to 2.0.11 PDF File denial of service
12403| [124876] Apache Ranger up to 1.1.x UnixAuthenticationService Stack-based memory corruption
12404| [124791] Apache Tomcat up to 7.0.90/8.5.33/9.0.11 URL Open Redirect
12405| [124787] Apache Pony Mail 0.7/0.8/0.9 Statistics Generator Timestamp Data information disclosure
12406| [124447] Apache HTTP Server up to 2.4.34 SETTINGS Frame denial of service
12407| [124346] Apache Mesos pre-1.4.2/1.5.0/1.5.1/1.6.0 on Executor HTTP API String Comparison validation JSON Web Token information disclosure
12408| [124286] Apache Tika up to 1.18 IptcAnpaParser Loop denial of service
12409| [124242] Apache Tika up to 0.18 C:/evil.bat" Directory unknown vulnerability
12410| [124241] Apache Tika up to 0.18 XML Parser Entity Expansion denial of service
12411| [124191] Apache Karaf up to 3.0.8/4.0.8/4.1.0 WebConsole .../gogo/ weak authentication
12412| [124190] Apache Karaf up to 4.1.x sshd privilege escalation
12413| [124152] Apache Camel Mail up to 2.22.0 Path directory traversal
12414| [124143] Apache SpamAssassin up to 3.4.1 PDFInfo Plugin Code Execution
12415| [124134] Apache SpamAssassin up to 3.4.1 Scan Engine HTML::Parser Email denial of service
12416| [124095] PHP up to 5.6.37/7.0.31/7.1.21/7.2.9 Apache2 sapi_apache2.c php_handler cross site scripting
12417| [124024] Apache Mesos 1.4.x/1.5.0 libprocess JSON Payload denial of service
12418| [123814] Apache ActiveMQ Client up to 5.15.5 TLS Hostname Verification Man-in-the-Middle weak authentication
12419| [123393] Apache Traffic Server up to 6.2.2/7.1.3 ESI Plugin Config privilege escalation
12420| [123392] Apache Traffic Server 6.2.2 TLS Handshake Segmentation Fault denial of service
12421| [123391] Apache Traffic Server up to 6.2.2/7.1.3 Range Request Performance denial of service
12422| [123390] Apache Traffic Server up to 6.2.2/7.1.3 Request HTTP Smuggling privilege escalation
12423| [123369] Apache Traffic Server up to 6.2.2/7.1.3 ACL remap.config Request denial of service
12424| [123197] Apache Sentry up to 2.0.0 privilege escalation
12425| [123145] Apache Struts up to 2.3.34/2.5.16 Namespace Code Execution
12426| [123144] Apache Cayenne up to 4.1.M1 CayenneModeler XML File File Transfer privilege escalation
12427| [122981] Apache Commons Compress 1.7 ZipArchiveInputStream ZIP Archive denial of service
12428| [122889] Apache HTTP Server up to 2.2.31/2.4.23 mod_userdir HTTP Response Splitting privilege escalation
12429| [122800] Apache Spark 1.3.0 REST API weak authentication
12430| [122642] Apache Airflow up to 1.8.x 404 Page Reflected cross site scripting
12431| [122568] Apache Tomcat up to 8.5.31/9.0.9 Connection Reuse weak authentication
12432| [122567] Apache Axis 1.0./1.1/1.2/1.3/1.4 cross site scripting
12433| [122556] Apache Tomcat up to 7.0.86/8.0.51/8.5.30/9.0.7 UTF-8 Decoder Loop denial of service
12434| [122531] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.9 WebSocket Client unknown vulnerability
12435| [122456] Apache Camel up to 2.20.3/2.21.0 XSD Validator XML External Entity
12436| [122455] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Revoked Certificate weak authentication
12437| [122454] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Responder Revoked Certificate weak authentication
12438| [122214] Apache Kafka up to 0.9.0.1/0.10.2.1/0.11.0.2/1.0.0 Broker Request Data Loss denial of service
12439| [122202] Apache Kafka up to 0.10.2.1/0.11.0.1 SASL Impersonation spoofing
12440| [122101] Docker Skeleton Runtime for Apache OpenWhisk Docker Action dockerskeleton:1.3.0 privilege escalation
12441| [122100] PHP Runtime for Apache OpenWhisk Docker Action action-php-v7.2:1.0.0 privilege escalation
12442| [122012] Apache Ignite up to 2.5 Serialization privilege escalation
12443| [121911] Apache Ambari up to 2.5.x/2.6.2 Log Message Credentials information disclosure
12444| [121910] Apache HTTP Server 2.4.33 mod_md HTTP Requests denial of service
12445| [121854] Oracle Tape Library ACSLS up to ACSLS 8.4.0-2 Apache Commons Collections unknown vulnerability
12446| [121752] Oracle Insurance Policy Administration 10.0/10.1/10.2/11.0 Apache Log4j unknown vulnerability
12447| [121370] Apache Spark up to 2.1.2/2.2.1/2.3.0 URL cross site scripting
12448| [121354] Apache CouchDB HTTP API Code Execution
12449| [121144] Apache LDAP API up to 1.0.1 SSL Filter information disclosure
12450| [121143] Apache Storm up to 0.10.2/1.0.6/1.1.2/1.2.1 Cluster privilege escalation
12451| [120436] Apache CXF Fediz up to 1.4.3 Application Plugin unknown vulnerability
12452| [120310] Apache PDFbox up to 1.8.14/2.0.10 AFMParser Loop denial of service
12453| [120168] Apache CXF weak authentication
12454| [120080] Apache Cassandra up to 3.11.1 JMX/RMI Interface RMI Request privilege escalation
12455| [120043] Apache HBase up to 1.2.6.0/1.3.2.0/1.4.4/2.0.0 Thrift 1 API Server weak authentication
12456| [119723] Apache Qpid Broker-J 7.0.0/7.0.1/7.0.2/7.0.3/7.0.4 AMQP Messages Crash denial of service
12457| [122569] Apache HTTP Server up to 2.4.33 HTTP2 Request denial of service
12458| [119486] Apache Geode up to 1.4.0 Security Manager Code Execution
12459| [119306] Apache MXNet Network Interface privilege escalation
12460| [118999] Apache Storm up to 1.0.6/1.1.2/1.2.1 Archive directory traversal
12461| [118996] Apache Storm up to 1.0.6/1.1.2/1.2.1 Daemon spoofing
12462| [118644] Apple macOS up to 10.13.5 apache_mod_php unknown vulnerability
12463| [118200] Apache Batik up to 1.9 Deserialization unknown vulnerability
12464| [118143] Apache NiFi activemq-client Library Deserialization denial of service
12465| [118142] Apache NiFi 1.6.0 SplitXML xxe privilege escalation
12466| [118051] Apache Zookeeper up to 3.4.9/3.5.3-beta weak authentication
12467| [117997] Apache ORC up to 1.4.3 ORC File Recursion denial of service
12468| [117825] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.8 CORS Filter privilege escalation
12469| [117405] Apache Derby up to 10.14.1.0 Network Server Network Packet privilege escalation
12470| [117347] Apache Ambari up to 2.6.1 HTTP Request directory traversal
12471| [117265] LibreOffice/Apache Office Writer SMB Connection XML Document information disclosure
12472| [117143] Apache uimaj/uima-as/uimaFIT/uimaDUCC XML XXE information disclosure
12473| [117117] Apache Tika up to 1.17 ChmParser Loop denial of service
12474| [117116] Apache Tika up to 1.17 BPGParser Loop denial of service
12475| [117115] Apache Tika up to 1.17 tika-server command injection
12476| [116929] Apache Fineract getReportType Parameter privilege escalation
12477| [116928] Apache Fineract REST Endpoint Parameter privilege escalation
12478| [116927] Apache Fineract MakercheckersApiResource Parameter sql injection
12479| [116926] Apache Fineract REST Parameter privilege escalation
12480| [116574] Apache wicket-jquery-ui up to 6.29.0/7.10.1/8.0.0-M9.1 WYSIWYG Editor privilege escalation
12481| [116622] Oracle Enterprise Manager for MySQL Database 12.1.0.4 EM Plugin: General (Apache Tomcat) unknown vulnerability
12482| [115931] Apache Solr up to 6.6.2/7.2.1 XML Data Parameter XML External Entity
12483| [115883] Apache Hive up to 2.3.2 privilege escalation
12484| [115882] Apache Hive up to 2.3.2 xpath_short information disclosure
12485| [115881] Apache DriverHive JDBC Driver up to 2.3.2 Escape Argument Bypass privilege escalation
12486| [115518] Apache Ignite 2.3 Deserialization privilege escalation
12487| [115260] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache cross site scripting
12488| [115259] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache Cookie Stack-based memory corruption
12489| [115500] CA Workload Control Center up to r11.4 SP5 Apache MyFaces Component Code Execution
12490| [115121] Apache Struts REST Plugin up to 2.5.15 Xstream XML Data denial of service
12491| [115061] Apache HTTP Server up to 2.4.29 HTTP Digest Authentication Challenge HTTP Requests Replay privilege escalation
12492| [115060] Apache HTTP Server up to 2.4.29 mod_cache_socache Request Header Crash denial of service
12493| [115059] Apache HTTP Server up to 2.4.29 HTTP2 NULL Pointer Dereference denial of service
12494| [115058] Apache HTTP Server up to 2.4.29 HTTP Header Crash denial of service
12495| [115057] Apache HTTP Server up to 2.4.29 mod_session Variable Name Cache privilege escalation
12496| [115039] Apache HTTP Server up to 2.4.29 FilesMatch File Upload privilege escalation
12497| [115038] Apache HTTP Server up to 2.0.65/2.2.34/2.4.29 mod_authnz_ldap Crash denial of service
12498| [114817] Apache Syncope up to 1.2.10/2.0.7 Search Parameter information disclosure
12499| [114816] Apache Syncope up to 1.2.10/2.0.7 XSLT Code Execution
12500| [114717] Apache Commons 1.11/1.12/1.13/1.14/1.15 ZIP Archive ZipFile/ZipArchiveInputStream denial of service
12501| [114661] Apache Allura up to 1.8.0 HTTP Response Splitting privilege escalation
12502| [114400] Apache Tomcat JK ISAPI Connector up to 1.2.42 IIS/ISAPI privilege escalation
12503| [114258] Apache HTTP Server up to 2.4.22 mod_cluster Segmentation Fault denial of service
12504| [114086] Apache ODE 1.3.3 ODE Process Deployment Web Service directory traversal
12505| [113955] Apache Xerces-C up to 3.2.0 XML Parser NULL Pointer Dereference denial of service
12506| [113945] Apache Tomcat up to 7.0.84/8.0.49/8.5.27/9.0.4 URL Pattern Empty String privilege escalation
12507| [113944] Apache OpenMeetings up to 3.x/4.0.1 CRUD Operation denial of service
12508| [113905] Apache Traffic Server up to 5.2.x/5.3.2/6.2.0/7.0.0 TLS Handshake Core Dump denial of service
12509| [113904] Apache Traffic Server up to 6.2.0 Host Header privilege escalation
12510| [113895] Apache Geode up to 1.3.x Code Execution
12511| [113894] Apache Geode up to 1.3.x TcpServer Code Execution
12512| [113888] Apache James Hupa WebMail 0.0.2 cross site scripting
12513| [113813] Apache Geode Cluster up to 1.3.x Secure Mode privilege escalation
12514| [113747] Apache Tomcat Servlets privilege escalation
12515| [113647] Apache Qpid up to 0.30 qpidd Broker AMQP Message Crash denial of service
12516| [113645] Apache VCL up to 2.1/2.2.1/2.3.1 Web GUI/XMLRPC API privilege escalation
12517| [113560] Apache jUDDI Console 3.0.0 Log Entries spoofing
12518| [113571] Apache Oozie up to 4.3.0/5.0.0-beta1 XML Data XML File privilege escalation
12519| [113569] Apache Karaf up to 4.0.7 LDAPLoginModule LDAP injection denial of service
12520| [113273] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
12521| [113198] Apache Qpid Dispatch Router 0.7.0/0.8.0 AMQP denial of service
12522| [113186] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
12523| [113145] Apache Thrift up to 0.9.3 Go Client Library privilege escalation
12524| [113106] Apache jUDDI up to 3.3.3 XML Data WADL2Java/WSDL2Java XML Document privilege escalation
12525| [113105] Apache Qpid Broker-J 7.0.0 AMQP Crash denial of service
12526| [112885] Apache Allura up to 1.8.0 File information disclosure
12527| [112856] Apache CloudStack up to 4.8.1.0/4.9.0.0 API weak authentication
12528| [112855] Apache CloudStack 4.1.0/4.1.1 API information disclosure
12529| [112678] Apache Tomcat up to 7.0.82/8.0.47/8.5.23/9.0.1 Bug Fix 61201 privilege escalation
12530| [112677] Apache Tomcat Native Connector up to 1.1.34/1.2.14 OCSP Checker Client weak authentication
12531| [112625] Apache POI up to 3.16 Loop denial of service
12532| [112448] Apache NiFi up to 1.3.x Deserialization privilege escalation
12533| [112396] Apache Hadoop 2.7.3/2.7.4 YARN NodeManager Credentials information disclosure
12534| [112339] Apache NiFi 1.5.0 Header privilege escalation
12535| [112330] Apache NiFi 1.5.0 Header HTTP Request privilege escalation
12536| [112314] NetGain Enterprise Manager 7.2.730 Build 1034 org.apache.jsp.u.jsp.tools.exec_jsp Servlet Parameter privilege escalation
12537| [112253] Apache Hadoop up to 0.23.x/2.7.4/2.8.2 MapReduce Job History Server Configuration File privilege escalation
12538| [112171] Oracle Secure Global Desktop 5.3 Apache Log4j privilege escalation
12539| [112164] Oracle Agile PLM 9.3.5/9.3.6 Apache Tomcat unknown vulnerability
12540| [112161] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Tomcat privilege escalation
12541| [112158] Oracle Autovue for Agile Product Lifecycle Management 21.0.0/21.0.1 Apache Log4j privilege escalation
12542| [112156] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Log4j privilege escalation
12543| [112155] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Apache Log4j privilege escalation
12544| [112137] Oracle MICROS Relate CRM Software 10.8.x/11.4.x/15.0.x, Apache Tomcat unknown vulnerability
12545| [112136] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat privilege escalation
12546| [112133] Oracle Retail Workforce Management 1.60.7/1.64.0 Apache Log4j privilege escalation
12547| [112129] Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 Apache Log4j privilege escalation
12548| [112114] Oracle 9.1 Apache Log4j privilege escalation
12549| [112113] Oracle 9.1 Apache Log4j privilege escalation
12550| [112045] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat privilege escalation
12551| [112038] Oracle Health Sciences Empirica Inspections 1.0.1.1 Apache Tomcat information disclosure
12552| [112019] Oracle Endeca Information Discovery Integrator 3.1.0/3.2.0 Apache Tomcat privilege escalation
12553| [112017] Oracle WebCenter Portal 11.1.1.9.0/12.2.1.2.0/12.2.1.3.0 Apache Struts 1 cross site scripting
12554| [112011] Oracle Identity Manager 11.1.2.3.0 Apache Commons Collections privilege escalation
12555| [111950] Oracle Database 12.2.0.1 Apache Tomcat information disclosure
12556| [111703] Apache Sling XSS Protection API 1.0.4 URL Encoding cross site scripting
12557| [111556] Apache Geode up to 1.2.x Secure Mode Parameter OQL privilege escalation
12558| [111555] Apache Geode up to 1.2.x Secure Mode OQL privilege escalation
12559| [111540] Apache Geode up to 1.2.x Secure Mode information disclosure
12560| [111519] Apache Sling JCR ContentLoader 2.1.4 xmlreader directory traversal
12561| [111338] Apache DeltaSpike-JSF 1.8.0 cross site scripting
12562| [111330] Apache OFBiz 16.11.01/16.11.02/16.11.03 BIRT Plugin cross site scripting
12563| [110789] Apache Sling up to 1.4.0 Authentication Service Credentials information disclosure
12564| [110785] Apache Drill up to 1.11.0 Query Page unknown vulnerability
12565| [110701] Apache Fineract Query Parameter sql injection
12566| [110484] Apache Synapse up to 3.0.0 Apache Commons Collections Serialized Object Code Injection privilege escalation
12567| [110426] Adobe Experience Manager 6.0/6.1/6.2/6.3 Apache Sling Servlets Post cross site scripting
12568| [110141] Apache Struts up to 2.5.14 REST Plugin denial of service
12569| [110140] Apache Qpid Broker-J up to 0.32 privilege escalation
12570| [110139] Apache Qpid Broker-J up to 6.1.4 AMQP Frame denial of service
12571| [110106] Apache CXF Fediz Spring cross site request forgery
12572| [109766] Apache OpenOffice up to 4.1.3 DOC File Parser WW8Fonts memory corruption
12573| [109750] Apache OpenOffice up to 4.1.3 DOC File Parser ImportOldFormatStyles memory corruption
12574| [109749] Apache OpenOffice up to 4.1.3 PPT File Parser PPTStyleSheet memory corruption
12575| [109606] October CMS Build 412 Apache Configuration File Upload privilege escalation
12576| [109419] Apache Camel up to 2.19.3/2.20.0 camel-castor Java Object Deserialization privilege escalation
12577| [109418] Apache Camel up to 2.19.3/2.20.0 camel-hessian Java Object Deserialization privilege escalation
12578| [109400] Apache CouchDB up to 1.6.x/2.1.0 Database Server Shell privilege escalation
12579| [109399] Apache CouchDB up to 1.6.x/2.1.0 JSON Parser Shell privilege escalation
12580| [109398] Apache CXF 3.1.14/3.2.1 JAX-WS/JAX-RS Attachment denial of service
12581| [108872] Apache Hive up to 2.1.1/2.2.0/2.3.0 Policy Enforcement privilege escalation
12582| [108939] Apple macOS up to 10.13.1 apache unknown vulnerability
12583| [108938] Apple macOS up to 10.13.1 apache denial of service
12584| [108937] Apple macOS up to 10.13.1 apache unknown vulnerability
12585| [108936] Apple macOS up to 10.13.1 apache unknown vulnerability
12586| [108935] Apple macOS up to 10.13.1 apache denial of service
12587| [108934] Apple macOS up to 10.13.1 apache unknown vulnerability
12588| [108933] Apple macOS up to 10.13.1 apache unknown vulnerability
12589| [108932] Apple macOS up to 10.13.1 apache unknown vulnerability
12590| [108931] Apple macOS up to 10.13.1 apache denial of service
12591| [108930] Apple macOS up to 10.13.1 apache unknown vulnerability
12592| [108929] Apple macOS up to 10.13.1 apache denial of service
12593| [108928] Apple macOS up to 10.13.1 apache unknown vulnerability
12594| [108797] Apache Struts up to 2.3.19 TextParseUtiltranslateVariables OGNL Expression privilege escalation
12595| [108795] Apache Traffic Server up to 5.3.0 HTTP2 set_dynamic_table_size memory corruption
12596| [108794] Apache WSS4J up to 1.6.16/2.0.1 Incomplete Fix Leak information disclosure
12597| [108793] Apache Qpid up to 0.30 qpidd Crash denial of service
12598| [108792] Apache Traffic Server up to 5.1.0 Access Restriction privilege escalation
12599| [108791] Apache Wicket up to 1.5.11/6.16.x/7.0.0-M2 Session information disclosure
12600| [108790] Apache Storm 0.9.0.1 Log Viewer directory traversal
12601| [108789] Apache Cordova In-App-Browser Standalone Plugin up to 0.3.1 on iOS CDVInAppBrowser privilege escalation
12602| [108788] Apache Cordova File-Transfer Standalone Plugin up to 0.4.1 on iOS ios/CDVFileTransfer.m spoofing
12603| [108787] Apache HttpClient up to 4.3.0 HttpClientBuilder.java unknown vulnerability
12604| [108786] Apache Wicket up to 1.4.21/1.5.9/6.3.x script Tag cross site scripting
12605| [108783] Apache Hadoop up to 0.23.3/1.0.3/2.0.1 Kerberos Security Feature Key weak encryption
12606| [108782] Apache Xerces2 XML Service denial of service
12607| [108781] Apache jUDDI up to 1.x happyjuddi.jsp Parameter cross site scripting
12608| [108780] Apache jUDDI up to 1.x Log File uddiget.jsp spoofing
12609| [108709] Apache Cordova Android up to 3.7.1/4.0.1 intent URL privilege escalation
12610| [108708] Apache ActiveMQ up to 5.10.0 XML Data XML External Entity
12611| [108707] Apache ActiveMQ up to 1.7.0 XML Data XML External Entity
12612| [108629] Apache OFBiz up to 10.04.01 privilege escalation
12613| [108543] Apache Derby 10.1.2.1/10.2.2.0/10.3.1.4/10.4.1.3 Export File privilege escalation
12614| [108312] Apache HTTP Server on RHEL IP Address Filter privilege escalation
12615| [108297] Apache NiFi up to 0.7.1/1.1.1 Proxy Chain Username Deserialization privilege escalation
12616| [108296] Apache NiFi up to 0.7.1/1.1.1 Cluster Request privilege escalation
12617| [108250] Oracle Secure Global Desktop 5.3 Apache HTTP Server memory corruption
12618| [108245] Oracle Transportation Management up to 6.3.7 Apache Tomcat unknown vulnerability
12619| [108244] Oracle Transportation Management 6.4.1/6.4.2 Apache Commons FileUpload denial of service
12620| [108243] Oracle Agile Engineering Data Management 6.1.3/6.2.0 Apache Commons Collections memory corruption
12621| [108222] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Batik denial of service
12622| [108219] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat unknown vulnerability
12623| [108217] Oracle Retail Store Inventory Management 13.2.9/14.0.4/14.1.3/15.0.1/16.0.1 Apache Groovy unknown vulnerability
12624| [108216] Oracle Retail Convenience and Fuel POS Software 2.1.132 Apache Groovy unknown vulnerability
12625| [108169] Oracle MySQL Enterprise Monitor up to 3.2.8.2223/3.3.4.3247/3.4.2.4181 Apache Tomcat unknown vulnerability
12626| [108113] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Batik denial of service
12627| [108107] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat unknown vulnerability
12628| [108102] Oracle Healthcare Master Person Index 4.x Apache Groovy unknown vulnerability
12629| [108085] Oracle Identity Manager 11.1.2.3.0 Apache Struts 1 memory corruption
12630| [108083] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
12631| [108080] Oracle GlassFish Server 3.1.2 Apache Commons FileUpload denial of service
12632| [108066] Oracle Management Pack for GoldenGate 11.2.1.0.12 Apache Tomcat memory corruption
12633| [108062] Oracle BI Publisher 11.1.1.7.0/12.2.1.1.0/12.2.1.2.0 Apache ActiveMQ memory corruption
12634| [108060] Oracle Enterprise Manager Ops Center 12.2.2/12.3.2 Apache Groovy unknown vulnerability
12635| [108033] Oracle Primavera Unifier 9.13/9.14/10.x/15.x/16.x, Apache Groovy unknown vulnerability
12636| [108013] Oracle Communications WebRTC Session Controller 7.0/7.1/7.2 Apache Groovy unknown vulnerability
12637| [108011] Oracle Communications Services Gatekeeper 5.1/6.0 Apache Trinidad unknown vulnerability
12638| [107904] Apache Struts up to 2.3.28 Double OGNL Evaluation privilege escalation
12639| [107860] Apache Solr up to 7.0 Apache Lucene RunExecutableListener XML External Entity
12640| [107834] Apache Ranger up to 0.6.1 Change Password privilege escalation
12641| [107639] Apache NiFi 1.4.0 XML External Entity
12642| [107606] Apache ZooKeper up to 3.4.9/3.5.2 Command CPU Exhaustion denial of service
12643| [107597] Apache Roller up to 5.0.2 XML-RPC Protocol Support XML External Entity
12644| [107429] Apache Impala up to 2.9.x Kudu Table privilege escalation
12645| [107411] Apache Tomcat up to 7.0.81/8.0.46/8.5.22/9.0.0 JSP File File Upload privilege escalation
12646| [107385] Apache Geode up to 1.2.0 Secure Mode privilege escalation
12647| [107339] Apache OpenNLP up to 1.5.3/1.6.0/1.7.2/1.8.1 XML Data XML External Entity
12648| [107333] Apache Wicket up to 8.0.0-M1 CSRF Prevention HTTP Header privilege escalation
12649| [107323] Apache Wicket 1.5.10/6.13.0 Class Request information disclosure
12650| [107310] Apache Geode up to 1.2.0 Command Line Utility Query privilege escalation
12651| [107276] ArcSight ESM/ArcSight ESM Express up to 6.9.1c Patch 3/6.11.0 Apache Tomcat Version information disclosure
12652| [107266] Apache Tika up to 1.12 XML Parser XML External Entity
12653| [107262] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
12654| [107258] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
12655| [107197] Apache Xerces Jelly Parser XML File XML External Entity
12656| [107193] ZTE NR8950 Apache Commons Collections RMI Request Deserialization privilege escalation
12657| [107084] Apache Struts up to 2.3.19 cross site scripting
12658| [106877] Apache Struts up to 2.0.33/2.5.10 Freemarker Tag privilege escalation
12659| [106875] Apache Struts up to 2.5.5 URL Validator denial of service
12660| [106874] Apache Struts up to 2.3.30 Convention Plugin directory traversal
12661| [106847] Apache Tomcat up to 7.0.80 VirtualDirContext Source information disclosure
12662| [106846] Apache Tomcat up to 7.0.79 on Windows HTTP PUT Method Parameter File Upload privilege escalation
12663| [106777] Apache HTTP Server up to 2.2.34/2.4.27 Limit Directive ap_limit_section HTTP Request information disclosure
12664| [106739] puppetlabs-apache up to 1.11.0/2.0.x weak authentication
12665| [106720] Apache Wicket up to 1.5.12/6.18.x/7.0.0-M4 CryptoMapper privilege escalation
12666| [106586] Apache Brooklyn up to 0.9.x REST Server cross site scripting
12667| [106562] Apache Spark up to 2.1.1 Launcher API Deserialization privilege escalation
12668| [106559] Apache Brooklyn up to 0.9.x SnakeYAML YAML Data Java privilege escalation
12669| [106558] Apache Brooklyn up to 0.9.x REST Server cross site request forgery
12670| [106556] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
12671| [106555] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
12672| [106171] Apache Directory LDAP API up to 1.0.0-M30 Timing unknown vulnerability
12673| [106167] Apache Struts up to 2.5.12 REST Plugin XML Data privilege escalation
12674| [106166] Apache Struts up to 2.3.33/2.5.12 REST Plugin denial of service
12675| [106165] Apache Struts up to 2.3.33/2.5.12 URLValidator Regex CPU Exhaustion denial of service
12676| [106115] Apache Hadoop up to 2.6.4/2.7.2 YARN NodeManager Password information disclosure
12677| [106012] Apache Solr up to 5.5.3/6.4.0 Replication directory traversal
12678| [105980] Apache Engine 16.11.01 Parameter Reflected unknown vulnerability
12679| [105962] Apache Atlas 0.6.0/0.7.0 Frame cross site scripting
12680| [105961] Apache Atlas 0.6.0/0.7.0 Stack Trace information disclosure
12681| [105960] Apache Atlas 0.6.0/0.7.0 Search Reflected cross site scripting
12682| [105959] Apache Atlas 0.6.0/0.7.0 edit Tag DOM cross site scripting
12683| [105958] Apache Atlas 0.6.0/0.7.0 edit Tag Stored cross site scripting
12684| [105957] Apache Atlas 0.6.0/0.7.0 Cookie privilege escalation
12685| [105905] Apache Atlas 0.6.0/0.7.0/0.7.1 /js privilege escalation
12686| [105878] Apache Struts up to 2.3.24.0 privilege escalation
12687| [105682] Apache2Triad 1.5.4 phpsftpd/users.php Parameter cross site scripting
12688| [105681] Apache2Triad 1.5.4 phpsftpd/users.php Request cross site request forgery
12689| [105680] Apache2Triad 1.5.4 Parameter Session Fixation weak authentication
12690| [105643] Apache Pony Mail up to 0.8b weak authentication
12691| [105288] Apache Sling up to 2.3.21 Sling.evalString() String cross site scripting
12692| [105219] Apache Tomcat up to 8.5.15/9.0.0.M21 HTTP2 Bypass directory traversal
12693| [105218] Apache Tomcat up to 7.0.78/8.0.44/8.5.15/9.0.0.M21 CORS Filter Cache Poisoning privilege escalation
12694| [105215] Apache CXF up to 3.0.12/3.1.9 OAuth2 Hawk/JOSE MAC Validation Timing unknown vulnerability
12695| [105206] Apache CXF up to 3.0.11/3.1.8 JAX-RS Module XML External Entity
12696| [105205] Apache CXF up to 3.0.11/3.1.8 HTTP Transport Module Parameter cross site scripting
12697| [105202] Apache Storm 1.0.0/1.0.1/1.0.2/1.0.3/1.1.0 Worker privilege escalation
12698| [104987] Apache Xerces-C++ XML Service CPU Exhaustion denial of service
12699| [104986] Apache CXF 2.4.5/2.5.1 WS-SP UsernameToken Policy SOAP Request weak authentication
12700| [104985] Apache MyFaces Core up to 2.1.4 EL Expression Parameter Injection information disclosure
12701| [104983] Apache Wink up to 1.1.1 XML Document xxe privilege escalation
12702| [104981] Apache Commons Email 1.0/1.1/1.2/1.3/1.4 Subject Linebreak SMTP privilege escalation
12703| [104591] MEDHOST Document Management System Apache Solr Default Credentials weak authentication
12704| [104062] Oracle MySQL Enterprise Monitor up to 3.3.3.1199 Apache Tomcat unknown vulnerability
12705| [104061] Oracle MySQL Enterprise Monitor up to 3.2.7.1204/3.3.3.1199 Apache Tomcat unknown vulnerability
12706| [104060] Oracle MySQL Enterprise Monitor up to 3.1.5.7958/3.2.5.1141/3.3.2.1162 Apache Struts 2 unknown vulnerability
12707| [103995] Oracle 8.3/8.4/15.1/15.2 Apache Trinidad unknown vulnerability
12708| [103993] Oracle Policy Automation up to 12.2.3 Apache Commons FileUplaod denial of service
12709| [103916] Oracle Banking Platform 2.3/2.4/2.4.1/2.5 Apache Commons FileUpload denial of service
12710| [103906] Oracle Communications BRM 11.2.0.0.0 Apache Commons Collections privilege escalation
12711| [103904] Oracle Communications BRM 11.2.0.0.0/11.3.0.0.0 Apache Groovy memory corruption
12712| [103866] Oracle Transportation Management 6.1/6.2 Apache Webserver unknown vulnerability
12713| [103816] Oracle BI Publisher 11.1.1.9.0/12.2.1.1.0/12.2.1.2.0 Apache Commons Fileupload denial of service
12714| [103797] Oracle Tuxedo System and Applications Monitor Apache Commons Collections privilege escalation
12715| [103792] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Commons Fileupload privilege escalation
12716| [103791] Oracle Endeca Server 7.6.0.0/7.6.1.0 Apache Commons Collections privilege escalation
12717| [103788] Oracle Enterprise Repository 11.1.1.7.0/12.1.3.0.0 Apache ActiveMQ memory corruption
12718| [103787] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Groovy memory corruption
12719| [103763] Apache Sling up to 1.0.11 XSS Protection API XSS.getValidXML() Application XML External Entity
12720| [103762] Apache Sling up to 1.0.12 XSS Protection API XSSAPI.encodeForJSString() Script Tag cross site scripting
12721| [103693] Apache OpenMeetings 1.0.0 HTTP Method privilege escalation
12722| [103692] Apache OpenMeetings 1.0.0 Tomcat Error information disclosure
12723| [103691] Apache OpenMeetings 3.2.0 Parameter privilege escalation
12724| [103690] Apache OpenMeetings 1.0.0 sql injection
12725| [103689] Apache OpenMeetings 1.0.0 crossdomain.xml privilege escalation
12726| [103688] Apache OpenMeetings 1.0.0 weak encryption
12727| [103687] Apache OpenMeetings 1.0.0 cross site request forgery
12728| [103556] Apache Roller 5.1.0/5.1.1 Weblog Page Template VTL privilege escalation
12729| [103554] Apache OpenMeetings 1.0.0 Password Update unknown vulnerability
12730| [103553] Apache OpenMeetings 1.0.0 File Upload privilege escalation
12731| [103552] Apache OpenMeetings 3.2.0 Chat cross site scripting
12732| [103551] Apache OpenMeetings 3.1.0 XML unknown vulnerability
12733| [103521] Apache HTTP Server 2.4.26 HTTP2 Free memory corruption
12734| [103520] Apache HTTP Server up to 2.2.33/2.4.26 mod_auth_digest Authorization Header memory corruption
12735| [103519] Apache Struts up to 2.5.11/2.3.32 Spring AOP denial of service
12736| [103518] Apache Struts up to 2.5.11 URLValidator directory traversal
12737| [103492] Apache Spark up to 2.1.x Web UI Reflected cross site scripting
12738| [103401] Apache Struts 2.3.x Struts 1 Plugin ActionMessage privilege escalation
12739| [103399] Apache Traffic Control Traffic Router TCP Connection Slowloris denial of service
12740| [103387] Apache Impala up to 2.8.0 StatestoreSubscriber weak encryption
12741| [103386] Apache Impala up to 2.7.x/2.8.0 Kerberos weak authentication
12742| [103352] Apache Solr Node weak authentication
12743| [102897] Apache Ignite up to 2.0 Update Notifier information disclosure
12744| [102878] Code42 CrashPlan 5.4.x RMI Server org.apache.commons.ssl.rmi.DateRMI privilege escalation
12745| [102698] Apache HTTP Server up to 2.2.32/2.4.25 mod_mime Content-Type memory corruption
12746| [102697] Apache HTTP Server 2.2.24/2.2.32 HTTP Strict Parsing ap_find_token Request Header memory corruption
12747| [102690] Apache HTTP Server up to 2.2.32/2.4.25 mod_ssl ap_hook_process_connection() denial of service
12748| [102689] Apache HTTP Server up to 2.2.32/2.4.25 ap_get_basic_auth_pw weak authentication
12749| [102622] Apache Thrift up to 0.9.2 Client Libraries skip denial of service
12750| [102538] Apache Ranger up to 0.7.0 Authorizer unknown vulnerability
12751| [102537] Apache Ranger up to 0.7.0 Wildcard Character unknown vulnerability
12752| [102536] Apache Ranger up to 0.6 Stored cross site scripting
12753| [102535] Apache Ranger up to 0.6.2 Policy Engine unknown vulnerability
12754| [102255] Apache NiFi up to 0.7.3/1.2.x Response Header privilege escalation
12755| [102254] Apache NiFi up to 0.7.3/1.2.x UI cross site scripting
12756| [102070] Apache CXF Fediz up to 1.1.2/1.2.0 Application Plugin denial of service
12757| [102020] Apache Tomcat up to 9.0.0.M1 Java Servlet HTTP Method unknown vulnerability
12758| [101858] Apache Hive up to 1.2.1/2.0.0 Client weak authentication
12759| [101802] Apache KNOX up to 0.11.0 WebHDFS privilege escalation
12760| [101928] HPE Aruba ClearPass Apache Tomcat information disclosure
12761| [101524] Apache Archiva up to 1.x/2.2.1 REST Endpoint cross site request forgery
12762| [101513] Apache jUDDI 3.1./3.1.2/3.1.3/3.1.4 Logout Open Redirect
12763| [101430] Apache CXF Fediz up to 1.3.1 OIDC Service cross site request forgery
12764| [101429] Apache CXF Fediz up to 1.2.3/1.3.1 Plugins cross site request forgery
12765| [100619] Apache Hadoop up to 2.6.x HDFS Servlet unknown vulnerability
12766| [100618] Apache Hadoop up to 2.7.0 HDFS Web UI cross site scripting
12767| [100621] Adobe ColdFusion 10/11/2016 Apache BlazeDS Library Deserialization privilege escalation
12768| [100205] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Apache Commons FileUpload denial of service
12769| [100191] Oracle Secure Global Desktop 4.71/5.2/5.3 Web Server (Apache HTTP Server) information disclosure
12770| [100162] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Commons Collections privilege escalation
12771| [100160] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Trinidad unknown vulnerability
12772| [99969] Oracle WebCenter Sites 11.1.1.8.0 Apache Tomcat memory corruption
12773| [99937] Apache Batik up to 1.8 privilege escalation
12774| [99936] Apache FOP up to 2.1 privilege escalation
12775| [99935] Apache CXF up to 3.0.12/3.1.10 STSClient Cache information disclosure
12776| [99934] Apache CXF up to 3.0.12/3.1.10 JAX-RS XML Security Streaming Client spoofing
12777| [99930] Apache Traffic Server up to 6.2.0 denial of service
12778| [99929] Apache Log4j up to 2.8.1 Socket Server Deserialization privilege escalation
12779| [99925] Apache Traffic Server 6.0.0/6.1.0/6.2.0 HPACK Bomb denial of service
12780| [99738] Ping Identity OpenID Connect Authentication Module up to 2.13 on Apache Mod_auth_openidc.c spoofing
12781| [117569] Apache Hadoop up to 2.7.3 privilege escalation
12782| [99591] Apache TomEE up to 1.7.3/7.0.0-M2 EjbObjectInputStream Serialized Object privilege escalation
12783| [99370] Apache Ignite up to 1.8 update-notifier Document XML External Entity
12784| [99299] Apache Geode up to 1.1.0 Pulse OQL Query privilege escalation
12785| [99572] Apache Tomcat up to 7.0.75/8.0.41/8.5.11/9.0.0.M17 Application Listener privilege escalation
12786| [99570] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP Connector Cache information disclosure
12787| [99569] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP/2 GOAWAY Frame Resource Exhaustion denial of service
12788| [99568] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 Pipelined Request information disclosure
12789| [99048] Apache Ambari up to 2.3.x REST API Shell Metacharacter privilege escalation
12790| [99014] Apache Camel Jackson/JacksonXML privilege escalation
12791| [98610] Apple macOS up to 10.12.3 apache_mod_php memory corruption
12792| [98609] Apple macOS up to 10.12.3 apache_mod_php denial of service
12793| [98608] Apple macOS up to 10.12.3 apache_mod_php memory corruption
12794| [98607] Apple macOS up to 10.12.3 apache_mod_php denial of service
12795| [98606] Apple macOS up to 10.12.3 apache_mod_php denial of service
12796| [98605] Apple macOS up to 10.12.3 Apache denial of service
12797| [98604] Apple macOS up to 10.12.3 Apache denial of service
12798| [98603] Apple macOS up to 10.12.3 Apache denial of service
12799| [98602] Apple macOS up to 10.12.3 Apache denial of service
12800| [98601] Apple macOS up to 10.12.3 Apache denial of service
12801| [98517] Apache POI up to 3.14 OOXML File XXE denial of service
12802| [98405] Apache Hadoop up to 0.23.10 privilege escalation
12803| [98199] Apache Camel Validation XML External Entity
12804| [97892] Apache Tomcat up to 9.0.0.M15 Reverse-Proxy Http11InputBuffer.java information disclosure
12805| [97617] Apache Camel camel-snakeyaml Deserialization privilege escalation
12806| [97602] Apache Camel camel-jackson/camel-jacksonxml CamelJacksonUnmarshalType privilege escalation
12807| [97732] Apache Struts up to 2.3.31/2.5.10 Jakarta Multipart Parser Content-Type privilege escalation
12808| [97466] mod_auth_openidc up to 2.1.5 on Apache weak authentication
12809| [97455] mod_auth_openidc up to 2.1.4 on Apache weak authentication
12810| [97081] Apache Tomcat HTTPS Request denial of service
12811| [97162] EMC OpenText Documentum D2 BeanShell/Apache Commons privilege escalation
12812| [96949] Hanwha Techwin Smart Security Manager up to 1.5 Redis/Apache Felix Gogo privilege escalation
12813| [96314] Apache Cordova up to 6.1.1 on Android weak authentication
12814| [95945] Apple macOS up to 10.12.2 apache_mod_php denial of service
12815| [95944] Apple macOS up to 10.12.2 apache_mod_php denial of service
12816| [95943] Apple macOS up to 10.12.2 apache_mod_php memory corruption
12817| [95666] Oracle FLEXCUBE Direct Banking 12.0.0/12.0.1/12.0.2/12.0.3 Apache Commons Collections privilege escalation
12818| [95455] Apache NiFi up to 1.0.0/1.1.0 Connection Details Dialogue cross site scripting
12819| [95311] Apache Storm UI Daemon privilege escalation
12820| [95291] ZoneMinder 1.30.0 Apache httpd privilege escalation
12821| [94800] Apache Wicket up to 1.5.16/6.24.x Deserialize DiskFileItem denial of service
12822| [94705] Apache Qpid Broker for Java up to 6.1.0 SCRAM-SHA-1/SCRAM-SHA-256 User information disclosure
12823| [94627] Apache HTTP Server up to 2.4.24 mod_auth_digest Crash denial of service
12824| [94626] Apache HTTP Server up to 2.4.24 mod_session_crypto Padding weak encryption
12825| [94625] Apache HTTP Server up to 2.4.24 Response Split privilege escalation
12826| [94540] Apache Tika 1.9 tika-server File information disclosure
12827| [94600] Apache ActiveMQ up to 5.14.1 Administration Console cross site scripting
12828| [94348] Apple macOS up to 10.12.1 apache_mod_php denial of service
12829| [94347] Apple macOS up to 10.12.1 apache_mod_php denial of service
12830| [94346] Apple macOS up to 10.12.1 apache_mod_php denial of service
12831| [94345] Apple macOS up to 10.12.1 apache_mod_php denial of service
12832| [94344] Apple macOS up to 10.12.1 apache_mod_php denial of service
12833| [94343] Apple macOS up to 10.12.1 apache_mod_php memory corruption
12834| [94342] Apple macOS up to 10.12.1 apache_mod_php memory corruption
12835| [94128] Apache Tomcat up to 9.0.0.M13 Error information disclosure
12836| [93958] Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c denial of service
12837| [93874] Apache Subversion up to 1.8.16/1.9.4 mod_dontdothat XXE denial of service
12838| [93855] Apache Hadoop up to 2.6.4/2.7.2 HDFS Service privilege escalation
12839| [93609] Apache OpenMeetings 3.1.0 RMI Registry privilege escalation
12840| [93555] Apache Tika 1.6-1.13 jmatio MATLAB File privilege escalation
12841| [93799] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
12842| [93798] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
12843| [93797] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 HTTP Split privilege escalation
12844| [93796] Apache Tomcat up to 8.5.6/9.0.0.M11 HTTP/2 Header Parser denial of service
12845| [93532] Apache Commons Collections Library Java privilege escalation
12846| [93210] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 ResourceLinkFactory privilege escalation
12847| [93209] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Realm Authentication User information disclosure
12848| [93208] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 System Property Replacement information disclosure
12849| [93207] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Utility Method privilege escalation
12850| [93206] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Configuration privilege escalation
12851| [93098] Apache Commons FileUpload privilege escalation
12852| [92987] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Commons Collection memory corruption
12853| [92986] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Tomcat memory corruption
12854| [92982] Oracle Insurance IStream 4.3.2 Apache Commons Collections memory corruption
12855| [92981] Oracle Financial Services Lending and Leasing 14.1.0/14.2.0 Apache Commons Collections memory corruption
12856| [92979] Oracle up to 8.0.3 Apache Commons Collections memory corruption
12857| [92977] Oracle FLEXCUBE Universal Banking up to 12.2.0 Apache Commons Collections memory corruption
12858| [92976] Oracle FLEXCUBE Universal Banking 12.87.1/12.87.2 Apache Commons Collections memory corruption
12859| [92975] Oracle FLEXCUBE Private Banking up to 12.1.0 Apache Commons Collections memory corruption
12860| [92974] Oracle FLEXCUBE Investor Servicing 12.0.1 Apache Commons Collections memory corruption
12861| [92973] Oracle 12.0.0/12.1.0 Apache Commons Collections memory corruption
12862| [92972] Oracle FLEXCUBE Core Banking 11.5.0.0.0/11.6.0.0.0 Apache Commons Collections memory corruption
12863| [92962] Oracle Agile PLM 9.3.4/9.3.5 Apache Commons Collections memory corruption
12864| [92909] Oracle Agile PLM 9.3.4/9.3.5 Apache Tomcat unknown vulnerability
12865| [92786] Oracle Banking Digital Experience 15.1 Apache Commons Collections information disclosure
12866| [92549] Apache Tomcat on Red Hat privilege escalation
12867| [92509] Apache Tomcat JK ISAPI Connector up to 1.2.41 jk_uri_worker_map.c memory corruption
12868| [92314] Apache MyFaces Trinidad up to 1.0.13/1.2.15/2.0.1/2.1.1 CoreResponseStateManager memory corruption
12869| [92313] Apache Struts2 up to 2.3.28/2.5.0 Action Name Cleanup cross site request forgery
12870| [92299] Apache Derby up to 10.12.1.0 SqlXmlUtil XML External Entity
12871| [92217] Apache ActiveMQ Artemis up to 1.3.x Broker/REST GetObject privilege escalation
12872| [92174] Apache Ranger up to 0.6.0 Policy cross site scripting
12873| [91831] Apache Jackrabbit up to 2.13.2 HTTP Header cross site request forgery
12874| [91825] Apache Zookeeper up to 3.4.8/3.5.2 C CLI Shell memory corruption
12875| [91818] Apache CXF Fediz up to 1.2.2/1.3.0 Application Plugin privilege escalation
12876| [92056] Apple macOS up to 10.11 apache_mod_php memory corruption
12877| [92055] Apple macOS up to 10.11 apache_mod_php memory corruption
12878| [92054] Apple macOS up to 10.11 apache_mod_php denial of service
12879| [92053] Apple macOS up to 10.11 apache_mod_php denial of service
12880| [92052] Apple macOS up to 10.11 apache_mod_php denial of service
12881| [92051] Apple macOS up to 10.11 apache_mod_php memory corruption
12882| [92050] Apple macOS up to 10.11 apache_mod_php denial of service
12883| [92049] Apple macOS up to 10.11 apache_mod_php memory corruption
12884| [92048] Apple macOS up to 10.11 apache_mod_php denial of service
12885| [92047] Apple macOS up to 10.11 apache_mod_php memory corruption
12886| [92046] Apple macOS up to 10.11 apache_mod_php memory corruption
12887| [92045] Apple macOS up to 10.11 apache_mod_php memory corruption
12888| [92044] Apple macOS up to 10.11 apache_mod_php memory corruption
12889| [92043] Apple macOS up to 10.11 apache_mod_php denial of service
12890| [92042] Apple macOS up to 10.11 apache_mod_php memory corruption
12891| [92041] Apple macOS up to 10.11 apache_mod_php memory corruption
12892| [92040] Apple macOS up to 10.11 Apache Proxy privilege escalation
12893| [91785] Apache Shiro up to 1.3.1 Servlet Filter privilege escalation
12894| [90879] Apache OpenMeetings up to 3.1.1 SWF Panel cross site scripting
12895| [90878] Apache Sentry up to 1.6.x Blacklist Filter reflect/reflect2/java_method privilege escalation
12896| [90610] Apache POI up to 3.13 XLSX2CSV Example OpenXML Document XML External Entity
12897| [90584] Apache ActiveMQ up to 5.11.3/5.12.2/5.13/1 Administration Web Console privilege escalation
12898| [90385] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site scripting
12899| [90384] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site request forgery
12900| [90383] Apache OpenOffice up to 4.1.2 Impress File memory corruption
12901| [89670] Apache Tomcat up to 8.5.4 CGI Servlet Environment Variable Open Redirect
12902| [89669] Apache HTTP Server up to 2.4.23 RFC 3875 Namespace Conflict Environment Variable Open Redirect
12903| [89726] Apple Mac OS X up to 10.11.5 apache_mod_php memory corruption
12904| [89484] Apache Qpid up to 0.13.0 on Windows Proton Library Certificate weak authentication
12905| [89473] HPE iMC PLAT/EAD/APM/iMC NTA/iMC BIMS/iMC UAM_TAM up to 7.2 Apache Commons Collections Library Command privilege escalation
12906| [90263] Apache Archiva Header denial of service
12907| [90262] Apache Archiva Deserialize privilege escalation
12908| [90261] Apache Archiva XML DTD Connection privilege escalation
12909| [88827] Apache Xerces-C++ up to 3.1.3 DTD Stack-Based memory corruption
12910| [88747] Apache HTTP Server 2.4.17/2.4.18 mod_http2 denial of service
12911| [88608] Apache Struts up to 2.3.28.1/2.5.0 URLValidator Null Value denial of service
12912| [88607] Apache Struts up to 2.3.28.1 REST Plugin Expression privilege escalation
12913| [88606] Apache Struts up to 2.3.28.1 Restriction privilege escalation
12914| [88605] Apache Struts up to 2.3.28.1 Restriction privilege escalation
12915| [88604] Apache Struts up to 2.3.28.1 Token Validator cross site request forgery
12916| [88603] Apache Commons FileUpload up to 1.3.1 MultipartStream denial of service
12917| [88602] Apache Struts up to 1.3.10 ActionServlet.java cross site scripting
12918| [88601] Apache Struts up to 1.3.10 Multithreading ActionServlet.java memory corruption
12919| [88600] Apache Struts up to 1.3.10 MultiPageValidator privilege escalation
12920| [89005] Apache Qpid AMQP JMS Client getObject privilege escalation
12921| [87888] Apache Ranger up to 0.5.2 Policy Admin Tool eventTime sql injection
12922| [87835] Apache CloudStack up to 4.5.2.0/4.6.2.0/4.7.1.0/4.8.0.0 SAML-based Authentication privilege escalation
12923| [87806] HPE Discovery and Dependency Mapping Inventory up to 9.32 update 3 Apache Commons Collections Library privilege escalation
12924| [87805] HPE Universal CMDB up to 10.21 Apache Commons Collections Library privilege escalation
12925| [87768] Apache Shiro up to 1.2.4 Cipher Key privilege escalation
12926| [87765] Apache James Server 2.3.2 Command privilege escalation
12927| [88667] Apache HTTP Server up to 2.4.20 mod_http2 Certificate weak authentication
12928| [87718] Apache Struts up to 2.3.24.1 OGNL Caching denial of service
12929| [87717] Apache Struts up to 2.3.28 REST Plugin privilege escalation
12930| [87706] Apache Qpid Java up to 6.0.2 AMQP privilege escalation
12931| [87703] Apache Qbid Java up to 6.0.2 PlainSaslServer.java denial of service
12932| [87702] Apache ActiveMQ up to 5.13.x Fileserver Web Application Upload privilege escalation
12933| [87700] Apache PDFbox up to 1.8.11/2.0.0 XML Parser PDF Document XML External Entity
12934| [87679] HP Release Control 9.13/9.20/9.21 Apache Commons Collections Library Java Object privilege escalation
12935| [87540] Apache Ambari up to 2.2.0 File Browser View information disclosure
12936| [87433] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
12937| [87432] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
12938| [87431] Apple Mac OS X up to 10.11.4 apache_mod_php Format String
12939| [87430] Apple Mac OS X up to 10.11.4 apache_mod_php denial of service
12940| [87429] Apple Mac OS X up to 10.11.4 apache_mod_php information disclosure
12941| [87428] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
12942| [87427] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
12943| [87389] Apache Xerces C++ up to 3.1.3 XML Document DTDScanner.cpp memory corruption
12944| [87172] Adobe ColdFusion 11 Update 7/2016/up to 10 Update 18 Apache Commons Collections Library privilege escalation
12945| [87121] Apache Cordova iOS up to 3.x Plugin privilege escalation
12946| [87120] Apache Cordova iOS up to 3.x URL Whitelist privilege escalation
12947| [83806] HPE Network Node Manager i up to 10.01 Apache Commons Collections Library privilege escalation
12948| [83077] Apache Subversion up to 1.8.15/1.9.3 mod_authz_svn mod_authz_svn.c denial of service
12949| [83076] Apache Subversion up to 1.8.15/1.9.3 svnserve svnserve/cyrus_auth.c privilege escalation
12950| [82790] Apache Struts 2.0.0/2.3.24/2.3.28 Dynamic Method privilege escalation
12951| [82789] Apache Struts 2.0.0/2.3.24/2.3.28 XSLTResult privilege escalation
12952| [82725] HPE P9000 Command View up to 7.x/8.4.0 Apache Commons Collections Library privilege escalation
12953| [82444] Apache Camel up to 2.14.x/2.15.4/2.16.0 HTTP Request privilege escalation
12954| [82389] Apache Subversion up to 1.7.x/1.8.14/1.9.2 mod_dav_svn util.c memory corruption
12955| [82280] Apache Struts up to 1.7 JRE URLDecoder cross site scripting
12956| [82260] Apache OFBiz up to 12.04.05/13.07.02 Java Object privilege escalation
12957| [82259] Apache Qpid Proton up to 0.12.0 proton.reactor.Connector weak encryption
12958| [82250] Apache Ranger up to 0.5.0 Admin UI weak authentication
12959| [82214] Apache Wicket up to 1.5.14/6.21.x/7.1.x Input Element cross site scripting
12960| [82213] Apache Wicket up to 1.5.14/6.21.x/7.1.x ModalWindow Title getWindowOpenJavaScript cross site scripting
12961| [82212] Apache Ranger up to 0.5.0 Policy Admin Tool privilege escalation
12962| [82211] Apache OFBiz up to 12.04.06/13.07.02 ModelFormField.java DisplayEntityField.getDescription cross site scripting
12963| [82082] Apache JetSpeed up to 2.3.0 User Manager Service privilege escalation
12964| [82081] Apache OpenMeetings up to 3.1.0 SOAP API information disclosure
12965| [82080] Apache OpenMeetings up to 3.1.0 Event cross site scripting
12966| [82078] Apache OpenMeetings up to 3.1.0 Import/Export System Backup ZIP Archive directory traversal
12967| [82077] Apache OpenMeetings up to 3.1.0 Password Reset sendHashByUser privilege escalation
12968| [82076] Apache Ranger up to 0.5.1 privilege escalation
12969| [82075] Apache JetSpeed up to 2.3.0 Portal cross site scripting
12970| [82074] Apache JetSpeed up to 2.3.0 cross site scripting
12971| [82073] Apache JetSpeed up to 2.3.0 User Manager Service sql injection
12972| [82072] Apache JetSpeed up to 2.3.0 Portal Site Manager ZIP Archive directory traversal
12973| [82058] Apache LDAP Studio/Directory Studio up to 2.0.0-M9 CSV Export privilege escalation
12974| [82053] Apache Ranger up to 0.4.x Policy Admin Tool privilege escalation
12975| [82052] Apache Ranger up to 0.4.x Policy Admin Tool HTTP Request cross site scripting
12976| [81696] Apache ActiveMQ up to 5.13.1 HTTP Header privilege escalation
12977| [81695] Apache Xerces-C up to 3.1.2 internal/XMLReader.cpp memory corruption
12978| [81622] HPE Asset Manager 9.40/9.41/9.50 Apache Commons Collections Library Java Object privilege escalation
12979| [81406] HPE Service Manager up to 9.35 P3/9.41 P1 Apache Commons Collections Library Command privilege escalation
12980| [81405] HPE Operations Orchestration up to 10.50 Apache Commons Collections Library Command privilege escalation
12981| [81427] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
12982| [81426] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
12983| [81372] Apache Struts up to 2.3.24.1 I18NInterceptor cross site scripting
12984| [81371] Apache Struts up to 2.3.24.1 Double OGNL Evaluation privilege escalation
12985| [81370] Apache Struts up to 2.3.24.1 Java URLDecoder cross site scripting
12986| [81084] Apache Tomcat 6.0/7.0/8.0/9.0 ServletContext directory traversal
12987| [81083] Apache Tomcat 7.0/8.0/9.0 Index Page cross site request forgery
12988| [81082] Apache Tomcat 7.0/8.0/9.0 ResourceLinkFactory.setGlobalContext privilege escalation
12989| [81081] Apache Tomcat 6.0/7.0/8.0/9.0 Error information disclosure
12990| [81080] Apache Tomcat 6.0/7.0/8.0/9.0 Session Persistence privilege escalation
12991| [81079] Apache Tomcat 6.0/7.0/8.0/9.0 StatusManagerServlet information disclosure
12992| [81078] Apache Tomcat 7.0/8.0/9.0 Session privilege escalation
12993| [80970] Apache Solr up to 5.3.0 Admin UI plugins.js cross site scripting
12994| [80969] Apache Solr up to 5.2 Schema schema-browser.js cross site scripting
12995| [80968] Apache Solr up to 5.0 analysis.js cross site scripting
12996| [80940] HP Continuous Delivery Automation 1.30 Apache Commons Collections Library privilege escalation
12997| [80823] Apache CloudStack up to 4.5.1 KVM Virtual Machine Migration privilege escalation
12998| [80822] Apache CloudStack up to 4.5.1 API Call information disclosure
12999| [80778] Apache Camel up to 2.15.4/2.16.0 camel-xstream privilege escalation
13000| [80750] HPE Operations Manager 8.x/9.0 on Windows Apache Commons Collections Library privilege escalation
13001| [80724] Apache Hive up to 1.2.1 Authorization Framework privilege escalation
13002| [80577] Oracle Secure Global Desktop 4.63/4.71/5.2 Apache HTTP Server denial of service
13003| [80165] Intel McAfee ePolicy Orchestrator up to 4.6.9/5.0.3/5.3.1 Apache Commons Collections Library privilege escalation
13004| [80116] Apache Subversion up to 1.9.2 svn Protocol libsvn_ra_svn/marshal.c read_string memory corruption
13005| [80115] Apache ActiveMQ up to 5.12.x Broker Service privilege escalation
13006| [80036] IBM Cognos Business Intelligence Apache Commons Collections Library InvokerTransformer privilege escalation
13007| [79873] VMware vCenter Operations/vRealize Orchestrator Apache Commons Collections Library Serialized Java Object privilege escalation
13008| [79840] Apache Cordova File Transfer Plugin up to 1.2.x on Android unknown vulnerability
13009| [79839] Apache TomEE Serialized Java Stream EjbObjectInputStream privilege escalation
13010| [79791] Cisco Products Apache Commons Collections Library privilege escalation
13011| [79539] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
13012| [79538] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
13013| [79294] Apache Cordova-Android up to 3.6 BridgeSecret Random Generator weak encryption
13014| [79291] Apache Cordova-Android up to 4.0 Javascript Whitelist privilege escalation
13015| [79244] Apache CXF up to 2.7.17/3.0.7/3.1.2 SAML Web SSO Module SAML Response weak authentication
13016| [79243] Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0 WLS Security com.bea.core.apache.commons.collections.jar privilege escalation
13017| [78989] Apache Ambari up to 2.1.1 Open Redirect
13018| [78988] Apache Ambari up to 2.0.1/2.1.0 Password privilege escalation
13019| [78987] Apache Ambari up to 2.0.x cross site scripting
13020| [78986] Apache Ambari up to 2.0.x Proxy Endpoint api/v1/proxy privilege escalation
13021| [78780] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
13022| [78779] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
13023| [78778] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
13024| [78777] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
13025| [78776] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
13026| [78775] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
13027| [78774] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
13028| [78297] Apache Commons Components HttpClient up to 4.3.5 HTTPS Timeout denial of service
13029| [77406] Apache Flex BlazeDS AMF Message XML External Entity
13030| [77429] Apache ActiveMQ up to 5.10.0 LDAPLoginModule privilege escalation
13031| [77399] Apache ActiveMQ up to 5.10.0 LDAPLoginModule weak authentication
13032| [77375] Apache Tapestry up to 5.3.5 Client-Side Object Storage privilege escalation
13033| [77331] Apache ActiveMQ up to 5.11.1 on Windows Fileserver Upload/Download directory traversal
13034| [77299] Apache Solr Real-Time Module up to 7.x-1.1 Index Content information disclosure
13035| [77247] Apache ActiveMQ up to 5.10 TransportConnection.java processControlCommand denial of service
13036| [77083] Apache Groovy up to 2.4.3 MethodClosure.java MethodClosure memory corruption
13037| [76953] Apache Subversion 1.7.0/1.8.0/1.8.10 svn_repos_trace_node_locations information disclosure
13038| [76952] Apache Subversion 1.7.0/1.8.0/1.8.10 mod_authz_svn anonymous/authenticated information disclosure
13039| [76567] Apache Struts 2.3.20 unknown vulnerability
13040| [76733] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 ap_some_auth_required unknown vulnerability
13041| [76732] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 Request apr_brigade_flatten privilege escalation
13042| [76731] Apache HTTP Server 2.4.12 ErrorDocument 400 Crash denial of service
13043| [75690] Apache Camel up to 2.13.3/2.14.1 XPathBuilder.java XML External Entity
13044| [75689] Apache Camel up to 2.13.3/2.14.1 XML Converter Setup XmlConverter.java SAXSource privilege escalation
13045| [75668] Apache Sling API/Sling Servlets Post up to 2.2.1 HtmlResponse cross site scripting
13046| [75601] Apache Jackrabbit up to 2.10.0 WebDAV Request XML External Entity
13047| [75420] Apache Tomcat up to 6.0.43/7.0.58/8.0.16 Security Manager privilege escalation
13048| [75145] Apache OpenOffice up to 4.1.1 HWP Filter Crash denial of service
13049| [75032] Apache Tomcat Connectors up to 1.2.40 mod_jk privilege escalation
13050| [75135] PHP 5.4/5.5 HTTP Request sapi_apache2.c apache2handler privilege escalation
13051| [74793] Apache Tomcat File Upload denial of service
13052| [74708] Apple MacOS X up to 10.10.2 Apache denial of service
13053| [74707] Apple MacOS X up to 10.10.2 Apache denial of service
13054| [74706] Apple MacOS X up to 10.10.2 Apache memory corruption
13055| [74705] Apple MacOS X up to 10.10.2 Apache denial of service
13056| [74704] Apple MacOS X up to 10.10.2 Apache denial of service
13057| [74703] Apple MacOS X up to 10.10.2 Apache denial of service
13058| [74702] Apple MacOS X up to 10.10.2 Apache denial of service
13059| [74701] Apple MacOS X up to 10.10.2 Apache cross site request forgery
13060| [74700] Apple MacOS X up to 10.10.2 Apache unknown vulnerability
13061| [74661] Apache Flex up to 4.14.0 asdoc index.html cross site scripting
13062| [74609] Apache Cassandra up to 1.2.19/2.0.13/2.1.3 JMX/RMI Interface privilege escalation
13063| [74469] Apache Xerces-C up to 7.0 internal/XMLReader.cpp denial of service
13064| [74468] Apache Batik up to 1.6 denial of service
13065| [74414] Apache Mod-gnutls up to 0.5.1 Authentication spoofing
13066| [74371] Apache Standard Taglibs up to 1.2.0 memory corruption
13067| [74367] Apache HTTP Server up to 2.4.12 mod_lua lua_request.c wsupgrade denial of service
13068| [74174] Apache WSS4J up to 2.0.0 privilege escalation
13069| [74172] Apache ActiveMQ up to 5.5.0 Administration Console cross site scripting
13070| [69092] Apache Tomcat up to 6.0.42/7.0.54/8.0.8 HTTP Request Smuggling privilege escalation
13071| [73831] Apache Qpid up to 0.30 Access Restriction unknown vulnerability
13072| [73731] Apache XML Security unknown vulnerability
13073| [68660] Oracle BI Publisher 10.1.3.4.2/11.1.1.7 Apache Tomcat cross site scripting
13074| [73659] Apache CloudStack up to 4.3.0 Stack-Based unknown vulnerability
13075| [73593] Apache Traffic Server up to 5.1.0 denial of service
13076| [73511] Apache POI up to 3.10 Deadlock denial of service
13077| [73510] Apache Solr up to 4.3.0 cross site scripting
13078| [68447] Apache Subversion up to 1.7.18/1.8.10 mod_dav_svn Crash denial of service
13079| [68446] Apache Subversion up to 1.7.18/1.8.10 REPORT Request Crash denial of service
13080| [73173] Apache CloudStack Stack-Based unknown vulnerability
13081| [68357] Apache Struts up to 2.3.16.3 Random Number Generator cross site request forgery
13082| [73106] Apache Hadoop up to 2.4.0 Symlink privilege escalation
13083| [68575] Apache HTTP Server up to 2.4.10 LuaAuthzProvider mod_lua.c privilege escalation
13084| [72890] Apache Qpid 0.30 unknown vulnerability
13085| [72887] Apache Hive 0.13.0 File Permission privilege escalation
13086| [72878] Apache Cordova 3.5.0 cross site request forgery
13087| [72877] Apache Cordova 3.5.0 cross site request forgery
13088| [72876] Apache Cordova 3.5.0 cross site request forgery
13089| [68435] Apache HTTP Server 2.4.10 mod_proxy_fcgi.c handle_headers denial of service
13090| [68065] Apache CXF up to 3.0.1 JAX-RS SAML denial of service
13091| [68064] Apache CXF up to 3.0.0 SAML Token denial of service
13092| [67913] Oracle Retail Markdown Optimization 12.0/13.0/13.1/13.2/13.4 Apache commons-beanutils-1.8.0.jar memory corruption
13093| [67912] Oracle Retail Invoice Matching up to 14.0 Apache commons-beanutils-1.8.0.jar memory corruption
13094| [67911] Oracle Retail Clearance Optimization Engine 13.3/13.4/14.0 Apache commons-beanutils-1.8.0.jar memory corruption
13095| [67910] Oracle Retail Allocation up to 13.2 Apache commons-beanutils-1.8.0.jar memory corruption
13096| [71835] Apache Shiro 1.0.0/1.1.0/1.2.0/1.2.1/1.2.2 unknown vulnerability
13097| [71633] Apachefriends XAMPP 1.8.1 cross site scripting
13098| [71629] Apache Axis2/C spoofing
13099| [67633] Apple Mac OS X up to 10.9.4 apache_mod_php ext/standard/dns.c dns_get_record memory corruption
13100| [67631] Apple Mac OS X up to 10.9.4 apache_mod_php Symlink memory corruption
13101| [67630] Apple Mac OS X up to 10.9.4 apache_mod_php cdf_read_property_info denial of service
13102| [67629] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_count_chain denial of service
13103| [67628] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_check_stream_offset denial of service
13104| [67627] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c mconvert memory corruption
13105| [67626] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c denial of service
13106| [67625] Apple Mac OS X up to 10.9.4 apache_mod_php Crash denial of service
13107| [67624] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_property_info denial of service
13108| [67623] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_unpack_summary_info denial of service
13109| [67622] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_short_sector denial of service
13110| [67620] Apple Mac OS X up to 10.9.4 apache_mod_php magic/Magdir/commands denial of service
13111| [67790] Apache HTTP Server mod_cache NULL Pointer Dereference denial of service
13112| [67522] Apache Tomcat up to 7.0.39 JSP Upload privilege escalation
13113| [70809] Apache POI up to 3.11 Crash denial of service
13114| [70808] Apache POI up to 3.10 unknown vulnerability
13115| [70806] Apache Commons-httpclient 4.2/4.2.1/4.2.2 spoofing
13116| [70749] Apache Axis up to 1.4 getCN spoofing
13117| [70701] Apache Traffic Server up to 3.3.5 denial of service
13118| [70700] Apache OFBiz up to 12.04.03 cross site scripting
13119| [67402] Apache OpenOffice 4.0.0/4.0.1/4.1.0 Calc privilege escalation
13120| [67401] Apache OpenOffice up to 4.1.0 OLE Object information disclosure
13121| [70661] Apache Subversion up to 1.6.17 denial of service
13122| [70660] Apache Subversion up to 1.6.17 spoofing
13123| [70659] Apache Subversion up to 1.6.17 spoofing
13124| [67183] Apache HTTP Server up to 2.4.9 mod_proxy denial of service
13125| [67180] Apache HTTP Server up to 2.4.9 WinNT MPM Memory Leak denial of service
13126| [67185] Apache HTTP Server up to 2.4.9 mod_status Heap-Based memory corruption
13127| [67184] Apache HTTP Server 2.4.5/2.4.6 mod_cache NULL Pointer Dereference denial of service
13128| [67182] Apache HTTP Server up to 2.4.9 mod_deflate Memory Consumption denial of service
13129| [67181] Apache HTTP Server up to 2.4.9 mod_cgid denial of service
13130| [70338] Apache Syncope up to 1.1.7 unknown vulnerability
13131| [70295] Apache CXF up to 2.7.9 Cleartext information disclosure
13132| [70106] Apache Open For Business Project up to 10.04.0 getServerError cross site scripting
13133| [70105] Apache MyFaces up to 2.1.5 JavaServer Faces directory traversal
13134| [69846] Apache HBase up to 0.94.8 information disclosure
13135| [69783] Apache CouchDB up to 1.2.0 memory corruption
13136| [13383] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 XML Parser privilege escalation
13137| [13300] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi setuid privilege escalation
13138| [13299] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi Content-Type Header information disclosure
13139| [13164] Apache CXF up to 2.6.13/2.7.10 SOAP OutgoingChainInterceptor.java Invalid Content denial of service
13140| [13163] Apache CXF up to 2.6.13/2.7.10 SOAP HTML Content denial of service
13141| [13158] Apache Struts up to 2.3.16.2 ParametersInterceptor getClass privilege escalation
13142| [69515] Apache Struts up to 2.3.15.0 CookieInterceptor memory corruption
13143| [13086] Apache Struts up to 1.3.10 Class Loader privilege escalation
13144| [13067] Apache Struts up to 2.3.16.1 Class Loader privilege escalation
13145| [69431] Apache Archiva up to 1.3.6 cross site scripting
13146| [69385] Apache Syncope up to 1.1.6 unknown vulnerability
13147| [69338] Apache Xalan-Java up to 2.7.1 system-property unknown vulnerability
13148| [12742] Trustwave ModSecurity up to 2.7.5 Chunk Extension apache2/modsecurity.c modsecurity_tx_init privilege escalation
13149| [12741] Trustwave ModSecurity up to 2.7.6 Chunked HTTP Transfer apache2/modsecurity.c modsecurity_tx_init Trailing Header privilege escalation
13150| [13387] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Content-Length Header privilege escalation
13151| [13386] Apache Tomcat Security Manager up to 6.0.39/7.0.53/8.0.5 XSLT privilege escalation
13152| [13385] Apache Tomcat 8.0.0/8.0.1/8.0.3 AJP Request Zero Length denial of service
13153| [13384] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Chunked HTTP Request denial of service
13154| [12748] Apache CouchDB 1.5.0 UUIDS /_uuids denial of service
13155| [66739] Apache Camel up to 2.12.2 unknown vulnerability
13156| [66738] Apache Camel up to 2.12.2 unknown vulnerability
13157| [12667] Apache HTTP Server 2.4.7 mod_log_config.c log_cookie denial of service
13158| [66695] Apache CouchDB up to 1.2.0 cross site scripting
13159| [66694] Apache CouchDB up to 1.2.0 Partition partition2 directory traversal
13160| [66689] Apache HTTP Server up to 2.0.33 mod_dav dav_xml_get_cdata denial of service
13161| [12518] Apache Tomcat up to 6.0.38/7.0.49/8.0.0-RC9 HTTP Header denial of service
13162| [66498] Apache expressions up to 3.3.0 Whitelist unknown vulnerability
13163| [12781] Apache Struts up to 2.3.8 ParametersInterceptor getClass denial of service
13164| [12439] Apache Tomcat 6.0.33 XML XXE information disclosure
13165| [12438] Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37 coyoteadapter.java disableURLRewriting privilege escalation
13166| [66356] Apache Wicket up to 6.8.0 information disclosure
13167| [12209] Apache Tomcat 7.0.0/7.0.50/8.0.0-RC1/8.0.1 Content-Type Header for Multi-Part Request Infinite Loop denial of service
13168| [66322] Apache ActiveMQ up to 5.8.0 cross site scripting
13169| [12291] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
13170| [66255] Apache Open For Business Project up to 10.04.3 cross site scripting
13171| [66200] Apache Hadoop up to 2.0.5 Security Feature information disclosure
13172| [66072] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
13173| [66068] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
13174| [11928] Oracle Secure Global Desktop up to 4.71 Apache Tomcat unknown vulnerability
13175| [11924] Oracle Secure Global Desktop up to 4.63 Apache Tomcat denial of service
13176| [11922] Oracle Secure Global Desktop up to 4.63 Apache Tomcat unknown vulnerability
13177| [66049] Apache XML Security for Java up to 1.4.6 Memory Consumption denial of service
13178| [12199] Apache Subversion up to 1.8.5 mod_dav_svn/repos.c get_resource denial of service
13179| [65946] askapache Firefox Adsense up to 3.0 askapache-firefox-adsense.php cross site request forgery
13180| [65668] Apache Solr 4.0.0 Updater denial of service
13181| [65665] Apache Solr up to 4.3.0 denial of service
13182| [65664] Apache Solr 3.6.0/3.6.1/3.6.2/4.0.0 Updater denial of service
13183| [65663] Apache Solr up to 4.5.1 ResourceLoader directory traversal
13184| [65658] Apache roller 4.0/4.0.1/5.0/5.0.1 unknown vulnerability
13185| [65657] Apache Roller 4.0/4.0.1/5.0/5.0.1 cross site scripting
13186| [11325] Apache Subversion 1.7.13 mod_dontdothat Bypass denial of service
13187| [11324] Apache Subversion up to 1.8.4 mod_dav_svn denial of service
13188| [11098] Apache Tomcat 5.5.25 HTTP Request cross site request forgery
13189| [65410] Apache Struts 2.3.15.3 cross site scripting
13190| [65386] Apache Solr up to 2.2.1 on TYPO3 cross site scripting
13191| [65385] Apache Solr up to 2.2.1 on TYPO3 unknown vulnerability
13192| [11044] Apache Struts 2.3.15.3 showConfig.action cross site scripting
13193| [11043] Apache Struts 2.3.15.3 actionNames.action cross site scripting
13194| [11018] cPanel WHM up to 11.40.0.11 Apache mod_userdir Tweak Interface privilege escalation
13195| [65342] Apache Sling 1.0.2/1.0.4/1.0.6/1.1.0/1.1.2 Auth Core cross site scripting
13196| [65340] Apache Shindig 2.5.0 information disclosure
13197| [65316] Apache Mod Fcgid up to 2.3.7 mod_fcgid fcgid_bucket.c fcgid_header_bucket_read memory corruption
13198| [65313] Apache Sling 2.2.0/2.3.0 AbstractCreateOperation.java deepGetOrCreateNode denial of service
13199| [10826] Apache Struts 2 File privilege escalation
13200| [65204] Apache Camel up to 2.10.1 unknown vulnerability
13201| [10460] Apache Struts 2.0.0/2.3.15.1 Action Mapping Mechanism Bypass privilege escalation
13202| [10459] Apache Struts 2.0.0/2.3.15 Dynamic Method Invocation unknown vulnerability
13203| [10160] Apache Subversion 1.8.0/1.8.1/1.8.2 svnwcsub.py handle_options race condition
13204| [10159] Apache Subversion up to 1.8.2 svnserve write_pid_file race condition
13205| [10158] Apache Subversion 1.8.0/1.8.1/1.8.2 daemonize.py daemon::daemonize race condition
13206| [10157] Apache Subversion up to 1.8.1 FSFS Repository Symlink privilege escalation
13207| [64808] Fail2ban up to 0.8.9 apache-auth.conf denial of service
13208| [64760] Best Practical RT up to 4.0.12 Apache::Session::File information disclosure
13209| [64722] Apache XML Security for C++ Heap-based memory corruption
13210| [64719] Apache XML Security for C++ Heap-based memory corruption
13211| [64718] Apache XML Security for C++ verify denial of service
13212| [64717] Apache XML Security for C++ getURIBaseTXFM memory corruption
13213| [64716] Apache XML Security for C++ spoofing
13214| [64701] Apache CXF up to 2.7.3 XML Parser Memory Consumption denial of service
13215| [64700] Apache CloudStack up to 4.1.0 Stack-Based cross site scripting
13216| [64667] Apache Open For Business Project up to 10.04.04 unknown vulnerability
13217| [64666] Apache Open For Business Project up to 10.04.04 cross site scripting
13218| [9891] Apache HTTP Server 2.2.22 suEXEC Feature .htaccess information disclosure
13219| [64509] Apache ActiveMQ up to 5.8.0 scheduled.jsp cross site scripting
13220| [9826] Apache Subversion up to 1.8.0 mod_dav_svn denial of service
13221| [9683] Apache HTTP Server 2.4.5 mod_session_dbd denial of service
13222| [64485] Apache Struts up to 2.2.3.0 privilege escalation
13223| [9568] Apache Struts up to 2.3.15 DefaultActionMapper cross site request forgery
13224| [9567] Apache Struts up to 2.3.15 DefaultActionMapper memory corruption
13225| [64467] Apache Geronimo 3.0 memory corruption
13226| [64466] Apache OpenJPA up to 2.2.1 Serialization memory corruption
13227| [64457] Apache Struts up to 2.2.3.0 cross site scripting
13228| [64326] Alejandro Garza Apachesolr Autocomplete up to 7.x-1.1 cross site scripting
13229| [9184] Apache Qpid up to 0.20 SSL misconfiguration
13230| [8935] Apache Subversion up to 1.7.9 FSFS Format Repository denial of service
13231| [8934] Apache Subversion up to 1.7.9 Svnserve Server denial of service
13232| [8933] Apache Subversion up to 1.6.21 check-mime-type.pl svnlook memory corruption
13233| [8932] Apache Subversion up to 1.6.21 svn-keyword-check.pl svnlook changed memory corruption
13234| [9022] Apache Struts up to 2.3.14.2 OGNL Expression memory corruption
13235| [8873] Apache Struts 2.3.14 privilege escalation
13236| [8872] Apache Struts 2.3.14 privilege escalation
13237| [8746] Apache HTTP Server Log File Terminal Escape Sequence Filtering mod_rewrite.c do_rewritelog privilege escalation
13238| [8666] Apache Tomcat up to 7.0.32 AsyncListener information disclosure
13239| [8665] Apache Tomcat up to 7.0.29 Chunked Transfer Encoding Extension Size denial of service
13240| [8664] Apache Tomcat up to 7.0.32 FORM Authentication weak authentication
13241| [64075] Apache Subversion up to 1.7.7 mod_dav_svn Crash denial of service
13242| [64074] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
13243| [64073] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
13244| [64072] Apache Subversion up to 1.7.7 mod_dav_svn NULL Pointer Dereference denial of service
13245| [64071] Apache Subversion up to 1.7.8 mod_dav_svn Memory Consumption denial of service
13246| [8768] Apache Struts up to 2.3.14 on Mac EL and OGNL Interpreter memory corruption
13247| [64006] Apache ActiveMQ up to 5.7.0 denial of service
13248| [64005] Apache ActiveMQ up to 5.7.0 Default Configuration denial of service
13249| [64004] Apache ActiveMQ up to 5.7.0 PortfolioPublishServlet.java cross site scripting
13250| [8427] Apache Tomcat Session Transaction weak authentication
13251| [63960] Apache Maven 3.0.4 Default Configuration spoofing
13252| [63751] Apache qpid up to 0.20 qpid::framing::Buffer denial of service
13253| [63750] Apache qpid up to 0.20 checkAvailable denial of service
13254| [63749] Apache Qpid up to 0.20 Memory Consumption denial of service
13255| [63748] Apache Qpid up to 0.20 Default Configuration denial of service
13256| [63747] Apache Rave up to 0.20 User Account information disclosure
13257| [7889] Apache Subversion up to 1.6.17 mod_dav_svn/svn_fs_file_length() denial of service
13258| [63646] Apache HTTP Server up to 2.2.23/2.4.3 mod_proxy_balancer.c balancer_handler cross site scripting
13259| [7688] Apache CXF up to 2.7.1 WSS4JInterceptor Bypass weak authentication
13260| [7687] Apache CXF up to 2.7.2 Token weak authentication
13261| [63334] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
13262| [63299] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
13263| [7202] Apache HTTP Server 2.4.2 on Oracle Solaris ld_library_path cross site scripting
13264| [7075] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector NioEndpoint.java denial of service
13265| [7074] Apache Tomcat up to 6.0.35/7.0.29 FORM Authentication RealmBase.java weak authentication
13266| [7073] Apache Tomcat up to 6.0.35/7.0.31 CSRF Prevention Filter cross site request forgery
13267| [63090] Apache Tomcat up to 4.1.24 denial of service
13268| [63089] Apache HTTP Server up to 2.2.13 mod_proxy_ajp denial of service
13269| [62933] Apache Tomcat up to 5.5.0 Access Restriction unknown vulnerability
13270| [62929] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector Memory Consumption denial of service
13271| [62833] Apache CXF -/2.6.0 spoofing
13272| [62832] Apache Axis2 up to 1.6.2 spoofing
13273| [62831] Apache Axis up to 1.4 Java Message Service spoofing
13274| [62830] Apache Commons-httpclient 3.0 Payments spoofing
13275| [62826] Apache Libcloud up to 0.11.0 spoofing
13276| [62757] Apache Open For Business Project up to 10.04.0 unknown vulnerability
13277| [8830] Red Hat JBoss Enterprise Application Platform 6.0.1 org.apache.catalina.connector.Response.encodeURL information disclosure
13278| [62661] Apache Axis2 unknown vulnerability
13279| [62658] Apache Axis2 unknown vulnerability
13280| [62467] Apache Qpid up to 0.17 denial of service
13281| [62417] Apache CXF 2.4.7/2.4.8/2.5.3/2.5.4/2.6.1 spoofing
13282| [6301] Apache HTTP Server mod_pagespeed cross site scripting
13283| [6300] Apache HTTP Server mod_pagespeed Hostname information disclosure
13284| [6123] Apache Wicket up to 1.5.7 Ajax Link cross site scripting
13285| [62035] Apache Struts up to 2.3.4 denial of service
13286| [61916] Apache QPID 0.5/0.6/0.14/0.16 unknown vulnerability
13287| [6998] Apache Tomcat 5.5.35/6.0.35/7.0.28 DIGEST Authentication Session State Caching privilege escalation
13288| [6997] Apache Tomcat 5.5.35/6.0.35/7.0.28 HTTP Digest Authentication Implementation privilege escalation
13289| [6092] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_ajp.c information disclosure
13290| [6090] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_http.c information disclosure
13291| [61507] Apache POI up to 3.8 UnhandledDataStructure denial of service
13292| [6070] Apache Struts up to 2.3.4 Token Name Configuration Parameter privilege escalation
13293| [6069] Apache Struts up to 2.3.4 Request Parameter OGNL Expression denial of service
13294| [5764] Oracle Solaris 10 Apache HTTP Server information disclosure
13295| [5700] Oracle Secure Backup 10.3.0.3/10.4.0.1 Apache denial of service
13296| [61255] Apache Hadoop 2.0.0 Kerberos unknown vulnerability
13297| [61229] Apache Sling up to 2.1.1 denial of service
13298| [61152] Apache Commons-compress 1.0/1.1/1.2/1.3/1.4 denial of service
13299| [61094] Apache Roller up to 5.0 cross site scripting
13300| [61093] Apache Roller up to 5.0 cross site request forgery
13301| [61005] Apache OpenOffice 3.3/3.4 unknown vulnerability
13302| [9673] Apache HTTP Server up to 2.4.4 mod_dav mod_dav.c Request denial of service
13303| [5436] Apache OpenOffice 3.3/3.4 WPXContentListener.cpp _closeTableRow File memory corruption
13304| [5435] Apache OpenOffice 3.3/3.4 vclmi.dll File memory corruption
13305| [60730] PHP 5.4.0/5.4.1/5.4.2 apache_request_headers memory corruption
13306| [60708] Apache Qpid 0.12 unknown vulnerability
13307| [5032] Apache Hadoop up to 0.20.205.0/1.0.1/0.23.1 Kerberos/MapReduce Security Feature privilege escalation
13308| [4949] Apache Struts File Upload XSLTResult.java XSLT File privilege escalation
13309| [4955] Apache Traffic Server 3.0.3/3.1.2 HTTP Header Parser memory corruption
13310| [4882] Apache Wicket up to 1.5.4 directory traversal
13311| [4881] Apache Wicket up to 1.4.19 cross site scripting
13312| [4884] Apache HTTP Server up to 2.3.6 mod_fcgid fcgid_spawn_ctl.c FcgidMaxProcessesPerClass HTTP Requests denial of service
13313| [60352] Apache Struts up to 2.2.3 memory corruption
13314| [60153] Apache Portable Runtime up to 1.4.3 denial of service
13315| [4598] Apache Struts 1.3.10 upload-submit.do cross site scripting
13316| [4597] Apache Struts 1.3.10 processSimple.do cross site scripting
13317| [4596] Apache Struts 2.0.14/2.2.3 struts2-rest-showcase/orders cross site scripting
13318| [4595] Apache Struts 2.0.14/2.2.3 struts2-showcase/person/editPerson.action cross site scripting
13319| [4583] Apache HTTP Server up to 2.2.21 Threaded MPM denial of service
13320| [4582] Apache HTTP Server up to 2.2.21 protocol.c information disclosure
13321| [4571] Apache Struts up to 2.3.1.2 privilege escalation
13322| [4557] Apache Tomcat up to 7.0.21 Caching/Recycling information disclosure
13323| [59934] Apache Tomcat up to 6.0.9 DigestAuthenticator.java unknown vulnerability
13324| [59933] Apache Tomcat up to 6.0.9 Access Restriction unknown vulnerability
13325| [59932] Apache Tomcat up to 6.0.9 unknown vulnerability
13326| [59931] Apache Tomcat up to 6.0.9 Access Restriction information disclosure
13327| [59902] Apache Struts up to 2.2.3 Interfaces unknown vulnerability
13328| [4528] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
13329| [4527] Apache Struts up to 2.2.3 ExceptionDelegator cross site scripting
13330| [59888] Apache Tomcat up to 6.0.6 denial of service
13331| [59886] Apache ActiveMQ up to 5.5.1 Crash denial of service
13332| [4513] Apache Struts up to 2.3.1 ParameterInterceptor directory traversal
13333| [4512] Apache Struts up to 2.2.3 CookieInterceptor privilege escalation
13334| [59850] Apache Geronimo up to 2.2.1 denial of service
13335| [59825] Apache HTTP Server up to 2.1.7 mod_reqtimeout denial of service
13336| [59556] Apache HTTP Server up to 2.0.53 mod_proxy information disclosure
13337| [58467] Apache libcloud 0.2.0/0.3.0/0.3.1/0.4.0 Access Restriction spoofing
13338| [58413] Apache Tomcat up to 6.0.10 spoofing
13339| [58381] Apache Wicket up to 1.4.17 cross site scripting
13340| [58296] Apache Tomcat up to 7.0.19 unknown vulnerability
13341| [57888] Apache HttpClient 4.0/4.0.1/4.1 Authorization information disclosure
13342| [57587] Apache Subversion up to 1.6.16 mod_dav_svn information disclosure
13343| [57585] Apache Subversion up to 1.6.16 mod_dav_svn Memory Consumption denial of service
13344| [57584] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
13345| [57577] Apache Rampart-C 1.3.0 Access Restriction rampart_timestamp_token_validate privilege escalation
13346| [57568] Apache Archiva up to 1.3.4 cross site scripting
13347| [57567] Apache Archiva up to 1.3.4 cross site request forgery
13348| [57481] Apache Tomcat 7.0.12/7.0.13 Access Restriction unknown vulnerability
13349| [4355] Apache HTTP Server APR apr_fnmatch denial of service
13350| [57435] Apache Struts up to 2.2.1.1 FileHandler.java cross site scripting
13351| [57425] Apache Struts up to 2.2.1.1 cross site scripting
13352| [4352] Apache HTTP Server 2.2.x APR apr_fnmatch denial of service
13353| [57025] Apache Tomcat up to 7.0.11 information disclosure
13354| [57024] Apache Tomcat 7.0.11 Access Restriction information disclosure
13355| [56774] IBM WebSphere Application Server up to 7.0.0.14 org.apache.jasper.runtime.JspWriterImpl.response denial of service
13356| [56824] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
13357| [56832] Apache Tomcat up to 7.0.10 Access Restriction information disclosure
13358| [56830] Apache Tomcat up to 7.0.9 Access Restriction privilege escalation
13359| [12440] Apache Tomcat 6.0.33 Malicious Request cross site scripting
13360| [56512] Apache Continuum up to 1.4.0 cross site scripting
13361| [4285] Apache Tomcat 5.x JVM getLocale denial of service
13362| [4284] Apache Tomcat 5.x HTML Manager Infinite Loop cross site scripting
13363| [4283] Apache Tomcat 5.x ServletContect privilege escalation
13364| [56441] Apache Tomcat up to 7.0.6 denial of service
13365| [56300] Apache CouchDB up to 1.0.1 Web Administration Interface cross site scripting
13366| [55967] Apache Subversion up to 1.6.4 rev_hunt.c denial of service
13367| [55966] Apache Subversion up to 1.6.4 mod_dav_svn repos.c walk denial of service
13368| [55095] Apache Axis2 up to 1.6 Default Password memory corruption
13369| [55631] Apache Archiva up to 1.3.1 User Account cross site request forgery
13370| [55556] Apache Tomcat up to 6.0.29 Default Configuration information disclosure
13371| [55553] Apache Tomcat up to 7.0.4 sessionsList.jsp cross site scripting
13372| [55162] Apache MyFaces up to 2.0.0 Authentication Code unknown vulnerability
13373| [54881] Apache Subversion up to 1.6.12 mod_dav_svn authz.c privilege escalation
13374| [54879] Apache APR-util up to 0.9.14 mod_reqtimeout apr_brigade_split_line denial of service
13375| [54693] Apache Traffic Server DNS Cache unknown vulnerability
13376| [54416] Apache CouchDB up to 0.11.0 cross site request forgery
13377| [54394] Apache CXF up to 2.2.8 Memory Consumption denial of service
13378| [54261] Apache Tomcat jsp/cal/cal2.jsp cross site scripting
13379| [54166] Apache HTTP Server up to 2.2.12 mod_cache Crash denial of service
13380| [54385] Apache Struts up to 2.1.8.1 ParameterInterceptor unknown vulnerability
13381| [54012] Apache Tomcat up to 6.0.10 denial of service
13382| [53763] Apache Axis2 1.3/1.4/1.4.1/1.5/1.5.1 Memory Consumption denial of service
13383| [53368] Apache MyFaces 1.1.7/1.2.8 cross site scripting
13384| [53397] Apache axis2 1.4.1/1.5.1 Administration Console cross site scripting
13385| [52894] Apache Tomcat up to 6.0.7 information disclosure
13386| [52960] Apache ActiveMQ up to 5.4-snapshot information disclosure
13387| [52843] Apache HTTP Server mod_auth_shadow unknown vulnerability
13388| [52786] Apache Open For Business Project up to 09.04 cross site scripting
13389| [52587] Apache ActiveMQ up to 5.3.0 cross site request forgery
13390| [52586] Apache ActiveMQ up to 5.3.0 cross site scripting
13391| [52584] Apache CouchDB up to 0.10.1 information disclosure
13392| [51757] Apache HTTP Server 2.0.44 cross site scripting
13393| [51756] Apache HTTP Server 2.0.44 spoofing
13394| [51717] Apache HTTP Server up to 1.3.3 mod_proxy ap_proxy_send_fb memory corruption
13395| [51690] Apache Tomcat up to 6.0 directory traversal
13396| [51689] Apache Tomcat up to 6.0 information disclosure
13397| [51688] Apache Tomcat up to 6.0 directory traversal
13398| [50886] HP Operations Manager 8.10 on Windows File Upload org.apache.catalina.manager.HTMLManagerServlet memory corruption
13399| [50802] Apache Tomcat up to 3.3 Default Password weak authentication
13400| [50626] Apache Solr 1.0.0 cross site scripting
13401| [49857] Apache HTTP Server mod_proxy_ftp cross site scripting
13402| [49856] Apache HTTP Server 2.2.13 mod_proxy_ftp ap_proxy_ftp_handler denial of service
13403| [49348] Apache Xerces-C++ 2.7.0 Stack-Based denial of service
13404| [86789] Apache Portable Runtime memory/unix/apr_pools.c unknown vulnerability
13405| [49283] Apache APR-util up to 1.3.8 apr-util misc/apr_rmm.c apr_rmm_realloc memory corruption
13406| [48952] Apache HTTP Server up to 1.3.6 mod_deflate denial of service
13407| [48626] Apache Tomcat up to 4.1.23 Access Restriction directory traversal
13408| [48431] Apache Tomcat up to 4.1.23 j_security_check cross site scripting
13409| [48430] Apache Tomcat up to 4.1.23 mod_jk denial of service
13410| [47801] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site request forgery
13411| [47800] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site scripting
13412| [47799] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console directory traversal
13413| [47648] Apache Tiles 2.1.0/2.1.1 cross site scripting
13414| [47640] Apache Struts 2.0.6/2.0.8/2.0.9/2.0.11/2.1 cross site scripting
13415| [47638] Apache Tomcat up to 4.1.23 mod_jk information disclosure
13416| [47636] Apache Struts 2.0.9 xip_client.html cross site scripting
13417| [47593] Apache Mod Perl 1 perl-status Apache::Status cross site scripting
13418| [47637] Apache Struts 1.0.2/1.1/1.2.4/1.2.7/1.2.8 cross site scripting
13419| [47239] Apache Struts up to 2.1.2 Beta struts directory traversal
13420| [47214] Apachefriends xampp 1.6.8 spoofing
13421| [47213] Apachefriends xampp 1.6.8 htaccess cross site request forgery
13422| [47162] Apachefriends XAMPP 1.4.4 weak authentication
13423| [47065] Apache Tomcat 4.1.23 cross site scripting
13424| [46834] Apache Tomcat up to 5.5.20 cross site scripting
13425| [46004] Apache Jackrabbit 1.4/1.5.0 search.jsp cross site scripting
13426| [49205] Apache Roller 2.3/3.0/3.1/4.0 Search cross site scripting
13427| [86625] Apache Struts directory traversal
13428| [44461] Apache Tomcat up to 5.5.0 information disclosure
13429| [44389] Apache Xerces-C++ XML Parser Memory Consumption denial of service
13430| [44352] Apache Friends XAMPP 1.6.8 adodb.php cross site scripting
13431| [43663] Apache Tomcat up to 6.0.16 directory traversal
13432| [43612] Apache Friends XAMPP 1.6.7 iart.php cross site scripting
13433| [43556] Apache HTTP Server up to 2.1.8 mod_proxy_ftp proxy_ftp.c cross site scripting
13434| [43516] Apache Tomcat up to 4.1.20 directory traversal
13435| [43509] Apache Tomcat up to 6.0.13 cross site scripting
13436| [42637] Apache Tomcat up to 6.0.16 cross site scripting
13437| [42325] Apache HTTP Server up to 2.1.8 Error Page cross site scripting
13438| [41838] Apache-SSL 1.3.34 1.57 expandcert privilege escalation
13439| [41091] Apache Software Foundation Mod Jk up to 2.0.1 mod_jk2 Stack-based memory corruption
13440| [40924] Apache Tomcat up to 6.0.15 information disclosure
13441| [40923] Apache Tomcat up to 6.0.15 unknown vulnerability
13442| [40922] Apache Tomcat up to 6.0 information disclosure
13443| [40710] Apache HTTP Server up to 2.0.61 mod_negotiation cross site scripting
13444| [40709] Apache HTTP Server up to 2.0.53 mod_negotiation cross site scripting
13445| [40656] Apache Tomcat 5.5.20 information disclosure
13446| [40503] Apache HTTP Server mod_proxy_ftp cross site scripting
13447| [40502] Apache HTTP Server up to 2.2.5 mod_proxy_balancer memory corruption
13448| [40501] Apache HTTP Server 2.2.6 mod_proxy_balancer cross site request forgery
13449| [40398] Apache HTTP Server up to 2.2 mod_proxy_balancer cross site scripting
13450| [40397] Apache HTTP Server up to 2.2 mod_proxy_balancer balancer_handler denial of service
13451| [40234] Apache Tomcat up to 6.0.15 directory traversal
13452| [40221] Apache HTTP Server 2.2.6 information disclosure
13453| [40027] David Castro Apache Authcas 0.4 sql injection
13454| [3495] Apache OpenOffice up to 2.3 Database Document Processor unknown vulnerability
13455| [3489] Apache HTTP Server 2.x HTTP Header cross site scripting
13456| [3414] Apache Tomcat WebDAV Stored privilege escalation
13457| [39489] Apache Jakarta Slide up to 2.1 directory traversal
13458| [39540] Apache Geronimo 2.0/2.0.1/2.0.2/2.1 unknown vulnerability
13459| [3310] Apache OpenOffice 1.1.3/2.0.4/2.2.1 TIFF Image Parser Heap-based memory corruption
13460| [38768] Apache HTTP Server up to 2.1.7 mod_autoindex.c cross site scripting
13461| [38952] Apache Geronimo 2.0.1/2.1 unknown vulnerability
13462| [38658] Apache Tomcat 4.1.31 cal2.jsp cross site request forgery
13463| [38524] Apache Geronimo 2.0 unknown vulnerability
13464| [3256] Apache Tomcat up to 6.0.13 cross site scripting
13465| [38331] Apache Tomcat 4.1.24 information disclosure
13466| [38330] Apache Tomcat 4.1.24 information disclosure
13467| [38185] Apache Tomcat 3.3/3.3.1/3.3.1a/3.3.2 Error Message CookieExample cross site scripting
13468| [37967] Apache Tomcat up to 4.1.36 Error Message sendmail.jsp cross site scripting
13469| [37647] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 Authorization unknown vulnerability
13470| [37646] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 unknown vulnerability
13471| [3141] Apache Tomcat up to 4.1.31 Accept-Language Header cross site scripting
13472| [3133] Apache Tomcat up to 6.0 HTTP cross site scripting
13473| [37292] Apache Tomcat up to 5.5.1 cross site scripting
13474| [3130] Apache OpenOffice 2.2.1 RTF Document Heap-based memory corruption
13475| [36981] Apache Tomcat JK Web Server Connector up to 1.2.22 mod_jk directory traversal
13476| [36892] Apache Tomcat up to 4.0.0 hello.jsp cross site scripting
13477| [37320] Apache MyFaces Tomahawk up to 1.1.4 cross site scripting
13478| [36697] Apache Tomcat up to 5.5.17 implicit-objects.jsp cross site scripting
13479| [36491] Apache Axis 1.0 Installation javaioFileNotFoundException information disclosure
13480| [36400] Apache Tomcat 5.5.15 mod_jk cross site scripting
13481| [36698] Apache Tomcat up to 4.0.0 cal2.jsp cross site scripting
13482| [36224] XAMPP Apache Distribution up to 1.6.0a adodb.php connect memory corruption
13483| [36225] XAMPP Apache Distribution 1.6.0a sql injection
13484| [2997] Apache httpd/Tomcat 5.5/6.0 directory traversal
13485| [35896] Apache Apache Test up to 1.29 mod_perl denial of service
13486| [35653] Avaya S8300 Cm 3.1.2 Apache Tomcat unknown vulnerability
13487| [35402] Apache Tomcat JK Web Server Connector 1.2.19 mod_jk.so map_uri_to_worker memory corruption
13488| [35067] Apache Stats up to 0.0.2 extract unknown vulnerability
13489| [35025] Apache Stats up to 0.0.3 extract unknown vulnerability
13490| [34252] Apache HTTP Server denial of service
13491| [2795] Apache OpenOffice 2.0.4 WMF/EMF File Heap-based memory corruption
13492| [33877] Apache Opentaps 0.9.3 cross site scripting
13493| [33876] Apache Open For Business Project unknown vulnerability
13494| [33875] Apache Open For Business Project cross site scripting
13495| [2703] Apache Jakarta Tomcat up to 5.x der_get_oid memory corruption
13496| [2611] Apache HTTP Server up to 1.0.1 set_var Format String
13497|
13498| MITRE CVE - https://cve.mitre.org:
13499| [CVE-2013-4156] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.
13500| [CVE-2013-4131] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
13501| [CVE-2013-3239] phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.
13502| [CVE-2013-3060] The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
13503| [CVE-2013-2765] The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
13504| [CVE-2013-2251] Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
13505| [CVE-2013-2249] mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
13506| [CVE-2013-2248] Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
13507| [CVE-2013-2189] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.
13508| [CVE-2013-2135] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
13509| [CVE-2013-2134] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
13510| [CVE-2013-2115] Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
13511| [CVE-2013-2071] java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
13512| [CVE-2013-2067] java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
13513| [CVE-2013-1966] Apache Struts 2 before 2.3.14.1 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
13514| [CVE-2013-1965] Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.1, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
13515| [CVE-2013-1896] mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
13516| [CVE-2013-1884] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
13517| [CVE-2013-1879] Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."
13518| [CVE-2013-1862] mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
13519| [CVE-2013-1849] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
13520| [CVE-2013-1847] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
13521| [CVE-2013-1846] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL.
13522| [CVE-2013-1845] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file or directory.
13523| [CVE-2013-1814] The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
13524| [CVE-2013-1777] The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not property implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
13525| [CVE-2013-1768] The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
13526| [CVE-2013-1088] Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
13527| [CVE-2013-1048] The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
13528| [CVE-2013-0966] The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
13529| [CVE-2013-0942] Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
13530| [CVE-2013-0941] EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
13531| [CVE-2013-0253] The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
13532| [CVE-2013-0248] The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
13533| [CVE-2013-0239] Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
13534| [CVE-2012-6573] Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.
13535| [CVE-2012-6551] The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
13536| [CVE-2012-6092] Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
13537| [CVE-2012-5887] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.
13538| [CVE-2012-5886] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
13539| [CVE-2012-5885] The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
13540| [CVE-2012-5786] The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF, possibly 2.6.0, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
13541| [CVE-2012-5785] Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
13542| [CVE-2012-5784] Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
13543| [CVE-2012-5783] Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
13544| [CVE-2012-5633] The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
13545| [CVE-2012-5616] Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.
13546| [CVE-2012-5568] Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
13547| [CVE-2012-5351] Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
13548| [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
13549| [CVE-2012-4557] The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
13550| [CVE-2012-4556] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query.
13551| [CVE-2012-4555] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors.
13552| [CVE-2012-4534] org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
13553| [CVE-2012-4528] The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
13554| [CVE-2012-4501] Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
13555| [CVE-2012-4460] The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an out-of-bounds read, but it might not trigger a crash.
13556| [CVE-2012-4459] Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.
13557| [CVE-2012-4458] The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the client-properties map in a connection.start-ok message.
13558| [CVE-2012-4446] The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
13559| [CVE-2012-4431] org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
13560| [CVE-2012-4418] Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
13561| [CVE-2012-4387] Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
13562| [CVE-2012-4386] The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
13563| [CVE-2012-4360] Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
13564| [CVE-2012-4063] The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via unspecified vectors.
13565| [CVE-2012-4001] The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.
13566| [CVE-2012-3908] Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
13567| [CVE-2012-3546] org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
13568| [CVE-2012-3544] Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
13569| [CVE-2012-3526] The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.
13570| [CVE-2012-3513] munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
13571| [CVE-2012-3506] Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
13572| [CVE-2012-3502] The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
13573| [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
13574| [CVE-2012-3467] Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
13575| [CVE-2012-3451] Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
13576| [CVE-2012-3446] Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
13577| [CVE-2012-3376] DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
13578| [CVE-2012-3373] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
13579| [CVE-2012-3126] Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Products Suite 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Apache Tomcat Agent.
13580| [CVE-2012-3123] Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.
13581| [CVE-2012-2760] mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
13582| [CVE-2012-2733] java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
13583| [CVE-2012-2687] Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
13584| [CVE-2012-2381] Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
13585| [CVE-2012-2380] Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.
13586| [CVE-2012-2379] Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
13587| [CVE-2012-2378] Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
13588| [CVE-2012-2329] Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.
13589| [CVE-2012-2145] Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.
13590| [CVE-2012-2138] The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.
13591| [CVE-2012-2098] Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
13592| [CVE-2012-1574] The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
13593| [CVE-2012-1181] fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.
13594| [CVE-2012-1089] Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
13595| [CVE-2012-1007] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.
13596| [CVE-2012-1006] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
13597| [CVE-2012-0883] envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
13598| [CVE-2012-0840] tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
13599| [CVE-2012-0838] Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
13600| [CVE-2012-0788] The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.
13601| [CVE-2012-0394] ** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
13602| [CVE-2012-0393] The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
13603| [CVE-2012-0392] The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
13604| [CVE-2012-0391] The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
13605| [CVE-2012-0256] Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
13606| [CVE-2012-0216] The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
13607| [CVE-2012-0213] The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
13608| [CVE-2012-0053] protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
13609| [CVE-2012-0047] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
13610| [CVE-2012-0031] scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
13611| [CVE-2012-0022] Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
13612| [CVE-2012-0021] The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
13613| [CVE-2011-5064] DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
13614| [CVE-2011-5063] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
13615| [CVE-2011-5062] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
13616| [CVE-2011-5057] Apache Struts 2.3.1.1 and earlier provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
13617| [CVE-2011-5034] Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
13618| [CVE-2011-4905] Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
13619| [CVE-2011-4858] Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
13620| [CVE-2011-4668] IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
13621| [CVE-2011-4449] actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.
13622| [CVE-2011-4415] The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
13623| [CVE-2011-4317] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
13624| [CVE-2011-3639] The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
13625| [CVE-2011-3620] Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
13626| [CVE-2011-3607] Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.
13627| [CVE-2011-3376] org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
13628| [CVE-2011-3375] Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
13629| [CVE-2011-3368] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
13630| [CVE-2011-3348] The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
13631| [CVE-2011-3192] The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
13632| [CVE-2011-3190] Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
13633| [CVE-2011-2729] native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
13634| [CVE-2011-2712] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
13635| [CVE-2011-2688] SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
13636| [CVE-2011-2526] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.
13637| [CVE-2011-2516] Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
13638| [CVE-2011-2481] Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
13639| [CVE-2011-2329] The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730.
13640| [CVE-2011-2204] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.
13641| [CVE-2011-2088] XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
13642| [CVE-2011-2087] Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
13643| [CVE-2011-1928] The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.
13644| [CVE-2011-1921] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
13645| [CVE-2011-1783] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
13646| [CVE-2011-1772] Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
13647| [CVE-2011-1752] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
13648| [CVE-2011-1610] Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
13649| [CVE-2011-1582] Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
13650| [CVE-2011-1571] Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
13651| [CVE-2011-1570] Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
13652| [CVE-2011-1503] The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.
13653| [CVE-2011-1502] Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
13654| [CVE-2011-1498] Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
13655| [CVE-2011-1475] The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
13656| [CVE-2011-1419] Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
13657| [CVE-2011-1318] Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
13658| [CVE-2011-1184] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
13659| [CVE-2011-1183] Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
13660| [CVE-2011-1176] The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
13661| [CVE-2011-1088] Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
13662| [CVE-2011-1077] Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
13663| [CVE-2011-1026] Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of administrators.
13664| [CVE-2011-0715] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
13665| [CVE-2011-0534] Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
13666| [CVE-2011-0533] Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta
13667| [CVE-2011-0419] Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
13668| [CVE-2011-0013] Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
13669| [CVE-2010-4644] Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
13670| [CVE-2010-4539] The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.
13671| [CVE-2010-4476] The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
13672| [CVE-2010-4455] Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.2 and 11.1.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Apache Plugin.
13673| [CVE-2010-4408] Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.
13674| [CVE-2010-4312] The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
13675| [CVE-2010-4172] Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
13676| [CVE-2010-3872] The fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.6 for the Apache HTTP Server does not use bytewise pointer arithmetic in certain circumstances, which has unspecified impact and attack vectors related to "untrusted FastCGI applications" and a "stack buffer overwrite."
13677| [CVE-2010-3863] Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
13678| [CVE-2010-3854] Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
13679| [CVE-2010-3718] Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
13680| [CVE-2010-3449] Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1
13681| [CVE-2010-3315] authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
13682| [CVE-2010-3083] sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.
13683| [CVE-2010-2952] Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.
13684| [CVE-2010-2791] mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
13685| [CVE-2010-2375] Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
13686| [CVE-2010-2234] Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.
13687| [CVE-2010-2227] Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
13688| [CVE-2010-2103] Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.
13689| [CVE-2010-2086] Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
13690| [CVE-2010-2076] Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
13691| [CVE-2010-2068] mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.
13692| [CVE-2010-2057] shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.
13693| [CVE-2010-1632] Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.
13694| [CVE-2010-1623] Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
13695| [CVE-2010-1587] The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
13696| [CVE-2010-1452] The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
13697| [CVE-2010-1325] Cross-site request forgery (CSRF) vulnerability in the apache2-slms package in SUSE Lifecycle Management Server (SLMS) 1.0 on SUSE Linux Enterprise (SLE) 11 allows remote attackers to hijack the authentication of unspecified victims via vectors related to improper parameter quoting. NOTE: some sources report that this is a vulnerability in a product named "Apache SLMS," but that is incorrect.
13698| [CVE-2010-1244] Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
13699| [CVE-2010-1157] Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.
13700| [CVE-2010-1151] Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.
13701| [CVE-2010-0684] Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
13702| [CVE-2010-0434] The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
13703| [CVE-2010-0432] Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewprofile (aka partymgr/control/login), (3) the start parameter to myportal/control/showPortalPage, (4) an invalid URI beginning with /facility/control/ReceiveReturn (aka /crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the contentId parameter (aka the entityName variable) to ecommerce/control/ViewBlogArticle, (6) the entityName parameter to webtools/control/FindGeneric, or the (7) subject or (8) content parameter to an unspecified component under ecommerce/control/contactus.
13704| [CVE-2010-0425] modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
13705| [CVE-2010-0408] The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
13706| [CVE-2010-0390] Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.
13707| [CVE-2010-0219] Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
13708| [CVE-2010-0010] Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
13709| [CVE-2010-0009] Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.
13710| [CVE-2009-5120] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a Project Woodstock service on this port.
13711| [CVE-2009-5119] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted session data.
13712| [CVE-2009-5006] The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.
13713| [CVE-2009-5005] The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.
13714| [CVE-2009-4355] Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
13715| [CVE-2009-4269] The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
13716| [CVE-2009-3923] The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
13717| [CVE-2009-3890] Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.
13718| [CVE-2009-3843] HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
13719| [CVE-2009-3821] Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
13720| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
13721| [CVE-2009-3548] The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
13722| [CVE-2009-3250] The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.
13723| [CVE-2009-3095] The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
13724| [CVE-2009-3094] The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
13725| [CVE-2009-2902] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
13726| [CVE-2009-2901] The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
13727| [CVE-2009-2823] The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.
13728| [CVE-2009-2699] The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
13729| [CVE-2009-2696] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.
13730| [CVE-2009-2693] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
13731| [CVE-2009-2625] XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
13732| [CVE-2009-2412] Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR
13733| [CVE-2009-2299] The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.
13734| [CVE-2009-1956] Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
13735| [CVE-2009-1955] The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
13736| [CVE-2009-1903] The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
13737| [CVE-2009-1891] The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
13738| [CVE-2009-1890] The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
13739| [CVE-2009-1885] Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.
13740| [CVE-2009-1462] The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.
13741| [CVE-2009-1275] Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
13742| [CVE-2009-1195] The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
13743| [CVE-2009-1191] mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
13744| [CVE-2009-1012] Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.
13745| [CVE-2009-0918] Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.
13746| [CVE-2009-0796] Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.
13747| [CVE-2009-0783] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
13748| [CVE-2009-0781] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
13749| [CVE-2009-0754] PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.
13750| [CVE-2009-0580] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.
13751| [CVE-2009-0486] Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
13752| [CVE-2009-0039] Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.
13753| [CVE-2009-0038] Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring
13754| [CVE-2009-0033] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.
13755| [CVE-2009-0026] Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
13756| [CVE-2009-0023] The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
13757| [CVE-2008-6879] Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
13758| [CVE-2008-6755] ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.
13759| [CVE-2008-6722] Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.
13760| [CVE-2008-6682] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
13761| [CVE-2008-6505] Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.
13762| [CVE-2008-6504] ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.
13763| [CVE-2008-5696] Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
13764| [CVE-2008-5676] Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."
13765| [CVE-2008-5519] The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.
13766| [CVE-2008-5518] Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet)
13767| [CVE-2008-5515] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.
13768| [CVE-2008-5457] Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
13769| [CVE-2008-4308] The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
13770| [CVE-2008-4008] Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.
13771| [CVE-2008-3666] Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured
13772| [CVE-2008-3271] Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
13773| [CVE-2008-3257] Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
13774| [CVE-2008-2939] Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
13775| [CVE-2008-2938] Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
13776| [CVE-2008-2742] Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.
13777| [CVE-2008-2717] TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
13778| [CVE-2008-2579] Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.
13779| [CVE-2008-2384] SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
13780| [CVE-2008-2370] Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
13781| [CVE-2008-2364] The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
13782| [CVE-2008-2168] Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
13783| [CVE-2008-2025] Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
13784| [CVE-2008-1947] Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
13785| [CVE-2008-1734] Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.
13786| [CVE-2008-1678] Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
13787| [CVE-2008-1232] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.
13788| [CVE-2008-0869] Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.
13789| [CVE-2008-0732] The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.
13790| [CVE-2008-0555] The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.
13791| [CVE-2008-0457] Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
13792| [CVE-2008-0456] CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
13793| [CVE-2008-0455] Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
13794| [CVE-2008-0128] The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
13795| [CVE-2008-0005] mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
13796| [CVE-2008-0002] Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
13797| [CVE-2007-6750] The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
13798| [CVE-2007-6726] Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
13799| [CVE-2007-6514] Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
13800| [CVE-2007-6423] ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
13801| [CVE-2007-6422] The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
13802| [CVE-2007-6421] Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
13803| [CVE-2007-6420] Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
13804| [CVE-2007-6388] Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
13805| [CVE-2007-6361] Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
13806| [CVE-2007-6342] SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.
13807| [CVE-2007-6286] Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
13808| [CVE-2007-6258] Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.
13809| [CVE-2007-6231] Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_includepath parameter to (1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php, or (5) libchart-1.1/libchart.php in include/. NOTE: access to include/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
13810| [CVE-2007-6203] Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
13811| [CVE-2007-5797] SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
13812| [CVE-2007-5731] Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.
13813| [CVE-2007-5461] Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
13814| [CVE-2007-5342] The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
13815| [CVE-2007-5333] Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
13816| [CVE-2007-5156] Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
13817| [CVE-2007-5085] Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
13818| [CVE-2007-5000] Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
13819| [CVE-2007-4724] Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.
13820| [CVE-2007-4723] Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
13821| [CVE-2007-4641] Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.
13822| [CVE-2007-4556] Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.
13823| [CVE-2007-4548] The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
13824| [CVE-2007-4465] Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
13825| [CVE-2007-3847] The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
13826| [CVE-2007-3571] The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.
13827| [CVE-2007-3386] Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
13828| [CVE-2007-3385] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
13829| [CVE-2007-3384] Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.
13830| [CVE-2007-3383] Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.
13831| [CVE-2007-3382] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
13832| [CVE-2007-3304] Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
13833| [CVE-2007-3303] Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
13834| [CVE-2007-3101] Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.
13835| [CVE-2007-2450] Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.
13836| [CVE-2007-2449] Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the '
13837| [CVE-2007-2353] Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
13838| [CVE-2007-2025] Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.
13839| [CVE-2007-1863] cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
13840| [CVE-2007-1862] The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
13841| [CVE-2007-1860] mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.
13842| [CVE-2007-1858] The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
13843| [CVE-2007-1842] Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.
13844| [CVE-2007-1801] Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.
13845| [CVE-2007-1743] suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
13846| [CVE-2007-1742] suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
13847| [CVE-2007-1741] Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
13848| [CVE-2007-1720] Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.
13849| [CVE-2007-1636] Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.
13850| [CVE-2007-1633] Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.
13851| [CVE-2007-1577] Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
13852| [CVE-2007-1539] Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.
13853| [CVE-2007-1524] Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.
13854| [CVE-2007-1491] Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.
13855| [CVE-2007-1358] Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
13856| [CVE-2007-1349] PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
13857| [CVE-2007-0975] Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.
13858| [CVE-2007-0930] Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.
13859| [CVE-2007-0792] The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
13860| [CVE-2007-0774] Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
13861| [CVE-2007-0637] Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.
13862| [CVE-2007-0451] Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
13863| [CVE-2007-0450] Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
13864| [CVE-2007-0419] The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).
13865| [CVE-2007-0173] Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
13866| [CVE-2007-0098] Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
13867| [CVE-2007-0086] ** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.
13868| [CVE-2006-7217] Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.
13869| [CVE-2006-7216] Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.
13870| [CVE-2006-7197] The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.
13871| [CVE-2006-7196] Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
13872| [CVE-2006-7195] Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
13873| [CVE-2006-7098] The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
13874| [CVE-2006-6869] Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
13875| [CVE-2006-6675] Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecifeid parameters in Welcome web-app.
13876| [CVE-2006-6613] Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive information via a .. (dot dot) in the pa_lang[include_file] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
13877| [CVE-2006-6589] Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.
13878| [CVE-2006-6588] The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
13879| [CVE-2006-6587] Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.
13880| [CVE-2006-6445] Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
13881| [CVE-2006-6071] TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.
13882| [CVE-2006-6047] Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
13883| [CVE-2006-5894] Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
13884| [CVE-2006-5752] Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
13885| [CVE-2006-5733] Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
13886| [CVE-2006-5263] Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apache HTTP Server log file that apparently contains PHP code.
13887| [CVE-2006-4994] Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted "Program Files" pathname.
13888| [CVE-2006-4636] Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.
13889| [CVE-2006-4625] PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
13890| [CVE-2006-4558] DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
13891| [CVE-2006-4191] Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
13892| [CVE-2006-4154] Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
13893| [CVE-2006-4110] Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
13894| [CVE-2006-4004] Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
13895| [CVE-2006-3918] http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
13896| [CVE-2006-3835] Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (
13897| [CVE-2006-3747] Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
13898| [CVE-2006-3362] Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
13899| [CVE-2006-3102] Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of time under the webroot in the temp/articles directory.
13900| [CVE-2006-3070] write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.
13901| [CVE-2006-2831] Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
13902| [CVE-2006-2806] The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.
13903| [CVE-2006-2743] Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
13904| [CVE-2006-2514] Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
13905| [CVE-2006-2330] PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
13906| [CVE-2006-1777] Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache error_log file, which is then included by doc/index.php.
13907| [CVE-2006-1564] Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.
13908| [CVE-2006-1548] Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
13909| [CVE-2006-1547] ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
13910| [CVE-2006-1546] Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
13911| [CVE-2006-1393] Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
13912| [CVE-2006-1346] Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.
13913| [CVE-2006-1292] Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
13914| [CVE-2006-1243] Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
13915| [CVE-2006-1095] Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
13916| [CVE-2006-1079] htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
13917| [CVE-2006-1078] Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
13918| [CVE-2006-0743] Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
13919| [CVE-2006-0254] Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.
13920| [CVE-2006-0150] Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
13921| [CVE-2006-0144] The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.
13922| [CVE-2006-0042] Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.
13923| [CVE-2005-4857] eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a "memory addressing error".
13924| [CVE-2005-4849] Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information.
13925| [CVE-2005-4836] The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
13926| [CVE-2005-4814] Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.
13927| [CVE-2005-4703] Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
13928| [CVE-2005-3745] Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
13929| [CVE-2005-3630] Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.
13930| [CVE-2005-3510] Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
13931| [CVE-2005-3392] Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.
13932| [CVE-2005-3357] mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
13933| [CVE-2005-3352] Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
13934| [CVE-2005-3319] The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.
13935| [CVE-2005-3164] The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
13936| [CVE-2005-2970] Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
13937| [CVE-2005-2963] The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.
13938| [CVE-2005-2728] The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
13939| [CVE-2005-2660] apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.
13940| [CVE-2005-2088] The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
13941| [CVE-2005-1754] ** DISPUTED ** JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
13942| [CVE-2005-1753] ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
13943| [CVE-2005-1344] Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
13944| [CVE-2005-1268] Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
13945| [CVE-2005-1266] Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
13946| [CVE-2005-0808] Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
13947| [CVE-2005-0182] The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.
13948| [CVE-2005-0108] Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.
13949| [CVE-2004-2734] webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
13950| [CVE-2004-2680] mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
13951| [CVE-2004-2650] Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
13952| [CVE-2004-2343] ** DISPUTED ** Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument.
13953| [CVE-2004-2336] Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.
13954| [CVE-2004-2115] Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.
13955| [CVE-2004-1834] mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
13956| [CVE-2004-1765] Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.
13957| [CVE-2004-1545] UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
13958| [CVE-2004-1438] The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
13959| [CVE-2004-1405] MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
13960| [CVE-2004-1404] Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
13961| [CVE-2004-1387] The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
13962| [CVE-2004-1084] Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
13963| [CVE-2004-1083] Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
13964| [CVE-2004-1082] mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
13965| [CVE-2004-0942] Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
13966| [CVE-2004-0940] Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
13967| [CVE-2004-0885] The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
13968| [CVE-2004-0811] Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
13969| [CVE-2004-0809] The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
13970| [CVE-2004-0786] The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
13971| [CVE-2004-0751] The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
13972| [CVE-2004-0748] mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
13973| [CVE-2004-0747] Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
13974| [CVE-2004-0700] Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
13975| [CVE-2004-0646] Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
13976| [CVE-2004-0529] The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.
13977| [CVE-2004-0493] The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
13978| [CVE-2004-0492] Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
13979| [CVE-2004-0490] cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.
13980| [CVE-2004-0488] Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
13981| [CVE-2004-0263] PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
13982| [CVE-2004-0174] Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
13983| [CVE-2004-0173] Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
13984| [CVE-2004-0113] Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
13985| [CVE-2004-0009] Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.
13986| [CVE-2003-1581] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
13987| [CVE-2003-1580] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
13988| [CVE-2003-1573] The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."
13989| [CVE-2003-1521] Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
13990| [CVE-2003-1516] The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
13991| [CVE-2003-1502] mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.
13992| [CVE-2003-1418] Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child proccess IDs (PID).
13993| [CVE-2003-1307] ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."
13994| [CVE-2003-1172] Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
13995| [CVE-2003-1171] Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.
13996| [CVE-2003-1138] The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
13997| [CVE-2003-1054] mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.
13998| [CVE-2003-0993] mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
13999| [CVE-2003-0987] mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
14000| [CVE-2003-0866] The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
14001| [CVE-2003-0844] mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.
14002| [CVE-2003-0843] Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.
14003| [CVE-2003-0789] mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
14004| [CVE-2003-0771] Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.
14005| [CVE-2003-0658] Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
14006| [CVE-2003-0542] Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
14007| [CVE-2003-0460] The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
14008| [CVE-2003-0254] Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
14009| [CVE-2003-0253] The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
14010| [CVE-2003-0249] ** DISPUTED ** PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."
14011| [CVE-2003-0245] Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
14012| [CVE-2003-0192] Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
14013| [CVE-2003-0189] The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
14014| [CVE-2003-0134] Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.
14015| [CVE-2003-0132] A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.
14016| [CVE-2003-0083] Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
14017| [CVE-2003-0020] Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
14018| [CVE-2003-0017] Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.
14019| [CVE-2003-0016] Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
14020| [CVE-2002-2310] ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
14021| [CVE-2002-2309] php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
14022| [CVE-2002-2272] Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
14023| [CVE-2002-2103] Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
14024| [CVE-2002-2029] PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
14025| [CVE-2002-2012] Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
14026| [CVE-2002-2009] Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
14027| [CVE-2002-2008] Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.
14028| [CVE-2002-2007] The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
14029| [CVE-2002-2006] The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
14030| [CVE-2002-1895] The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
14031| [CVE-2002-1850] mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
14032| [CVE-2002-1793] HTTP Server mod_ssl module running on HP-UX 11.04 with Virtualvault OS (VVOS) 4.5 through 4.6 closes the connection when the Apache server times out during an SSL request, which may allow attackers to cause a denial of service.
14033| [CVE-2002-1658] Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
14034| [CVE-2002-1635] The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin.
14035| [CVE-2002-1593] mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.
14036| [CVE-2002-1592] The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.
14037| [CVE-2002-1567] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
14038| [CVE-2002-1394] Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
14039| [CVE-2002-1233] A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
14040| [CVE-2002-1157] Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
14041| [CVE-2002-1156] Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
14042| [CVE-2002-1148] The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
14043| [CVE-2002-0935] Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
14044| [CVE-2002-0843] Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
14045| [CVE-2002-0840] Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
14046| [CVE-2002-0839] The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
14047| [CVE-2002-0682] Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
14048| [CVE-2002-0661] Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
14049| [CVE-2002-0658] OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.
14050| [CVE-2002-0654] Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
14051| [CVE-2002-0653] Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
14052| [CVE-2002-0513] The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.
14053| [CVE-2002-0493] Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
14054| [CVE-2002-0392] Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
14055| [CVE-2002-0259] InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.
14056| [CVE-2002-0249] PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
14057| [CVE-2002-0240] PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
14058| [CVE-2002-0082] The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
14059| [CVE-2002-0061] Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
14060| [CVE-2001-1556] The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
14061| [CVE-2001-1534] mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
14062| [CVE-2001-1510] Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.
14063| [CVE-2001-1449] The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
14064| [CVE-2001-1385] The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
14065| [CVE-2001-1342] Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
14066| [CVE-2001-1217] Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
14067| [CVE-2001-1216] Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
14068| [CVE-2001-1072] Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
14069| [CVE-2001-1013] Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
14070| [CVE-2001-0925] The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
14071| [CVE-2001-0829] A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
14072| [CVE-2001-0766] Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
14073| [CVE-2001-0731] Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
14074| [CVE-2001-0730] split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
14075| [CVE-2001-0729] Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
14076| [CVE-2001-0590] Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
14077| [CVE-2001-0131] htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
14078| [CVE-2001-0108] PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
14079| [CVE-2001-0042] PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
14080| [CVE-2000-1247] The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
14081| [CVE-2000-1210] Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
14082| [CVE-2000-1206] Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
14083| [CVE-2000-1205] Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.
14084| [CVE-2000-1204] Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
14085| [CVE-2000-1168] IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
14086| [CVE-2000-1016] The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
14087| [CVE-2000-0913] mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
14088| [CVE-2000-0883] The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.
14089| [CVE-2000-0869] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method.
14090| [CVE-2000-0868] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
14091| [CVE-2000-0791] Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.
14092| [CVE-2000-0760] The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
14093| [CVE-2000-0759] Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
14094| [CVE-2000-0628] The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.
14095| [CVE-2000-0505] The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
14096| [CVE-1999-1412] A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
14097| [CVE-1999-1293] mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
14098| [CVE-1999-1237] Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
14099| [CVE-1999-1199] Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
14100| [CVE-1999-1053] guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
14101| [CVE-1999-0926] Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
14102| [CVE-1999-0678] A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
14103| [CVE-1999-0448] IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
14104| [CVE-1999-0289] The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
14105| [CVE-1999-0236] ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
14106| [CVE-1999-0107] Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
14107| [CVE-1999-0071] Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
14108|
14109| SecurityFocus - https://www.securityfocus.com/bid/:
14110| [104554] Apache HBase CVE-2018-8025 Security Bypass Vulnerability
14111| [104465] Apache Geode CVE-2017-15695 Remote Code Execution Vulnerability
14112| [104418] Apache Storm CVE-2018-8008 Arbitrary File Write Vulnerability
14113| [104399] Apache Storm CVE-2018-1332 User Impersonation Vulnerability
14114| [104348] Apache UIMA CVE-2017-15691 XML External Entity Injection Vulnerability
14115| [104313] Apache NiFi XML External Entity Injection and Denial of Service Vulnerability
14116| [104259] Apache Geode CVE-2017-12622 Authorization Bypass Vulnerability
14117| [104257] Apache Sling XSS Protection API CVE-2017-15717 Cross Site Scripting Vulnerability
14118| [104253] Apache ZooKeeper CVE-2018-8012 Security Bypass Vulnerability
14119| [104252] Apache Batik CVE-2018-8013 Information Disclosure Vulnerability
14120| [104239] Apache Solr CVE-2018-8010 XML External Entity Multiple Information Disclosure Vulnerabilities
14121| [104215] Apache ORC CVE-2018-8015 Denial of Service Vulnerability
14122| [104203] Apache Tomcat CVE-2018-8014 Security Bypass Vulnerability
14123| [104161] Apache Ambari CVE-2018-8003 Directory Traversal Vulnerability
14124| [104140] Apache Derby CVE-2018-1313 Security Bypass Vulnerability
14125| [104135] Apache Tika CVE-2018-1338 Denial of Service Vulnerability
14126| [104008] Apache Fineract CVE-2018-1291 SQL Injection Vulnerability
14127| [104007] Apache Fineract CVE-2018-1292 SQL Injection Vulnerability
14128| [104005] Apache Fineract CVE-2018-1289 SQL Injection Vulnerability
14129| [104001] Apache Tika CVE-2018-1335 Remote Command Injection Vulnerability
14130| [103975] Apache Fineract CVE-2018-1290 SQL Injection Vulnerability
14131| [103974] Apache Solr CVE-2018-1308 XML External Entity Injection Vulnerability
14132| [103772] Apache Traffic Server CVE-2017-7671 Denial of Service Vulnerability
14133| [103770] Apache Traffic Server CVE-2017-5660 Security Bypass Vulnerability
14134| [103751] Apache Hive CVE-2018-1282 SQL Injection Vulnerability
14135| [103750] Apache Hive CVE-2018-1284 Security Bypass Vulnerability
14136| [103692] Apache Ignite CVE-2018-1295 Arbitrary Code Execution Vulnerability
14137| [103528] Apache HTTP Server CVE-2018-1302 Denial of Service Vulnerability
14138| [103525] Apache HTTP Server CVE-2017-15715 Remote Security Bypass Vulnerability
14139| [103524] Apache HTTP Server CVE-2018-1312 Remote Security Bypass Vulnerability
14140| [103522] Apache HTTP Server CVE-2018-1303 Denial of Service Vulnerability
14141| [103520] Apache HTTP Server CVE-2018-1283 Remote Security Vulnerability
14142| [103516] Apache Struts CVE-2018-1327 Denial of Service Vulnerability
14143| [103515] Apache HTTP Server CVE-2018-1301 Denial of Service Vulnerability
14144| [103512] Apache HTTP Server CVE-2017-15710 Denial of Service Vulnerability
14145| [103508] Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
14146| [103507] Apache Syncope CVE-2018-1322 Multiple Information Disclosure Vulnerabilities
14147| [103490] Apache Commons Compress CVE-2018-1324 Multiple Denial Of Service Vulnerabilities
14148| [103434] APACHE Allura CVE-2018-1319 HTTP Response Splitting Vulnerability
14149| [103389] Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
14150| [103222] Apache CloudStack CVE-2013-4317 Information Disclosure Vulnerability
14151| [103219] Apache Xerces-C CVE-2017-12627 Null Pointer Dereference Denial of Service Vulnerability
14152| [103206] Apache Geode CVE-2017-15693 Remote Code Execution Vulnerability
14153| [103205] Apache Geode CVE-2017-15692 Remote Code Execution Vulnerability
14154| [103170] Apache Tomcat CVE-2018-1304 Security Bypass Vulnerability
14155| [103144] Apache Tomcat CVE-2018-1305 Security Bypass Vulnerability
14156| [103102] Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
14157| [103098] Apache Karaf CVE-2016-8750 LDAP Injection Vulnerability
14158| [103069] Apache Tomcat CVE-2017-15706 Remote Security Weakness
14159| [103068] Apache JMeter CVE-2018-1287 Security Bypass Vulnerability
14160| [103067] Apache Qpid Dispatch Router 'router_core/connections.c' Denial of Service Vulnerability
14161| [103036] Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
14162| [103025] Apache Thrift CVE-2016-5397 Remote Command Injection Vulnerability
14163| [102879] Apache POI CVE-2017-12626 Multiple Denial of Service Vulnerabilities
14164| [102842] Apache NiFi CVE-2017-12632 Host Header Injection Vulnerability
14165| [102815] Apache NiFi CVE-2017-15697 Multiple Cross Site Scripting Vulnerabilities
14166| [102488] Apache Geode CVE-2017-9795 Remote Code Execution Vulnerability
14167| [102229] Apache Sling CVE-2017-15700 Information Disclosure Vulnerability
14168| [102226] Apache Drill CVE-2017-12630 Cross Site Scripting Vulnerability
14169| [102154] Multiple Apache Products CVE-2017-15708 Remote Code Execution Vulnerability
14170| [102127] Apache CXF Fediz CVE-2017-12631 Multiple Cross Site Request Forgery Vulnerabilities
14171| [102041] Apache Qpid Broker-J CVE-2017-15701 Denial of Service Vulnerability
14172| [102040] Apache Qpid Broker CVE-2017-15702 Security Weakness
14173| [102021] Apache Struts CVE-2017-15707 Denial of Service Vulnerability
14174| [101980] EMC RSA Authentication Agent for Web: Apache Web Server Authentication Bypass Vulnerability
14175| [101876] Apache Camel CVE-2017-12634 Deserialization Remote Code Execution Vulnerability
14176| [101874] Apache Camel CVE-2017-12633 Deserialization Remote Code Execution Vulnerability
14177| [101872] Apache Karaf CVE-2014-0219 Local Denial of Service Vulnerability
14178| [101868] Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
14179| [101859] Apache CXF CVE-2017-12624 Denial of Service Vulnerability
14180| [101844] Apache Sling Servlets Post CVE-2017-11296 Cross Site Scripting Vulnerability
14181| [101686] Apache Hive CVE-2017-12625 Information Disclosure Vulnerability
14182| [101644] Apache Wicket CVE-2012-5636 Cross Site Scripting Vulnerability
14183| [101631] Apache Traffic Server CVE-2015-3249 Multiple Remote Code Execution Vulnerabilities
14184| [101630] Apache Traffic Server CVE-2014-3624 Access Bypass Vulnerability
14185| [101625] Apache jUDDI CVE-2009-1197 Security Bypass Vulnerability
14186| [101623] Apache jUDDI CVE-2009-1198 Cross Site Scripting Vulnerability
14187| [101620] Apache Subversion 'libsvn_fs_fs/fs_fs.c' Denial of Service Vulnerability
14188| [101585] Apache OpenOffice Multiple Remote Code Execution Vulnerabilities
14189| [101577] Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
14190| [101575] Apache Wicket CVE-2014-0043 Information Disclosure Vulnerability
14191| [101570] Apache Geode CVE-2017-9797 Information Disclosure Vulnerability
14192| [101562] Apache Derby CVE-2010-2232 Arbitrary File Overwrite Vulnerability
14193| [101560] Apache Portable Runtime Utility CVE-2017-12613 Multiple Information Disclosure Vulnerabilities
14194| [101558] Apache Portable Runtime Utility Local Out-of-Bounds Read Denial of Service Vulnerability
14195| [101532] Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
14196| [101516] Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
14197| [101261] Apache Solr/Lucene CVE-2017-12629 Information Disclosure and Remote Code Execution Vulnerabilities
14198| [101230] Apache Roller CVE-2014-0030 XML External Entity Injection Vulnerability
14199| [101173] Apache IMPALA CVE-2017-9792 Information Disclosure Vulnerability
14200| [101052] Apache Commons Jelly CVE-2017-12621 Security Bypass Vulnerability
14201| [101027] Apache Mesos CVE-2017-7687 Denial of Service Vulnerability
14202| [101023] Apache Mesos CVE-2017-9790 Denial of Service Vulnerability
14203| [100954] Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
14204| [100946] Apache Wicket CVE-2014-7808 Cross Site Request Forgery Vulnerability
14205| [100901] Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability
14206| [100897] Apache Tomcat CVE-2017-12616 Information Disclosure Vulnerability
14207| [100880] Apache Directory LDAP API CVE-2015-3250 Unspecified Information Disclosure Vulnerability
14208| [100872] Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
14209| [100870] Apache Solr CVE-2017-9803 Remote Privilege Escalation Vulnerability
14210| [100859] puppetlabs-apache CVE-2017-2299 Information Disclosure Vulnerability
14211| [100829] Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
14212| [100823] Apache Spark CVE-2017-12612 Deserialization Remote Code Execution Vulnerability
14213| [100612] Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
14214| [100611] Apache Struts CVE-2017-9793 Denial of Service Vulnerability
14215| [100609] Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
14216| [100587] Apache Atlas CVE-2017-3155 Cross Frame Scripting Vulnerability
14217| [100581] Apache Atlas CVE-2017-3154 Information Disclosure Vulnerability
14218| [100578] Apache Atlas CVE-2017-3153 Cross Site Scripting Vulnerability
14219| [100577] Apache Atlas CVE-2017-3152 Cross Site Scripting Vulnerability
14220| [100547] Apache Atlas CVE-2017-3151 HTML Injection Vulnerability
14221| [100536] Apache Atlas CVE-2017-3150 Cross Site Scripting Vulnerability
14222| [100449] Apache Pony Mail CVE-2016-4460 Authentication Bypass Vulnerability
14223| [100447] Apache2Triad Multiple Security Vulnerabilities
14224| [100284] Apache Sling Servlets Post CVE-2017-9802 Cross Site Scripting Vulnerability
14225| [100280] Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
14226| [100259] Apache Subversion CVE-2017-9800 Remote Command Execution Vulnerability
14227| [100256] Apache Tomcat CVE-2017-7675 Directory Traversal Vulnerability
14228| [100235] Apache Storm CVE-2017-9799 Remote Code Execution Vulnerability
14229| [100082] Apache Commons Email CVE-2017-9801 SMTP Header Injection Vulnerability
14230| [99873] Apache Sling XSS Protection API CVE-2016-6798 XML External Entity Injection Vulnerability
14231| [99870] Apache Sling API CVE-2016-5394 Cross Site Scripting Vulnerability
14232| [99603] Apache Spark CVE-2017-7678 Cross Site Scripting Vulnerability
14233| [99592] Apache OpenMeetings CVE-2017-7685 Security Bypass Vulnerability
14234| [99587] Apache OpenMeetings CVE-2017-7673 Security Bypass Vulnerability
14235| [99586] Apache OpenMeetings CVE-2017-7688 Security Bypass Vulnerability
14236| [99584] Apache OpenMeetings CVE-2017-7684 Denial of Service Vulnerability
14237| [99577] Apache OpenMeetings CVE-2017-7663 Cross Site Scripting Vulnerability
14238| [99576] Apache OpenMeetings CVE-2017-7664 XML External Entity Injection Vulnerability
14239| [99569] Apache HTTP Server CVE-2017-9788 Memory Corruption Vulnerability
14240| [99568] Apache HTTP Server CVE-2017-9789 Denial of Service Vulnerability
14241| [99563] Apache Struts CVE-2017-7672 Denial of Service Vulnerability
14242| [99562] Apache Struts Spring AOP Functionality Denial of Service Vulnerability
14243| [99509] Apache Impala CVE-2017-5652 Information Disclosure Vulnerability
14244| [99508] Apache IMPALA CVE-2017-5640 Authentication Bypass Vulnerability
14245| [99486] Apache Traffic Control CVE-2017-7670 Denial of Service Vulnerability
14246| [99485] Apache Solr CVE-2017-7660 Security Bypass Vulnerability
14247| [99484] Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
14248| [99292] Apache Ignite CVE-2017-7686 Information Disclosure Vulnerability
14249| [99170] Apache HTTP Server CVE-2017-7679 Buffer Overflow Vulnerability
14250| [99137] Apache HTTP Server CVE-2017-7668 Denial of Service Vulnerability
14251| [99135] Apache HTTP Server CVE-2017-3167 Authentication Bypass Vulnerability
14252| [99134] Apache HTTP Server CVE-2017-3169 Denial of Service Vulnerability
14253| [99132] Apache HTTP Server CVE-2017-7659 Denial of Service Vulnerability
14254| [99112] Apache Thrift CVE-2015-3254 Denial of Service Vulnerability
14255| [99067] Apache Ranger CVE-2016-8751 HTML Injection Vulnerability
14256| [99018] Apache NiFi CVE-2017-7667 Cross Frame Scripting Vulnerability
14257| [99009] Apache NiFi CVE-2017-7665 Cross Site Scripting Vulnerability
14258| [98961] Apache Ranger CVE-2017-7677 Security Bypass Vulnerability
14259| [98958] Apache Ranger CVE-2017-7676 Security Bypass Vulnerability
14260| [98888] Apache Tomcat CVE-2017-5664 Security Bypass Vulnerability
14261| [98814] Apache Zookeeper CVE-2017-5637 Denial of Service Vulnerability
14262| [98795] Apache Hadoop CVE-2017-7669 Remote Privilege Escalation Vulnerability
14263| [98739] Apache Knox CVE-2017-5646 User Impersonation Vulnerability
14264| [98669] Apache Hive CVE-2016-3083 Security Bypass Vulnerability
14265| [98646] Apache Atlas CVE-2016-8752 Information Disclosure Vulnerability
14266| [98570] Apache Archiva CVE-2017-5657 Multiple Cross-Site Request Forgery Vulnerabilities
14267| [98489] Apache CXF Fediz CVE-2017-7661 Multiple Cross Site Request Forgery Vulnerabilities
14268| [98485] Apache CXF Fediz CVE-2017-7662 Cross Site Request Forgery Vulnerability
14269| [98466] Apache Ambari CVE-2017-5655 Insecure Temporary File Handling Vulnerability
14270| [98365] Apache Cordova For Android CVE-2016-6799 Information Disclosure Vulnerability
14271| [98025] Apache Hadoop CVE-2017-3161 Cross Site Scripting Vulnerability
14272| [98017] Apache Hadoop CVE-2017-3162 Input Validation Vulnerability
14273| [97971] Apache CXF CVE-2017-5656 Information Disclosure Vulnerability
14274| [97968] Apache CXF CVE-2017-5653 Spoofing Vulnerability
14275| [97967] Apache ActiveMQ CVE-2015-7559 Denial of Service Vulnerability
14276| [97949] Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
14277| [97948] Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
14278| [97947] Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
14279| [97945] Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
14280| [97702] Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
14281| [97582] Apache CXF CVE-2016-6812 Cross Site Scripting Vulnerability
14282| [97579] Apache CXF JAX-RS CVE-2016-8739 XML External Entity Injection Vulnerability
14283| [97544] Apache Tomcat CVE-2017-5651 Information Disclosure Vulnerability
14284| [97531] Apache Tomcat CVE-2017-5650 Denial of Service Vulnerability
14285| [97530] Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
14286| [97509] Apache Ignite CVE-2016-6805 Information Disclosure and XML External Entity Injection Vulnerabilities
14287| [97383] Apache Flex BlazeDS CVE-2017-5641 Remote Code Execution Vulnerability
14288| [97378] Apache Geode CVE-2017-5649 Information Disclosure Vulnerability
14289| [97229] Apache Ambari CVE-2016-4976 Local Information Disclosure Vulnerability
14290| [97226] Apache Camel CVE-2017-5643 Server Side Request Forgery Security Bypass Vulnerability
14291| [97184] Apache Ambari CVE-2016-6807 Remote Command Execution Vulnerability
14292| [97179] Apache Camel CVE-2016-8749 Java Deserialization Multiple Remote Code Execution Vulnerabilities
14293| [96983] Apache POI CVE-2017-5644 Denial Of Service Vulnerability
14294| [96895] Apache Tomcat CVE-2016-8747 Information Disclosure Vulnerability
14295| [96731] Apache NiFi CVE-2017-5636 Remote Code Injection Vulnerability
14296| [96730] Apache NiFi CVE-2017-5635 Security Bypass Vulnerability
14297| [96729] Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
14298| [96540] IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
14299| [96398] Apache CXF CVE-2017-3156 Information Disclosure Vulnerability
14300| [96321] Apache Camel CVE-2017-3159 Remote Code Execution Vulnerability
14301| [96293] Apache Tomcat 'http11/AbstractInputBuffer.java' Denial of Service Vulnerability
14302| [96228] Apache Brooklyn Cross Site Request Forgery and Multiple Cross Site Scripting Vulnerabilities
14303| [95998] Apache Ranger CVE-2016-8746 Security Bypass Vulnerability
14304| [95929] Apache Groovy CVE-2016-6497 Information Disclosure Vulnerability
14305| [95838] Apache Cordova For Android CVE-2017-3160 Man in the Middle Security Bypass Vulnerability
14306| [95675] Apache Struts Remote Code Execution Vulnerability
14307| [95621] Apache NiFi CVE-2106-8748 Cross Site Scripting Vulnerability
14308| [95429] Apache Groovy CVE-2016-6814 Remote Code Execution Vulnerability
14309| [95335] Apache Hadoop CVE-2016-3086 Information Disclosure Vulnerability
14310| [95168] Apache Wicket CVE-2016-6793 Denial of Service Vulnerability
14311| [95136] Apache Qpid Broker for Java CVE-2016-8741 Remote Information Disclosure Vulnerability
14312| [95078] Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
14313| [95077] Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
14314| [95076] Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
14315| [95020] Apache Tika CVE-2015-3271 Remote Information Disclosure Vulnerability
14316| [94950] Apache Hadoop CVE-2016-5001 Local Information Disclosure Vulnerability
14317| [94882] Apache ActiveMQ CVE-2016-6810 HTML Injection Vulnerability
14318| [94828] Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
14319| [94766] Apache CouchDB CVE-2016-8742 Local Privilege Escalation Vulnerability
14320| [94657] Apache Struts CVE-2016-8738 Denial of Service Vulnerability
14321| [94650] Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
14322| [94588] Apache Subversion CVE-2016-8734 XML External Entity Denial of Service Vulnerability
14323| [94513] Apache Karaf CVE-2016-8648 Remote Code Execution Vulnerability
14324| [94463] Apache Tomcat CVE-2016-8735 Remote Code Execution Vulnerability
14325| [94462] Apache Tomcat CVE-2016-6817 Denial of Service Vulnerability
14326| [94461] Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
14327| [94418] Apache OpenOffice CVE-2016-6803 Local Privilege Escalation Vulnerability
14328| [94247] Apache Tika CVE-2016-6809 Remote Code Execution Vulnerability
14329| [94221] Apache Ranger CVE-2016-6815 Local Privilege Escalation Vulnerability
14330| [94145] Apache OpenMeetings CVE-2016-8736 Remote Code Execution Vulnerability
14331| [93945] Apache CloudStack CVE-2016-6813 Authorization Bypass Vulnerability
14332| [93944] Apache Tomcat Security Manager CVE-2016-6796 Security Bypass Vulnerability
14333| [93943] Apache Tomcat CVE-2016-6794 Security Bypass Vulnerability
14334| [93942] Apache Tomcat Security Manager CVE-2016-5018 Security Bypass Vulnerability
14335| [93940] Apache Tomcat CVE-2016-6797 Security Bypass Vulnerability
14336| [93939] Apache Tomcat CVE-2016-0762 Information Disclosure Vulnerability
14337| [93774] Apache OpenOffice CVE-2016-6804 DLL Loading Remote Code Execution Vulnerability
14338| [93773] Apache Struts CVE-2016-6795 Directory Traversal Vulnerability
14339| [93478] Apache Tomcat CVE-2016-6325 Local Privilege Escalation Vulnerability
14340| [93472] Apache Tomcat CVE-2016-5425 Insecure File Permissions Vulnerability
14341| [93429] Apache Tomcat JK Connector CVE-2016-6808 Remote Buffer Overflow Vulnerability
14342| [93263] Apache Tomcat CVE-2016-1240 Local Privilege Escalation Vulnerability
14343| [93236] Apache MyFaces Trinidad CVE-2016-5019 Remote Code Execution Vulnerability
14344| [93142] Apache ActiveMQ Artemis CVE-2016-4978 Remote Code Execution Vulnerability
14345| [93132] Apache Derby CVE-2015-1832 XML External Entity Information Disclosure Vulnerability
14346| [93044] Apache Zookeeper CVE-2016-5017 Buffer Overflow Vulnerability
14347| [92966] Apache Jackrabbit CVE-2016-6801 Cross-Site Request Forgery Vulnerability
14348| [92947] Apache Shiro CVE-2016-6802 Remote Security Bypass Vulnerability
14349| [92905] Apache CXF Fediz CVE-2016-4464 Security Bypass Vulnerability
14350| [92577] Apache Ranger CVE-2016-5395 HTML Injection Vulnerability
14351| [92331] Apache HTTP Server CVE-2016-1546 Remote Denial of Service Vulnerability
14352| [92328] Apache Hive CVE-2016-0760 Multiple Remote Code Execution Vulnerabilities
14353| [92320] Apache APR-util and httpd CVE-2016-6312 Denial of Service Vulnerability
14354| [92100] Apache POI CVE-2016-5000 XML External Entity Injection Vulnerability
14355| [92079] Apache OpenOffice CVE-2016-1513 Remote Code Execution Vulnerability
14356| [91818] Apache Tomcat CVE-2016-5388 Security Bypass Vulnerability
14357| [91816] Apache HTTP Server CVE-2016-5387 Security Bypass Vulnerability
14358| [91788] Apache Qpid Proton CVE-2016-4467 Certificate Verification Security Bypass Vulnerability
14359| [91738] Apache XML-RPC CVE-2016-5003 Remote Code Execution Vulnerability
14360| [91736] Apache XML-RPC Multiple Security Vulnerabilities
14361| [91707] Apache Archiva CVE-2016-5005 HTML Injection Vulnerability
14362| [91703] Apache Archiva CVE-2016-4469 Multiple Cross-Site Request Forgery Vulnerabilities
14363| [91566] Apache HTTP Server CVE-2016-4979 Authentication Bypass Vulnerability
14364| [91537] Apache QPID CVE-2016-4974 Deserialization Security Bypass Vulnerability
14365| [91501] Apache Xerces-C CVE-2016-4463 Stack Buffer Overflow Vulnerability
14366| [91453] Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
14367| [91284] Apache Struts CVE-2016-4431 Security Bypass Vulnerability
14368| [91282] Apache Struts CVE-2016-4433 Security Bypass Vulnerability
14369| [91281] Apache Struts CVE-2016-4430 Cross-Site Request Forgery Vulnerability
14370| [91280] Apache Struts CVE-2016-4436 Security Bypass Vulnerability
14371| [91278] Apache Struts CVE-2016-4465 Denial of Service Vulnerability
14372| [91277] Apache Struts Incomplete Fix Remote Code Execution Vulnerability
14373| [91275] Apache Struts CVE-2016-4438 Remote Code Execution Vulnerability
14374| [91217] Apache Continuum 'saveInstallation.action' Command Execution Vulnerability
14375| [91141] Apache CloudStack CVE-2016-3085 Authentication Bypass Vulnerability
14376| [91068] Apache Struts CVE-2016-1181 Remote Code Execution Vulnerability
14377| [91067] Apache Struts CVE-2016-1182 Security Bypass Vulnerability
14378| [91024] Apache Shiro CVE-2016-4437 Information Disclosure Vulnerability
14379| [90988] Apache Ranger CVE-2016-2174 SQL Injection Vulnerability
14380| [90961] Apache Struts CVE-2016-3093 Denial of Service Vulnerability
14381| [90960] Apache Struts CVE-2016-3087 Remote Code Execution Vulnerability
14382| [90921] Apache Qpid CVE-2016-4432 Authentication Bypass Vulnerability
14383| [90920] Apache Qpid CVE-2016-3094 Denial of Service Vulnerability
14384| [90902] Apache PDFBox CVE-2016-2175 XML External Entity Injection Vulnerability
14385| [90897] Apache Tika CVE-2016-4434 XML External Entity Injection Vulnerability
14386| [90827] Apache ActiveMQ CVE-2016-3088 Multiple Arbitrary File Upload Vulnerabilities
14387| [90755] Apache Ambari CVE-2016-0707 Multiple Local Information Disclosure Vulnerabilities
14388| [90482] Apache CVE-2004-1387 Local Security Vulnerability
14389| [89762] Apache CVE-2001-1556 Remote Security Vulnerability
14390| [89417] Apache Subversion CVE-2016-2167 Authentication Bypass Vulnerability
14391| [89326] RETIRED: Apache Subversion CVE-2016-2167 Security Bypass Vulnerability
14392| [89320] Apache Subversion CVE-2016-2168 Remote Denial of Service Vulnerability
14393| [88826] Apache Struts CVE-2016-3082 Remote Code Execution Vulnerability
14394| [88797] Apache Cordova For iOS CVE-2015-5208 Arbitrary Code Execution Vulnerability
14395| [88764] Apache Cordova iOS CVE-2015-5207 Multiple Security Bypass Vulnerabilities
14396| [88701] Apache CVE-2001-1449 Remote Security Vulnerability
14397| [88635] Apache CVE-2000-1204 Remote Security Vulnerability
14398| [88590] Apache WWW server CVE-1999-1199 Denial-Of-Service Vulnerability
14399| [88496] Apache CVE-2000-1206 Remote Security Vulnerability
14400| [87828] Apache CVE-1999-1237 Remote Security Vulnerability
14401| [87784] Apache CVE-1999-1293 Denial-Of-Service Vulnerability
14402| [87327] Apache Struts CVE-2016-3081 Remote Code Execution Vulnerability
14403| [86622] Apache Stats CVE-2007-0975 Remote Security Vulnerability
14404| [86399] Apache CVE-2007-1743 Local Security Vulnerability
14405| [86397] Apache CVE-2007-1742 Local Security Vulnerability
14406| [86311] Apache Struts CVE-2016-4003 Cross Site Scripting Vulnerability
14407| [86174] Apache Wicket CVE-2015-5347 Cross Site Scripting Vulnerability
14408| [85971] Apache OFBiz CVE-2016-2170 Java Deserialization Remote Code Execution Vulnerability
14409| [85967] Apache OFBiz CVE-2015-3268 HTML Injection Vulnerability
14410| [85759] Apache Jetspeed CVE-2016-2171 Unauthorized Access Vulnerability
14411| [85758] Apache Jetspeed CVE-2016-0712 Cross Site Scripting Vulnerability
14412| [85756] Apache Jetspeed CVE-2016-0710 Multiple SQL Injection Vulnerabilities
14413| [85755] Apache Jetspeed CVE-2016-0711 Mulitple HTML Injection Vulnerabilities
14414| [85754] Apache Jetspeed CVE-2016-0709 Directory Traversal Vulnerability
14415| [85730] Apache Subversion CVE-2015-5343 Integer Overflow Vulnerability
14416| [85691] Apache Ranger CVE-2016-0735 Security Bypass Vulnerability
14417| [85578] Apache ActiveMQ CVE-2010-1244 Cross-Site Request Forgery Vulnerability
14418| [85554] Apache OpenMeetings CVE-2016-2164 Multiple Information Disclosure Vulnerabilities
14419| [85553] Apache OpenMeetings CVE-2016-0783 Information Disclosure Vulnerability
14420| [85552] Apache OpenMeetings CVE-2016-2163 HTML Injection Vulnerability
14421| [85550] Apache OpenMeetings CVE-2016-0784 Directory Traversal Vulnerability
14422| [85386] Apache Hadoop CVE-2015-7430 Local Privilege Escalation Vulnerability
14423| [85377] Apache Qpid Proton Python API CVE-2016-2166 Man in the Middle Security Bypass Vulnerability
14424| [85205] Apache Solr CVE-2015-8796 Cross Site Scripting Vulnerability
14425| [85203] Apache Solr CVE-2015-8795 Mulitple HTML Injection Vulnerabilities
14426| [85163] Apache Geronimo CVE-2008-0732 Local Security Vulnerability
14427| [85131] Apache Struts 'TextParseUtil.translateVariables()' Method Remote Code Execution Vulnerability
14428| [85070] Apache Struts CVE-2016-2162 Cross Site Scripting Vulnerability
14429| [85066] Apache Struts CVE-2016-0785 Remote Code Execution Vulnerability
14430| [84422] Apache TomEE CVE-2016-0779 Unspecified Security Vulnerability
14431| [84321] Apache ActiveMQ CVE-2016-0734 Clickjacking Vulnerability
14432| [84316] Apache ActiveMQ CVE-2016-0782 Multiple Cross Site Scripting Vulnerabilities
14433| [83910] Apache Wicket CVE-2015-7520 Cross Site Scripting Vulnerability
14434| [83423] Apache Xerces-C CVE-2016-0729 Buffer Overflow Vulnerability
14435| [83330] Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability
14436| [83329] Apache Tomcat CVE-2015-5174 Directory Traversal Vulnerability
14437| [83328] Apache Tomcat CVE-2015-5345 Directory Traversal Vulnerability
14438| [83327] Apache Tomcat Security Manager CVE-2016-0714 Remote Code Execution Vulnerability
14439| [83326] Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
14440| [83324] Apache Tomcat Security Manager CVE-2016-0706 Information Disclosure Vulnerability
14441| [83323] Apache Tomcat CVE-2015-5346 Session Fixation Vulnerability
14442| [83259] Apache Hadoop CVE-2015-1776 Information Disclosure Vulnerability
14443| [83243] Apache Solr CVE-2015-8797 Cross Site Scripting Vulnerability
14444| [83119] Apache Sling CVE-2016-0956 Information Disclosure Vulnerability
14445| [83002] Apache CVE-2000-1205 Cross-Site Scripting Vulnerability
14446| [82871] Apache Ranger Authentication Bypass and Security Bypass Vulnerabilities
14447| [82800] Apache CloudStack CVE-2015-3251 Information Disclosure Vulnerability
14448| [82798] Apache CloudStack CVE-2015-3252 Authentication Bypass Vulnerability
14449| [82732] Apache Gallery CVE-2003-0771 Local Security Vulnerability
14450| [82676] Apache CVE-2003-1581 Cross-Site Scripting Vulnerability
14451| [82550] Apache Struts CVE-2015-5209 Security Bypass Vulnerability
14452| [82300] Apache Subversion CVE-2015-5259 Integer Overflow Vulnerability
14453| [82260] Apache Camel CVE-2015-5344 Remote Code Execution Vulnerability
14454| [82234] Apache Hive CVE-2015-7521 Security Bypass Vulnerability
14455| [82082] Apache CVE-1999-0289 Remote Security Vulnerability
14456| [81821] Apache Distribution for Solaris CVE-2007-2080 SQL-Injection Vulnerability
14457| [80696] Apache Camel CVE-2015-5348 Information Disclosure Vulnerability
14458| [80525] Apache CVE-2003-1580 Remote Security Vulnerability
14459| [80354] Drupal Apache Solr Search Module Access Bypass Vulnerability
14460| [80193] Apache CVE-1999-0107 Denial-Of-Service Vulnerability
14461| [79812] Apache Directory Studio CVE-2015-5349 Command Injection Vulnerability
14462| [79744] Apache HBase CVE-2015-1836 Unauthorized Access Vulnerability
14463| [79204] Apache TomEE 'EjbObjectInputStream' Remote Code Execution Vulnerability
14464| [77679] Apache Cordova For Android CVE-2015-8320 Weak Randomization Security Bypass Vulnerability
14465| [77677] Apache Cordova For Android CVE-2015-5256 Security Bypass Vulnerability
14466| [77591] Apache CXF SAML SSO Processing CVE-2015-5253 Security Bypass Vulnerability
14467| [77521] Apache Commons Collections 'InvokerTransformer.java' Remote Code Execution Vulnerability
14468| [77110] Apache HttpComponents HttpClient CVE-2015-5262 Denial of Service Vulnerability
14469| [77086] Apache Ambari CVE-2015-1775 Server Side Request Forgery Security Bypass Vulnerability
14470| [77085] Apache Ambari CVE-2015-3270 Remote Privilege Escalation Vulnerability
14471| [77082] Apache Ambari 'targetURI' Parameter Open Redirection Vulnerability
14472| [77059] Apache Ambari CVE-2015-3186 Cross Site Scripting Vulnerability
14473| [76933] Apache James Server Unspecified Command Execution Vulnerability
14474| [76832] Apache cordova-plugin-file-transfer CVE-2015-5204 HTTP Header Injection Vulnerability
14475| [76625] Apache Struts CVE-2015-5169 Cross Site Scripting Vulnerability
14476| [76624] Apache Struts CVE-2015-2992 Cross Site Scripting Vulnerability
14477| [76522] Apache Tapestry CVE-2014-1972 Security Bypass Vulnerability
14478| [76486] Apache CXF Fediz CVE-2015-5175 Denial of Service Vulnerability
14479| [76452] Apache ActiveMQ CVE-2015-1830 Directory Traversal Vulnerability
14480| [76446] Apache Subversion 'libsvn_fs_fs/tree.c' Denial of Service Vulnerability
14481| [76274] Apache Subversion CVE-2015-3184 Information Disclosure Vulnerability
14482| [76273] Apache Subversion CVE-2015-3187 Information Disclosure Vulnerability
14483| [76272] Apache ActiveMQ CVE-2014-3576 Denial of Service Vulnerability
14484| [76221] Apache Ranger CVE-2015-0266 Access Bypass Vulnerability
14485| [76208] Apache Ranger CVE-2015-0265 JavaScript Code Injection Vulnerability
14486| [76025] Apache ActiveMQ Artemis CVE-2015-3208 XML External Entity Information Disclosure Vulnerability
14487| [75965] Apache HTTP Server CVE-2015-3185 Security Bypass Vulnerability
14488| [75964] Apache HTTP Server CVE-2015-0253 Remote Denial of Service Vulnerability
14489| [75963] Apache HTTP Server CVE-2015-3183 Security Vulnerability
14490| [75940] Apache Struts CVE-2015-1831 Security Bypass Vulnerability
14491| [75919] Apache Groovy CVE-2015-3253 Remote Code Execution Vulnerability
14492| [75338] Apache Storm CVE-2015-3188 Remote Code Execution Vulnerability
14493| [75275] Drupal Apache Solr Real-Time Module Access Bypass Vulnerability
14494| [74866] Apache Cordova For Android CVE-2015-1835 Security Bypass Vulnerability
14495| [74839] Apache Sling API and Sling Servlets CVE-2015-2944 Cross Site Scripting Vulnerability
14496| [74761] Apache Jackrabbit CVE-2015-1833 XML External Entity Information Disclosure Vulnerability
14497| [74686] Apache Ambari '/var/lib/ambari-server/ambari-env.sh' Local Privilege Escalation Vulnerability
14498| [74665] Apache Tomcat CVE-2014-7810 Security Bypass Vulnerability
14499| [74475] Apache Tomcat CVE-2014-0230 Denial of Service Vulnerability
14500| [74423] Apache Struts CVE-2015-0899 Security Bypass Vulnerability
14501| [74338] Apache OpenOffice HWP Filter Memory Corruption Vulnerability
14502| [74265] Apache Tomcat 'mod_jk' CVE-2014-8111 Information Disclosure Vulnerability
14503| [74260] Apache Subversion CVE-2015-0248 Multiple Denial of Service Vulnerabilities
14504| [74259] Apache Subversion 'deadprops.c' Security Bypass Vulnerability
14505| [74204] PHP 'sapi/apache2handler/sapi_apache2.c' Remote Code Execution Vulnerability
14506| [74158] Apache HTTP Server 'protocol.c' Remote Denial of Service Vulnerability
14507| [73954] Apache Flex 'asdoc/templates/index.html' Cross Site Scripting Vulnerability
14508| [73851] Apache2 CVE-2012-0216 Cross-Site Scripting Vulnerability
14509| [73478] Apache Cassandra CVE-2015-0225 Remote Code Execution Vulnerability
14510| [73041] Apache HTTP Server 'mod_lua' Module Denial of Service Vulnerability
14511| [73040] Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
14512| [72809] Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
14513| [72717] Apache Tomcat CVE-2014-0227 Chunk Request Remote Denial Of Service Vulnerability
14514| [72557] Apache WSS4J CVE-2015-0227 Security Bypass Vulnerability
14515| [72553] Apache WSS4J CVE-2015-0226 Information Disclosure Vulnerability
14516| [72513] Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
14517| [72511] Apache ActiveMQ CVE-2014-8110 Multiple Cross Site Scripting Vulnerabilities
14518| [72510] Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
14519| [72508] Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
14520| [72319] Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
14521| [72317] Apache Qpid CVE-2015-0224 Incomplete Fix Multiple Denial of Service Vulnerabilities
14522| [72115] Apache Santuario 'XML Signature Verification' Security Bypass Vulnerability
14523| [72053] Apache HTTP Server 'mod_remoteip.c' IP Address Spoofing Vulnerability
14524| [72030] Apache Qpid CVE-2015-0203 Multiple Denial of Service Vulnerabilities
14525| [71879] Apache Traffic Server 'HttpTransact.cc' Denial of Service Vulnerability
14526| [71726] Apache Subversion CVE-2014-3580 Remote Denial of Service Vulnerability
14527| [71725] Apache Subversion CVE-2014-8108 Remote Denial of Service Vulnerability
14528| [71657] Apache HTTP Server 'mod_proxy_fcgi' Module Denial of Service Vulnerability
14529| [71656] Apache HTTP Server 'mod_cache' Module Denial of Service Vulnerability
14530| [71548] Apache Struts CVE-2014-7809 Security Bypass Vulnerability
14531| [71466] Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
14532| [71353] Apache HTTP Server 'LuaAuthzProvider' Authorization Bypass Vulnerability
14533| [71004] Apache Qpid CVE-2014-3629 XML External Entity Injection Vulnerability
14534| [70970] Apache Traffic Server Cross Site Scripting Vulnerability
14535| [70738] Apache CXF CVE-2014-3584 Denial of Service Vulnerability
14536| [70736] Apache CXF SAML SubjectConfirmation Security Bypass Vulnerability
14537| [69728] Apache Tomcat CVE-2013-4444 Arbitrary File Upload Vulnerability
14538| [69648] Apache POI CVE-2014-3574 Denial Of Service Vulnerability
14539| [69647] Apache POI OpenXML parser CVE-2014-3529 XML External Entity Information Disclosure Vulnerability
14540| [69351] Apache OpenOffice Calc CVE-2014-3524 Command Injection Vulnerability
14541| [69295] Apache Axis Incomplete Fix CVE-2014-3596 SSL Certificate Validation Security Bypass Vulnerability
14542| [69286] Apache OFBiz CVE-2014-0232 Multiple Cross Site Scripting Vulnerabilities
14543| [69258] Apache HttpComponents Incomplete Fix CVE-2014-3577 SSL Validation Security Bypass Vulnerability
14544| [69257] Apache HttpComponents Incomplete Fix SSL Certificate Validation Security Bypass Vulnerability
14545| [69248] Apache HTTP Server CVE-2013-4352 Remote Denial of Service Vulnerability
14546| [69237] Apache Subversion CVE-2014-3522 SSL Certificate Validation Information Disclosure Vulnerability
14547| [69173] Apache Traffic Server CVE-2014-3525 Unspecified Security Vulnerability
14548| [69046] Apache Cordova For Android CVE-2014-3502 Information Disclosure Vulnerability
14549| [69041] Apache Cordova For Android CVE-2014-3501 Security Bypass Vulnerability
14550| [69038] Apache Cordova For Android CVE-2014-3500 Security Bypass Vulnerability
14551| [68995] Apache Subversion CVE-2014-3528 Insecure Authentication Weakness
14552| [68966] Apache Subversion 'irkerbridge.py' Local Privilege Escalation Vulnerability
14553| [68965] Apache Subversion 'svnwcsub.py' Local Privilege Escalation Vulnerability
14554| [68863] Apache HTTP Server 'mod_cache' Module Remote Denial of Service Vulnerability
14555| [68747] Apache HTTP Server CVE-2014-3523 Remote Denial of Service Vulnerability
14556| [68745] Apache HTTP Server CVE-2014-0118 Remote Denial of Service Vulnerability
14557| [68742] Apache HTTP Server CVE-2014-0231 Remote Denial of Service Vulnerability
14558| [68740] Apache HTTP Server CVE-2014-0117 Remote Denial of Service Vulnerability
14559| [68678] Apache HTTP Server 'mod_status' CVE-2014-0226 Remote Code Execution Vulnerability
14560| [68445] Apache CXF UsernameToken Information Disclosure Vulnerability
14561| [68441] Apache CXF SAML Tokens Validation Security Bypass Vulnerability
14562| [68431] Apache Syncope CVE-2014-3503 Insecure Password Generation Weakness
14563| [68229] Apache Harmony PRNG Entropy Weakness
14564| [68111] Apache 'mod_wsgi' Module Privilege Escalation Vulnerability
14565| [68072] Apache Tomcat CVE-2014-0186 Remote Denial of Service Vulnerability
14566| [68039] Apache Hive CVE-2014-0228 Security Bypass Vulnerability
14567| [67673] Apache Tomcat CVE-2014-0095 AJP Request Remote Denial Of Service Vulnerability
14568| [67671] Apache Tomcat CVE-2014-0075 Chunk Request Remote Denial Of Service Vulnerability
14569| [67669] Apache Tomcat CVE-2014-0119 XML External Entity Information Disclosure Vulnerability
14570| [67668] Apache Tomcat CVE-2014-0099 Request Processing Information Disclosure Vulnerability
14571| [67667] Apache Tomcat CVE-2014-0096 XML External Entity Information Disclosure Vulnerability
14572| [67534] Apache 'mod_wsgi' Module CVE-2014-0242 Information Disclosure Vulnerability
14573| [67532] Apache 'mod_wsgi' Module Local Privilege Escalation Vulnerability
14574| [67530] Apache Solr Search Template Cross Site Scripting Vulnerability
14575| [67236] Apache CXF CVE-2014-0109 Remote Denial of Service Vulnerability
14576| [67232] Apache CXF CVE-2014-0110 Denial of Service Vulnerability
14577| [67121] Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
14578| [67081] Apache Struts 'getClass()' Method Security Bypass Vulnerability
14579| [67064] Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
14580| [67013] Apache Zookeeper CVE-2014-0085 Local Information Disclosure Vulnerability
14581| [66998] Apache Archiva CVE-2013-2187 Unspecified Cross Site Scripting Vulnerability
14582| [66991] Apache Archiva CVE-2013-2187 HTML Injection Vulnerability
14583| [66927] Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
14584| [66474] Apache CouchDB Universally Unique IDentifier (UUID) Remote Denial of Service Vulnerability
14585| [66397] Apache Xalan-Java Library CVE-2014-0107 Security Bypass Vulnerability
14586| [66303] Apache HTTP Server Multiple Denial of Service Vulnerabilities
14587| [66041] RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
14588| [65999] Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability
14589| [65967] Apache Cordova File-Transfer Unspecified Security Vulnerability
14590| [65959] Apache Cordova InAppBrowser Remote Privilege Escalation Vulnerability
14591| [65935] Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
14592| [65902] Apache Camel CVE-2014-0003 Remote Code Execution Vulnerability
14593| [65901] Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
14594| [65773] Apache Tomcat CVE-2013-4286 Security Bypass Vulnerability
14595| [65769] Apache Tomcat CVE-2014-0033 Session Fixation Vulnerability
14596| [65768] Apache Tomcat CVE-2013-4590 XML External Entity Information Disclosure Vulnerability
14597| [65767] Apache Tomcat CVE-2013-4322 Incomplete Fix Denial of Service Vulnerability
14598| [65615] Apache ActiveMQ 'refresh' Parameter Cross Site Scripting Vulnerability
14599| [65434] Apache Subversion 'mod_dav_svn' Module SVNListParentPath Denial of Service Vulnerability
14600| [65431] Apache Wicket CVE-2013-2055 Information Disclosure Vulnerability
14601| [65400] Apache Commons FileUpload CVE-2014-0050 Denial Of Service Vulnerability
14602| [64782] Apache CloudStack Virtual Router Component Security Bypass Vulnerability
14603| [64780] Apache CloudStack Unauthorized Access Vulnerability
14604| [64617] Apache Libcloud Digital Ocean API Local Information Disclosure Vulnerability
14605| [64437] Apache Santuario XML Security For JAVA XML Signature Denial of Service Vulnerability
14606| [64427] Apache Solr Multiple XML External Entity Injection Vulnerabilities
14607| [64009] Apache Solr CVE-2013-6408 XML External Entity Injection Vulnerability
14608| [64008] Apache Solr CVE-2013-6407 XML External Entity Injection Vulnerability
14609| [63981] Apache Subversion 'mod_dav_svn' Module Denial of Service Vulnerability
14610| [63966] Apache Subversion CVE-2013-4505 Security Bypass Vulnerability
14611| [63963] Apache Roller CVE-2013-4171 Cross Site Scripting Vulnerability
14612| [63935] Apache Solr 'SolrResourceLoader' Directory Traversal Vulnerability
14613| [63928] Apache Roller CVE-2013-4212 OGNL Expression Injection Remote Code Execution Vulnerability
14614| [63515] Apache Tomcat Manager Component CVE-2013-6357 Cross Site Request Forgery Vulnerability
14615| [63403] Apache Struts Multiple Cross Site Scripting Vulnerabilities
14616| [63400] Apache 'mod_pagespeed' Module Unspecified Cross Site Scripting Vulnerability
14617| [63260] Apache Shindig CVE-2013-4295 XML External Entity Information Disclosure Vulnerability
14618| [63241] Apache Sling 'AbstractAuthenticationFormServlet' Open Redirection Vulnerability
14619| [63174] Apache Commons FileUpload 'DiskFileItem' Class Null Byte Arbitrary File Write Vulnerability
14620| [62939] Apache 'mod_fcgid' Module CVE-2013-4365 Heap Buffer Overflow Vulnerability
14621| [62903] Apache Sling 'deepGetOrCreateNode()' Function Denial Of Service Vulnerability
14622| [62706] Apache Camel CVE-2013-4330 Information Disclosure Vulnerability
14623| [62677] Apache 'mod_accounting' Module CVE-2013-5697 SQL Injection Vulnerability
14624| [62674] TYPO3 Apache Solr Unspecified Cross Site Scripting and PHP Code Execution Vulnerabilities
14625| [62587] Apache Struts CVE-2013-4316 Remote Code Execution Vulnerability
14626| [62584] Apache Struts CVE-2013-4310 Security Bypass Vulnerability
14627| [62266] Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
14628| [61984] Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
14629| [61981] Apache HBase RPC Authentication Man In The Middle Security Bypass Vulnerability
14630| [61638] Apache CloudStack CVE-2013-2136 Multiple Cross Site Scripting Vulnerabilities
14631| [61454] Apache Subversion CVE-2013-4131 Denial Of Service Vulnerability
14632| [61379] Apache HTTP Server CVE-2013-2249 Unspecified Remote Security Vulnerability
14633| [61370] Apache OFBiz CVE-2013-2317 'View Log' Cross Site Scripting Vulnerability
14634| [61369] Apache OFBiz Nested Expression Remote Code Execution Vulnerability
14635| [61196] Apache Struts CVE-2013-2248 Multiple Open Redirection Vulnerabilities
14636| [61189] Apache Struts CVE-2013-2251 Multiple Remote Command Execution Vulnerabilities
14637| [61129] Apache HTTP Server CVE-2013-1896 Remote Denial of Service Vulnerability
14638| [61030] Apache CXF CVE-2013-2160 Multiple Remote Denial of Service Vulnerabilities
14639| [60875] Apache Geronimo RMI Classloader Security Bypass Vulnerability
14640| [60846] Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
14641| [60817] Apache Santuario XML Security for C++ CVE-2013-2210 Heap Buffer Overflow Vulnerability
14642| [60800] Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
14643| [60599] Apache Santuario XML Security for C++ CVE-2013-2156 Remote Heap Buffer Overflow Vulnerability
14644| [60595] Apache Santuario XML Security for C++ XML Signature CVE-2013-2155 Denial of Service Vulnerability
14645| [60594] Apache Santuario XML Security for C++ CVE-2013-2154 Stack Buffer Overflow Vulnerability
14646| [60592] Apache Santuario XML Security for C++ XML Signature CVE-2013-2153 Security Bypass Vulnerability
14647| [60534] Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
14648| [60346] Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
14649| [60345] Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
14650| [60267] Apache Subversion CVE-2013-1968 Remote Denial of Service Vulnerability
14651| [60265] Apache Subversion CVE-2013-2088 Command Injection Vulnerability
14652| [60264] Apache Subversion CVE-2013-2112 Remote Denial of Service Vulnerability
14653| [60187] Apache Tomcat DIGEST Authentication CVE-2013-2051 Incomplete Fix Security Weakness
14654| [60186] Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
14655| [60167] Apache Struts 'includeParams' CVE-2013-2115 Incomplete Fix Security Bypass Vulnerability
14656| [60166] Apache Struts 'includeParams' CVE-2013-1966 Security Bypass Vulnerability
14657| [60082] Apache Struts 'ParameterInterceptor' Class OGNL CVE-2013-1965 Security Bypass Vulnerability
14658| [59826] Apache HTTP Server Terminal Escape Sequence in Logs Command Injection Vulnerability
14659| [59799] Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
14660| [59798] Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
14661| [59797] Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
14662| [59670] Apache VCL Multiple Input Validation Vulnerabilities
14663| [59464] Apache CloudStack CVE-2013-2758 Hash Information Disclosure Vulnerability
14664| [59463] Apache CloudStack CVE-2013-2756 Authentication Bypass Vulnerability
14665| [59402] Apache ActiveMQ CVE-2013-3060 Information Disclosure and Denial of Service Vulnerability
14666| [59401] Apache ActiveMQ CVE-2012-6551 Denial of Service Vulnerability
14667| [59400] Apache ActiveMQ CVE-2012-6092 Multiple Cross Site Scripting Vulnerabilities
14668| [58898] Apache Subversion CVE-2013-1884 Remote Denial of Service Vulnerability
14669| [58897] Apache Subversion 'mod_dav_svn/lock.c' Remote Denial of Service Vulnerability
14670| [58895] Apache Subversion 'mod_dav_svn' Remote Denial of Service Vulnerability
14671| [58455] Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
14672| [58379] Apache Qpid CVE-2012-4446 Authentication Bypass Vulnerability
14673| [58378] Apache Qpid CVE-2012-4460 Denial of Service Vulnerability
14674| [58376] Apache Qpid CVE-2012-4458 Denial of Service Vulnerability
14675| [58337] Apache Qpid CVE-2012-4459 Denial of Service Vulnerability
14676| [58326] Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
14677| [58325] Debian Apache HTTP Server CVE-2013-1048 Symlink Attack Local Privilege Escalation Vulnerability
14678| [58323] Apache Subversion 'svn_fs_file_length()' Remote Denial of Service Vulnerability
14679| [58165] Apache HTTP Server Multiple Cross Site Scripting Vulnerabilities
14680| [58136] Apache Maven CVE-2013-0253 SSL Certificate Validation Security Bypass Vulnerability
14681| [58124] Apache Tomcat 'log/logdir' Directory Insecure File Permissions Vulnerability
14682| [58073] Apache Commons HttpClient CVE-2012-5783 SSL Certificate Validation Security Bypass Vulnerability
14683| [57876] Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
14684| [57874] Apache CXF CVE-2012-5633 Security Bypass Vulnerability
14685| [57463] Apache OFBiz CVE-2013-0177 Multiple Cross Site Scripting Vulnerabilities
14686| [57425] Apache CXF CVE-2012-5786 SSL Certificate Validation Security Bypass Vulnerability
14687| [57321] Apache CouchDB CVE-2012-5650 Cross Site Scripting Vulnerability
14688| [57314] Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
14689| [57267] Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
14690| [57259] Apache CloudStack CVE-2012-5616 Local Information Disclosure Vulnerability
14691| [56814] Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
14692| [56813] Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
14693| [56812] Apache Tomcat CVE-2012-3546 Security Bypass Vulnerability
14694| [56753] Apache Apache HTTP Server 'mod_proxy_ajp Module Denial Of Service Vulnerability
14695| [56686] Apache Tomcat CVE-2012-5568 Denial of Service Vulnerability
14696| [56408] Apache Axis and Axis2/Java SSL Certificate Validation Security Bypass Vulnerability
14697| [56403] Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
14698| [56402] Apache Tomcat CVE-2012-2733 Denial of Service Vulnerability
14699| [56171] Apache OFBiz CVE-2012-3506 Unspecified Security Vulnerability
14700| [55876] Apache CloudStack CVE-2012-4501 Security Bypass Vulnerability
14701| [55628] Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
14702| [55608] Apache Qpid (qpidd) Denial of Service Vulnerability
14703| [55536] Apache 'mod_pagespeed' Module Cross Site Scripting and Security Bypass Vulnerabilities
14704| [55508] Apache Axis2 XML Signature Wrapping Security Vulnerability
14705| [55445] Apache Wicket CVE-2012-3373 Cross Site Scripting Vulnerability
14706| [55346] Apache Struts Cross Site Request Forgery and Denial of Service Vulnerabilities
14707| [55290] Drupal Apache Solr Autocomplete Module Cross Site Scripting Vulnerability
14708| [55165] Apache Struts2 Skill Name Remote Code Execution Vulnerability
14709| [55154] Apache 'mod-rpaf' Module Denial of Service Vulnerability
14710| [55131] Apache HTTP Server HTML-Injection And Information Disclosure Vulnerabilities
14711| [54954] Apache QPID NullAuthenticator Authentication Bypass Vulnerability
14712| [54798] Apache Libcloud Man In The Middle Vulnerability
14713| [54358] Apache Hadoop CVE-2012-3376 Information Disclosure Vulnerability
14714| [54341] Apache Sling CVE-2012-2138 Denial Of Service Vulnerability
14715| [54268] Apache Hadoop Symlink Attack Local Privilege Escalation Vulnerability
14716| [54189] Apache Roller Cross Site Request Forgery Vulnerability
14717| [54187] Apache Roller CVE-2012-2381 Cross Site Scripting Vulnerability
14718| [53880] Apache CXF Child Policies Security Bypass Vulnerability
14719| [53877] Apache CXF Elements Validation Security Bypass Vulnerability
14720| [53676] Apache Commons Compress and Apache Ant CVE-2012-2098 Denial Of Service Vulnerability
14721| [53487] Apache POI CVE-2012-0213 Denial Of Service Vulnerability
14722| [53455] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability
14723| [53305] Apache Qpid CVE-2011-3620 Unauthorized Access Security Bypass Vulnerability
14724| [53046] Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
14725| [53025] Apache OFBiz Unspecified Remote Code Execution Vulnerability
14726| [53023] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
14727| [52939] Apache Hadoop CVE-2012-1574 Unspecified User Impersonation Vulnerability
14728| [52702] Apache Struts2 'XSLTResult.java' Remote Arbitrary File Upload Vulnerability
14729| [52696] Apache Traffic Server HTTP Host Header Handling Heap Based Buffer Overflow Vulnerability
14730| [52680] Apache Wicket 'pageMapName' Parameter Cross Site Scripting Vulnerability
14731| [52679] Apache Wicket Hidden Files Information Disclosure Vulnerability
14732| [52565] Apache 'mod_fcgid' Module Denial Of Service Vulnerability
14733| [52146] TYPO3 Apache Solr Extension Unspecified Cross Site Scripting Vulnerability
14734| [51939] Apache MyFaces 'ln' Parameter Information Disclosure Vulnerability
14735| [51917] Apache APR Hash Collision Denial Of Service Vulnerability
14736| [51902] Apache Struts Multiple HTML Injection Vulnerabilities
14737| [51900] Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
14738| [51886] Apache CXF UsernameToken Policy Validation Security Bypass Vulnerability
14739| [51869] Apache HTTP Server CVE-2011-3639 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
14740| [51706] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
14741| [51705] Apache HTTP Server CVE-2012-0021 mod_log_config Denial Of Service Vulnerability
14742| [51628] Apache Struts 'ParameterInterceptor' Class OGNL (CVE-2011-3923) Security Bypass Vulnerability
14743| [51447] Apache Tomcat Parameter Handling Denial of Service Vulnerability
14744| [51442] Apache Tomcat Request Object Security Bypass Vulnerability
14745| [51407] Apache HTTP Server Scoreboard Local Security Bypass Vulnerability
14746| [51257] Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
14747| [51238] Apache Geronimo Hash Collision Denial Of Service Vulnerability
14748| [51200] Apache Tomcat Hash Collision Denial Of Service Vulnerability
14749| [50940] Apache Struts Session Tampering Security Bypass Vulnerability
14750| [50912] RETIRED: Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
14751| [50904] Apache ActiveMQ Failover Mechanism Remote Denial Of Service Vulnerability
14752| [50848] Apache MyFaces EL Expression Evaluation Security Bypass Vulnerability
14753| [50802] Apache HTTP Server 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
14754| [50639] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
14755| [50603] Apache Tomcat Manager Application Security Bypass Vulnerability
14756| [50494] Apache HTTP Server 'ap_pregsub()' Function Local Privilege Escalation Vulnerability
14757| [49957] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
14758| [49762] Apache Tomcat HTTP DIGEST Authentication Multiple Security Weaknesses
14759| [49728] Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
14760| [49616] Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
14761| [49470] Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
14762| [49353] Apache Tomcat AJP Protocol Security Bypass Vulnerability
14763| [49303] Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability
14764| [49290] Apache Wicket Cross Site Scripting Vulnerability
14765| [49147] Apache Tomcat CVE-2011-2481 Information Disclosure Vulnerability
14766| [49143] Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
14767| [48667] Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability
14768| [48653] Apache 'mod_authnz_external' Module SQL Injection Vulnerability
14769| [48611] Apache XML Security for C++ Signature Key Parsing Denial of Service Vulnerability
14770| [48456] Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability
14771| [48015] Apache Archiva Multiple Cross Site Request Forgery Vulnerabilities
14772| [48011] Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
14773| [47929] Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
14774| [47890] Apache Struts 'javatemplates' Plugin Multiple Cross Site Scripting Vulnerabilities
14775| [47886] Apache Tomcat SecurityConstraints Security Bypass Vulnerability
14776| [47820] Apache APR 'apr_fnmatch()' Denial of Service Vulnerability
14777| [47784] Apache Struts XWork 's:submit' HTML Tag Cross Site Scripting Vulnerability
14778| [47199] Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
14779| [47196] Apache Tomcat Login Constraints Security Bypass Vulnerability
14780| [46974] Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
14781| [46953] Apache MPM-ITK Module Security Weakness
14782| [46734] Subversion 'mod_dav_svn' Apache Server NULL Pointer Dereference Denial Of Service Vulnerability
14783| [46685] Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
14784| [46311] Apache Continuum and Archiva Cross Site Scripting Vulnerability
14785| [46177] Apache Tomcat SecurityManager Security Bypass Vulnerability
14786| [46174] Apache Tomcat HTML Manager Interface HTML Injection Vulnerability
14787| [46166] Apache Tomcat JVM Denial of Service Vulnerability
14788| [46164] Apache Tomcat NIO Connector Denial of Service Vulnerability
14789| [46066] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
14790| [45655] Apache Subversion Server Component Multiple Remote Denial Of Service Vulnerabilities
14791| [45123] Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Vulnerability
14792| [45095] Apache Archiva Cross Site Request Forgery Vulnerability
14793| [45015] Apache Tomcat 'sort' and 'orderBy' Parameters Cross Site Scripting Vulnerabilities
14794| [44900] Apache 'mod_fcgid' Module Unspecified Stack Buffer Overflow Vulnerability
14795| [44616] Apache Shiro Directory Traversal Vulnerability
14796| [44355] Apache MyFaces Encrypted View State Oracle Padding Security Vulnerability
14797| [44068] Apache::AuthenHook Local Information Disclosure Vulnerability
14798| [43862] Apache QPID SSL Connection Denial of Service Vulnerability
14799| [43673] Apache APR-util 'apr_brigade_split_line()' Denial of Service Vulnerability
14800| [43637] Apache XML-RPC SAX Parser Information Disclosure Vulnerability
14801| [43111] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
14802| [42637] Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
14803| [42501] Apache CouchDB Cross Site Request Forgery Vulnerability
14804| [42492] Apache CXF XML DTD Processing Security Vulnerability
14805| [42121] Apache SLMS Insufficient Quoting Cross Site Request Forgery Vulnerability
14806| [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
14807| [41963] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
14808| [41544] Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities
14809| [41076] Apache Axis2 '/axis2/axis2-admin' Session Fixation Vulnerability
14810| [40976] Apache Axis2 Document Type Declaration Processing Security Vulnerability
14811| [40827] Apache 'mod_proxy_http' Timeout Handling Information Disclosure Vulnerability
14812| [40343] Apache Axis2 'xsd' Parameter Directory Traversal Vulnerability
14813| [40327] Apache Axis2 'engagingglobally' Cross-Site Scripting Vulnerability
14814| [39771] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
14815| [39636] Apache ActiveMQ Source Code Information Disclosure Vulnerability
14816| [39635] Apache Tomcat Authentication Header Realm Name Information Disclosure Vulnerability
14817| [39538] Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
14818| [39489] Apache OFBiz Multiple Cross Site Scripting and HTML Injection Vulnerabilities
14819| [39119] Apache ActiveMQ 'createDestination.action' HTML Injection Vulnerability
14820| [38580] Apache Subrequest Handling Information Disclosure Vulnerability
14821| [38494] Apache 'mod_isapi' Memory Corruption Vulnerability
14822| [38491] Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
14823| [37966] Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability
14824| [37945] Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability
14825| [37944] Apache Tomcat WAR File Directory Traversal Vulnerability
14826| [37942] Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability
14827| [37149] Apache Tomcat 404 Error Page Cross Site Scripting Vulnerability
14828| [37027] RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
14829| [36990] Apache HTTP TRACE Cross Site Scripting Vulnerability
14830| [36954] Apache Tomcat Windows Installer Insecure Password Vulnerability
14831| [36889] TYPO3 Apache Solr Search Extension Unspecified Cross Site Scripting Vulnerability
14832| [36596] Apache HTTP Server Solaris Event Port Pollset Support Remote Denial Of Service Vulnerability
14833| [36260] Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
14834| [36254] Apache mod_proxy_ftp Remote Command Injection Vulnerability
14835| [35949] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
14836| [35840] Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
14837| [35623] Apache 'mod_deflate' Remote Denial Of Service Vulnerability
14838| [35565] Apache 'mod_proxy' Remote Denial Of Service Vulnerability
14839| [35416] Apache Tomcat XML Parser Information Disclosure Vulnerability
14840| [35263] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
14841| [35253] Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
14842| [35251] Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
14843| [35221] Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
14844| [35196] Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness
14845| [35193] Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability
14846| [35115] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
14847| [34686] Apache Struts Multiple Cross Site Scripting Vulnerabilities
14848| [34663] Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
14849| [34657] Apache Tiles Cross Site Scripting And Information Disclosure Vulnerabilities
14850| [34562] Apache Geronimo Application Server Multiple Remote Vulnerabilities
14851| [34552] Apache ActiveMQ Web Console Multiple Unspecified HTML Injection Vulnerabilities
14852| [34412] Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability
14853| [34399] Apache Struts Unspecified Cross Site Scripting Vulnerability
14854| [34383] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
14855| [33913] Apache Tomcat POST Data Information Disclosure Vulnerability
14856| [33360] Apache Jackrabbit 'q' Parameter Multiple Cross Site Scripting Vulnerabilities
14857| [33110] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
14858| [32657] Novell NetWare ApacheAdmin Security Bypass Vulnerability
14859| [31805] Apache HTTP Server OS Fingerprinting Unspecified Security Vulnerability
14860| [31761] Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
14861| [31698] Apache Tomcat 'RemoteFilterValve' Security Bypass Vulnerability
14862| [31165] Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
14863| [30560] Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability
14864| [30496] Apache Tomcat 'HttpServletResponse.sendError()' Cross Site Scripting Vulnerability
14865| [30494] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
14866| [29653] Apache 'mod_proxy_http' Interim Response Denial of Service Vulnerability
14867| [29502] Apache Tomcat Host Manager Cross Site Scripting Vulnerability
14868| [28576] Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
14869| [28484] Apache Tomcat Requests Containing MS-DOS Device Names Information Disclosure Vulnerability
14870| [28483] Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
14871| [28482] Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
14872| [28481] Apache Tomcat Cross-Site Scripting Vulnerability
14873| [28477] Apache Tomcat AJP Connector Information Disclosure Vulnerability
14874| [27752] Apache mod_jk2 Host Header Multiple Stack Based Buffer Overflow Vulnerabilities
14875| [27706] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
14876| [27703] Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
14877| [27409] Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
14878| [27365] Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
14879| [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
14880| [27236] Apache 'mod_proxy_balancer' Multiple Vulnerabilities
14881| [27234] Apache 'mod_proxy_ftp' Undefined Charset UTF-7 Cross-Site Scripting Vulnerability
14882| [27006] Apache Tomcat JULI Logging Component Default Security Policy Vulnerability
14883| [26939] Apache HTTP Server Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
14884| [26838] Apache mod_imagemap and mod_imap Cross-Site Scripting Vulnerability
14885| [26762] Apache::AuthCAS Cookie SQL Injection Vulnerability
14886| [26663] Apache HTTP Server 413 Error HTTP Request Method Cross-Site Scripting Weakness
14887| [26287] Apache Geronimo SQLLoginModule Authentication Bypass Vulnerability
14888| [26070] Apache Tomcat WebDav Remote Information Disclosure Vulnerability
14889| [25804] Apache Geronimo Management EJB Security Bypass Vulnerability
14890| [25653] Apache Mod_AutoIndex.C Undefined Charset Cross-Site Scripting Vulnerability
14891| [25531] Apache Tomcat Cal2.JSP Cross-Site Scripting Vulnerability
14892| [25489] Apache HTTP Server Mod_Proxy Denial of Service Vulnerability
14893| [25316] Apache Tomcat Multiple Remote Information Disclosure Vulnerabilities
14894| [25314] Apache Tomcat Host Manager Servlet Cross Site Scripting Vulnerability
14895| [25174] Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
14896| [24999] Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
14897| [24759] MySQLDumper Apache Access Control Authentication Bypass Vulnerability
14898| [24649] Apache HTTP Server Mod_Cache Denial of Service Vulnerability
14899| [24645] Apache HTTP Server Mod_Status Cross-Site Scripting Vulnerability
14900| [24553] Apache Mod_Mem_Cache Information Disclosure Vulnerability
14901| [24524] Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
14902| [24480] Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
14903| [24476] Apache Tomcat JSP Example Web Applications Cross Site Scripting Vulnerability
14904| [24475] Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
14905| [24215] Apache HTTP Server Worker Process Multiple Denial of Service Vulnerabilities
14906| [24147] Apache Tomcat JK Connector Double Encoding Security Bypass Vulnerability
14907| [24058] Apache Tomcat Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
14908| [23687] Apache AXIS Non-Existent WSDL Path Information Disclosure Vulnerability
14909| [23438] Apache HTTPD suEXEC Local Multiple Privilege Escalation Weaknesses
14910| [22960] Apache HTTP Server Tomcat Directory Traversal Vulnerability
14911| [22849] Apache mod_python Output Filter Mode Information Disclosure Vulnerability
14912| [22791] Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability
14913| [22732] Debian Apache Root Shell Local Privilege Escalation Vulnerabilities
14914| [22388] Apache Stats Extract Function Multiple Input Validation Vulnerabilities
14915| [21865] Apache And Microsoft IIS Range Denial of Service Vulnerability
14916| [21214] Apache Mod_Auth_Kerb Off-By-One Denial of Service Vulnerability
14917| [20527] Apache Mod_TCL Remote Format String Vulnerability
14918| [19661] Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
14919| [19447] Apache CGI Script Source Code Information Disclosure Vulnerability
14920| [19204] Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
14921| [19106] Apache Tomcat Information Disclosure Vulnerability
14922| [18138] Apache James SMTP Denial Of Service Vulnerability
14923| [17342] Apache Struts Multiple Remote Vulnerabilities
14924| [17095] Apache Log4Net Denial Of Service Vulnerability
14925| [16916] Apache mod_python FileSession Code Execution Vulnerability
14926| [16710] Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
14927| [16260] Apache Geronimo Multiple Input Validation Vulnerabilities
14928| [16153] Apache mod_auth_pgsql Multiple Format String Vulnerabilities
14929| [16152] Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
14930| [15834] Apache 'mod_imap' Referer Cross-Site Scripting Vulnerability
14931| [15765] Apache James Spooler Memory Leak Denial Of Service Vulnerability
14932| [15762] Apache MPM Worker.C Denial Of Service Vulnerability
14933| [15512] Apache Struts Error Response Cross-Site Scripting Vulnerability
14934| [15413] PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
14935| [15325] Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
14936| [15224] Apache Mod_Auth_Shadow Authentication Bypass Vulnerability
14937| [15177] PHP Apache 2 Local Denial of Service Vulnerability
14938| [14982] ApacheTop Insecure Temporary File Creation Vulnerability
14939| [14721] Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
14940| [14660] Apache CGI Byterange Request Denial of Service Vulnerability
14941| [14366] Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
14942| [14106] Apache HTTP Request Smuggling Vulnerability
14943| [13778] Apache HTPasswd Password Command Line Argument Buffer Overflow Vulnerability
14944| [13777] Apache HTPasswd User Command Line Argument Buffer Overflow Vulnerability
14945| [13756] Apache Tomcat Java Security Manager Bypass Vulnerability
14946| [13537] Apache HTDigest Realm Command Line Argument Buffer Overflow Vulnerability
14947| [12877] Apache mod_ssl ssl_io_filter_cleanup Remote Denial Of Service Vulnerability
14948| [12795] Apache Tomcat Remote Malformed Request Denial Of Service Vulnerability
14949| [12619] Apache Software Foundation Batik Squiggle Browser Access Validation Vulnerability
14950| [12519] Apache mod_python Module Publisher Handler Information Disclosure Vulnerability
14951| [12308] Apache Utilities Insecure Temporary File Creation Vulnerability
14952| [12217] Apache mod_auth_radius Malformed RADIUS Server Reply Integer Overflow Vulnerability
14953| [12181] Mod_DOSEvasive Apache Module Local Insecure Temporary File Creation Vulnerability
14954| [11803] Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
14955| [11471] Apache mod_include Local Buffer Overflow Vulnerability
14956| [11360] Apache mod_ssl SSLCipherSuite Restriction Bypass Vulnerability
14957| [11239] Apache Satisfy Directive Access Control Bypass Vulnerability
14958| [11187] Apache Web Server Remote IPv6 Buffer Overflow Vulnerability
14959| [11185] Apache Mod_DAV LOCK Denial Of Service Vulnerability
14960| [11182] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
14961| [11154] Apache mod_ssl Remote Denial of Service Vulnerability
14962| [11094] Apache mod_ssl Denial Of Service Vulnerability
14963| [10789] Apache mod_userdir Module Information Disclosure Vulnerability
14964| [10736] Apache 'mod_ssl' Log Function Format String Vulnerability
14965| [10619] Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
14966| [10508] Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow Vulnerability
14967| [10478] ClueCentral Apache Suexec Patch Security Weakness
14968| [10355] Apache 'mod_ssl' 'ssl_util_uuencode_binary()' Stack Buffer Overflow Vulnerability
14969| [10212] Apache mod_auth Malformed Password Potential Memory Corruption Vulnerability
14970| [9933] Apache mod_disk_cache Module Client Authentication Credential Storage Weakness
14971| [9930] Apache Error and Access Logs Escape Sequence Injection Vulnerability
14972| [9921] Apache Connection Blocking Denial Of Service Vulnerability
14973| [9885] Apache Mod_Security Module SecFilterScanPost Off-By-One Buffer Overflow Vulnerability
14974| [9874] Apache HTAccess LIMIT Directive Bypass Configuration Error Weakness
14975| [9829] Apache Mod_Access Access Control Rule Bypass Vulnerability
14976| [9826] Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
14977| [9733] Apache Cygwin Directory Traversal Vulnerability
14978| [9599] Apache mod_php Global Variables Information Disclosure Weakness
14979| [9590] Apache-SSL Client Certificate Forging Vulnerability
14980| [9571] Apache mod_digest Client-Supplied Nonce Verification Vulnerability
14981| [9471] Apache mod_perl Module File Descriptor Leakage Vulnerability
14982| [9404] Mod-Auth-Shadow Apache Module Expired User Credential Weakness
14983| [9302] Apache mod_php Module File Descriptor Leakage Vulnerability
14984| [9129] Apache mod_python Module Malformed Query Denial of Service Vulnerability
14985| [8926] Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
14986| [8919] Apache Mod_Security Module Heap Corruption Vulnerability
14987| [8911] Apache Web Server Multiple Module Local Buffer Overflow Vulnerability
14988| [8898] Red Hat Apache Directory Index Default Configuration Error
14989| [8883] Apache Cocoon Directory Traversal Vulnerability
14990| [8824] Apache Tomcat Non-HTTP Request Denial Of Service Vulnerability
14991| [8822] Apache Mod_Throttle Module Local Shared Memory Corruption Vulnerability
14992| [8725] Apache2 MOD_CGI STDERR Denial Of Service Vulnerability
14993| [8707] Apache htpasswd Password Entropy Weakness
14994| [8561] Apache::Gallery Insecure Local File Storage Privilege Escalation Vulnerability
14995| [8287] Mod_Mylo Apache Module REQSTR Buffer Overflow Vulnerability
14996| [8226] Apache HTTP Server Multiple Vulnerabilities
14997| [8138] Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
14998| [8137] Apache Web Server Prefork MPM Denial Of Service Vulnerability
14999| [8136] Macromedia Apache Web Server Encoded Space Source Disclosure Vulnerability
15000| [8135] Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
15001| [8134] Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness
15002| [7768] Apache Tomcat Insecure Directory Permissions Vulnerability
15003| [7725] Apache Basic Authentication Module Valid User Login Denial Of Service Vulnerability
15004| [7723] Apache APR_PSPrintf Memory Corruption Vulnerability
15005| [7448] Apache Mod_Auth_Any Remote Command Execution Vulnerability
15006| [7375] Apache Mod_Access_Referer NULL Pointer Dereference Denial of Service Vulnerability
15007| [7332] Apache Web Server OS2 Filestat Denial Of Service Vulnerability
15008| [7255] Apache Web Server File Descriptor Leakage Vulnerability
15009| [7254] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
15010| [6943] Apache Web Server MIME Boundary Information Disclosure Vulnerability
15011| [6939] Apache Web Server ETag Header Information Disclosure Weakness
15012| [6722] Apache Tomcat Web.XML File Contents Disclosure Vulnerability
15013| [6721] Apache Tomcat Null Byte Directory/File Disclosure Vulnerability
15014| [6720] Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
15015| [6662] Apache Web Server MS-DOS Device Name Denial Of Service Vulnerability
15016| [6661] Apache Web Server Default Script Mapping Bypass Vulnerability
15017| [6660] Apache Web Server Illegal Character HTTP Request File Disclosure Vulnerability
15018| [6659] Apache Web Server MS-DOS Device Name Arbitrary Code Execution Vulnerability
15019| [6562] Apache Tomcat Invoker Servlet File Disclosure Vulnerability
15020| [6320] Apache/Tomcat Mod_JK Chunked Encoding Denial Of Service Vulnerability
15021| [6117] Apache mod_php File Descriptor Leakage Vulnerability
15022| [6065] Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
15023| [5996] Apache AB.C Web Benchmarking Buffer Overflow Vulnerability
15024| [5995] Apache AB.C Web Benchmarking Read_Connection() Buffer Overflow Vulnerability
15025| [5993] Multiple Apache HTDigest Buffer Overflow Vulnerabilities
15026| [5992] Apache HTDigest Insecure Temporary File Vulnerability
15027| [5991] Apache HTDigest Arbitrary Command Execution Vulnerability
15028| [5990] Apache HTPasswd Insecure Temporary File Vulnerability
15029| [5981] Multiple Apache HTDigest and HTPassWD Component Vulnerabilites
15030| [5884] Apache Web Server Scoreboard Memory Segment Overwriting SIGUSR1 Sending Vulnerability
15031| [5847] Apache Server Side Include Cross Site Scripting Vulnerability
15032| [5838] Apache Tomcat 3.2 Directory Disclosure Vulnerability
15033| [5816] Apache 2 mod_dav Denial Of Service Vulnerability
15034| [5791] HP VirtualVault Apache mod_ssl Denial Of Service Vulnerability
15035| [5787] Apache Oversized STDERR Buffer Denial Of Service Vulnerability
15036| [5786] Apache Tomcat DefaultServlet File Disclosure Vulnerability
15037| [5542] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
15038| [5486] Apache 2.0 CGI Path Disclosure Vulnerability
15039| [5485] Apache 2.0 Path Disclosure Vulnerability
15040| [5434] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
15041| [5256] Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
15042| [5194] Apache Tomcat DOS Device Name Cross Site Scripting Vulnerability
15043| [5193] Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
15044| [5067] Apache Tomcat Null Character Malformed Request Denial Of Service Vulnerability
15045| [5054] Apache Tomcat Web Root Path Disclosure Vulnerability
15046| [5033] Apache Chunked-Encoding Memory Corruption Vulnerability
15047| [4995] Apache Tomcat JSP Engine Denial of Service Vulnerability
15048| [4878] Apache Tomcat RealPath.JSP Malformed Request Information Disclosure Vulnerability
15049| [4877] Apache Tomcat Example Files Web Root Path Disclosure Vulnerability
15050| [4876] Apache Tomcat Source.JSP Malformed Request Information Disclosure Vulnerability
15051| [4575] Apache Tomcat Servlet Path Disclosure Vulnerability
15052| [4557] Apache Tomcat System Path Information Disclosure Vulnerability
15053| [4437] Apache Error Message Cross-Site Scripting Vulnerability
15054| [4431] Apache PrintEnv/Test_CGI Script Injection Vulnerability
15055| [4358] Apache Double-Reverse Lookup Log Entry Spoofing Vulnerability
15056| [4335] Apache Win32 Batch File Remote Command Execution Vulnerability
15057| [4292] Oracle 9iAS Apache PL/SQL Module Web Administration Access Vulnerability
15058| [4189] Apache mod_ssl/Apache-SSL Buffer Overflow Vulnerability
15059| [4057] Apache 2 for Windows OPTIONS request Path Disclosure Vulnerability
15060| [4056] Apache 2 for Windows php.exe Path Disclosure Vulnerability
15061| [4037] Oracle 9iAS Apache PL/SQL Module Denial of Service Vulnerability
15062| [4032] Oracle 9iAS Apache PL/SQL Module Multiple Buffer Overflows Vulnerability
15063| [3796] Apache HTTP Request Unexpected Behavior Vulnerability
15064| [3790] Apache Non-Existent Log Directory Denial Of Service Vulnerability
15065| [3786] Apache Win32 PHP.EXE Remote File Disclosure Vulnerability
15066| [3727] Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
15067| [3726] Oracle 9I Application Server PL/SQL Apache Module Buffer Overflow Vulnerability
15068| [3596] Apache Split-Logfile File Append Vulnerability
15069| [3521] Apache mod_usertrack Predictable ID Generation Vulnerability
15070| [3335] Red Hat Linux Apache Remote Username Enumeration Vulnerability
15071| [3316] MacOS X Client Apache Directory Contents Disclosure Vulnerability
15072| [3256] Apache mod_auth_oracle Remote SQL Query Manipulation Vulnerability
15073| [3255] Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
15074| [3254] Apache AuthPG Remote SQL Query Manipulation Vulnerability
15075| [3253] Apache mod_auth_pgsql_sys Remote SQL Query Manipulation Vulnerability
15076| [3251] Apache mod_auth_pgsql Remote SQL Query Manipulation Vulnerability
15077| [3176] Apache Mod ReWrite Rules Bypassing Image Linking Vulnerability
15078| [3169] Apache Server Address Disclosure Vulnerability
15079| [3009] Apache Possible Directory Index Disclosure Vulnerability
15080| [2982] Apache Tomcat Cross-Site Scripting Vulnerability
15081| [2852] MacOS X Client Apache File Protection Bypass Vulnerability
15082| [2740] Apache Web Server HTTP Request Denial of Service Vulnerability
15083| [2518] Apache Tomcat 3.0 Directory Traversal Vulnerability
15084| [2503] Apache Artificially Long Slash Path Directory Listing Vulnerability
15085| [2300] NCSA/Apache httpd ScriptAlias Source Retrieval Vulnerability
15086| [2216] Apache Web Server DoS Vulnerability
15087| [2182] Apache /tmp File Race Vulnerability
15088| [2171] Oracle Apache+WebDB Documented Backdoor Vulnerability
15089| [2060] Apache Web Server with Php 3 File Disclosure Vulnerability
15090| [1821] Apache mod_cookies Buffer Overflow Vulnerability
15091| [1728] Apache Rewrite Module Arbitrary File Disclosure Vulnerability
15092| [1658] SuSE Apache CGI Source Code Viewing Vulnerability
15093| [1656] SuSE Apache WebDAV Directory Listings Vulnerability
15094| [1575] Trustix Apache-SSL RPM Permissions Vulnerability
15095| [1548] Apache Jakarta-Tomcat /admin Context Vulnerability
15096| [1532] Apache Tomcat Snoop Servlet Information Disclosure Vulnerability
15097| [1531] Apache Tomcat 3.1 Path Revealing Vulnerability
15098| [1457] Apache::ASP source.asp Example Script Vulnerability
15099| [1284] Apache HTTP Server (win32) Root Directory Access Vulnerability
15100| [1083] Cobalt Raq Apache .htaccess Disclosure Vulnerability
15101|
15102| IBM X-Force - https://exchange.xforce.ibmcloud.com:
15103| [86258] Apache CloudStack text fields cross-site scripting
15104| [85983] Apache Subversion mod_dav_svn module denial of service
15105| [85875] Apache OFBiz UEL code execution
15106| [85874] Apache OFBiz Webtools View Log screen cross-site scripting
15107| [85871] Apache HTTP Server mod_session_dbd unspecified
15108| [85756] Apache Struts OGNL expression command execution
15109| [85755] Apache Struts DefaultActionMapper class open redirect
15110| [85586] Apache ActiveMQ CVE-2013-1879 cross-site scripting
15111| [85574] Apache HTTP Server mod_dav denial of service
15112| [85573] Apache Struts Showcase App OGNL code execution
15113| [85496] Apache CXF denial of service
15114| [85423] Apache Geronimo RMI classloader code execution
15115| [85326] Apache Santuario XML Security for C++ buffer overflow
15116| [85323] Apache Santuario XML Security for Java spoofing
15117| [85319] Apache Qpid Python client SSL spoofing
15118| [85019] Apache Santuario XML Security for C++ CVE-2013-2156 buffer overflow
15119| [85018] Apache Santuario XML Security for C++ CVE-2013-2155 denial of service
15120| [85017] Apache Santuario XML Security for C++ CVE-2013-2154 buffer overflow
15121| [85016] Apache Santuario XML Security for C++ CVE-2013-2153 spoofing
15122| [84952] Apache Tomcat CVE-2012-3544 denial of service
15123| [84763] Apache Struts CVE-2013-2135 security bypass
15124| [84762] Apache Struts CVE-2013-2134 security bypass
15125| [84719] Apache Subversion CVE-2013-2088 command execution
15126| [84718] Apache Subversion CVE-2013-2112 denial of service
15127| [84717] Apache Subversion CVE-2013-1968 denial of service
15128| [84577] Apache Tomcat security bypass
15129| [84576] Apache Tomcat symlink
15130| [84543] Apache Struts CVE-2013-2115 security bypass
15131| [84542] Apache Struts CVE-2013-1966 security bypass
15132| [84154] Apache Tomcat session hijacking
15133| [84144] Apache Tomcat denial of service
15134| [84143] Apache Tomcat information disclosure
15135| [84111] Apache HTTP Server command execution
15136| [84043] Apache Virtual Computing Lab cross-site scripting
15137| [84042] Apache Virtual Computing Lab cross-site scripting
15138| [83782] Apache CloudStack information disclosure
15139| [83781] Apache CloudStack security bypass
15140| [83720] Apache ActiveMQ cross-site scripting
15141| [83719] Apache ActiveMQ denial of service
15142| [83718] Apache ActiveMQ denial of service
15143| [83263] Apache Subversion denial of service
15144| [83262] Apache Subversion denial of service
15145| [83261] Apache Subversion denial of service
15146| [83259] Apache Subversion denial of service
15147| [83035] Apache mod_ruid2 security bypass
15148| [82852] Apache Qpid federation_tag security bypass
15149| [82851] Apache Qpid qpid::framing::Buffer denial of service
15150| [82758] Apache Rave User RPC API information disclosure
15151| [82663] Apache Subversion svn_fs_file_length() denial of service
15152| [82642] Apache Qpid qpid::framing::Buffer::checkAvailable() denial of service
15153| [82641] Apache Qpid AMQP denial of service
15154| [82626] Apache HTTP Server on Debian GNU/Linux Debian apache2ctl symlink
15155| [82618] Apache Commons FileUpload symlink
15156| [82360] Apache HTTP Server manager interface cross-site scripting
15157| [82359] Apache HTTP Server hostnames cross-site scripting
15158| [82338] Apache Tomcat log/logdir information disclosure
15159| [82328] Apache Maven and Apache Maven Wagon SSL spoofing
15160| [82268] Apache OpenJPA deserialization command execution
15161| [81981] Apache CXF UsernameTokens security bypass
15162| [81980] Apache CXF WS-Security security bypass
15163| [81398] Apache OFBiz cross-site scripting
15164| [81240] Apache CouchDB directory traversal
15165| [81226] Apache CouchDB JSONP code execution
15166| [81225] Apache CouchDB Futon user interface cross-site scripting
15167| [81211] Apache Axis2/C SSL spoofing
15168| [81167] Apache CloudStack DeployVM information disclosure
15169| [81166] Apache CloudStack AddHost API information disclosure
15170| [81165] Apache CloudStack createSSHKeyPair API information disclosure
15171| [80518] Apache Tomcat cross-site request forgery security bypass
15172| [80517] Apache Tomcat FormAuthenticator security bypass
15173| [80516] Apache Tomcat NIO denial of service
15174| [80408] Apache Tomcat replay-countermeasure security bypass
15175| [80407] Apache Tomcat HTTP Digest Access Authentication security bypass
15176| [80317] Apache Tomcat slowloris denial of service
15177| [79984] Apache Commons HttpClient SSL spoofing
15178| [79983] Apache CXF SSL spoofing
15179| [79830] Apache Axis2/Java SSL spoofing
15180| [79829] Apache Axis SSL spoofing
15181| [79809] Apache Tomcat DIGEST security bypass
15182| [79806] Apache Tomcat parseHeaders() denial of service
15183| [79540] Apache OFBiz unspecified
15184| [79487] Apache Axis2 SAML security bypass
15185| [79212] Apache Cloudstack code execution
15186| [78734] Apache CXF SOAP Action security bypass
15187| [78730] Apache Qpid broker denial of service
15188| [78617] Eucalyptus Apache Santuario (XML Security for Java) denial of service
15189| [78563] Apache mod_pagespeed module unspecified cross-site scripting
15190| [78562] Apache mod_pagespeed module security bypass
15191| [78454] Apache Axis2 security bypass
15192| [78452] Websense Web Security and Web Filter Apache Tomcat information disclosure
15193| [78451] Websense Web Security and Web Filter Apache Tomcat cross-site scripting
15194| [78321] Apache Wicket unspecified cross-site scripting
15195| [78183] Apache Struts parameters denial of service
15196| [78182] Apache Struts cross-site request forgery
15197| [78153] Apache Solr Autocomplete module for Drupal autocomplete results cross-site scripting
15198| [77987] mod_rpaf module for Apache denial of service
15199| [77958] Apache Struts skill name code execution
15200| [77914] Apache HTTP Server mod_negotiation module cross-site scripting
15201| [77913] Apache HTTP Server mod_proxy_ajp information disclosure
15202| [77568] Apache Qpid broker security bypass
15203| [77421] Apache Libcloud spoofing
15204| [77059] Oracle Solaris Cluster Apache Tomcat Agent unspecified
15205| [77046] Oracle Solaris Apache HTTP Server information disclosure
15206| [76837] Apache Hadoop information disclosure
15207| [76802] Apache Sling CopyFrom denial of service
15208| [76692] Apache Hadoop symlink
15209| [76535] Apache Roller console cross-site request forgery
15210| [76534] Apache Roller weblog cross-site scripting
15211| [76152] Apache CXF elements security bypass
15212| [76151] Apache CXF child policies security bypass
15213| [75983] MapServer for Windows Apache file include
15214| [75857] Apache Commons Compress and Apache Ant bzip2 denial of service
15215| [75558] Apache POI denial of service
15216| [75545] PHP apache_request_headers() buffer overflow
15217| [75302] Apache Qpid SASL security bypass
15218| [75211] Debian GNU/Linux apache 2 cross-site scripting
15219| [74901] Apache HTTP Server LD_LIBRARY_PATH privilege escalation
15220| [74871] Apache OFBiz FlexibleStringExpander code execution
15221| [74870] Apache OFBiz multiple cross-site scripting
15222| [74750] Apache Hadoop unspecified spoofing
15223| [74319] Apache Struts XSLTResult.java file upload
15224| [74313] Apache Traffic Server header buffer overflow
15225| [74276] Apache Wicket directory traversal
15226| [74273] Apache Wicket unspecified cross-site scripting
15227| [74181] Apache HTTP Server mod_fcgid module denial of service
15228| [73690] Apache Struts OGNL code execution
15229| [73432] Apache Solr extension for TYPO3 unspecified cross-site scripting
15230| [73100] Apache MyFaces in directory traversal
15231| [73096] Apache APR hash denial of service
15232| [73052] Apache Struts name cross-site scripting
15233| [73030] Apache CXF UsernameToken security bypass
15234| [72888] Apache Struts lastName cross-site scripting
15235| [72758] Apache HTTP Server httpOnly information disclosure
15236| [72757] Apache HTTP Server MPM denial of service
15237| [72585] Apache Struts ParameterInterceptor security bypass
15238| [72438] Apache Tomcat Digest security bypass
15239| [72437] Apache Tomcat Digest security bypass
15240| [72436] Apache Tomcat DIGEST security bypass
15241| [72425] Apache Tomcat parameter denial of service
15242| [72422] Apache Tomcat request object information disclosure
15243| [72377] Apache HTTP Server scoreboard security bypass
15244| [72345] Apache HTTP Server HTTP request denial of service
15245| [72229] Apache Struts ExceptionDelegator command execution
15246| [72089] Apache Struts ParameterInterceptor directory traversal
15247| [72088] Apache Struts CookieInterceptor command execution
15248| [72047] Apache Geronimo hash denial of service
15249| [72016] Apache Tomcat hash denial of service
15250| [71711] Apache Struts OGNL expression code execution
15251| [71654] Apache Struts interfaces security bypass
15252| [71620] Apache ActiveMQ failover denial of service
15253| [71617] Apache HTTP Server mod_proxy module information disclosure
15254| [71508] Apache MyFaces EL security bypass
15255| [71445] Apache HTTP Server mod_proxy security bypass
15256| [71203] Apache Tomcat servlets privilege escalation
15257| [71181] Apache HTTP Server ap_pregsub() denial of service
15258| [71093] Apache HTTP Server ap_pregsub() buffer overflow
15259| [70336] Apache HTTP Server mod_proxy information disclosure
15260| [69804] Apache HTTP Server mod_proxy_ajp denial of service
15261| [69472] Apache Tomcat AJP security bypass
15262| [69396] Apache HTTP Server ByteRange filter denial of service
15263| [69394] Apache Wicket multi window support cross-site scripting
15264| [69176] Apache Tomcat XML information disclosure
15265| [69161] Apache Tomcat jsvc information disclosure
15266| [68799] mod_authnz_external module for Apache mysql-auth.pl SQL injection
15267| [68541] Apache Tomcat sendfile information disclosure
15268| [68420] Apache XML Security denial of service
15269| [68238] Apache Tomcat JMX information disclosure
15270| [67860] Apache Rampart/C rampart_timestamp_token_validate security bypass
15271| [67804] Apache Subversion control rules information disclosure
15272| [67803] Apache Subversion control rules denial of service
15273| [67802] Apache Subversion baselined denial of service
15274| [67672] Apache Archiva multiple cross-site scripting
15275| [67671] Apache Archiva multiple cross-site request forgery
15276| [67564] Apache APR apr_fnmatch() denial of service
15277| [67532] IBM WebSphere Application Server org.apache.jasper.runtime.JspWriterImpl.response denial of service
15278| [67515] Apache Tomcat annotations security bypass
15279| [67480] Apache Struts s:submit information disclosure
15280| [67414] Apache APR apr_fnmatch() denial of service
15281| [67356] Apache Struts javatemplates cross-site scripting
15282| [67354] Apache Struts Xwork cross-site scripting
15283| [66676] Apache Tomcat HTTP BIO information disclosure
15284| [66675] Apache Tomcat web.xml security bypass
15285| [66640] Apache HttpComponents HttpClient Proxy-Authorization information disclosure
15286| [66241] Apache HttpComponents information disclosure
15287| [66154] Apache Tomcat ServletSecurity security bypass
15288| [65971] Apache Tomcat ServletSecurity security bypass
15289| [65876] Apache Subversion mod_dav_svn denial of service
15290| [65343] Apache Continuum unspecified cross-site scripting
15291| [65162] Apache Tomcat NIO connector denial of service
15292| [65161] Apache Tomcat javax.servlet.ServletRequest.getLocale() denial of service
15293| [65160] Apache Tomcat HTML Manager interface cross-site scripting
15294| [65159] Apache Tomcat ServletContect security bypass
15295| [65050] Apache CouchDB web-based administration UI cross-site scripting
15296| [64773] Oracle HTTP Server Apache Plugin unauthorized access
15297| [64473] Apache Subversion blame -g denial of service
15298| [64472] Apache Subversion walk() denial of service
15299| [64407] Apache Axis2 CVE-2010-0219 code execution
15300| [63926] Apache Archiva password privilege escalation
15301| [63785] Apache CouchDB LD_LIBRARY_PATH privilege escalation
15302| [63493] Apache Archiva credentials cross-site request forgery
15303| [63477] Apache Tomcat HttpOnly session hijacking
15304| [63422] Apache Tomcat sessionsList.jsp cross-site scripting
15305| [63303] Apache mod_fcgid module fcgid_header_bucket_read() buffer overflow
15306| [62959] Apache Shiro filters security bypass
15307| [62790] Apache Perl cgi module denial of service
15308| [62576] Apache Qpid exchange denial of service
15309| [62575] Apache Qpid AMQP denial of service
15310| [62354] Apache Qpid SSL denial of service
15311| [62235] Apache APR-util apr_brigade_split_line() denial of service
15312| [62181] Apache XML-RPC SAX Parser information disclosure
15313| [61721] Apache Traffic Server cache poisoning
15314| [61202] Apache Derby BUILTIN authentication functionality information disclosure
15315| [61186] Apache CouchDB Futon cross-site request forgery
15316| [61169] Apache CXF DTD denial of service
15317| [61070] Apache Jackrabbit search.jsp SQL injection
15318| [61006] Apache SLMS Quoting cross-site request forgery
15319| [60962] Apache Tomcat time cross-site scripting
15320| [60883] Apache mod_proxy_http information disclosure
15321| [60671] Apache HTTP Server mod_cache and mod_dav denial of service
15322| [60264] Apache Tomcat Transfer-Encoding denial of service
15323| [59746] Apache Axis2 axis2/axis2-admin page session hijacking
15324| [59588] Apache Axis2/Java XML DTD (Document Type Declaration) data denial of service
15325| [59413] Apache mod_proxy_http timeout information disclosure
15326| [59058] Apache MyFaces unencrypted view state cross-site scripting
15327| [58827] Apache Axis2 xsd file include
15328| [58790] Apache Axis2 modules cross-site scripting
15329| [58299] Apache ActiveMQ queueBrowse cross-site scripting
15330| [58169] Apache Tomcat Web Application Manager / Host Manager cross-site request forgery
15331| [58056] Apache ActiveMQ .jsp source code disclosure
15332| [58055] Apache Tomcat realm name information disclosure
15333| [58046] Apache HTTP Server mod_auth_shadow security bypass
15334| [57841] Apache Open For Business Project (OFBiz) subject cross-site scripting
15335| [57840] Apache Open For Business Project (OFBiz) multiple parameters cross-site scripting
15336| [57429] Apache CouchDB algorithms information disclosure
15337| [57398] Apache ActiveMQ Web console cross-site request forgery
15338| [57397] Apache ActiveMQ createDestination.action cross-site scripting
15339| [56653] Apache HTTP Server DNS spoofing
15340| [56652] Apache HTTP Server DNS cross-site scripting
15341| [56625] Apache HTTP Server request header information disclosure
15342| [56624] Apache HTTP Server mod_isapi orphaned callback pointer code execution
15343| [56623] Apache HTTP Server mod_proxy_ajp denial of service
15344| [55941] mod_proxy module for Apache ap_proxy_send_fb() buffer overflow
15345| [55857] Apache Tomcat WAR files directory traversal
15346| [55856] Apache Tomcat autoDeploy attribute security bypass
15347| [55855] Apache Tomcat WAR directory traversal
15348| [55210] Intuit component for Joomla! Apache information disclosure
15349| [54533] Apache Tomcat 404 error page cross-site scripting
15350| [54182] Apache Tomcat admin default password
15351| [53878] Apache Solr Search (solr) extension for TYPO3 unspecified cross-site scripting
15352| [53666] Apache HTTP Server Solaris pollset support denial of service
15353| [53650] Apache HTTP Server HTTP basic-auth module security bypass
15354| [53124] mod_proxy_ftp module for Apache HTTP header security bypass
15355| [53041] mod_proxy_ftp module for Apache denial of service
15356| [52540] Apache Portable Runtime and Apache Portable Utility library multiple buffer overflow
15357| [51953] Apache Tomcat Path Disclosure
15358| [51952] Apache Tomcat Path Traversal
15359| [51951] Apache stronghold-status Information Disclosure
15360| [51950] Apache stronghold-info Information Disclosure
15361| [51949] Apache PHP Source Code Disclosure
15362| [51948] Apache Multiviews Attack
15363| [51946] Apache JServ Environment Status Information Disclosure
15364| [51945] Apache error_log Information Disclosure
15365| [51944] Apache Default Installation Page Pattern Found
15366| [51943] Apache AXIS XML Parser echoheaders.jws Sample Web Service Denial of Service
15367| [51942] Apache AXIS XML External Entity File Retrieval
15368| [51941] Apache AXIS Sample Servlet Information Leak
15369| [51940] Apache access_log Information Disclosure
15370| [51626] Apache mod_deflate denial of service
15371| [51532] mod_proxy module for the Apache HTTP Server stream_reqbody_cl denial of service
15372| [51365] Apache Tomcat RequestDispatcher security bypass
15373| [51273] Apache HTTP Server Incomplete Request denial of service
15374| [51195] Apache Tomcat XML information disclosure
15375| [50994] Apache APR-util xml/apr_xml.c denial of service
15376| [50993] Apache APR-util apr_brigade_vprintf denial of service
15377| [50964] Apache APR-util apr_strmatch_precompile() denial of service
15378| [50930] Apache Tomcat j_security_check information disclosure
15379| [50928] Apache Tomcat AJP denial of service
15380| [50884] Apache HTTP Server XML ENTITY denial of service
15381| [50808] Apache HTTP Server AllowOverride privilege escalation
15382| [50108] Apache Struts s:a tag and s:url tag cross-site scripting
15383| [50059] Apache mod_proxy_ajp information disclosure
15384| [49951] Apache Tiles Expression Language (EL) expressions cross-site scripting
15385| [49925] Apache Geronimo Web Administrative Console cross-site request forgery
15386| [49924] Apache Geronimo console/portal/Server/Monitoring cross-site scripting
15387| [49921] Apache ActiveMQ Web interface cross-site scripting
15388| [49898] Apache Geronimo Services/Repository directory traversal
15389| [49725] Apache Tomcat mod_jk module information disclosure
15390| [49715] Apache mod_perl Apache::Status and Apache2::Status modules cross-site scripting
15391| [49712] Apache Struts unspecified cross-site scripting
15392| [49213] Apache Tomcat cal2.jsp cross-site scripting
15393| [48934] Apache Tomcat POST doRead method information disclosure
15394| [48211] Apache Tomcat header HTTP request smuggling
15395| [48163] libapache2-mod-auth-mysql module for Debian multibyte encoding SQL injection
15396| [48110] Apache Jackrabbit search.jsp and swr.jsp cross-site scripting
15397| [47709] Apache Roller "
15398| [47104] Novell Netware ApacheAdmin console security bypass
15399| [47086] Apache HTTP Server OS fingerprinting unspecified
15400| [46329] Apache Struts FilterDispatcher and DefaultStaticContentLoader class directory traversal
15401| [45791] Apache Tomcat RemoteFilterValve security bypass
15402| [44435] Oracle WebLogic Apache Connector buffer overflow
15403| [44411] Apache Tomcat allowLinking UTF-8 directory traversal
15404| [44223] Apache HTTP Server mod_proxy_ftp cross-site scripting
15405| [44156] Apache Tomcat RequestDispatcher directory traversal
15406| [44155] Apache Tomcat HttpServletResponse.sendError() cross-site scripting
15407| [43885] Oracle WebLogic Server Apache Connector buffer overflow
15408| [42987] Apache HTTP Server mod_proxy module denial of service
15409| [42915] Apache Tomcat JSP files path disclosure
15410| [42914] Apache Tomcat MS-DOS path disclosure
15411| [42892] Apache Tomcat unspecified unauthorized access
15412| [42816] Apache Tomcat Host Manager cross-site scripting
15413| [42303] Apache 403 error cross-site scripting
15414| [41618] Apache-SSL ExpandCert() authentication bypass
15415| [40761] Apache Derby RDBNAM parameter and DatabaseMetaData.getURL information disclosure
15416| [40736] Apache Tomcat HTTP/1.1 connector information disclosure
15417| [40614] Apache mod_jk2 HTTP Host header buffer overflow
15418| [40562] Apache Geronimo init information disclosure
15419| [40478] Novell Web Manager webadmin-apache.conf security bypass
15420| [40411] Apache Tomcat exception handling information disclosure
15421| [40409] Apache Tomcat native (APR based) connector weak security
15422| [40403] Apache Tomcat quotes and %5C cookie information disclosure
15423| [40388] Sun Java Plug-In org.apache.crimson.tree.XmlDocument security bypass
15424| [39893] Apache HTTP Server mod_negotiation HTTP response splitting
15425| [39867] Apache HTTP Server mod_negotiation cross-site scripting
15426| [39804] Apache Tomcat SingleSignOn information disclosure
15427| [39615] Apache HTTP Server mod_proxy_ftp.c UTF-7 cross-site scripting
15428| [39612] Apache HTTP Server mod_proxy_balancer buffer overflow
15429| [39608] Apache HTTP Server balancer manager cross-site request forgery
15430| [39476] Apache mod_proxy_balancer balancer_handler function denial of service
15431| [39474] Apache HTTP Server mod_proxy_balancer cross-site scripting
15432| [39472] Apache HTTP Server mod_status cross-site scripting
15433| [39201] Apache Tomcat JULI logging weak security
15434| [39158] Apache HTTP Server Windows SMB shares information disclosure
15435| [39001] Apache HTTP Server mod_imap and mod_imagemap module cross-site scripting
15436| [38951] Apache::AuthCAS Perl module cookie SQL injection
15437| [38800] Apache HTTP Server 413 error page cross-site scripting
15438| [38211] Apache Geronimo SQLLoginModule authentication bypass
15439| [37243] Apache Tomcat WebDAV directory traversal
15440| [37178] RHSA update for Apache HTTP Server mod_status module cross-site scripting not installed
15441| [37177] RHSA update for Apache HTTP Server Apache child process denial of service not installed
15442| [37119] RHSA update for Apache mod_auth_kerb off-by-one buffer overflow not installed
15443| [37100] RHSA update for Apache and IBM HTTP Server Expect header cross-site scripting not installed
15444| [36782] Apache Geronimo MEJB unauthorized access
15445| [36586] Apache HTTP Server UTF-7 cross-site scripting
15446| [36468] Apache Geronimo LoginModule security bypass
15447| [36467] Apache Tomcat functions.jsp cross-site scripting
15448| [36402] Apache Tomcat calendar cross-site request forgery
15449| [36354] Apache HTTP Server mod_proxy module denial of service
15450| [36352] Apache HTTP Server ap_proxy_date_canon() denial of service
15451| [36336] Apache Derby lock table privilege escalation
15452| [36335] Apache Derby schema privilege escalation
15453| [36006] Apache Tomcat "
15454| [36001] Apache Tomcat Host Manager Servlet alias cross-site scripting
15455| [35999] Apache Tomcat \"
15456| [35795] Apache Tomcat CookieExample cross-site scripting
15457| [35536] Apache Tomcat SendMailServlet example cross-site scripting
15458| [35384] Apache HTTP Server mod_cache module denial of service
15459| [35097] Apache HTTP Server mod_status module cross-site scripting
15460| [35095] Apache HTTP Server Prefork MPM module denial of service
15461| [34984] Apache HTTP Server recall_headers information disclosure
15462| [34966] Apache HTTP Server MPM content spoofing
15463| [34965] Apache HTTP Server MPM information disclosure
15464| [34963] Apache HTTP Server MPM multiple denial of service
15465| [34872] Apache MyFaces Tomahawk autoscroll parameter cross-site scripting
15466| [34869] Apache Tomcat JSP example Web application cross-site scripting
15467| [34868] Apache Tomcat Manager and Host Manager cross-site scripting
15468| [34496] Apache Tomcat JK Connector security bypass
15469| [34377] Apache Tomcat hello.jsp cross-site scripting
15470| [34212] Apache Tomcat SSL configuration security bypass
15471| [34210] Apache Tomcat Accept-Language cross-site scripting
15472| [34209] Apache Tomcat calendar application cross-site scripting
15473| [34207] Apache Tomcat implicit-objects.jsp cross-site scripting
15474| [34167] Apache Axis WSDL file path disclosure
15475| [34068] Apache Tomcat AJP connector information disclosure
15476| [33584] Apache HTTP Server suEXEC privilege escalation
15477| [32988] Apache Tomcat proxy module directory traversal
15478| [32794] Apache Tomcat JK Web Server Connector map_uri_to_worker() buffer overflow
15479| [32708] Debian Apache tty privilege escalation
15480| [32441] ApacheStats extract() PHP call unspecified
15481| [32128] Apache Tomcat default account
15482| [31680] Apache Tomcat RequestParamExample cross-site scripting
15483| [31649] Apache Tomcat Sample Servlet TroubleShooter detected
15484| [31557] BEA WebLogic Server and WebLogic Express Apache proxy plug-in denial of service
15485| [31236] Apache HTTP Server htpasswd.c strcpy buffer overflow
15486| [30456] Apache mod_auth_kerb off-by-one buffer overflow
15487| [29550] Apache mod_tcl set_var() format string
15488| [28620] Apache and IBM HTTP Server Expect header cross-site scripting
15489| [28357] Apache HTTP Server mod_alias script source information disclosure
15490| [28063] Apache mod_rewrite off-by-one buffer overflow
15491| [27902] Apache Tomcat URL information disclosure
15492| [26786] Apache James SMTP server denial of service
15493| [25680] libapache2 /tmp/svn file upload
15494| [25614] Apache Struts lookupMap cross-site scripting
15495| [25613] Apache Struts ActionForm denial of service
15496| [25612] Apache Struts isCancelled() security bypass
15497| [24965] Apache mod_python FileSession command execution
15498| [24716] Apache James spooler memory leak denial of service
15499| [24159] Apache Geronimo Web-Access-Log Viewer cross-site scripting
15500| [24158] Apache Geronimo jsp-examples cross-site scripting
15501| [24030] Apache auth_ldap module multiple format strings
15502| [24008] Apache mod_ssl custom error message denial of service
15503| [24003] Apache mod_auth_pgsql module multiple syslog format strings
15504| [23612] Apache mod_imap referer field cross-site scripting
15505| [23173] Apache Struts error message cross-site scripting
15506| [22942] Apache Tomcat directory listing denial of service
15507| [22858] Apache Multi-Processing Module code allows denial of service
15508| [22602] RHSA-2005:582 updates for Apache httpd not installed
15509| [22520] Apache mod-auth-shadow "
15510| [22466] ApacheTop symlink
15511| [22109] Apache HTTP Server ssl_engine_kernel client certificate validation
15512| [22006] Apache HTTP Server byte-range filter denial of service
15513| [21567] Apache mod_ssl off-by-one buffer overflow
15514| [21195] Apache HTTP Server header HTTP request smuggling
15515| [20383] Apache HTTP Server htdigest buffer overflow
15516| [19681] Apache Tomcat AJP12 request denial of service
15517| [18993] Apache HTTP server check_forensic symlink attack
15518| [18790] Apache Tomcat Manager cross-site scripting
15519| [18349] Apache HTTP server Apple HFS+ filesystem obtain information
15520| [18348] Apache HTTP server Apple HFS+ filesystem .DS_Store and .ht file disclosure
15521| [18347] Apache HTTP server Apple Mac OS X Server mod_digest_apple module could allow an attacker to replay responses
15522| [17961] Apache Web server ServerTokens has not been set
15523| [17930] Apache HTTP Server HTTP GET request denial of service
15524| [17785] Apache mod_include module buffer overflow
15525| [17671] Apache HTTP Server SSLCipherSuite bypass restrictions
15526| [17473] Apache HTTP Server Satisfy directive allows access to resources
15527| [17413] Apache htpasswd buffer overflow
15528| [17384] Apache HTTP Server environment variable configuration file buffer overflow
15529| [17382] Apache HTTP Server IPv6 apr_util denial of service
15530| [17366] Apache HTTP Server mod_dav module LOCK denial of service
15531| [17273] Apache HTTP Server speculative mode denial of service
15532| [17200] Apache HTTP Server mod_ssl denial of service
15533| [16890] Apache HTTP Server server-info request has been detected
15534| [16889] Apache HTTP Server server-status request has been detected
15535| [16705] Apache mod_ssl format string attack
15536| [16524] Apache HTTP Server ap_get_mime_headers_core denial of service
15537| [16387] Apache HTTP Server mod_proxy Content-Length buffer overflow
15538| [16230] Apache HTTP Server PHP denial of service
15539| [16214] Apache mod_ssl ssl_util_uuencode_binary buffer overflow
15540| [15958] Apache HTTP Server authentication modules memory corruption
15541| [15547] Apache HTTP Server mod_disk_cache local information disclosure
15542| [15540] Apache HTTP Server socket starvation denial of service
15543| [15467] Novell GroupWise WebAccess using Apache Web server allows viewing of files on the server
15544| [15422] Apache HTTP Server mod_access information disclosure
15545| [15419] Apache HTTP Server mod_ssl plain HTTP request denial of service
15546| [15293] Apache for Cygwin "
15547| [15065] Apache-SSL has a default password
15548| [15041] Apache HTTP Server mod_digest module could allow an attacker to replay responses
15549| [15015] Apache httpd server httpd.conf could allow a local user to bypass restrictions
15550| [14751] Apache Mod_python output filter information disclosure
15551| [14125] Apache HTTP Server mod_userdir module information disclosure
15552| [14075] Apache HTTP Server mod_php file descriptor leak
15553| [13703] Apache HTTP Server account
15554| [13689] Apache HTTP Server configuration allows symlinks
15555| [13688] Apache HTTP Server configuration allows SSI
15556| [13687] Apache HTTP Server Server: header value
15557| [13685] Apache HTTP Server ServerTokens value
15558| [13684] Apache HTTP Server ServerSignature value
15559| [13672] Apache HTTP Server config allows directory autoindexing
15560| [13671] Apache HTTP Server default content
15561| [13670] Apache HTTP Server config file directive references outside content root
15562| [13668] Apache HTTP Server httpd not running in chroot environment
15563| [13666] Apache HTTP Server CGI directory contains possible command interpreter or compiler
15564| [13664] Apache HTTP Server config file contains ScriptAlias entry
15565| [13663] Apache HTTP Server CGI support modules loaded
15566| [13661] Apache HTTP Server config file contains AddHandler entry
15567| [13660] Apache HTTP Server 500 error page not CGI script
15568| [13659] Apache HTTP Server 413 error page not CGI script
15569| [13658] Apache HTTP Server 403 error page not CGI script
15570| [13657] Apache HTTP Server 401 error page not CGI script
15571| [13552] Apache HTTP Server mod_cgid module information disclosure
15572| [13550] Apache GET request directory traversal
15573| [13516] Apache Cocoon XMLForm and JXForm could allow execution of code
15574| [13499] Apache Cocoon directory traversal allows downloading of boot.ini file
15575| [13429] Apache Tomcat non-HTTP request denial of service
15576| [13400] Apache HTTP server mod_alias and mod_rewrite buffer overflow
15577| [13295] Apache weak password encryption
15578| [13254] Apache Tomcat .jsp cross-site scripting
15579| [13125] Apache::Gallery Inline::C could allow arbitrary code execution
15580| [13086] Apache Jakarta Tomcat mod_jk format string allows remote access
15581| [12681] Apache HTTP Server mod_proxy could allow mail relaying
15582| [12662] Apache HTTP Server rotatelogs denial of service
15583| [12554] Apache Tomcat stores password in plain text
15584| [12553] Apache HTTP Server redirects and subrequests denial of service
15585| [12552] Apache HTTP Server FTP proxy server denial of service
15586| [12551] Apache HTTP Server prefork MPM denial of service
15587| [12550] Apache HTTP Server weaker than expected encryption
15588| [12549] Apache HTTP Server type-map file denial of service
15589| [12206] Apache Tomcat /opt/tomcat directory insecure permissions
15590| [12102] Apache Jakarta Tomcat MS-DOS device name request denial of service
15591| [12091] Apache HTTP Server apr_password_validate denial of service
15592| [12090] Apache HTTP Server apr_psprintf code execution
15593| [11804] Apache HTTP Server mod_access_referer denial of service
15594| [11750] Apache HTTP Server could leak sensitive file descriptors
15595| [11730] Apache HTTP Server error log and access log terminal escape sequence injection
15596| [11703] Apache long slash path allows directory listing
15597| [11695] Apache HTTP Server LF (Line Feed) denial of service
15598| [11694] Apache HTTP Server filestat.c denial of service
15599| [11438] Apache HTTP Server MIME message boundaries information disclosure
15600| [11412] Apache HTTP Server error log terminal escape sequence injection
15601| [11196] Apache Tomcat examples and ROOT Web applications cross-site scripting
15602| [11195] Apache Tomcat web.xml could be used to read files
15603| [11194] Apache Tomcat URL appended with a null character could list directories
15604| [11139] Apache HTTP Server mass virtual hosting with mod_rewrite or mod_vhost_alias could allow an attacker to obtain files
15605| [11126] Apache HTTP Server illegal character file disclosure
15606| [11125] Apache HTTP Server DOS device name HTTP POST code execution
15607| [11124] Apache HTTP Server DOS device name denial of service
15608| [11088] Apache HTTP Server mod_vhost_alias CGI source disclosure
15609| [10938] Apache HTTP Server printenv test CGI cross-site scripting
15610| [10771] Apache Tomcat mod_jk module multiple HTTP GET request buffer overflow
15611| [10575] Apache mod_php module could allow an attacker to take over the httpd process
15612| [10499] Apache HTTP Server WebDAV HTTP POST view source
15613| [10457] Apache HTTP Server mod_ssl "
15614| [10415] Apache HTTP Server htdigest insecure system() call could allow command execution
15615| [10414] Apache HTTP Server htdigest multiple buffer overflows
15616| [10413] Apache HTTP Server htdigest temporary file race condition
15617| [10412] Apache HTTP Server htpasswd temporary file race condition
15618| [10376] Apache Tomcat invoker servlet used in conjunction with the default servlet reveals source code
15619| [10348] Apache Tomcat HTTP GET request DOS device reference could cause a denial of service
15620| [10281] Apache HTTP Server ab.c ApacheBench long response buffer overflow
15621| [10280] Apache HTTP Server shared memory scorecard overwrite
15622| [10263] Apache Tomcat mod_jk or mod_jserv connector directory disclosure
15623| [10241] Apache HTTP Server Host: header cross-site scripting
15624| [10230] Slapper worm variants A, B, and C target OpenSSL/Apache systems
15625| [10208] Apache HTTP Server mod_dav denial of service
15626| [10206] HP VVOS Apache mod_ssl denial of service
15627| [10200] Apache HTTP Server stderr denial of service
15628| [10175] Apache Tomcat org.apache.catalina.servlets.DefaultServlet reveals source code
15629| [10169] Slapper worm variant (Slapper.C) targets OpenSSL/Apache systems
15630| [10154] Slapper worm variant (Slapper.B) targets OpenSSL/Apache systems
15631| [10098] Slapper worm targets OpenSSL/Apache systems
15632| [9876] Apache HTTP Server cgi/cgid request could disclose the path to a requested script
15633| [9875] Apache HTTP Server .var file request could disclose installation path
15634| [9863] Apache Tomcat web.xml file could allow a remote attacker to bypass restrictions
15635| [9808] Apache HTTP Server non-Unix version URL encoded directory traversal
15636| [9623] Apache HTTP Server ap_log_rerror() path disclosure
15637| [9520] Apache Tomcat /servlet/ mapping cross-site scripting
15638| [9415] Apache HTTP Server mod_ssl .htaccess off-by-one buffer overflow
15639| [9396] Apache Tomcat null character to threads denial of service
15640| [9394] Apache Tomcat HTTP request for LPT9 reveals Web root path
15641| [9249] Apache HTTP Server chunked encoding heap buffer overflow
15642| [9208] Apache Tomcat sample file requests could reveal directory listing and path to Web root directory
15643| [8932] Apache Tomcat example class information disclosure
15644| [8633] Apache HTTP Server with mod_rewrite could allow an attacker to bypass directives
15645| [8629] Apache HTTP Server double-reverse DNS lookup spoofing
15646| [8589] Apache HTTP Server for Windows DOS batch file remote command execution
15647| [8457] Oracle9i Application Server Apache PL/SQL HTTP Location header buffer overflow
15648| [8455] Oracle9i Application Server default installation could allow an attacker to access certain Apache Services
15649| [8400] Apache HTTP Server mod_frontpage buffer overflows
15650| [8326] Apache HTTP Server multiple MIME headers (sioux) denial of service
15651| [8308] Apache "
15652| [8275] Apache HTTP Server with Multiviews enabled could disclose directory contents
15653| [8119] Apache and PHP OPTIONS request reveals "
15654| [8054] Apache is running on the system
15655| [8029] Mandrake Linux default Apache configuration could allow an attacker to browse files and directories
15656| [8027] Mandrake Linux default Apache configuration has remote management interface enabled
15657| [8026] Mandrake Linux Apache sample programs could disclose sensitive information about the server
15658| [7836] Apache HTTP Server log directory denial of service
15659| [7815] Apache for Windows "
15660| [7810] Apache HTTP request could result in unexpected behavior
15661| [7599] Apache Tomcat reveals installation path
15662| [7494] Apache "
15663| [7419] Apache Web Server could allow remote attackers to overwrite .log files
15664| [7363] Apache Web Server hidden HTTP requests
15665| [7249] Apache mod_proxy denial of service
15666| [7129] Linux with Apache Web server could allow an attacker to determine if a specified username exists
15667| [7103] Apple Mac OS X used with Apache Web server could disclose directory contents
15668| [7059] Apache "
15669| [7057] Apache "
15670| [7056] Apache "
15671| [7055] Apache "
15672| [7054] Apache "
15673| [6997] Apache Jakarta Tomcat error message may reveal information
15674| [6971] Apache Jakarta Tomcat may reveal JSP source code with missing HTTP protocol specification
15675| [6970] Apache crafted HTTP request could reveal the internal IP address
15676| [6921] Apache long slash path allows directory listing
15677| [6687] Apple Mac OS X used with Apache Web server could allow arbitrary file disclosure
15678| [6527] Apache Web Server for Windows and OS2 denial of service
15679| [6316] Apache Jakarta Tomcat may reveal JSP source code
15680| [6305] Apache Jakarta Tomcat directory traversal
15681| [5926] Linux Apache symbolic link
15682| [5659] Apache Web server discloses files when used with php script
15683| [5310] Apache mod_rewrite allows attacker to view arbitrary files
15684| [5204] Apache WebDAV directory listings
15685| [5197] Apache Web server reveals CGI script source code
15686| [5160] Apache Jakarta Tomcat default installation
15687| [5099] Trustix Secure Linux installs Apache with world writable access
15688| [4968] Apache Jakarta Tomcat snoop servlet gives out information which could be used in attack
15689| [4967] Apache Jakarta Tomcat 404 error reveals the pathname of the requested file
15690| [4931] Apache source.asp example file allows users to write to files
15691| [4575] IBM HTTP Server running Apache allows users to directory listing and file retrieval
15692| [4205] Apache Jakarta Tomcat delivers file contents
15693| [2084] Apache on Debian by default serves the /usr/doc directory
15694| [1630] MessageMedia UnityMail and Apache Web server MIME header flood denial of service
15695| [697] Apache HTTP server beck exploit
15696| [331] Apache cookies buffer overflow
15697|
15698| Exploit-DB - https://www.exploit-db.com:
15699| [31130] Apache Tomcat <= 6.0.15 Cookie Quote Handling Remote Information Disclosure Vulnerability
15700| [31052] Apache <= 2.2.6 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
15701| [30901] Apache HTTP Server 2.2.6 Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
15702| [30835] Apache HTTP Server <= 2.2.4 413 Error HTTP Request Method Cross-Site Scripting Weakness
15703| [30563] Apache Tomcat <= 5.5.15 Cal2.JSP Cross-Site Scripting Vulnerability
15704| [30496] Apache Tomcat <= 6.0.13 Cookie Handling Quote Delimiter Session ID Disclosure
15705| [30495] Apache Tomcat <= 6.0.13 Host Manager Servlet Cross Site Scripting Vulnerability
15706| [30191] Apache MyFaces Tomahawk JSF Framework 1.1.5 Autoscroll Parameter Cross Site Scripting Vulnerability
15707| [30189] Apache Tomcat <= 6.0.13 JSP Example Web Applications Cross Site Scripting Vulnerability
15708| [30052] Apache Tomcat 6.0.10 Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
15709| [29930] Apache AXIS 1.0 Non-Existent WSDL Path Information Disclosure Vulnerability
15710| [29859] Apache Roller OGNL Injection
15711| [29739] Apache HTTP Server Tomcat 5.x/6.0.x Directory Traversal Vulnerability
15712| [29435] Apache Tomcat 5.5.25 - CSRF Vulnerabilities
15713| [29316] Apache + PHP 5.x - Remote Code Execution (Multithreaded Scanner) (2)
15714| [29290] Apache / PHP 5.x Remote Code Execution Exploit
15715| [28713] Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object RCE
15716| [28424] Apache 2.x HTTP Server Arbitrary HTTP Request Headers Security Weakness
15717| [28365] Apache 2.2.2 CGI Script Source Code Information Disclosure Vulnerability
15718| [28254] Apache Tomcat 5 Information Disclosure Vulnerability
15719| [27915] Apache James 2.2 SMTP Denial of Service Vulnerability
15720| [27397] Apache suEXEC Privilege Elevation / Information Disclosure
15721| [27135] Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
15722| [27096] Apache Geronimo 1.0 Error Page XSS
15723| [27095] Apache Tomcat / Geronimo 1.0 Sample Script cal2.jsp time Parameter XSS
15724| [26710] Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4 - Denial of Service
15725| [26542] Apache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability
15726| [25986] Plesk Apache Zeroday Remote Exploit
15727| [25980] Apache Struts includeParams Remote Code Execution
15728| [25625] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (2)
15729| [25624] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (1)
15730| [24874] Apache Struts ParametersInterceptor Remote Code Execution
15731| [24744] Apache Rave 0.11 - 0.20 - User Information Disclosure
15732| [24694] Apache 1.3.x mod_include Local Buffer Overflow Vulnerability
15733| [24590] Apache 2.0.x mod_ssl Remote Denial of Service Vulnerability
15734| [23751] Apache Cygwin 1.3.x/2.0.x Directory Traversal Vulnerability
15735| [23581] Apache 2.0.4x mod_perl Module File Descriptor Leakage Vulnerability
15736| [23482] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (2)
15737| [23481] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (1)
15738| [23296] Red Hat Apache 2.0.40 Directory Index Default Configuration Error
15739| [23282] apache cocoon 2.14/2.2 - Directory Traversal vulnerability
15740| [23245] Apache Tomcat 4.0.x Non-HTTP Request Denial of Service Vulnerability
15741| [23119] Apache::Gallery 0.4/0.5/0.6 Insecure Local File Storage Privilege Escalation Vulnerability
15742| [22505] Apache Mod_Access_Referer 1.0.2 NULL Pointer Dereference Denial of Service Vulnerability
15743| [22205] Apache Tomcat 3.x Null Byte Directory/File Disclosure Vulnerability
15744| [22191] Apache Web Server 2.0.x MS-DOS Device Name Denial of Service Vulnerability
15745| [22068] Apache 1.3.x,Tomcat 4.0.x/4.1.x Mod_JK Chunked Encoding Denial of Service Vulnerability
15746| [21885] Apache 1.3/2.0.x Server Side Include Cross Site Scripting Vulnerability
15747| [21882] Apache Tomcat 3.2 Directory Disclosure Vulnerability
15748| [21854] Apache 2.0.39/40 Oversized STDERR Buffer Denial of Service Vulnerability
15749| [21853] Apache Tomcat 3/4 DefaultServlet File Disclosure Vulnerability
15750| [21734] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
15751| [21719] Apache 2.0 Path Disclosure Vulnerability
15752| [21697] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
15753| [21605] Apache Tomcat 4.0.3 DoS Device Name Cross Site Scripting Vulnerability
15754| [21604] Apache Tomcat 4.0.3 Servlet Mapping Cross Site Scripting Vulnerability
15755| [21560] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (2)
15756| [21559] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (1)
15757| [21534] Apache Tomcat 3/4 JSP Engine Denial of Service Vulnerability
15758| [21492] Apache Tomcat 3.2.3/3.2.4 RealPath.JSP Malformed Request Information Disclosure
15759| [21491] Apache Tomcat 3.2.3/3.2.4 Example Files Web Root Path Disclosure
15760| [21490] Apache Tomcat 3.2.3/3.2.4 Source.JSP Malformed Request Information Disclosure
15761| [21412] Apache Tomcat 4.0/4.1 Servlet Path Disclosure Vulnerability
15762| [21350] Apache Win32 1.3.x/2.0.x Batch File Remote Command Execution Vulnerability
15763| [21204] Apache 1.3.20 Win32 PHP.EXE Remote File Disclosure Vulnerability
15764| [21112] Red Hat Linux 7.0 Apache Remote Username Enumeration Vulnerability
15765| [21067] Apache 1.0/1.2/1.3 Server Address Disclosure Vulnerability
15766| [21002] Apache 1.3 Possible Directory Index Disclosure Vulnerability
15767| [20911] Apache 1.3.14 Mac File Protection Bypass Vulnerability
15768| [20716] apache tomcat 3.0 - Directory Traversal vulnerability
15769| [20695] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (4)
15770| [20694] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (3)
15771| [20693] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (2)
15772| [20692] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (1)
15773| [20595] NCSA 1.3/1.4.x/1.5,Apache httpd 0.8.11/0.8.14 ScriptAlias Source Retrieval Vulnerability
15774| [20558] Apache 1.2 Web Server DoS Vulnerability
15775| [20466] Apache 1.3 Web Server with Php 3 File Disclosure Vulnerability
15776| [20435] Apache 0.8.x/1.0.x,NCSA httpd 1.x test-cgi Directory Listing Vulnerability
15777| [20272] Apache 1.2.5/1.3.1,UnityMail 2.0 MIME Header DoS Vulnerability
15778| [20210] Apache 1.3.12 WebDAV Directory Listings Vulnerability
15779| [20131] Apache Tomcat 3.1 Path Revealing Vulnerability
15780| [19975] Apache 1.3.6/1.3.9/1.3.11/1.3.12/1.3.20 Root Directory Access Vulnerability
15781| [19828] Cobalt RaQ 2.0/3.0 Apache .htaccess Disclosure Vulnerability
15782| [19536] Apache <= 1.1,NCSA httpd <= 1.5.2,Netscape Server 1.12/1.1/2.0 a nph-test-cgi Vulnerability
15783| [19231] PHP apache_request_headers Function Buffer Overflow
15784| [18984] Apache Struts <= 2.2.1.1 - Remote Command Execution
15785| [18897] Oracle Weblogic Apache Connector POST Request Buffer Overflow
15786| [18619] Apache Tomcat Remote Exploit (PUT Request) and Account Scanner
15787| [18452] Apache Struts Multiple Persistent Cross-Site Scripting Vulnerabilities
15788| [18442] Apache httpOnly Cookie Disclosure
15789| [18329] Apache Struts2 <= 2.3.1 - Multiple Vulnerabilities
15790| [18221] Apache HTTP Server Denial of Service
15791| [17969] Apache mod_proxy Reverse Proxy Exposure Vulnerability PoC
15792| [17696] Apache httpd Remote Denial of Service (memory exhaustion)
15793| [17691] Apache Struts < 2.2.0 - Remote Command Execution
15794| [16798] Apache mod_jk 1.2.20 Buffer Overflow
15795| [16782] Apache Win32 Chunked Encoding
15796| [16752] Apache module mod_rewrite LDAP protocol Buffer Overflow
15797| [16317] Apache Tomcat Manager Application Deployer Authenticated Code Execution
15798| [15710] Apache Archiva 1.0 - 1.3.1 CSRF Vulnerability
15799| [15319] Apache 2.2 (Windows) Local Denial of Service
15800| [14617] Apache JackRabbit 2.0.0 webapp XPath Injection
15801| [14489] Apache Tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
15802| [12721] Apache Axis2 1.4.1 - Local File Inclusion Vulnerability
15803| [12689] Authenticated Cross-Site Scripting Vulnerability (XSS) within Apache Axis2 administration console
15804| [12343] Apache Tomcat 5.5.0 to 5.5.29 & 6.0.0 to 6.0.26 - Information Disclosure Vulnerability
15805| [12330] Apache OFBiz - Multiple XSS
15806| [12264] Apache OFBiz - FULLADMIN Creator PoC Payload
15807| [12263] Apache OFBiz - SQL Remote Execution PoC Payload
15808| [11662] Apache Spamassassin Milter Plugin Remote Root Command Execution
15809| [11650] Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit
15810| [10811] Joomla.Tutorials GHDB: Apache directory listing Download Vulnerability
15811| [10292] Apache Tomcat 3.2.1 - 404 Error Page Cross Site Scripting Vulnerability
15812| [9995] Apache Tomcat Form Authentication Username Enumeration Weakness
15813| [9994] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
15814| [9993] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
15815| [8842] Apache mod_dav / svn Remote Denial of Service Exploit
15816| [8458] Apache Geronimo <= 2.1.3 - Multiple Directory Traversal Vulnerabilities
15817| [7264] Apache Tomcat runtime.getRuntime().exec() Privilege Escalation (win)
15818| [6229] apache tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
15819| [6100] Apache mod_jk 1.2.19 Remote Buffer Overflow Exploit (win32)
15820| [6089] Bea Weblogic Apache Connector Code Exec / Denial of Service Exploit
15821| [5386] Apache Tomcat Connector jk2-2.0.2 (mod_jk2) Remote Overflow Exploit
15822| [5330] Apache 2.0 mod_jk2 2.0.2 - Remote Buffer Overflow Exploit (win32)
15823| [4552] Apache Tomcat (webdav) Remote File Disclosure Exploit (ssl support)
15824| [4530] Apache Tomcat (webdav) Remote File Disclosure Exploit
15825| [4162] Apache Tomcat Connector (mod_jk) Remote Exploit (exec-shield)
15826| [4093] Apache mod_jk 1.2.19/1.2.20 Remote Buffer Overflow Exploit
15827| [3996] Apache 2.0.58 mod_rewrite Remote Overflow Exploit (win2k3)
15828| [3680] Apache Mod_Rewrite Off-by-one Remote Overflow Exploit (win32)
15829| [3384] Ubuntu/Debian Apache 1.3.33/1.3.34 (CGI TTY) Local Root Exploit
15830| [2237] Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
15831| [2061] Apache Tomcat < 5.5.17 Remote Directory Listing Vulnerability
15832| [1056] Apache <= 2.0.49 Arbitrary Long HTTP Headers Denial of Service
15833| [855] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit
15834| [764] Apache OpenSSL - Remote Exploit (Multiple Targets) (OpenFuckV2.c)
15835| [587] Apache <= 1.3.31 mod_include Local Buffer Overflow Exploit
15836| [466] htpasswd Apache 1.3.31 - Local Exploit
15837| [371] Apache HTTPd Arbitrary Long HTTP Headers DoS (c version)
15838| [360] Apache HTTPd Arbitrary Long HTTP Headers DoS
15839| [132] Apache 1.3.x - 2.0.48 - mod_userdir Remote Users Disclosure Exploit
15840| [126] Apache mod_gzip (with debug_mode) <= 1.2.26.1a Remote Exploit
15841| [67] Apache 1.3.x mod_mylo Remote Code Execution Exploit
15842| [38] Apache <= 2.0.45 APR Remote Exploit -Apache-Knacker.pl
15843| [34] Webfroot Shoutbox < 2.32 (Apache) Remote Exploit
15844| [11] Apache <= 2.0.44 Linux Remote Denial of Service Exploit
15845| [9] Apache HTTP Server 2.x Memory Leak Exploit
15846|
15847| OpenVAS (Nessus) - http://www.openvas.org:
15848| [902924] Apache Struts2 Showcase Skill Name Remote Code Execution Vulnerability
15849| [902837] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability (Windows)
15850| [902830] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
15851| [902664] Apache Traffic Server HTTP Host Header Denial of Service Vulnerability
15852| [901203] Apache httpd Web Server Range Header Denial of Service Vulnerability
15853| [901110] Apache ActiveMQ Source Code Information Disclosure Vulnerability
15854| [901105] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
15855| [900842] Apache 'mod_proxy_ftp' Module Command Injection Vulnerability (Linux)
15856| [900841] Apache 'mod_proxy_ftp' Module Denial Of Service Vulnerability (Linux)
15857| [900573] Apache APR-Utils XML Parser Denial of Service Vulnerability
15858| [900572] Apache APR-Utils Multiple Denial of Service Vulnerabilities
15859| [900571] Apache APR-Utils Version Detection
15860| [900499] Apache mod_proxy_ajp Information Disclosure Vulnerability
15861| [900496] Apache Tiles Multiple XSS Vulnerability
15862| [900493] Apache Tiles Version Detection
15863| [900107] Apache mod_proxy_ftp Wildcard Characters XSS Vulnerability
15864| [900021] Apache Tomcat Cross-Site Scripting and Security Bypass Vulnerabilities
15865| [880086] CentOS Update for apache CESA-2008:0004-01 centos2 i386
15866| [870175] RedHat Update for apache RHSA-2008:0004-01
15867| [864591] Fedora Update for apache-poi FEDORA-2012-10835
15868| [864383] Fedora Update for apache-commons-compress FEDORA-2012-8428
15869| [864280] Fedora Update for apache-commons-compress FEDORA-2012-8465
15870| [864250] Fedora Update for apache-poi FEDORA-2012-7683
15871| [864249] Fedora Update for apache-poi FEDORA-2012-7686
15872| [863993] Fedora Update for apache-commons-daemon FEDORA-2011-10880
15873| [863466] Fedora Update for apache-commons-daemon FEDORA-2011-10936
15874| [855821] Solaris Update for Apache 1.3 122912-19
15875| [855812] Solaris Update for Apache 1.3 122911-19
15876| [855737] Solaris Update for Apache 1.3 122911-17
15877| [855731] Solaris Update for Apache 1.3 122912-17
15878| [855695] Solaris Update for Apache 1.3 122911-16
15879| [855645] Solaris Update for Apache 1.3 122912-16
15880| [855587] Solaris Update for kernel update and Apache 108529-29
15881| [855566] Solaris Update for Apache 116973-07
15882| [855531] Solaris Update for Apache 116974-07
15883| [855524] Solaris Update for Apache 2 120544-14
15884| [855494] Solaris Update for Apache 1.3 122911-15
15885| [855478] Solaris Update for Apache Security 114145-11
15886| [855472] Solaris Update for Apache Security 113146-12
15887| [855179] Solaris Update for Apache 1.3 122912-15
15888| [855147] Solaris Update for kernel update and Apache 108528-29
15889| [855077] Solaris Update for Apache 2 120543-14
15890| [850196] SuSE Update for apache2 openSUSE-SU-2012:0314-1 (apache2)
15891| [850088] SuSE Update for apache2 SUSE-SA:2007:061
15892| [850009] SuSE Update for apache2,apache SUSE-SA:2008:021
15893| [841209] Ubuntu Update for apache2 USN-1627-1
15894| [840900] Ubuntu Update for apache2 USN-1368-1
15895| [840798] Ubuntu Update for apache2 USN-1259-1
15896| [840734] Ubuntu Update for apache2 USN-1199-1
15897| [840542] Ubuntu Update for apache2 vulnerabilities USN-1021-1
15898| [840504] Ubuntu Update for apache2 vulnerability USN-990-2
15899| [840399] Ubuntu Update for apache2 vulnerabilities USN-908-1
15900| [840304] Ubuntu Update for apache2 vulnerabilities USN-575-1
15901| [840118] Ubuntu Update for libapache2-mod-perl2 vulnerability USN-488-1
15902| [840092] Ubuntu Update for apache2 vulnerabilities USN-499-1
15903| [840039] Ubuntu Update for libapache2-mod-python vulnerability USN-430-1
15904| [835253] HP-UX Update for Apache Web Server HPSBUX02645
15905| [835247] HP-UX Update for Apache-based Web Server HPSBUX02612
15906| [835243] HP-UX Update for Apache Running Tomcat Servlet Engine HPSBUX02579
15907| [835236] HP-UX Update for Apache with PHP HPSBUX02543
15908| [835233] HP-UX Update for Apache-based Web Server HPSBUX02531
15909| [835224] HP-UX Update for Apache-based Web Server HPSBUX02465
15910| [835200] HP-UX Update for Apache Web Server Suite HPSBUX02431
15911| [835190] HP-UX Update for Apache Web Server Suite HPSBUX02401
15912| [835188] HP-UX Update for Apache HPSBUX02308
15913| [835181] HP-UX Update for Apache With PHP HPSBUX02332
15914| [835180] HP-UX Update for Apache with PHP HPSBUX02342
15915| [835172] HP-UX Update for Apache HPSBUX02365
15916| [835168] HP-UX Update for Apache HPSBUX02313
15917| [835148] HP-UX Update for Apache HPSBUX01064
15918| [835139] HP-UX Update for Apache with PHP HPSBUX01090
15919| [835131] HP-UX Update for Apache HPSBUX00256
15920| [835119] HP-UX Update for Apache Remote Execution of Arbitrary Code HPSBUX02186
15921| [835104] HP-UX Update for Apache HPSBUX00224
15922| [835103] HP-UX Update for Apache mod_cgid HPSBUX00301
15923| [835101] HP-UX Update for Apache HPSBUX01232
15924| [835080] HP-UX Update for Apache HPSBUX02273
15925| [835078] HP-UX Update for ApacheStrong HPSBUX00255
15926| [835044] HP-UX Update for Apache HPSBUX01019
15927| [835040] HP-UX Update for Apache PHP HPSBUX00207
15928| [835025] HP-UX Update for Apache HPSBUX00197
15929| [835023] HP-UX Update for Apache HPSBUX01022
15930| [835022] HP-UX Update for Apache HPSBUX02292
15931| [835005] HP-UX Update for Apache HPSBUX02262
15932| [831759] Mandriva Update for apache-mod_security MDVSA-2012:182 (apache-mod_security)
15933| [831737] Mandriva Update for apache MDVSA-2012:154-1 (apache)
15934| [831534] Mandriva Update for apache MDVSA-2012:012 (apache)
15935| [831523] Mandriva Update for apache MDVSA-2012:003 (apache)
15936| [831491] Mandriva Update for apache MDVSA-2011:168 (apache)
15937| [831460] Mandriva Update for apache MDVSA-2011:144 (apache)
15938| [831449] Mandriva Update for apache MDVSA-2011:130 (apache)
15939| [831357] Mandriva Update for apache MDVSA-2011:057 (apache)
15940| [831132] Mandriva Update for apache MDVSA-2010:153 (apache)
15941| [831131] Mandriva Update for apache MDVSA-2010:152 (apache)
15942| [830989] Mandriva Update for apache-mod_auth_shadow MDVSA-2010:081 (apache-mod_auth_shadow)
15943| [830931] Mandriva Update for apache MDVSA-2010:057 (apache)
15944| [830926] Mandriva Update for apache MDVSA-2010:053 (apache)
15945| [830918] Mandriva Update for apache-mod_security MDVSA-2010:050 (apache-mod_security)
15946| [830799] Mandriva Update for apache-conf MDVSA-2009:300-2 (apache-conf)
15947| [830797] Mandriva Update for apache-conf MDVSA-2009:300-1 (apache-conf)
15948| [830791] Mandriva Update for apache-conf MDVA-2010:011 (apache-conf)
15949| [830652] Mandriva Update for apache MDVSA-2008:195 (apache)
15950| [830621] Mandriva Update for apache-conf MDVA-2008:129 (apache-conf)
15951| [830581] Mandriva Update for apache MDVSA-2008:016 (apache)
15952| [830294] Mandriva Update for apache MDKSA-2007:140 (apache)
15953| [830196] Mandriva Update for apache MDKSA-2007:235 (apache)
15954| [830112] Mandriva Update for apache MDKSA-2007:127 (apache)
15955| [830109] Mandriva Update for apache-mod_perl MDKSA-2007:083 (apache-mod_perl)
15956| [802425] Apache Struts2 Showcase Arbitrary Java Method Execution vulnerability
15957| [802423] Apache Struts CookBook/Examples Multiple Cross-Site Scripting Vulnerabilities
15958| [802422] Apache Struts Showcase Multiple Persistence Cross-Site Scripting Vulnerabilities
15959| [802415] Apache Tomcat Multiple Security Bypass Vulnerabilities (Win)
15960| [802385] Apache Tomcat Request Object Security Bypass Vulnerability (Win)
15961| [802384] Apache Tomcat Parameter Handling Denial of Service Vulnerability (Win)
15962| [802378] Apache Tomcat Hash Collision Denial Of Service Vulnerability
15963| [801942] Apache Archiva Multiple Vulnerabilities
15964| [801940] Apache Struts2 'XWork' Information Disclosure Vulnerability
15965| [801663] Apache Struts2/XWork Remote Command Execution Vulnerability
15966| [801521] Apache APR-util 'buckets/apr_brigade.c' Denial Of Service Vulnerability
15967| [801284] Apache Derby Information Disclosure Vulnerability
15968| [801203] Apache ActiveMQ Persistent Cross-Site Scripting Vulnerability
15969| [800837] Apache 'mod_deflate' Denial Of Service Vulnerability - July09
15970| [800827] Apache 'mod_proxy_http.c' Denial Of Service Vulnerability
15971| [800680] Apache APR Version Detection
15972| [800679] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
15973| [800678] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
15974| [800677] Apache Roller Version Detection
15975| [800279] Apache mod_jk Module Version Detection
15976| [800278] Apache Struts Cross Site Scripting Vulnerability
15977| [800277] Apache Tomcat mod_jk Information Disclosure Vulnerability
15978| [800276] Apache Struts Version Detection
15979| [800271] Apache Struts Directory Traversal Vulnerability
15980| [800024] Apache Tomcat RemoteFilterValve Security Bypass Vulnerability
15981| [103333] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
15982| [103293] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
15983| [103122] Apache Web Server ETag Header Information Disclosure Weakness
15984| [103074] Apache Continuum Cross Site Scripting Vulnerability
15985| [103073] Apache Continuum Detection
15986| [103053] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
15987| [101023] Apache Open For Business Weak Password security check
15988| [101020] Apache Open For Business HTML injection vulnerability
15989| [101019] Apache Open For Business service detection
15990| [100924] Apache Archiva Cross Site Request Forgery Vulnerability
15991| [100923] Apache Archiva Detection
15992| [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
15993| [100814] Apache Axis2 Document Type Declaration Processing Security Vulnerability
15994| [100813] Apache Axis2 Detection
15995| [100797] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
15996| [100795] Apache Derby Detection
15997| [100762] Apache CouchDB Cross Site Request Forgery Vulnerability
15998| [100725] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
15999| [100613] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
16000| [100514] Apache Multiple Security Vulnerabilities
16001| [100211] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
16002| [100172] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
16003| [100171] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
16004| [100130] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
16005| [72626] Debian Security Advisory DSA 2579-1 (apache2)
16006| [72612] FreeBSD Ports: apache22
16007| [71551] Gentoo Security Advisory GLSA 201206-25 (apache)
16008| [71550] Gentoo Security Advisory GLSA 201206-24 (apache tomcat)
16009| [71512] FreeBSD Ports: apache
16010| [71485] Debian Security Advisory DSA 2506-1 (libapache-mod-security)
16011| [71256] Debian Security Advisory DSA 2452-1 (apache2)
16012| [71238] Debian Security Advisory DSA 2436-1 (libapache2-mod-fcgid)
16013| [70737] FreeBSD Ports: apache
16014| [70724] Debian Security Advisory DSA 2405-1 (apache2)
16015| [70600] FreeBSD Ports: apache
16016| [70253] FreeBSD Ports: apache, apache-event, apache-itk, apache-peruser, apache-worker
16017| [70235] Debian Security Advisory DSA 2298-2 (apache2)
16018| [70233] Debian Security Advisory DSA 2298-1 (apache2)
16019| [69988] Debian Security Advisory DSA 2279-1 (libapache2-mod-authnz-external)
16020| [69338] Debian Security Advisory DSA 2202-1 (apache2)
16021| [67868] FreeBSD Ports: apache
16022| [66816] FreeBSD Ports: apache
16023| [66553] Mandriva Security Advisory MDVSA-2009:189-1 (apache-mod_auth_mysql)
16024| [66414] Mandriva Security Advisory MDVSA-2009:323 (apache)
16025| [66106] SuSE Security Advisory SUSE-SA:2009:050 (apache2,libapr1)
16026| [66081] SLES11: Security update for Apache 2
16027| [66074] SLES10: Security update for Apache 2
16028| [66070] SLES9: Security update for Apache 2
16029| [65998] SLES10: Security update for apache2-mod_python
16030| [65893] SLES10: Security update for Apache 2
16031| [65888] SLES10: Security update for Apache 2
16032| [65575] SLES9: Security update for apache2,apache2-prefork,apache2-worker
16033| [65510] SLES9: Security update for Apache 2
16034| [65472] SLES9: Security update for Apache
16035| [65467] SLES9: Security update for Apache
16036| [65450] SLES9: Security update for apache2
16037| [65390] SLES9: Security update for Apache2
16038| [65363] SLES9: Security update for Apache2
16039| [65309] SLES9: Security update for Apache and mod_ssl
16040| [65296] SLES9: Security update for webdav apache module
16041| [65283] SLES9: Security update for Apache2
16042| [65249] SLES9: Security update for Apache 2
16043| [65230] SLES9: Security update for Apache 2
16044| [65228] SLES9: Security update for Apache 2
16045| [65212] SLES9: Security update for apache2-mod_python
16046| [65209] SLES9: Security update for apache2-worker
16047| [65207] SLES9: Security update for Apache 2
16048| [65168] SLES9: Security update for apache2-mod_python
16049| [65142] SLES9: Security update for Apache2
16050| [65136] SLES9: Security update for Apache 2
16051| [65132] SLES9: Security update for apache
16052| [65131] SLES9: Security update for Apache 2 oes/CORE
16053| [65113] SLES9: Security update for apache2
16054| [65072] SLES9: Security update for apache and mod_ssl
16055| [65017] SLES9: Security update for Apache 2
16056| [64950] Mandrake Security Advisory MDVSA-2009:240 (apache)
16057| [64783] FreeBSD Ports: apache
16058| [64774] Ubuntu USN-802-2 (apache2)
16059| [64653] Ubuntu USN-813-2 (apache2)
16060| [64559] Debian Security Advisory DSA 1834-2 (apache2)
16061| [64532] Mandrake Security Advisory MDVSA-2009:189 (apache-mod_auth_mysql)
16062| [64527] Mandrake Security Advisory MDVSA-2009:184 (apache-mod_security)
16063| [64526] Mandrake Security Advisory MDVSA-2009:183 (apache-mod_security)
16064| [64500] Mandrake Security Advisory MDVSA-2009:168 (apache)
16065| [64443] Ubuntu USN-802-1 (apache2)
16066| [64426] Gentoo Security Advisory GLSA 200907-04 (apache)
16067| [64423] Debian Security Advisory DSA 1834-1 (apache2)
16068| [64391] Mandrake Security Advisory MDVSA-2009:149 (apache)
16069| [64377] Mandrake Security Advisory MDVSA-2009:124-1 (apache)
16070| [64251] Debian Security Advisory DSA 1816-1 (apache2)
16071| [64201] Ubuntu USN-787-1 (apache2)
16072| [64140] Mandrake Security Advisory MDVSA-2009:124 (apache)
16073| [64136] Mandrake Security Advisory MDVSA-2009:102 (apache)
16074| [63565] FreeBSD Ports: apache
16075| [63562] Ubuntu USN-731-1 (apache2)
16076| [61381] Gentoo Security Advisory GLSA 200807-06 (apache)
16077| [61185] FreeBSD Ports: apache
16078| [60582] Gentoo Security Advisory GLSA 200803-19 (apache)
16079| [60387] Slackware Advisory SSA:2008-045-02 apache
16080| [58826] FreeBSD Ports: apache-tomcat
16081| [58825] FreeBSD Ports: apache-tomcat
16082| [58804] FreeBSD Ports: apache
16083| [58745] Gentoo Security Advisory GLSA 200711-06 (apache)
16084| [58360] Debian Security Advisory DSA 1312-1 (libapache-mod-jk)
16085| [57851] Gentoo Security Advisory GLSA 200608-01 (apache)
16086| [57788] Debian Security Advisory DSA 1247-1 (libapache-mod-auth-kerb)
16087| [57335] Debian Security Advisory DSA 1167-1 (apache)
16088| [57201] Debian Security Advisory DSA 1131-1 (apache)
16089| [57200] Debian Security Advisory DSA 1132-1 (apache2)
16090| [57168] Slackware Advisory SSA:2006-209-01 Apache httpd
16091| [57145] FreeBSD Ports: apache
16092| [56731] Slackware Advisory SSA:2006-129-01 Apache httpd
16093| [56729] Slackware Advisory SSA:2006-130-01 Apache httpd redux
16094| [56246] Gentoo Security Advisory GLSA 200602-03 (Apache)
16095| [56212] Debian Security Advisory DSA 952-1 (libapache-auth-ldap)
16096| [56115] Debian Security Advisory DSA 935-1 (libapache2-mod-auth-pgsql)
16097| [56067] FreeBSD Ports: apache
16098| [55803] Slackware Advisory SSA:2005-310-04 apache
16099| [55519] Debian Security Advisory DSA 839-1 (apachetop)
16100| [55392] Gentoo Security Advisory GLSA 200509-12 (Apache)
16101| [55355] FreeBSD Ports: apache
16102| [55284] Debian Security Advisory DSA 807-1 (libapache-mod-ssl)
16103| [55261] Debian Security Advisory DSA 805-1 (apache2)
16104| [55259] Debian Security Advisory DSA 803-1 (apache)
16105| [55129] Gentoo Security Advisory GLSA 200508-15 (apache)
16106| [54739] Gentoo Security Advisory GLSA 200411-18 (apache)
16107| [54724] Gentoo Security Advisory GLSA 200411-03 (apache)
16108| [54712] Gentoo Security Advisory GLSA 200410-21 (apache)
16109| [54689] Gentoo Security Advisory GLSA 200409-33 (net=www/apache)
16110| [54677] Gentoo Security Advisory GLSA 200409-21 (apache)
16111| [54610] Gentoo Security Advisory GLSA 200407-03 (Apache)
16112| [54601] Gentoo Security Advisory GLSA 200406-16 (Apache)
16113| [54590] Gentoo Security Advisory GLSA 200406-05 (Apache)
16114| [54582] Gentoo Security Advisory GLSA 200405-22 (Apache)
16115| [54529] Gentoo Security Advisory GLSA 200403-04 (Apache)
16116| [54499] Gentoo Security Advisory GLSA 200310-04 (Apache)
16117| [54498] Gentoo Security Advisory GLSA 200310-03 (Apache)
16118| [54439] FreeBSD Ports: apache
16119| [53931] Slackware Advisory SSA:2004-133-01 apache
16120| [53903] Slackware Advisory SSA:2004-299-01 apache, mod_ssl, php
16121| [53902] Slackware Advisory SSA:2004-305-01 apache+mod_ssl
16122| [53878] Slackware Advisory SSA:2003-308-01 apache security update
16123| [53851] Debian Security Advisory DSA 135-1 (libapache-mod-ssl)
16124| [53849] Debian Security Advisory DSA 132-1 (apache-ssl)
16125| [53848] Debian Security Advisory DSA 131-1 (apache)
16126| [53784] Debian Security Advisory DSA 021-1 (apache)
16127| [53738] Debian Security Advisory DSA 195-1 (apache-perl)
16128| [53737] Debian Security Advisory DSA 188-1 (apache-ssl)
16129| [53735] Debian Security Advisory DSA 187-1 (apache)
16130| [53703] Debian Security Advisory DSA 532-1 (libapache-mod-ssl)
16131| [53577] Debian Security Advisory DSA 120-1 (libapache-mod-ssl, apache-ssl)
16132| [53568] Debian Security Advisory DSA 067-1 (apache,apache-ssl)
16133| [53519] Debian Security Advisory DSA 689-1 (libapache-mod-python)
16134| [53433] Debian Security Advisory DSA 181-1 (libapache-mod-ssl)
16135| [53282] Debian Security Advisory DSA 594-1 (apache)
16136| [53248] Debian Security Advisory DSA 558-1 (libapache-mod-dav)
16137| [53224] Debian Security Advisory DSA 532-2 (libapache-mod-ssl)
16138| [53215] Debian Security Advisory DSA 525-1 (apache)
16139| [53151] Debian Security Advisory DSA 452-1 (libapache-mod-python)
16140| [52529] FreeBSD Ports: apache+ssl
16141| [52501] FreeBSD Ports: apache
16142| [52461] FreeBSD Ports: apache
16143| [52390] FreeBSD Ports: apache
16144| [52389] FreeBSD Ports: apache
16145| [52388] FreeBSD Ports: apache
16146| [52383] FreeBSD Ports: apache
16147| [52339] FreeBSD Ports: apache+mod_ssl
16148| [52331] FreeBSD Ports: apache
16149| [52329] FreeBSD Ports: ru-apache+mod_ssl
16150| [52314] FreeBSD Ports: apache
16151| [52310] FreeBSD Ports: apache
16152| [15588] Detect Apache HTTPS
16153| [15555] Apache mod_proxy content-length buffer overflow
16154| [15554] Apache mod_include priviledge escalation
16155| [14771] Apache <= 1.3.33 htpasswd local overflow
16156| [14177] Apache mod_access rule bypass
16157| [13644] Apache mod_rootme Backdoor
16158| [12293] Apache Input Header Folding and mod_ssl ssl_io_filter_cleanup DoS Vulnerabilities
16159| [12280] Apache Connection Blocking Denial of Service
16160| [12239] Apache Error Log Escape Sequence Injection
16161| [12123] Apache Tomcat source.jsp malformed request information disclosure
16162| [12085] Apache Tomcat servlet/JSP container default files
16163| [11438] Apache Tomcat Directory Listing and File disclosure
16164| [11204] Apache Tomcat Default Accounts
16165| [11092] Apache 2.0.39 Win32 directory traversal
16166| [11046] Apache Tomcat TroubleShooter Servlet Installed
16167| [11042] Apache Tomcat DOS Device Name XSS
16168| [11041] Apache Tomcat /servlet Cross Site Scripting
16169| [10938] Apache Remote Command Execution via .bat files
16170| [10839] PHP.EXE / Apache Win32 Arbitrary File Reading Vulnerability
16171| [10773] MacOS X Finder reveals contents of Apache Web files
16172| [10766] Apache UserDir Sensitive Information Disclosure
16173| [10756] MacOS X Finder reveals contents of Apache Web directories
16174| [10752] Apache Auth Module SQL Insertion Attack
16175| [10704] Apache Directory Listing
16176| [10678] Apache /server-info accessible
16177| [10677] Apache /server-status accessible
16178| [10440] Check for Apache Multiple / vulnerability
16179|
16180| SecurityTracker - https://www.securitytracker.com:
16181| [1028865] Apache Struts Bugs Permit Remote Code Execution and URL Redirection Attacks
16182| [1028864] Apache Struts Wildcard Matching and Expression Evaluation Bugs Let Remote Users Execute Arbitrary Code
16183| [1028824] Apache mod_dav_svn URI Processing Flaw Lets Remote Users Deny Service
16184| [1028823] Apache Unspecified Flaw in mod_session_dbd Has Unspecified Impact
16185| [1028724] (HP Issues Fix for HP-UX) Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
16186| [1028722] (Red Hat Issues Fix for JBoss) Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
16187| [1028693] (Red Hat Issues Fix) Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
16188| [1028622] Apache Struts 'includeParams' Bugs Permit Remote Command Execution and Cross-Site Scripting Attacks
16189| [1028621] Apache Subversion Bugs Let Remote Authenticated Users Execute Arbitrary Commands and Deny Service
16190| [1028540] Apache mod_rewrite Input Validation Flaw Lets Remote Users Execute Arbitrary Commands
16191| [1028534] Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
16192| [1028533] Apache Tomcat Lack of Chunked Transfer Encoding Extension Size Limit Lets Remote Users Deny Service
16193| [1028532] Apache Tomcat AsyncListeners Bug May Disclose Information from One Request to Another User
16194| [1028515] Apache VCL Input Validation Flaw Lets Remote Authenticated Users Gain Elevated Privileges
16195| [1028457] Apache ActiveMQ Bugs Let Remote Users Conduct Cross-Site Scripting Attacks, Deny Service, and Obtain Potentially Sensitive Information
16196| [1028287] Apache CXF WSS4JInInterceptor Grants Service Access to Remote Users
16197| [1028286] Apache CXF WS-Security UsernameToken Processing Flaw Lets Remote Users Bypass Authentication
16198| [1028252] Apache Commons FileUpload Unsafe Temporary File Lets Local Users Gain Elevated Privileges
16199| [1028207] Apache Input Validation Bugs Permit Cross-Site Scripting Attacks
16200| [1027836] Apache Tomcat Connection Processing Bug Lets Remote Users Deny Service
16201| [1027834] Apache Tomcat Bug Lets Remote Users Bypass Cross-Site Request Forgery Prevention Filter
16202| [1027833] Apache Tomcat Bug Lets Remote Users Bypass Security Constraints
16203| [1027729] Apache Tomcat Header Processing Bug Lets Remote Users Deny Service
16204| [1027728] Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
16205| [1027554] Apache CXF Lets Remote Authenticated Users Execute Unauthorized SOAP Actions
16206| [1027508] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
16207| [1027421] Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
16208| [1027096] Apache Commons Compress BZip2CompressorOutputStream() Sorting Algorithm Lets Remote or Local Users Deny Service
16209| [1026932] Apache LD_LIBRARY_PATH Processing Lets Local Users Gain Elevated Privileges
16210| [1026928] Apache OFBiz Unspecified Flaw Lets Remote Users Execute Arbitrary Code
16211| [1026927] Apache OFBiz Input Validation Flaws Permit Cross-Site Scripting Attacks
16212| [1026847] Apache Traffic Server Host Header Processing Flaw Lets Remote Users Deny Service
16213| [1026846] Apache Wicket Discloses Hidden Application Files to Remote Users
16214| [1026839] Apache Wicket Input Validation Flaw in 'wicket:pageMapName' Parameter Permits Cross-Site Scripting Attacks
16215| [1026616] Apache Bugs Let Remote Users Deny Service and Obtain Cookie Data
16216| [1026575] Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
16217| [1026484] Apache Struts Bug Lets Remote Users Overwrite Files and Execute Arbitrary Code
16218| [1026477] Apache Tomcat Hash Table Collision Bug Lets Remote Users Deny Service
16219| [1026402] Apache Struts Conversion Error Lets Remote Users Inject Arbitrary Commands
16220| [1026353] Apache mod_proxy/mod_rewrite Bug Lets Remote Users Access Internal Servers
16221| [1026295] Apache Tomcat Lets Untrusted Web Applications Gain Elevated Privileges
16222| [1026267] Apache .htaccess File Integer Overflow Lets Local Users Execute Arbitrary Code
16223| [1026144] Apache mod_proxy Pattern Matching Bug Lets Remote Users Access Internal Servers
16224| [1026095] Apache Tomcat HTTP DIGEST Authentication Weaknesses Let Remote Users Conduct Bypass Attacks
16225| [1026054] Apache mod_proxy_ajp HTTP Processing Error Lets Remote Users Deny Service
16226| [1025993] Apache Tomcat AJP Protocol Processing Bug Lets Remote Users Bypass Authentication or Obtain Information
16227| [1025976] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
16228| [1025960] Apache httpd Byterange Filter Processing Error Lets Remote Users Deny Service
16229| [1025925] Apache Tomcat Commons Daemon jsvc Lets Local Users Gain Elevated Privileges
16230| [1025924] Apache Tomcat XML Validation Flaw Lets Applications Obtain Potentially Sensitive Information
16231| [1025788] Apache Tomcat Lets Malicious Applications Obtain Information and Deny Service
16232| [1025755] Apache Santuario Buffer Overflow Lets Remote Users Deny Service
16233| [1025712] Apache Tomcat Discloses Passwords to Local Users in Certain Cases
16234| [1025577] Apache Archiva Input Validation Hole Permits Cross-Site Scripting Attacks
16235| [1025576] Apache Archiva Request Validation Flaw Permits Cross-Site Request Forgery Attacks
16236| [1025527] Apache APR Library apr_fnmatch() Flaw Lets Remote Users Execute Arbitrary Code
16237| [1025303] Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
16238| [1025215] Apache Tomcat May Ignore @ServletSecurity Annotation Protections
16239| [1025066] Apache Continuum Input Validation Flaw Permits Cross-Site Request Forgery Attacks
16240| [1025065] Apache Continuum Input Validation Hole Permits Cross-Site Scripting Attacks
16241| [1025027] Apache Tomcat maxHttpHeaderSize Parsing Error Lets Remote Users Deny Service
16242| [1025026] Apache Tomcat Manager Input Validation Hole Permits Cross-Site Scripting Attacks
16243| [1025025] Apache Tomcat Security Manager Lets Local Users Bypass File Permissions
16244| [1024764] Apache Tomcat Manager Input Validation Hole in 'sessionList.jsp' Permits Cross-Site Scripting Attacks
16245| [1024417] Apache Traffic Server Insufficient Randomization Lets Remote Users Poison the DNS Cache
16246| [1024332] Apache mod_cache and mod_dav Request Processing Flaw Lets Remote Users Deny Service
16247| [1024180] Apache Tomcat 'Transfer-Encoding' Header Processing Flaw Lets Remote Users Deny Service and Obtain Potentially Sensitive Information
16248| [1024096] Apache mod_proxy_http May Return Results for a Different Request
16249| [1023942] Apache mod_proxy_ajp Error Condition Lets Remote Users Deny Service
16250| [1023941] Apache ap_read_request() Memory Error May Let Remote Users Access Potentially Sensitive Information
16251| [1023778] Apache ActiveMQ Input Validation Flaw Permits Cross-Site Scripting Attacks
16252| [1023701] Apache mod_isapi Error Processing Flaw May Let Remote Users Deny Service
16253| [1023533] Apache mod_proxy Integer Overflow May Let Remote Users Execute Arbitrary Code
16254| [1022988] Apache Solaris Support Code Bug Lets Remote Users Deny Service
16255| [1022529] Apache mod_deflate Connection State Bug Lets Remote Users Deny Service
16256| [1022509] Apache mod_proxy stream_reqbody_cl() Infinite Loop Lets Remote Users Deny Service
16257| [1022296] Apache IncludesNoExec Options Restrictions Can Be Bypass By Local Users
16258| [1022264] Apache mod_proxy_ajp Bug May Disclose Another User's Response Data
16259| [1022001] Apache Tomcat mod_jk May Disclose Responses to the Wrong User
16260| [1021988] mod_perl Input Validation Flaw in Apache::Status and Apache2::Status Permits Cross-Site Scripting Attacks
16261| [1021350] NetWare Bug Lets Remote Users Access the ApacheAdmin Console
16262| [1020635] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
16263| [1020520] Oracle WebLogic Apache Connector Lets Remote Users Execute Arbitrary Code
16264| [1020267] Apache mod_proxy Interim Response Process Bug Lets Remote Users Deny Service
16265| [1019784] Apache-SSL Certificate Processing Bug May Let Remote Users View Portions of Kernel Memory
16266| [1019256] Apache mod_negotiation Input Validation Hole Permits Cross-Site Scripting Attacks
16267| [1019194] Apache Input Validation Hole in Mod_AutoIndex When the Character Set is Undefined May Permit Cross-Site Scripting Attacks
16268| [1019185] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
16269| [1019154] Apache Input Validation Hole in mod_status Permits Cross-Site Scripting Attacks
16270| [1019093] Apache Input Validation Hole in mod_imap Permits Cross-Site Scripting Attacks
16271| [1019030] Apache Input Validation Hole in Default HTTP 413 Error Page Permits Cross-Site Scripting Attacks
16272| [1018633] Apache mod_proxy Bug Lets Remote Users Deny Service
16273| [1018304] Apache HTTPD scoreboard Protection Flaw Lets Local Users Terminate Arbitrary Processes
16274| [1018303] Apache HTTPD mod_cache May Let Remote Users Deny Service
16275| [1018302] Apache mod_status Input Validation Hole Permits Cross-Site Scripting Attacks
16276| [1018269] Apache Tomcat Input Validation Hole in Processing Accept-Language Header Permits Cross-Site Scripting Attacks
16277| [1017904] Apache suEXEC Bugs May Let Local Users Gain Elevated Privileges
16278| [1017719] Apache Tomcat JK Web Server Connector Buffer Overflow in map_uri_to_worker() Lets Remote Users Execute Arbitrary Code
16279| [1017062] Apache mod_tcl Format String Bug in set_var() Function May Let Remote Users Execute Arbitrary Code
16280| [1016601] Apache mod_rewrite Off-by-one Error Lets Remote Users Execute Arbitrary Code
16281| [1016576] Apache Tomcat Discloses Directory Listings to Remote Users
16282| [1015447] Apache mod_ssl Null Pointer Dereference May Let Remote Users Deny Service
16283| [1015344] Apache mod_imap Input Validation Flaw in Referer Field Lets Remote Users Conduct Cross-Site Scripting Attacks
16284| [1015093] Apache Memory Leak in MPM 'worker.c' Code May Let Remote Users Deny Service
16285| [1014996] ApacheTop Unsafe Temporary File May Let Local Users Gain Elevated Privileges
16286| [1014833] Apache ssl_hook_Access() Function May Fail to Verify Client Certificates
16287| [1014826] Apache Memory Leak in 'byterange filter' Lets Remote Users Deny Service
16288| [1014575] Apache mod_ssl Off-by-one Buffer Overflow in Processing CRLs May Let Remote Users Deny Service
16289| [1014323] Apache Chunked Transfer-Encoding and Content-Length Processing Lets Remote Users Smuggle HTTP Requests
16290| [1013156] Apache mod_python Publisher Handler Discloses Information to Remote Users
16291| [1012829] Apache mod_auth_radius radcpy() Integer Overflow Lets Remote Users Deny Service in Certain Cases
16292| [1012416] Apache on Apple OS X Lets Remote Users Bypass Apache File Handlers and Directly Access Files
16293| [1012415] Apache on Apple HFS+ Filesystems May Disclose '.DS_Store' Files to Remote Users
16294| [1012414] Apache mod_digest_apple Lets Remote Users Replay Authentication Credentials
16295| [1012083] Apache Web Server Error in Processing Requests With Many Space Characters Lets Remote Users Deny Service
16296| [1011783] Apache mod_include Buffer Overflow Lets Local Users Execute Arbitrary Code
16297| [1011557] Apache mod_ssl SSLCipherSuite Directive Can By Bypassed in Certain Cases
16298| [1011385] Apache Satsify Directive Error May Let Remote Users Access Restricted Resources
16299| [1011340] Apache SSL Connection Abort State Error Lets Remote Users Deny Service
16300| [1011303] Apache ap_resolve_env() Buffer Overflow in Reading Configuration Files May Let Local Users Gain Elevated Privileges
16301| [1011299] Apache IPv6 Address Parsing Flaw May Let Remote Users Deny Service
16302| [1011248] Apache mod_dav LOCK Method Error May Let Remote Users Deny Service
16303| [1011213] Apache mod_ssl Can Be Crashed By Remote Users When Reverse Proxying SSL Connections
16304| [1010674] Apache Can Be Crashed By PHP Code Invoking Nested Remote Sockets
16305| [1010599] Apache httpd Header Line Memory Allocation Lets Remote Users Crash the Server
16306| [1010462] Apache mod_proxy Buffer Overflow May Let Remote Users Execute Arbitrary Code
16307| [1010322] Apache mod_ssl Stack Overflow in ssl_util_uuencode_binary() May Let Remote Users Execute Arbitrary Code
16308| [1010270] cPanel Apache mod_phpsuexec Options Let Local Users Gain Elevated Privileges
16309| [1009934] Apache Web Server Has Buffer Overflow in ebcdic2ascii() on Older Processor Architectures
16310| [1009516] Apache mod_survey HTML Report Format Lets Remote Users Conduct Cross-Site Scripting Attacks
16311| [1009509] Apache mod_disk_cache Stores Authentication Credentials on Disk
16312| [1009495] Apache Web Server Socket Starvation Flaw May Let Remote Users Deny Service
16313| [1009417] GroupWise WebAccess With Apache on NetWare Has Configuration Flaw That May Grant Web Access to Remote Users
16314| [1009338] Apache mod_access Parsing Flaw May Fail to Enforce Allow/Deny Rules
16315| [1009337] Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon
16316| [1009182] Apache for Cygwin '..%5C' Input Validation Flaw Discloses Files to Remote Users
16317| [1008973] PHP May Apply Incorrect php_admin_* Settings To Requests for Apache Virtual Hosts
16318| [1008967] Apache-SSL 'SSLFakeBasicAuth' Lets Remote Users Forge Client Certificates to Be Authenticated
16319| [1008920] Apache mod_digest May Validate Replayed Client Responses
16320| [1008828] Apache mod_python String Processing Bug Still Lets Remote Users Crash the Web Server
16321| [1008822] Apache mod_perl File Descriptor Leak May Let Local Users Hijack the http and https Services
16322| [1008675] mod_auth_shadow Apache Module Authenticates Expired Passwords
16323| [1008559] Apache mod_php File Descriptor Leak May Let Local Users Hijack the https Service
16324| [1008335] Apache mod_python String Processing Bug Lets Remote Users Crash the Web Server
16325| [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
16326| [1008030] Apache mod_rewrite Contains a Buffer Overflow
16327| [1008029] Apache mod_alias Contains a Buffer Overflow
16328| [1008028] Apache mod_cgid May Disclose CGI Output to Another Client
16329| [1007995] Apache Cocoon Forms May Let Remote Users Execute Arbitrary Java Code on the System
16330| [1007993] Apache Cocoon 'view-source' Sample Script Discloses Files to Remote Users
16331| [1007823] Apache Web Server mod_cgi Error May Let Malicious CGI Scripts Crash the Web Service
16332| [1007664] Apache::Gallery Unsafe Temporary Files May Let Local Users Gain Apache Web Server Privileges
16333| [1007557] Apache Web Server Does Not Filter Terminal Escape Sequences From Log Files
16334| [1007230] Apache HTTP Server 'rotatelogs' Bug on Win32 and OS/2 May Cause the Logging to Stop
16335| [1007146] Apache HTTP Server FTP Proxy Bug May Cause Denial of Service Conditions
16336| [1007145] Apache 'accept()' Errors May Cause Denial of Service Conditions
16337| [1007144] Apache Web Server 'type-map' File Error Permits Local Denial of Service Attacks
16338| [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
16339| [1006864] Apache Web Server Can Be Crashed By Remote Users Via mod_dav Flaws and Also Via Basic Authentication
16340| [1006709] Apache mod_survey Input Validation Flaw Lets Remote Users Fill Up Disk Space
16341| [1006614] Apache mod_ntlm Buffer Overflow and Format String Flaw Let Remote Users Execute Arbitary Code
16342| [1006591] Apache mod_access_referer Module Null Pointer Dereference May Faciliate Denial of Service Attacks
16343| [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
16344| [1006021] Apache Tomcat Server URL Parsing Error May Disclose Otherwise Inaccessible Web Directory Listings and Files to Remote Users
16345| [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
16346| [1005962] Apache Web Server Path Parsing Flaw May Allow Remote Users to Execute Code in Certain Configurations
16347| [1005848] Apache 'printenv' Script Input Validation Bugs in Older Versions May Let Remote Users Conduct Cross-Site Scripting Attacks
16348| [1005765] Apache mod_jk Module Processing Bug When Used With Tomcat May Disclose Information to Remote Users or Crash
16349| [1005548] Apache mod_php Module May Allow Local Users to Gain Control of the Web Port
16350| [1005499] Apache Web Server (2.0.42) May Disclose CGI Source Code to Remote Users When Used With WebDAV
16351| [1005410] Apache Tomcat Java Servlet Engine Can Be Crashed Via Multiple Requests for DOS Device Names
16352| [1005351] Apache Web Server (1.3.x) Shared Memory Scoreboard Bug Lets Certain Local Users Issue Signals With Root Privileges
16353| [1005331] Apache Web Server (2.x) SSI Server Signature Filtering Hole Lets Remote Users Conduct Cross-Site Scripting Attacks
16354| [1005290] Apache Tomcat Java Server Default Servlet Returns JSP Source Code to Remote Users
16355| [1005285] Apache Web Server 'mod_dav' Has Null Pointer Bug That May Allow Remote Users to Cause Denial of Service Conditions
16356| [1005010] Apache Web Server (2.0) Has Unspecified Flaw That Allows Remote Users to Obtain Sensitive Data and Cause Denial of Service Conditions
16357| [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
16358| [1004745] Apache Tomcat Java Server Allows Cross-Site Scripting Attacks
16359| [1004636] Apache mod_ssl 'Off-by-One' Bug May Let Local Users Crash the Web Server or Possibly Execute Arbitrary Code
16360| [1004602] Apache Tomcat Java Server for Windows Can Be Crashed By Remote Users Sending Malicious Requests to Hang All Available Working Threads
16361| [1004586] Apache Tomcat Java Server May Disclose the Installation Path to Remote Users
16362| [1004555] Apache Web Server Chunked Encoding Flaw May Let Remote Users Execute Arbitrary Code on the Server
16363| [1004209] Apache 'mod_python' Python Language Interpreter Bug in Publisher Handler May Allow Remote Users to Modify Files on the System
16364| [1003874] Apache Web Server for Windows Has Batch File Processing Hole That Lets Remote Users Execute Commands on the System
16365| [1003767] 'mod_frontpage' Module for Apache Web Server Has Buffer Overlow in 'fpexec.c' That Allows Remote Users to Execute Arbitrary Code on the System with Root Privileges
16366| [1003723] Apache-SSL for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
16367| [1003664] 'mod_ssl' Security Package for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
16368| [1003602] GNUJSP Java Server Pages Implementation Discloses Web Files and Source Code to Remote Users and Bypasses Apache Access Control Restrictions
16369| [1003465] PHP for Apache Web Server May Disclose Installation Path Information to Remote Users Making 'OPTIONS' Requests
16370| [1003451] Oracle Application Server PL/SQL Module for Apache Has Buffer Overflows That Allow Remote Users to Execute Arbitrary Code and Gain Access to the Server
16371| [1003131] Apache Web Server in Virtual Hosting Mode Can Be Crashed By a Local User Removing a Log Directory
16372| [1003104] PHP.EXE Windows CGI for Apache Web Server May Let Remote Users View Files on the Server Due to Configuration Error
16373| [1003008] Apache 'mod_bf' Module Lets Remote Users Execute Arbitrary Code
16374| [1002629] Apache suEXEC Wrapper Fails to Observe Minimum Group ID Security Settings in Certain Situations
16375| [1002542] Apache Web Server Virtual Hosting Split-Logfile Function Lets Remote Users Write Log Entries to Arbitrary Files on the System
16376| [1002400] Apache mod_gzip Module Has Buffer Overflow That Can Be Exploited By Local Users to Gain Elevated Privileges
16377| [1002303] Several 3rd Party Apache Authentication Modules Allow Remote Users to Execute Arbitrary Code to Gain Access to the System or Execute Stored Procedures to Obtain Arbitrary Database Information
16378| [1002188] Apache Web Server Discloses Internal IP Addresses to Remote Users in Certain Configurations
16379| [1001989] Apache Web Server May Disclose Directory Contents Even If an Index.html File is Present in the Directory
16380| [1001719] Apache Web Server on Mac OS X Client Fails to Enforce File and Directory Access Protections, Giving Remote Users Access to Restricted Pages
16381| [1001572] Apache Web Server on Microsoft Windows Platforms Allows Remote Users to Crash the Web Server
16382| [1001304] Apache Web Server for Windows Lets Remote Users Crash the Web Server Application
16383| [1001083] Apache Web Server May Display Directory Index Listings Even if Directory Listings Are Disabled
16384|
16385| OSVDB - http://www.osvdb.org:
16386| [96078] Apache CloudStack Infrastructure Menu Setup Network Multiple Field XSS
16387| [96077] Apache CloudStack Global Settings Multiple Field XSS
16388| [96076] Apache CloudStack Instances Menu Display Name Field XSS
16389| [96075] Apache CloudStack Instances Menu Add Instances Network Name Field XSS
16390| [96074] Apache CloudStack Instances Menu Add Instances Review Step Multiple Field XSS
16391| [96031] Apache HTTP Server suEXEC Symlink Arbitrary File Access
16392| [95888] Apache Archiva Single / Double Quote Character Handling XSS Weakness
16393| [95885] Apache Subversion mod_dav_svn Module Crafted HTTP Request Handling Remote DoS
16394| [95706] Apache OpenOffice.org (OOo) OOXML Document File XML Element Handling Memory Corruption
16395| [95704] Apache OpenOffice.org (OOo) DOC File PLCF Data Handling Memory Corruption
16396| [95603] Apache Continuum web/util/GenerateRecipentNotifier.java recipient Parameter XSS
16397| [95602] Apache Continuum web/action/notifier/JabberProjectNotifierEditAction-jabberProjectNotifierSave-validation.xml Multiple Parameter XSS
16398| [95601] Apache Continuum web/action/notifier/JabberGroupNotifierEditAction-jabberProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
16399| [95600] Apache Continuum web/action/ScheduleAction-saveSchedule-validation.xml Multiple Parameter XSS
16400| [95599] Apache Continuumweb/action/BuildDefinitionAction-saveBuildDefinition-validation.xml Multiple Parameter XSS
16401| [95598] Apache Continuum web/action/AddProjectAction-addProject-validation.xml Multiple Parameter XSS
16402| [95597] Apache Continuum web/action/ProjectEditAction-projectSave-validation.xml Multiple Parameter XSS
16403| [95596] Apache Continuum web/action/notifier/IrcGroupNotifierEditAction-ircProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
16404| [95595] Apache Continuum web/action/notifier/IrcProjectNotifierEditAction-ircProjectNotifierSave-validation.xml Multiple Parameter XSS
16405| [95594] Apache Continuum web/action/ProjectGroupAction.java Multiple Parameter XSS
16406| [95593] Apache Continuum web/action/AddProjectGroupAction.java Multiple Parameter XSS
16407| [95592] Apache Continuum web/action/AddProjectAction.java Multiple Parameter XSS
16408| [95523] Apache OFBiz Webtools Application View Log Screen Unspecified XSS
16409| [95522] Apache OFBiz Nested Expression Evaluation Arbitrary UEL Function Execution
16410| [95521] Apache HTTP Server mod_session_dbd Session Saving Unspecified Issue
16411| [95498] Apache HTTP Server mod_dav.c Crafted MERGE Request Remote DoS
16412| [95406] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Arbitrary Site Redirect
16413| [95405] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Remote Code Execution
16414| [95011] Apache CXF XML Parser SOAP Message Handling CPU Resource Exhaustion Remote DoS
16415| [94705] Apache Geronimo RMI Classloader Exposure Serialized Object Handling Remote Code Execution
16416| [94651] Apache Santuario (XML Security for C++) XML Signature CanonicalizationMethod Parameter Spoofing Weakness
16417| [94636] Apache Continuum workingCopy.action userDirectory Traversal Arbitrary File Access
16418| [94635] Apache Maven SCM SvnCommandlineUtils Process Listing Local Password Disclosure
16419| [94632] Apache Maven Wagon SSH (wagon-ssh) Host Verification Failure MitM Weakness
16420| [94625] Apache Santuario (XML Security for C++) XML Signature Reference Crafted XPointer Expression Handling Heap Buffer Overflow
16421| [94618] Apache Archiva /archiva/security/useredit.action username Parameter XSS
16422| [94617] Apache Archiva /archiva/security/roleedit.action name Parameter XSS
16423| [94616] Apache Archiva /archiva/security/userlist!show.action roleName Parameter XSS
16424| [94615] Apache Archiva /archiva/deleteArtifact!doDelete.action groupId Parameter XSS
16425| [94614] Apache Archiva /archiva/admin/addLegacyArtifactPath!commit.action legacyArtifactPath.path Parameter XSS
16426| [94613] Apache Archiva /archiva/admin/addRepository.action Multiple Parameter XSS
16427| [94612] Apache Archiva /archiva/admin/editAppearance.action Multiple Parameter XSS
16428| [94611] Apache Archiva /archiva/admin/addLegacyArtifactPath.action Multiple Parameter XSS
16429| [94610] Apache Archiva /archiva/admin/addNetworkProxy.action Multiple Parameter XSS
16430| [94403] Apache Santuario (XML Security for C++) InclusiveNamespace PrefixList Processing Heap Overflow
16431| [94402] Apache Santuario (XML Security for C++) HMAC-based XML Signature Processing DoS
16432| [94401] Apache Santuario (XML Security for C++) XPointer Evaluation Stack Overflow
16433| [94400] Apache Santuario (XML Security for C++) HMAC-Based XML Signature Reference Element Validation Spoofing Weakness
16434| [94279] Apache Qpid CA Certificate Validation Bypass
16435| [94275] Apache Solr JettySolrRunner.java Can Not Find Error Message XSS
16436| [94233] Apache OpenJPA Object Deserialization Arbitrary Executable Creation
16437| [94042] Apache Axis JAX-WS Java Unspecified Exposure
16438| [93969] Apache Struts OGNL Expression Handling Double Evaluation Error Remote Command Execution
16439| [93796] Apache Subversion Filename Handling FSFS Repository Corruption Remote DoS
16440| [93795] Apache Subversion svnserve Server Aborted Connection Message Handling Remote DoS
16441| [93794] Apache Subversion contrib/hook-scripts/check-mime-type.pl svnlook Hyphenated argv Argument Handling Remote DoS
16442| [93793] Apache Subversion contrib/hook-scripts/svn-keyword-check.pl Filename Handling Remote Command Execution
16443| [93646] Apache Struts Crafted Parameter Arbitrary OGNL Code Execution
16444| [93645] Apache Struts URL / Anchor Tag includeParams Attribute Remote Command Execution
16445| [93636] Apache Pig Multiple Physical Operator Memory Exhaustion Remote Remote DoS
16446| [93635] Apache Wink DTD (Document Type Definition) Expansion Data Parsing Information Disclosure
16447| [93605] RT Apache::Session::File Session Replay Reuse Information Disclosure
16448| [93599] Apache Derby SYSCS_UTIL.SYSCS_SET_DATABASE_PROPERTY Boot Password Manipulation Re-encryption Failure Password Corruption
16449| [93555] Apache Commons Codec Invalid Base32 String Information Tunneling Weakness
16450| [93554] Apache HBase bulkLoadHFiles() Method ACL Bypass
16451| [93543] JBoss Enterprise Application Platform org.apache.catalina.connector.Response.encodeURL() Method MitM jsessionid Disclosure
16452| [93542] Apache ManifoldCF (Connectors Framework) org.apache.manifoldcf.crawler.ExportConfiguration Class Configuration Export Password Disclosure
16453| [93541] Apache Solr json.wrf Callback XSS
16454| [93524] Apache Hadoop GetSecurityDescriptorControl() Function Absolute Security Descriptor Handling NULL Descriptor Weakness
16455| [93521] Apache jUDDI Security API Token Session Persistence Weakness
16456| [93520] Apache CloudStack Default SSL Key Weakness
16457| [93519] Apache Shindig /ifr Cross-site Arbitrary Gadget Invocation
16458| [93518] Apache Solr /admin/analysis.jsp name Parameter XSS
16459| [93517] Apache CloudStack setup-cloud-management /etc/sudoers Modification Local Privilege Escalation
16460| [93516] Apache CXF UsernameTokenInterceptor Nonce Caching Replay Weakness
16461| [93515] Apache HBase table.jsp name Parameter XSS
16462| [93514] Apache CloudStack Management Server Unauthenticated Remote JMX Connection Default Setting Weakness
16463| [93463] Apache Struts EL / OGNL Interpretation Unspecified Remote Code Execution
16464| [93462] Apache CXF WS-SecurityPolicy AlgorithmSuite Arbitrary Ciphertext Decryption Weakness
16465| [93401] Apache Hadoop core-site.xml Permission Weakness Local Alfredo Secret Disclosure
16466| [93400] Apache Hadoop Map/Reduce Job Log Directory Symlink Arbitrary File Mode Manipulation
16467| [93397] Apache Wicket Referrer HTTP Header Session ID Disclosure
16468| [93366] Apache HTTP Server modules/mappers/mod_rewrite.c do_rewritelog() Function Log File Terminal Escape Sequence Filtering Remote Command Execution
16469| [93254] Apache Tomcat AsyncListener Method Cross-session Information Disclosure
16470| [93253] Apache Tomcat Chunked Transfer Encoding Data Saturation Remote DoS
16471| [93252] Apache Tomcat FORM Authenticator Session Fixation
16472| [93172] Apache Camel camel/endpoints/ Endpoint XSS
16473| [93171] Apache Sling HtmlResponse Error Message XSS
16474| [93170] Apache Directory DelegatingAuthenticator MitM Spoofing Weakness
16475| [93169] Apache Wave AuthenticationServlet.java Session Fixation Weakness
16476| [93168] Apache Click ErrorReport.java id Parameter XSS
16477| [93167] Apache ActiveMQ JMSXUserId Spoofing Weakness
16478| [93166] Apache CXF Crafted Message Element Count Handling System Resource Exhaustion Remote DoS
16479| [93165] Apache CXF Crafted Message Element Level Handling System Resource Exhaustion Remote DoS
16480| [93164] Apache Harmony DatagramSocket Class connect Method CheckAccept() IP Blacklist Bypass
16481| [93163] Apache Hadoop Map/Reduce Daemon Symlink Arbitrary File Overwrite
16482| [93162] Apache VelocityStruts struts/ErrorsTool.getMsgs Error Message XSS
16483| [93161] Apache CouchDB Rewriter VM Atom Table Memory Exhaustion Remote DoS
16484| [93158] Apache Wicket BookmarkablePageLink Feature XSS CSRF
16485| [93157] Apache Struts UrlHelper.java s:url includeParams Functionality XSS
16486| [93156] Apache Tapestry Calendar Component datefield.js datefield Parameter XSS
16487| [93155] Apache Struts fielderror.ftl fielderror Parameter Error Message XSS
16488| [93154] Apache JSPWiki Edit.jsp createPages WikiPermission Bypass
16489| [93153] Apache PDFBox PDFXrefStreamParser Missing Element Handling PDF Parsing DoS
16490| [93152] Apache Hadoop HttpServer.java Multiple Function XSS
16491| [93151] Apache Shiro Search Filter userName Parameter LDAP Code Injection Weakness
16492| [93150] Apache Harmony java.net.SocketPermission Class boolean equals Function checkConnect() Weakness Host Name Retrieval
16493| [93149] Apache Harmony java.security.Provider Class void load Function checkSecurityAccess() Weakness
16494| [93148] Apache Harmony java.security.ProtectionDomain Class java.lang.String.toString() Function checkPermission() Weakness
16495| [93147] Apache Harmony java.net.URLConnection openConnection Function checkConnect Weakness Proxy Connection Permission Bypass
16496| [93146] Apache Harmony java.net.ServerSocket Class void implAccept Function checkAccept() Weakness SerSocket Subclass Creation
16497| [93145] Apache Qpid JMS Client Detached Session Frame Handling NULL Pointer Dereference Remote DoS
16498| [93144] Apache Solr Admin Command Execution CSRF
16499| [93009] Apache VCL XMLRPC API Unspecified Function Remote Privilege Escalation
16500| [93008] Apache VCL Web GUI Unspecified Remote Privilege Escalation
16501| [92997] Apache Commons Codec org.apache.commons.codec.net.URLCodec Fields Missing 'final' Thread-safety Unspecified Issue
16502| [92976] Apache ActiveMQ scheduled.jsp crontab Command XSS
16503| [92947] Apache Commons Codec org.apache.commons.codec.language.Soundex.US_ENGLISH_MAPPING Missing MS_PKGPROTECT Field Manipulation Unspecified Issue
16504| [92749] Apache CloudStack Predictable Hash Virtual Machine Console Console Access URL Generation
16505| [92748] Apache CloudStack VM Console Access Restriction Bypass
16506| [92709] Apache ActiveMQ Web Console Unauthenticated Remote Access
16507| [92708] Apache ActiveMQ Sample Web Application Broker Resource Consumption Remote DoS
16508| [92707] Apache ActiveMQ webapp/websocket/chat.js Subscribe Message XSS
16509| [92706] Apache ActiveMQ Debug Log Rendering XSS
16510| [92705] Apache ActiveMQ PortfolioPublishServlet.java refresh Parameter XSS
16511| [92270] Apache Tomcat Unspecified CSRF
16512| [92094] Apache Subversion mod_dav_svn Module Nonexistent URL Lock Request Handling NULL Pointer Dereference Remote DoS
16513| [92093] Apache Subversion mod_dav_svn Module Activity URL PROPFIND Request Handling NULL Pointer Dereference Remote DoS
16514| [92092] Apache Subversion mod_dav_svn Module Log REPORT Request Handling NULL Pointer Dereference Remote DoS
16515| [92091] Apache Subversion mod_dav_svn Module Node Property Handling Resource Exhaustion Remote DoS
16516| [92090] Apache Subversion mod_dav_svn Module Activity URL Lock Request Handling NULL Pointer Dereference Remote DoS
16517| [91774] Apache Commons Codec Unspecified Non-private Field Manipulation Weakness
16518| [91628] mod_ruid2 for Apache HTTP Server fchdir() Inherited File Descriptor chroot Restriction Bypass
16519| [91328] Apache Wicket $up$ Traversal Arbitrary File Access
16520| [91295] Apple Mac OS X Apache Unicode Character URI Handling Authentication Bypass
16521| [91235] Apache Rave /app/api/rpc/users/get User Object Hashed Password Remote Disclosure
16522| [91185] Munin Default Apache Configuration Permission Weakness Remote Information Disclosure
16523| [91173] Apache Wicket WebApplicationPath Constructor Bypass /WEB-INF/ Directory File Access
16524| [91172] Apache Wicket PackageResourceGuard File Extension Filter Bypass
16525| [91025] Apache Qpid qpid::framing::Buffer Class Multiple Method Out-of-bounds Access Remote DoS
16526| [91024] Apache Qpid federation_tag Attribute Handling Federated Interbroker Link Access Restriction Bypass
16527| [91023] Apache Qpid AMQP Type Decoder Exposure Array Size Value Handling Memory Consumption Remote DoS
16528| [91022] Apache Qpid qpid/cpp/include/qpid/framing/Buffer.h qpid::framing::Buffer::checkAvailable() Function Integer Overflow
16529| [90986] Apache Jena ARQ INSERT DATA Request Handling Overflow
16530| [90907] Apache Subversion mod_dav_svn / libsvn_fs svn_fs_file_length() Function MKACTIVITY / PROPFIND Option Request Handling Remote DoS
16531| [90906] Apache Commons FileUpload /tmp Storage Symlink Arbitrary File Overwrite
16532| [90864] Apache Batik 1xx Redirect Script Origin Restriction Bypass
16533| [90858] Apache Ant Malformed TAR File Handling Infinite Loop DoS
16534| [90852] Apache HTTP Server for Debian apachectl /var/lock Permission Weakness Symlink Directory Permission Manipulation
16535| [90804] Apache Commons CLI Path Subversion Local Privilege Escalation
16536| [90802] Apache Avro Recursive Schema Handling Infinite Recursion DoS
16537| [90592] Apache Batik ApplicationSecurityEnforcer.java Multiple Method Security Restriction Bypass
16538| [90591] Apache Batik XML External Entity (XXE) Data Parsing Arbitrary File Disclosure
16539| [90565] Apache Tomcat Log Directory Permission Weakness Local Information Disclosure
16540| [90564] Apache Maven / Maven Wagon SSL Certificate Validation MitM Spoofing Weakness
16541| [90557] Apache HTTP Server mod_proxy_balancer balancer-manager Interface Multiple Parameter XSS
16542| [90556] Apache HTTP Server Multiple Module Multiple Parameter XSS
16543| [90276] Apache Axis2 axis2.xml Plaintext Password Local Disclosure
16544| [90249] Apache Axiom ClassLoader XMLInputFactory / XMLOutputFactory Construction Unspecified Issue
16545| [90235] Apache Commons HttpClient Certificate Wildcard Matching Weakness
16546| [90079] Apache CXF WSS4JInInterceptor URIMappingInterceptor WS-Security SOAP Service Access Restriction Bypass
16547| [90078] Apache CXF WS-SecurityPolicy Enabled Plaintext UsernameTokens Handling Authentication Bypass
16548| [89453] Apache Open For Business Project (OFBiz) Screenlet.title Widget Attribute XSS
16549| [89452] Apache Open For Business Project (OFBiz) Image.alt Widget Attribute XSS
16550| [89294] Apache CouchDB Futon UI Browser-based Test Suite Query Parameter XSS
16551| [89293] Apache CouchDB Unspecified Traversal Arbitrary File Access
16552| [89275] Apache HTTP Server mod_proxy_ajp Module Expensive Request Parsing Remote DoS
16553| [89267] Apache CouchDB JSONP Callback Handling Unspecified XSS
16554| [89146] Apache CloudStack Master Server log4j.conf SSH Private Key / Plaintext Password Disclosure
16555| [88603] Apache OpenOffice.org (OOo) Unspecified Information Disclosure
16556| [88602] Apache OpenOffice.org (OOo) Unspecified Manifest-processing Issue
16557| [88601] Apache OpenOffice.org (OOo) Unspecified PowerPoint File Handling Issue
16558| [88285] Apache Tomcat Partial HTTP Request Saturation Remote DoS
16559| [88095] Apache Tomcat NIO Connector Terminated Connection Infinte Loop DoS
16560| [88094] Apache Tomcat FORM Authentication Crafted j_security_check Request Security Constraint Bypass
16561| [88093] Apache Tomcat Null Session Requst CSRF Prevention Filter Bypass
16562| [88043] IBM Tivoli Netcool/Reporter Apache CGI Unspecified Remote Command Execution
16563| [87580] Apache Tomcat DIGEST Authentication Session State Caching Authentication Bypass Weakness
16564| [87579] Apache Tomcat DIGEST Authentication Stale Nonce Verification Authentication Bypass Weakness
16565| [87477] Apache Tomcat Project Woodstock Service Error Page UTF-7 XSS Weakness
16566| [87227] Apache Tomcat InternalNioInputBuffer.java parseHeaders() Function Request Header Size Parsing Remote DoS
16567| [87223] Apache Tomcat DIGEST Authentication replay-countermeasure Functionality cnonce / cn Verification Authentication Bypass Weakness
16568| [87160] Apache Commons HttpClient X.509 Certificate Domain Name Matching MiTM Weakness
16569| [87159] Apache CXF X.509 Certificate Domain Name Matching MiTM Weakness
16570| [87150] Apache Axis / Axis2 X.509 Certificate Domain Name Matching MiTM Weakness
16571| [86902] Apache HTTP Server 3xx Redirect Internal IP Address Remote Disclosure
16572| [86901] Apache Tomcat Error Message Path Disclosure
16573| [86684] Apache CloudStack Unauthorized Arbitrary API Call Invocation
16574| [86556] Apache Open For Business Project (OFBiz) Unspecified Issue
16575| [86503] Visual Tools VS home/apache/DiskManager/cron/init_diskmgr Local Command Execution
16576| [86401] Apache ActiveMQ ResourceHandler Traversal Arbitrary File Access
16577| [86225] Apache Axis2 XML Signature Wrapping (XSW) Authentication Bypass
16578| [86206] Apache Axis2 Crafted SAML Assertion Signature Exclusion Attack Authentication Bypass
16579| [85722] Apache CXF SOAP Request Parsing Access Restriction Bypass
16580| [85704] Apache Qpid Incoming Client Connection Saturation Remote DoS
16581| [85474] Eucalyptus Apache Santuario (XML Security for Java) Library XML Signature Transform Handling DoS
16582| [85430] Apache mod_pagespeed Module Unspecified XSS
16583| [85429] Apache mod_pagespeed Module Hostname Verification Cross-host Resource Disclosure
16584| [85249] Apache Wicket Unspecified XSS
16585| [85236] Apache Hadoop conf/hadoop-env.sh Temporary File Symlink Arbitrary File Manipulation
16586| [85090] Apache HTTP Server mod_proxy_ajp.c mod_proxy_ajp Module Proxy Functionality Cross-client Information Disclosure
16587| [85089] Apache HTTP Server mod_proxy_http.c mod_proxy_http Module Cross-client Information Disclosure
16588| [85062] Apache Solr Autocomplete Module for Drupal Autocomplete Results XSS
16589| [85010] Apache Struts Token Handling Mechanism Token Name Configuration Parameter CSRF Weakness
16590| [85009] Apache Struts Request Parameter OGNL Expression Parsing Remote DoS
16591| [84911] libapache2-mod-rpaf X-Forward-For HTTP Header Parsing Remote DoS
16592| [84823] Apache HTTP Server Multiple Module Back End Server Error Handling HTTP Request Parsing Remote Information Disclosure
16593| [84818] Apache HTTP Server mod_negotiation Module mod_negotiation.c make_variant_list Function XSS
16594| [84562] Apache Qpid Broker Authentication Mechanism AMQP Client Shadow Connection NullAuthenticator Request Parsing Authentication Bypass
16595| [84458] Apache Libcloud SSL Certificate Validation MitM Spoofing Weakness
16596| [84279] PHP on Apache php_default_post_reader POST Request Handling Overflow DoS
16597| [84278] PHP w/ Apache PDO::ATTR_DEFAULT_FETCH_MODE / PDO::FETCH_CLASS DoS
16598| [84231] Apache Hadoop DataNodes Client BlockTokens Arbitrary Block Access
16599| [83943] Oracle Solaris Cluster Apache Tomcat Agent Subcomponent Unspecified Local Privilege Escalation
16600| [83939] Oracle Solaris Apache HTTP Server Subcomponent Unspecified Remote Information Disclosure
16601| [83685] svnauthcheck Apache HTTP Configuration File Permission Revocation Weakness
16602| [83682] Apache Sling POST Servlet @CopyFrom Operation HTTP Request Parsing Infinite Loop Remote DoS
16603| [83339] Apache Roller Blogger Roll Unspecified XSS
16604| [83270] Apache Roller Unspecified Admin Action CSRF
16605| [82782] Apache CXF WS-SecurityPolicy 1.1 SupportingToken Policy Bypass
16606| [82781] Apache CXF WS-SecurityPolicy Supporting Token Children Specification Token Signing Verification Weakness
16607| [82611] cPanel Apache Piped Log Configuration Log Message Formatting Traversal Arbitrary File Creation
16608| [82436] MapServer for Windows Bundled Apache / PHP Configuration Local File Inclusion
16609| [82215] PHP sapi/cgi/cgi_main.c apache_request_headers Function HTTP Header Handling Remote Overflow
16610| [82161] Apache Commons Compress bzip2 File Compression BZip2CompressorOutputStream Class File Handling Remote DoS
16611| [81965] Apache Batik Squiggle SVG Browser JAR File Arbitrary Code Execution
16612| [81790] Apache POI src/org/apache/poi/hwpf/model/UnhandledDataStructure.java UnhandledDataStructure() constructor Length Attribute CDF / CFBF File Handling Remote DoS
16613| [81660] Apache Qpid Credential Checking Cluster Authentication Bypass
16614| [81511] Apache for Debian /usr/share/doc HTTP Request Parsing Local Script Execution
16615| [81359] Apache HTTP Server LD_LIBRARY_PATH Variable Local Privilege Escalation
16616| [81349] Apache Open For Business Project (OFBiz) Webslinger Component Unspecified XSS
16617| [81348] Apache Open For Business Project (OFBiz) Content IDs / Map-Keys Unspecified XSS
16618| [81347] Apache Open For Business Project (OFBiz) Parameter Arrays Unspecified XSS
16619| [81346] Apache Open For Business Project (OFBiz) checkoutProcess.js getServerError() Function Unspecified XSS
16620| [81196] Apache Open For Business Project (OFBiz) FlexibleStringExpander Nested Script String Parsing Remote Code Execution
16621| [80981] Apache Hadoop Kerberos/MapReduce Security Feature User Impersonation Weakness
16622| [80571] Apache Traffic Server Host HTTP Header Parsing Remote Overflow
16623| [80547] Apache Struts XSLTResult.java File Upload Arbitrary Command Execution
16624| [80360] AskApache Password Protector Plugin for WordPress Error Page $_SERVER Superglobal XSS
16625| [80349] Apache HTTP Server mod_fcgid Module fcgid_spawn_ctl.c FcgidMaxProcessesPerClass Virtual Host Directive HTTP Request Parsing Remote DoS
16626| [80301] Apache Wicket /resources/ Absolute Path Arbitrary File Access
16627| [80300] Apache Wicket wicket:pageMapName Parameter XSS
16628| [79478] Apache Solr Extension for TYPO3 Unspecified XSS
16629| [79002] Apache MyFaces javax.faces.resource In Parameter Traversal Arbitrary File Access
16630| [78994] Apache Struts struts-examples/upload/upload-submit.do name Parameter XSS
16631| [78993] Apache Struts struts-cookbook/processDyna.do message Parameter XSS
16632| [78992] Apache Struts struts-cookbook/processSimple.do message Parameter XSS
16633| [78991] Apache Struts struts2-rest-showcase/orders clientName Parameter XSS
16634| [78990] Apache Struts struts2-showcase/person/editPerson.action Multiple Parameter XSS
16635| [78932] Apache APR Hash Collision Form Parameter Parsing Remote DoS
16636| [78903] Apache CXF SOAP Request Parsing WS-Security UsernameToken Policy Bypass
16637| [78600] Apache Tomcat HTTP DIGEST Authentication DigestAuthenticator.java Catalina Weakness Security Bypass
16638| [78599] Apache Tomcat HTTP DIGEST Authentication Realm Value Parsing Security Bypass
16639| [78598] Apache Tomcat HTTP DIGEST Authentication qop Value Parsing Security Bypass
16640| [78573] Apache Tomcat Parameter Saturation CPU Consumption Remote DoS
16641| [78556] Apache HTTP Server Status Code 400 Default Error Response httpOnly Cookie Disclosure
16642| [78555] Apache HTTP Server Threaded MPM %{cookiename}C Log Format String Cookie Handling Remote DoS
16643| [78501] Apache Struts ParameterInterceptor Class OGNL Expression Parsing Remote Command Execution
16644| [78331] Apache Tomcat Request Object Recycling Information Disclosure
16645| [78293] Apache HTTP Server Scoreboard Invalid Free Operation Local Security Bypass
16646| [78277] Apache Struts ExceptionDelegator Component Parameter Parsing Remote Code Execution
16647| [78276] Apache Struts DebuggingInterceptor Component Developer Mode Unspecified Remote Command Execution
16648| [78113] Apache Tomcat Hash Collision Form Parameter Parsing Remote DoS
16649| [78112] Apache Geronimo Hash Collision Form Parameter Parsing Remote DoS
16650| [78109] Apache Struts ParameterInterceptor Traversal Arbitrary File Overwrite
16651| [78108] Apache Struts CookieInterceptor Cookie Name Handling Remote Command Execution
16652| [77593] Apache Struts Conversion Error OGNL Expression Injection
16653| [77496] Apache ActiveMQ Failover Mechanism Openwire Request Parsing Remote DoS
16654| [77444] Apache HTTP Server mod_proxy Mdule Web Request HTTP/0.9 Protocol URL Parsing Proxy Remote Security Bypass
16655| [77374] Apache MyFaces Java Bean includeViewParameters Parsing EL Expression Security Weakness
16656| [77310] Apache HTTP Server mod_proxy Reverse Proxy Mode Security Bypass Weakness (2011-4317)
16657| [77234] Apache HTTP Server on cygwin Encoded Traversal Arbitrary File Access
16658| [77012] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Memory Consumption DoS
16659| [76944] Apache Tomcat Manager Application Servlets Access Restriction Bypass
16660| [76744] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Overflow
16661| [76189] Apache Tomcat HTTP DIGEST Authentication Weakness
16662| [76079] Apache HTTP Server mod_proxy Mdule Web Request URL Parsing Proxy Remote Security Bypass (2011-3368)
16663| [76072] Apache JServ jserv.conf jserv-status Handler jserv/ URI Request Parsing Local Information Disclosure
16664| [75807] Apache HTTP Server Incomplete Header Connection Saturation Remote DoS
16665| [75647] Apache HTTP Server mod_proxy_ajp Module mod_proxy_balancer HTTP Request Remote DoS
16666| [75376] Apache Libcloud SSL Certificate Validation MitM Server Spoofing Weakness
16667| [74853] Domain Technologie Control /etc/apache2/apache2.conf File Permissions Weakness dtcdaemons User Password Disclosure
16668| [74818] Apache Tomcat AJP Message Injection Authentication Bypass
16669| [74725] Apache Wicket Multi Window Support Unspecified XSS
16670| [74721] Apache HTTP Server ByteRange Filter Memory Exhaustion Remote DoS
16671| [74541] Apache Commons Daemon Jsvc Permissions Weakness Arbitrary File Access
16672| [74535] Apache Tomcat XML Parser Cross-application Multiple File Manipulation
16673| [74447] Apache Struts XWork Nonexistent Method s:submit Element Internal Java Class Remote Path Disclosure
16674| [74262] Apache HTTP Server Multi-Processing Module itk.c Configuration Merger mpm-itk root UID / GID Remote Privilege Escalation
16675| [74120] Apache HTTP Server mod_authnz_external mysql/mysql-auth.pl user Field SQL Injection
16676| [73920] Oracle Secure Backup /apache/htdocts/php/common.php username Parameter Remote Code Execution
16677| [73798] Apache Tomcat sendfile Request Start / Endpoint Parsing Local DoS
16678| [73797] Apache Tomcat sendfile Request Attribute Validation Weakness Local Access Restriction Bypass
16679| [73776] Apache Tomcat HTTP BIO Connector HTTP Pipelining Cross-user Remote Response Access
16680| [73644] Apache XML Security Signature Key Parsing Overflow DoS
16681| [73600] Apache Struts javatemplates Plugin Component Handlers .action URI Multiple Parameter XSS
16682| [73462] Apache Rampart/C util/rampart_timestamp_token.c rampart_timestamp_token_validate Function Expired Token Remote Access Restriction Bypass
16683| [73429] Apache Tomcat JMX MemoryUserDatabase Local Password Disclosure
16684| [73384] Apache HTTP Server mod_rewrite PCRE Resource Exhaustion DoS
16685| [73383] Apache HTTP Server Portable Runtime (APR) Library apr_fnmatch() Infinite Loop Remote DoS
16686| [73378] IBM WebSphere Application Server (WAS) JavaServer Pages org.apache.jasper.runtime.JspWriterImpl.response JSP Page Application Restart Remote DoS
16687| [73247] Apache Subversion mod_dav_svn File Permission Weakness Information Disclosure
16688| [73246] Apache Subversion mod_dav_svn Path-based Access Control Rule Handling Remote DoS
16689| [73245] Apache Subversion mod_dav_svn Baselined Resource Request Handling Remote DoS
16690| [73154] Apache Archiva Multiple Unspecified CSRF
16691| [73153] Apache Archiva /archiva/admin/deleteNetworkProxy!confirm.action proxyid Parameter XSS
16692| [72407] Apache Tomcat @ServletSecurity Initial Load Annotation Security Constraint Bypass Information Disclosure
16693| [72238] Apache Struts Action / Method Names <
16694| [71647] Apache HttpComponents HttpClient Proxy-Authorization Credentials Remote Disclosure
16695| [71558] Apache Tomcat SecurityManager ServletContext Attribute Traversal Arbitrary File Manipulation
16696| [71557] Apache Tomcat HTML Manager Multiple XSS
16697| [71075] Apache Archiva User Management Page XSS
16698| [71027] Apache Tomcat @ServletSecurity Annotation Security Constraint Bypass Information Disclosure
16699| [70925] Apache Continuum Project Pages Unspecified XSS (2011-0533)
16700| [70924] Apache Continuum Multiple Admin Function CSRF
16701| [70809] Apache Tomcat NIO HTTP Connector Request Line Processing DoS
16702| [70734] Apache CouchDB Request / Cookie Handling Unspecified XSS
16703| [70585] Oracle Fusion Middleware Oracle HTTP Server Apache Plugin Unspecified Remote Issue
16704| [70333] Apache Subversion rev_hunt.c blame Command Multiple Memory Leak Remote DoS
16705| [70332] Apache Subversion Apache HTTP Server mod_dav_svn repos.c walk FunctionSVNParentPath Collection Remote DoS
16706| [69659] Apache Archiva Admin Authentication Weakness Privilege Escalation
16707| [69520] Apache Archiva Administrator Credential Manipulation CSRF
16708| [69512] Apache Tomcat Set-Cookie Header HTTPOnly Flag Session Hijacking Weakness
16709| [69456] Apache Tomcat Manager manager/html/sessions Multiple Parameter XSS
16710| [69275] Apache mod_fcgid Module fcgid_bucket.c fcgid_header_bucket_read() Function Remote Overflow
16711| [69067] Apache Shiro URI Path Security Traversal Information Disclosure
16712| [68815] Apache MyFaces shared/util/StateUtils.java View State MAC Weakness Cryptographic Padding Remote View State Modification
16713| [68670] Apache Qpid C++ Broker Component broker/SessionAdapter.cpp SessionAdapter::ExchangeHandlerImpl::checkAlternate Function Exchange Alternate Remote DoS
16714| [68669] Apache Qpid cluster/Cluster.cpp Cluster::deliveredEvent Function Invalid AMQP Data Remote DoS
16715| [68662] Apache Axis2 dswsbobje.war Module Admin Account Default Password
16716| [68531] Apache Qpid qpidd sys/ssl/SslSocket.cpp Incomplete SSL Handshake Remote DoS
16717| [68327] Apache APR-util buckets/apr_brigade.c apr_brigade_split_line() Function Memory Consumption DoS
16718| [68314] Apache XML-RPC SAX Parser External Entity Information Disclosure
16719| [67964] Apache Traffic Server Transaction ID / Source Port Randomization Weakness DNS Cache Poisoning
16720| [67846] SUSE Lifecycle Management Server on SUSE Linux Enterprise apache2-slms Parameter Quoting CSRF
16721| [67294] Apache CXF XML SOAP Message Crafted Document Type Declaration Remote DoS
16722| [67240] Apache CouchDB Installation Page Direct Request Arbitrary JavaScript Code Execution CSRF
16723| [67205] Apache Derby BUILTIN Authentication Password Hash Generation Algorithm SHA-1 Transformation Password Substitution
16724| [66745] Apache HTTP Server Multiple Modules Pathless Request Remote DoS
16725| [66319] Apache Tomcat Crafted Transfer-Encoding Header Handling Buffer Recycling Remote DoS
16726| [66280] Apache Struts XWork ParameterInterceptor Server-Side Object Remote Code Execution
16727| [66226] Apache Axis2 Admin Interface Cookie Session Fixation
16728| [65697] Apache Axis2 / Java SOAP Message DTD Rejection Weakness Arbitrary File Access
16729| [65654] Apache HTTP Server mod_proxy_http mod_proxy_http.c Timeout Detection Weakness HTTP Request Response Disclosure
16730| [65429] Apache MyFaces Unencrypted ViewState Serialized View Object Manipulation Arbitrary Expression Language (EL) Statement Execution
16731| [65054] Apache ActiveMQ Jetty Error Handler XSS
16732| [64844] Apache Axis2/Java axis2/axis2-admin/engagingglobally modules Parameter XSS
16733| [64522] Apache Open For Business Project (OFBiz) ecommerce/control/contactus Multiple Parameter XSS
16734| [64521] Apache Open For Business Project (OFBiz) Web Tools Section entityName Parameter XSS
16735| [64520] Apache Open For Business Project (OFBiz) ecommerce/control/ViewBlogArticle contentId Parameter XSS
16736| [64519] Apache Open For Business Project (OFBiz) Control Servlet URI XSS
16737| [64518] Apache Open For Business Project (OFBiz) Show Portal Page Section start Parameter XSS
16738| [64517] Apache Open For Business Project (OFBiz) View Profile Section partyId Parameter XSS
16739| [64516] Apache Open For Business Project (OFBiz) Export Product Listing Section productStoreId Parameter XSS
16740| [64307] Apache Tomcat Web Application Manager/Host Manager CSRF
16741| [64056] mod_auth_shadow for Apache HTTP Server wait() Function Authentication Bypass
16742| [64023] Apache Tomcat WWW-Authenticate Header Local Host Information Disclosure
16743| [64020] Apache ActiveMQ Jetty ResourceHandler Crafted Request JSP File Source Disclosure
16744| [63895] Apache HTTP Server mod_headers Unspecified Issue
16745| [63368] Apache ActiveMQ createDestination.action JMSDestination Parameter CSRF
16746| [63367] Apache ActiveMQ createDestination.action JMSDestination Parameter XSS
16747| [63350] Apache CouchDB Hash Verification Algorithm Predictable Execution Time Weakness
16748| [63140] Apache Thrift Service Malformed Data Remote DoS
16749| [62676] Apache HTTP Server mod_proxy_ajp Module Crafted Request Remote DoS
16750| [62675] Apache HTTP Server Multi-Processing Module (MPM) Subrequest Header Handling Cross-thread Information Disclosure
16751| [62674] Apache HTTP Server mod_isapi Module Unloading Crafted Request Remote DoS
16752| [62231] Apache HTTP Server Logging Format Weakness Crafted DNS Response IP Address Spoofing
16753| [62230] Apache HTTP Server Crafted DNS Response Inverse Lookup Log Corruption XSS
16754| [62054] Apache Tomcat WAR Filename Traversal Work-directory File Deletion
16755| [62053] Apache Tomcat Autodeployment Process appBase File HTTP Request Authentication Bypass
16756| [62052] Apache Tomcat WAR File Traversal Arbitrary File Overwrite
16757| [62009] Apache HTTP Server src/modules/proxy/proxy_util.c mod_proxy ap_proxy_send_fb() Function Overflow
16758| [61379] Apache River Outrigger Entry Storage Saturation Memory Exhaustion DoS
16759| [61378] Apache Hadoop Map/Reduce JobTracker Memory Consumption DoS
16760| [61377] Apache Commons Modeler Multiple Mutable Static Fields Weakness
16761| [61376] Apache Rampart wsse:security Tag Signature Value Checking Weakness
16762| [60687] Apache C++ Standard Library (STDCXX) strxfrm() Function Overflow
16763| [60680] Apache Hadoop JobHistory Job Name Manipulation Weakness
16764| [60679] Apache ODE DeploymentWebService OMElement zipPart CRLF Injection
16765| [60678] Apache Roller Comment Email Notification Manipulation DoS
16766| [60677] Apache CouchDB Unspecified Document Handling Remote DoS
16767| [60428] Sun Java Plug-in org.apache.crimson.tree.XmlDocument Class reateXmlDocument Method Floppy Drive Access Bypass
16768| [60413] mod_throttle for Apache Shared Memory File Manipulation Local Privilege Escalation
16769| [60412] Sun Java Plug-in org.apache.xalan.processor.XSLProcessorVersion Class Unsigned Applet Variable Sharing Privilege Escalation
16770| [60396] Apache HTTP Server on OpenBSD Multipart MIME Boundary Remote Information Disclosure
16771| [60395] Apache HTTP Server on OpenBSD ETag HTTP Header Remote Information Disclosure
16772| [60232] PHP on Apache php.exe Direct Request Remote DoS
16773| [60176] Apache Tomcat Windows Installer Admin Default Password
16774| [60016] Apache HTTP Server on HP Secure OS for Linux HTTP Request Handling Unspecified Issue
16775| [59979] Apache HTTP Server on Apple Mac OS X HTTP TRACE Method Unspecified Client XSS
16776| [59969] Apache HTTP Server mod_ssl SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection
16777| [59944] Apache Hadoop jobhistory.jsp XSS
16778| [59374] Apache Solr Search Extension for TYPO3 Unspecified XSS
16779| [59022] Apache Shindig ConcatProxyServlet HTTP Header Response Splitting
16780| [59021] Apache Cocoon X-Cocoon-Version Header Remote Information Disclosure
16781| [59020] Apache Tapestry HTTPS Session Cookie Secure Flag Weakness
16782| [59019] Apache mod_python Cookie Salting Weakness
16783| [59018] Apache Harmony Error Message Handling Overflow
16784| [59013] Apache Derby SYSCS_EXPORT_TABLE Arbitrary File Overwrite
16785| [59012] Apache Derby Driver Auto-loading Non-deterministic Startup Weakness
16786| [59011] Apache JSPWiki Page Attachment Change Note Function XSS
16787| [59010] Apache Solr get-file.jsp XSS
16788| [59009] Apache Solr action.jsp XSS
16789| [59008] Apache Solr analysis.jsp XSS
16790| [59007] Apache Solr schema.jsp Multiple Parameter XSS
16791| [59006] Apache Beehive select / checkbox Tag XSS
16792| [59005] Apache Beehive jpfScopeID Global Parameter XSS
16793| [59004] Apache Beehive Error Message XSS
16794| [59003] Apache HttpClient POST Request Handling Memory Consumption DoS
16795| [59002] Apache Jetspeed default-page.psml URI XSS
16796| [59001] Apache Axis2 xsd Parameter Traversal Arbitrary File Disclosure
16797| [59000] Apache CXF Unsigned Message Policy Bypass
16798| [58999] Apache WSS4J CallbackHandler Plaintext Password Validation Weakness
16799| [58998] Apache OpenJPA persistence.xml Cleartext Password Local Disclosure
16800| [58997] Apache OpenEJB openejb.xml Cleartext Password Local Disclosure
16801| [58996] Apache Hadoop Map/Reduce LinuxTaskController File Group Ownership Weakness
16802| [58995] Apache Hadoop Map/Reduce Task Ownership Weakness
16803| [58994] Apache Hadoop Map/Reduce DistributedCache Localized File Permission Weakness
16804| [58993] Apache Hadoop browseBlock.jsp XSS
16805| [58991] Apache Hadoop browseDirectory.jsp XSS
16806| [58990] Apache Hadoop Map/Reduce HTTP TaskTrackers User Data Remote Disclosure
16807| [58989] Apache Hadoop Sqoop Process Listing Local Cleartext Password Disclosure
16808| [58988] Apache Hadoop Chukwa HICC Portal Unspecified XSS
16809| [58987] Apache Hadoop Map/Reduce TaskTracker User File Permission Weakness
16810| [58986] Apache Qpid Encrypted Message Handling Remote Overflow DoS
16811| [58985] Apache Qpid Process Listing Local Cleartext Password Disclosure
16812| [58984] Apache Jackrabbit Content Repository (JCR) Default Account Privilege Access Weakness
16813| [58983] Apache Jackrabbit Content Repository (JCR) NamespaceRegistry API Registration Method Race Condition
16814| [58982] Apache Synapse Proxy Service Security Policy Mismatch Weakness
16815| [58981] Apache Geronimo TomcatGeronimoRealm Security Context Persistence Weakness
16816| [58980] Apache Geronimo LDAP Realm Configuration Restart Reversion Weakness
16817| [58979] Apache MyFaces Tomahawk ExtensionsPhaseListener HTML Injection Information Disclosure
16818| [58978] Apache MyFaces Trinidad LocaleInfoScriptlet XSS
16819| [58977] Apache Open For Business Project (OFBiz) Multiple Default Accounts
16820| [58976] Apache Open For Business Project (OFBiz) URI passThru Parameter XSS
16821| [58975] Apache Open For Business Project (OFBiz) PARTYMGR_CREATE/UPDATE Permission Arbitrary User Password Modification
16822| [58974] Apache Sling /apps Script User Session Management Access Weakness
16823| [58973] Apache Tuscany Crafted SOAP Request Access Restriction Bypass
16824| [58931] Apache Geronimo Cookie Parameters Validation Weakness
16825| [58930] Apache Xalan-C++ XPath Handling Remote DoS
16826| [58879] Apache Portable Runtime (APR-util) poll/unix/port.c Event Port Backend Pollset Feature Remote DoS
16827| [58837] Apache Commons Net FTPSClient CipherSuites / Protocols Mutable Object Unspecified Data Security Issue
16828| [58813] Apache MyFaces Trinidad tr:table / HTML Comment Handling DoS
16829| [58812] Apache Open For Business Project (OFBiz) JSESSIONID Session Hijacking Weakness
16830| [58811] Apache Open For Business Project (OFBiz) /catalog/control/EditProductConfigItem configItemId Parameter XSS
16831| [58810] Apache Open For Business Project (OFBiz) /catalog/control/EditProdCatalo prodCatalogId Parameter XSS
16832| [58809] Apache Open For Business Project (OFBiz) /partymgr/control/viewprofile partyId Parameter XSS
16833| [58808] Apache Open For Business Project (OFBiz) /catalog/control/createProduct internalName Parameter XSS
16834| [58807] Apache Open For Business Project (OFBiz) Multiple Unspecified CSRF
16835| [58806] Apache FtpServer MINA Logging Filter Cleartext Credential Local Disclosure
16836| [58805] Apache Derby Unauthenticated Database / Admin Access
16837| [58804] Apache Wicket Header Contribution Unspecified Issue
16838| [58803] Apache Wicket Session Fixation
16839| [58802] Apache Directory Server (ApacheDS) userPassword Attribute Search Password Disclosure
16840| [58801] Apache ActiveMQ Stomp Client Credential Validation Bypass
16841| [58800] Apache Tapestry (context)/servicestatus Internal Service Information Disclosure
16842| [58799] Apache Tapestry Logging Cleartext Password Disclosure
16843| [58798] Apache Jetspeed pipeline Parameter pipeline-map Policy Bypass
16844| [58797] Apache Jetspeed Password Policy Multiple Weaknesses
16845| [58796] Apache Jetspeed Unsalted Password Storage Weakness
16846| [58795] Apache Rampart Crafted SOAP Header Authentication Bypass
16847| [58794] Apache Roller Admin Protocol (RAP) Malformed Header Authentication Bypass
16848| [58793] Apache Hadoop Map/Reduce mapred.system.dir Permission Weakness Job Manipulation
16849| [58792] Apache Shindig gadgets.rpc iframe RPC Call Validation Weakness
16850| [58791] Apache Synapse synapse.properties Cleartext Credential Local Disclosure
16851| [58790] Apache WSS4J SOAP Message UsernameToken Remote Password Disclosure
16852| [58789] Apache WSS4J SOAP Header Malformed UsernameToken Authentication Bypass
16853| [58776] Apache JSPWiki PreviewContent.jsp Edited Text XSS
16854| [58775] Apache JSPWiki preview.jsp action Parameter XSS
16855| [58774] Apache JSPWiki Edit.jsp Multiple Parameter XSS
16856| [58773] Apache JSPWiki Accept-Language Header Multiple Script language Parameter XSS
16857| [58772] Apache JSPWiki EditorManager.java editor Parameter XSS
16858| [58771] Apache JSPWiki GroupContent.jsp Multiple Parameter XSS
16859| [58770] Apache JSPWiki Group.jsp group Parameter XSS
16860| [58769] Apache JSPWiki Database Connection Termination DoS Weakness
16861| [58768] Apache JSPWiki Attachment Servlet nextpage Parameter Arbitrary Site Redirect
16862| [58766] Apache JSPWiki /admin/SecurityConfig.jsp Direct Request Information Disclosure
16863| [58765] Apache JSPWiki Spam Filter UniqueID RNG Weakness
16864| [58764] Apache JSPWiki Edit.jsp Multiple Parameter XSS
16865| [58763] Apache JSPWiki Include Tag Multiple Script XSS
16866| [58762] Apache JSPWiki Multiple .java Tags pageContext Parameter XSS
16867| [58761] Apache JSPWiki Wiki.jsp skin Parameter XSS
16868| [58760] Apache Commons VFS Exception Error Message Cleartext Credential Disclosure
16869| [58759] Apache Jackrabbit Content Repository (JCR) UUID System.currentTimeMillis() RNG Weakness
16870| [58758] Apache River GrantPermission Policy Manipulation Privilege Escalation
16871| [58757] Apache WS-Commons Java2 StaXUtils Multiple Unspecified Minor Issues
16872| [58756] Apache WSS4J WSHandler Client Certificate Signature Validation Weakness
16873| [58755] Apache Harmony DRLVM Non-public Class Member Access
16874| [58754] Apache Harmony File.createTempFile() Temporary File Creation Prediction Weakness
16875| [58751] Apache Geronimo GeronimoIdentityResolver Subject Handling Multiple Issues
16876| [58750] Apache MyFaces Trinidad Generated HTML Information Disclosure
16877| [58749] Apache MyFaces Trinidad Database Access Error Message Information Disclosure
16878| [58748] Apache MyFaces Trinidad Image Resource Loader Traversal Arbitrary Image Access
16879| [58747] Apache MyFaces Trinidad Error Message User Entered Data Disclosure Weakness
16880| [58746] Apache Axis2 JAX-WS Java2 WSDL4J Unspecified Issue
16881| [58744] Apache Wicket Crafted File Upload Disk Space Exhaustion DoS
16882| [58743] Apache Wicket wicket.util.crypt.SunJceCrypt Encryption Reversion Weakness
16883| [58742] Apache Rampart PolicyBasedValiadtor HttpsToken Endpoint Connection Weakness
16884| [58741] Apache Rampart WSSecSignature / WSSecEncryptedKey KeyIdentifierType Validation Weakness
16885| [58740] Apache Rampart TransportBinding Message Payload Cleartext Disclosure
16886| [58739] Apache Open For Business Project (OFBiz) Unsalted Password Storage Weakness
16887| [58738] Apache Open For Business Project (OFBiz) orderId Parameter Arbitrary Order Access
16888| [58737] Apache mod_python w/ mod_python.publisher index.py Underscore Prefixed Variable Disclosure
16889| [58735] Apache Open For Business Project (OFBiz) /ecommerce/control/keywordsearch SEARCH_STRING Parameter XSS
16890| [58734] Apache Torque Log File Cleartext Credential Local Disclosure
16891| [58733] Apache Axis2 doGet Implementation Authentication Bypass Service State Manipulation
16892| [58732] Apache MyFaces UIInput.validate() Null Value Validation Bypass Weakness
16893| [58731] Apache MyFaces /faces/* Prefix Mapping Authentication Bypass
16894| [58725] Apache Tapestry Basic String ACL Bypass Weakness
16895| [58724] Apache Roller Logout Functionality Failure Session Persistence
16896| [58723] Apache Roller User Profile / Admin Page Cleartext Password Disclosure
16897| [58722] Apache Derby Connection URL Encryption Method Reversion Weakness
16898| [58721] Apache Geronimo on Tomcat Security-constraint Resource ACL Bypass
16899| [58720] Apache Geronimo Explicit Servlet Mapping Access Bypass Weakness
16900| [58719] Apache Geronimo Keystore Unprivileged Service Disable DoS
16901| [58718] Apache Geronimo Deployment Plans Remote Password Disclosure
16902| [58717] Apache Jetspeed Portlet Application Edit Access Restriction Bypass
16903| [58716] Apache Jetspeed PSML Management Cached Constraint Authentication Weakness
16904| [58707] Apache WSS4J Crafted PasswordDigest Request Authentication Bypass
16905| [58706] Apache HttpClient Pre-emptive Authorization Remote Credential Disclosure
16906| [58705] Apache Directory Server (ApacheDS) User Passwords Cleartext Disclosure
16907| [58704] Apache Directory Server (ApacheDS) Non-existent User LDAP Bind Remote DoS
16908| [58703] Apache Geronimo Debug Console Unauthenticated Remote Information Disclosure
16909| [58702] Apache Directory Server (ApacheDS) Persistent LDAP Anonymous Bind Weakness
16910| [58701] Apache Jetspeed User Admin Portlet Unpassworded Account Creation Weakness
16911| [58700] Apache MyFaces /faces/* Path Handling Remote Overflow DoS
16912| [58699] Apache MyFaces Disable Property Client Side Manipulation Privilege Escalation
16913| [58698] Apache Roller Remember Me Functionality Cleartext Password Disclosure
16914| [58697] Apache XalanJ2 org.apache.xalan.xsltc.runtime.CallFunction Class Unspecified Issue
16915| [58696] Apache Tapestry Encoded Traversal Arbitrary File Access
16916| [58695] Apache Jetspeed Unauthenticated PSML Tags / Admin Folder Access
16917| [58694] Apache Geronimo Deploy Tool Process List Local Credential Disclosure
16918| [58693] Apache Derby service.properties File Encryption Key Information Disclosure
16919| [58692] Apache Geronimo Default Security Realm Login Brute Force Weakness
16920| [58689] Apache Roller Retrieve Last 5 Post Feature Unauthorized Blog Post Manipulation
16921| [58688] Apache Xalan-Java (XalanJ2) Static Variables Multiple Unspecified Issues
16922| [58687] Apache Axis Invalid wsdl Request XSS
16923| [58686] Apache Cocoon Temporary File Creation Unspecified Race Condition
16924| [58685] Apache Velocity Template Designer Privileged Code Execution
16925| [58684] Apache Jetspeed controls.Customize Action Security Check Bypass
16926| [58675] Apache Open For Business Project (OFBiz) eCommerce/ordermgr Multiple Field XSS
16927| [58674] Apache Open For Business Project (OFBiz) ecommerce/control/login Multiple Field XSS
16928| [58673] Apache Open For Business Project (OFBiz) ecommerce/control/viewprofile Multiple Field XSS
16929| [58672] Apache Open For Business Project (OFBiz) POS Input Panel Cleartext Password Disclosure
16930| [58671] Apache Axis2 JMS Signed Message Crafted WS-Security Header Security Bypass
16931| [58670] Apache Jetspeed JetspeedTool.getPortletFromRegistry Portlet Security Validation Failure
16932| [58669] Apache Jetspeed LDAP Cleartext Passwords Disclosure
16933| [58668] Apache Axis External Entity (XXE) Data Parsing Privilege Escalation
16934| [58667] Apache Roller Database Cleartext Passwords Disclosure
16935| [58666] Apache Xerces-C++ UTF-8 Transcoder Overlong Code Handling Unspecified Issue
16936| [58665] Apache Jetspeed Turbine: Cross-user Privileged Action Execution
16937| [58664] Apache Jetspeed EditAccount.vm Password Modification Weakness
16938| [58663] Apache Jetspeed Role Parameter Arbitrary Portlet Disclosure
16939| [58662] Apache Axis JWS Page Generated .class File Direct Request Information Disclosure
16940| [58661] Apache Jetspeed user-form.vm Password Reset Cleartext Disclosure
16941| [58660] Apache WSS4J checkReceiverResults Function Crafted SOAP Request Authentication Bypass
16942| [58658] Apache Rampart Crafted SOAP Request Security Verification Bypass
16943| [57882] Apache HTTP Server mod_proxy_ftp Authorization HTTP Header Arbitrary FTP Command Injection
16944| [57851] Apache HTTP Server mod_proxy_ftp EPSV Command NULL Dereference Remote DoS
16945| [56984] Apache Xerces2 Java Malformed XML Input DoS
16946| [56903] Apache ODE (Orchestration Director Engine) Process Deployment Web Service Traversal Arbitrary File Manipulation
16947| [56859] Apache Xerces-C++ Multiple Sub-project XML Nested DTD Structures Parsing Recursion Error DoS
16948| [56766] Apache Portable Runtime (APR-util) memory/unix/apr_pools.c Relocatable Memory Block Aligning Overflow
16949| [56765] Apache Portable Runtime (APR-util) misc/apr_rmm.c Multiple Function Overflows
16950| [56517] Apache HTTP Server File Descriptor Leak Arbitrary Local File Append
16951| [56443] PTK Unspecified Apache Sub-process Arbitrary Command Execution
16952| [56414] Apache Tiles Duplicate Expression Language (EL) Expression Evaluation XSS
16953| [55814] mod_NTLM for Apache HTTP Server ap_log_rerror() Function Remote Format String
16954| [55813] mod_NTLM for Apache HTTP Server log() Function Remote Overflow
16955| [55782] Apache HTTP Server mod_deflate Module Aborted Connection DoS
16956| [55553] Apache HTTP Server mod_proxy Module mod_proxy_http.c stream_reqbody_cl Function CPU Consumption DoS
16957| [55059] Apache APR-util strmatch/apr_strmatch.c apr_strmatch_precompile Function Crafted Input Remote DoS
16958| [55058] Apache APR-util apr_brigade_vprintf Function Crafted Input Off-by-one Remote DoS
16959| [55057] Apache APR-util xml/apr_xml.c apr_xml_* Interface Expat XML Parser Crafted XML Document Remote DoS
16960| [55056] Apache Tomcat Cross-application TLD File Manipulation
16961| [55055] Apache Tomcat Illegal URL Encoded Password Request Username Enumeration
16962| [55054] Apache Tomcat Java AJP Connector mod_jk Load Balancing Worker Malformed Header Remote DoS
16963| [55053] Apache Tomcat Crafted Request Security Restraint Bypass Arbitrary Content Access
16964| [54733] Apache HTTP Server AllowOverride Directive .htaccess Options Bypass
16965| [54713] razorCMS Security Manager apache User Account Unspecified File Permission Weakness Issue
16966| [54589] Apache Jserv Nonexistent JSP Request XSS
16967| [54122] Apache Struts s:a / s:url Tag href Element XSS
16968| [54093] Apache ActiveMQ Web Console JMS Message XSS
16969| [53932] Apache Geronimo Multiple Admin Function CSRF
16970| [53931] Apache Geronimo /console/portal/Server/Monitoring Multiple Parameter XSS
16971| [53930] Apache Geronimo /console/portal/ URI XSS
16972| [53929] Apache Geronimo on Windows Security/Keystores Portlet Traversal Arbitrary File Upload
16973| [53928] Apache Geronimo on Windows Embedded DB/DB Manager Portlet Traversal Arbitrary File Upload
16974| [53927] Apache Geronimo on Windows Services/Repository Portlet Traversal Arbitrary File Upload
16975| [53921] Apache HTTP Server mod_proxy_ajp Cross Thread/Session Information Disclosure
16976| [53766] Oracle BEA WebLogic Server Plug-ins for Apache Certificate Handling Remote Overflow
16977| [53574] PHP on Apache .htaccess mbstring.func_overload Setting Cross Hosted Site Behavior Modification
16978| [53381] Apache Tomcat JK Connector Content-Length Header Cross-user Information Disclosure
16979| [53380] Apache Struts Unspecified XSS
16980| [53289] Apache mod_perl Apache::Status /perl-status Unspecified XSS
16981| [53186] Apache HTTP Server htpasswd Predictable Salt Weakness
16982| [52899] Apache Tomcat Examples Web Application Calendar Application jsp/cal/cal2.jsp time Parameter XSS
16983| [52407] Apache Tomcat doRead Method POST Content Information Disclosure
16984| [51923] Apache HTTP Server mod-auth-mysql Module mod_auth_mysql.c Multibyte Character Encoding SQL Injection
16985| [51613] Apache HTTP Server Third-party Module Child Process File Descriptor Leak
16986| [51612] Apache HTTP Server Internal Redirect Handling Infinite Loop DoS
16987| [51468] Apache Jackrabbit Content Repository (JCR) swr.jsp q Parameter XSS
16988| [51467] Apache Jackrabbit Content Repository (JCR) search.jsp q Parameter XSS
16989| [51151] Apache Roller Search Function q Parameter XSS
16990| [50482] PHP with Apache php_value Order Unspecified Issue
16991| [50475] Novell NetWare ApacheAdmin Console Unauthenticated Access
16992| [49734] Apache Struts DefaultStaticContentLoader Class Traversal Arbitrary File Access
16993| [49733] Apache Struts FilterDispatcher Class Traversal Arbitrary File Access
16994| [49283] Oracle BEA WebLogic Server Plugins for Apache Remote Transfer-Encoding Overflow
16995| [49062] Apache Tomcat Cross-thread Concurrent Request Variable Overwrite Information Disclosure
16996| [48847] ModSecurity (mod_security) Transformation Caching Unspecified Apache DoS
16997| [48788] Apache Xerces-C++ XML Schema maxOccurs Value XML File Handling DoS
16998| [47474] Apache HTTP Server mod_proxy_ftp Directory Component Wildcard Character XSS
16999| [47464] Apache Tomcat allowLinking / UTF-8 Traversal Arbitrary File Access
17000| [47463] Apache Tomcat RequestDispatcher Traversal Arbitrary File Access
17001| [47462] Apache Tomcat HttpServletResponse.sendError Method Message Argument XSS
17002| [47096] Oracle Weblogic Apache Connector POST Request Overflow
17003| [46382] Frontend Filemanager (air_filemanager) Extension for TYPO3 on Apache Unspecified Arbitrary Code Execution
17004| [46285] TYPO3 on Apache Crafted Filename Upload Arbitrary Command Execution
17005| [46085] Apache HTTP Server mod_proxy ap_proxy_http_process_response() Function Interim Response Forwarding Remote DoS
17006| [45905] Apache Tomcat Host Manager host-manager/html/add name Parameter XSS
17007| [45879] Ragnarok Online Control Panel on Apache Crafted Traversal Authentication Bypass
17008| [45742] Apache HTTP Server on Novell Unspecified Request Directive Internal IP Disclosure
17009| [45740] Apache Derby DropSchemaNode Bind Phase Arbitrary Scheme Statement Dropping
17010| [45599] Apache Derby Lock Table Statement Privilege Requirement Bypass Arbitrary Table Lock
17011| [45585] Apache Derby ACCSEC Command RDBNAM Parameter Cleartext Credential Disclosure
17012| [45584] Apache Derby DatabaseMetaData.getURL Function Cleartext Credential Disclosure
17013| [45420] Apache HTTP Server 403 Error Page UTF-7 Encoded XSS
17014| [44728] PHP Toolkit on Gentoo Linux Interpretation Conflict Apache HTTP Server Local DoS
17015| [44618] Oracle JSP Apache/Jserv Path Translation Traversal Arbitrary JSP File Execution
17016| [44159] Apache HTTP Server Remote Virtual Host Name Disclosure
17017| [43997] Apache-SSL ExpandCert() Function Certificate Handling Arbitrary Environment Variables Manipulation
17018| [43994] suPHP for Apache (mod_suphp) Directory Symlink Local Privilege Escalation
17019| [43993] suPHP for Apache (mod_suphp) Owner Mode Race Condition Symlink Local Privilege Escalation
17020| [43663] Apache HTTP Server Mixed Platform AddType Directive Crafted Request PHP Source Disclosure
17021| [43658] AuthCAS Module (AuthCAS.pm) for Apache HTTP Server SESSION_COOKIE_NAME SQL Injection
17022| [43452] Apache Tomcat HTTP Request Smuggling
17023| [43309] Apache Geronimo LoginModule Login Method Bypass
17024| [43290] Apache JSPWiki Entry Page Attachment Unrestricted File Upload
17025| [43259] Apache HTTP Server on Windows mod_proxy_balancer URL Handling Remote Memory Corruption
17026| [43224] Apache Geronimo on SuSE Linux init Script Symlink Unspecified File/Directory Access
17027| [43189] Apache mod_jk2 Host Header Multiple Fields Remote Overflow
17028| [42937] Apache HTTP Server mod_proxy_balancer balancer-manager Unspecified CSRF
17029| [42341] MOD_PLSQL for Apache Unspecified URL SQL Injection
17030| [42340] MOD_PLSQL for Apache CGI Environment Handling Unspecified Overflow
17031| [42214] Apache HTTP Server mod_proxy_ftp UTF-7 Encoded XSS
17032| [42091] Apache Maven Site Plugin Installation Permission Weakness
17033| [42089] Apache Maven .m2/settings.xml Cleartext Password Disclosure
17034| [42088] Apache Maven Defined Repo Process Listing Password Disclosure
17035| [42087] Apache Maven Site Plugin SSH Deployment Permission Setting Weakness
17036| [42036] Apache HTTP Server MS-DOS Device Request Host OS Disclosure
17037| [41891] BEA WebLogic Apache Beehive NetUI Page Flow Unspecified XSS
17038| [41436] Apache Tomcat Native APR Connector Duplicate Request Issue
17039| [41435] Apache Tomcat %5C Cookie Handling Session ID Disclosure
17040| [41434] Apache Tomcat Exception Handling Subsequent Request Information Disclosure
17041| [41400] LimeSurvey save.php Apache Log File PHP Code Injection
17042| [41029] Apache Tomcat Calendar Examples Application cal2.jsp Multiple Parameter CSRF
17043| [41019] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload XSS
17044| [41018] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload CRLF
17045| [40853] Apache Tomcat SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) JSESSIONIDSSO Cookie Security Weakness
17046| [40264] Apache HTTP Server mod_proxy_balancer balancer_handler Function bb Variable Remote DoS
17047| [40263] Apache HTTP Server mod_proxy_balancer balancer-manager Multiple Parameter XSS
17048| [40262] Apache HTTP Server mod_status refresh XSS
17049| [39833] Apache Tomcat JULI Logging Component catalina.policy Security Bypass
17050| [39251] Coppermine Photo Gallery on Apache Multiple File Extension Upload Arbitrary Code Execution
17051| [39166] Apache Tomcat on Windows caseSensitive Attribute Mixed Case Request JSP Source Disclosure
17052| [39134] Apache mod_imagemap Module Imagemap Unspecified XSS
17053| [39133] Apache mod_imap Module Imagemap File Unspecified XSS
17054| [39035] Apache Tomcat examples/servlet/CookieExample Multiple Parameter XSS
17055| [39003] Apache HTTP Server HTTP Method Header Request Entity Too Large XSS
17056| [39000] Apache Tomcat SendMailServlet sendmail.jsp mailfrom Parameter XSS
17057| [38939] Apache HTTP Server Prefork MPM Module Array Modification Local DoS
17058| [38673] Apache Jakarta Slide WebDAV SYSTEM Request Traversal Arbitrary File Access
17059| [38662] Apache Geronimo SQLLoginModule Nonexistent User Authentication Bypass
17060| [38661] Apache Geronimo MEJB Unspecified Authentication Bypass
17061| [38641] Apache HTTP Server mod_mem_cache recall_headers Function Information Disclosure
17062| [38640] Apache HTTP Server suexec Document Root Unauthorized Operations
17063| [38639] Apache HTTP Server suexec Multiple Symlink Privilege Escalation
17064| [38636] Apache HTTP Server mod_autoindex.c P Variable UTF-7 Charset XSS
17065| [38513] BEA WebLogic Server Proxy Plug-in for Apache Protocol Error Handling Remote DoS
17066| [38187] Apache Geronimo / Tomcat WebDAV XML SYSTEM Tag Arbitrary File Access
17067| [37079] Apache HTTP Server mod_cache cache_util.c Malformed Cache-Control Header DoS
17068| [37071] Apache Tomcat Cookie Handling Session ID Disclosure
17069| [37070] Apache Tomcat Cookie Handling Quote Delimiter Session ID Disclosure
17070| [37052] Apache HTTP Server mod_status mod_status.c Unspecified XSS
17071| [37051] Apache HTTP Server mod_proxy modules/proxy/proxy_util.c Crafted Header Remote DoS
17072| [37050] Apache HTTP Server Prefork MPM Module Crafted Code Sequence Local DoS
17073| [36417] Apache Tomcat Host Manager Servlet html/add Action aliases Parameter XSS
17074| [36377] Apache MyFaces Tomahawk JSF Application autoscroll Multiple Script XSS
17075| [36080] Apache Tomcat JSP Examples Crafted URI XSS
17076| [36079] Apache Tomcat Manager Uploaded Filename XSS
17077| [34888] Apache Tomcat Example Calendar Application cal2.jsp time Parameter XSS
17078| [34887] Apache Tomcat implicit-objects.jsp Crafted Header XSS
17079| [34885] Apache Tomcat on IIS Servlet Engine MS-DOS Device Request DoS
17080| [34884] Apache Tomcat on Windows Nonexistent Resource Request Path Disclosure
17081| [34883] Apache Tomcat Crafted JSP File Request Path Disclosure
17082| [34882] Apache Tomcat Default SSL Ciphersuite Configuration Weakness
17083| [34881] Apache Tomcat Malformed Accept-Language Header XSS
17084| [34880] Apache Tomcat HTTP/1.1 Connector NULL Byte Request JSP Source Disclosure
17085| [34879] Apache Tomcat examples/jsp2/jspx/textRotate.jspx XSS
17086| [34878] Apache Tomcat examples/jsp2/el/implicit-objects.jsp XSS
17087| [34877] Apache Tomcat JK Web Server Connector (mod_jk) Double Encoded Traversal Arbitrary File Access
17088| [34876] Apache HTTP Server ScriptAlias CGI Source Disclosure
17089| [34875] Apache Tomcat appdev/sample/web/hello.jsp Multiple Parameter XSS
17090| [34874] Apache Tomcat AJP Connector mod_jk ajp_process_callback Remote Memory Disclosure
17091| [34873] Apache Stats Variable Extraction _REQUEST Ssuperglobal Array Overwrite
17092| [34872] Apache HTTP Server suexec User/Group Combination Weakness Local Privilege Escalation
17093| [34769] Apache Tomcat w/ Proxy Module Double Encoded Traversal Arbitrary File Access
17094| [34541] mod_perl for Apache HTTP Server RegistryCooker.pm PATH_INFO Crafted URI Remote DoS
17095| [34540] mod_perl for Apache HTTP Server PerlRun.pm PATH_INFO Crafted URI Remote DoS
17096| [34398] Apache Tomcat mod_jk Invalid Chunked Encoded Body Information Disclosure
17097| [34154] Apache Axis Nonexistent Java Web Service Path Disclosure
17098| [33855] Apache Tomcat JK Web Server Connector mod_jk.so Long URI Worker Map Remote Overflow
17099| [33816] Apache HTTP Server on Debian Linux TTY Local Privilege Escalation
17100| [33456] Apache HTTP Server Crafted TCP Connection Range Header DoS
17101| [33346] Avaya Multiple Products Apache Tomcat Port Weakness
17102| [32979] Apache Java Mail Enterprise Server (JAMES) Phoenix/MX4J Interface Arbitrary User Creation
17103| [32978] Apache Java Mail Enterprise Server (JAMES) POP3Server Log File Plaintext Password Disclosure
17104| [32724] Apache mod_python _filter_read Freed Memory Disclosure
17105| [32723] Apache Tomcat semicolon Crafted Filename Request Forced Directory Listing
17106| [32396] Apache Open For Business Project (OFBiz) Ecommerce Component Forum Implementation Message Body XSS
17107| [32395] Apache Open For Business Project (OFBiz) Ecommerce Component Form Field Manipulation Privilege Escalation
17108| [30354] Linux Subversion libapache2-svn Search Path Subversion Local Privilege Escalation
17109| [29603] PHP ini_restore() Apache httpd.conf Options Bypass
17110| [29536] Apache Tcl mod_tcl set_var Function Remote Format String
17111| [28919] Apache Roller Weblogger Blog Comment Multiple Field XSS
17112| [28130] PHP with Apache Mixed Case Method Limit Directive Bypass
17113| [27913] Apache HTTP Server on Windows mod_alias URL Validation Canonicalization CGI Source Disclosure
17114| [27588] Apache HTTP Server mod_rewrite LDAP Protocol URL Handling Overflow
17115| [27487] Apache HTTP Server Crafted Expect Header Cross Domain HTML Injection
17116| [26935] FCKeditor on Apache connector.php Crafted File Extension Arbitrary File Upload
17117| [26572] Apache Java Mail Enterprise Server (JAMES) MAIL Command Overflow DoS
17118| [25909] Drupal on Apache files Directory File Upload Arbitrary Code Execution
17119| [24825] Oracle ModPL/SQL for Apache Unspecified Remote HTTP Issue
17120| [24365] Apache Struts Multiple Function Error Message XSS
17121| [24364] Apache Struts getMultipartRequestHandler() Function Crafted Request DoS
17122| [24363] Apache Struts org.apache.struts.taglib.html.Constants.CANCEL Validation Bypass
17123| [24103] Pubcookie Apache mod_pubcookie Unspecified XSS
17124| [23906] Apache mod_python for Apache HTTP Server FileSession Privileged Local Command Execution
17125| [23905] Apache Log4net LocalSyslogAppender Format String Memory Corruption DoS
17126| [23198] Apache WSS4J Library SOAP Signature Verification Bypass
17127| [23124] Generic Apache Request Library (libapreq) apreq_parse_* Functions Remote DoS
17128| [22652] mod_php for Apache HTTP Server Crafted import_request_variables Function DoS
17129| [22475] PHP w/ Apache PDO::FETCH_CLASS __set() Function DoS
17130| [22473] PHP w/ Apache2 Crafted PDOStatement DoS
17131| [22459] Apache Geronimo Error Page XSS
17132| [22458] Apache Tomcat / Geronimo Sample Script cal2.jsp time Parameter XSS
17133| [22301] auth_ldap for Apache HTTP Server auth_ldap_log_reason() Function Remote Format String
17134| [22261] Apache HTTP Server mod_ssl ssl_hook_Access Error Handling DoS
17135| [22259] mod_auth_pgsql for Apache HTTP Server Log Function Format String
17136| [21736] Apache Java Mail Enterprise Server (JAMES) Spooler retrieve Function DoS
17137| [21705] Apache HTTP Server mod_imap Image Map Referer XSS
17138| [21021] Apache Struts Error Message XSS
17139| [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
17140| [20491] PHP mod_php apache2handler SAPI Crafted .htaccess DoS
17141| [20462] Apache HTTP Server worker.c MPM Memory Exhaustion DoS
17142| [20439] Apache Tomcat Directory Listing Saturation DoS
17143| [20373] Apache Tomcat on HP Secure OS for Linux Unspecified Servlet Access Issue
17144| [20285] Apache HTTP Server Log File Control Character Injection
17145| [20242] Apache HTTP Server mod_usertrack Predictable Session ID Generation
17146| [20209] Brainf*ck Module (mod_bf) for Apache HTTP Server Local Overflow
17147| [20033] Apache Tomcat MS-DOS Device Request Error Message Path Disclosure
17148| [19883] apachetop atop.debug Symlink Arbitrary File Overwrite
17149| [19863] mod_auth_shadow for Apache HTTP Server require group Authentication Bypass
17150| [19855] Apache HTTP Server ErrorDocument Directive .htaccess Bypass
17151| [19821] Apache Tomcat Malformed Post Request Information Disclosure
17152| [19769] Apache HTTP Server Double-reverse DNS Lookup Spoofing
17153| [19188] Apache HTTP Server mod_ssl SSLVerifyClient Per-location Context Restriction Bypass
17154| [19137] Apache HTTP Server on Red Hat Linux Double Slash GET Request Forced Directory Listing
17155| [19136] Apache on Mandrake Linux Arbitrary Directory Forced Listing
17156| [18977] Apache HTTP Server Crafted HTTP Range Header DoS
17157| [18389] Ragnarok Online Control Panel Apache Authentication Bypass
17158| [18286] Apache HTTP Server mod_ssl ssl_callback_SSLVerify_CRL( ) Function Overflow
17159| [18233] Apache HTTP Server htdigest user Variable Overfow
17160| [17738] Apache HTTP Server HTTP Request Smuggling
17161| [16586] Apache HTTP Server Win32 GET Overflow DoS
17162| [15889] Apache HTTP Server mod_cgid Threaded MPM CGI Output Misdirection
17163| [14896] mod_dav for Apache HTTP Server Remote Null Dereference Child Process Termination
17164| [14879] Apache HTTP Server ap_log_rerror Function Error Message Path Disclosure
17165| [14770] Apache Tomcat AJP12 Protocol Malformed Packet Remote DoS
17166| [14597] Apache Tomcat IntegerOverflow.jsp Test JSP Script Path Disclosure
17167| [14596] Apache Tomcat pageSession.jsp Test JSP Script Path Disclosure
17168| [14595] Apache Tomcat pageLanguage.jsp Test JSP Script Path Disclosure
17169| [14594] Apache Tomcat pageIsThreadSafe.jsp Test JSP Script Path Disclosure
17170| [14593] Apache Tomcat pageIsErrorPage.jsp Test JSP Script Path Disclosure
17171| [14592] Apache Tomcat pageInvalid.jsp Test JSP Script Path Disclosure
17172| [14591] Apache Tomcat pageExtends.jsp Test JSP Script Path Disclosure
17173| [14590] Apache Tomcat pageDouble.jsp Test JSP Script Path Disclosure
17174| [14589] Apache Tomcat pageAutoFlush.jsp Test JSP Script Path Disclosure
17175| [14588] Apache Tomcat extends2.jsp Test JSP Script Path Disclosure
17176| [14587] Apache Tomcat extends1.jsp Test JSP Script Path Disclosure
17177| [14586] Apache Tomcat comments.jsp Test JSP Script Path Disclosure
17178| [14585] Apache Tomcat buffer4.jsp Test JSP Script Path Disclosure
17179| [14584] Apache Tomcat buffer3.jsp Test JSP Script Path Disclosure
17180| [14583] Apache Tomcat buffer2.jsp Test JSP Script Path Disclosure
17181| [14582] Apache Tomcat buffer1.jsp Test JSP Script Path Disclosure
17182| [14581] Apache Tomcat pageImport2.jsp Test JSP Script Path Disclosure
17183| [14580] Apache Tomcat pageInfo.jsp Test JSP Script Path Disclosure
17184| [14410] mod_frontpage for Apache HTTP Server fpexec Remote Overflow
17185| [14044] Apache Batik Squiggle Browser with Rhino Scripting Engine Unspecified File System Access
17186| [13737] mod_access_referer for Apache HTTP Server Malformed Referer DoS
17187| [13711] Apache mod_python publisher.py Traversal Arbitrary Object Information Disclosure
17188| [13640] mod_auth_any for Apache HTTP Server on Red Hat Linux Metacharacter Command Execution
17189| [13304] Apache Tomcat realPath.jsp Path Disclosure
17190| [13303] Apache Tomcat source.jsp Arbitrary Directory Listing
17191| [13087] Apache HTTP Server mod_log_forensic check_forensic Symlink Arbitrary File Creation / Overwrite
17192| [12849] mod_auth_radius for Apache HTTP Server radcpy() Function Overflow DoS
17193| [12848] Apache HTTP Server htdigest realm Variable Overflow
17194| [12721] Apache Tomcat examples/jsp2/el/functions.jsp XSS
17195| [12720] mod_dosevasive for Apache HTTP Server Symlink Arbitrary File Create/Overwrite
17196| [12558] Apache HTTP Server IPv6 FTP Proxy Socket Failure DoS
17197| [12557] Apache HTTP Server prefork MPM accept Error DoS
17198| [12233] Apache Tomcat MS-DOS Device Name Request DoS
17199| [12232] Apache Tomcat with JDK Arbitrary Directory/Source Disclosure
17200| [12231] Apache Tomcat web.xml Arbitrary File Access
17201| [12193] Apache HTTP Server on Mac OS X File Handler Bypass
17202| [12192] Apache HTTP Server on Mac OS X Unauthorized .ht and .DS_Store File Access
17203| [12178] Apache Jakarta Lucene results.jsp XSS
17204| [12176] mod_digest_apple for Apache HTTP Server on Mac OS X Authentication Replay
17205| [11391] Apache HTTP Server Header Parsing Space Saturation DoS
17206| [11003] Apache HTTP Server mod_include get_tag() Function Local Overflow
17207| [10976] mod_mylo for Apache HTTP Server mylo_log Logging Function HTTP GET Overflow
17208| [10637] Apache HTTP Server mod_ssl SSLCipherSuite Access Restriction Bypass
17209| [10546] Macromedia JRun4 mod_jrun Apache Module Remote Overflow
17210| [10471] Apache Xerces-C++ XML Parser DoS
17211| [10218] Apache HTTP Server Satisfy Directive Access Control Bypass
17212| [10068] Apache HTTP Server htpasswd Local Overflow
17213| [10049] mod_cplusplus For Apache HTTP Server Unspecified Overflow
17214| [9994] Apache HTTP Server apr-util IPV6 Parsing DoS
17215| [9991] Apache HTTP Server ap_resolve_env Environment Variable Local Overflow
17216| [9948] mod_dav for Apache HTTP Server LOCK Request DoS
17217| [9742] Apache HTTP Server mod_ssl char_buffer_read Function Reverse Proxy DoS
17218| [9718] Apache HTTP Server Win32 Single Dot Append Arbitrary File Access
17219| [9717] Apache HTTP Server mod_cookies Cookie Overflow
17220| [9716] Apache::Gallery Gallery.pm Inline::C Predictable Filename Code Execution
17221| [9715] Apache HTTP Server rotatelogs Control Characters Over Pipe DoS
17222| [9714] Apache Authentication Module Threaded MPM DoS
17223| [9713] Apache HTTP Server on OS2 filestat.c Device Name Request DoS
17224| [9712] Apache HTTP Server Multiple Linefeed Request Memory Consumption DoS
17225| [9711] Apache HTTP Server Access Log Terminal Escape Sequence Injection
17226| [9710] Apache HTTP Server on Windows Illegal Character Default Script Mapping Bypass
17227| [9709] Apache HTTP Server on Windows MS-DOS Device Name HTTP Post Code Execution
17228| [9708] Apache HTTP Server on Windows MS-DOS Device Name DoS
17229| [9707] Apache HTTP Server Duplicate MIME Header Saturation DoS
17230| [9706] Apache Web Server Multiple MIME Header Saturation Remote DoS
17231| [9705] Apache Tomcat Invoker/Default Servlet Source Disclosure
17232| [9702] Apache HTTP Server CGI/WebDAV HTTP POST Request Source Disclosure
17233| [9701] Apache HTTP Server for Windows Multiple Slash Forced Directory Listing
17234| [9700] Apache HTTP Server mod_autoindex Multiple Slash Request Forced Directory Listing
17235| [9699] Apache HTTP Server mod_dir Multiple Slash Request Forced Directory Listing
17236| [9698] Apache HTTP Server mod_negotiation Multiple Slash Request Forced Directory Listing
17237| [9697] Apache HTTP Server htdigest Local Symlink Arbitrary File Overwrite
17238| [9696] Apache HTTP Server htpasswd Local Symlink Arbitrary File Overwrite
17239| [9695] Apache Tomcat SnoopServlet Servlet Information Disclosure
17240| [9694] PHP3 on Apache HTTP Server Encoded Traversal Arbitrary File Access
17241| [9693] mod_auth_pgsql_sys for Apache HTTP Server User Name SQL Injection
17242| [9692] Apache HTTP Server mod_vhost_alias Mass Virtual Hosting Arbitrary File Access
17243| [9691] Apache HTTP Server mod_rewrite Mass Virtual Hosting Arbitrary File Access
17244| [9690] Apache HTTP Server mod_vhost_alias CGI Program Source Disclosure
17245| [9689] Trustix httpsd for Apache-SSL Permission Weakness Privilege Escalation
17246| [9688] Apache HTTP Server mod_proxy Malformed FTP Command DoS
17247| [9687] Apache::AuthenSmb smbval SMB Authentication Library Multiple Overflows
17248| [9686] Apache::AuthenSmb smbvalid SMB Authentication Library Multiple Overflows
17249| [9523] Apache HTTP Server mod_ssl Aborted Connection DoS
17250| [9459] Oracle PL/SQL (mod_plsql) Apache Module Help Page Request Remote Overflow
17251| [9208] Apache Tomcat .jsp Encoded Newline XSS
17252| [9204] Apache Tomcat ROOT Application XSS
17253| [9203] Apache Tomcat examples Application XSS
17254| [9068] Apache HTTP Server mod_userdir User Account Information Disclosure
17255| [8773] Apache Tomcat Catalina org.apache.catalina.servlets.DefaultServlet Source Code Disclosure
17256| [8772] Apache Tomcat Catalina org.apache.catalina.connector.http DoS
17257| [7943] Apache HTTP Server mod_ssl sslkeys File Disclosure
17258| [7942] Apache HTTP Server mod_ssl Default Pass Phrase
17259| [7941] Apache HTTP Server mod_ssl Encrypted Private Key File Descriptor Leak
17260| [7935] Apache HTTP Server mod_ssl ssl_gcache Race Conditions
17261| [7934] Apache HTTP Server mod_ssl SSLSessionCache File Content Disclosure
17262| [7933] Apache HTTP Server mod_ssl SSLMutex File Content Disclosure
17263| [7932] Apache HTTP Server mod_ssl mkcert.sh File Creation Permission Weakness
17264| [7931] Apache HTTP Server mod_ssl X.509 Client Certificate Authentication Bypass
17265| [7930] Apache HTTP Server mod_ssl ssl_expr_eval_func_file() Overflow
17266| [7929] Apache HTTP Server mod_ssl ssl_engine_log.c mod_proxy Hook Function Remote Format String
17267| [7611] Apache HTTP Server mod_alias Local Overflow
17268| [7394] Apache Tomcat mod_jk Invalid Transfer-Encoding Chunked Field DoS
17269| [7203] Apache Tomcat source.jsp Traversal Arbitrary File Access
17270| [7039] Apache HTTP Server on Mac OS X HFS+ File System Access Bypass
17271| [6882] Apache mod_python Malformed Query String Variant DoS
17272| [6839] Apache HTTP Server mod_proxy Content-Length Overflow
17273| [6630] Apache Tomcat Java Server Pages (JSP) Engine WPrinterJob() DoS
17274| [6472] Apache HTTP Server mod_ssl ssl_util_uuencode_binary Remote Overflow
17275| [5821] Apache HTTP Server Multiple / GET Remote Overflow DoS
17276| [5580] Apache Tomcat Servlet Malformed URL JSP Source Disclosure
17277| [5552] Apache HTTP Server split-logfile Arbitrary .log File Overwrite
17278| [5526] Apache Tomcat Long .JSP URI Path Disclosure
17279| [5278] Apache Tomcat web.xml Restriction Bypass
17280| [5051] Apache Tomcat Null Character DoS
17281| [4973] Apache Tomcat servlet Mapping XSS
17282| [4650] mod_gzip for Apache HTTP Server Debug Mode Printf Stack Overflow
17283| [4649] mod_gzip for Apache HTTP Server Debug Mode Format String Overflow
17284| [4648] mod_gzip for Apache HTTP Server Debug Mode Race Condition
17285| [4568] mod_survey For Apache ENV Tags SQL Injection
17286| [4553] Apache HTTP Server ApacheBench Overflow DoS
17287| [4552] Apache HTTP Server Shared Memory Scoreboard DoS
17288| [4446] Apache HTTP Server mod_disk_cache Stores Credentials
17289| [4383] Apache HTTP Server Socket Race Condition DoS
17290| [4382] Apache HTTP Server Log Entry Terminal Escape Sequence Injection
17291| [4340] Apache Portable Runtime (APR) apr_psprintf DoS
17292| [4232] Apache Cocoon DatabaseAuthenticatorAction SQL Injection
17293| [4231] Apache Cocoon Error Page Server Path Disclosure
17294| [4182] Apache HTTP Server mod_ssl Plain HTTP Request DoS
17295| [4181] Apache HTTP Server mod_access IP Address Netmask Rule Bypass
17296| [4075] Apache HTTP Sever on Windows .var File Request Path Disclosure
17297| [4037] Apache HTTP Server on Cygwin Encoded GET Request Arbitrary File Access
17298| [3877] Apache-SSL SSLVerifyClient SSLFakeBasicAuth Client Certificate Forgery
17299| [3819] Apache HTTP Server mod_digest Cross Realm Credential Replay
17300| [3322] mod_php for Apache HTTP Server Process Hijack
17301| [3215] mod_php for Apache HTTP Server File Descriptor Leakage
17302| [2885] Apache mod_python Malformed Query String DoS
17303| [2749] Apache Cocoon view-source Sample File Traversal Arbitrary File Access
17304| [2733] Apache HTTP Server mod_rewrite Local Overflow
17305| [2672] Apache HTTP Server mod_ssl SSLCipherSuite Ciphersuite Downgrade Weakness
17306| [2613] Apache HTTP Server mod_cgi stderr Output Handling Local DoS
17307| [2149] Apache::Gallery Privilege Escalation
17308| [2107] Apache HTTP Server mod_ssl Host: Header XSS
17309| [1926] Apache HTTP Server mod_rewrite Crafted URI Rule Bypass
17310| [1833] Apache HTTP Server Multiple Slash GET Request DoS
17311| [1577] Apache HTTP Server mod_rewrite RewriteRule Expansion Arbitrary File Access
17312| [872] Apache Tomcat Multiple Default Accounts
17313| [862] Apache HTTP Server SSI Error Page XSS
17314| [859] Apache HTTP Server Win32 Crafted Traversal Arbitrary File Access
17315| [849] Apache Tomcat TroubleShooter Servlet Information Disclosure
17316| [845] Apache Tomcat MSDOS Device XSS
17317| [844] Apache Tomcat Java Servlet Error Page XSS
17318| [842] Apache HTTP Server mod_ssl ssl_compat_directive Function Overflow
17319| [838] Apache HTTP Server Chunked Encoding Remote Overflow
17320| [827] PHP4 for Apache on Windows php.exe Malformed Request Path Disclosure
17321| [775] Apache mod_python Module Importing Privilege Function Execution
17322| [769] Apache HTTP Server Win32 DOS Batch File Arbitrary Command Execution
17323| [756] Apache HTTP Server mod_ssl i2d_SSL_SESSION Function SSL Client Certificate Overflow
17324| [701] Apache HTTP Server Win32 ScriptAlias php.exe Arbitrary File Access
17325| [674] Apache Tomcat Nonexistent File Error Message Path Disclosure
17326| [637] Apache HTTP Server UserDir Directive Username Enumeration
17327| [623] mod_auth_pgsql for Apache HTTP Server User Name SQL Injection
17328| [582] Apache HTTP Server Multiviews Feature Arbitrary Directory Listing
17329| [562] Apache HTTP Server mod_info /server-info Information Disclosure
17330| [561] Apache Web Servers mod_status /server-status Information Disclosure
17331| [417] Apache HTTP Server on SuSE Linux /doc/packages Remote Information Disclosure
17332| [410] mod_perl for Apache HTTP Server /perl/ Directory Listing
17333| [404] Apache HTTP Server on SuSE Linux WebDAV PROPFIND Arbitrary Directory Listing
17334| [402] Apache HTTP Server on SuSE Linux cgi-bin-sdb Request Script Source Disclosure
17335| [379] Apache ASP module Apache::ASP source.asp Example File Arbitrary File Creation
17336| [377] Apache Tomcat Snoop Servlet Remote Information Disclosure
17337| [376] Apache Tomcat contextAdmin Arbitrary File Access
17338| [342] Apache HTTP Server for Windows Multiple Forward Slash Directory Listing
17339| [222] Apache HTTP Server test-cgi Arbitrary File Access
17340| [143] Apache HTTP Server printenv.pl Multiple Method CGI XSS
17341| [48] Apache HTTP Server on Debian /usr/doc Directory Information Disclosure
17342|_
17343443/tcp open ssl/http Apache httpd
17344|_http-server-header: Apache
17345| vulscan: VulDB - https://vuldb.com:
17346| [141649] Apache OFBiz up to 16.11.05 Form Widget Freemarker Markup Code Execution
17347| [141648] Apache OFBiz up to 16.11.05 Application Stored cross site scripting
17348| [140386] Apache Commons Beanutils 1.9.2 BeanIntrospector unknown vulnerability
17349| [139708] Apache Ranger up to 1.2.0 Policy Import cross site scripting
17350| [139540] cPanel up to 60.0.24 Apache HTTP Server Key information disclosure
17351| [139386] Apache Tike up to 1.21 RecursiveParserWrapper Stack-based memory corruption
17352| [139385] Apache Tika 1.19/1.20/1.21 SAXParsers Hang denial of service
17353| [139384] Apache Tika up to 1.21 RecursiveParserWrapper ZIP File denial of service
17354| [139261] Apache Solr 8.2.0 DataImportHandler Parameter unknown vulnerability
17355| [139259] cPanel up to 68.0.26 WHM Apache Includes Editor information disclosure
17356| [139256] cPanel up to 68.0.26 WHM Apache Configuration Include Editor cross site scripting
17357| [139239] cPanel up to 70.0.22 Apache HTTP Server Log information disclosure
17358| [139141] Apache ActiveMQ Client up to 5.15.4 ActiveMQConnection.java ActiveMQConnection denial of service
17359| [139130] cPanel up to 73.x Apache HTTP Server Injection privilege escalation
17360| [138914] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 VM sql injection
17361| [138913] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Block Argument privilege escalation
17362| [138912] Venustech Apache VCL 2.1/2.2/2.3/2.4/2.5 Cookie sql injection
17363| [138816] Apache Storm up to 1.2.2 Logviewer Daemon Log information disclosure
17364| [138815] Apache Storm up to 1.2.2 UI Daemon Deserialization privilege escalation
17365| [138164] Oracle 2.7.0.1 Apache Log4j unknown vulnerability
17366| [138155] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Tomcat unknown vulnerability
17367| [138151] Oracle Transportation Management 6.3.7 Apache Tomcat unknown vulnerability
17368| [138149] Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Commons FileUpload unknown vulnerability
17369| [138131] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Tomcat unknown vulnerability
17370| [138129] Oracle Retail Xstore Point of Service 7.0/7.1 Apache HTTP Server denial of service
17371| [138123] Oracle Retail Order Management System 5.0 Apache Struts 1 unknown vulnerability
17372| [138122] Oracle Retail Order Broker 5.2/15.0 Apache Tomcat unknown vulnerability
17373| [138121] Oracle Retail Order Broker 5.2/15.0 Apache CXF unknown vulnerability
17374| [138112] Oracle Retail Integration Bus 15.0/16.0 Apache Commons FileUpload unknown vulnerability
17375| [138111] Oracle MICROS Retail XBRi Loss Prevention 10.8.0/10.8.1/10.8.2/10.8.3 Apache Commons FileUpload unknown vulnerability
17376| [138103] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56/8.57 Apache WSS4J information disclosure
17377| [138053] Oracle JD Edwards EnterpriseOne Tools 9.2 Apache Log4j unknown vulnerability
17378| [138036] Oracle Insurance Rules Palette 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
17379| [138035] Oracle Insurance Policy Administration J2EE 10.0/10.1/10.2/11.0 Apache Commons FileUpload unknown vulnerability
17380| [138034] Oracle Insurance Calculation Engine 9.7/10.0/10.1/10.2 Apache Commons FileUpload unknown vulnerability
17381| [138028] Oracle Identity Manager 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
17382| [138020] Oracle BI Publisher 11.1.1.9.0 Apache Tomcat unknown vulnerability
17383| [138019] Oracle BI Publisher (formerly XML Publisher) 11.1.1.9.0 Apache Tomcat unknown vulnerability
17384| [138017] Oracle Outside In Technology 8.5.4 Apache Commons FileUpload unknown vulnerability
17385| [138013] Oracle Outside In Technology 8.5.4 Apache Tomcat unknown vulnerability
17386| [138012] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
17387| [138009] Oracle Outside In Technology 8.5.4 Apache HTTP Server unknown vulnerability
17388| [138008] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Struts 1 denial of service
17389| [138007] Oracle WebCenter Sites 12.2.1.3.0 Apache Tomcat denial of service
17390| [138006] Oracle Enterprise Repository 12.1.3.0.0 Apache CXF denial of service
17391| [138000] Oracle WebCenter Sites 12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
17392| [137999] Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0 Apache Commons FileUpload unknown vulnerability
17393| [137995] Oracle Hospitality Simphony 18.2.1 Apache WSS4J information disclosure
17394| [137987] Oracle FLEXCUBE Universal Banking up to 12.0.3/12.4.0/14.2.0 Apache Log4j unknown vulnerability
17395| [137981] Oracle Insurance IFRS 17 Analyzer 8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
17396| [137980] Oracle Insurance Data Foundation 8.0.4/8.0.5/8.0.6/8.0.7 Apache Commons FileUpload unknown vulnerability
17397| [137979] Oracle 8.0.8 Apache Commons FileUpload unknown vulnerability
17398| [137973] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Batik unknown vulnerability
17399| [137970] Oracle Financial Services Profitability Management 8.0.4/8.0.5/8.0.6/8.0.7 Apache ActiveMQ unknown vulnerability
17400| [137967] Oracle up to 8.0.7 Apache httpd unknown vulnerability
17401| [137966] Oracle 8.0.7/8.0.8 Apache Groovy unknown vulnerability
17402| [137965] Oracle Financial Services Liquidity Risk Management 8.0.1/8.0.2/8.0.4/8.0.5/8.0.6 Apache Commons FileUpload unknown vulnerability
17403| [137964] Oracle 8.0.4/8.0.5/8.0.6/8.0.7 Apache Log4j unknown vulnerability
17404| [137933] Oracle Banking Platform up to 2.7.1 Apache Tika unknown vulnerability
17405| [137926] Oracle Enterprise Manager for Fusion Middleware 13.2/13.3 Apache Commons FileUpload information disclosure
17406| [137924] Oracle Enterprise Manager Base Platform 12.1.0.5.0/13.2.0.0.0/13.3.0.0.0 Apache Commons FileUpload unknown vulnerability
17407| [137914] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
17408| [137913] Oracle E-Business Suite up to 12.2.8 Apache ActiveMQ unknown vulnerability
17409| [137911] Oracle E-Business Suite up to 12.2.8 Apache HTTP Server unknown vulnerability
17410| [137910] Oracle E-Business Suite up to 12.2.8 Apache CXF information disclosure
17411| [137909] Oracle E-Business Suite up to 12.2.8 Apache Commons FileUpload unknown vulnerability
17412| [137905] Oracle Primavera Gateway 15.2/16.2/17.12/18.8 Apache Tika denial of service
17413| [137901] Oracle Primavera Unifier up to 18.8 Apache HTTP Server unknown vulnerability
17414| [137895] Oracle Instant Messaging Server 10.0.1.2.0 Apache Tika information disclosure
17415| [137894] Oracle EAGLE (Software) 46.5/46.6/46.7 Apache Tomcat information disclosure
17416| [137892] Oracle Online Mediation Controller 6.1 Apache Batik denial of service
17417| [137891] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Tomcat unknown vulnerability
17418| [137885] Oracle Diameter Signaling Router (DSR) 8.0/8.1/8.2 Apache cxf unknown vulnerability
17419| [137882] Oracle Unified 8.0.0.2.0 Apache Commons FileUpload unknown vulnerability
17420| [137881] Oracle Online Mediation Controller 6.1 Apache Commons FileUpload unknown vulnerability
17421| [137880] Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Log4j unknown vulnerability
17422| [137879] Oracle Convergence 3.0.2 Apache Commons FileUpload unknown vulnerability
17423| [137876] Oracle Application Session Controller 3.7.1/3.8.0 Apache Commons FileUpload unknown vulnerability
17424| [137829] Apache Roller 5.2.3 Math Comment Authenticator Reflected cross site scripting
17425| [137736] Apache Kafka 0.11.0.0/2.1.0 ACL Validation Request privilege escalation
17426| [136858] MakerBot Replicator 5G Printer Apache HTTP Server information disclosure
17427| [136849] Analogic Poste.io 2.1.6 on Apache RoundCube logs/ information disclosure
17428| [136822] Apache Tomcat up to 8.5.40/9.0.19 Incomplete Fix CVE-2019-0199 Resource Exhaustion denial of service
17429| [136808] Apache Geode up to 1.8.0 Secure Mode privilege escalation
17430| [136646] Apache Allura up to 1.10.x Dropdown Selector Stored cross site scripting
17431| [136374] Apache HTTP Server up to 2.4.38 Slash Regular Expression unknown vulnerability
17432| [136373] Apache HTTP Server 2.4.34/2.4.35/2.4.36/2.4.37/2.4.38 HTTP2 Request Crash denial of service
17433| [136372] Apache HTTP Server up to 2.4.38 HTTP2 Request unknown vulnerability
17434| [136370] Apache Fineract up to 1.2.x sql injection
17435| [136369] Apache Fineract up to 1.2.x sql injection
17436| [135731] Apache Hadoop up to 2.8.4/2.9.1/3.1.0 yarn privilege escalation
17437| [135664] Apache Tomcat up to 7.0.93/8.5.39/9.0.0.17 SSI printenv Command cross site scripting
17438| [135663] Apache Camel up to 2.23.x JSON-lib Library XML Data XML External Entity
17439| [135661] Apache Roller up to 5.2.1/5.2.0 XML-RPC Interface XML File Server-Side Request Forgery
17440| [135402] Apache Zookeeper up to 3.4.13/3.5.0-alpha to 3.5.4-beta getACL() information disclosure
17441| [135270] Apache JSPWiki up to 2.11.0.M3 Plugin Link cross site scripting
17442| [135269] Apache JSPWiki up to 2.11.0.M3 InterWiki Link cross site scripting
17443| [135268] Apache JSPWiki up to 2.11.0.M3 Attachment cross site scripting
17444| [134527] Apache Karaf up to 4.2.4 Config Service directory traversal
17445| [134416] Apache Sanselan 0.97-incubator Loop denial of service
17446| [134415] Apache Sanselan 0.97-incubator Hang denial of service
17447| [134291] Apache Axis up to 1.7.8 Server-Side Request Forgery
17448| [134290] Apache UIMA DUCC up to 2.2.2 cross site scripting
17449| [134248] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
17450| [134247] Apache Archiva up to 2.2.3 Artifact Upload directory traversal
17451| [134246] Apache Camel up to 2.19/2.21.3/2.22.2/2.23.0 directory traversal
17452| [134138] Apache Pluto 3.0.0/3.0.1 Chat Room Demo Portlet cross site scripting
17453| [133992] Apache Qpid Proton up to 0.27.0 Certificate Validation Man-in-the-Middle weak authentication
17454| [133977] Apache Zeppelin up to 0.7.x Stored cross site scripting
17455| [133976] Apache Zeppelin up to 0.7.x Cron Scheduler privilege escalation
17456| [133975] Apache Zeppelin up to 0.7.2 Session Fixation weak authentication
17457| [133444] Apache PDFbox 2.0.14 XML Parser XML External Entity
17458| [133573] Oracle FLEXCUBE Private Banking 2.0.0.0/2.2.0.1/12.0.1.0/12.0.3.0/12.1.0.0 Apache ActiveMQ unknown vulnerability
17459| [133407] Apache Tomcat up to 7.0.93/8.5.39/9.0.17 on Windows JRE Command Line Argument Code Execution
17460| [133315] Apache Airflow up to 1.10.2 HTTP Endpoint cross site request forgery
17461| [133314] Apache Airflow up to 1.10.2 Metadata Database cross site scripting
17462| [133290] Apache Tomcat up to 8.5.37/9.0.14 HTTP2 Stream Execution denial of service
17463| [133112] Apache HTTP Server up to 2.4.38 mod_auth_digest race condition privilege escalation
17464| [133111] Apache HTTP Server 2.4.37/2.4.38 mod_ssl Bypass privilege escalation
17465| [133092] Airsonic 10.2.1 org.apache.commons.lang.RandomStringUtils RecoverController.java java.util.Random weak authentication
17466| [132568] Apache JSPWiki up to 2.11.0.M2 URL User information disclosure
17467| [132567] Apache JSPWiki up to 2.11.0.M2 URL cross site scripting
17468| [132566] Apache ActiveMQ up to 5.15.8 MQTT Frame Memory denial of service
17469| [132565] Apache HBase up to 2.1.3 REST Server Request privilege escalation
17470| [132183] Apache Mesos up to pre-1.4.x Docker Image Code Execution
17471| [131988] Apache Karaf up to 4.2.2 kar Deployer directory traversal
17472| [131859] Apache Hadoop up to 2.9.1 privilege escalation
17473| [131479] Apache Solr up to 7.6 HTTP GET Request Server-Side Request Forgery
17474| [131446] Apache Solr up to 5.0.5/6.6.5 Config API HTTP POST Request Code Execution
17475| [131385] Apache Qpid Broker-J up to 6.x/7.0.6/7.1.0 AMQP Command Crash denial of service
17476| [131315] Apache Mesos up to pre-1.4.x Mesos Masters Rendering JSON Payload Recursion denial of service
17477| [131236] Apache Airflow up to 1.10.1 Metadata Database cross site scripting
17478| [130755] Apache JSPWiki up to 2.10.5 URL cross site scripting
17479| [130629] Apache Guacamole Cookie Flag weak encryption
17480| [130628] Apache Hadoop up to 3.0.0 HDFS information disclosure
17481| [130529] Apache Subversion 1.10.0/1.10.1/1.10.2/1.10.3/1.11.0 mod_dav_svn Directory Crash denial of service
17482| [130353] Apache Open Office up to 4.1.5 Document Loader String memory corruption
17483| [130341] Apache HTTP Server 2.4.37 mod_ssl Loop denial of service
17484| [130330] Apache HTTP Server up to 2.4.37 mod_session Expired privilege escalation
17485| [130329] Apache HTTP Server 2.4.37 mod_http2 Slowloris denial of service
17486| [130212] Apache Airflow up to 1.10.0 LDAP Auth Backend Certificate weak authentication
17487| [130123] Apache Airflow up to 1.8.2 information disclosure
17488| [130122] Apache Airflow up to 1.8.2 command injection cross site request forgery
17489| [130121] Apache Airflow up to 1.8.2 Webserver Object Code Execution
17490| [129717] Oracle Secure Global Desktop 5.4 Apache HTTP Server denial of service
17491| [129688] Oracle Tape Library ACSLS 8.4 Apache Log4j unknown vulnerability
17492| [129673] Oracle Retail Returns Management 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
17493| [129672] Oracle Retail Central Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
17494| [129671] Oracle Retail Back Office 13.3/13.4/14.0/14.1 Apache Commons Fileupload unknown vulnerability
17495| [129574] Oracle Outside In Technology 8.5.3/8.5.4 Apache Tomcat denial of service
17496| [129573] Oracle WebLogic Server 10.3.6.0 Apache HTTP Server denial of service
17497| [129563] Oracle Enterprise Repository 12.1.3.0.0 Apache Log4j unknown vulnerability
17498| [129555] Oracle Outside In Technology 8.5.3 Apache Batik denial of service
17499| [129551] Oracle Outside In Technology 8.5.3/8.5.4 Apache Commons FileUpload denial of service
17500| [129542] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
17501| [129538] Oracle SOA Suite 12.1.3.0.0/12.2.1.3.0 Apache Batik unknown vulnerability
17502| [129519] Oracle Enterprise Manager Ops Center 12.2.2/12.3.3 Apache ActiveMQ unknown vulnerability
17503| [129508] Oracle Applications Manager up to 12.2.8 Apache Derby unknown vulnerability
17504| [129507] Oracle Mobile Field Service up to 12.2.8 Apache Log4j unknown vulnerability
17505| [129505] Oracle Email Center up to 12.2.8 Apache Log4j unknown vulnerability
17506| [129504] Oracle CRM Technical Foundation up to 12.2.8 Apache Commons FileUpload unknown vulnerability
17507| [129499] Oracle Partner Management up to 12.2.8 Apache Log4j unknown vulnerability
17508| [129498] Oracle Marketing up to 12.2.8 Apache Commons FileUpload unknown vulnerability
17509| [129480] Oracle Communications WebRTC Session Controller up to 7.1 Apache Batik unknown vulnerability
17510| [129479] Oracle Communications Diameter Signaling Router up to 8.2 Apache Batik unknown vulnerability
17511| [129474] Oracle Communications Diameter Signaling Router up to 8.2 Apache HTTP Server information disclosure
17512| [129472] Oracle Communications WebRTC Session Controller up to 7.1 Apache Struts 1 unknown vulnerability
17513| [129470] Oracle Communications Converged Application Server up to 7.0.0.0 Apache Struts 1 unknown vulnerability
17514| [129463] Oracle Communications WebRTC Session Controller up to 7.1 Apache Log4j unknown vulnerability
17515| [129461] Oracle Communications Services Gatekeeper up to 6.1.0.3.x Apache Commons Collections Fileupload unknown vulnerability
17516| [129460] Oracle Communications Service Broker 6.0 Apache Log4j unknown vulnerability
17517| [129459] Oracle Communications Policy Management up to 12.4 Apache Struts 2 unknown vulnerability
17518| [129458] Oracle Communications Online Mediation Controller 6.1 Apache Log4j unknown vulnerability
17519| [129457] Oracle Communications Diameter Signaling Router up to 8.2 Apache Commons Fileupload unknown vulnerability
17520| [129456] Oracle Communications Converged Application Server 6.1 Apache Log4j unknown vulnerability
17521| [128714] Apache Thrift Java Client Library up to 0.11.0 SASL Negotiation org.apache.thrift.transport.TSaslTransport unknown vulnerability
17522| [128713] Apache Thrift Node.js Static Web Server up to 0.11.0 directory traversal
17523| [128709] Apache Karaf up to 4.1.6/4.2.1 Features Deployer XMLInputFactory XML External Entity
17524| [128575] Apache NetBeans 9.0 Proxy Auto-Config Code Execution
17525| [128369] Apache Tika 1.8-1.19.1 SQLite3Parser Loop sql injection
17526| [128111] Apache NiFi 1.8.0 Template Upload Man-in-the-Middle cross site request forgery
17527| [128110] Apache NiFi 1.8.0 Cluster Request privilege escalation
17528| [128109] Apache NiFi 1.8.0 Error Page message-page.jsp Request Header cross site scripting
17529| [128108] Apache NiFi up to 1.7.x X-Frame-Options Header privilege escalation
17530| [128102] Apache Oozie up to 5.0.0 Workflow XML Impersonation spoofing
17531| [127994] WordPress up to 5.0.0 on Apache httpd MIME Restriction cross site scripting
17532| [127981] Apache OFBiz 16.11.01/16.11.02/16.11.03/16.11.04 HTTP Engine httpService GET Request privilege escalation
17533| [127161] Apache Hadoop 2.7.4/2.7.5/2.7.6 Incomplete Fix CVE-2016-6811 privilege escalation
17534| [127040] Loadbalancer.org Enterprise VA MAX up to 8.3.2 Apache HTTP Server Log cross site scripting
17535| [127007] Apache Spark Request Code Execution
17536| [126791] Apache Hadoop up to 0.23.11/2.7.6/2.8.4/2.9.1/3.0.2 ZIP File unknown vulnerability
17537| [126767] Apache Qpid Proton-J Transport 0.3 Certificate Verification Man-in-the-Middle weak authentication
17538| [126896] Apache Commons FileUpload 1.3.3 on LDAP Manager DiskFileItem File privilege escalation
17539| [126574] Apache Hive up to 2.3.3/3.1.0 Query privilege escalation
17540| [126573] Apache Hive up to 2.3.3/3.1.0 HiveServer2 privilege escalation
17541| [126564] Apache Superset up to 0.22 Pickle Library load Code Execution
17542| [126488] Apache Syncope up to 2.0.10/2.1.1 BPMN Definition xxe privilege escalation
17543| [126487] Apache Syncope up to 2.0.10/2.1.1 cross site scripting
17544| [126346] Apache Tomcat Path privilege escalation
17545| [125922] Apache Impala up to 3.0.0 ALTER privilege escalation
17546| [125921] Apache Impala up to 3.0.0 Queue Injection privilege escalation
17547| [125647] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Install (Apache Tomcat) information disclosure
17548| [125617] Oracle Retail Returns Management 14.1 Apache Batik unknown vulnerability
17549| [125616] Oracle Retail Point-of-Service 13.4/14.0/14.1 Apache Batik unknown vulnerability
17550| [125614] Oracle Retail Central Office 14.1 Apache Batik unknown vulnerability
17551| [125613] Oracle Retail Back Office 13.3/13.4/14/14.1 Apache Batik unknown vulnerability
17552| [125599] Oracle Retail Open Commerce Platform 5.3.0/6.0.0/6.0.1 Apache Log4j unknown vulnerability
17553| [125569] Oracle PeopleSoft Enterprise PeopleTools 8.55/8.56 Apache HTTP Server information disclosure
17554| [125494] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat information disclosure
17555| [125447] Oracle Business Intelligence Enterprise Edition 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Batik unknown vulnerability
17556| [125428] Oracle Identity Management Suite 11.1.2.3.0/12.2.1.3.0 Apache Log4j unknown vulnerability
17557| [125427] Oracle Identity Analytics 11.1.1.5.8 Apache Log4j unknown vulnerability
17558| [125424] Oracle API Gateway 11.1.2.4.0 Apache Log4j unknown vulnerability
17559| [125423] Oracle BI Publisher 11.1.1.7.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Apache Log4j unknown vulnerability
17560| [125383] Oracle up to 10.2.0 Apache Trinidad unknown vulnerability
17561| [125379] Oracle up to 10.1.x Apache Struts 1 cross site scripting
17562| [125377] Oracle up to 10.2.0 Apache Commons Collections unknown vulnerability
17563| [125376] Oracle Communications Application Session Controller up to 3.7.0 Apache Commons Collections unknown vulnerability
17564| [125375] Oracle Communications User Data Repository up to 12.1.x Apache Xerces memory corruption
17565| [125248] Apache ActiveMQ up to 5.15.5 Web-based Administration Console queue.jsp Parameter cross site scripting
17566| [125133] Apache Tika up to 1.19 XML Parser reset() denial of service
17567| [124877] Apache PDFbox up to 2.0.11 PDF File denial of service
17568| [124876] Apache Ranger up to 1.1.x UnixAuthenticationService Stack-based memory corruption
17569| [124791] Apache Tomcat up to 7.0.90/8.5.33/9.0.11 URL Open Redirect
17570| [124787] Apache Pony Mail 0.7/0.8/0.9 Statistics Generator Timestamp Data information disclosure
17571| [124447] Apache HTTP Server up to 2.4.34 SETTINGS Frame denial of service
17572| [124346] Apache Mesos pre-1.4.2/1.5.0/1.5.1/1.6.0 on Executor HTTP API String Comparison validation JSON Web Token information disclosure
17573| [124286] Apache Tika up to 1.18 IptcAnpaParser Loop denial of service
17574| [124242] Apache Tika up to 0.18 C:/evil.bat" Directory unknown vulnerability
17575| [124241] Apache Tika up to 0.18 XML Parser Entity Expansion denial of service
17576| [124191] Apache Karaf up to 3.0.8/4.0.8/4.1.0 WebConsole .../gogo/ weak authentication
17577| [124190] Apache Karaf up to 4.1.x sshd privilege escalation
17578| [124152] Apache Camel Mail up to 2.22.0 Path directory traversal
17579| [124143] Apache SpamAssassin up to 3.4.1 PDFInfo Plugin Code Execution
17580| [124134] Apache SpamAssassin up to 3.4.1 Scan Engine HTML::Parser Email denial of service
17581| [124095] PHP up to 5.6.37/7.0.31/7.1.21/7.2.9 Apache2 sapi_apache2.c php_handler cross site scripting
17582| [124024] Apache Mesos 1.4.x/1.5.0 libprocess JSON Payload denial of service
17583| [123814] Apache ActiveMQ Client up to 5.15.5 TLS Hostname Verification Man-in-the-Middle weak authentication
17584| [123393] Apache Traffic Server up to 6.2.2/7.1.3 ESI Plugin Config privilege escalation
17585| [123392] Apache Traffic Server 6.2.2 TLS Handshake Segmentation Fault denial of service
17586| [123391] Apache Traffic Server up to 6.2.2/7.1.3 Range Request Performance denial of service
17587| [123390] Apache Traffic Server up to 6.2.2/7.1.3 Request HTTP Smuggling privilege escalation
17588| [123369] Apache Traffic Server up to 6.2.2/7.1.3 ACL remap.config Request denial of service
17589| [123197] Apache Sentry up to 2.0.0 privilege escalation
17590| [123145] Apache Struts up to 2.3.34/2.5.16 Namespace Code Execution
17591| [123144] Apache Cayenne up to 4.1.M1 CayenneModeler XML File File Transfer privilege escalation
17592| [122981] Apache Commons Compress 1.7 ZipArchiveInputStream ZIP Archive denial of service
17593| [122889] Apache HTTP Server up to 2.2.31/2.4.23 mod_userdir HTTP Response Splitting privilege escalation
17594| [122800] Apache Spark 1.3.0 REST API weak authentication
17595| [122642] Apache Airflow up to 1.8.x 404 Page Reflected cross site scripting
17596| [122568] Apache Tomcat up to 8.5.31/9.0.9 Connection Reuse weak authentication
17597| [122567] Apache Axis 1.0./1.1/1.2/1.3/1.4 cross site scripting
17598| [122556] Apache Tomcat up to 7.0.86/8.0.51/8.5.30/9.0.7 UTF-8 Decoder Loop denial of service
17599| [122531] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.9 WebSocket Client unknown vulnerability
17600| [122456] Apache Camel up to 2.20.3/2.21.0 XSD Validator XML External Entity
17601| [122455] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Revoked Certificate weak authentication
17602| [122454] Apache Tomcat Native up to 1.1.34/1.2.16 OSCP Responder Revoked Certificate weak authentication
17603| [122214] Apache Kafka up to 0.9.0.1/0.10.2.1/0.11.0.2/1.0.0 Broker Request Data Loss denial of service
17604| [122202] Apache Kafka up to 0.10.2.1/0.11.0.1 SASL Impersonation spoofing
17605| [122101] Docker Skeleton Runtime for Apache OpenWhisk Docker Action dockerskeleton:1.3.0 privilege escalation
17606| [122100] PHP Runtime for Apache OpenWhisk Docker Action action-php-v7.2:1.0.0 privilege escalation
17607| [122012] Apache Ignite up to 2.5 Serialization privilege escalation
17608| [121911] Apache Ambari up to 2.5.x/2.6.2 Log Message Credentials information disclosure
17609| [121910] Apache HTTP Server 2.4.33 mod_md HTTP Requests denial of service
17610| [121854] Oracle Tape Library ACSLS up to ACSLS 8.4.0-2 Apache Commons Collections unknown vulnerability
17611| [121752] Oracle Insurance Policy Administration 10.0/10.1/10.2/11.0 Apache Log4j unknown vulnerability
17612| [121370] Apache Spark up to 2.1.2/2.2.1/2.3.0 URL cross site scripting
17613| [121354] Apache CouchDB HTTP API Code Execution
17614| [121144] Apache LDAP API up to 1.0.1 SSL Filter information disclosure
17615| [121143] Apache Storm up to 0.10.2/1.0.6/1.1.2/1.2.1 Cluster privilege escalation
17616| [120436] Apache CXF Fediz up to 1.4.3 Application Plugin unknown vulnerability
17617| [120310] Apache PDFbox up to 1.8.14/2.0.10 AFMParser Loop denial of service
17618| [120168] Apache CXF weak authentication
17619| [120080] Apache Cassandra up to 3.11.1 JMX/RMI Interface RMI Request privilege escalation
17620| [120043] Apache HBase up to 1.2.6.0/1.3.2.0/1.4.4/2.0.0 Thrift 1 API Server weak authentication
17621| [119723] Apache Qpid Broker-J 7.0.0/7.0.1/7.0.2/7.0.3/7.0.4 AMQP Messages Crash denial of service
17622| [122569] Apache HTTP Server up to 2.4.33 HTTP2 Request denial of service
17623| [119486] Apache Geode up to 1.4.0 Security Manager Code Execution
17624| [119306] Apache MXNet Network Interface privilege escalation
17625| [118999] Apache Storm up to 1.0.6/1.1.2/1.2.1 Archive directory traversal
17626| [118996] Apache Storm up to 1.0.6/1.1.2/1.2.1 Daemon spoofing
17627| [118644] Apple macOS up to 10.13.5 apache_mod_php unknown vulnerability
17628| [118200] Apache Batik up to 1.9 Deserialization unknown vulnerability
17629| [118143] Apache NiFi activemq-client Library Deserialization denial of service
17630| [118142] Apache NiFi 1.6.0 SplitXML xxe privilege escalation
17631| [118051] Apache Zookeeper up to 3.4.9/3.5.3-beta weak authentication
17632| [117997] Apache ORC up to 1.4.3 ORC File Recursion denial of service
17633| [117825] Apache Tomcat up to 7.0.88/8.0.52/8.5.31/9.0.8 CORS Filter privilege escalation
17634| [117405] Apache Derby up to 10.14.1.0 Network Server Network Packet privilege escalation
17635| [117347] Apache Ambari up to 2.6.1 HTTP Request directory traversal
17636| [117265] LibreOffice/Apache Office Writer SMB Connection XML Document information disclosure
17637| [117143] Apache uimaj/uima-as/uimaFIT/uimaDUCC XML XXE information disclosure
17638| [117117] Apache Tika up to 1.17 ChmParser Loop denial of service
17639| [117116] Apache Tika up to 1.17 BPGParser Loop denial of service
17640| [117115] Apache Tika up to 1.17 tika-server command injection
17641| [116929] Apache Fineract getReportType Parameter privilege escalation
17642| [116928] Apache Fineract REST Endpoint Parameter privilege escalation
17643| [116927] Apache Fineract MakercheckersApiResource Parameter sql injection
17644| [116926] Apache Fineract REST Parameter privilege escalation
17645| [116574] Apache wicket-jquery-ui up to 6.29.0/7.10.1/8.0.0-M9.1 WYSIWYG Editor privilege escalation
17646| [116622] Oracle Enterprise Manager for MySQL Database 12.1.0.4 EM Plugin: General (Apache Tomcat) unknown vulnerability
17647| [115931] Apache Solr up to 6.6.2/7.2.1 XML Data Parameter XML External Entity
17648| [115883] Apache Hive up to 2.3.2 privilege escalation
17649| [115882] Apache Hive up to 2.3.2 xpath_short information disclosure
17650| [115881] Apache DriverHive JDBC Driver up to 2.3.2 Escape Argument Bypass privilege escalation
17651| [115518] Apache Ignite 2.3 Deserialization privilege escalation
17652| [115260] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache cross site scripting
17653| [115259] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache Cookie Stack-based memory corruption
17654| [115500] CA Workload Control Center up to r11.4 SP5 Apache MyFaces Component Code Execution
17655| [115121] Apache Struts REST Plugin up to 2.5.15 Xstream XML Data denial of service
17656| [115061] Apache HTTP Server up to 2.4.29 HTTP Digest Authentication Challenge HTTP Requests Replay privilege escalation
17657| [115060] Apache HTTP Server up to 2.4.29 mod_cache_socache Request Header Crash denial of service
17658| [115059] Apache HTTP Server up to 2.4.29 HTTP2 NULL Pointer Dereference denial of service
17659| [115058] Apache HTTP Server up to 2.4.29 HTTP Header Crash denial of service
17660| [115057] Apache HTTP Server up to 2.4.29 mod_session Variable Name Cache privilege escalation
17661| [115039] Apache HTTP Server up to 2.4.29 FilesMatch File Upload privilege escalation
17662| [115038] Apache HTTP Server up to 2.0.65/2.2.34/2.4.29 mod_authnz_ldap Crash denial of service
17663| [114817] Apache Syncope up to 1.2.10/2.0.7 Search Parameter information disclosure
17664| [114816] Apache Syncope up to 1.2.10/2.0.7 XSLT Code Execution
17665| [114717] Apache Commons 1.11/1.12/1.13/1.14/1.15 ZIP Archive ZipFile/ZipArchiveInputStream denial of service
17666| [114661] Apache Allura up to 1.8.0 HTTP Response Splitting privilege escalation
17667| [114400] Apache Tomcat JK ISAPI Connector up to 1.2.42 IIS/ISAPI privilege escalation
17668| [114258] Apache HTTP Server up to 2.4.22 mod_cluster Segmentation Fault denial of service
17669| [114086] Apache ODE 1.3.3 ODE Process Deployment Web Service directory traversal
17670| [113955] Apache Xerces-C up to 3.2.0 XML Parser NULL Pointer Dereference denial of service
17671| [113945] Apache Tomcat up to 7.0.84/8.0.49/8.5.27/9.0.4 URL Pattern Empty String privilege escalation
17672| [113944] Apache OpenMeetings up to 3.x/4.0.1 CRUD Operation denial of service
17673| [113905] Apache Traffic Server up to 5.2.x/5.3.2/6.2.0/7.0.0 TLS Handshake Core Dump denial of service
17674| [113904] Apache Traffic Server up to 6.2.0 Host Header privilege escalation
17675| [113895] Apache Geode up to 1.3.x Code Execution
17676| [113894] Apache Geode up to 1.3.x TcpServer Code Execution
17677| [113888] Apache James Hupa WebMail 0.0.2 cross site scripting
17678| [113813] Apache Geode Cluster up to 1.3.x Secure Mode privilege escalation
17679| [113747] Apache Tomcat Servlets privilege escalation
17680| [113647] Apache Qpid up to 0.30 qpidd Broker AMQP Message Crash denial of service
17681| [113645] Apache VCL up to 2.1/2.2.1/2.3.1 Web GUI/XMLRPC API privilege escalation
17682| [113560] Apache jUDDI Console 3.0.0 Log Entries spoofing
17683| [113571] Apache Oozie up to 4.3.0/5.0.0-beta1 XML Data XML File privilege escalation
17684| [113569] Apache Karaf up to 4.0.7 LDAPLoginModule LDAP injection denial of service
17685| [113273] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
17686| [113198] Apache Qpid Dispatch Router 0.7.0/0.8.0 AMQP denial of service
17687| [113186] Apache JMeter 2.x/3.x Distributed Test Only privilege escalation
17688| [113145] Apache Thrift up to 0.9.3 Go Client Library privilege escalation
17689| [113106] Apache jUDDI up to 3.3.3 XML Data WADL2Java/WSDL2Java XML Document privilege escalation
17690| [113105] Apache Qpid Broker-J 7.0.0 AMQP Crash denial of service
17691| [112885] Apache Allura up to 1.8.0 File information disclosure
17692| [112856] Apache CloudStack up to 4.8.1.0/4.9.0.0 API weak authentication
17693| [112855] Apache CloudStack 4.1.0/4.1.1 API information disclosure
17694| [112678] Apache Tomcat up to 7.0.82/8.0.47/8.5.23/9.0.1 Bug Fix 61201 privilege escalation
17695| [112677] Apache Tomcat Native Connector up to 1.1.34/1.2.14 OCSP Checker Client weak authentication
17696| [112625] Apache POI up to 3.16 Loop denial of service
17697| [112448] Apache NiFi up to 1.3.x Deserialization privilege escalation
17698| [112396] Apache Hadoop 2.7.3/2.7.4 YARN NodeManager Credentials information disclosure
17699| [112339] Apache NiFi 1.5.0 Header privilege escalation
17700| [112330] Apache NiFi 1.5.0 Header HTTP Request privilege escalation
17701| [112314] NetGain Enterprise Manager 7.2.730 Build 1034 org.apache.jsp.u.jsp.tools.exec_jsp Servlet Parameter privilege escalation
17702| [112253] Apache Hadoop up to 0.23.x/2.7.4/2.8.2 MapReduce Job History Server Configuration File privilege escalation
17703| [112171] Oracle Secure Global Desktop 5.3 Apache Log4j privilege escalation
17704| [112164] Oracle Agile PLM 9.3.5/9.3.6 Apache Tomcat unknown vulnerability
17705| [112161] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Tomcat privilege escalation
17706| [112158] Oracle Autovue for Agile Product Lifecycle Management 21.0.0/21.0.1 Apache Log4j privilege escalation
17707| [112156] Oracle Agile PLM 9.3.3/9.3.4/9.3.5/9.3.6 Apache Log4j privilege escalation
17708| [112155] Oracle Agile Engineering Data Management 6.1.3/6.2.0/6.2.1 Apache Log4j privilege escalation
17709| [112137] Oracle MICROS Relate CRM Software 10.8.x/11.4.x/15.0.x, Apache Tomcat unknown vulnerability
17710| [112136] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat privilege escalation
17711| [112133] Oracle Retail Workforce Management 1.60.7/1.64.0 Apache Log4j privilege escalation
17712| [112129] Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 Apache Log4j privilege escalation
17713| [112114] Oracle 9.1 Apache Log4j privilege escalation
17714| [112113] Oracle 9.1 Apache Log4j privilege escalation
17715| [112045] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat privilege escalation
17716| [112038] Oracle Health Sciences Empirica Inspections 1.0.1.1 Apache Tomcat information disclosure
17717| [112019] Oracle Endeca Information Discovery Integrator 3.1.0/3.2.0 Apache Tomcat privilege escalation
17718| [112017] Oracle WebCenter Portal 11.1.1.9.0/12.2.1.2.0/12.2.1.3.0 Apache Struts 1 cross site scripting
17719| [112011] Oracle Identity Manager 11.1.2.3.0 Apache Commons Collections privilege escalation
17720| [111950] Oracle Database 12.2.0.1 Apache Tomcat information disclosure
17721| [111703] Apache Sling XSS Protection API 1.0.4 URL Encoding cross site scripting
17722| [111556] Apache Geode up to 1.2.x Secure Mode Parameter OQL privilege escalation
17723| [111555] Apache Geode up to 1.2.x Secure Mode OQL privilege escalation
17724| [111540] Apache Geode up to 1.2.x Secure Mode information disclosure
17725| [111519] Apache Sling JCR ContentLoader 2.1.4 xmlreader directory traversal
17726| [111338] Apache DeltaSpike-JSF 1.8.0 cross site scripting
17727| [111330] Apache OFBiz 16.11.01/16.11.02/16.11.03 BIRT Plugin cross site scripting
17728| [110789] Apache Sling up to 1.4.0 Authentication Service Credentials information disclosure
17729| [110785] Apache Drill up to 1.11.0 Query Page unknown vulnerability
17730| [110701] Apache Fineract Query Parameter sql injection
17731| [110484] Apache Synapse up to 3.0.0 Apache Commons Collections Serialized Object Code Injection privilege escalation
17732| [110426] Adobe Experience Manager 6.0/6.1/6.2/6.3 Apache Sling Servlets Post cross site scripting
17733| [110141] Apache Struts up to 2.5.14 REST Plugin denial of service
17734| [110140] Apache Qpid Broker-J up to 0.32 privilege escalation
17735| [110139] Apache Qpid Broker-J up to 6.1.4 AMQP Frame denial of service
17736| [110106] Apache CXF Fediz Spring cross site request forgery
17737| [109766] Apache OpenOffice up to 4.1.3 DOC File Parser WW8Fonts memory corruption
17738| [109750] Apache OpenOffice up to 4.1.3 DOC File Parser ImportOldFormatStyles memory corruption
17739| [109749] Apache OpenOffice up to 4.1.3 PPT File Parser PPTStyleSheet memory corruption
17740| [109606] October CMS Build 412 Apache Configuration File Upload privilege escalation
17741| [109419] Apache Camel up to 2.19.3/2.20.0 camel-castor Java Object Deserialization privilege escalation
17742| [109418] Apache Camel up to 2.19.3/2.20.0 camel-hessian Java Object Deserialization privilege escalation
17743| [109400] Apache CouchDB up to 1.6.x/2.1.0 Database Server Shell privilege escalation
17744| [109399] Apache CouchDB up to 1.6.x/2.1.0 JSON Parser Shell privilege escalation
17745| [109398] Apache CXF 3.1.14/3.2.1 JAX-WS/JAX-RS Attachment denial of service
17746| [108872] Apache Hive up to 2.1.1/2.2.0/2.3.0 Policy Enforcement privilege escalation
17747| [108939] Apple macOS up to 10.13.1 apache unknown vulnerability
17748| [108938] Apple macOS up to 10.13.1 apache denial of service
17749| [108937] Apple macOS up to 10.13.1 apache unknown vulnerability
17750| [108936] Apple macOS up to 10.13.1 apache unknown vulnerability
17751| [108935] Apple macOS up to 10.13.1 apache denial of service
17752| [108934] Apple macOS up to 10.13.1 apache unknown vulnerability
17753| [108933] Apple macOS up to 10.13.1 apache unknown vulnerability
17754| [108932] Apple macOS up to 10.13.1 apache unknown vulnerability
17755| [108931] Apple macOS up to 10.13.1 apache denial of service
17756| [108930] Apple macOS up to 10.13.1 apache unknown vulnerability
17757| [108929] Apple macOS up to 10.13.1 apache denial of service
17758| [108928] Apple macOS up to 10.13.1 apache unknown vulnerability
17759| [108797] Apache Struts up to 2.3.19 TextParseUtiltranslateVariables OGNL Expression privilege escalation
17760| [108795] Apache Traffic Server up to 5.3.0 HTTP2 set_dynamic_table_size memory corruption
17761| [108794] Apache WSS4J up to 1.6.16/2.0.1 Incomplete Fix Leak information disclosure
17762| [108793] Apache Qpid up to 0.30 qpidd Crash denial of service
17763| [108792] Apache Traffic Server up to 5.1.0 Access Restriction privilege escalation
17764| [108791] Apache Wicket up to 1.5.11/6.16.x/7.0.0-M2 Session information disclosure
17765| [108790] Apache Storm 0.9.0.1 Log Viewer directory traversal
17766| [108789] Apache Cordova In-App-Browser Standalone Plugin up to 0.3.1 on iOS CDVInAppBrowser privilege escalation
17767| [108788] Apache Cordova File-Transfer Standalone Plugin up to 0.4.1 on iOS ios/CDVFileTransfer.m spoofing
17768| [108787] Apache HttpClient up to 4.3.0 HttpClientBuilder.java unknown vulnerability
17769| [108786] Apache Wicket up to 1.4.21/1.5.9/6.3.x script Tag cross site scripting
17770| [108783] Apache Hadoop up to 0.23.3/1.0.3/2.0.1 Kerberos Security Feature Key weak encryption
17771| [108782] Apache Xerces2 XML Service denial of service
17772| [108781] Apache jUDDI up to 1.x happyjuddi.jsp Parameter cross site scripting
17773| [108780] Apache jUDDI up to 1.x Log File uddiget.jsp spoofing
17774| [108709] Apache Cordova Android up to 3.7.1/4.0.1 intent URL privilege escalation
17775| [108708] Apache ActiveMQ up to 5.10.0 XML Data XML External Entity
17776| [108707] Apache ActiveMQ up to 1.7.0 XML Data XML External Entity
17777| [108629] Apache OFBiz up to 10.04.01 privilege escalation
17778| [108543] Apache Derby 10.1.2.1/10.2.2.0/10.3.1.4/10.4.1.3 Export File privilege escalation
17779| [108312] Apache HTTP Server on RHEL IP Address Filter privilege escalation
17780| [108297] Apache NiFi up to 0.7.1/1.1.1 Proxy Chain Username Deserialization privilege escalation
17781| [108296] Apache NiFi up to 0.7.1/1.1.1 Cluster Request privilege escalation
17782| [108250] Oracle Secure Global Desktop 5.3 Apache HTTP Server memory corruption
17783| [108245] Oracle Transportation Management up to 6.3.7 Apache Tomcat unknown vulnerability
17784| [108244] Oracle Transportation Management 6.4.1/6.4.2 Apache Commons FileUpload denial of service
17785| [108243] Oracle Agile Engineering Data Management 6.1.3/6.2.0 Apache Commons Collections memory corruption
17786| [108222] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Batik denial of service
17787| [108219] Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 Apache Tomcat unknown vulnerability
17788| [108217] Oracle Retail Store Inventory Management 13.2.9/14.0.4/14.1.3/15.0.1/16.0.1 Apache Groovy unknown vulnerability
17789| [108216] Oracle Retail Convenience and Fuel POS Software 2.1.132 Apache Groovy unknown vulnerability
17790| [108169] Oracle MySQL Enterprise Monitor up to 3.2.8.2223/3.3.4.3247/3.4.2.4181 Apache Tomcat unknown vulnerability
17791| [108113] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Batik denial of service
17792| [108107] Oracle Hospitality Guest Access 4.2.0/4.2.1 Apache Tomcat unknown vulnerability
17793| [108102] Oracle Healthcare Master Person Index 4.x Apache Groovy unknown vulnerability
17794| [108085] Oracle Identity Manager 11.1.2.3.0 Apache Struts 1 memory corruption
17795| [108083] Oracle API Gateway 11.1.2.4.0 Apache Batik denial of service
17796| [108080] Oracle GlassFish Server 3.1.2 Apache Commons FileUpload denial of service
17797| [108066] Oracle Management Pack for GoldenGate 11.2.1.0.12 Apache Tomcat memory corruption
17798| [108062] Oracle BI Publisher 11.1.1.7.0/12.2.1.1.0/12.2.1.2.0 Apache ActiveMQ memory corruption
17799| [108060] Oracle Enterprise Manager Ops Center 12.2.2/12.3.2 Apache Groovy unknown vulnerability
17800| [108033] Oracle Primavera Unifier 9.13/9.14/10.x/15.x/16.x, Apache Groovy unknown vulnerability
17801| [108013] Oracle Communications WebRTC Session Controller 7.0/7.1/7.2 Apache Groovy unknown vulnerability
17802| [108011] Oracle Communications Services Gatekeeper 5.1/6.0 Apache Trinidad unknown vulnerability
17803| [107904] Apache Struts up to 2.3.28 Double OGNL Evaluation privilege escalation
17804| [107860] Apache Solr up to 7.0 Apache Lucene RunExecutableListener XML External Entity
17805| [107834] Apache Ranger up to 0.6.1 Change Password privilege escalation
17806| [107639] Apache NiFi 1.4.0 XML External Entity
17807| [107606] Apache ZooKeper up to 3.4.9/3.5.2 Command CPU Exhaustion denial of service
17808| [107597] Apache Roller up to 5.0.2 XML-RPC Protocol Support XML External Entity
17809| [107429] Apache Impala up to 2.9.x Kudu Table privilege escalation
17810| [107411] Apache Tomcat up to 7.0.81/8.0.46/8.5.22/9.0.0 JSP File File Upload privilege escalation
17811| [107385] Apache Geode up to 1.2.0 Secure Mode privilege escalation
17812| [107339] Apache OpenNLP up to 1.5.3/1.6.0/1.7.2/1.8.1 XML Data XML External Entity
17813| [107333] Apache Wicket up to 8.0.0-M1 CSRF Prevention HTTP Header privilege escalation
17814| [107323] Apache Wicket 1.5.10/6.13.0 Class Request information disclosure
17815| [107310] Apache Geode up to 1.2.0 Command Line Utility Query privilege escalation
17816| [107276] ArcSight ESM/ArcSight ESM Express up to 6.9.1c Patch 3/6.11.0 Apache Tomcat Version information disclosure
17817| [107266] Apache Tika up to 1.12 XML Parser XML External Entity
17818| [107262] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
17819| [107258] Apache Mesos up to 1.1.2/1.2.1/1.3.0/1.4.0-dev libprocess HTTP Request Crash denial of service
17820| [107197] Apache Xerces Jelly Parser XML File XML External Entity
17821| [107193] ZTE NR8950 Apache Commons Collections RMI Request Deserialization privilege escalation
17822| [107084] Apache Struts up to 2.3.19 cross site scripting
17823| [106877] Apache Struts up to 2.0.33/2.5.10 Freemarker Tag privilege escalation
17824| [106875] Apache Struts up to 2.5.5 URL Validator denial of service
17825| [106874] Apache Struts up to 2.3.30 Convention Plugin directory traversal
17826| [106847] Apache Tomcat up to 7.0.80 VirtualDirContext Source information disclosure
17827| [106846] Apache Tomcat up to 7.0.79 on Windows HTTP PUT Method Parameter File Upload privilege escalation
17828| [106777] Apache HTTP Server up to 2.2.34/2.4.27 Limit Directive ap_limit_section HTTP Request information disclosure
17829| [106739] puppetlabs-apache up to 1.11.0/2.0.x weak authentication
17830| [106720] Apache Wicket up to 1.5.12/6.18.x/7.0.0-M4 CryptoMapper privilege escalation
17831| [106586] Apache Brooklyn up to 0.9.x REST Server cross site scripting
17832| [106562] Apache Spark up to 2.1.1 Launcher API Deserialization privilege escalation
17833| [106559] Apache Brooklyn up to 0.9.x SnakeYAML YAML Data Java privilege escalation
17834| [106558] Apache Brooklyn up to 0.9.x REST Server cross site request forgery
17835| [106556] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
17836| [106555] Apache Traffic Server up to 5.3.1 HTTP2 unknown vulnerability
17837| [106171] Apache Directory LDAP API up to 1.0.0-M30 Timing unknown vulnerability
17838| [106167] Apache Struts up to 2.5.12 REST Plugin XML Data privilege escalation
17839| [106166] Apache Struts up to 2.3.33/2.5.12 REST Plugin denial of service
17840| [106165] Apache Struts up to 2.3.33/2.5.12 URLValidator Regex CPU Exhaustion denial of service
17841| [106115] Apache Hadoop up to 2.6.4/2.7.2 YARN NodeManager Password information disclosure
17842| [106012] Apache Solr up to 5.5.3/6.4.0 Replication directory traversal
17843| [105980] Apache Engine 16.11.01 Parameter Reflected unknown vulnerability
17844| [105962] Apache Atlas 0.6.0/0.7.0 Frame cross site scripting
17845| [105961] Apache Atlas 0.6.0/0.7.0 Stack Trace information disclosure
17846| [105960] Apache Atlas 0.6.0/0.7.0 Search Reflected cross site scripting
17847| [105959] Apache Atlas 0.6.0/0.7.0 edit Tag DOM cross site scripting
17848| [105958] Apache Atlas 0.6.0/0.7.0 edit Tag Stored cross site scripting
17849| [105957] Apache Atlas 0.6.0/0.7.0 Cookie privilege escalation
17850| [105905] Apache Atlas 0.6.0/0.7.0/0.7.1 /js privilege escalation
17851| [105878] Apache Struts up to 2.3.24.0 privilege escalation
17852| [105682] Apache2Triad 1.5.4 phpsftpd/users.php Parameter cross site scripting
17853| [105681] Apache2Triad 1.5.4 phpsftpd/users.php Request cross site request forgery
17854| [105680] Apache2Triad 1.5.4 Parameter Session Fixation weak authentication
17855| [105643] Apache Pony Mail up to 0.8b weak authentication
17856| [105288] Apache Sling up to 2.3.21 Sling.evalString() String cross site scripting
17857| [105219] Apache Tomcat up to 8.5.15/9.0.0.M21 HTTP2 Bypass directory traversal
17858| [105218] Apache Tomcat up to 7.0.78/8.0.44/8.5.15/9.0.0.M21 CORS Filter Cache Poisoning privilege escalation
17859| [105215] Apache CXF up to 3.0.12/3.1.9 OAuth2 Hawk/JOSE MAC Validation Timing unknown vulnerability
17860| [105206] Apache CXF up to 3.0.11/3.1.8 JAX-RS Module XML External Entity
17861| [105205] Apache CXF up to 3.0.11/3.1.8 HTTP Transport Module Parameter cross site scripting
17862| [105202] Apache Storm 1.0.0/1.0.1/1.0.2/1.0.3/1.1.0 Worker privilege escalation
17863| [104987] Apache Xerces-C++ XML Service CPU Exhaustion denial of service
17864| [104986] Apache CXF 2.4.5/2.5.1 WS-SP UsernameToken Policy SOAP Request weak authentication
17865| [104985] Apache MyFaces Core up to 2.1.4 EL Expression Parameter Injection information disclosure
17866| [104983] Apache Wink up to 1.1.1 XML Document xxe privilege escalation
17867| [104981] Apache Commons Email 1.0/1.1/1.2/1.3/1.4 Subject Linebreak SMTP privilege escalation
17868| [104591] MEDHOST Document Management System Apache Solr Default Credentials weak authentication
17869| [104062] Oracle MySQL Enterprise Monitor up to 3.3.3.1199 Apache Tomcat unknown vulnerability
17870| [104061] Oracle MySQL Enterprise Monitor up to 3.2.7.1204/3.3.3.1199 Apache Tomcat unknown vulnerability
17871| [104060] Oracle MySQL Enterprise Monitor up to 3.1.5.7958/3.2.5.1141/3.3.2.1162 Apache Struts 2 unknown vulnerability
17872| [103995] Oracle 8.3/8.4/15.1/15.2 Apache Trinidad unknown vulnerability
17873| [103993] Oracle Policy Automation up to 12.2.3 Apache Commons FileUplaod denial of service
17874| [103916] Oracle Banking Platform 2.3/2.4/2.4.1/2.5 Apache Commons FileUpload denial of service
17875| [103906] Oracle Communications BRM 11.2.0.0.0 Apache Commons Collections privilege escalation
17876| [103904] Oracle Communications BRM 11.2.0.0.0/11.3.0.0.0 Apache Groovy memory corruption
17877| [103866] Oracle Transportation Management 6.1/6.2 Apache Webserver unknown vulnerability
17878| [103816] Oracle BI Publisher 11.1.1.9.0/12.2.1.1.0/12.2.1.2.0 Apache Commons Fileupload denial of service
17879| [103797] Oracle Tuxedo System and Applications Monitor Apache Commons Collections privilege escalation
17880| [103792] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Commons Fileupload privilege escalation
17881| [103791] Oracle Endeca Server 7.6.0.0/7.6.1.0 Apache Commons Collections privilege escalation
17882| [103788] Oracle Enterprise Repository 11.1.1.7.0/12.1.3.0.0 Apache ActiveMQ memory corruption
17883| [103787] Oracle Enterprise Data Quality 8.1.13.0.0 Apache Groovy memory corruption
17884| [103763] Apache Sling up to 1.0.11 XSS Protection API XSS.getValidXML() Application XML External Entity
17885| [103762] Apache Sling up to 1.0.12 XSS Protection API XSSAPI.encodeForJSString() Script Tag cross site scripting
17886| [103693] Apache OpenMeetings 1.0.0 HTTP Method privilege escalation
17887| [103692] Apache OpenMeetings 1.0.0 Tomcat Error information disclosure
17888| [103691] Apache OpenMeetings 3.2.0 Parameter privilege escalation
17889| [103690] Apache OpenMeetings 1.0.0 sql injection
17890| [103689] Apache OpenMeetings 1.0.0 crossdomain.xml privilege escalation
17891| [103688] Apache OpenMeetings 1.0.0 weak encryption
17892| [103687] Apache OpenMeetings 1.0.0 cross site request forgery
17893| [103556] Apache Roller 5.1.0/5.1.1 Weblog Page Template VTL privilege escalation
17894| [103554] Apache OpenMeetings 1.0.0 Password Update unknown vulnerability
17895| [103553] Apache OpenMeetings 1.0.0 File Upload privilege escalation
17896| [103552] Apache OpenMeetings 3.2.0 Chat cross site scripting
17897| [103551] Apache OpenMeetings 3.1.0 XML unknown vulnerability
17898| [103521] Apache HTTP Server 2.4.26 HTTP2 Free memory corruption
17899| [103520] Apache HTTP Server up to 2.2.33/2.4.26 mod_auth_digest Authorization Header memory corruption
17900| [103519] Apache Struts up to 2.5.11/2.3.32 Spring AOP denial of service
17901| [103518] Apache Struts up to 2.5.11 URLValidator directory traversal
17902| [103492] Apache Spark up to 2.1.x Web UI Reflected cross site scripting
17903| [103401] Apache Struts 2.3.x Struts 1 Plugin ActionMessage privilege escalation
17904| [103399] Apache Traffic Control Traffic Router TCP Connection Slowloris denial of service
17905| [103387] Apache Impala up to 2.8.0 StatestoreSubscriber weak encryption
17906| [103386] Apache Impala up to 2.7.x/2.8.0 Kerberos weak authentication
17907| [103352] Apache Solr Node weak authentication
17908| [102897] Apache Ignite up to 2.0 Update Notifier information disclosure
17909| [102878] Code42 CrashPlan 5.4.x RMI Server org.apache.commons.ssl.rmi.DateRMI privilege escalation
17910| [102698] Apache HTTP Server up to 2.2.32/2.4.25 mod_mime Content-Type memory corruption
17911| [102697] Apache HTTP Server 2.2.24/2.2.32 HTTP Strict Parsing ap_find_token Request Header memory corruption
17912| [102690] Apache HTTP Server up to 2.2.32/2.4.25 mod_ssl ap_hook_process_connection() denial of service
17913| [102689] Apache HTTP Server up to 2.2.32/2.4.25 ap_get_basic_auth_pw weak authentication
17914| [102622] Apache Thrift up to 0.9.2 Client Libraries skip denial of service
17915| [102538] Apache Ranger up to 0.7.0 Authorizer unknown vulnerability
17916| [102537] Apache Ranger up to 0.7.0 Wildcard Character unknown vulnerability
17917| [102536] Apache Ranger up to 0.6 Stored cross site scripting
17918| [102535] Apache Ranger up to 0.6.2 Policy Engine unknown vulnerability
17919| [102255] Apache NiFi up to 0.7.3/1.2.x Response Header privilege escalation
17920| [102254] Apache NiFi up to 0.7.3/1.2.x UI cross site scripting
17921| [102070] Apache CXF Fediz up to 1.1.2/1.2.0 Application Plugin denial of service
17922| [102020] Apache Tomcat up to 9.0.0.M1 Java Servlet HTTP Method unknown vulnerability
17923| [101858] Apache Hive up to 1.2.1/2.0.0 Client weak authentication
17924| [101802] Apache KNOX up to 0.11.0 WebHDFS privilege escalation
17925| [101928] HPE Aruba ClearPass Apache Tomcat information disclosure
17926| [101524] Apache Archiva up to 1.x/2.2.1 REST Endpoint cross site request forgery
17927| [101513] Apache jUDDI 3.1./3.1.2/3.1.3/3.1.4 Logout Open Redirect
17928| [101430] Apache CXF Fediz up to 1.3.1 OIDC Service cross site request forgery
17929| [101429] Apache CXF Fediz up to 1.2.3/1.3.1 Plugins cross site request forgery
17930| [100619] Apache Hadoop up to 2.6.x HDFS Servlet unknown vulnerability
17931| [100618] Apache Hadoop up to 2.7.0 HDFS Web UI cross site scripting
17932| [100621] Adobe ColdFusion 10/11/2016 Apache BlazeDS Library Deserialization privilege escalation
17933| [100205] Oracle MySQL Enterprise Monitor up to 3.1.6.8003/3.2.1182/3.3.2.1162 Apache Commons FileUpload denial of service
17934| [100191] Oracle Secure Global Desktop 4.71/5.2/5.3 Web Server (Apache HTTP Server) information disclosure
17935| [100162] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Commons Collections privilege escalation
17936| [100160] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 Apache Trinidad unknown vulnerability
17937| [99969] Oracle WebCenter Sites 11.1.1.8.0 Apache Tomcat memory corruption
17938| [99937] Apache Batik up to 1.8 privilege escalation
17939| [99936] Apache FOP up to 2.1 privilege escalation
17940| [99935] Apache CXF up to 3.0.12/3.1.10 STSClient Cache information disclosure
17941| [99934] Apache CXF up to 3.0.12/3.1.10 JAX-RS XML Security Streaming Client spoofing
17942| [99930] Apache Traffic Server up to 6.2.0 denial of service
17943| [99929] Apache Log4j up to 2.8.1 Socket Server Deserialization privilege escalation
17944| [99925] Apache Traffic Server 6.0.0/6.1.0/6.2.0 HPACK Bomb denial of service
17945| [99738] Ping Identity OpenID Connect Authentication Module up to 2.13 on Apache Mod_auth_openidc.c spoofing
17946| [117569] Apache Hadoop up to 2.7.3 privilege escalation
17947| [99591] Apache TomEE up to 1.7.3/7.0.0-M2 EjbObjectInputStream Serialized Object privilege escalation
17948| [99370] Apache Ignite up to 1.8 update-notifier Document XML External Entity
17949| [99299] Apache Geode up to 1.1.0 Pulse OQL Query privilege escalation
17950| [99572] Apache Tomcat up to 7.0.75/8.0.41/8.5.11/9.0.0.M17 Application Listener privilege escalation
17951| [99570] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP Connector Cache information disclosure
17952| [99569] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 HTTP/2 GOAWAY Frame Resource Exhaustion denial of service
17953| [99568] Apache Tomcat up to 6.0.52/7.0.76/8.0.42/8.5.12/9.0.0.M18 Pipelined Request information disclosure
17954| [99048] Apache Ambari up to 2.3.x REST API Shell Metacharacter privilege escalation
17955| [99014] Apache Camel Jackson/JacksonXML privilege escalation
17956| [98610] Apple macOS up to 10.12.3 apache_mod_php memory corruption
17957| [98609] Apple macOS up to 10.12.3 apache_mod_php denial of service
17958| [98608] Apple macOS up to 10.12.3 apache_mod_php memory corruption
17959| [98607] Apple macOS up to 10.12.3 apache_mod_php denial of service
17960| [98606] Apple macOS up to 10.12.3 apache_mod_php denial of service
17961| [98605] Apple macOS up to 10.12.3 Apache denial of service
17962| [98604] Apple macOS up to 10.12.3 Apache denial of service
17963| [98603] Apple macOS up to 10.12.3 Apache denial of service
17964| [98602] Apple macOS up to 10.12.3 Apache denial of service
17965| [98601] Apple macOS up to 10.12.3 Apache denial of service
17966| [98517] Apache POI up to 3.14 OOXML File XXE denial of service
17967| [98405] Apache Hadoop up to 0.23.10 privilege escalation
17968| [98199] Apache Camel Validation XML External Entity
17969| [97892] Apache Tomcat up to 9.0.0.M15 Reverse-Proxy Http11InputBuffer.java information disclosure
17970| [97617] Apache Camel camel-snakeyaml Deserialization privilege escalation
17971| [97602] Apache Camel camel-jackson/camel-jacksonxml CamelJacksonUnmarshalType privilege escalation
17972| [97732] Apache Struts up to 2.3.31/2.5.10 Jakarta Multipart Parser Content-Type privilege escalation
17973| [97466] mod_auth_openidc up to 2.1.5 on Apache weak authentication
17974| [97455] mod_auth_openidc up to 2.1.4 on Apache weak authentication
17975| [97081] Apache Tomcat HTTPS Request denial of service
17976| [97162] EMC OpenText Documentum D2 BeanShell/Apache Commons privilege escalation
17977| [96949] Hanwha Techwin Smart Security Manager up to 1.5 Redis/Apache Felix Gogo privilege escalation
17978| [96314] Apache Cordova up to 6.1.1 on Android weak authentication
17979| [95945] Apple macOS up to 10.12.2 apache_mod_php denial of service
17980| [95944] Apple macOS up to 10.12.2 apache_mod_php denial of service
17981| [95943] Apple macOS up to 10.12.2 apache_mod_php memory corruption
17982| [95666] Oracle FLEXCUBE Direct Banking 12.0.0/12.0.1/12.0.2/12.0.3 Apache Commons Collections privilege escalation
17983| [95455] Apache NiFi up to 1.0.0/1.1.0 Connection Details Dialogue cross site scripting
17984| [95311] Apache Storm UI Daemon privilege escalation
17985| [95291] ZoneMinder 1.30.0 Apache httpd privilege escalation
17986| [94800] Apache Wicket up to 1.5.16/6.24.x Deserialize DiskFileItem denial of service
17987| [94705] Apache Qpid Broker for Java up to 6.1.0 SCRAM-SHA-1/SCRAM-SHA-256 User information disclosure
17988| [94627] Apache HTTP Server up to 2.4.24 mod_auth_digest Crash denial of service
17989| [94626] Apache HTTP Server up to 2.4.24 mod_session_crypto Padding weak encryption
17990| [94625] Apache HTTP Server up to 2.4.24 Response Split privilege escalation
17991| [94540] Apache Tika 1.9 tika-server File information disclosure
17992| [94600] Apache ActiveMQ up to 5.14.1 Administration Console cross site scripting
17993| [94348] Apple macOS up to 10.12.1 apache_mod_php denial of service
17994| [94347] Apple macOS up to 10.12.1 apache_mod_php denial of service
17995| [94346] Apple macOS up to 10.12.1 apache_mod_php denial of service
17996| [94345] Apple macOS up to 10.12.1 apache_mod_php denial of service
17997| [94344] Apple macOS up to 10.12.1 apache_mod_php denial of service
17998| [94343] Apple macOS up to 10.12.1 apache_mod_php memory corruption
17999| [94342] Apple macOS up to 10.12.1 apache_mod_php memory corruption
18000| [94128] Apache Tomcat up to 9.0.0.M13 Error information disclosure
18001| [93958] Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c denial of service
18002| [93874] Apache Subversion up to 1.8.16/1.9.4 mod_dontdothat XXE denial of service
18003| [93855] Apache Hadoop up to 2.6.4/2.7.2 HDFS Service privilege escalation
18004| [93609] Apache OpenMeetings 3.1.0 RMI Registry privilege escalation
18005| [93555] Apache Tika 1.6-1.13 jmatio MATLAB File privilege escalation
18006| [93799] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
18007| [93798] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener privilege escalation
18008| [93797] Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 HTTP Split privilege escalation
18009| [93796] Apache Tomcat up to 8.5.6/9.0.0.M11 HTTP/2 Header Parser denial of service
18010| [93532] Apache Commons Collections Library Java privilege escalation
18011| [93210] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 ResourceLinkFactory privilege escalation
18012| [93209] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Realm Authentication User information disclosure
18013| [93208] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 System Property Replacement information disclosure
18014| [93207] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Utility Method privilege escalation
18015| [93206] Apache Tomcat up to 6.0.45/7.0.70/8.0.36/8.5.4/9.0.0.M9 Configuration privilege escalation
18016| [93098] Apache Commons FileUpload privilege escalation
18017| [92987] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Commons Collection memory corruption
18018| [92986] Oracle Virtual Desktop Infrastructure up to 3.5.2 Apache Tomcat memory corruption
18019| [92982] Oracle Insurance IStream 4.3.2 Apache Commons Collections memory corruption
18020| [92981] Oracle Financial Services Lending and Leasing 14.1.0/14.2.0 Apache Commons Collections memory corruption
18021| [92979] Oracle up to 8.0.3 Apache Commons Collections memory corruption
18022| [92977] Oracle FLEXCUBE Universal Banking up to 12.2.0 Apache Commons Collections memory corruption
18023| [92976] Oracle FLEXCUBE Universal Banking 12.87.1/12.87.2 Apache Commons Collections memory corruption
18024| [92975] Oracle FLEXCUBE Private Banking up to 12.1.0 Apache Commons Collections memory corruption
18025| [92974] Oracle FLEXCUBE Investor Servicing 12.0.1 Apache Commons Collections memory corruption
18026| [92973] Oracle 12.0.0/12.1.0 Apache Commons Collections memory corruption
18027| [92972] Oracle FLEXCUBE Core Banking 11.5.0.0.0/11.6.0.0.0 Apache Commons Collections memory corruption
18028| [92962] Oracle Agile PLM 9.3.4/9.3.5 Apache Commons Collections memory corruption
18029| [92909] Oracle Agile PLM 9.3.4/9.3.5 Apache Tomcat unknown vulnerability
18030| [92786] Oracle Banking Digital Experience 15.1 Apache Commons Collections information disclosure
18031| [92549] Apache Tomcat on Red Hat privilege escalation
18032| [92509] Apache Tomcat JK ISAPI Connector up to 1.2.41 jk_uri_worker_map.c memory corruption
18033| [92314] Apache MyFaces Trinidad up to 1.0.13/1.2.15/2.0.1/2.1.1 CoreResponseStateManager memory corruption
18034| [92313] Apache Struts2 up to 2.3.28/2.5.0 Action Name Cleanup cross site request forgery
18035| [92299] Apache Derby up to 10.12.1.0 SqlXmlUtil XML External Entity
18036| [92217] Apache ActiveMQ Artemis up to 1.3.x Broker/REST GetObject privilege escalation
18037| [92174] Apache Ranger up to 0.6.0 Policy cross site scripting
18038| [91831] Apache Jackrabbit up to 2.13.2 HTTP Header cross site request forgery
18039| [91825] Apache Zookeeper up to 3.4.8/3.5.2 C CLI Shell memory corruption
18040| [91818] Apache CXF Fediz up to 1.2.2/1.3.0 Application Plugin privilege escalation
18041| [92056] Apple macOS up to 10.11 apache_mod_php memory corruption
18042| [92055] Apple macOS up to 10.11 apache_mod_php memory corruption
18043| [92054] Apple macOS up to 10.11 apache_mod_php denial of service
18044| [92053] Apple macOS up to 10.11 apache_mod_php denial of service
18045| [92052] Apple macOS up to 10.11 apache_mod_php denial of service
18046| [92051] Apple macOS up to 10.11 apache_mod_php memory corruption
18047| [92050] Apple macOS up to 10.11 apache_mod_php denial of service
18048| [92049] Apple macOS up to 10.11 apache_mod_php memory corruption
18049| [92048] Apple macOS up to 10.11 apache_mod_php denial of service
18050| [92047] Apple macOS up to 10.11 apache_mod_php memory corruption
18051| [92046] Apple macOS up to 10.11 apache_mod_php memory corruption
18052| [92045] Apple macOS up to 10.11 apache_mod_php memory corruption
18053| [92044] Apple macOS up to 10.11 apache_mod_php memory corruption
18054| [92043] Apple macOS up to 10.11 apache_mod_php denial of service
18055| [92042] Apple macOS up to 10.11 apache_mod_php memory corruption
18056| [92041] Apple macOS up to 10.11 apache_mod_php memory corruption
18057| [92040] Apple macOS up to 10.11 Apache Proxy privilege escalation
18058| [91785] Apache Shiro up to 1.3.1 Servlet Filter privilege escalation
18059| [90879] Apache OpenMeetings up to 3.1.1 SWF Panel cross site scripting
18060| [90878] Apache Sentry up to 1.6.x Blacklist Filter reflect/reflect2/java_method privilege escalation
18061| [90610] Apache POI up to 3.13 XLSX2CSV Example OpenXML Document XML External Entity
18062| [90584] Apache ActiveMQ up to 5.11.3/5.12.2/5.13/1 Administration Web Console privilege escalation
18063| [90385] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site scripting
18064| [90384] Apache Archiva up to 1.3.9 addProxyConnector_commit.action cross site request forgery
18065| [90383] Apache OpenOffice up to 4.1.2 Impress File memory corruption
18066| [89670] Apache Tomcat up to 8.5.4 CGI Servlet Environment Variable Open Redirect
18067| [89669] Apache HTTP Server up to 2.4.23 RFC 3875 Namespace Conflict Environment Variable Open Redirect
18068| [89726] Apple Mac OS X up to 10.11.5 apache_mod_php memory corruption
18069| [89484] Apache Qpid up to 0.13.0 on Windows Proton Library Certificate weak authentication
18070| [89473] HPE iMC PLAT/EAD/APM/iMC NTA/iMC BIMS/iMC UAM_TAM up to 7.2 Apache Commons Collections Library Command privilege escalation
18071| [90263] Apache Archiva Header denial of service
18072| [90262] Apache Archiva Deserialize privilege escalation
18073| [90261] Apache Archiva XML DTD Connection privilege escalation
18074| [88827] Apache Xerces-C++ up to 3.1.3 DTD Stack-Based memory corruption
18075| [88747] Apache HTTP Server 2.4.17/2.4.18 mod_http2 denial of service
18076| [88608] Apache Struts up to 2.3.28.1/2.5.0 URLValidator Null Value denial of service
18077| [88607] Apache Struts up to 2.3.28.1 REST Plugin Expression privilege escalation
18078| [88606] Apache Struts up to 2.3.28.1 Restriction privilege escalation
18079| [88605] Apache Struts up to 2.3.28.1 Restriction privilege escalation
18080| [88604] Apache Struts up to 2.3.28.1 Token Validator cross site request forgery
18081| [88603] Apache Commons FileUpload up to 1.3.1 MultipartStream denial of service
18082| [88602] Apache Struts up to 1.3.10 ActionServlet.java cross site scripting
18083| [88601] Apache Struts up to 1.3.10 Multithreading ActionServlet.java memory corruption
18084| [88600] Apache Struts up to 1.3.10 MultiPageValidator privilege escalation
18085| [89005] Apache Qpid AMQP JMS Client getObject privilege escalation
18086| [87888] Apache Ranger up to 0.5.2 Policy Admin Tool eventTime sql injection
18087| [87835] Apache CloudStack up to 4.5.2.0/4.6.2.0/4.7.1.0/4.8.0.0 SAML-based Authentication privilege escalation
18088| [87806] HPE Discovery and Dependency Mapping Inventory up to 9.32 update 3 Apache Commons Collections Library privilege escalation
18089| [87805] HPE Universal CMDB up to 10.21 Apache Commons Collections Library privilege escalation
18090| [87768] Apache Shiro up to 1.2.4 Cipher Key privilege escalation
18091| [87765] Apache James Server 2.3.2 Command privilege escalation
18092| [88667] Apache HTTP Server up to 2.4.20 mod_http2 Certificate weak authentication
18093| [87718] Apache Struts up to 2.3.24.1 OGNL Caching denial of service
18094| [87717] Apache Struts up to 2.3.28 REST Plugin privilege escalation
18095| [87706] Apache Qpid Java up to 6.0.2 AMQP privilege escalation
18096| [87703] Apache Qbid Java up to 6.0.2 PlainSaslServer.java denial of service
18097| [87702] Apache ActiveMQ up to 5.13.x Fileserver Web Application Upload privilege escalation
18098| [87700] Apache PDFbox up to 1.8.11/2.0.0 XML Parser PDF Document XML External Entity
18099| [87679] HP Release Control 9.13/9.20/9.21 Apache Commons Collections Library Java Object privilege escalation
18100| [87540] Apache Ambari up to 2.2.0 File Browser View information disclosure
18101| [87433] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
18102| [87432] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
18103| [87431] Apple Mac OS X up to 10.11.4 apache_mod_php Format String
18104| [87430] Apple Mac OS X up to 10.11.4 apache_mod_php denial of service
18105| [87429] Apple Mac OS X up to 10.11.4 apache_mod_php information disclosure
18106| [87428] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
18107| [87427] Apple Mac OS X up to 10.11.4 apache_mod_php memory corruption
18108| [87389] Apache Xerces C++ up to 3.1.3 XML Document DTDScanner.cpp memory corruption
18109| [87172] Adobe ColdFusion 11 Update 7/2016/up to 10 Update 18 Apache Commons Collections Library privilege escalation
18110| [87121] Apache Cordova iOS up to 3.x Plugin privilege escalation
18111| [87120] Apache Cordova iOS up to 3.x URL Whitelist privilege escalation
18112| [83806] HPE Network Node Manager i up to 10.01 Apache Commons Collections Library privilege escalation
18113| [83077] Apache Subversion up to 1.8.15/1.9.3 mod_authz_svn mod_authz_svn.c denial of service
18114| [83076] Apache Subversion up to 1.8.15/1.9.3 svnserve svnserve/cyrus_auth.c privilege escalation
18115| [82790] Apache Struts 2.0.0/2.3.24/2.3.28 Dynamic Method privilege escalation
18116| [82789] Apache Struts 2.0.0/2.3.24/2.3.28 XSLTResult privilege escalation
18117| [82725] HPE P9000 Command View up to 7.x/8.4.0 Apache Commons Collections Library privilege escalation
18118| [82444] Apache Camel up to 2.14.x/2.15.4/2.16.0 HTTP Request privilege escalation
18119| [82389] Apache Subversion up to 1.7.x/1.8.14/1.9.2 mod_dav_svn util.c memory corruption
18120| [82280] Apache Struts up to 1.7 JRE URLDecoder cross site scripting
18121| [82260] Apache OFBiz up to 12.04.05/13.07.02 Java Object privilege escalation
18122| [82259] Apache Qpid Proton up to 0.12.0 proton.reactor.Connector weak encryption
18123| [82250] Apache Ranger up to 0.5.0 Admin UI weak authentication
18124| [82214] Apache Wicket up to 1.5.14/6.21.x/7.1.x Input Element cross site scripting
18125| [82213] Apache Wicket up to 1.5.14/6.21.x/7.1.x ModalWindow Title getWindowOpenJavaScript cross site scripting
18126| [82212] Apache Ranger up to 0.5.0 Policy Admin Tool privilege escalation
18127| [82211] Apache OFBiz up to 12.04.06/13.07.02 ModelFormField.java DisplayEntityField.getDescription cross site scripting
18128| [82082] Apache JetSpeed up to 2.3.0 User Manager Service privilege escalation
18129| [82081] Apache OpenMeetings up to 3.1.0 SOAP API information disclosure
18130| [82080] Apache OpenMeetings up to 3.1.0 Event cross site scripting
18131| [82078] Apache OpenMeetings up to 3.1.0 Import/Export System Backup ZIP Archive directory traversal
18132| [82077] Apache OpenMeetings up to 3.1.0 Password Reset sendHashByUser privilege escalation
18133| [82076] Apache Ranger up to 0.5.1 privilege escalation
18134| [82075] Apache JetSpeed up to 2.3.0 Portal cross site scripting
18135| [82074] Apache JetSpeed up to 2.3.0 cross site scripting
18136| [82073] Apache JetSpeed up to 2.3.0 User Manager Service sql injection
18137| [82072] Apache JetSpeed up to 2.3.0 Portal Site Manager ZIP Archive directory traversal
18138| [82058] Apache LDAP Studio/Directory Studio up to 2.0.0-M9 CSV Export privilege escalation
18139| [82053] Apache Ranger up to 0.4.x Policy Admin Tool privilege escalation
18140| [82052] Apache Ranger up to 0.4.x Policy Admin Tool HTTP Request cross site scripting
18141| [81696] Apache ActiveMQ up to 5.13.1 HTTP Header privilege escalation
18142| [81695] Apache Xerces-C up to 3.1.2 internal/XMLReader.cpp memory corruption
18143| [81622] HPE Asset Manager 9.40/9.41/9.50 Apache Commons Collections Library Java Object privilege escalation
18144| [81406] HPE Service Manager up to 9.35 P3/9.41 P1 Apache Commons Collections Library Command privilege escalation
18145| [81405] HPE Operations Orchestration up to 10.50 Apache Commons Collections Library Command privilege escalation
18146| [81427] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
18147| [81426] Apple Mac OS X up to 10.11.3 apache_mod_php PNG File memory corruption
18148| [81372] Apache Struts up to 2.3.24.1 I18NInterceptor cross site scripting
18149| [81371] Apache Struts up to 2.3.24.1 Double OGNL Evaluation privilege escalation
18150| [81370] Apache Struts up to 2.3.24.1 Java URLDecoder cross site scripting
18151| [81084] Apache Tomcat 6.0/7.0/8.0/9.0 ServletContext directory traversal
18152| [81083] Apache Tomcat 7.0/8.0/9.0 Index Page cross site request forgery
18153| [81082] Apache Tomcat 7.0/8.0/9.0 ResourceLinkFactory.setGlobalContext privilege escalation
18154| [81081] Apache Tomcat 6.0/7.0/8.0/9.0 Error information disclosure
18155| [81080] Apache Tomcat 6.0/7.0/8.0/9.0 Session Persistence privilege escalation
18156| [81079] Apache Tomcat 6.0/7.0/8.0/9.0 StatusManagerServlet information disclosure
18157| [81078] Apache Tomcat 7.0/8.0/9.0 Session privilege escalation
18158| [80970] Apache Solr up to 5.3.0 Admin UI plugins.js cross site scripting
18159| [80969] Apache Solr up to 5.2 Schema schema-browser.js cross site scripting
18160| [80968] Apache Solr up to 5.0 analysis.js cross site scripting
18161| [80940] HP Continuous Delivery Automation 1.30 Apache Commons Collections Library privilege escalation
18162| [80823] Apache CloudStack up to 4.5.1 KVM Virtual Machine Migration privilege escalation
18163| [80822] Apache CloudStack up to 4.5.1 API Call information disclosure
18164| [80778] Apache Camel up to 2.15.4/2.16.0 camel-xstream privilege escalation
18165| [80750] HPE Operations Manager 8.x/9.0 on Windows Apache Commons Collections Library privilege escalation
18166| [80724] Apache Hive up to 1.2.1 Authorization Framework privilege escalation
18167| [80577] Oracle Secure Global Desktop 4.63/4.71/5.2 Apache HTTP Server denial of service
18168| [80165] Intel McAfee ePolicy Orchestrator up to 4.6.9/5.0.3/5.3.1 Apache Commons Collections Library privilege escalation
18169| [80116] Apache Subversion up to 1.9.2 svn Protocol libsvn_ra_svn/marshal.c read_string memory corruption
18170| [80115] Apache ActiveMQ up to 5.12.x Broker Service privilege escalation
18171| [80036] IBM Cognos Business Intelligence Apache Commons Collections Library InvokerTransformer privilege escalation
18172| [79873] VMware vCenter Operations/vRealize Orchestrator Apache Commons Collections Library Serialized Java Object privilege escalation
18173| [79840] Apache Cordova File Transfer Plugin up to 1.2.x on Android unknown vulnerability
18174| [79839] Apache TomEE Serialized Java Stream EjbObjectInputStream privilege escalation
18175| [79791] Cisco Products Apache Commons Collections Library privilege escalation
18176| [79539] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
18177| [79538] Apple Mac OS X up to 10.11.1 apache_mod_php memory corruption
18178| [79294] Apache Cordova-Android up to 3.6 BridgeSecret Random Generator weak encryption
18179| [79291] Apache Cordova-Android up to 4.0 Javascript Whitelist privilege escalation
18180| [79244] Apache CXF up to 2.7.17/3.0.7/3.1.2 SAML Web SSO Module SAML Response weak authentication
18181| [79243] Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0 WLS Security com.bea.core.apache.commons.collections.jar privilege escalation
18182| [78989] Apache Ambari up to 2.1.1 Open Redirect
18183| [78988] Apache Ambari up to 2.0.1/2.1.0 Password privilege escalation
18184| [78987] Apache Ambari up to 2.0.x cross site scripting
18185| [78986] Apache Ambari up to 2.0.x Proxy Endpoint api/v1/proxy privilege escalation
18186| [78780] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
18187| [78779] Apple Mac OS X up to 10.11.0 apache_mod_php denial of service
18188| [78778] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
18189| [78777] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
18190| [78776] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
18191| [78775] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
18192| [78774] Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption
18193| [78297] Apache Commons Components HttpClient up to 4.3.5 HTTPS Timeout denial of service
18194| [77406] Apache Flex BlazeDS AMF Message XML External Entity
18195| [77429] Apache ActiveMQ up to 5.10.0 LDAPLoginModule privilege escalation
18196| [77399] Apache ActiveMQ up to 5.10.0 LDAPLoginModule weak authentication
18197| [77375] Apache Tapestry up to 5.3.5 Client-Side Object Storage privilege escalation
18198| [77331] Apache ActiveMQ up to 5.11.1 on Windows Fileserver Upload/Download directory traversal
18199| [77299] Apache Solr Real-Time Module up to 7.x-1.1 Index Content information disclosure
18200| [77247] Apache ActiveMQ up to 5.10 TransportConnection.java processControlCommand denial of service
18201| [77083] Apache Groovy up to 2.4.3 MethodClosure.java MethodClosure memory corruption
18202| [76953] Apache Subversion 1.7.0/1.8.0/1.8.10 svn_repos_trace_node_locations information disclosure
18203| [76952] Apache Subversion 1.7.0/1.8.0/1.8.10 mod_authz_svn anonymous/authenticated information disclosure
18204| [76567] Apache Struts 2.3.20 unknown vulnerability
18205| [76733] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 ap_some_auth_required unknown vulnerability
18206| [76732] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 Request apr_brigade_flatten privilege escalation
18207| [76731] Apache HTTP Server 2.4.12 ErrorDocument 400 Crash denial of service
18208| [75690] Apache Camel up to 2.13.3/2.14.1 XPathBuilder.java XML External Entity
18209| [75689] Apache Camel up to 2.13.3/2.14.1 XML Converter Setup XmlConverter.java SAXSource privilege escalation
18210| [75668] Apache Sling API/Sling Servlets Post up to 2.2.1 HtmlResponse cross site scripting
18211| [75601] Apache Jackrabbit up to 2.10.0 WebDAV Request XML External Entity
18212| [75420] Apache Tomcat up to 6.0.43/7.0.58/8.0.16 Security Manager privilege escalation
18213| [75145] Apache OpenOffice up to 4.1.1 HWP Filter Crash denial of service
18214| [75032] Apache Tomcat Connectors up to 1.2.40 mod_jk privilege escalation
18215| [75135] PHP 5.4/5.5 HTTP Request sapi_apache2.c apache2handler privilege escalation
18216| [74793] Apache Tomcat File Upload denial of service
18217| [74708] Apple MacOS X up to 10.10.2 Apache denial of service
18218| [74707] Apple MacOS X up to 10.10.2 Apache denial of service
18219| [74706] Apple MacOS X up to 10.10.2 Apache memory corruption
18220| [74705] Apple MacOS X up to 10.10.2 Apache denial of service
18221| [74704] Apple MacOS X up to 10.10.2 Apache denial of service
18222| [74703] Apple MacOS X up to 10.10.2 Apache denial of service
18223| [74702] Apple MacOS X up to 10.10.2 Apache denial of service
18224| [74701] Apple MacOS X up to 10.10.2 Apache cross site request forgery
18225| [74700] Apple MacOS X up to 10.10.2 Apache unknown vulnerability
18226| [74661] Apache Flex up to 4.14.0 asdoc index.html cross site scripting
18227| [74609] Apache Cassandra up to 1.2.19/2.0.13/2.1.3 JMX/RMI Interface privilege escalation
18228| [74469] Apache Xerces-C up to 7.0 internal/XMLReader.cpp denial of service
18229| [74468] Apache Batik up to 1.6 denial of service
18230| [74414] Apache Mod-gnutls up to 0.5.1 Authentication spoofing
18231| [74371] Apache Standard Taglibs up to 1.2.0 memory corruption
18232| [74367] Apache HTTP Server up to 2.4.12 mod_lua lua_request.c wsupgrade denial of service
18233| [74174] Apache WSS4J up to 2.0.0 privilege escalation
18234| [74172] Apache ActiveMQ up to 5.5.0 Administration Console cross site scripting
18235| [69092] Apache Tomcat up to 6.0.42/7.0.54/8.0.8 HTTP Request Smuggling privilege escalation
18236| [73831] Apache Qpid up to 0.30 Access Restriction unknown vulnerability
18237| [73731] Apache XML Security unknown vulnerability
18238| [68660] Oracle BI Publisher 10.1.3.4.2/11.1.1.7 Apache Tomcat cross site scripting
18239| [73659] Apache CloudStack up to 4.3.0 Stack-Based unknown vulnerability
18240| [73593] Apache Traffic Server up to 5.1.0 denial of service
18241| [73511] Apache POI up to 3.10 Deadlock denial of service
18242| [73510] Apache Solr up to 4.3.0 cross site scripting
18243| [68447] Apache Subversion up to 1.7.18/1.8.10 mod_dav_svn Crash denial of service
18244| [68446] Apache Subversion up to 1.7.18/1.8.10 REPORT Request Crash denial of service
18245| [73173] Apache CloudStack Stack-Based unknown vulnerability
18246| [68357] Apache Struts up to 2.3.16.3 Random Number Generator cross site request forgery
18247| [73106] Apache Hadoop up to 2.4.0 Symlink privilege escalation
18248| [68575] Apache HTTP Server up to 2.4.10 LuaAuthzProvider mod_lua.c privilege escalation
18249| [72890] Apache Qpid 0.30 unknown vulnerability
18250| [72887] Apache Hive 0.13.0 File Permission privilege escalation
18251| [72878] Apache Cordova 3.5.0 cross site request forgery
18252| [72877] Apache Cordova 3.5.0 cross site request forgery
18253| [72876] Apache Cordova 3.5.0 cross site request forgery
18254| [68435] Apache HTTP Server 2.4.10 mod_proxy_fcgi.c handle_headers denial of service
18255| [68065] Apache CXF up to 3.0.1 JAX-RS SAML denial of service
18256| [68064] Apache CXF up to 3.0.0 SAML Token denial of service
18257| [67913] Oracle Retail Markdown Optimization 12.0/13.0/13.1/13.2/13.4 Apache commons-beanutils-1.8.0.jar memory corruption
18258| [67912] Oracle Retail Invoice Matching up to 14.0 Apache commons-beanutils-1.8.0.jar memory corruption
18259| [67911] Oracle Retail Clearance Optimization Engine 13.3/13.4/14.0 Apache commons-beanutils-1.8.0.jar memory corruption
18260| [67910] Oracle Retail Allocation up to 13.2 Apache commons-beanutils-1.8.0.jar memory corruption
18261| [71835] Apache Shiro 1.0.0/1.1.0/1.2.0/1.2.1/1.2.2 unknown vulnerability
18262| [71633] Apachefriends XAMPP 1.8.1 cross site scripting
18263| [71629] Apache Axis2/C spoofing
18264| [67633] Apple Mac OS X up to 10.9.4 apache_mod_php ext/standard/dns.c dns_get_record memory corruption
18265| [67631] Apple Mac OS X up to 10.9.4 apache_mod_php Symlink memory corruption
18266| [67630] Apple Mac OS X up to 10.9.4 apache_mod_php cdf_read_property_info denial of service
18267| [67629] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_count_chain denial of service
18268| [67628] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_check_stream_offset denial of service
18269| [67627] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c mconvert memory corruption
18270| [67626] Apple Mac OS X up to 10.9.4 apache_mod_php softmagic.c denial of service
18271| [67625] Apple Mac OS X up to 10.9.4 apache_mod_php Crash denial of service
18272| [67624] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_property_info denial of service
18273| [67623] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_unpack_summary_info denial of service
18274| [67622] Apple Mac OS X up to 10.9.4 apache_mod_php cdf.c cdf_read_short_sector denial of service
18275| [67620] Apple Mac OS X up to 10.9.4 apache_mod_php magic/Magdir/commands denial of service
18276| [67790] Apache HTTP Server mod_cache NULL Pointer Dereference denial of service
18277| [67522] Apache Tomcat up to 7.0.39 JSP Upload privilege escalation
18278| [70809] Apache POI up to 3.11 Crash denial of service
18279| [70808] Apache POI up to 3.10 unknown vulnerability
18280| [70806] Apache Commons-httpclient 4.2/4.2.1/4.2.2 spoofing
18281| [70749] Apache Axis up to 1.4 getCN spoofing
18282| [70701] Apache Traffic Server up to 3.3.5 denial of service
18283| [70700] Apache OFBiz up to 12.04.03 cross site scripting
18284| [67402] Apache OpenOffice 4.0.0/4.0.1/4.1.0 Calc privilege escalation
18285| [67401] Apache OpenOffice up to 4.1.0 OLE Object information disclosure
18286| [70661] Apache Subversion up to 1.6.17 denial of service
18287| [70660] Apache Subversion up to 1.6.17 spoofing
18288| [70659] Apache Subversion up to 1.6.17 spoofing
18289| [67183] Apache HTTP Server up to 2.4.9 mod_proxy denial of service
18290| [67180] Apache HTTP Server up to 2.4.9 WinNT MPM Memory Leak denial of service
18291| [67185] Apache HTTP Server up to 2.4.9 mod_status Heap-Based memory corruption
18292| [67184] Apache HTTP Server 2.4.5/2.4.6 mod_cache NULL Pointer Dereference denial of service
18293| [67182] Apache HTTP Server up to 2.4.9 mod_deflate Memory Consumption denial of service
18294| [67181] Apache HTTP Server up to 2.4.9 mod_cgid denial of service
18295| [70338] Apache Syncope up to 1.1.7 unknown vulnerability
18296| [70295] Apache CXF up to 2.7.9 Cleartext information disclosure
18297| [70106] Apache Open For Business Project up to 10.04.0 getServerError cross site scripting
18298| [70105] Apache MyFaces up to 2.1.5 JavaServer Faces directory traversal
18299| [69846] Apache HBase up to 0.94.8 information disclosure
18300| [69783] Apache CouchDB up to 1.2.0 memory corruption
18301| [13383] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 XML Parser privilege escalation
18302| [13300] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi setuid privilege escalation
18303| [13299] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi Content-Type Header information disclosure
18304| [13164] Apache CXF up to 2.6.13/2.7.10 SOAP OutgoingChainInterceptor.java Invalid Content denial of service
18305| [13163] Apache CXF up to 2.6.13/2.7.10 SOAP HTML Content denial of service
18306| [13158] Apache Struts up to 2.3.16.2 ParametersInterceptor getClass privilege escalation
18307| [69515] Apache Struts up to 2.3.15.0 CookieInterceptor memory corruption
18308| [13086] Apache Struts up to 1.3.10 Class Loader privilege escalation
18309| [13067] Apache Struts up to 2.3.16.1 Class Loader privilege escalation
18310| [69431] Apache Archiva up to 1.3.6 cross site scripting
18311| [69385] Apache Syncope up to 1.1.6 unknown vulnerability
18312| [69338] Apache Xalan-Java up to 2.7.1 system-property unknown vulnerability
18313| [12742] Trustwave ModSecurity up to 2.7.5 Chunk Extension apache2/modsecurity.c modsecurity_tx_init privilege escalation
18314| [12741] Trustwave ModSecurity up to 2.7.6 Chunked HTTP Transfer apache2/modsecurity.c modsecurity_tx_init Trailing Header privilege escalation
18315| [13387] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Content-Length Header privilege escalation
18316| [13386] Apache Tomcat Security Manager up to 6.0.39/7.0.53/8.0.5 XSLT privilege escalation
18317| [13385] Apache Tomcat 8.0.0/8.0.1/8.0.3 AJP Request Zero Length denial of service
18318| [13384] Apache Tomcat up to 6.0.39/7.0.53/8.0.5 Chunked HTTP Request denial of service
18319| [12748] Apache CouchDB 1.5.0 UUIDS /_uuids denial of service
18320| [66739] Apache Camel up to 2.12.2 unknown vulnerability
18321| [66738] Apache Camel up to 2.12.2 unknown vulnerability
18322| [12667] Apache HTTP Server 2.4.7 mod_log_config.c log_cookie denial of service
18323| [66695] Apache CouchDB up to 1.2.0 cross site scripting
18324| [66694] Apache CouchDB up to 1.2.0 Partition partition2 directory traversal
18325| [66689] Apache HTTP Server up to 2.0.33 mod_dav dav_xml_get_cdata denial of service
18326| [12518] Apache Tomcat up to 6.0.38/7.0.49/8.0.0-RC9 HTTP Header denial of service
18327| [66498] Apache expressions up to 3.3.0 Whitelist unknown vulnerability
18328| [12781] Apache Struts up to 2.3.8 ParametersInterceptor getClass denial of service
18329| [12439] Apache Tomcat 6.0.33 XML XXE information disclosure
18330| [12438] Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37 coyoteadapter.java disableURLRewriting privilege escalation
18331| [66356] Apache Wicket up to 6.8.0 information disclosure
18332| [12209] Apache Tomcat 7.0.0/7.0.50/8.0.0-RC1/8.0.1 Content-Type Header for Multi-Part Request Infinite Loop denial of service
18333| [66322] Apache ActiveMQ up to 5.8.0 cross site scripting
18334| [12291] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
18335| [66255] Apache Open For Business Project up to 10.04.3 cross site scripting
18336| [66200] Apache Hadoop up to 2.0.5 Security Feature information disclosure
18337| [66072] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
18338| [66068] Apache CloudStack up to 4.2.0 Stack-Based unknown vulnerability
18339| [11928] Oracle Secure Global Desktop up to 4.71 Apache Tomcat unknown vulnerability
18340| [11924] Oracle Secure Global Desktop up to 4.63 Apache Tomcat denial of service
18341| [11922] Oracle Secure Global Desktop up to 4.63 Apache Tomcat unknown vulnerability
18342| [66049] Apache XML Security for Java up to 1.4.6 Memory Consumption denial of service
18343| [12199] Apache Subversion up to 1.8.5 mod_dav_svn/repos.c get_resource denial of service
18344| [65946] askapache Firefox Adsense up to 3.0 askapache-firefox-adsense.php cross site request forgery
18345| [65668] Apache Solr 4.0.0 Updater denial of service
18346| [65665] Apache Solr up to 4.3.0 denial of service
18347| [65664] Apache Solr 3.6.0/3.6.1/3.6.2/4.0.0 Updater denial of service
18348| [65663] Apache Solr up to 4.5.1 ResourceLoader directory traversal
18349| [65658] Apache roller 4.0/4.0.1/5.0/5.0.1 unknown vulnerability
18350| [65657] Apache Roller 4.0/4.0.1/5.0/5.0.1 cross site scripting
18351| [11325] Apache Subversion 1.7.13 mod_dontdothat Bypass denial of service
18352| [11324] Apache Subversion up to 1.8.4 mod_dav_svn denial of service
18353| [11098] Apache Tomcat 5.5.25 HTTP Request cross site request forgery
18354| [65410] Apache Struts 2.3.15.3 cross site scripting
18355| [65386] Apache Solr up to 2.2.1 on TYPO3 cross site scripting
18356| [65385] Apache Solr up to 2.2.1 on TYPO3 unknown vulnerability
18357| [11044] Apache Struts 2.3.15.3 showConfig.action cross site scripting
18358| [11043] Apache Struts 2.3.15.3 actionNames.action cross site scripting
18359| [11018] cPanel WHM up to 11.40.0.11 Apache mod_userdir Tweak Interface privilege escalation
18360| [65342] Apache Sling 1.0.2/1.0.4/1.0.6/1.1.0/1.1.2 Auth Core cross site scripting
18361| [65340] Apache Shindig 2.5.0 information disclosure
18362| [65316] Apache Mod Fcgid up to 2.3.7 mod_fcgid fcgid_bucket.c fcgid_header_bucket_read memory corruption
18363| [65313] Apache Sling 2.2.0/2.3.0 AbstractCreateOperation.java deepGetOrCreateNode denial of service
18364| [10826] Apache Struts 2 File privilege escalation
18365| [65204] Apache Camel up to 2.10.1 unknown vulnerability
18366| [10460] Apache Struts 2.0.0/2.3.15.1 Action Mapping Mechanism Bypass privilege escalation
18367| [10459] Apache Struts 2.0.0/2.3.15 Dynamic Method Invocation unknown vulnerability
18368| [10160] Apache Subversion 1.8.0/1.8.1/1.8.2 svnwcsub.py handle_options race condition
18369| [10159] Apache Subversion up to 1.8.2 svnserve write_pid_file race condition
18370| [10158] Apache Subversion 1.8.0/1.8.1/1.8.2 daemonize.py daemon::daemonize race condition
18371| [10157] Apache Subversion up to 1.8.1 FSFS Repository Symlink privilege escalation
18372| [64808] Fail2ban up to 0.8.9 apache-auth.conf denial of service
18373| [64760] Best Practical RT up to 4.0.12 Apache::Session::File information disclosure
18374| [64722] Apache XML Security for C++ Heap-based memory corruption
18375| [64719] Apache XML Security for C++ Heap-based memory corruption
18376| [64718] Apache XML Security for C++ verify denial of service
18377| [64717] Apache XML Security for C++ getURIBaseTXFM memory corruption
18378| [64716] Apache XML Security for C++ spoofing
18379| [64701] Apache CXF up to 2.7.3 XML Parser Memory Consumption denial of service
18380| [64700] Apache CloudStack up to 4.1.0 Stack-Based cross site scripting
18381| [64667] Apache Open For Business Project up to 10.04.04 unknown vulnerability
18382| [64666] Apache Open For Business Project up to 10.04.04 cross site scripting
18383| [9891] Apache HTTP Server 2.2.22 suEXEC Feature .htaccess information disclosure
18384| [64509] Apache ActiveMQ up to 5.8.0 scheduled.jsp cross site scripting
18385| [9826] Apache Subversion up to 1.8.0 mod_dav_svn denial of service
18386| [9683] Apache HTTP Server 2.4.5 mod_session_dbd denial of service
18387| [64485] Apache Struts up to 2.2.3.0 privilege escalation
18388| [9568] Apache Struts up to 2.3.15 DefaultActionMapper cross site request forgery
18389| [9567] Apache Struts up to 2.3.15 DefaultActionMapper memory corruption
18390| [64467] Apache Geronimo 3.0 memory corruption
18391| [64466] Apache OpenJPA up to 2.2.1 Serialization memory corruption
18392| [64457] Apache Struts up to 2.2.3.0 cross site scripting
18393| [64326] Alejandro Garza Apachesolr Autocomplete up to 7.x-1.1 cross site scripting
18394| [9184] Apache Qpid up to 0.20 SSL misconfiguration
18395| [8935] Apache Subversion up to 1.7.9 FSFS Format Repository denial of service
18396| [8934] Apache Subversion up to 1.7.9 Svnserve Server denial of service
18397| [8933] Apache Subversion up to 1.6.21 check-mime-type.pl svnlook memory corruption
18398| [8932] Apache Subversion up to 1.6.21 svn-keyword-check.pl svnlook changed memory corruption
18399| [9022] Apache Struts up to 2.3.14.2 OGNL Expression memory corruption
18400| [8873] Apache Struts 2.3.14 privilege escalation
18401| [8872] Apache Struts 2.3.14 privilege escalation
18402| [8746] Apache HTTP Server Log File Terminal Escape Sequence Filtering mod_rewrite.c do_rewritelog privilege escalation
18403| [8666] Apache Tomcat up to 7.0.32 AsyncListener information disclosure
18404| [8665] Apache Tomcat up to 7.0.29 Chunked Transfer Encoding Extension Size denial of service
18405| [8664] Apache Tomcat up to 7.0.32 FORM Authentication weak authentication
18406| [64075] Apache Subversion up to 1.7.7 mod_dav_svn Crash denial of service
18407| [64074] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
18408| [64073] Apache Subversion up to 1.7.8 mod_dav_svn NULL Pointer Dereference denial of service
18409| [64072] Apache Subversion up to 1.7.7 mod_dav_svn NULL Pointer Dereference denial of service
18410| [64071] Apache Subversion up to 1.7.8 mod_dav_svn Memory Consumption denial of service
18411| [8768] Apache Struts up to 2.3.14 on Mac EL and OGNL Interpreter memory corruption
18412| [64006] Apache ActiveMQ up to 5.7.0 denial of service
18413| [64005] Apache ActiveMQ up to 5.7.0 Default Configuration denial of service
18414| [64004] Apache ActiveMQ up to 5.7.0 PortfolioPublishServlet.java cross site scripting
18415| [8427] Apache Tomcat Session Transaction weak authentication
18416| [63960] Apache Maven 3.0.4 Default Configuration spoofing
18417| [63751] Apache qpid up to 0.20 qpid::framing::Buffer denial of service
18418| [63750] Apache qpid up to 0.20 checkAvailable denial of service
18419| [63749] Apache Qpid up to 0.20 Memory Consumption denial of service
18420| [63748] Apache Qpid up to 0.20 Default Configuration denial of service
18421| [63747] Apache Rave up to 0.20 User Account information disclosure
18422| [7889] Apache Subversion up to 1.6.17 mod_dav_svn/svn_fs_file_length() denial of service
18423| [63646] Apache HTTP Server up to 2.2.23/2.4.3 mod_proxy_balancer.c balancer_handler cross site scripting
18424| [7688] Apache CXF up to 2.7.1 WSS4JInterceptor Bypass weak authentication
18425| [7687] Apache CXF up to 2.7.2 Token weak authentication
18426| [63334] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
18427| [63299] Apache CXF up to 2.6.0 WS-Security unknown vulnerability
18428| [7202] Apache HTTP Server 2.4.2 on Oracle Solaris ld_library_path cross site scripting
18429| [7075] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector NioEndpoint.java denial of service
18430| [7074] Apache Tomcat up to 6.0.35/7.0.29 FORM Authentication RealmBase.java weak authentication
18431| [7073] Apache Tomcat up to 6.0.35/7.0.31 CSRF Prevention Filter cross site request forgery
18432| [63090] Apache Tomcat up to 4.1.24 denial of service
18433| [63089] Apache HTTP Server up to 2.2.13 mod_proxy_ajp denial of service
18434| [62933] Apache Tomcat up to 5.5.0 Access Restriction unknown vulnerability
18435| [62929] Apache Tomcat up to 6.0.35/7.0.27 NIO Connector Memory Consumption denial of service
18436| [62833] Apache CXF -/2.6.0 spoofing
18437| [62832] Apache Axis2 up to 1.6.2 spoofing
18438| [62831] Apache Axis up to 1.4 Java Message Service spoofing
18439| [62830] Apache Commons-httpclient 3.0 Payments spoofing
18440| [62826] Apache Libcloud up to 0.11.0 spoofing
18441| [62757] Apache Open For Business Project up to 10.04.0 unknown vulnerability
18442| [8830] Red Hat JBoss Enterprise Application Platform 6.0.1 org.apache.catalina.connector.Response.encodeURL information disclosure
18443| [62661] Apache Axis2 unknown vulnerability
18444| [62658] Apache Axis2 unknown vulnerability
18445| [62467] Apache Qpid up to 0.17 denial of service
18446| [62417] Apache CXF 2.4.7/2.4.8/2.5.3/2.5.4/2.6.1 spoofing
18447| [6301] Apache HTTP Server mod_pagespeed cross site scripting
18448| [6300] Apache HTTP Server mod_pagespeed Hostname information disclosure
18449| [6123] Apache Wicket up to 1.5.7 Ajax Link cross site scripting
18450| [62035] Apache Struts up to 2.3.4 denial of service
18451| [61916] Apache QPID 0.5/0.6/0.14/0.16 unknown vulnerability
18452| [6998] Apache Tomcat 5.5.35/6.0.35/7.0.28 DIGEST Authentication Session State Caching privilege escalation
18453| [6997] Apache Tomcat 5.5.35/6.0.35/7.0.28 HTTP Digest Authentication Implementation privilege escalation
18454| [6092] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_ajp.c information disclosure
18455| [6090] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_http.c information disclosure
18456| [61507] Apache POI up to 3.8 UnhandledDataStructure denial of service
18457| [6070] Apache Struts up to 2.3.4 Token Name Configuration Parameter privilege escalation
18458| [6069] Apache Struts up to 2.3.4 Request Parameter OGNL Expression denial of service
18459| [5764] Oracle Solaris 10 Apache HTTP Server information disclosure
18460| [5700] Oracle Secure Backup 10.3.0.3/10.4.0.1 Apache denial of service
18461| [61255] Apache Hadoop 2.0.0 Kerberos unknown vulnerability
18462| [61229] Apache Sling up to 2.1.1 denial of service
18463| [61152] Apache Commons-compress 1.0/1.1/1.2/1.3/1.4 denial of service
18464| [61094] Apache Roller up to 5.0 cross site scripting
18465| [61093] Apache Roller up to 5.0 cross site request forgery
18466| [61005] Apache OpenOffice 3.3/3.4 unknown vulnerability
18467| [9673] Apache HTTP Server up to 2.4.4 mod_dav mod_dav.c Request denial of service
18468| [5436] Apache OpenOffice 3.3/3.4 WPXContentListener.cpp _closeTableRow File memory corruption
18469| [5435] Apache OpenOffice 3.3/3.4 vclmi.dll File memory corruption
18470| [60730] PHP 5.4.0/5.4.1/5.4.2 apache_request_headers memory corruption
18471| [60708] Apache Qpid 0.12 unknown vulnerability
18472| [5032] Apache Hadoop up to 0.20.205.0/1.0.1/0.23.1 Kerberos/MapReduce Security Feature privilege escalation
18473| [4949] Apache Struts File Upload XSLTResult.java XSLT File privilege escalation
18474| [4955] Apache Traffic Server 3.0.3/3.1.2 HTTP Header Parser memory corruption
18475| [4882] Apache Wicket up to 1.5.4 directory traversal
18476| [4881] Apache Wicket up to 1.4.19 cross site scripting
18477| [4884] Apache HTTP Server up to 2.3.6 mod_fcgid fcgid_spawn_ctl.c FcgidMaxProcessesPerClass HTTP Requests denial of service
18478| [60352] Apache Struts up to 2.2.3 memory corruption
18479| [60153] Apache Portable Runtime up to 1.4.3 denial of service
18480| [4598] Apache Struts 1.3.10 upload-submit.do cross site scripting
18481| [4597] Apache Struts 1.3.10 processSimple.do cross site scripting
18482| [4596] Apache Struts 2.0.14/2.2.3 struts2-rest-showcase/orders cross site scripting
18483| [4595] Apache Struts 2.0.14/2.2.3 struts2-showcase/person/editPerson.action cross site scripting
18484| [4583] Apache HTTP Server up to 2.2.21 Threaded MPM denial of service
18485| [4582] Apache HTTP Server up to 2.2.21 protocol.c information disclosure
18486| [4571] Apache Struts up to 2.3.1.2 privilege escalation
18487| [4557] Apache Tomcat up to 7.0.21 Caching/Recycling information disclosure
18488| [59934] Apache Tomcat up to 6.0.9 DigestAuthenticator.java unknown vulnerability
18489| [59933] Apache Tomcat up to 6.0.9 Access Restriction unknown vulnerability
18490| [59932] Apache Tomcat up to 6.0.9 unknown vulnerability
18491| [59931] Apache Tomcat up to 6.0.9 Access Restriction information disclosure
18492| [59902] Apache Struts up to 2.2.3 Interfaces unknown vulnerability
18493| [4528] Apache Struts up to 2.2.3 DebuggingInterceptor privilege escalation
18494| [4527] Apache Struts up to 2.2.3 ExceptionDelegator cross site scripting
18495| [59888] Apache Tomcat up to 6.0.6 denial of service
18496| [59886] Apache ActiveMQ up to 5.5.1 Crash denial of service
18497| [4513] Apache Struts up to 2.3.1 ParameterInterceptor directory traversal
18498| [4512] Apache Struts up to 2.2.3 CookieInterceptor privilege escalation
18499| [59850] Apache Geronimo up to 2.2.1 denial of service
18500| [59825] Apache HTTP Server up to 2.1.7 mod_reqtimeout denial of service
18501| [59556] Apache HTTP Server up to 2.0.53 mod_proxy information disclosure
18502| [58467] Apache libcloud 0.2.0/0.3.0/0.3.1/0.4.0 Access Restriction spoofing
18503| [58413] Apache Tomcat up to 6.0.10 spoofing
18504| [58381] Apache Wicket up to 1.4.17 cross site scripting
18505| [58296] Apache Tomcat up to 7.0.19 unknown vulnerability
18506| [57888] Apache HttpClient 4.0/4.0.1/4.1 Authorization information disclosure
18507| [57587] Apache Subversion up to 1.6.16 mod_dav_svn information disclosure
18508| [57585] Apache Subversion up to 1.6.16 mod_dav_svn Memory Consumption denial of service
18509| [57584] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
18510| [57577] Apache Rampart-C 1.3.0 Access Restriction rampart_timestamp_token_validate privilege escalation
18511| [57568] Apache Archiva up to 1.3.4 cross site scripting
18512| [57567] Apache Archiva up to 1.3.4 cross site request forgery
18513| [57481] Apache Tomcat 7.0.12/7.0.13 Access Restriction unknown vulnerability
18514| [4355] Apache HTTP Server APR apr_fnmatch denial of service
18515| [57435] Apache Struts up to 2.2.1.1 FileHandler.java cross site scripting
18516| [57425] Apache Struts up to 2.2.1.1 cross site scripting
18517| [4352] Apache HTTP Server 2.2.x APR apr_fnmatch denial of service
18518| [57025] Apache Tomcat up to 7.0.11 information disclosure
18519| [57024] Apache Tomcat 7.0.11 Access Restriction information disclosure
18520| [56774] IBM WebSphere Application Server up to 7.0.0.14 org.apache.jasper.runtime.JspWriterImpl.response denial of service
18521| [56824] Apache Subversion up to 1.6.4 mod_dav_svn NULL Pointer Dereference denial of service
18522| [56832] Apache Tomcat up to 7.0.10 Access Restriction information disclosure
18523| [56830] Apache Tomcat up to 7.0.9 Access Restriction privilege escalation
18524| [12440] Apache Tomcat 6.0.33 Malicious Request cross site scripting
18525| [56512] Apache Continuum up to 1.4.0 cross site scripting
18526| [4285] Apache Tomcat 5.x JVM getLocale denial of service
18527| [4284] Apache Tomcat 5.x HTML Manager Infinite Loop cross site scripting
18528| [4283] Apache Tomcat 5.x ServletContect privilege escalation
18529| [56441] Apache Tomcat up to 7.0.6 denial of service
18530| [56300] Apache CouchDB up to 1.0.1 Web Administration Interface cross site scripting
18531| [55967] Apache Subversion up to 1.6.4 rev_hunt.c denial of service
18532| [55966] Apache Subversion up to 1.6.4 mod_dav_svn repos.c walk denial of service
18533| [55095] Apache Axis2 up to 1.6 Default Password memory corruption
18534| [55631] Apache Archiva up to 1.3.1 User Account cross site request forgery
18535| [55556] Apache Tomcat up to 6.0.29 Default Configuration information disclosure
18536| [55553] Apache Tomcat up to 7.0.4 sessionsList.jsp cross site scripting
18537| [55162] Apache MyFaces up to 2.0.0 Authentication Code unknown vulnerability
18538| [54881] Apache Subversion up to 1.6.12 mod_dav_svn authz.c privilege escalation
18539| [54879] Apache APR-util up to 0.9.14 mod_reqtimeout apr_brigade_split_line denial of service
18540| [54693] Apache Traffic Server DNS Cache unknown vulnerability
18541| [54416] Apache CouchDB up to 0.11.0 cross site request forgery
18542| [54394] Apache CXF up to 2.2.8 Memory Consumption denial of service
18543| [54261] Apache Tomcat jsp/cal/cal2.jsp cross site scripting
18544| [54166] Apache HTTP Server up to 2.2.12 mod_cache Crash denial of service
18545| [54385] Apache Struts up to 2.1.8.1 ParameterInterceptor unknown vulnerability
18546| [54012] Apache Tomcat up to 6.0.10 denial of service
18547| [53763] Apache Axis2 1.3/1.4/1.4.1/1.5/1.5.1 Memory Consumption denial of service
18548| [53368] Apache MyFaces 1.1.7/1.2.8 cross site scripting
18549| [53397] Apache axis2 1.4.1/1.5.1 Administration Console cross site scripting
18550| [52894] Apache Tomcat up to 6.0.7 information disclosure
18551| [52960] Apache ActiveMQ up to 5.4-snapshot information disclosure
18552| [52843] Apache HTTP Server mod_auth_shadow unknown vulnerability
18553| [52786] Apache Open For Business Project up to 09.04 cross site scripting
18554| [52587] Apache ActiveMQ up to 5.3.0 cross site request forgery
18555| [52586] Apache ActiveMQ up to 5.3.0 cross site scripting
18556| [52584] Apache CouchDB up to 0.10.1 information disclosure
18557| [51757] Apache HTTP Server 2.0.44 cross site scripting
18558| [51756] Apache HTTP Server 2.0.44 spoofing
18559| [51717] Apache HTTP Server up to 1.3.3 mod_proxy ap_proxy_send_fb memory corruption
18560| [51690] Apache Tomcat up to 6.0 directory traversal
18561| [51689] Apache Tomcat up to 6.0 information disclosure
18562| [51688] Apache Tomcat up to 6.0 directory traversal
18563| [50886] HP Operations Manager 8.10 on Windows File Upload org.apache.catalina.manager.HTMLManagerServlet memory corruption
18564| [50802] Apache Tomcat up to 3.3 Default Password weak authentication
18565| [50626] Apache Solr 1.0.0 cross site scripting
18566| [49857] Apache HTTP Server mod_proxy_ftp cross site scripting
18567| [49856] Apache HTTP Server 2.2.13 mod_proxy_ftp ap_proxy_ftp_handler denial of service
18568| [49348] Apache Xerces-C++ 2.7.0 Stack-Based denial of service
18569| [86789] Apache Portable Runtime memory/unix/apr_pools.c unknown vulnerability
18570| [49283] Apache APR-util up to 1.3.8 apr-util misc/apr_rmm.c apr_rmm_realloc memory corruption
18571| [48952] Apache HTTP Server up to 1.3.6 mod_deflate denial of service
18572| [48626] Apache Tomcat up to 4.1.23 Access Restriction directory traversal
18573| [48431] Apache Tomcat up to 4.1.23 j_security_check cross site scripting
18574| [48430] Apache Tomcat up to 4.1.23 mod_jk denial of service
18575| [47801] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site request forgery
18576| [47800] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console cross site scripting
18577| [47799] Apache Geronimo 2.1/2.1.1/2.1.2/2.1.3 Administration Console directory traversal
18578| [47648] Apache Tiles 2.1.0/2.1.1 cross site scripting
18579| [47640] Apache Struts 2.0.6/2.0.8/2.0.9/2.0.11/2.1 cross site scripting
18580| [47638] Apache Tomcat up to 4.1.23 mod_jk information disclosure
18581| [47636] Apache Struts 2.0.9 xip_client.html cross site scripting
18582| [47593] Apache Mod Perl 1 perl-status Apache::Status cross site scripting
18583| [47637] Apache Struts 1.0.2/1.1/1.2.4/1.2.7/1.2.8 cross site scripting
18584| [47239] Apache Struts up to 2.1.2 Beta struts directory traversal
18585| [47214] Apachefriends xampp 1.6.8 spoofing
18586| [47213] Apachefriends xampp 1.6.8 htaccess cross site request forgery
18587| [47162] Apachefriends XAMPP 1.4.4 weak authentication
18588| [47065] Apache Tomcat 4.1.23 cross site scripting
18589| [46834] Apache Tomcat up to 5.5.20 cross site scripting
18590| [46004] Apache Jackrabbit 1.4/1.5.0 search.jsp cross site scripting
18591| [49205] Apache Roller 2.3/3.0/3.1/4.0 Search cross site scripting
18592| [86625] Apache Struts directory traversal
18593| [44461] Apache Tomcat up to 5.5.0 information disclosure
18594| [44389] Apache Xerces-C++ XML Parser Memory Consumption denial of service
18595| [44352] Apache Friends XAMPP 1.6.8 adodb.php cross site scripting
18596| [43663] Apache Tomcat up to 6.0.16 directory traversal
18597| [43612] Apache Friends XAMPP 1.6.7 iart.php cross site scripting
18598| [43556] Apache HTTP Server up to 2.1.8 mod_proxy_ftp proxy_ftp.c cross site scripting
18599| [43516] Apache Tomcat up to 4.1.20 directory traversal
18600| [43509] Apache Tomcat up to 6.0.13 cross site scripting
18601| [42637] Apache Tomcat up to 6.0.16 cross site scripting
18602| [42325] Apache HTTP Server up to 2.1.8 Error Page cross site scripting
18603| [41838] Apache-SSL 1.3.34 1.57 expandcert privilege escalation
18604| [41091] Apache Software Foundation Mod Jk up to 2.0.1 mod_jk2 Stack-based memory corruption
18605| [40924] Apache Tomcat up to 6.0.15 information disclosure
18606| [40923] Apache Tomcat up to 6.0.15 unknown vulnerability
18607| [40922] Apache Tomcat up to 6.0 information disclosure
18608| [40710] Apache HTTP Server up to 2.0.61 mod_negotiation cross site scripting
18609| [40709] Apache HTTP Server up to 2.0.53 mod_negotiation cross site scripting
18610| [40656] Apache Tomcat 5.5.20 information disclosure
18611| [40503] Apache HTTP Server mod_proxy_ftp cross site scripting
18612| [40502] Apache HTTP Server up to 2.2.5 mod_proxy_balancer memory corruption
18613| [40501] Apache HTTP Server 2.2.6 mod_proxy_balancer cross site request forgery
18614| [40398] Apache HTTP Server up to 2.2 mod_proxy_balancer cross site scripting
18615| [40397] Apache HTTP Server up to 2.2 mod_proxy_balancer balancer_handler denial of service
18616| [40234] Apache Tomcat up to 6.0.15 directory traversal
18617| [40221] Apache HTTP Server 2.2.6 information disclosure
18618| [40027] David Castro Apache Authcas 0.4 sql injection
18619| [3495] Apache OpenOffice up to 2.3 Database Document Processor unknown vulnerability
18620| [3489] Apache HTTP Server 2.x HTTP Header cross site scripting
18621| [3414] Apache Tomcat WebDAV Stored privilege escalation
18622| [39489] Apache Jakarta Slide up to 2.1 directory traversal
18623| [39540] Apache Geronimo 2.0/2.0.1/2.0.2/2.1 unknown vulnerability
18624| [3310] Apache OpenOffice 1.1.3/2.0.4/2.2.1 TIFF Image Parser Heap-based memory corruption
18625| [38768] Apache HTTP Server up to 2.1.7 mod_autoindex.c cross site scripting
18626| [38952] Apache Geronimo 2.0.1/2.1 unknown vulnerability
18627| [38658] Apache Tomcat 4.1.31 cal2.jsp cross site request forgery
18628| [38524] Apache Geronimo 2.0 unknown vulnerability
18629| [3256] Apache Tomcat up to 6.0.13 cross site scripting
18630| [38331] Apache Tomcat 4.1.24 information disclosure
18631| [38330] Apache Tomcat 4.1.24 information disclosure
18632| [38185] Apache Tomcat 3.3/3.3.1/3.3.1a/3.3.2 Error Message CookieExample cross site scripting
18633| [37967] Apache Tomcat up to 4.1.36 Error Message sendmail.jsp cross site scripting
18634| [37647] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 Authorization unknown vulnerability
18635| [37646] Apache Derby 10.1.1.0/10.1.2.1/10.1.3.1 unknown vulnerability
18636| [3141] Apache Tomcat up to 4.1.31 Accept-Language Header cross site scripting
18637| [3133] Apache Tomcat up to 6.0 HTTP cross site scripting
18638| [37292] Apache Tomcat up to 5.5.1 cross site scripting
18639| [3130] Apache OpenOffice 2.2.1 RTF Document Heap-based memory corruption
18640| [36981] Apache Tomcat JK Web Server Connector up to 1.2.22 mod_jk directory traversal
18641| [36892] Apache Tomcat up to 4.0.0 hello.jsp cross site scripting
18642| [37320] Apache MyFaces Tomahawk up to 1.1.4 cross site scripting
18643| [36697] Apache Tomcat up to 5.5.17 implicit-objects.jsp cross site scripting
18644| [36491] Apache Axis 1.0 Installation javaioFileNotFoundException information disclosure
18645| [36400] Apache Tomcat 5.5.15 mod_jk cross site scripting
18646| [36698] Apache Tomcat up to 4.0.0 cal2.jsp cross site scripting
18647| [36224] XAMPP Apache Distribution up to 1.6.0a adodb.php connect memory corruption
18648| [36225] XAMPP Apache Distribution 1.6.0a sql injection
18649| [2997] Apache httpd/Tomcat 5.5/6.0 directory traversal
18650| [35896] Apache Apache Test up to 1.29 mod_perl denial of service
18651| [35653] Avaya S8300 Cm 3.1.2 Apache Tomcat unknown vulnerability
18652| [35402] Apache Tomcat JK Web Server Connector 1.2.19 mod_jk.so map_uri_to_worker memory corruption
18653| [35067] Apache Stats up to 0.0.2 extract unknown vulnerability
18654| [35025] Apache Stats up to 0.0.3 extract unknown vulnerability
18655| [34252] Apache HTTP Server denial of service
18656| [2795] Apache OpenOffice 2.0.4 WMF/EMF File Heap-based memory corruption
18657| [33877] Apache Opentaps 0.9.3 cross site scripting
18658| [33876] Apache Open For Business Project unknown vulnerability
18659| [33875] Apache Open For Business Project cross site scripting
18660| [2703] Apache Jakarta Tomcat up to 5.x der_get_oid memory corruption
18661| [2611] Apache HTTP Server up to 1.0.1 set_var Format String
18662|
18663| MITRE CVE - https://cve.mitre.org:
18664| [CVE-2013-4156] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.
18665| [CVE-2013-4131] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
18666| [CVE-2013-3239] phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.
18667| [CVE-2013-3060] The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
18668| [CVE-2013-2765] The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
18669| [CVE-2013-2251] Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
18670| [CVE-2013-2249] mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
18671| [CVE-2013-2248] Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
18672| [CVE-2013-2189] Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.
18673| [CVE-2013-2135] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
18674| [CVE-2013-2134] Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
18675| [CVE-2013-2115] Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
18676| [CVE-2013-2071] java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
18677| [CVE-2013-2067] java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
18678| [CVE-2013-1966] Apache Struts 2 before 2.3.14.1 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
18679| [CVE-2013-1965] Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.1, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
18680| [CVE-2013-1896] mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
18681| [CVE-2013-1884] The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
18682| [CVE-2013-1879] Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."
18683| [CVE-2013-1862] mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
18684| [CVE-2013-1849] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
18685| [CVE-2013-1847] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
18686| [CVE-2013-1846] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL.
18687| [CVE-2013-1845] The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file or directory.
18688| [CVE-2013-1814] The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
18689| [CVE-2013-1777] The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not property implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
18690| [CVE-2013-1768] The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
18691| [CVE-2013-1088] Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
18692| [CVE-2013-1048] The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
18693| [CVE-2013-0966] The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
18694| [CVE-2013-0942] Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
18695| [CVE-2013-0941] EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
18696| [CVE-2013-0253] The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
18697| [CVE-2013-0248] The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
18698| [CVE-2013-0239] Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
18699| [CVE-2012-6573] Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.
18700| [CVE-2012-6551] The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
18701| [CVE-2012-6092] Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
18702| [CVE-2012-5887] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.
18703| [CVE-2012-5886] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
18704| [CVE-2012-5885] The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
18705| [CVE-2012-5786] The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF, possibly 2.6.0, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
18706| [CVE-2012-5785] Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
18707| [CVE-2012-5784] Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
18708| [CVE-2012-5783] Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
18709| [CVE-2012-5633] The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
18710| [CVE-2012-5616] Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.
18711| [CVE-2012-5568] Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
18712| [CVE-2012-5351] Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
18713| [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
18714| [CVE-2012-4557] The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
18715| [CVE-2012-4556] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query.
18716| [CVE-2012-4555] The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors.
18717| [CVE-2012-4534] org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
18718| [CVE-2012-4528] The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
18719| [CVE-2012-4501] Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
18720| [CVE-2012-4460] The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an out-of-bounds read, but it might not trigger a crash.
18721| [CVE-2012-4459] Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.
18722| [CVE-2012-4458] The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the client-properties map in a connection.start-ok message.
18723| [CVE-2012-4446] The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
18724| [CVE-2012-4431] org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
18725| [CVE-2012-4418] Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
18726| [CVE-2012-4387] Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
18727| [CVE-2012-4386] The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
18728| [CVE-2012-4360] Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
18729| [CVE-2012-4063] The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via unspecified vectors.
18730| [CVE-2012-4001] The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.
18731| [CVE-2012-3908] Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
18732| [CVE-2012-3546] org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
18733| [CVE-2012-3544] Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
18734| [CVE-2012-3526] The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.
18735| [CVE-2012-3513] munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
18736| [CVE-2012-3506] Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
18737| [CVE-2012-3502] The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
18738| [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
18739| [CVE-2012-3467] Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
18740| [CVE-2012-3451] Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
18741| [CVE-2012-3446] Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
18742| [CVE-2012-3376] DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
18743| [CVE-2012-3373] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
18744| [CVE-2012-3126] Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Products Suite 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Apache Tomcat Agent.
18745| [CVE-2012-3123] Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.
18746| [CVE-2012-2760] mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
18747| [CVE-2012-2733] java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
18748| [CVE-2012-2687] Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
18749| [CVE-2012-2381] Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
18750| [CVE-2012-2380] Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.
18751| [CVE-2012-2379] Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
18752| [CVE-2012-2378] Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
18753| [CVE-2012-2329] Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.
18754| [CVE-2012-2145] Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.
18755| [CVE-2012-2138] The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.
18756| [CVE-2012-2098] Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
18757| [CVE-2012-1574] The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
18758| [CVE-2012-1181] fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.
18759| [CVE-2012-1089] Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
18760| [CVE-2012-1007] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.
18761| [CVE-2012-1006] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
18762| [CVE-2012-0883] envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
18763| [CVE-2012-0840] tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
18764| [CVE-2012-0838] Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
18765| [CVE-2012-0788] The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.
18766| [CVE-2012-0394] ** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
18767| [CVE-2012-0393] The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
18768| [CVE-2012-0392] The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
18769| [CVE-2012-0391] The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
18770| [CVE-2012-0256] Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
18771| [CVE-2012-0216] The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
18772| [CVE-2012-0213] The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
18773| [CVE-2012-0053] protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
18774| [CVE-2012-0047] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
18775| [CVE-2012-0031] scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
18776| [CVE-2012-0022] Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
18777| [CVE-2012-0021] The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
18778| [CVE-2011-5064] DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
18779| [CVE-2011-5063] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
18780| [CVE-2011-5062] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
18781| [CVE-2011-5057] Apache Struts 2.3.1.1 and earlier provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
18782| [CVE-2011-5034] Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
18783| [CVE-2011-4905] Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
18784| [CVE-2011-4858] Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
18785| [CVE-2011-4668] IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
18786| [CVE-2011-4449] actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.
18787| [CVE-2011-4415] The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
18788| [CVE-2011-4317] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
18789| [CVE-2011-3639] The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
18790| [CVE-2011-3620] Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
18791| [CVE-2011-3607] Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.
18792| [CVE-2011-3376] org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
18793| [CVE-2011-3375] Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
18794| [CVE-2011-3368] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
18795| [CVE-2011-3348] The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
18796| [CVE-2011-3192] The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
18797| [CVE-2011-3190] Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
18798| [CVE-2011-2729] native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
18799| [CVE-2011-2712] Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
18800| [CVE-2011-2688] SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
18801| [CVE-2011-2526] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.
18802| [CVE-2011-2516] Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
18803| [CVE-2011-2481] Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
18804| [CVE-2011-2329] The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730.
18805| [CVE-2011-2204] Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.
18806| [CVE-2011-2088] XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
18807| [CVE-2011-2087] Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
18808| [CVE-2011-1928] The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.
18809| [CVE-2011-1921] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
18810| [CVE-2011-1783] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
18811| [CVE-2011-1772] Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
18812| [CVE-2011-1752] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
18813| [CVE-2011-1610] Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
18814| [CVE-2011-1582] Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
18815| [CVE-2011-1571] Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
18816| [CVE-2011-1570] Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
18817| [CVE-2011-1503] The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.
18818| [CVE-2011-1502] Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
18819| [CVE-2011-1498] Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
18820| [CVE-2011-1475] The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
18821| [CVE-2011-1419] Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
18822| [CVE-2011-1318] Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
18823| [CVE-2011-1184] The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
18824| [CVE-2011-1183] Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
18825| [CVE-2011-1176] The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
18826| [CVE-2011-1088] Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
18827| [CVE-2011-1077] Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
18828| [CVE-2011-1026] Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of administrators.
18829| [CVE-2011-0715] The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
18830| [CVE-2011-0534] Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
18831| [CVE-2011-0533] Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta
18832| [CVE-2011-0419] Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
18833| [CVE-2011-0013] Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
18834| [CVE-2010-4644] Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
18835| [CVE-2010-4539] The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.
18836| [CVE-2010-4476] The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
18837| [CVE-2010-4455] Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.2 and 11.1.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Apache Plugin.
18838| [CVE-2010-4408] Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.
18839| [CVE-2010-4312] The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
18840| [CVE-2010-4172] Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
18841| [CVE-2010-3872] The fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.6 for the Apache HTTP Server does not use bytewise pointer arithmetic in certain circumstances, which has unspecified impact and attack vectors related to "untrusted FastCGI applications" and a "stack buffer overwrite."
18842| [CVE-2010-3863] Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
18843| [CVE-2010-3854] Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
18844| [CVE-2010-3718] Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
18845| [CVE-2010-3449] Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1
18846| [CVE-2010-3315] authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
18847| [CVE-2010-3083] sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.
18848| [CVE-2010-2952] Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.
18849| [CVE-2010-2791] mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
18850| [CVE-2010-2375] Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
18851| [CVE-2010-2234] Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.
18852| [CVE-2010-2227] Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
18853| [CVE-2010-2103] Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.
18854| [CVE-2010-2086] Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
18855| [CVE-2010-2076] Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
18856| [CVE-2010-2068] mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.
18857| [CVE-2010-2057] shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.
18858| [CVE-2010-1632] Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.
18859| [CVE-2010-1623] Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
18860| [CVE-2010-1587] The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
18861| [CVE-2010-1452] The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
18862| [CVE-2010-1325] Cross-site request forgery (CSRF) vulnerability in the apache2-slms package in SUSE Lifecycle Management Server (SLMS) 1.0 on SUSE Linux Enterprise (SLE) 11 allows remote attackers to hijack the authentication of unspecified victims via vectors related to improper parameter quoting. NOTE: some sources report that this is a vulnerability in a product named "Apache SLMS," but that is incorrect.
18863| [CVE-2010-1244] Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
18864| [CVE-2010-1157] Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.
18865| [CVE-2010-1151] Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.
18866| [CVE-2010-0684] Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
18867| [CVE-2010-0434] The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
18868| [CVE-2010-0432] Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewprofile (aka partymgr/control/login), (3) the start parameter to myportal/control/showPortalPage, (4) an invalid URI beginning with /facility/control/ReceiveReturn (aka /crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the contentId parameter (aka the entityName variable) to ecommerce/control/ViewBlogArticle, (6) the entityName parameter to webtools/control/FindGeneric, or the (7) subject or (8) content parameter to an unspecified component under ecommerce/control/contactus.
18869| [CVE-2010-0425] modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
18870| [CVE-2010-0408] The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
18871| [CVE-2010-0390] Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.
18872| [CVE-2010-0219] Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
18873| [CVE-2010-0010] Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
18874| [CVE-2010-0009] Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.
18875| [CVE-2009-5120] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a Project Woodstock service on this port.
18876| [CVE-2009-5119] The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted session data.
18877| [CVE-2009-5006] The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.
18878| [CVE-2009-5005] The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.
18879| [CVE-2009-4355] Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
18880| [CVE-2009-4269] The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
18881| [CVE-2009-3923] The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
18882| [CVE-2009-3890] Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.
18883| [CVE-2009-3843] HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
18884| [CVE-2009-3821] Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
18885| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
18886| [CVE-2009-3548] The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
18887| [CVE-2009-3250] The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.
18888| [CVE-2009-3095] The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
18889| [CVE-2009-3094] The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
18890| [CVE-2009-2902] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
18891| [CVE-2009-2901] The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
18892| [CVE-2009-2823] The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.
18893| [CVE-2009-2699] The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
18894| [CVE-2009-2696] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.
18895| [CVE-2009-2693] Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
18896| [CVE-2009-2625] XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
18897| [CVE-2009-2412] Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR
18898| [CVE-2009-2299] The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.
18899| [CVE-2009-1956] Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
18900| [CVE-2009-1955] The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
18901| [CVE-2009-1903] The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
18902| [CVE-2009-1891] The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
18903| [CVE-2009-1890] The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
18904| [CVE-2009-1885] Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.
18905| [CVE-2009-1462] The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.
18906| [CVE-2009-1275] Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
18907| [CVE-2009-1195] The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
18908| [CVE-2009-1191] mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
18909| [CVE-2009-1012] Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.
18910| [CVE-2009-0918] Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.
18911| [CVE-2009-0796] Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.
18912| [CVE-2009-0783] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
18913| [CVE-2009-0781] Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
18914| [CVE-2009-0754] PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.
18915| [CVE-2009-0580] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.
18916| [CVE-2009-0486] Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
18917| [CVE-2009-0039] Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.
18918| [CVE-2009-0038] Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring
18919| [CVE-2009-0033] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.
18920| [CVE-2009-0026] Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
18921| [CVE-2009-0023] The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
18922| [CVE-2008-6879] Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
18923| [CVE-2008-6755] ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.
18924| [CVE-2008-6722] Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.
18925| [CVE-2008-6682] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
18926| [CVE-2008-6505] Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.
18927| [CVE-2008-6504] ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.
18928| [CVE-2008-5696] Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
18929| [CVE-2008-5676] Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."
18930| [CVE-2008-5519] The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.
18931| [CVE-2008-5518] Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet)
18932| [CVE-2008-5515] Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.
18933| [CVE-2008-5457] Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
18934| [CVE-2008-4308] The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
18935| [CVE-2008-4008] Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.
18936| [CVE-2008-3666] Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured
18937| [CVE-2008-3271] Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
18938| [CVE-2008-3257] Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
18939| [CVE-2008-2939] Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
18940| [CVE-2008-2938] Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
18941| [CVE-2008-2742] Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.
18942| [CVE-2008-2717] TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
18943| [CVE-2008-2579] Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.
18944| [CVE-2008-2384] SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
18945| [CVE-2008-2370] Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
18946| [CVE-2008-2364] The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
18947| [CVE-2008-2168] Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
18948| [CVE-2008-2025] Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
18949| [CVE-2008-1947] Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
18950| [CVE-2008-1734] Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.
18951| [CVE-2008-1678] Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
18952| [CVE-2008-1232] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.
18953| [CVE-2008-0869] Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.
18954| [CVE-2008-0732] The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.
18955| [CVE-2008-0555] The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.
18956| [CVE-2008-0457] Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
18957| [CVE-2008-0456] CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
18958| [CVE-2008-0455] Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
18959| [CVE-2008-0128] The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
18960| [CVE-2008-0005] mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
18961| [CVE-2008-0002] Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
18962| [CVE-2007-6750] The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
18963| [CVE-2007-6726] Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
18964| [CVE-2007-6514] Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
18965| [CVE-2007-6423] ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
18966| [CVE-2007-6422] The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
18967| [CVE-2007-6421] Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
18968| [CVE-2007-6420] Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
18969| [CVE-2007-6388] Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
18970| [CVE-2007-6361] Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
18971| [CVE-2007-6342] SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.
18972| [CVE-2007-6286] Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
18973| [CVE-2007-6258] Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.
18974| [CVE-2007-6231] Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_includepath parameter to (1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php, or (5) libchart-1.1/libchart.php in include/. NOTE: access to include/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
18975| [CVE-2007-6203] Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
18976| [CVE-2007-5797] SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
18977| [CVE-2007-5731] Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.
18978| [CVE-2007-5461] Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
18979| [CVE-2007-5342] The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
18980| [CVE-2007-5333] Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
18981| [CVE-2007-5156] Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
18982| [CVE-2007-5085] Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
18983| [CVE-2007-5000] Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
18984| [CVE-2007-4724] Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.
18985| [CVE-2007-4723] Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
18986| [CVE-2007-4641] Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.
18987| [CVE-2007-4556] Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.
18988| [CVE-2007-4548] The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
18989| [CVE-2007-4465] Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
18990| [CVE-2007-3847] The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
18991| [CVE-2007-3571] The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.
18992| [CVE-2007-3386] Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
18993| [CVE-2007-3385] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
18994| [CVE-2007-3384] Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.
18995| [CVE-2007-3383] Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.
18996| [CVE-2007-3382] Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
18997| [CVE-2007-3304] Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
18998| [CVE-2007-3303] Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
18999| [CVE-2007-3101] Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.
19000| [CVE-2007-2450] Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.
19001| [CVE-2007-2449] Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the '
19002| [CVE-2007-2353] Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
19003| [CVE-2007-2025] Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.
19004| [CVE-2007-1863] cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
19005| [CVE-2007-1862] The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
19006| [CVE-2007-1860] mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.
19007| [CVE-2007-1858] The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
19008| [CVE-2007-1842] Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.
19009| [CVE-2007-1801] Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.
19010| [CVE-2007-1743] suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
19011| [CVE-2007-1742] suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
19012| [CVE-2007-1741] Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
19013| [CVE-2007-1720] Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.
19014| [CVE-2007-1636] Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.
19015| [CVE-2007-1633] Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.
19016| [CVE-2007-1577] Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
19017| [CVE-2007-1539] Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.
19018| [CVE-2007-1524] Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.
19019| [CVE-2007-1491] Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.
19020| [CVE-2007-1358] Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
19021| [CVE-2007-1349] PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
19022| [CVE-2007-0975] Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.
19023| [CVE-2007-0930] Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.
19024| [CVE-2007-0792] The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
19025| [CVE-2007-0774] Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
19026| [CVE-2007-0637] Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.
19027| [CVE-2007-0451] Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
19028| [CVE-2007-0450] Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
19029| [CVE-2007-0419] The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).
19030| [CVE-2007-0173] Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
19031| [CVE-2007-0098] Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
19032| [CVE-2007-0086] ** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.
19033| [CVE-2006-7217] Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.
19034| [CVE-2006-7216] Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.
19035| [CVE-2006-7197] The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.
19036| [CVE-2006-7196] Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
19037| [CVE-2006-7195] Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
19038| [CVE-2006-7098] The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
19039| [CVE-2006-6869] Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
19040| [CVE-2006-6675] Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecifeid parameters in Welcome web-app.
19041| [CVE-2006-6613] Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive information via a .. (dot dot) in the pa_lang[include_file] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
19042| [CVE-2006-6589] Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.
19043| [CVE-2006-6588] The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.
19044| [CVE-2006-6587] Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.
19045| [CVE-2006-6445] Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
19046| [CVE-2006-6071] TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.
19047| [CVE-2006-6047] Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
19048| [CVE-2006-5894] Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
19049| [CVE-2006-5752] Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
19050| [CVE-2006-5733] Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
19051| [CVE-2006-5263] Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apache HTTP Server log file that apparently contains PHP code.
19052| [CVE-2006-4994] Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted "Program Files" pathname.
19053| [CVE-2006-4636] Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.
19054| [CVE-2006-4625] PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
19055| [CVE-2006-4558] DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
19056| [CVE-2006-4191] Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
19057| [CVE-2006-4154] Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
19058| [CVE-2006-4110] Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
19059| [CVE-2006-4004] Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
19060| [CVE-2006-3918] http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
19061| [CVE-2006-3835] Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (
19062| [CVE-2006-3747] Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
19063| [CVE-2006-3362] Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
19064| [CVE-2006-3102] Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of time under the webroot in the temp/articles directory.
19065| [CVE-2006-3070] write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.
19066| [CVE-2006-2831] Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
19067| [CVE-2006-2806] The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.
19068| [CVE-2006-2743] Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
19069| [CVE-2006-2514] Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
19070| [CVE-2006-2330] PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
19071| [CVE-2006-1777] Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache error_log file, which is then included by doc/index.php.
19072| [CVE-2006-1564] Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.
19073| [CVE-2006-1548] Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
19074| [CVE-2006-1547] ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
19075| [CVE-2006-1546] Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
19076| [CVE-2006-1393] Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
19077| [CVE-2006-1346] Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.
19078| [CVE-2006-1292] Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
19079| [CVE-2006-1243] Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
19080| [CVE-2006-1095] Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
19081| [CVE-2006-1079] htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
19082| [CVE-2006-1078] Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
19083| [CVE-2006-0743] Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
19084| [CVE-2006-0254] Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.
19085| [CVE-2006-0150] Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
19086| [CVE-2006-0144] The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.
19087| [CVE-2006-0042] Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.
19088| [CVE-2005-4857] eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a "memory addressing error".
19089| [CVE-2005-4849] Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information.
19090| [CVE-2005-4836] The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
19091| [CVE-2005-4814] Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.
19092| [CVE-2005-4703] Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
19093| [CVE-2005-3745] Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
19094| [CVE-2005-3630] Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.
19095| [CVE-2005-3510] Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
19096| [CVE-2005-3392] Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.
19097| [CVE-2005-3357] mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
19098| [CVE-2005-3352] Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
19099| [CVE-2005-3319] The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.
19100| [CVE-2005-3164] The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
19101| [CVE-2005-2970] Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
19102| [CVE-2005-2963] The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.
19103| [CVE-2005-2728] The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
19104| [CVE-2005-2660] apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.
19105| [CVE-2005-2088] The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
19106| [CVE-2005-1754] ** DISPUTED ** JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
19107| [CVE-2005-1753] ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."
19108| [CVE-2005-1344] Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
19109| [CVE-2005-1268] Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
19110| [CVE-2005-1266] Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
19111| [CVE-2005-0808] Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
19112| [CVE-2005-0182] The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.
19113| [CVE-2005-0108] Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.
19114| [CVE-2004-2734] webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
19115| [CVE-2004-2680] mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
19116| [CVE-2004-2650] Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
19117| [CVE-2004-2343] ** DISPUTED ** Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument.
19118| [CVE-2004-2336] Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.
19119| [CVE-2004-2115] Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.
19120| [CVE-2004-1834] mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
19121| [CVE-2004-1765] Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.
19122| [CVE-2004-1545] UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
19123| [CVE-2004-1438] The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
19124| [CVE-2004-1405] MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
19125| [CVE-2004-1404] Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
19126| [CVE-2004-1387] The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
19127| [CVE-2004-1084] Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
19128| [CVE-2004-1083] Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
19129| [CVE-2004-1082] mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
19130| [CVE-2004-0942] Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
19131| [CVE-2004-0940] Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
19132| [CVE-2004-0885] The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
19133| [CVE-2004-0811] Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
19134| [CVE-2004-0809] The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
19135| [CVE-2004-0786] The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
19136| [CVE-2004-0751] The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
19137| [CVE-2004-0748] mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
19138| [CVE-2004-0747] Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
19139| [CVE-2004-0700] Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
19140| [CVE-2004-0646] Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
19141| [CVE-2004-0529] The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.
19142| [CVE-2004-0493] The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
19143| [CVE-2004-0492] Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
19144| [CVE-2004-0490] cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.
19145| [CVE-2004-0488] Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
19146| [CVE-2004-0263] PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
19147| [CVE-2004-0174] Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
19148| [CVE-2004-0173] Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
19149| [CVE-2004-0113] Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
19150| [CVE-2004-0009] Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.
19151| [CVE-2003-1581] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
19152| [CVE-2003-1580] The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
19153| [CVE-2003-1573] The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."
19154| [CVE-2003-1521] Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
19155| [CVE-2003-1516] The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
19156| [CVE-2003-1502] mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.
19157| [CVE-2003-1418] Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child proccess IDs (PID).
19158| [CVE-2003-1307] ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."
19159| [CVE-2003-1172] Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
19160| [CVE-2003-1171] Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.
19161| [CVE-2003-1138] The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
19162| [CVE-2003-1054] mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.
19163| [CVE-2003-0993] mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
19164| [CVE-2003-0987] mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
19165| [CVE-2003-0866] The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
19166| [CVE-2003-0844] mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.
19167| [CVE-2003-0843] Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.
19168| [CVE-2003-0789] mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
19169| [CVE-2003-0771] Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.
19170| [CVE-2003-0658] Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
19171| [CVE-2003-0542] Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
19172| [CVE-2003-0460] The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
19173| [CVE-2003-0254] Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
19174| [CVE-2003-0253] The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
19175| [CVE-2003-0249] ** DISPUTED ** PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."
19176| [CVE-2003-0245] Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
19177| [CVE-2003-0192] Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
19178| [CVE-2003-0189] The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
19179| [CVE-2003-0134] Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.
19180| [CVE-2003-0132] A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.
19181| [CVE-2003-0083] Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
19182| [CVE-2003-0020] Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
19183| [CVE-2003-0017] Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.
19184| [CVE-2003-0016] Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
19185| [CVE-2002-2310] ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
19186| [CVE-2002-2309] php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
19187| [CVE-2002-2272] Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
19188| [CVE-2002-2103] Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
19189| [CVE-2002-2029] PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
19190| [CVE-2002-2012] Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
19191| [CVE-2002-2009] Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
19192| [CVE-2002-2008] Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.
19193| [CVE-2002-2007] The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
19194| [CVE-2002-2006] The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
19195| [CVE-2002-1895] The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
19196| [CVE-2002-1850] mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
19197| [CVE-2002-1793] HTTP Server mod_ssl module running on HP-UX 11.04 with Virtualvault OS (VVOS) 4.5 through 4.6 closes the connection when the Apache server times out during an SSL request, which may allow attackers to cause a denial of service.
19198| [CVE-2002-1658] Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
19199| [CVE-2002-1635] The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin.
19200| [CVE-2002-1593] mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.
19201| [CVE-2002-1592] The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.
19202| [CVE-2002-1567] Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
19203| [CVE-2002-1394] Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
19204| [CVE-2002-1233] A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
19205| [CVE-2002-1157] Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
19206| [CVE-2002-1156] Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
19207| [CVE-2002-1148] The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
19208| [CVE-2002-0935] Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.
19209| [CVE-2002-0843] Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
19210| [CVE-2002-0840] Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
19211| [CVE-2002-0839] The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
19212| [CVE-2002-0682] Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
19213| [CVE-2002-0661] Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
19214| [CVE-2002-0658] OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.
19215| [CVE-2002-0654] Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
19216| [CVE-2002-0653] Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
19217| [CVE-2002-0513] The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.
19218| [CVE-2002-0493] Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
19219| [CVE-2002-0392] Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
19220| [CVE-2002-0259] InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.
19221| [CVE-2002-0249] PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
19222| [CVE-2002-0240] PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
19223| [CVE-2002-0082] The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
19224| [CVE-2002-0061] Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
19225| [CVE-2001-1556] The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
19226| [CVE-2001-1534] mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
19227| [CVE-2001-1510] Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.
19228| [CVE-2001-1449] The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
19229| [CVE-2001-1385] The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
19230| [CVE-2001-1342] Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
19231| [CVE-2001-1217] Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
19232| [CVE-2001-1216] Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
19233| [CVE-2001-1072] Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
19234| [CVE-2001-1013] Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
19235| [CVE-2001-0925] The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
19236| [CVE-2001-0829] A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
19237| [CVE-2001-0766] Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
19238| [CVE-2001-0731] Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
19239| [CVE-2001-0730] split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
19240| [CVE-2001-0729] Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
19241| [CVE-2001-0590] Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
19242| [CVE-2001-0131] htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
19243| [CVE-2001-0108] PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
19244| [CVE-2001-0042] PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
19245| [CVE-2000-1247] The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
19246| [CVE-2000-1210] Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
19247| [CVE-2000-1206] Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
19248| [CVE-2000-1205] Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.
19249| [CVE-2000-1204] Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
19250| [CVE-2000-1168] IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
19251| [CVE-2000-1016] The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
19252| [CVE-2000-0913] mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
19253| [CVE-2000-0883] The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.
19254| [CVE-2000-0869] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method.
19255| [CVE-2000-0868] The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
19256| [CVE-2000-0791] Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.
19257| [CVE-2000-0760] The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
19258| [CVE-2000-0759] Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
19259| [CVE-2000-0628] The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.
19260| [CVE-2000-0505] The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
19261| [CVE-1999-1412] A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
19262| [CVE-1999-1293] mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
19263| [CVE-1999-1237] Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
19264| [CVE-1999-1199] Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
19265| [CVE-1999-1053] guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
19266| [CVE-1999-0926] Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
19267| [CVE-1999-0678] A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
19268| [CVE-1999-0448] IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
19269| [CVE-1999-0289] The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
19270| [CVE-1999-0236] ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
19271| [CVE-1999-0107] Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
19272| [CVE-1999-0071] Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
19273|
19274| SecurityFocus - https://www.securityfocus.com/bid/:
19275| [104554] Apache HBase CVE-2018-8025 Security Bypass Vulnerability
19276| [104465] Apache Geode CVE-2017-15695 Remote Code Execution Vulnerability
19277| [104418] Apache Storm CVE-2018-8008 Arbitrary File Write Vulnerability
19278| [104399] Apache Storm CVE-2018-1332 User Impersonation Vulnerability
19279| [104348] Apache UIMA CVE-2017-15691 XML External Entity Injection Vulnerability
19280| [104313] Apache NiFi XML External Entity Injection and Denial of Service Vulnerability
19281| [104259] Apache Geode CVE-2017-12622 Authorization Bypass Vulnerability
19282| [104257] Apache Sling XSS Protection API CVE-2017-15717 Cross Site Scripting Vulnerability
19283| [104253] Apache ZooKeeper CVE-2018-8012 Security Bypass Vulnerability
19284| [104252] Apache Batik CVE-2018-8013 Information Disclosure Vulnerability
19285| [104239] Apache Solr CVE-2018-8010 XML External Entity Multiple Information Disclosure Vulnerabilities
19286| [104215] Apache ORC CVE-2018-8015 Denial of Service Vulnerability
19287| [104203] Apache Tomcat CVE-2018-8014 Security Bypass Vulnerability
19288| [104161] Apache Ambari CVE-2018-8003 Directory Traversal Vulnerability
19289| [104140] Apache Derby CVE-2018-1313 Security Bypass Vulnerability
19290| [104135] Apache Tika CVE-2018-1338 Denial of Service Vulnerability
19291| [104008] Apache Fineract CVE-2018-1291 SQL Injection Vulnerability
19292| [104007] Apache Fineract CVE-2018-1292 SQL Injection Vulnerability
19293| [104005] Apache Fineract CVE-2018-1289 SQL Injection Vulnerability
19294| [104001] Apache Tika CVE-2018-1335 Remote Command Injection Vulnerability
19295| [103975] Apache Fineract CVE-2018-1290 SQL Injection Vulnerability
19296| [103974] Apache Solr CVE-2018-1308 XML External Entity Injection Vulnerability
19297| [103772] Apache Traffic Server CVE-2017-7671 Denial of Service Vulnerability
19298| [103770] Apache Traffic Server CVE-2017-5660 Security Bypass Vulnerability
19299| [103751] Apache Hive CVE-2018-1282 SQL Injection Vulnerability
19300| [103750] Apache Hive CVE-2018-1284 Security Bypass Vulnerability
19301| [103692] Apache Ignite CVE-2018-1295 Arbitrary Code Execution Vulnerability
19302| [103528] Apache HTTP Server CVE-2018-1302 Denial of Service Vulnerability
19303| [103525] Apache HTTP Server CVE-2017-15715 Remote Security Bypass Vulnerability
19304| [103524] Apache HTTP Server CVE-2018-1312 Remote Security Bypass Vulnerability
19305| [103522] Apache HTTP Server CVE-2018-1303 Denial of Service Vulnerability
19306| [103520] Apache HTTP Server CVE-2018-1283 Remote Security Vulnerability
19307| [103516] Apache Struts CVE-2018-1327 Denial of Service Vulnerability
19308| [103515] Apache HTTP Server CVE-2018-1301 Denial of Service Vulnerability
19309| [103512] Apache HTTP Server CVE-2017-15710 Denial of Service Vulnerability
19310| [103508] Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
19311| [103507] Apache Syncope CVE-2018-1322 Multiple Information Disclosure Vulnerabilities
19312| [103490] Apache Commons Compress CVE-2018-1324 Multiple Denial Of Service Vulnerabilities
19313| [103434] APACHE Allura CVE-2018-1319 HTTP Response Splitting Vulnerability
19314| [103389] Apache Tomcat JK Connector CVE-2018-1323 Directory Traversal Vulnerability
19315| [103222] Apache CloudStack CVE-2013-4317 Information Disclosure Vulnerability
19316| [103219] Apache Xerces-C CVE-2017-12627 Null Pointer Dereference Denial of Service Vulnerability
19317| [103206] Apache Geode CVE-2017-15693 Remote Code Execution Vulnerability
19318| [103205] Apache Geode CVE-2017-15692 Remote Code Execution Vulnerability
19319| [103170] Apache Tomcat CVE-2018-1304 Security Bypass Vulnerability
19320| [103144] Apache Tomcat CVE-2018-1305 Security Bypass Vulnerability
19321| [103102] Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
19322| [103098] Apache Karaf CVE-2016-8750 LDAP Injection Vulnerability
19323| [103069] Apache Tomcat CVE-2017-15706 Remote Security Weakness
19324| [103068] Apache JMeter CVE-2018-1287 Security Bypass Vulnerability
19325| [103067] Apache Qpid Dispatch Router 'router_core/connections.c' Denial of Service Vulnerability
19326| [103036] Apache CouchDB CVE-2017-12636 Remote Code Execution Vulnerability
19327| [103025] Apache Thrift CVE-2016-5397 Remote Command Injection Vulnerability
19328| [102879] Apache POI CVE-2017-12626 Multiple Denial of Service Vulnerabilities
19329| [102842] Apache NiFi CVE-2017-12632 Host Header Injection Vulnerability
19330| [102815] Apache NiFi CVE-2017-15697 Multiple Cross Site Scripting Vulnerabilities
19331| [102488] Apache Geode CVE-2017-9795 Remote Code Execution Vulnerability
19332| [102229] Apache Sling CVE-2017-15700 Information Disclosure Vulnerability
19333| [102226] Apache Drill CVE-2017-12630 Cross Site Scripting Vulnerability
19334| [102154] Multiple Apache Products CVE-2017-15708 Remote Code Execution Vulnerability
19335| [102127] Apache CXF Fediz CVE-2017-12631 Multiple Cross Site Request Forgery Vulnerabilities
19336| [102041] Apache Qpid Broker-J CVE-2017-15701 Denial of Service Vulnerability
19337| [102040] Apache Qpid Broker CVE-2017-15702 Security Weakness
19338| [102021] Apache Struts CVE-2017-15707 Denial of Service Vulnerability
19339| [101980] EMC RSA Authentication Agent for Web: Apache Web Server Authentication Bypass Vulnerability
19340| [101876] Apache Camel CVE-2017-12634 Deserialization Remote Code Execution Vulnerability
19341| [101874] Apache Camel CVE-2017-12633 Deserialization Remote Code Execution Vulnerability
19342| [101872] Apache Karaf CVE-2014-0219 Local Denial of Service Vulnerability
19343| [101868] Apache CouchDB CVE-2017-12635 Remote Privilege Escalation Vulnerability
19344| [101859] Apache CXF CVE-2017-12624 Denial of Service Vulnerability
19345| [101844] Apache Sling Servlets Post CVE-2017-11296 Cross Site Scripting Vulnerability
19346| [101686] Apache Hive CVE-2017-12625 Information Disclosure Vulnerability
19347| [101644] Apache Wicket CVE-2012-5636 Cross Site Scripting Vulnerability
19348| [101631] Apache Traffic Server CVE-2015-3249 Multiple Remote Code Execution Vulnerabilities
19349| [101630] Apache Traffic Server CVE-2014-3624 Access Bypass Vulnerability
19350| [101625] Apache jUDDI CVE-2009-1197 Security Bypass Vulnerability
19351| [101623] Apache jUDDI CVE-2009-1198 Cross Site Scripting Vulnerability
19352| [101620] Apache Subversion 'libsvn_fs_fs/fs_fs.c' Denial of Service Vulnerability
19353| [101585] Apache OpenOffice Multiple Remote Code Execution Vulnerabilities
19354| [101577] Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
19355| [101575] Apache Wicket CVE-2014-0043 Information Disclosure Vulnerability
19356| [101570] Apache Geode CVE-2017-9797 Information Disclosure Vulnerability
19357| [101562] Apache Derby CVE-2010-2232 Arbitrary File Overwrite Vulnerability
19358| [101560] Apache Portable Runtime Utility CVE-2017-12613 Multiple Information Disclosure Vulnerabilities
19359| [101558] Apache Portable Runtime Utility Local Out-of-Bounds Read Denial of Service Vulnerability
19360| [101532] Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
19361| [101516] Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
19362| [101261] Apache Solr/Lucene CVE-2017-12629 Information Disclosure and Remote Code Execution Vulnerabilities
19363| [101230] Apache Roller CVE-2014-0030 XML External Entity Injection Vulnerability
19364| [101173] Apache IMPALA CVE-2017-9792 Information Disclosure Vulnerability
19365| [101052] Apache Commons Jelly CVE-2017-12621 Security Bypass Vulnerability
19366| [101027] Apache Mesos CVE-2017-7687 Denial of Service Vulnerability
19367| [101023] Apache Mesos CVE-2017-9790 Denial of Service Vulnerability
19368| [100954] Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
19369| [100946] Apache Wicket CVE-2014-7808 Cross Site Request Forgery Vulnerability
19370| [100901] Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability
19371| [100897] Apache Tomcat CVE-2017-12616 Information Disclosure Vulnerability
19372| [100880] Apache Directory LDAP API CVE-2015-3250 Unspecified Information Disclosure Vulnerability
19373| [100872] Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
19374| [100870] Apache Solr CVE-2017-9803 Remote Privilege Escalation Vulnerability
19375| [100859] puppetlabs-apache CVE-2017-2299 Information Disclosure Vulnerability
19376| [100829] Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
19377| [100823] Apache Spark CVE-2017-12612 Deserialization Remote Code Execution Vulnerability
19378| [100612] Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
19379| [100611] Apache Struts CVE-2017-9793 Denial of Service Vulnerability
19380| [100609] Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
19381| [100587] Apache Atlas CVE-2017-3155 Cross Frame Scripting Vulnerability
19382| [100581] Apache Atlas CVE-2017-3154 Information Disclosure Vulnerability
19383| [100578] Apache Atlas CVE-2017-3153 Cross Site Scripting Vulnerability
19384| [100577] Apache Atlas CVE-2017-3152 Cross Site Scripting Vulnerability
19385| [100547] Apache Atlas CVE-2017-3151 HTML Injection Vulnerability
19386| [100536] Apache Atlas CVE-2017-3150 Cross Site Scripting Vulnerability
19387| [100449] Apache Pony Mail CVE-2016-4460 Authentication Bypass Vulnerability
19388| [100447] Apache2Triad Multiple Security Vulnerabilities
19389| [100284] Apache Sling Servlets Post CVE-2017-9802 Cross Site Scripting Vulnerability
19390| [100280] Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
19391| [100259] Apache Subversion CVE-2017-9800 Remote Command Execution Vulnerability
19392| [100256] Apache Tomcat CVE-2017-7675 Directory Traversal Vulnerability
19393| [100235] Apache Storm CVE-2017-9799 Remote Code Execution Vulnerability
19394| [100082] Apache Commons Email CVE-2017-9801 SMTP Header Injection Vulnerability
19395| [99873] Apache Sling XSS Protection API CVE-2016-6798 XML External Entity Injection Vulnerability
19396| [99870] Apache Sling API CVE-2016-5394 Cross Site Scripting Vulnerability
19397| [99603] Apache Spark CVE-2017-7678 Cross Site Scripting Vulnerability
19398| [99592] Apache OpenMeetings CVE-2017-7685 Security Bypass Vulnerability
19399| [99587] Apache OpenMeetings CVE-2017-7673 Security Bypass Vulnerability
19400| [99586] Apache OpenMeetings CVE-2017-7688 Security Bypass Vulnerability
19401| [99584] Apache OpenMeetings CVE-2017-7684 Denial of Service Vulnerability
19402| [99577] Apache OpenMeetings CVE-2017-7663 Cross Site Scripting Vulnerability
19403| [99576] Apache OpenMeetings CVE-2017-7664 XML External Entity Injection Vulnerability
19404| [99569] Apache HTTP Server CVE-2017-9788 Memory Corruption Vulnerability
19405| [99568] Apache HTTP Server CVE-2017-9789 Denial of Service Vulnerability
19406| [99563] Apache Struts CVE-2017-7672 Denial of Service Vulnerability
19407| [99562] Apache Struts Spring AOP Functionality Denial of Service Vulnerability
19408| [99509] Apache Impala CVE-2017-5652 Information Disclosure Vulnerability
19409| [99508] Apache IMPALA CVE-2017-5640 Authentication Bypass Vulnerability
19410| [99486] Apache Traffic Control CVE-2017-7670 Denial of Service Vulnerability
19411| [99485] Apache Solr CVE-2017-7660 Security Bypass Vulnerability
19412| [99484] Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
19413| [99292] Apache Ignite CVE-2017-7686 Information Disclosure Vulnerability
19414| [99170] Apache HTTP Server CVE-2017-7679 Buffer Overflow Vulnerability
19415| [99137] Apache HTTP Server CVE-2017-7668 Denial of Service Vulnerability
19416| [99135] Apache HTTP Server CVE-2017-3167 Authentication Bypass Vulnerability
19417| [99134] Apache HTTP Server CVE-2017-3169 Denial of Service Vulnerability
19418| [99132] Apache HTTP Server CVE-2017-7659 Denial of Service Vulnerability
19419| [99112] Apache Thrift CVE-2015-3254 Denial of Service Vulnerability
19420| [99067] Apache Ranger CVE-2016-8751 HTML Injection Vulnerability
19421| [99018] Apache NiFi CVE-2017-7667 Cross Frame Scripting Vulnerability
19422| [99009] Apache NiFi CVE-2017-7665 Cross Site Scripting Vulnerability
19423| [98961] Apache Ranger CVE-2017-7677 Security Bypass Vulnerability
19424| [98958] Apache Ranger CVE-2017-7676 Security Bypass Vulnerability
19425| [98888] Apache Tomcat CVE-2017-5664 Security Bypass Vulnerability
19426| [98814] Apache Zookeeper CVE-2017-5637 Denial of Service Vulnerability
19427| [98795] Apache Hadoop CVE-2017-7669 Remote Privilege Escalation Vulnerability
19428| [98739] Apache Knox CVE-2017-5646 User Impersonation Vulnerability
19429| [98669] Apache Hive CVE-2016-3083 Security Bypass Vulnerability
19430| [98646] Apache Atlas CVE-2016-8752 Information Disclosure Vulnerability
19431| [98570] Apache Archiva CVE-2017-5657 Multiple Cross-Site Request Forgery Vulnerabilities
19432| [98489] Apache CXF Fediz CVE-2017-7661 Multiple Cross Site Request Forgery Vulnerabilities
19433| [98485] Apache CXF Fediz CVE-2017-7662 Cross Site Request Forgery Vulnerability
19434| [98466] Apache Ambari CVE-2017-5655 Insecure Temporary File Handling Vulnerability
19435| [98365] Apache Cordova For Android CVE-2016-6799 Information Disclosure Vulnerability
19436| [98025] Apache Hadoop CVE-2017-3161 Cross Site Scripting Vulnerability
19437| [98017] Apache Hadoop CVE-2017-3162 Input Validation Vulnerability
19438| [97971] Apache CXF CVE-2017-5656 Information Disclosure Vulnerability
19439| [97968] Apache CXF CVE-2017-5653 Spoofing Vulnerability
19440| [97967] Apache ActiveMQ CVE-2015-7559 Denial of Service Vulnerability
19441| [97949] Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
19442| [97948] Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
19443| [97947] Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
19444| [97945] Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
19445| [97702] Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
19446| [97582] Apache CXF CVE-2016-6812 Cross Site Scripting Vulnerability
19447| [97579] Apache CXF JAX-RS CVE-2016-8739 XML External Entity Injection Vulnerability
19448| [97544] Apache Tomcat CVE-2017-5651 Information Disclosure Vulnerability
19449| [97531] Apache Tomcat CVE-2017-5650 Denial of Service Vulnerability
19450| [97530] Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
19451| [97509] Apache Ignite CVE-2016-6805 Information Disclosure and XML External Entity Injection Vulnerabilities
19452| [97383] Apache Flex BlazeDS CVE-2017-5641 Remote Code Execution Vulnerability
19453| [97378] Apache Geode CVE-2017-5649 Information Disclosure Vulnerability
19454| [97229] Apache Ambari CVE-2016-4976 Local Information Disclosure Vulnerability
19455| [97226] Apache Camel CVE-2017-5643 Server Side Request Forgery Security Bypass Vulnerability
19456| [97184] Apache Ambari CVE-2016-6807 Remote Command Execution Vulnerability
19457| [97179] Apache Camel CVE-2016-8749 Java Deserialization Multiple Remote Code Execution Vulnerabilities
19458| [96983] Apache POI CVE-2017-5644 Denial Of Service Vulnerability
19459| [96895] Apache Tomcat CVE-2016-8747 Information Disclosure Vulnerability
19460| [96731] Apache NiFi CVE-2017-5636 Remote Code Injection Vulnerability
19461| [96730] Apache NiFi CVE-2017-5635 Security Bypass Vulnerability
19462| [96729] Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
19463| [96540] IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
19464| [96398] Apache CXF CVE-2017-3156 Information Disclosure Vulnerability
19465| [96321] Apache Camel CVE-2017-3159 Remote Code Execution Vulnerability
19466| [96293] Apache Tomcat 'http11/AbstractInputBuffer.java' Denial of Service Vulnerability
19467| [96228] Apache Brooklyn Cross Site Request Forgery and Multiple Cross Site Scripting Vulnerabilities
19468| [95998] Apache Ranger CVE-2016-8746 Security Bypass Vulnerability
19469| [95929] Apache Groovy CVE-2016-6497 Information Disclosure Vulnerability
19470| [95838] Apache Cordova For Android CVE-2017-3160 Man in the Middle Security Bypass Vulnerability
19471| [95675] Apache Struts Remote Code Execution Vulnerability
19472| [95621] Apache NiFi CVE-2106-8748 Cross Site Scripting Vulnerability
19473| [95429] Apache Groovy CVE-2016-6814 Remote Code Execution Vulnerability
19474| [95335] Apache Hadoop CVE-2016-3086 Information Disclosure Vulnerability
19475| [95168] Apache Wicket CVE-2016-6793 Denial of Service Vulnerability
19476| [95136] Apache Qpid Broker for Java CVE-2016-8741 Remote Information Disclosure Vulnerability
19477| [95078] Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
19478| [95077] Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
19479| [95076] Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
19480| [95020] Apache Tika CVE-2015-3271 Remote Information Disclosure Vulnerability
19481| [94950] Apache Hadoop CVE-2016-5001 Local Information Disclosure Vulnerability
19482| [94882] Apache ActiveMQ CVE-2016-6810 HTML Injection Vulnerability
19483| [94828] Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
19484| [94766] Apache CouchDB CVE-2016-8742 Local Privilege Escalation Vulnerability
19485| [94657] Apache Struts CVE-2016-8738 Denial of Service Vulnerability
19486| [94650] Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
19487| [94588] Apache Subversion CVE-2016-8734 XML External Entity Denial of Service Vulnerability
19488| [94513] Apache Karaf CVE-2016-8648 Remote Code Execution Vulnerability
19489| [94463] Apache Tomcat CVE-2016-8735 Remote Code Execution Vulnerability
19490| [94462] Apache Tomcat CVE-2016-6817 Denial of Service Vulnerability
19491| [94461] Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
19492| [94418] Apache OpenOffice CVE-2016-6803 Local Privilege Escalation Vulnerability
19493| [94247] Apache Tika CVE-2016-6809 Remote Code Execution Vulnerability
19494| [94221] Apache Ranger CVE-2016-6815 Local Privilege Escalation Vulnerability
19495| [94145] Apache OpenMeetings CVE-2016-8736 Remote Code Execution Vulnerability
19496| [93945] Apache CloudStack CVE-2016-6813 Authorization Bypass Vulnerability
19497| [93944] Apache Tomcat Security Manager CVE-2016-6796 Security Bypass Vulnerability
19498| [93943] Apache Tomcat CVE-2016-6794 Security Bypass Vulnerability
19499| [93942] Apache Tomcat Security Manager CVE-2016-5018 Security Bypass Vulnerability
19500| [93940] Apache Tomcat CVE-2016-6797 Security Bypass Vulnerability
19501| [93939] Apache Tomcat CVE-2016-0762 Information Disclosure Vulnerability
19502| [93774] Apache OpenOffice CVE-2016-6804 DLL Loading Remote Code Execution Vulnerability
19503| [93773] Apache Struts CVE-2016-6795 Directory Traversal Vulnerability
19504| [93478] Apache Tomcat CVE-2016-6325 Local Privilege Escalation Vulnerability
19505| [93472] Apache Tomcat CVE-2016-5425 Insecure File Permissions Vulnerability
19506| [93429] Apache Tomcat JK Connector CVE-2016-6808 Remote Buffer Overflow Vulnerability
19507| [93263] Apache Tomcat CVE-2016-1240 Local Privilege Escalation Vulnerability
19508| [93236] Apache MyFaces Trinidad CVE-2016-5019 Remote Code Execution Vulnerability
19509| [93142] Apache ActiveMQ Artemis CVE-2016-4978 Remote Code Execution Vulnerability
19510| [93132] Apache Derby CVE-2015-1832 XML External Entity Information Disclosure Vulnerability
19511| [93044] Apache Zookeeper CVE-2016-5017 Buffer Overflow Vulnerability
19512| [92966] Apache Jackrabbit CVE-2016-6801 Cross-Site Request Forgery Vulnerability
19513| [92947] Apache Shiro CVE-2016-6802 Remote Security Bypass Vulnerability
19514| [92905] Apache CXF Fediz CVE-2016-4464 Security Bypass Vulnerability
19515| [92577] Apache Ranger CVE-2016-5395 HTML Injection Vulnerability
19516| [92331] Apache HTTP Server CVE-2016-1546 Remote Denial of Service Vulnerability
19517| [92328] Apache Hive CVE-2016-0760 Multiple Remote Code Execution Vulnerabilities
19518| [92320] Apache APR-util and httpd CVE-2016-6312 Denial of Service Vulnerability
19519| [92100] Apache POI CVE-2016-5000 XML External Entity Injection Vulnerability
19520| [92079] Apache OpenOffice CVE-2016-1513 Remote Code Execution Vulnerability
19521| [91818] Apache Tomcat CVE-2016-5388 Security Bypass Vulnerability
19522| [91816] Apache HTTP Server CVE-2016-5387 Security Bypass Vulnerability
19523| [91788] Apache Qpid Proton CVE-2016-4467 Certificate Verification Security Bypass Vulnerability
19524| [91738] Apache XML-RPC CVE-2016-5003 Remote Code Execution Vulnerability
19525| [91736] Apache XML-RPC Multiple Security Vulnerabilities
19526| [91707] Apache Archiva CVE-2016-5005 HTML Injection Vulnerability
19527| [91703] Apache Archiva CVE-2016-4469 Multiple Cross-Site Request Forgery Vulnerabilities
19528| [91566] Apache HTTP Server CVE-2016-4979 Authentication Bypass Vulnerability
19529| [91537] Apache QPID CVE-2016-4974 Deserialization Security Bypass Vulnerability
19530| [91501] Apache Xerces-C CVE-2016-4463 Stack Buffer Overflow Vulnerability
19531| [91453] Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
19532| [91284] Apache Struts CVE-2016-4431 Security Bypass Vulnerability
19533| [91282] Apache Struts CVE-2016-4433 Security Bypass Vulnerability
19534| [91281] Apache Struts CVE-2016-4430 Cross-Site Request Forgery Vulnerability
19535| [91280] Apache Struts CVE-2016-4436 Security Bypass Vulnerability
19536| [91278] Apache Struts CVE-2016-4465 Denial of Service Vulnerability
19537| [91277] Apache Struts Incomplete Fix Remote Code Execution Vulnerability
19538| [91275] Apache Struts CVE-2016-4438 Remote Code Execution Vulnerability
19539| [91217] Apache Continuum 'saveInstallation.action' Command Execution Vulnerability
19540| [91141] Apache CloudStack CVE-2016-3085 Authentication Bypass Vulnerability
19541| [91068] Apache Struts CVE-2016-1181 Remote Code Execution Vulnerability
19542| [91067] Apache Struts CVE-2016-1182 Security Bypass Vulnerability
19543| [91024] Apache Shiro CVE-2016-4437 Information Disclosure Vulnerability
19544| [90988] Apache Ranger CVE-2016-2174 SQL Injection Vulnerability
19545| [90961] Apache Struts CVE-2016-3093 Denial of Service Vulnerability
19546| [90960] Apache Struts CVE-2016-3087 Remote Code Execution Vulnerability
19547| [90921] Apache Qpid CVE-2016-4432 Authentication Bypass Vulnerability
19548| [90920] Apache Qpid CVE-2016-3094 Denial of Service Vulnerability
19549| [90902] Apache PDFBox CVE-2016-2175 XML External Entity Injection Vulnerability
19550| [90897] Apache Tika CVE-2016-4434 XML External Entity Injection Vulnerability
19551| [90827] Apache ActiveMQ CVE-2016-3088 Multiple Arbitrary File Upload Vulnerabilities
19552| [90755] Apache Ambari CVE-2016-0707 Multiple Local Information Disclosure Vulnerabilities
19553| [90482] Apache CVE-2004-1387 Local Security Vulnerability
19554| [89762] Apache CVE-2001-1556 Remote Security Vulnerability
19555| [89417] Apache Subversion CVE-2016-2167 Authentication Bypass Vulnerability
19556| [89326] RETIRED: Apache Subversion CVE-2016-2167 Security Bypass Vulnerability
19557| [89320] Apache Subversion CVE-2016-2168 Remote Denial of Service Vulnerability
19558| [88826] Apache Struts CVE-2016-3082 Remote Code Execution Vulnerability
19559| [88797] Apache Cordova For iOS CVE-2015-5208 Arbitrary Code Execution Vulnerability
19560| [88764] Apache Cordova iOS CVE-2015-5207 Multiple Security Bypass Vulnerabilities
19561| [88701] Apache CVE-2001-1449 Remote Security Vulnerability
19562| [88635] Apache CVE-2000-1204 Remote Security Vulnerability
19563| [88590] Apache WWW server CVE-1999-1199 Denial-Of-Service Vulnerability
19564| [88496] Apache CVE-2000-1206 Remote Security Vulnerability
19565| [87828] Apache CVE-1999-1237 Remote Security Vulnerability
19566| [87784] Apache CVE-1999-1293 Denial-Of-Service Vulnerability
19567| [87327] Apache Struts CVE-2016-3081 Remote Code Execution Vulnerability
19568| [86622] Apache Stats CVE-2007-0975 Remote Security Vulnerability
19569| [86399] Apache CVE-2007-1743 Local Security Vulnerability
19570| [86397] Apache CVE-2007-1742 Local Security Vulnerability
19571| [86311] Apache Struts CVE-2016-4003 Cross Site Scripting Vulnerability
19572| [86174] Apache Wicket CVE-2015-5347 Cross Site Scripting Vulnerability
19573| [85971] Apache OFBiz CVE-2016-2170 Java Deserialization Remote Code Execution Vulnerability
19574| [85967] Apache OFBiz CVE-2015-3268 HTML Injection Vulnerability
19575| [85759] Apache Jetspeed CVE-2016-2171 Unauthorized Access Vulnerability
19576| [85758] Apache Jetspeed CVE-2016-0712 Cross Site Scripting Vulnerability
19577| [85756] Apache Jetspeed CVE-2016-0710 Multiple SQL Injection Vulnerabilities
19578| [85755] Apache Jetspeed CVE-2016-0711 Mulitple HTML Injection Vulnerabilities
19579| [85754] Apache Jetspeed CVE-2016-0709 Directory Traversal Vulnerability
19580| [85730] Apache Subversion CVE-2015-5343 Integer Overflow Vulnerability
19581| [85691] Apache Ranger CVE-2016-0735 Security Bypass Vulnerability
19582| [85578] Apache ActiveMQ CVE-2010-1244 Cross-Site Request Forgery Vulnerability
19583| [85554] Apache OpenMeetings CVE-2016-2164 Multiple Information Disclosure Vulnerabilities
19584| [85553] Apache OpenMeetings CVE-2016-0783 Information Disclosure Vulnerability
19585| [85552] Apache OpenMeetings CVE-2016-2163 HTML Injection Vulnerability
19586| [85550] Apache OpenMeetings CVE-2016-0784 Directory Traversal Vulnerability
19587| [85386] Apache Hadoop CVE-2015-7430 Local Privilege Escalation Vulnerability
19588| [85377] Apache Qpid Proton Python API CVE-2016-2166 Man in the Middle Security Bypass Vulnerability
19589| [85205] Apache Solr CVE-2015-8796 Cross Site Scripting Vulnerability
19590| [85203] Apache Solr CVE-2015-8795 Mulitple HTML Injection Vulnerabilities
19591| [85163] Apache Geronimo CVE-2008-0732 Local Security Vulnerability
19592| [85131] Apache Struts 'TextParseUtil.translateVariables()' Method Remote Code Execution Vulnerability
19593| [85070] Apache Struts CVE-2016-2162 Cross Site Scripting Vulnerability
19594| [85066] Apache Struts CVE-2016-0785 Remote Code Execution Vulnerability
19595| [84422] Apache TomEE CVE-2016-0779 Unspecified Security Vulnerability
19596| [84321] Apache ActiveMQ CVE-2016-0734 Clickjacking Vulnerability
19597| [84316] Apache ActiveMQ CVE-2016-0782 Multiple Cross Site Scripting Vulnerabilities
19598| [83910] Apache Wicket CVE-2015-7520 Cross Site Scripting Vulnerability
19599| [83423] Apache Xerces-C CVE-2016-0729 Buffer Overflow Vulnerability
19600| [83330] Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability
19601| [83329] Apache Tomcat CVE-2015-5174 Directory Traversal Vulnerability
19602| [83328] Apache Tomcat CVE-2015-5345 Directory Traversal Vulnerability
19603| [83327] Apache Tomcat Security Manager CVE-2016-0714 Remote Code Execution Vulnerability
19604| [83326] Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
19605| [83324] Apache Tomcat Security Manager CVE-2016-0706 Information Disclosure Vulnerability
19606| [83323] Apache Tomcat CVE-2015-5346 Session Fixation Vulnerability
19607| [83259] Apache Hadoop CVE-2015-1776 Information Disclosure Vulnerability
19608| [83243] Apache Solr CVE-2015-8797 Cross Site Scripting Vulnerability
19609| [83119] Apache Sling CVE-2016-0956 Information Disclosure Vulnerability
19610| [83002] Apache CVE-2000-1205 Cross-Site Scripting Vulnerability
19611| [82871] Apache Ranger Authentication Bypass and Security Bypass Vulnerabilities
19612| [82800] Apache CloudStack CVE-2015-3251 Information Disclosure Vulnerability
19613| [82798] Apache CloudStack CVE-2015-3252 Authentication Bypass Vulnerability
19614| [82732] Apache Gallery CVE-2003-0771 Local Security Vulnerability
19615| [82676] Apache CVE-2003-1581 Cross-Site Scripting Vulnerability
19616| [82550] Apache Struts CVE-2015-5209 Security Bypass Vulnerability
19617| [82300] Apache Subversion CVE-2015-5259 Integer Overflow Vulnerability
19618| [82260] Apache Camel CVE-2015-5344 Remote Code Execution Vulnerability
19619| [82234] Apache Hive CVE-2015-7521 Security Bypass Vulnerability
19620| [82082] Apache CVE-1999-0289 Remote Security Vulnerability
19621| [81821] Apache Distribution for Solaris CVE-2007-2080 SQL-Injection Vulnerability
19622| [80696] Apache Camel CVE-2015-5348 Information Disclosure Vulnerability
19623| [80525] Apache CVE-2003-1580 Remote Security Vulnerability
19624| [80354] Drupal Apache Solr Search Module Access Bypass Vulnerability
19625| [80193] Apache CVE-1999-0107 Denial-Of-Service Vulnerability
19626| [79812] Apache Directory Studio CVE-2015-5349 Command Injection Vulnerability
19627| [79744] Apache HBase CVE-2015-1836 Unauthorized Access Vulnerability
19628| [79204] Apache TomEE 'EjbObjectInputStream' Remote Code Execution Vulnerability
19629| [77679] Apache Cordova For Android CVE-2015-8320 Weak Randomization Security Bypass Vulnerability
19630| [77677] Apache Cordova For Android CVE-2015-5256 Security Bypass Vulnerability
19631| [77591] Apache CXF SAML SSO Processing CVE-2015-5253 Security Bypass Vulnerability
19632| [77521] Apache Commons Collections 'InvokerTransformer.java' Remote Code Execution Vulnerability
19633| [77110] Apache HttpComponents HttpClient CVE-2015-5262 Denial of Service Vulnerability
19634| [77086] Apache Ambari CVE-2015-1775 Server Side Request Forgery Security Bypass Vulnerability
19635| [77085] Apache Ambari CVE-2015-3270 Remote Privilege Escalation Vulnerability
19636| [77082] Apache Ambari 'targetURI' Parameter Open Redirection Vulnerability
19637| [77059] Apache Ambari CVE-2015-3186 Cross Site Scripting Vulnerability
19638| [76933] Apache James Server Unspecified Command Execution Vulnerability
19639| [76832] Apache cordova-plugin-file-transfer CVE-2015-5204 HTTP Header Injection Vulnerability
19640| [76625] Apache Struts CVE-2015-5169 Cross Site Scripting Vulnerability
19641| [76624] Apache Struts CVE-2015-2992 Cross Site Scripting Vulnerability
19642| [76522] Apache Tapestry CVE-2014-1972 Security Bypass Vulnerability
19643| [76486] Apache CXF Fediz CVE-2015-5175 Denial of Service Vulnerability
19644| [76452] Apache ActiveMQ CVE-2015-1830 Directory Traversal Vulnerability
19645| [76446] Apache Subversion 'libsvn_fs_fs/tree.c' Denial of Service Vulnerability
19646| [76274] Apache Subversion CVE-2015-3184 Information Disclosure Vulnerability
19647| [76273] Apache Subversion CVE-2015-3187 Information Disclosure Vulnerability
19648| [76272] Apache ActiveMQ CVE-2014-3576 Denial of Service Vulnerability
19649| [76221] Apache Ranger CVE-2015-0266 Access Bypass Vulnerability
19650| [76208] Apache Ranger CVE-2015-0265 JavaScript Code Injection Vulnerability
19651| [76025] Apache ActiveMQ Artemis CVE-2015-3208 XML External Entity Information Disclosure Vulnerability
19652| [75965] Apache HTTP Server CVE-2015-3185 Security Bypass Vulnerability
19653| [75964] Apache HTTP Server CVE-2015-0253 Remote Denial of Service Vulnerability
19654| [75963] Apache HTTP Server CVE-2015-3183 Security Vulnerability
19655| [75940] Apache Struts CVE-2015-1831 Security Bypass Vulnerability
19656| [75919] Apache Groovy CVE-2015-3253 Remote Code Execution Vulnerability
19657| [75338] Apache Storm CVE-2015-3188 Remote Code Execution Vulnerability
19658| [75275] Drupal Apache Solr Real-Time Module Access Bypass Vulnerability
19659| [74866] Apache Cordova For Android CVE-2015-1835 Security Bypass Vulnerability
19660| [74839] Apache Sling API and Sling Servlets CVE-2015-2944 Cross Site Scripting Vulnerability
19661| [74761] Apache Jackrabbit CVE-2015-1833 XML External Entity Information Disclosure Vulnerability
19662| [74686] Apache Ambari '/var/lib/ambari-server/ambari-env.sh' Local Privilege Escalation Vulnerability
19663| [74665] Apache Tomcat CVE-2014-7810 Security Bypass Vulnerability
19664| [74475] Apache Tomcat CVE-2014-0230 Denial of Service Vulnerability
19665| [74423] Apache Struts CVE-2015-0899 Security Bypass Vulnerability
19666| [74338] Apache OpenOffice HWP Filter Memory Corruption Vulnerability
19667| [74265] Apache Tomcat 'mod_jk' CVE-2014-8111 Information Disclosure Vulnerability
19668| [74260] Apache Subversion CVE-2015-0248 Multiple Denial of Service Vulnerabilities
19669| [74259] Apache Subversion 'deadprops.c' Security Bypass Vulnerability
19670| [74204] PHP 'sapi/apache2handler/sapi_apache2.c' Remote Code Execution Vulnerability
19671| [74158] Apache HTTP Server 'protocol.c' Remote Denial of Service Vulnerability
19672| [73954] Apache Flex 'asdoc/templates/index.html' Cross Site Scripting Vulnerability
19673| [73851] Apache2 CVE-2012-0216 Cross-Site Scripting Vulnerability
19674| [73478] Apache Cassandra CVE-2015-0225 Remote Code Execution Vulnerability
19675| [73041] Apache HTTP Server 'mod_lua' Module Denial of Service Vulnerability
19676| [73040] Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
19677| [72809] Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
19678| [72717] Apache Tomcat CVE-2014-0227 Chunk Request Remote Denial Of Service Vulnerability
19679| [72557] Apache WSS4J CVE-2015-0227 Security Bypass Vulnerability
19680| [72553] Apache WSS4J CVE-2015-0226 Information Disclosure Vulnerability
19681| [72513] Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
19682| [72511] Apache ActiveMQ CVE-2014-8110 Multiple Cross Site Scripting Vulnerabilities
19683| [72510] Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
19684| [72508] Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
19685| [72319] Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
19686| [72317] Apache Qpid CVE-2015-0224 Incomplete Fix Multiple Denial of Service Vulnerabilities
19687| [72115] Apache Santuario 'XML Signature Verification' Security Bypass Vulnerability
19688| [72053] Apache HTTP Server 'mod_remoteip.c' IP Address Spoofing Vulnerability
19689| [72030] Apache Qpid CVE-2015-0203 Multiple Denial of Service Vulnerabilities
19690| [71879] Apache Traffic Server 'HttpTransact.cc' Denial of Service Vulnerability
19691| [71726] Apache Subversion CVE-2014-3580 Remote Denial of Service Vulnerability
19692| [71725] Apache Subversion CVE-2014-8108 Remote Denial of Service Vulnerability
19693| [71657] Apache HTTP Server 'mod_proxy_fcgi' Module Denial of Service Vulnerability
19694| [71656] Apache HTTP Server 'mod_cache' Module Denial of Service Vulnerability
19695| [71548] Apache Struts CVE-2014-7809 Security Bypass Vulnerability
19696| [71466] Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
19697| [71353] Apache HTTP Server 'LuaAuthzProvider' Authorization Bypass Vulnerability
19698| [71004] Apache Qpid CVE-2014-3629 XML External Entity Injection Vulnerability
19699| [70970] Apache Traffic Server Cross Site Scripting Vulnerability
19700| [70738] Apache CXF CVE-2014-3584 Denial of Service Vulnerability
19701| [70736] Apache CXF SAML SubjectConfirmation Security Bypass Vulnerability
19702| [69728] Apache Tomcat CVE-2013-4444 Arbitrary File Upload Vulnerability
19703| [69648] Apache POI CVE-2014-3574 Denial Of Service Vulnerability
19704| [69647] Apache POI OpenXML parser CVE-2014-3529 XML External Entity Information Disclosure Vulnerability
19705| [69351] Apache OpenOffice Calc CVE-2014-3524 Command Injection Vulnerability
19706| [69295] Apache Axis Incomplete Fix CVE-2014-3596 SSL Certificate Validation Security Bypass Vulnerability
19707| [69286] Apache OFBiz CVE-2014-0232 Multiple Cross Site Scripting Vulnerabilities
19708| [69258] Apache HttpComponents Incomplete Fix CVE-2014-3577 SSL Validation Security Bypass Vulnerability
19709| [69257] Apache HttpComponents Incomplete Fix SSL Certificate Validation Security Bypass Vulnerability
19710| [69248] Apache HTTP Server CVE-2013-4352 Remote Denial of Service Vulnerability
19711| [69237] Apache Subversion CVE-2014-3522 SSL Certificate Validation Information Disclosure Vulnerability
19712| [69173] Apache Traffic Server CVE-2014-3525 Unspecified Security Vulnerability
19713| [69046] Apache Cordova For Android CVE-2014-3502 Information Disclosure Vulnerability
19714| [69041] Apache Cordova For Android CVE-2014-3501 Security Bypass Vulnerability
19715| [69038] Apache Cordova For Android CVE-2014-3500 Security Bypass Vulnerability
19716| [68995] Apache Subversion CVE-2014-3528 Insecure Authentication Weakness
19717| [68966] Apache Subversion 'irkerbridge.py' Local Privilege Escalation Vulnerability
19718| [68965] Apache Subversion 'svnwcsub.py' Local Privilege Escalation Vulnerability
19719| [68863] Apache HTTP Server 'mod_cache' Module Remote Denial of Service Vulnerability
19720| [68747] Apache HTTP Server CVE-2014-3523 Remote Denial of Service Vulnerability
19721| [68745] Apache HTTP Server CVE-2014-0118 Remote Denial of Service Vulnerability
19722| [68742] Apache HTTP Server CVE-2014-0231 Remote Denial of Service Vulnerability
19723| [68740] Apache HTTP Server CVE-2014-0117 Remote Denial of Service Vulnerability
19724| [68678] Apache HTTP Server 'mod_status' CVE-2014-0226 Remote Code Execution Vulnerability
19725| [68445] Apache CXF UsernameToken Information Disclosure Vulnerability
19726| [68441] Apache CXF SAML Tokens Validation Security Bypass Vulnerability
19727| [68431] Apache Syncope CVE-2014-3503 Insecure Password Generation Weakness
19728| [68229] Apache Harmony PRNG Entropy Weakness
19729| [68111] Apache 'mod_wsgi' Module Privilege Escalation Vulnerability
19730| [68072] Apache Tomcat CVE-2014-0186 Remote Denial of Service Vulnerability
19731| [68039] Apache Hive CVE-2014-0228 Security Bypass Vulnerability
19732| [67673] Apache Tomcat CVE-2014-0095 AJP Request Remote Denial Of Service Vulnerability
19733| [67671] Apache Tomcat CVE-2014-0075 Chunk Request Remote Denial Of Service Vulnerability
19734| [67669] Apache Tomcat CVE-2014-0119 XML External Entity Information Disclosure Vulnerability
19735| [67668] Apache Tomcat CVE-2014-0099 Request Processing Information Disclosure Vulnerability
19736| [67667] Apache Tomcat CVE-2014-0096 XML External Entity Information Disclosure Vulnerability
19737| [67534] Apache 'mod_wsgi' Module CVE-2014-0242 Information Disclosure Vulnerability
19738| [67532] Apache 'mod_wsgi' Module Local Privilege Escalation Vulnerability
19739| [67530] Apache Solr Search Template Cross Site Scripting Vulnerability
19740| [67236] Apache CXF CVE-2014-0109 Remote Denial of Service Vulnerability
19741| [67232] Apache CXF CVE-2014-0110 Denial of Service Vulnerability
19742| [67121] Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
19743| [67081] Apache Struts 'getClass()' Method Security Bypass Vulnerability
19744| [67064] Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
19745| [67013] Apache Zookeeper CVE-2014-0085 Local Information Disclosure Vulnerability
19746| [66998] Apache Archiva CVE-2013-2187 Unspecified Cross Site Scripting Vulnerability
19747| [66991] Apache Archiva CVE-2013-2187 HTML Injection Vulnerability
19748| [66927] Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
19749| [66474] Apache CouchDB Universally Unique IDentifier (UUID) Remote Denial of Service Vulnerability
19750| [66397] Apache Xalan-Java Library CVE-2014-0107 Security Bypass Vulnerability
19751| [66303] Apache HTTP Server Multiple Denial of Service Vulnerabilities
19752| [66041] RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
19753| [65999] Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability
19754| [65967] Apache Cordova File-Transfer Unspecified Security Vulnerability
19755| [65959] Apache Cordova InAppBrowser Remote Privilege Escalation Vulnerability
19756| [65935] Apache Shiro 'login.jsp' Authentication Bypass Vulnerability
19757| [65902] Apache Camel CVE-2014-0003 Remote Code Execution Vulnerability
19758| [65901] Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
19759| [65773] Apache Tomcat CVE-2013-4286 Security Bypass Vulnerability
19760| [65769] Apache Tomcat CVE-2014-0033 Session Fixation Vulnerability
19761| [65768] Apache Tomcat CVE-2013-4590 XML External Entity Information Disclosure Vulnerability
19762| [65767] Apache Tomcat CVE-2013-4322 Incomplete Fix Denial of Service Vulnerability
19763| [65615] Apache ActiveMQ 'refresh' Parameter Cross Site Scripting Vulnerability
19764| [65434] Apache Subversion 'mod_dav_svn' Module SVNListParentPath Denial of Service Vulnerability
19765| [65431] Apache Wicket CVE-2013-2055 Information Disclosure Vulnerability
19766| [65400] Apache Commons FileUpload CVE-2014-0050 Denial Of Service Vulnerability
19767| [64782] Apache CloudStack Virtual Router Component Security Bypass Vulnerability
19768| [64780] Apache CloudStack Unauthorized Access Vulnerability
19769| [64617] Apache Libcloud Digital Ocean API Local Information Disclosure Vulnerability
19770| [64437] Apache Santuario XML Security For JAVA XML Signature Denial of Service Vulnerability
19771| [64427] Apache Solr Multiple XML External Entity Injection Vulnerabilities
19772| [64009] Apache Solr CVE-2013-6408 XML External Entity Injection Vulnerability
19773| [64008] Apache Solr CVE-2013-6407 XML External Entity Injection Vulnerability
19774| [63981] Apache Subversion 'mod_dav_svn' Module Denial of Service Vulnerability
19775| [63966] Apache Subversion CVE-2013-4505 Security Bypass Vulnerability
19776| [63963] Apache Roller CVE-2013-4171 Cross Site Scripting Vulnerability
19777| [63935] Apache Solr 'SolrResourceLoader' Directory Traversal Vulnerability
19778| [63928] Apache Roller CVE-2013-4212 OGNL Expression Injection Remote Code Execution Vulnerability
19779| [63515] Apache Tomcat Manager Component CVE-2013-6357 Cross Site Request Forgery Vulnerability
19780| [63403] Apache Struts Multiple Cross Site Scripting Vulnerabilities
19781| [63400] Apache 'mod_pagespeed' Module Unspecified Cross Site Scripting Vulnerability
19782| [63260] Apache Shindig CVE-2013-4295 XML External Entity Information Disclosure Vulnerability
19783| [63241] Apache Sling 'AbstractAuthenticationFormServlet' Open Redirection Vulnerability
19784| [63174] Apache Commons FileUpload 'DiskFileItem' Class Null Byte Arbitrary File Write Vulnerability
19785| [62939] Apache 'mod_fcgid' Module CVE-2013-4365 Heap Buffer Overflow Vulnerability
19786| [62903] Apache Sling 'deepGetOrCreateNode()' Function Denial Of Service Vulnerability
19787| [62706] Apache Camel CVE-2013-4330 Information Disclosure Vulnerability
19788| [62677] Apache 'mod_accounting' Module CVE-2013-5697 SQL Injection Vulnerability
19789| [62674] TYPO3 Apache Solr Unspecified Cross Site Scripting and PHP Code Execution Vulnerabilities
19790| [62587] Apache Struts CVE-2013-4316 Remote Code Execution Vulnerability
19791| [62584] Apache Struts CVE-2013-4310 Security Bypass Vulnerability
19792| [62266] Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
19793| [61984] Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
19794| [61981] Apache HBase RPC Authentication Man In The Middle Security Bypass Vulnerability
19795| [61638] Apache CloudStack CVE-2013-2136 Multiple Cross Site Scripting Vulnerabilities
19796| [61454] Apache Subversion CVE-2013-4131 Denial Of Service Vulnerability
19797| [61379] Apache HTTP Server CVE-2013-2249 Unspecified Remote Security Vulnerability
19798| [61370] Apache OFBiz CVE-2013-2317 'View Log' Cross Site Scripting Vulnerability
19799| [61369] Apache OFBiz Nested Expression Remote Code Execution Vulnerability
19800| [61196] Apache Struts CVE-2013-2248 Multiple Open Redirection Vulnerabilities
19801| [61189] Apache Struts CVE-2013-2251 Multiple Remote Command Execution Vulnerabilities
19802| [61129] Apache HTTP Server CVE-2013-1896 Remote Denial of Service Vulnerability
19803| [61030] Apache CXF CVE-2013-2160 Multiple Remote Denial of Service Vulnerabilities
19804| [60875] Apache Geronimo RMI Classloader Security Bypass Vulnerability
19805| [60846] Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
19806| [60817] Apache Santuario XML Security for C++ CVE-2013-2210 Heap Buffer Overflow Vulnerability
19807| [60800] Apache Qpid Python Client SSL Certificate Verification Information Disclosure Vulnerability
19808| [60599] Apache Santuario XML Security for C++ CVE-2013-2156 Remote Heap Buffer Overflow Vulnerability
19809| [60595] Apache Santuario XML Security for C++ XML Signature CVE-2013-2155 Denial of Service Vulnerability
19810| [60594] Apache Santuario XML Security for C++ CVE-2013-2154 Stack Buffer Overflow Vulnerability
19811| [60592] Apache Santuario XML Security for C++ XML Signature CVE-2013-2153 Security Bypass Vulnerability
19812| [60534] Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
19813| [60346] Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
19814| [60345] Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
19815| [60267] Apache Subversion CVE-2013-1968 Remote Denial of Service Vulnerability
19816| [60265] Apache Subversion CVE-2013-2088 Command Injection Vulnerability
19817| [60264] Apache Subversion CVE-2013-2112 Remote Denial of Service Vulnerability
19818| [60187] Apache Tomcat DIGEST Authentication CVE-2013-2051 Incomplete Fix Security Weakness
19819| [60186] Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
19820| [60167] Apache Struts 'includeParams' CVE-2013-2115 Incomplete Fix Security Bypass Vulnerability
19821| [60166] Apache Struts 'includeParams' CVE-2013-1966 Security Bypass Vulnerability
19822| [60082] Apache Struts 'ParameterInterceptor' Class OGNL CVE-2013-1965 Security Bypass Vulnerability
19823| [59826] Apache HTTP Server Terminal Escape Sequence in Logs Command Injection Vulnerability
19824| [59799] Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
19825| [59798] Apache Tomcat CVE-2013-2071 Information Disclosure Vulnerability
19826| [59797] Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
19827| [59670] Apache VCL Multiple Input Validation Vulnerabilities
19828| [59464] Apache CloudStack CVE-2013-2758 Hash Information Disclosure Vulnerability
19829| [59463] Apache CloudStack CVE-2013-2756 Authentication Bypass Vulnerability
19830| [59402] Apache ActiveMQ CVE-2013-3060 Information Disclosure and Denial of Service Vulnerability
19831| [59401] Apache ActiveMQ CVE-2012-6551 Denial of Service Vulnerability
19832| [59400] Apache ActiveMQ CVE-2012-6092 Multiple Cross Site Scripting Vulnerabilities
19833| [58898] Apache Subversion CVE-2013-1884 Remote Denial of Service Vulnerability
19834| [58897] Apache Subversion 'mod_dav_svn/lock.c' Remote Denial of Service Vulnerability
19835| [58895] Apache Subversion 'mod_dav_svn' Remote Denial of Service Vulnerability
19836| [58455] Apache Rave User RPC API CVE-2013-1814 Information Disclosure Vulnerability
19837| [58379] Apache Qpid CVE-2012-4446 Authentication Bypass Vulnerability
19838| [58378] Apache Qpid CVE-2012-4460 Denial of Service Vulnerability
19839| [58376] Apache Qpid CVE-2012-4458 Denial of Service Vulnerability
19840| [58337] Apache Qpid CVE-2012-4459 Denial of Service Vulnerability
19841| [58326] Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
19842| [58325] Debian Apache HTTP Server CVE-2013-1048 Symlink Attack Local Privilege Escalation Vulnerability
19843| [58323] Apache Subversion 'svn_fs_file_length()' Remote Denial of Service Vulnerability
19844| [58165] Apache HTTP Server Multiple Cross Site Scripting Vulnerabilities
19845| [58136] Apache Maven CVE-2013-0253 SSL Certificate Validation Security Bypass Vulnerability
19846| [58124] Apache Tomcat 'log/logdir' Directory Insecure File Permissions Vulnerability
19847| [58073] Apache Commons HttpClient CVE-2012-5783 SSL Certificate Validation Security Bypass Vulnerability
19848| [57876] Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
19849| [57874] Apache CXF CVE-2012-5633 Security Bypass Vulnerability
19850| [57463] Apache OFBiz CVE-2013-0177 Multiple Cross Site Scripting Vulnerabilities
19851| [57425] Apache CXF CVE-2012-5786 SSL Certificate Validation Security Bypass Vulnerability
19852| [57321] Apache CouchDB CVE-2012-5650 Cross Site Scripting Vulnerability
19853| [57314] Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
19854| [57267] Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
19855| [57259] Apache CloudStack CVE-2012-5616 Local Information Disclosure Vulnerability
19856| [56814] Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
19857| [56813] Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
19858| [56812] Apache Tomcat CVE-2012-3546 Security Bypass Vulnerability
19859| [56753] Apache Apache HTTP Server 'mod_proxy_ajp Module Denial Of Service Vulnerability
19860| [56686] Apache Tomcat CVE-2012-5568 Denial of Service Vulnerability
19861| [56408] Apache Axis and Axis2/Java SSL Certificate Validation Security Bypass Vulnerability
19862| [56403] Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
19863| [56402] Apache Tomcat CVE-2012-2733 Denial of Service Vulnerability
19864| [56171] Apache OFBiz CVE-2012-3506 Unspecified Security Vulnerability
19865| [55876] Apache CloudStack CVE-2012-4501 Security Bypass Vulnerability
19866| [55628] Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
19867| [55608] Apache Qpid (qpidd) Denial of Service Vulnerability
19868| [55536] Apache 'mod_pagespeed' Module Cross Site Scripting and Security Bypass Vulnerabilities
19869| [55508] Apache Axis2 XML Signature Wrapping Security Vulnerability
19870| [55445] Apache Wicket CVE-2012-3373 Cross Site Scripting Vulnerability
19871| [55346] Apache Struts Cross Site Request Forgery and Denial of Service Vulnerabilities
19872| [55290] Drupal Apache Solr Autocomplete Module Cross Site Scripting Vulnerability
19873| [55165] Apache Struts2 Skill Name Remote Code Execution Vulnerability
19874| [55154] Apache 'mod-rpaf' Module Denial of Service Vulnerability
19875| [55131] Apache HTTP Server HTML-Injection And Information Disclosure Vulnerabilities
19876| [54954] Apache QPID NullAuthenticator Authentication Bypass Vulnerability
19877| [54798] Apache Libcloud Man In The Middle Vulnerability
19878| [54358] Apache Hadoop CVE-2012-3376 Information Disclosure Vulnerability
19879| [54341] Apache Sling CVE-2012-2138 Denial Of Service Vulnerability
19880| [54268] Apache Hadoop Symlink Attack Local Privilege Escalation Vulnerability
19881| [54189] Apache Roller Cross Site Request Forgery Vulnerability
19882| [54187] Apache Roller CVE-2012-2381 Cross Site Scripting Vulnerability
19883| [53880] Apache CXF Child Policies Security Bypass Vulnerability
19884| [53877] Apache CXF Elements Validation Security Bypass Vulnerability
19885| [53676] Apache Commons Compress and Apache Ant CVE-2012-2098 Denial Of Service Vulnerability
19886| [53487] Apache POI CVE-2012-0213 Denial Of Service Vulnerability
19887| [53455] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability
19888| [53305] Apache Qpid CVE-2011-3620 Unauthorized Access Security Bypass Vulnerability
19889| [53046] Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
19890| [53025] Apache OFBiz Unspecified Remote Code Execution Vulnerability
19891| [53023] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
19892| [52939] Apache Hadoop CVE-2012-1574 Unspecified User Impersonation Vulnerability
19893| [52702] Apache Struts2 'XSLTResult.java' Remote Arbitrary File Upload Vulnerability
19894| [52696] Apache Traffic Server HTTP Host Header Handling Heap Based Buffer Overflow Vulnerability
19895| [52680] Apache Wicket 'pageMapName' Parameter Cross Site Scripting Vulnerability
19896| [52679] Apache Wicket Hidden Files Information Disclosure Vulnerability
19897| [52565] Apache 'mod_fcgid' Module Denial Of Service Vulnerability
19898| [52146] TYPO3 Apache Solr Extension Unspecified Cross Site Scripting Vulnerability
19899| [51939] Apache MyFaces 'ln' Parameter Information Disclosure Vulnerability
19900| [51917] Apache APR Hash Collision Denial Of Service Vulnerability
19901| [51902] Apache Struts Multiple HTML Injection Vulnerabilities
19902| [51900] Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
19903| [51886] Apache CXF UsernameToken Policy Validation Security Bypass Vulnerability
19904| [51869] Apache HTTP Server CVE-2011-3639 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
19905| [51706] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
19906| [51705] Apache HTTP Server CVE-2012-0021 mod_log_config Denial Of Service Vulnerability
19907| [51628] Apache Struts 'ParameterInterceptor' Class OGNL (CVE-2011-3923) Security Bypass Vulnerability
19908| [51447] Apache Tomcat Parameter Handling Denial of Service Vulnerability
19909| [51442] Apache Tomcat Request Object Security Bypass Vulnerability
19910| [51407] Apache HTTP Server Scoreboard Local Security Bypass Vulnerability
19911| [51257] Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
19912| [51238] Apache Geronimo Hash Collision Denial Of Service Vulnerability
19913| [51200] Apache Tomcat Hash Collision Denial Of Service Vulnerability
19914| [50940] Apache Struts Session Tampering Security Bypass Vulnerability
19915| [50912] RETIRED: Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
19916| [50904] Apache ActiveMQ Failover Mechanism Remote Denial Of Service Vulnerability
19917| [50848] Apache MyFaces EL Expression Evaluation Security Bypass Vulnerability
19918| [50802] Apache HTTP Server 'mod_proxy' Reverse Proxy Security Bypass Vulnerability
19919| [50639] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
19920| [50603] Apache Tomcat Manager Application Security Bypass Vulnerability
19921| [50494] Apache HTTP Server 'ap_pregsub()' Function Local Privilege Escalation Vulnerability
19922| [49957] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
19923| [49762] Apache Tomcat HTTP DIGEST Authentication Multiple Security Weaknesses
19924| [49728] Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
19925| [49616] Apache HTTP Server CVE-2011-3348 Denial Of Service Vulnerability
19926| [49470] Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
19927| [49353] Apache Tomcat AJP Protocol Security Bypass Vulnerability
19928| [49303] Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability
19929| [49290] Apache Wicket Cross Site Scripting Vulnerability
19930| [49147] Apache Tomcat CVE-2011-2481 Information Disclosure Vulnerability
19931| [49143] Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
19932| [48667] Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability
19933| [48653] Apache 'mod_authnz_external' Module SQL Injection Vulnerability
19934| [48611] Apache XML Security for C++ Signature Key Parsing Denial of Service Vulnerability
19935| [48456] Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability
19936| [48015] Apache Archiva Multiple Cross Site Request Forgery Vulnerabilities
19937| [48011] Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
19938| [47929] Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
19939| [47890] Apache Struts 'javatemplates' Plugin Multiple Cross Site Scripting Vulnerabilities
19940| [47886] Apache Tomcat SecurityConstraints Security Bypass Vulnerability
19941| [47820] Apache APR 'apr_fnmatch()' Denial of Service Vulnerability
19942| [47784] Apache Struts XWork 's:submit' HTML Tag Cross Site Scripting Vulnerability
19943| [47199] Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
19944| [47196] Apache Tomcat Login Constraints Security Bypass Vulnerability
19945| [46974] Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
19946| [46953] Apache MPM-ITK Module Security Weakness
19947| [46734] Subversion 'mod_dav_svn' Apache Server NULL Pointer Dereference Denial Of Service Vulnerability
19948| [46685] Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
19949| [46311] Apache Continuum and Archiva Cross Site Scripting Vulnerability
19950| [46177] Apache Tomcat SecurityManager Security Bypass Vulnerability
19951| [46174] Apache Tomcat HTML Manager Interface HTML Injection Vulnerability
19952| [46166] Apache Tomcat JVM Denial of Service Vulnerability
19953| [46164] Apache Tomcat NIO Connector Denial of Service Vulnerability
19954| [46066] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
19955| [45655] Apache Subversion Server Component Multiple Remote Denial Of Service Vulnerabilities
19956| [45123] Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Vulnerability
19957| [45095] Apache Archiva Cross Site Request Forgery Vulnerability
19958| [45015] Apache Tomcat 'sort' and 'orderBy' Parameters Cross Site Scripting Vulnerabilities
19959| [44900] Apache 'mod_fcgid' Module Unspecified Stack Buffer Overflow Vulnerability
19960| [44616] Apache Shiro Directory Traversal Vulnerability
19961| [44355] Apache MyFaces Encrypted View State Oracle Padding Security Vulnerability
19962| [44068] Apache::AuthenHook Local Information Disclosure Vulnerability
19963| [43862] Apache QPID SSL Connection Denial of Service Vulnerability
19964| [43673] Apache APR-util 'apr_brigade_split_line()' Denial of Service Vulnerability
19965| [43637] Apache XML-RPC SAX Parser Information Disclosure Vulnerability
19966| [43111] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
19967| [42637] Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
19968| [42501] Apache CouchDB Cross Site Request Forgery Vulnerability
19969| [42492] Apache CXF XML DTD Processing Security Vulnerability
19970| [42121] Apache SLMS Insufficient Quoting Cross Site Request Forgery Vulnerability
19971| [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
19972| [41963] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
19973| [41544] Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities
19974| [41076] Apache Axis2 '/axis2/axis2-admin' Session Fixation Vulnerability
19975| [40976] Apache Axis2 Document Type Declaration Processing Security Vulnerability
19976| [40827] Apache 'mod_proxy_http' Timeout Handling Information Disclosure Vulnerability
19977| [40343] Apache Axis2 'xsd' Parameter Directory Traversal Vulnerability
19978| [40327] Apache Axis2 'engagingglobally' Cross-Site Scripting Vulnerability
19979| [39771] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
19980| [39636] Apache ActiveMQ Source Code Information Disclosure Vulnerability
19981| [39635] Apache Tomcat Authentication Header Realm Name Information Disclosure Vulnerability
19982| [39538] Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
19983| [39489] Apache OFBiz Multiple Cross Site Scripting and HTML Injection Vulnerabilities
19984| [39119] Apache ActiveMQ 'createDestination.action' HTML Injection Vulnerability
19985| [38580] Apache Subrequest Handling Information Disclosure Vulnerability
19986| [38494] Apache 'mod_isapi' Memory Corruption Vulnerability
19987| [38491] Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
19988| [37966] Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability
19989| [37945] Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability
19990| [37944] Apache Tomcat WAR File Directory Traversal Vulnerability
19991| [37942] Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability
19992| [37149] Apache Tomcat 404 Error Page Cross Site Scripting Vulnerability
19993| [37027] RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
19994| [36990] Apache HTTP TRACE Cross Site Scripting Vulnerability
19995| [36954] Apache Tomcat Windows Installer Insecure Password Vulnerability
19996| [36889] TYPO3 Apache Solr Search Extension Unspecified Cross Site Scripting Vulnerability
19997| [36596] Apache HTTP Server Solaris Event Port Pollset Support Remote Denial Of Service Vulnerability
19998| [36260] Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
19999| [36254] Apache mod_proxy_ftp Remote Command Injection Vulnerability
20000| [35949] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
20001| [35840] Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
20002| [35623] Apache 'mod_deflate' Remote Denial Of Service Vulnerability
20003| [35565] Apache 'mod_proxy' Remote Denial Of Service Vulnerability
20004| [35416] Apache Tomcat XML Parser Information Disclosure Vulnerability
20005| [35263] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
20006| [35253] Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
20007| [35251] Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
20008| [35221] Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
20009| [35196] Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness
20010| [35193] Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability
20011| [35115] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
20012| [34686] Apache Struts Multiple Cross Site Scripting Vulnerabilities
20013| [34663] Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
20014| [34657] Apache Tiles Cross Site Scripting And Information Disclosure Vulnerabilities
20015| [34562] Apache Geronimo Application Server Multiple Remote Vulnerabilities
20016| [34552] Apache ActiveMQ Web Console Multiple Unspecified HTML Injection Vulnerabilities
20017| [34412] Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability
20018| [34399] Apache Struts Unspecified Cross Site Scripting Vulnerability
20019| [34383] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
20020| [33913] Apache Tomcat POST Data Information Disclosure Vulnerability
20021| [33360] Apache Jackrabbit 'q' Parameter Multiple Cross Site Scripting Vulnerabilities
20022| [33110] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
20023| [32657] Novell NetWare ApacheAdmin Security Bypass Vulnerability
20024| [31805] Apache HTTP Server OS Fingerprinting Unspecified Security Vulnerability
20025| [31761] Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
20026| [31698] Apache Tomcat 'RemoteFilterValve' Security Bypass Vulnerability
20027| [31165] Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
20028| [30560] Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability
20029| [30496] Apache Tomcat 'HttpServletResponse.sendError()' Cross Site Scripting Vulnerability
20030| [30494] Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
20031| [29653] Apache 'mod_proxy_http' Interim Response Denial of Service Vulnerability
20032| [29502] Apache Tomcat Host Manager Cross Site Scripting Vulnerability
20033| [28576] Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
20034| [28484] Apache Tomcat Requests Containing MS-DOS Device Names Information Disclosure Vulnerability
20035| [28483] Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
20036| [28482] Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
20037| [28481] Apache Tomcat Cross-Site Scripting Vulnerability
20038| [28477] Apache Tomcat AJP Connector Information Disclosure Vulnerability
20039| [27752] Apache mod_jk2 Host Header Multiple Stack Based Buffer Overflow Vulnerabilities
20040| [27706] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
20041| [27703] Apache Tomcat Parameter Processing Remote Information Disclosure Vulnerability
20042| [27409] Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
20043| [27365] Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
20044| [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
20045| [27236] Apache 'mod_proxy_balancer' Multiple Vulnerabilities
20046| [27234] Apache 'mod_proxy_ftp' Undefined Charset UTF-7 Cross-Site Scripting Vulnerability
20047| [27006] Apache Tomcat JULI Logging Component Default Security Policy Vulnerability
20048| [26939] Apache HTTP Server Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
20049| [26838] Apache mod_imagemap and mod_imap Cross-Site Scripting Vulnerability
20050| [26762] Apache::AuthCAS Cookie SQL Injection Vulnerability
20051| [26663] Apache HTTP Server 413 Error HTTP Request Method Cross-Site Scripting Weakness
20052| [26287] Apache Geronimo SQLLoginModule Authentication Bypass Vulnerability
20053| [26070] Apache Tomcat WebDav Remote Information Disclosure Vulnerability
20054| [25804] Apache Geronimo Management EJB Security Bypass Vulnerability
20055| [25653] Apache Mod_AutoIndex.C Undefined Charset Cross-Site Scripting Vulnerability
20056| [25531] Apache Tomcat Cal2.JSP Cross-Site Scripting Vulnerability
20057| [25489] Apache HTTP Server Mod_Proxy Denial of Service Vulnerability
20058| [25316] Apache Tomcat Multiple Remote Information Disclosure Vulnerabilities
20059| [25314] Apache Tomcat Host Manager Servlet Cross Site Scripting Vulnerability
20060| [25174] Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
20061| [24999] Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
20062| [24759] MySQLDumper Apache Access Control Authentication Bypass Vulnerability
20063| [24649] Apache HTTP Server Mod_Cache Denial of Service Vulnerability
20064| [24645] Apache HTTP Server Mod_Status Cross-Site Scripting Vulnerability
20065| [24553] Apache Mod_Mem_Cache Information Disclosure Vulnerability
20066| [24524] Apache Tomcat Accept-Language Cross Site Scripting Vulnerability
20067| [24480] Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
20068| [24476] Apache Tomcat JSP Example Web Applications Cross Site Scripting Vulnerability
20069| [24475] Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
20070| [24215] Apache HTTP Server Worker Process Multiple Denial of Service Vulnerabilities
20071| [24147] Apache Tomcat JK Connector Double Encoding Security Bypass Vulnerability
20072| [24058] Apache Tomcat Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
20073| [23687] Apache AXIS Non-Existent WSDL Path Information Disclosure Vulnerability
20074| [23438] Apache HTTPD suEXEC Local Multiple Privilege Escalation Weaknesses
20075| [22960] Apache HTTP Server Tomcat Directory Traversal Vulnerability
20076| [22849] Apache mod_python Output Filter Mode Information Disclosure Vulnerability
20077| [22791] Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability
20078| [22732] Debian Apache Root Shell Local Privilege Escalation Vulnerabilities
20079| [22388] Apache Stats Extract Function Multiple Input Validation Vulnerabilities
20080| [21865] Apache And Microsoft IIS Range Denial of Service Vulnerability
20081| [21214] Apache Mod_Auth_Kerb Off-By-One Denial of Service Vulnerability
20082| [20527] Apache Mod_TCL Remote Format String Vulnerability
20083| [19661] Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
20084| [19447] Apache CGI Script Source Code Information Disclosure Vulnerability
20085| [19204] Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
20086| [19106] Apache Tomcat Information Disclosure Vulnerability
20087| [18138] Apache James SMTP Denial Of Service Vulnerability
20088| [17342] Apache Struts Multiple Remote Vulnerabilities
20089| [17095] Apache Log4Net Denial Of Service Vulnerability
20090| [16916] Apache mod_python FileSession Code Execution Vulnerability
20091| [16710] Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
20092| [16260] Apache Geronimo Multiple Input Validation Vulnerabilities
20093| [16153] Apache mod_auth_pgsql Multiple Format String Vulnerabilities
20094| [16152] Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
20095| [15834] Apache 'mod_imap' Referer Cross-Site Scripting Vulnerability
20096| [15765] Apache James Spooler Memory Leak Denial Of Service Vulnerability
20097| [15762] Apache MPM Worker.C Denial Of Service Vulnerability
20098| [15512] Apache Struts Error Response Cross-Site Scripting Vulnerability
20099| [15413] PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
20100| [15325] Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
20101| [15224] Apache Mod_Auth_Shadow Authentication Bypass Vulnerability
20102| [15177] PHP Apache 2 Local Denial of Service Vulnerability
20103| [14982] ApacheTop Insecure Temporary File Creation Vulnerability
20104| [14721] Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
20105| [14660] Apache CGI Byterange Request Denial of Service Vulnerability
20106| [14366] Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
20107| [14106] Apache HTTP Request Smuggling Vulnerability
20108| [13778] Apache HTPasswd Password Command Line Argument Buffer Overflow Vulnerability
20109| [13777] Apache HTPasswd User Command Line Argument Buffer Overflow Vulnerability
20110| [13756] Apache Tomcat Java Security Manager Bypass Vulnerability
20111| [13537] Apache HTDigest Realm Command Line Argument Buffer Overflow Vulnerability
20112| [12877] Apache mod_ssl ssl_io_filter_cleanup Remote Denial Of Service Vulnerability
20113| [12795] Apache Tomcat Remote Malformed Request Denial Of Service Vulnerability
20114| [12619] Apache Software Foundation Batik Squiggle Browser Access Validation Vulnerability
20115| [12519] Apache mod_python Module Publisher Handler Information Disclosure Vulnerability
20116| [12308] Apache Utilities Insecure Temporary File Creation Vulnerability
20117| [12217] Apache mod_auth_radius Malformed RADIUS Server Reply Integer Overflow Vulnerability
20118| [12181] Mod_DOSEvasive Apache Module Local Insecure Temporary File Creation Vulnerability
20119| [11803] Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
20120| [11471] Apache mod_include Local Buffer Overflow Vulnerability
20121| [11360] Apache mod_ssl SSLCipherSuite Restriction Bypass Vulnerability
20122| [11239] Apache Satisfy Directive Access Control Bypass Vulnerability
20123| [11187] Apache Web Server Remote IPv6 Buffer Overflow Vulnerability
20124| [11185] Apache Mod_DAV LOCK Denial Of Service Vulnerability
20125| [11182] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
20126| [11154] Apache mod_ssl Remote Denial of Service Vulnerability
20127| [11094] Apache mod_ssl Denial Of Service Vulnerability
20128| [10789] Apache mod_userdir Module Information Disclosure Vulnerability
20129| [10736] Apache 'mod_ssl' Log Function Format String Vulnerability
20130| [10619] Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
20131| [10508] Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow Vulnerability
20132| [10478] ClueCentral Apache Suexec Patch Security Weakness
20133| [10355] Apache 'mod_ssl' 'ssl_util_uuencode_binary()' Stack Buffer Overflow Vulnerability
20134| [10212] Apache mod_auth Malformed Password Potential Memory Corruption Vulnerability
20135| [9933] Apache mod_disk_cache Module Client Authentication Credential Storage Weakness
20136| [9930] Apache Error and Access Logs Escape Sequence Injection Vulnerability
20137| [9921] Apache Connection Blocking Denial Of Service Vulnerability
20138| [9885] Apache Mod_Security Module SecFilterScanPost Off-By-One Buffer Overflow Vulnerability
20139| [9874] Apache HTAccess LIMIT Directive Bypass Configuration Error Weakness
20140| [9829] Apache Mod_Access Access Control Rule Bypass Vulnerability
20141| [9826] Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
20142| [9733] Apache Cygwin Directory Traversal Vulnerability
20143| [9599] Apache mod_php Global Variables Information Disclosure Weakness
20144| [9590] Apache-SSL Client Certificate Forging Vulnerability
20145| [9571] Apache mod_digest Client-Supplied Nonce Verification Vulnerability
20146| [9471] Apache mod_perl Module File Descriptor Leakage Vulnerability
20147| [9404] Mod-Auth-Shadow Apache Module Expired User Credential Weakness
20148| [9302] Apache mod_php Module File Descriptor Leakage Vulnerability
20149| [9129] Apache mod_python Module Malformed Query Denial of Service Vulnerability
20150| [8926] Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
20151| [8919] Apache Mod_Security Module Heap Corruption Vulnerability
20152| [8911] Apache Web Server Multiple Module Local Buffer Overflow Vulnerability
20153| [8898] Red Hat Apache Directory Index Default Configuration Error
20154| [8883] Apache Cocoon Directory Traversal Vulnerability
20155| [8824] Apache Tomcat Non-HTTP Request Denial Of Service Vulnerability
20156| [8822] Apache Mod_Throttle Module Local Shared Memory Corruption Vulnerability
20157| [8725] Apache2 MOD_CGI STDERR Denial Of Service Vulnerability
20158| [8707] Apache htpasswd Password Entropy Weakness
20159| [8561] Apache::Gallery Insecure Local File Storage Privilege Escalation Vulnerability
20160| [8287] Mod_Mylo Apache Module REQSTR Buffer Overflow Vulnerability
20161| [8226] Apache HTTP Server Multiple Vulnerabilities
20162| [8138] Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
20163| [8137] Apache Web Server Prefork MPM Denial Of Service Vulnerability
20164| [8136] Macromedia Apache Web Server Encoded Space Source Disclosure Vulnerability
20165| [8135] Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
20166| [8134] Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness
20167| [7768] Apache Tomcat Insecure Directory Permissions Vulnerability
20168| [7725] Apache Basic Authentication Module Valid User Login Denial Of Service Vulnerability
20169| [7723] Apache APR_PSPrintf Memory Corruption Vulnerability
20170| [7448] Apache Mod_Auth_Any Remote Command Execution Vulnerability
20171| [7375] Apache Mod_Access_Referer NULL Pointer Dereference Denial of Service Vulnerability
20172| [7332] Apache Web Server OS2 Filestat Denial Of Service Vulnerability
20173| [7255] Apache Web Server File Descriptor Leakage Vulnerability
20174| [7254] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
20175| [6943] Apache Web Server MIME Boundary Information Disclosure Vulnerability
20176| [6939] Apache Web Server ETag Header Information Disclosure Weakness
20177| [6722] Apache Tomcat Web.XML File Contents Disclosure Vulnerability
20178| [6721] Apache Tomcat Null Byte Directory/File Disclosure Vulnerability
20179| [6720] Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
20180| [6662] Apache Web Server MS-DOS Device Name Denial Of Service Vulnerability
20181| [6661] Apache Web Server Default Script Mapping Bypass Vulnerability
20182| [6660] Apache Web Server Illegal Character HTTP Request File Disclosure Vulnerability
20183| [6659] Apache Web Server MS-DOS Device Name Arbitrary Code Execution Vulnerability
20184| [6562] Apache Tomcat Invoker Servlet File Disclosure Vulnerability
20185| [6320] Apache/Tomcat Mod_JK Chunked Encoding Denial Of Service Vulnerability
20186| [6117] Apache mod_php File Descriptor Leakage Vulnerability
20187| [6065] Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
20188| [5996] Apache AB.C Web Benchmarking Buffer Overflow Vulnerability
20189| [5995] Apache AB.C Web Benchmarking Read_Connection() Buffer Overflow Vulnerability
20190| [5993] Multiple Apache HTDigest Buffer Overflow Vulnerabilities
20191| [5992] Apache HTDigest Insecure Temporary File Vulnerability
20192| [5991] Apache HTDigest Arbitrary Command Execution Vulnerability
20193| [5990] Apache HTPasswd Insecure Temporary File Vulnerability
20194| [5981] Multiple Apache HTDigest and HTPassWD Component Vulnerabilites
20195| [5884] Apache Web Server Scoreboard Memory Segment Overwriting SIGUSR1 Sending Vulnerability
20196| [5847] Apache Server Side Include Cross Site Scripting Vulnerability
20197| [5838] Apache Tomcat 3.2 Directory Disclosure Vulnerability
20198| [5816] Apache 2 mod_dav Denial Of Service Vulnerability
20199| [5791] HP VirtualVault Apache mod_ssl Denial Of Service Vulnerability
20200| [5787] Apache Oversized STDERR Buffer Denial Of Service Vulnerability
20201| [5786] Apache Tomcat DefaultServlet File Disclosure Vulnerability
20202| [5542] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
20203| [5486] Apache 2.0 CGI Path Disclosure Vulnerability
20204| [5485] Apache 2.0 Path Disclosure Vulnerability
20205| [5434] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
20206| [5256] Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
20207| [5194] Apache Tomcat DOS Device Name Cross Site Scripting Vulnerability
20208| [5193] Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
20209| [5067] Apache Tomcat Null Character Malformed Request Denial Of Service Vulnerability
20210| [5054] Apache Tomcat Web Root Path Disclosure Vulnerability
20211| [5033] Apache Chunked-Encoding Memory Corruption Vulnerability
20212| [4995] Apache Tomcat JSP Engine Denial of Service Vulnerability
20213| [4878] Apache Tomcat RealPath.JSP Malformed Request Information Disclosure Vulnerability
20214| [4877] Apache Tomcat Example Files Web Root Path Disclosure Vulnerability
20215| [4876] Apache Tomcat Source.JSP Malformed Request Information Disclosure Vulnerability
20216| [4575] Apache Tomcat Servlet Path Disclosure Vulnerability
20217| [4557] Apache Tomcat System Path Information Disclosure Vulnerability
20218| [4437] Apache Error Message Cross-Site Scripting Vulnerability
20219| [4431] Apache PrintEnv/Test_CGI Script Injection Vulnerability
20220| [4358] Apache Double-Reverse Lookup Log Entry Spoofing Vulnerability
20221| [4335] Apache Win32 Batch File Remote Command Execution Vulnerability
20222| [4292] Oracle 9iAS Apache PL/SQL Module Web Administration Access Vulnerability
20223| [4189] Apache mod_ssl/Apache-SSL Buffer Overflow Vulnerability
20224| [4057] Apache 2 for Windows OPTIONS request Path Disclosure Vulnerability
20225| [4056] Apache 2 for Windows php.exe Path Disclosure Vulnerability
20226| [4037] Oracle 9iAS Apache PL/SQL Module Denial of Service Vulnerability
20227| [4032] Oracle 9iAS Apache PL/SQL Module Multiple Buffer Overflows Vulnerability
20228| [3796] Apache HTTP Request Unexpected Behavior Vulnerability
20229| [3790] Apache Non-Existent Log Directory Denial Of Service Vulnerability
20230| [3786] Apache Win32 PHP.EXE Remote File Disclosure Vulnerability
20231| [3727] Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
20232| [3726] Oracle 9I Application Server PL/SQL Apache Module Buffer Overflow Vulnerability
20233| [3596] Apache Split-Logfile File Append Vulnerability
20234| [3521] Apache mod_usertrack Predictable ID Generation Vulnerability
20235| [3335] Red Hat Linux Apache Remote Username Enumeration Vulnerability
20236| [3316] MacOS X Client Apache Directory Contents Disclosure Vulnerability
20237| [3256] Apache mod_auth_oracle Remote SQL Query Manipulation Vulnerability
20238| [3255] Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
20239| [3254] Apache AuthPG Remote SQL Query Manipulation Vulnerability
20240| [3253] Apache mod_auth_pgsql_sys Remote SQL Query Manipulation Vulnerability
20241| [3251] Apache mod_auth_pgsql Remote SQL Query Manipulation Vulnerability
20242| [3176] Apache Mod ReWrite Rules Bypassing Image Linking Vulnerability
20243| [3169] Apache Server Address Disclosure Vulnerability
20244| [3009] Apache Possible Directory Index Disclosure Vulnerability
20245| [2982] Apache Tomcat Cross-Site Scripting Vulnerability
20246| [2852] MacOS X Client Apache File Protection Bypass Vulnerability
20247| [2740] Apache Web Server HTTP Request Denial of Service Vulnerability
20248| [2518] Apache Tomcat 3.0 Directory Traversal Vulnerability
20249| [2503] Apache Artificially Long Slash Path Directory Listing Vulnerability
20250| [2300] NCSA/Apache httpd ScriptAlias Source Retrieval Vulnerability
20251| [2216] Apache Web Server DoS Vulnerability
20252| [2182] Apache /tmp File Race Vulnerability
20253| [2171] Oracle Apache+WebDB Documented Backdoor Vulnerability
20254| [2060] Apache Web Server with Php 3 File Disclosure Vulnerability
20255| [1821] Apache mod_cookies Buffer Overflow Vulnerability
20256| [1728] Apache Rewrite Module Arbitrary File Disclosure Vulnerability
20257| [1658] SuSE Apache CGI Source Code Viewing Vulnerability
20258| [1656] SuSE Apache WebDAV Directory Listings Vulnerability
20259| [1575] Trustix Apache-SSL RPM Permissions Vulnerability
20260| [1548] Apache Jakarta-Tomcat /admin Context Vulnerability
20261| [1532] Apache Tomcat Snoop Servlet Information Disclosure Vulnerability
20262| [1531] Apache Tomcat 3.1 Path Revealing Vulnerability
20263| [1457] Apache::ASP source.asp Example Script Vulnerability
20264| [1284] Apache HTTP Server (win32) Root Directory Access Vulnerability
20265| [1083] Cobalt Raq Apache .htaccess Disclosure Vulnerability
20266|
20267| IBM X-Force - https://exchange.xforce.ibmcloud.com:
20268| [86258] Apache CloudStack text fields cross-site scripting
20269| [85983] Apache Subversion mod_dav_svn module denial of service
20270| [85875] Apache OFBiz UEL code execution
20271| [85874] Apache OFBiz Webtools View Log screen cross-site scripting
20272| [85871] Apache HTTP Server mod_session_dbd unspecified
20273| [85756] Apache Struts OGNL expression command execution
20274| [85755] Apache Struts DefaultActionMapper class open redirect
20275| [85586] Apache ActiveMQ CVE-2013-1879 cross-site scripting
20276| [85574] Apache HTTP Server mod_dav denial of service
20277| [85573] Apache Struts Showcase App OGNL code execution
20278| [85496] Apache CXF denial of service
20279| [85423] Apache Geronimo RMI classloader code execution
20280| [85326] Apache Santuario XML Security for C++ buffer overflow
20281| [85323] Apache Santuario XML Security for Java spoofing
20282| [85319] Apache Qpid Python client SSL spoofing
20283| [85019] Apache Santuario XML Security for C++ CVE-2013-2156 buffer overflow
20284| [85018] Apache Santuario XML Security for C++ CVE-2013-2155 denial of service
20285| [85017] Apache Santuario XML Security for C++ CVE-2013-2154 buffer overflow
20286| [85016] Apache Santuario XML Security for C++ CVE-2013-2153 spoofing
20287| [84952] Apache Tomcat CVE-2012-3544 denial of service
20288| [84763] Apache Struts CVE-2013-2135 security bypass
20289| [84762] Apache Struts CVE-2013-2134 security bypass
20290| [84719] Apache Subversion CVE-2013-2088 command execution
20291| [84718] Apache Subversion CVE-2013-2112 denial of service
20292| [84717] Apache Subversion CVE-2013-1968 denial of service
20293| [84577] Apache Tomcat security bypass
20294| [84576] Apache Tomcat symlink
20295| [84543] Apache Struts CVE-2013-2115 security bypass
20296| [84542] Apache Struts CVE-2013-1966 security bypass
20297| [84154] Apache Tomcat session hijacking
20298| [84144] Apache Tomcat denial of service
20299| [84143] Apache Tomcat information disclosure
20300| [84111] Apache HTTP Server command execution
20301| [84043] Apache Virtual Computing Lab cross-site scripting
20302| [84042] Apache Virtual Computing Lab cross-site scripting
20303| [83782] Apache CloudStack information disclosure
20304| [83781] Apache CloudStack security bypass
20305| [83720] Apache ActiveMQ cross-site scripting
20306| [83719] Apache ActiveMQ denial of service
20307| [83718] Apache ActiveMQ denial of service
20308| [83263] Apache Subversion denial of service
20309| [83262] Apache Subversion denial of service
20310| [83261] Apache Subversion denial of service
20311| [83259] Apache Subversion denial of service
20312| [83035] Apache mod_ruid2 security bypass
20313| [82852] Apache Qpid federation_tag security bypass
20314| [82851] Apache Qpid qpid::framing::Buffer denial of service
20315| [82758] Apache Rave User RPC API information disclosure
20316| [82663] Apache Subversion svn_fs_file_length() denial of service
20317| [82642] Apache Qpid qpid::framing::Buffer::checkAvailable() denial of service
20318| [82641] Apache Qpid AMQP denial of service
20319| [82626] Apache HTTP Server on Debian GNU/Linux Debian apache2ctl symlink
20320| [82618] Apache Commons FileUpload symlink
20321| [82360] Apache HTTP Server manager interface cross-site scripting
20322| [82359] Apache HTTP Server hostnames cross-site scripting
20323| [82338] Apache Tomcat log/logdir information disclosure
20324| [82328] Apache Maven and Apache Maven Wagon SSL spoofing
20325| [82268] Apache OpenJPA deserialization command execution
20326| [81981] Apache CXF UsernameTokens security bypass
20327| [81980] Apache CXF WS-Security security bypass
20328| [81398] Apache OFBiz cross-site scripting
20329| [81240] Apache CouchDB directory traversal
20330| [81226] Apache CouchDB JSONP code execution
20331| [81225] Apache CouchDB Futon user interface cross-site scripting
20332| [81211] Apache Axis2/C SSL spoofing
20333| [81167] Apache CloudStack DeployVM information disclosure
20334| [81166] Apache CloudStack AddHost API information disclosure
20335| [81165] Apache CloudStack createSSHKeyPair API information disclosure
20336| [80518] Apache Tomcat cross-site request forgery security bypass
20337| [80517] Apache Tomcat FormAuthenticator security bypass
20338| [80516] Apache Tomcat NIO denial of service
20339| [80408] Apache Tomcat replay-countermeasure security bypass
20340| [80407] Apache Tomcat HTTP Digest Access Authentication security bypass
20341| [80317] Apache Tomcat slowloris denial of service
20342| [79984] Apache Commons HttpClient SSL spoofing
20343| [79983] Apache CXF SSL spoofing
20344| [79830] Apache Axis2/Java SSL spoofing
20345| [79829] Apache Axis SSL spoofing
20346| [79809] Apache Tomcat DIGEST security bypass
20347| [79806] Apache Tomcat parseHeaders() denial of service
20348| [79540] Apache OFBiz unspecified
20349| [79487] Apache Axis2 SAML security bypass
20350| [79212] Apache Cloudstack code execution
20351| [78734] Apache CXF SOAP Action security bypass
20352| [78730] Apache Qpid broker denial of service
20353| [78617] Eucalyptus Apache Santuario (XML Security for Java) denial of service
20354| [78563] Apache mod_pagespeed module unspecified cross-site scripting
20355| [78562] Apache mod_pagespeed module security bypass
20356| [78454] Apache Axis2 security bypass
20357| [78452] Websense Web Security and Web Filter Apache Tomcat information disclosure
20358| [78451] Websense Web Security and Web Filter Apache Tomcat cross-site scripting
20359| [78321] Apache Wicket unspecified cross-site scripting
20360| [78183] Apache Struts parameters denial of service
20361| [78182] Apache Struts cross-site request forgery
20362| [78153] Apache Solr Autocomplete module for Drupal autocomplete results cross-site scripting
20363| [77987] mod_rpaf module for Apache denial of service
20364| [77958] Apache Struts skill name code execution
20365| [77914] Apache HTTP Server mod_negotiation module cross-site scripting
20366| [77913] Apache HTTP Server mod_proxy_ajp information disclosure
20367| [77568] Apache Qpid broker security bypass
20368| [77421] Apache Libcloud spoofing
20369| [77059] Oracle Solaris Cluster Apache Tomcat Agent unspecified
20370| [77046] Oracle Solaris Apache HTTP Server information disclosure
20371| [76837] Apache Hadoop information disclosure
20372| [76802] Apache Sling CopyFrom denial of service
20373| [76692] Apache Hadoop symlink
20374| [76535] Apache Roller console cross-site request forgery
20375| [76534] Apache Roller weblog cross-site scripting
20376| [76152] Apache CXF elements security bypass
20377| [76151] Apache CXF child policies security bypass
20378| [75983] MapServer for Windows Apache file include
20379| [75857] Apache Commons Compress and Apache Ant bzip2 denial of service
20380| [75558] Apache POI denial of service
20381| [75545] PHP apache_request_headers() buffer overflow
20382| [75302] Apache Qpid SASL security bypass
20383| [75211] Debian GNU/Linux apache 2 cross-site scripting
20384| [74901] Apache HTTP Server LD_LIBRARY_PATH privilege escalation
20385| [74871] Apache OFBiz FlexibleStringExpander code execution
20386| [74870] Apache OFBiz multiple cross-site scripting
20387| [74750] Apache Hadoop unspecified spoofing
20388| [74319] Apache Struts XSLTResult.java file upload
20389| [74313] Apache Traffic Server header buffer overflow
20390| [74276] Apache Wicket directory traversal
20391| [74273] Apache Wicket unspecified cross-site scripting
20392| [74181] Apache HTTP Server mod_fcgid module denial of service
20393| [73690] Apache Struts OGNL code execution
20394| [73432] Apache Solr extension for TYPO3 unspecified cross-site scripting
20395| [73100] Apache MyFaces in directory traversal
20396| [73096] Apache APR hash denial of service
20397| [73052] Apache Struts name cross-site scripting
20398| [73030] Apache CXF UsernameToken security bypass
20399| [72888] Apache Struts lastName cross-site scripting
20400| [72758] Apache HTTP Server httpOnly information disclosure
20401| [72757] Apache HTTP Server MPM denial of service
20402| [72585] Apache Struts ParameterInterceptor security bypass
20403| [72438] Apache Tomcat Digest security bypass
20404| [72437] Apache Tomcat Digest security bypass
20405| [72436] Apache Tomcat DIGEST security bypass
20406| [72425] Apache Tomcat parameter denial of service
20407| [72422] Apache Tomcat request object information disclosure
20408| [72377] Apache HTTP Server scoreboard security bypass
20409| [72345] Apache HTTP Server HTTP request denial of service
20410| [72229] Apache Struts ExceptionDelegator command execution
20411| [72089] Apache Struts ParameterInterceptor directory traversal
20412| [72088] Apache Struts CookieInterceptor command execution
20413| [72047] Apache Geronimo hash denial of service
20414| [72016] Apache Tomcat hash denial of service
20415| [71711] Apache Struts OGNL expression code execution
20416| [71654] Apache Struts interfaces security bypass
20417| [71620] Apache ActiveMQ failover denial of service
20418| [71617] Apache HTTP Server mod_proxy module information disclosure
20419| [71508] Apache MyFaces EL security bypass
20420| [71445] Apache HTTP Server mod_proxy security bypass
20421| [71203] Apache Tomcat servlets privilege escalation
20422| [71181] Apache HTTP Server ap_pregsub() denial of service
20423| [71093] Apache HTTP Server ap_pregsub() buffer overflow
20424| [70336] Apache HTTP Server mod_proxy information disclosure
20425| [69804] Apache HTTP Server mod_proxy_ajp denial of service
20426| [69472] Apache Tomcat AJP security bypass
20427| [69396] Apache HTTP Server ByteRange filter denial of service
20428| [69394] Apache Wicket multi window support cross-site scripting
20429| [69176] Apache Tomcat XML information disclosure
20430| [69161] Apache Tomcat jsvc information disclosure
20431| [68799] mod_authnz_external module for Apache mysql-auth.pl SQL injection
20432| [68541] Apache Tomcat sendfile information disclosure
20433| [68420] Apache XML Security denial of service
20434| [68238] Apache Tomcat JMX information disclosure
20435| [67860] Apache Rampart/C rampart_timestamp_token_validate security bypass
20436| [67804] Apache Subversion control rules information disclosure
20437| [67803] Apache Subversion control rules denial of service
20438| [67802] Apache Subversion baselined denial of service
20439| [67672] Apache Archiva multiple cross-site scripting
20440| [67671] Apache Archiva multiple cross-site request forgery
20441| [67564] Apache APR apr_fnmatch() denial of service
20442| [67532] IBM WebSphere Application Server org.apache.jasper.runtime.JspWriterImpl.response denial of service
20443| [67515] Apache Tomcat annotations security bypass
20444| [67480] Apache Struts s:submit information disclosure
20445| [67414] Apache APR apr_fnmatch() denial of service
20446| [67356] Apache Struts javatemplates cross-site scripting
20447| [67354] Apache Struts Xwork cross-site scripting
20448| [66676] Apache Tomcat HTTP BIO information disclosure
20449| [66675] Apache Tomcat web.xml security bypass
20450| [66640] Apache HttpComponents HttpClient Proxy-Authorization information disclosure
20451| [66241] Apache HttpComponents information disclosure
20452| [66154] Apache Tomcat ServletSecurity security bypass
20453| [65971] Apache Tomcat ServletSecurity security bypass
20454| [65876] Apache Subversion mod_dav_svn denial of service
20455| [65343] Apache Continuum unspecified cross-site scripting
20456| [65162] Apache Tomcat NIO connector denial of service
20457| [65161] Apache Tomcat javax.servlet.ServletRequest.getLocale() denial of service
20458| [65160] Apache Tomcat HTML Manager interface cross-site scripting
20459| [65159] Apache Tomcat ServletContect security bypass
20460| [65050] Apache CouchDB web-based administration UI cross-site scripting
20461| [64773] Oracle HTTP Server Apache Plugin unauthorized access
20462| [64473] Apache Subversion blame -g denial of service
20463| [64472] Apache Subversion walk() denial of service
20464| [64407] Apache Axis2 CVE-2010-0219 code execution
20465| [63926] Apache Archiva password privilege escalation
20466| [63785] Apache CouchDB LD_LIBRARY_PATH privilege escalation
20467| [63493] Apache Archiva credentials cross-site request forgery
20468| [63477] Apache Tomcat HttpOnly session hijacking
20469| [63422] Apache Tomcat sessionsList.jsp cross-site scripting
20470| [63303] Apache mod_fcgid module fcgid_header_bucket_read() buffer overflow
20471| [62959] Apache Shiro filters security bypass
20472| [62790] Apache Perl cgi module denial of service
20473| [62576] Apache Qpid exchange denial of service
20474| [62575] Apache Qpid AMQP denial of service
20475| [62354] Apache Qpid SSL denial of service
20476| [62235] Apache APR-util apr_brigade_split_line() denial of service
20477| [62181] Apache XML-RPC SAX Parser information disclosure
20478| [61721] Apache Traffic Server cache poisoning
20479| [61202] Apache Derby BUILTIN authentication functionality information disclosure
20480| [61186] Apache CouchDB Futon cross-site request forgery
20481| [61169] Apache CXF DTD denial of service
20482| [61070] Apache Jackrabbit search.jsp SQL injection
20483| [61006] Apache SLMS Quoting cross-site request forgery
20484| [60962] Apache Tomcat time cross-site scripting
20485| [60883] Apache mod_proxy_http information disclosure
20486| [60671] Apache HTTP Server mod_cache and mod_dav denial of service
20487| [60264] Apache Tomcat Transfer-Encoding denial of service
20488| [59746] Apache Axis2 axis2/axis2-admin page session hijacking
20489| [59588] Apache Axis2/Java XML DTD (Document Type Declaration) data denial of service
20490| [59413] Apache mod_proxy_http timeout information disclosure
20491| [59058] Apache MyFaces unencrypted view state cross-site scripting
20492| [58827] Apache Axis2 xsd file include
20493| [58790] Apache Axis2 modules cross-site scripting
20494| [58299] Apache ActiveMQ queueBrowse cross-site scripting
20495| [58169] Apache Tomcat Web Application Manager / Host Manager cross-site request forgery
20496| [58056] Apache ActiveMQ .jsp source code disclosure
20497| [58055] Apache Tomcat realm name information disclosure
20498| [58046] Apache HTTP Server mod_auth_shadow security bypass
20499| [57841] Apache Open For Business Project (OFBiz) subject cross-site scripting
20500| [57840] Apache Open For Business Project (OFBiz) multiple parameters cross-site scripting
20501| [57429] Apache CouchDB algorithms information disclosure
20502| [57398] Apache ActiveMQ Web console cross-site request forgery
20503| [57397] Apache ActiveMQ createDestination.action cross-site scripting
20504| [56653] Apache HTTP Server DNS spoofing
20505| [56652] Apache HTTP Server DNS cross-site scripting
20506| [56625] Apache HTTP Server request header information disclosure
20507| [56624] Apache HTTP Server mod_isapi orphaned callback pointer code execution
20508| [56623] Apache HTTP Server mod_proxy_ajp denial of service
20509| [55941] mod_proxy module for Apache ap_proxy_send_fb() buffer overflow
20510| [55857] Apache Tomcat WAR files directory traversal
20511| [55856] Apache Tomcat autoDeploy attribute security bypass
20512| [55855] Apache Tomcat WAR directory traversal
20513| [55210] Intuit component for Joomla! Apache information disclosure
20514| [54533] Apache Tomcat 404 error page cross-site scripting
20515| [54182] Apache Tomcat admin default password
20516| [53878] Apache Solr Search (solr) extension for TYPO3 unspecified cross-site scripting
20517| [53666] Apache HTTP Server Solaris pollset support denial of service
20518| [53650] Apache HTTP Server HTTP basic-auth module security bypass
20519| [53124] mod_proxy_ftp module for Apache HTTP header security bypass
20520| [53041] mod_proxy_ftp module for Apache denial of service
20521| [52540] Apache Portable Runtime and Apache Portable Utility library multiple buffer overflow
20522| [51953] Apache Tomcat Path Disclosure
20523| [51952] Apache Tomcat Path Traversal
20524| [51951] Apache stronghold-status Information Disclosure
20525| [51950] Apache stronghold-info Information Disclosure
20526| [51949] Apache PHP Source Code Disclosure
20527| [51948] Apache Multiviews Attack
20528| [51946] Apache JServ Environment Status Information Disclosure
20529| [51945] Apache error_log Information Disclosure
20530| [51944] Apache Default Installation Page Pattern Found
20531| [51943] Apache AXIS XML Parser echoheaders.jws Sample Web Service Denial of Service
20532| [51942] Apache AXIS XML External Entity File Retrieval
20533| [51941] Apache AXIS Sample Servlet Information Leak
20534| [51940] Apache access_log Information Disclosure
20535| [51626] Apache mod_deflate denial of service
20536| [51532] mod_proxy module for the Apache HTTP Server stream_reqbody_cl denial of service
20537| [51365] Apache Tomcat RequestDispatcher security bypass
20538| [51273] Apache HTTP Server Incomplete Request denial of service
20539| [51195] Apache Tomcat XML information disclosure
20540| [50994] Apache APR-util xml/apr_xml.c denial of service
20541| [50993] Apache APR-util apr_brigade_vprintf denial of service
20542| [50964] Apache APR-util apr_strmatch_precompile() denial of service
20543| [50930] Apache Tomcat j_security_check information disclosure
20544| [50928] Apache Tomcat AJP denial of service
20545| [50884] Apache HTTP Server XML ENTITY denial of service
20546| [50808] Apache HTTP Server AllowOverride privilege escalation
20547| [50108] Apache Struts s:a tag and s:url tag cross-site scripting
20548| [50059] Apache mod_proxy_ajp information disclosure
20549| [49951] Apache Tiles Expression Language (EL) expressions cross-site scripting
20550| [49925] Apache Geronimo Web Administrative Console cross-site request forgery
20551| [49924] Apache Geronimo console/portal/Server/Monitoring cross-site scripting
20552| [49921] Apache ActiveMQ Web interface cross-site scripting
20553| [49898] Apache Geronimo Services/Repository directory traversal
20554| [49725] Apache Tomcat mod_jk module information disclosure
20555| [49715] Apache mod_perl Apache::Status and Apache2::Status modules cross-site scripting
20556| [49712] Apache Struts unspecified cross-site scripting
20557| [49213] Apache Tomcat cal2.jsp cross-site scripting
20558| [48934] Apache Tomcat POST doRead method information disclosure
20559| [48211] Apache Tomcat header HTTP request smuggling
20560| [48163] libapache2-mod-auth-mysql module for Debian multibyte encoding SQL injection
20561| [48110] Apache Jackrabbit search.jsp and swr.jsp cross-site scripting
20562| [47709] Apache Roller "
20563| [47104] Novell Netware ApacheAdmin console security bypass
20564| [47086] Apache HTTP Server OS fingerprinting unspecified
20565| [46329] Apache Struts FilterDispatcher and DefaultStaticContentLoader class directory traversal
20566| [45791] Apache Tomcat RemoteFilterValve security bypass
20567| [44435] Oracle WebLogic Apache Connector buffer overflow
20568| [44411] Apache Tomcat allowLinking UTF-8 directory traversal
20569| [44223] Apache HTTP Server mod_proxy_ftp cross-site scripting
20570| [44156] Apache Tomcat RequestDispatcher directory traversal
20571| [44155] Apache Tomcat HttpServletResponse.sendError() cross-site scripting
20572| [43885] Oracle WebLogic Server Apache Connector buffer overflow
20573| [42987] Apache HTTP Server mod_proxy module denial of service
20574| [42915] Apache Tomcat JSP files path disclosure
20575| [42914] Apache Tomcat MS-DOS path disclosure
20576| [42892] Apache Tomcat unspecified unauthorized access
20577| [42816] Apache Tomcat Host Manager cross-site scripting
20578| [42303] Apache 403 error cross-site scripting
20579| [41618] Apache-SSL ExpandCert() authentication bypass
20580| [40761] Apache Derby RDBNAM parameter and DatabaseMetaData.getURL information disclosure
20581| [40736] Apache Tomcat HTTP/1.1 connector information disclosure
20582| [40614] Apache mod_jk2 HTTP Host header buffer overflow
20583| [40562] Apache Geronimo init information disclosure
20584| [40478] Novell Web Manager webadmin-apache.conf security bypass
20585| [40411] Apache Tomcat exception handling information disclosure
20586| [40409] Apache Tomcat native (APR based) connector weak security
20587| [40403] Apache Tomcat quotes and %5C cookie information disclosure
20588| [40388] Sun Java Plug-In org.apache.crimson.tree.XmlDocument security bypass
20589| [39893] Apache HTTP Server mod_negotiation HTTP response splitting
20590| [39867] Apache HTTP Server mod_negotiation cross-site scripting
20591| [39804] Apache Tomcat SingleSignOn information disclosure
20592| [39615] Apache HTTP Server mod_proxy_ftp.c UTF-7 cross-site scripting
20593| [39612] Apache HTTP Server mod_proxy_balancer buffer overflow
20594| [39608] Apache HTTP Server balancer manager cross-site request forgery
20595| [39476] Apache mod_proxy_balancer balancer_handler function denial of service
20596| [39474] Apache HTTP Server mod_proxy_balancer cross-site scripting
20597| [39472] Apache HTTP Server mod_status cross-site scripting
20598| [39201] Apache Tomcat JULI logging weak security
20599| [39158] Apache HTTP Server Windows SMB shares information disclosure
20600| [39001] Apache HTTP Server mod_imap and mod_imagemap module cross-site scripting
20601| [38951] Apache::AuthCAS Perl module cookie SQL injection
20602| [38800] Apache HTTP Server 413 error page cross-site scripting
20603| [38211] Apache Geronimo SQLLoginModule authentication bypass
20604| [37243] Apache Tomcat WebDAV directory traversal
20605| [37178] RHSA update for Apache HTTP Server mod_status module cross-site scripting not installed
20606| [37177] RHSA update for Apache HTTP Server Apache child process denial of service not installed
20607| [37119] RHSA update for Apache mod_auth_kerb off-by-one buffer overflow not installed
20608| [37100] RHSA update for Apache and IBM HTTP Server Expect header cross-site scripting not installed
20609| [36782] Apache Geronimo MEJB unauthorized access
20610| [36586] Apache HTTP Server UTF-7 cross-site scripting
20611| [36468] Apache Geronimo LoginModule security bypass
20612| [36467] Apache Tomcat functions.jsp cross-site scripting
20613| [36402] Apache Tomcat calendar cross-site request forgery
20614| [36354] Apache HTTP Server mod_proxy module denial of service
20615| [36352] Apache HTTP Server ap_proxy_date_canon() denial of service
20616| [36336] Apache Derby lock table privilege escalation
20617| [36335] Apache Derby schema privilege escalation
20618| [36006] Apache Tomcat "
20619| [36001] Apache Tomcat Host Manager Servlet alias cross-site scripting
20620| [35999] Apache Tomcat \"
20621| [35795] Apache Tomcat CookieExample cross-site scripting
20622| [35536] Apache Tomcat SendMailServlet example cross-site scripting
20623| [35384] Apache HTTP Server mod_cache module denial of service
20624| [35097] Apache HTTP Server mod_status module cross-site scripting
20625| [35095] Apache HTTP Server Prefork MPM module denial of service
20626| [34984] Apache HTTP Server recall_headers information disclosure
20627| [34966] Apache HTTP Server MPM content spoofing
20628| [34965] Apache HTTP Server MPM information disclosure
20629| [34963] Apache HTTP Server MPM multiple denial of service
20630| [34872] Apache MyFaces Tomahawk autoscroll parameter cross-site scripting
20631| [34869] Apache Tomcat JSP example Web application cross-site scripting
20632| [34868] Apache Tomcat Manager and Host Manager cross-site scripting
20633| [34496] Apache Tomcat JK Connector security bypass
20634| [34377] Apache Tomcat hello.jsp cross-site scripting
20635| [34212] Apache Tomcat SSL configuration security bypass
20636| [34210] Apache Tomcat Accept-Language cross-site scripting
20637| [34209] Apache Tomcat calendar application cross-site scripting
20638| [34207] Apache Tomcat implicit-objects.jsp cross-site scripting
20639| [34167] Apache Axis WSDL file path disclosure
20640| [34068] Apache Tomcat AJP connector information disclosure
20641| [33584] Apache HTTP Server suEXEC privilege escalation
20642| [32988] Apache Tomcat proxy module directory traversal
20643| [32794] Apache Tomcat JK Web Server Connector map_uri_to_worker() buffer overflow
20644| [32708] Debian Apache tty privilege escalation
20645| [32441] ApacheStats extract() PHP call unspecified
20646| [32128] Apache Tomcat default account
20647| [31680] Apache Tomcat RequestParamExample cross-site scripting
20648| [31649] Apache Tomcat Sample Servlet TroubleShooter detected
20649| [31557] BEA WebLogic Server and WebLogic Express Apache proxy plug-in denial of service
20650| [31236] Apache HTTP Server htpasswd.c strcpy buffer overflow
20651| [30456] Apache mod_auth_kerb off-by-one buffer overflow
20652| [29550] Apache mod_tcl set_var() format string
20653| [28620] Apache and IBM HTTP Server Expect header cross-site scripting
20654| [28357] Apache HTTP Server mod_alias script source information disclosure
20655| [28063] Apache mod_rewrite off-by-one buffer overflow
20656| [27902] Apache Tomcat URL information disclosure
20657| [26786] Apache James SMTP server denial of service
20658| [25680] libapache2 /tmp/svn file upload
20659| [25614] Apache Struts lookupMap cross-site scripting
20660| [25613] Apache Struts ActionForm denial of service
20661| [25612] Apache Struts isCancelled() security bypass
20662| [24965] Apache mod_python FileSession command execution
20663| [24716] Apache James spooler memory leak denial of service
20664| [24159] Apache Geronimo Web-Access-Log Viewer cross-site scripting
20665| [24158] Apache Geronimo jsp-examples cross-site scripting
20666| [24030] Apache auth_ldap module multiple format strings
20667| [24008] Apache mod_ssl custom error message denial of service
20668| [24003] Apache mod_auth_pgsql module multiple syslog format strings
20669| [23612] Apache mod_imap referer field cross-site scripting
20670| [23173] Apache Struts error message cross-site scripting
20671| [22942] Apache Tomcat directory listing denial of service
20672| [22858] Apache Multi-Processing Module code allows denial of service
20673| [22602] RHSA-2005:582 updates for Apache httpd not installed
20674| [22520] Apache mod-auth-shadow "
20675| [22466] ApacheTop symlink
20676| [22109] Apache HTTP Server ssl_engine_kernel client certificate validation
20677| [22006] Apache HTTP Server byte-range filter denial of service
20678| [21567] Apache mod_ssl off-by-one buffer overflow
20679| [21195] Apache HTTP Server header HTTP request smuggling
20680| [20383] Apache HTTP Server htdigest buffer overflow
20681| [19681] Apache Tomcat AJP12 request denial of service
20682| [18993] Apache HTTP server check_forensic symlink attack
20683| [18790] Apache Tomcat Manager cross-site scripting
20684| [18349] Apache HTTP server Apple HFS+ filesystem obtain information
20685| [18348] Apache HTTP server Apple HFS+ filesystem .DS_Store and .ht file disclosure
20686| [18347] Apache HTTP server Apple Mac OS X Server mod_digest_apple module could allow an attacker to replay responses
20687| [17961] Apache Web server ServerTokens has not been set
20688| [17930] Apache HTTP Server HTTP GET request denial of service
20689| [17785] Apache mod_include module buffer overflow
20690| [17671] Apache HTTP Server SSLCipherSuite bypass restrictions
20691| [17473] Apache HTTP Server Satisfy directive allows access to resources
20692| [17413] Apache htpasswd buffer overflow
20693| [17384] Apache HTTP Server environment variable configuration file buffer overflow
20694| [17382] Apache HTTP Server IPv6 apr_util denial of service
20695| [17366] Apache HTTP Server mod_dav module LOCK denial of service
20696| [17273] Apache HTTP Server speculative mode denial of service
20697| [17200] Apache HTTP Server mod_ssl denial of service
20698| [16890] Apache HTTP Server server-info request has been detected
20699| [16889] Apache HTTP Server server-status request has been detected
20700| [16705] Apache mod_ssl format string attack
20701| [16524] Apache HTTP Server ap_get_mime_headers_core denial of service
20702| [16387] Apache HTTP Server mod_proxy Content-Length buffer overflow
20703| [16230] Apache HTTP Server PHP denial of service
20704| [16214] Apache mod_ssl ssl_util_uuencode_binary buffer overflow
20705| [15958] Apache HTTP Server authentication modules memory corruption
20706| [15547] Apache HTTP Server mod_disk_cache local information disclosure
20707| [15540] Apache HTTP Server socket starvation denial of service
20708| [15467] Novell GroupWise WebAccess using Apache Web server allows viewing of files on the server
20709| [15422] Apache HTTP Server mod_access information disclosure
20710| [15419] Apache HTTP Server mod_ssl plain HTTP request denial of service
20711| [15293] Apache for Cygwin "
20712| [15065] Apache-SSL has a default password
20713| [15041] Apache HTTP Server mod_digest module could allow an attacker to replay responses
20714| [15015] Apache httpd server httpd.conf could allow a local user to bypass restrictions
20715| [14751] Apache Mod_python output filter information disclosure
20716| [14125] Apache HTTP Server mod_userdir module information disclosure
20717| [14075] Apache HTTP Server mod_php file descriptor leak
20718| [13703] Apache HTTP Server account
20719| [13689] Apache HTTP Server configuration allows symlinks
20720| [13688] Apache HTTP Server configuration allows SSI
20721| [13687] Apache HTTP Server Server: header value
20722| [13685] Apache HTTP Server ServerTokens value
20723| [13684] Apache HTTP Server ServerSignature value
20724| [13672] Apache HTTP Server config allows directory autoindexing
20725| [13671] Apache HTTP Server default content
20726| [13670] Apache HTTP Server config file directive references outside content root
20727| [13668] Apache HTTP Server httpd not running in chroot environment
20728| [13666] Apache HTTP Server CGI directory contains possible command interpreter or compiler
20729| [13664] Apache HTTP Server config file contains ScriptAlias entry
20730| [13663] Apache HTTP Server CGI support modules loaded
20731| [13661] Apache HTTP Server config file contains AddHandler entry
20732| [13660] Apache HTTP Server 500 error page not CGI script
20733| [13659] Apache HTTP Server 413 error page not CGI script
20734| [13658] Apache HTTP Server 403 error page not CGI script
20735| [13657] Apache HTTP Server 401 error page not CGI script
20736| [13552] Apache HTTP Server mod_cgid module information disclosure
20737| [13550] Apache GET request directory traversal
20738| [13516] Apache Cocoon XMLForm and JXForm could allow execution of code
20739| [13499] Apache Cocoon directory traversal allows downloading of boot.ini file
20740| [13429] Apache Tomcat non-HTTP request denial of service
20741| [13400] Apache HTTP server mod_alias and mod_rewrite buffer overflow
20742| [13295] Apache weak password encryption
20743| [13254] Apache Tomcat .jsp cross-site scripting
20744| [13125] Apache::Gallery Inline::C could allow arbitrary code execution
20745| [13086] Apache Jakarta Tomcat mod_jk format string allows remote access
20746| [12681] Apache HTTP Server mod_proxy could allow mail relaying
20747| [12662] Apache HTTP Server rotatelogs denial of service
20748| [12554] Apache Tomcat stores password in plain text
20749| [12553] Apache HTTP Server redirects and subrequests denial of service
20750| [12552] Apache HTTP Server FTP proxy server denial of service
20751| [12551] Apache HTTP Server prefork MPM denial of service
20752| [12550] Apache HTTP Server weaker than expected encryption
20753| [12549] Apache HTTP Server type-map file denial of service
20754| [12206] Apache Tomcat /opt/tomcat directory insecure permissions
20755| [12102] Apache Jakarta Tomcat MS-DOS device name request denial of service
20756| [12091] Apache HTTP Server apr_password_validate denial of service
20757| [12090] Apache HTTP Server apr_psprintf code execution
20758| [11804] Apache HTTP Server mod_access_referer denial of service
20759| [11750] Apache HTTP Server could leak sensitive file descriptors
20760| [11730] Apache HTTP Server error log and access log terminal escape sequence injection
20761| [11703] Apache long slash path allows directory listing
20762| [11695] Apache HTTP Server LF (Line Feed) denial of service
20763| [11694] Apache HTTP Server filestat.c denial of service
20764| [11438] Apache HTTP Server MIME message boundaries information disclosure
20765| [11412] Apache HTTP Server error log terminal escape sequence injection
20766| [11196] Apache Tomcat examples and ROOT Web applications cross-site scripting
20767| [11195] Apache Tomcat web.xml could be used to read files
20768| [11194] Apache Tomcat URL appended with a null character could list directories
20769| [11139] Apache HTTP Server mass virtual hosting with mod_rewrite or mod_vhost_alias could allow an attacker to obtain files
20770| [11126] Apache HTTP Server illegal character file disclosure
20771| [11125] Apache HTTP Server DOS device name HTTP POST code execution
20772| [11124] Apache HTTP Server DOS device name denial of service
20773| [11088] Apache HTTP Server mod_vhost_alias CGI source disclosure
20774| [10938] Apache HTTP Server printenv test CGI cross-site scripting
20775| [10771] Apache Tomcat mod_jk module multiple HTTP GET request buffer overflow
20776| [10575] Apache mod_php module could allow an attacker to take over the httpd process
20777| [10499] Apache HTTP Server WebDAV HTTP POST view source
20778| [10457] Apache HTTP Server mod_ssl "
20779| [10415] Apache HTTP Server htdigest insecure system() call could allow command execution
20780| [10414] Apache HTTP Server htdigest multiple buffer overflows
20781| [10413] Apache HTTP Server htdigest temporary file race condition
20782| [10412] Apache HTTP Server htpasswd temporary file race condition
20783| [10376] Apache Tomcat invoker servlet used in conjunction with the default servlet reveals source code
20784| [10348] Apache Tomcat HTTP GET request DOS device reference could cause a denial of service
20785| [10281] Apache HTTP Server ab.c ApacheBench long response buffer overflow
20786| [10280] Apache HTTP Server shared memory scorecard overwrite
20787| [10263] Apache Tomcat mod_jk or mod_jserv connector directory disclosure
20788| [10241] Apache HTTP Server Host: header cross-site scripting
20789| [10230] Slapper worm variants A, B, and C target OpenSSL/Apache systems
20790| [10208] Apache HTTP Server mod_dav denial of service
20791| [10206] HP VVOS Apache mod_ssl denial of service
20792| [10200] Apache HTTP Server stderr denial of service
20793| [10175] Apache Tomcat org.apache.catalina.servlets.DefaultServlet reveals source code
20794| [10169] Slapper worm variant (Slapper.C) targets OpenSSL/Apache systems
20795| [10154] Slapper worm variant (Slapper.B) targets OpenSSL/Apache systems
20796| [10098] Slapper worm targets OpenSSL/Apache systems
20797| [9876] Apache HTTP Server cgi/cgid request could disclose the path to a requested script
20798| [9875] Apache HTTP Server .var file request could disclose installation path
20799| [9863] Apache Tomcat web.xml file could allow a remote attacker to bypass restrictions
20800| [9808] Apache HTTP Server non-Unix version URL encoded directory traversal
20801| [9623] Apache HTTP Server ap_log_rerror() path disclosure
20802| [9520] Apache Tomcat /servlet/ mapping cross-site scripting
20803| [9415] Apache HTTP Server mod_ssl .htaccess off-by-one buffer overflow
20804| [9396] Apache Tomcat null character to threads denial of service
20805| [9394] Apache Tomcat HTTP request for LPT9 reveals Web root path
20806| [9249] Apache HTTP Server chunked encoding heap buffer overflow
20807| [9208] Apache Tomcat sample file requests could reveal directory listing and path to Web root directory
20808| [8932] Apache Tomcat example class information disclosure
20809| [8633] Apache HTTP Server with mod_rewrite could allow an attacker to bypass directives
20810| [8629] Apache HTTP Server double-reverse DNS lookup spoofing
20811| [8589] Apache HTTP Server for Windows DOS batch file remote command execution
20812| [8457] Oracle9i Application Server Apache PL/SQL HTTP Location header buffer overflow
20813| [8455] Oracle9i Application Server default installation could allow an attacker to access certain Apache Services
20814| [8400] Apache HTTP Server mod_frontpage buffer overflows
20815| [8326] Apache HTTP Server multiple MIME headers (sioux) denial of service
20816| [8308] Apache "
20817| [8275] Apache HTTP Server with Multiviews enabled could disclose directory contents
20818| [8119] Apache and PHP OPTIONS request reveals "
20819| [8054] Apache is running on the system
20820| [8029] Mandrake Linux default Apache configuration could allow an attacker to browse files and directories
20821| [8027] Mandrake Linux default Apache configuration has remote management interface enabled
20822| [8026] Mandrake Linux Apache sample programs could disclose sensitive information about the server
20823| [7836] Apache HTTP Server log directory denial of service
20824| [7815] Apache for Windows "
20825| [7810] Apache HTTP request could result in unexpected behavior
20826| [7599] Apache Tomcat reveals installation path
20827| [7494] Apache "
20828| [7419] Apache Web Server could allow remote attackers to overwrite .log files
20829| [7363] Apache Web Server hidden HTTP requests
20830| [7249] Apache mod_proxy denial of service
20831| [7129] Linux with Apache Web server could allow an attacker to determine if a specified username exists
20832| [7103] Apple Mac OS X used with Apache Web server could disclose directory contents
20833| [7059] Apache "
20834| [7057] Apache "
20835| [7056] Apache "
20836| [7055] Apache "
20837| [7054] Apache "
20838| [6997] Apache Jakarta Tomcat error message may reveal information
20839| [6971] Apache Jakarta Tomcat may reveal JSP source code with missing HTTP protocol specification
20840| [6970] Apache crafted HTTP request could reveal the internal IP address
20841| [6921] Apache long slash path allows directory listing
20842| [6687] Apple Mac OS X used with Apache Web server could allow arbitrary file disclosure
20843| [6527] Apache Web Server for Windows and OS2 denial of service
20844| [6316] Apache Jakarta Tomcat may reveal JSP source code
20845| [6305] Apache Jakarta Tomcat directory traversal
20846| [5926] Linux Apache symbolic link
20847| [5659] Apache Web server discloses files when used with php script
20848| [5310] Apache mod_rewrite allows attacker to view arbitrary files
20849| [5204] Apache WebDAV directory listings
20850| [5197] Apache Web server reveals CGI script source code
20851| [5160] Apache Jakarta Tomcat default installation
20852| [5099] Trustix Secure Linux installs Apache with world writable access
20853| [4968] Apache Jakarta Tomcat snoop servlet gives out information which could be used in attack
20854| [4967] Apache Jakarta Tomcat 404 error reveals the pathname of the requested file
20855| [4931] Apache source.asp example file allows users to write to files
20856| [4575] IBM HTTP Server running Apache allows users to directory listing and file retrieval
20857| [4205] Apache Jakarta Tomcat delivers file contents
20858| [2084] Apache on Debian by default serves the /usr/doc directory
20859| [1630] MessageMedia UnityMail and Apache Web server MIME header flood denial of service
20860| [697] Apache HTTP server beck exploit
20861| [331] Apache cookies buffer overflow
20862|
20863| Exploit-DB - https://www.exploit-db.com:
20864| [31130] Apache Tomcat <= 6.0.15 Cookie Quote Handling Remote Information Disclosure Vulnerability
20865| [31052] Apache <= 2.2.6 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
20866| [30901] Apache HTTP Server 2.2.6 Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
20867| [30835] Apache HTTP Server <= 2.2.4 413 Error HTTP Request Method Cross-Site Scripting Weakness
20868| [30563] Apache Tomcat <= 5.5.15 Cal2.JSP Cross-Site Scripting Vulnerability
20869| [30496] Apache Tomcat <= 6.0.13 Cookie Handling Quote Delimiter Session ID Disclosure
20870| [30495] Apache Tomcat <= 6.0.13 Host Manager Servlet Cross Site Scripting Vulnerability
20871| [30191] Apache MyFaces Tomahawk JSF Framework 1.1.5 Autoscroll Parameter Cross Site Scripting Vulnerability
20872| [30189] Apache Tomcat <= 6.0.13 JSP Example Web Applications Cross Site Scripting Vulnerability
20873| [30052] Apache Tomcat 6.0.10 Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
20874| [29930] Apache AXIS 1.0 Non-Existent WSDL Path Information Disclosure Vulnerability
20875| [29859] Apache Roller OGNL Injection
20876| [29739] Apache HTTP Server Tomcat 5.x/6.0.x Directory Traversal Vulnerability
20877| [29435] Apache Tomcat 5.5.25 - CSRF Vulnerabilities
20878| [29316] Apache + PHP 5.x - Remote Code Execution (Multithreaded Scanner) (2)
20879| [29290] Apache / PHP 5.x Remote Code Execution Exploit
20880| [28713] Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object RCE
20881| [28424] Apache 2.x HTTP Server Arbitrary HTTP Request Headers Security Weakness
20882| [28365] Apache 2.2.2 CGI Script Source Code Information Disclosure Vulnerability
20883| [28254] Apache Tomcat 5 Information Disclosure Vulnerability
20884| [27915] Apache James 2.2 SMTP Denial of Service Vulnerability
20885| [27397] Apache suEXEC Privilege Elevation / Information Disclosure
20886| [27135] Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
20887| [27096] Apache Geronimo 1.0 Error Page XSS
20888| [27095] Apache Tomcat / Geronimo 1.0 Sample Script cal2.jsp time Parameter XSS
20889| [26710] Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4 - Denial of Service
20890| [26542] Apache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability
20891| [25986] Plesk Apache Zeroday Remote Exploit
20892| [25980] Apache Struts includeParams Remote Code Execution
20893| [25625] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (2)
20894| [25624] Apache 1.3.x HTDigest Realm Command Line Argument Buffer Overflow Vulnerability (1)
20895| [24874] Apache Struts ParametersInterceptor Remote Code Execution
20896| [24744] Apache Rave 0.11 - 0.20 - User Information Disclosure
20897| [24694] Apache 1.3.x mod_include Local Buffer Overflow Vulnerability
20898| [24590] Apache 2.0.x mod_ssl Remote Denial of Service Vulnerability
20899| [23751] Apache Cygwin 1.3.x/2.0.x Directory Traversal Vulnerability
20900| [23581] Apache 2.0.4x mod_perl Module File Descriptor Leakage Vulnerability
20901| [23482] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (2)
20902| [23481] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (1)
20903| [23296] Red Hat Apache 2.0.40 Directory Index Default Configuration Error
20904| [23282] apache cocoon 2.14/2.2 - Directory Traversal vulnerability
20905| [23245] Apache Tomcat 4.0.x Non-HTTP Request Denial of Service Vulnerability
20906| [23119] Apache::Gallery 0.4/0.5/0.6 Insecure Local File Storage Privilege Escalation Vulnerability
20907| [22505] Apache Mod_Access_Referer 1.0.2 NULL Pointer Dereference Denial of Service Vulnerability
20908| [22205] Apache Tomcat 3.x Null Byte Directory/File Disclosure Vulnerability
20909| [22191] Apache Web Server 2.0.x MS-DOS Device Name Denial of Service Vulnerability
20910| [22068] Apache 1.3.x,Tomcat 4.0.x/4.1.x Mod_JK Chunked Encoding Denial of Service Vulnerability
20911| [21885] Apache 1.3/2.0.x Server Side Include Cross Site Scripting Vulnerability
20912| [21882] Apache Tomcat 3.2 Directory Disclosure Vulnerability
20913| [21854] Apache 2.0.39/40 Oversized STDERR Buffer Denial of Service Vulnerability
20914| [21853] Apache Tomcat 3/4 DefaultServlet File Disclosure Vulnerability
20915| [21734] Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
20916| [21719] Apache 2.0 Path Disclosure Vulnerability
20917| [21697] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
20918| [21605] Apache Tomcat 4.0.3 DoS Device Name Cross Site Scripting Vulnerability
20919| [21604] Apache Tomcat 4.0.3 Servlet Mapping Cross Site Scripting Vulnerability
20920| [21560] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (2)
20921| [21559] Apache 1.x/2.0.x Chunked-Encoding Memory Corruption Vulnerability (1)
20922| [21534] Apache Tomcat 3/4 JSP Engine Denial of Service Vulnerability
20923| [21492] Apache Tomcat 3.2.3/3.2.4 RealPath.JSP Malformed Request Information Disclosure
20924| [21491] Apache Tomcat 3.2.3/3.2.4 Example Files Web Root Path Disclosure
20925| [21490] Apache Tomcat 3.2.3/3.2.4 Source.JSP Malformed Request Information Disclosure
20926| [21412] Apache Tomcat 4.0/4.1 Servlet Path Disclosure Vulnerability
20927| [21350] Apache Win32 1.3.x/2.0.x Batch File Remote Command Execution Vulnerability
20928| [21204] Apache 1.3.20 Win32 PHP.EXE Remote File Disclosure Vulnerability
20929| [21112] Red Hat Linux 7.0 Apache Remote Username Enumeration Vulnerability
20930| [21067] Apache 1.0/1.2/1.3 Server Address Disclosure Vulnerability
20931| [21002] Apache 1.3 Possible Directory Index Disclosure Vulnerability
20932| [20911] Apache 1.3.14 Mac File Protection Bypass Vulnerability
20933| [20716] apache tomcat 3.0 - Directory Traversal vulnerability
20934| [20695] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (4)
20935| [20694] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (3)
20936| [20693] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (2)
20937| [20692] Apache 1.3 Artificially Long Slash Path Directory Listing Vulnerability (1)
20938| [20595] NCSA 1.3/1.4.x/1.5,Apache httpd 0.8.11/0.8.14 ScriptAlias Source Retrieval Vulnerability
20939| [20558] Apache 1.2 Web Server DoS Vulnerability
20940| [20466] Apache 1.3 Web Server with Php 3 File Disclosure Vulnerability
20941| [20435] Apache 0.8.x/1.0.x,NCSA httpd 1.x test-cgi Directory Listing Vulnerability
20942| [20272] Apache 1.2.5/1.3.1,UnityMail 2.0 MIME Header DoS Vulnerability
20943| [20210] Apache 1.3.12 WebDAV Directory Listings Vulnerability
20944| [20131] Apache Tomcat 3.1 Path Revealing Vulnerability
20945| [19975] Apache 1.3.6/1.3.9/1.3.11/1.3.12/1.3.20 Root Directory Access Vulnerability
20946| [19828] Cobalt RaQ 2.0/3.0 Apache .htaccess Disclosure Vulnerability
20947| [19536] Apache <= 1.1,NCSA httpd <= 1.5.2,Netscape Server 1.12/1.1/2.0 a nph-test-cgi Vulnerability
20948| [19231] PHP apache_request_headers Function Buffer Overflow
20949| [18984] Apache Struts <= 2.2.1.1 - Remote Command Execution
20950| [18897] Oracle Weblogic Apache Connector POST Request Buffer Overflow
20951| [18619] Apache Tomcat Remote Exploit (PUT Request) and Account Scanner
20952| [18452] Apache Struts Multiple Persistent Cross-Site Scripting Vulnerabilities
20953| [18442] Apache httpOnly Cookie Disclosure
20954| [18329] Apache Struts2 <= 2.3.1 - Multiple Vulnerabilities
20955| [18221] Apache HTTP Server Denial of Service
20956| [17969] Apache mod_proxy Reverse Proxy Exposure Vulnerability PoC
20957| [17696] Apache httpd Remote Denial of Service (memory exhaustion)
20958| [17691] Apache Struts < 2.2.0 - Remote Command Execution
20959| [16798] Apache mod_jk 1.2.20 Buffer Overflow
20960| [16782] Apache Win32 Chunked Encoding
20961| [16752] Apache module mod_rewrite LDAP protocol Buffer Overflow
20962| [16317] Apache Tomcat Manager Application Deployer Authenticated Code Execution
20963| [15710] Apache Archiva 1.0 - 1.3.1 CSRF Vulnerability
20964| [15319] Apache 2.2 (Windows) Local Denial of Service
20965| [14617] Apache JackRabbit 2.0.0 webapp XPath Injection
20966| [14489] Apache Tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
20967| [12721] Apache Axis2 1.4.1 - Local File Inclusion Vulnerability
20968| [12689] Authenticated Cross-Site Scripting Vulnerability (XSS) within Apache Axis2 administration console
20969| [12343] Apache Tomcat 5.5.0 to 5.5.29 & 6.0.0 to 6.0.26 - Information Disclosure Vulnerability
20970| [12330] Apache OFBiz - Multiple XSS
20971| [12264] Apache OFBiz - FULLADMIN Creator PoC Payload
20972| [12263] Apache OFBiz - SQL Remote Execution PoC Payload
20973| [11662] Apache Spamassassin Milter Plugin Remote Root Command Execution
20974| [11650] Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit
20975| [10811] Joomla.Tutorials GHDB: Apache directory listing Download Vulnerability
20976| [10292] Apache Tomcat 3.2.1 - 404 Error Page Cross Site Scripting Vulnerability
20977| [9995] Apache Tomcat Form Authentication Username Enumeration Weakness
20978| [9994] Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
20979| [9993] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
20980| [8842] Apache mod_dav / svn Remote Denial of Service Exploit
20981| [8458] Apache Geronimo <= 2.1.3 - Multiple Directory Traversal Vulnerabilities
20982| [7264] Apache Tomcat runtime.getRuntime().exec() Privilege Escalation (win)
20983| [6229] apache tomcat < 6.0.18 utf8 - Directory Traversal vulnerability
20984| [6100] Apache mod_jk 1.2.19 Remote Buffer Overflow Exploit (win32)
20985| [6089] Bea Weblogic Apache Connector Code Exec / Denial of Service Exploit
20986| [5386] Apache Tomcat Connector jk2-2.0.2 (mod_jk2) Remote Overflow Exploit
20987| [5330] Apache 2.0 mod_jk2 2.0.2 - Remote Buffer Overflow Exploit (win32)
20988| [4552] Apache Tomcat (webdav) Remote File Disclosure Exploit (ssl support)
20989| [4530] Apache Tomcat (webdav) Remote File Disclosure Exploit
20990| [4162] Apache Tomcat Connector (mod_jk) Remote Exploit (exec-shield)
20991| [4093] Apache mod_jk 1.2.19/1.2.20 Remote Buffer Overflow Exploit
20992| [3996] Apache 2.0.58 mod_rewrite Remote Overflow Exploit (win2k3)
20993| [3680] Apache Mod_Rewrite Off-by-one Remote Overflow Exploit (win32)
20994| [3384] Ubuntu/Debian Apache 1.3.33/1.3.34 (CGI TTY) Local Root Exploit
20995| [2237] Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
20996| [2061] Apache Tomcat < 5.5.17 Remote Directory Listing Vulnerability
20997| [1056] Apache <= 2.0.49 Arbitrary Long HTTP Headers Denial of Service
20998| [855] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit
20999| [764] Apache OpenSSL - Remote Exploit (Multiple Targets) (OpenFuckV2.c)
21000| [587] Apache <= 1.3.31 mod_include Local Buffer Overflow Exploit
21001| [466] htpasswd Apache 1.3.31 - Local Exploit
21002| [371] Apache HTTPd Arbitrary Long HTTP Headers DoS (c version)
21003| [360] Apache HTTPd Arbitrary Long HTTP Headers DoS
21004| [132] Apache 1.3.x - 2.0.48 - mod_userdir Remote Users Disclosure Exploit
21005| [126] Apache mod_gzip (with debug_mode) <= 1.2.26.1a Remote Exploit
21006| [67] Apache 1.3.x mod_mylo Remote Code Execution Exploit
21007| [38] Apache <= 2.0.45 APR Remote Exploit -Apache-Knacker.pl
21008| [34] Webfroot Shoutbox < 2.32 (Apache) Remote Exploit
21009| [11] Apache <= 2.0.44 Linux Remote Denial of Service Exploit
21010| [9] Apache HTTP Server 2.x Memory Leak Exploit
21011|
21012| OpenVAS (Nessus) - http://www.openvas.org:
21013| [902924] Apache Struts2 Showcase Skill Name Remote Code Execution Vulnerability
21014| [902837] PHP 'apache_request_headers()' Function Buffer Overflow Vulnerability (Windows)
21015| [902830] Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
21016| [902664] Apache Traffic Server HTTP Host Header Denial of Service Vulnerability
21017| [901203] Apache httpd Web Server Range Header Denial of Service Vulnerability
21018| [901110] Apache ActiveMQ Source Code Information Disclosure Vulnerability
21019| [901105] Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
21020| [900842] Apache 'mod_proxy_ftp' Module Command Injection Vulnerability (Linux)
21021| [900841] Apache 'mod_proxy_ftp' Module Denial Of Service Vulnerability (Linux)
21022| [900573] Apache APR-Utils XML Parser Denial of Service Vulnerability
21023| [900572] Apache APR-Utils Multiple Denial of Service Vulnerabilities
21024| [900571] Apache APR-Utils Version Detection
21025| [900499] Apache mod_proxy_ajp Information Disclosure Vulnerability
21026| [900496] Apache Tiles Multiple XSS Vulnerability
21027| [900493] Apache Tiles Version Detection
21028| [900107] Apache mod_proxy_ftp Wildcard Characters XSS Vulnerability
21029| [900021] Apache Tomcat Cross-Site Scripting and Security Bypass Vulnerabilities
21030| [880086] CentOS Update for apache CESA-2008:0004-01 centos2 i386
21031| [870175] RedHat Update for apache RHSA-2008:0004-01
21032| [864591] Fedora Update for apache-poi FEDORA-2012-10835
21033| [864383] Fedora Update for apache-commons-compress FEDORA-2012-8428
21034| [864280] Fedora Update for apache-commons-compress FEDORA-2012-8465
21035| [864250] Fedora Update for apache-poi FEDORA-2012-7683
21036| [864249] Fedora Update for apache-poi FEDORA-2012-7686
21037| [863993] Fedora Update for apache-commons-daemon FEDORA-2011-10880
21038| [863466] Fedora Update for apache-commons-daemon FEDORA-2011-10936
21039| [855821] Solaris Update for Apache 1.3 122912-19
21040| [855812] Solaris Update for Apache 1.3 122911-19
21041| [855737] Solaris Update for Apache 1.3 122911-17
21042| [855731] Solaris Update for Apache 1.3 122912-17
21043| [855695] Solaris Update for Apache 1.3 122911-16
21044| [855645] Solaris Update for Apache 1.3 122912-16
21045| [855587] Solaris Update for kernel update and Apache 108529-29
21046| [855566] Solaris Update for Apache 116973-07
21047| [855531] Solaris Update for Apache 116974-07
21048| [855524] Solaris Update for Apache 2 120544-14
21049| [855494] Solaris Update for Apache 1.3 122911-15
21050| [855478] Solaris Update for Apache Security 114145-11
21051| [855472] Solaris Update for Apache Security 113146-12
21052| [855179] Solaris Update for Apache 1.3 122912-15
21053| [855147] Solaris Update for kernel update and Apache 108528-29
21054| [855077] Solaris Update for Apache 2 120543-14
21055| [850196] SuSE Update for apache2 openSUSE-SU-2012:0314-1 (apache2)
21056| [850088] SuSE Update for apache2 SUSE-SA:2007:061
21057| [850009] SuSE Update for apache2,apache SUSE-SA:2008:021
21058| [841209] Ubuntu Update for apache2 USN-1627-1
21059| [840900] Ubuntu Update for apache2 USN-1368-1
21060| [840798] Ubuntu Update for apache2 USN-1259-1
21061| [840734] Ubuntu Update for apache2 USN-1199-1
21062| [840542] Ubuntu Update for apache2 vulnerabilities USN-1021-1
21063| [840504] Ubuntu Update for apache2 vulnerability USN-990-2
21064| [840399] Ubuntu Update for apache2 vulnerabilities USN-908-1
21065| [840304] Ubuntu Update for apache2 vulnerabilities USN-575-1
21066| [840118] Ubuntu Update for libapache2-mod-perl2 vulnerability USN-488-1
21067| [840092] Ubuntu Update for apache2 vulnerabilities USN-499-1
21068| [840039] Ubuntu Update for libapache2-mod-python vulnerability USN-430-1
21069| [835253] HP-UX Update for Apache Web Server HPSBUX02645
21070| [835247] HP-UX Update for Apache-based Web Server HPSBUX02612
21071| [835243] HP-UX Update for Apache Running Tomcat Servlet Engine HPSBUX02579
21072| [835236] HP-UX Update for Apache with PHP HPSBUX02543
21073| [835233] HP-UX Update for Apache-based Web Server HPSBUX02531
21074| [835224] HP-UX Update for Apache-based Web Server HPSBUX02465
21075| [835200] HP-UX Update for Apache Web Server Suite HPSBUX02431
21076| [835190] HP-UX Update for Apache Web Server Suite HPSBUX02401
21077| [835188] HP-UX Update for Apache HPSBUX02308
21078| [835181] HP-UX Update for Apache With PHP HPSBUX02332
21079| [835180] HP-UX Update for Apache with PHP HPSBUX02342
21080| [835172] HP-UX Update for Apache HPSBUX02365
21081| [835168] HP-UX Update for Apache HPSBUX02313
21082| [835148] HP-UX Update for Apache HPSBUX01064
21083| [835139] HP-UX Update for Apache with PHP HPSBUX01090
21084| [835131] HP-UX Update for Apache HPSBUX00256
21085| [835119] HP-UX Update for Apache Remote Execution of Arbitrary Code HPSBUX02186
21086| [835104] HP-UX Update for Apache HPSBUX00224
21087| [835103] HP-UX Update for Apache mod_cgid HPSBUX00301
21088| [835101] HP-UX Update for Apache HPSBUX01232
21089| [835080] HP-UX Update for Apache HPSBUX02273
21090| [835078] HP-UX Update for ApacheStrong HPSBUX00255
21091| [835044] HP-UX Update for Apache HPSBUX01019
21092| [835040] HP-UX Update for Apache PHP HPSBUX00207
21093| [835025] HP-UX Update for Apache HPSBUX00197
21094| [835023] HP-UX Update for Apache HPSBUX01022
21095| [835022] HP-UX Update for Apache HPSBUX02292
21096| [835005] HP-UX Update for Apache HPSBUX02262
21097| [831759] Mandriva Update for apache-mod_security MDVSA-2012:182 (apache-mod_security)
21098| [831737] Mandriva Update for apache MDVSA-2012:154-1 (apache)
21099| [831534] Mandriva Update for apache MDVSA-2012:012 (apache)
21100| [831523] Mandriva Update for apache MDVSA-2012:003 (apache)
21101| [831491] Mandriva Update for apache MDVSA-2011:168 (apache)
21102| [831460] Mandriva Update for apache MDVSA-2011:144 (apache)
21103| [831449] Mandriva Update for apache MDVSA-2011:130 (apache)
21104| [831357] Mandriva Update for apache MDVSA-2011:057 (apache)
21105| [831132] Mandriva Update for apache MDVSA-2010:153 (apache)
21106| [831131] Mandriva Update for apache MDVSA-2010:152 (apache)
21107| [830989] Mandriva Update for apache-mod_auth_shadow MDVSA-2010:081 (apache-mod_auth_shadow)
21108| [830931] Mandriva Update for apache MDVSA-2010:057 (apache)
21109| [830926] Mandriva Update for apache MDVSA-2010:053 (apache)
21110| [830918] Mandriva Update for apache-mod_security MDVSA-2010:050 (apache-mod_security)
21111| [830799] Mandriva Update for apache-conf MDVSA-2009:300-2 (apache-conf)
21112| [830797] Mandriva Update for apache-conf MDVSA-2009:300-1 (apache-conf)
21113| [830791] Mandriva Update for apache-conf MDVA-2010:011 (apache-conf)
21114| [830652] Mandriva Update for apache MDVSA-2008:195 (apache)
21115| [830621] Mandriva Update for apache-conf MDVA-2008:129 (apache-conf)
21116| [830581] Mandriva Update for apache MDVSA-2008:016 (apache)
21117| [830294] Mandriva Update for apache MDKSA-2007:140 (apache)
21118| [830196] Mandriva Update for apache MDKSA-2007:235 (apache)
21119| [830112] Mandriva Update for apache MDKSA-2007:127 (apache)
21120| [830109] Mandriva Update for apache-mod_perl MDKSA-2007:083 (apache-mod_perl)
21121| [802425] Apache Struts2 Showcase Arbitrary Java Method Execution vulnerability
21122| [802423] Apache Struts CookBook/Examples Multiple Cross-Site Scripting Vulnerabilities
21123| [802422] Apache Struts Showcase Multiple Persistence Cross-Site Scripting Vulnerabilities
21124| [802415] Apache Tomcat Multiple Security Bypass Vulnerabilities (Win)
21125| [802385] Apache Tomcat Request Object Security Bypass Vulnerability (Win)
21126| [802384] Apache Tomcat Parameter Handling Denial of Service Vulnerability (Win)
21127| [802378] Apache Tomcat Hash Collision Denial Of Service Vulnerability
21128| [801942] Apache Archiva Multiple Vulnerabilities
21129| [801940] Apache Struts2 'XWork' Information Disclosure Vulnerability
21130| [801663] Apache Struts2/XWork Remote Command Execution Vulnerability
21131| [801521] Apache APR-util 'buckets/apr_brigade.c' Denial Of Service Vulnerability
21132| [801284] Apache Derby Information Disclosure Vulnerability
21133| [801203] Apache ActiveMQ Persistent Cross-Site Scripting Vulnerability
21134| [800837] Apache 'mod_deflate' Denial Of Service Vulnerability - July09
21135| [800827] Apache 'mod_proxy_http.c' Denial Of Service Vulnerability
21136| [800680] Apache APR Version Detection
21137| [800679] Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
21138| [800678] Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
21139| [800677] Apache Roller Version Detection
21140| [800279] Apache mod_jk Module Version Detection
21141| [800278] Apache Struts Cross Site Scripting Vulnerability
21142| [800277] Apache Tomcat mod_jk Information Disclosure Vulnerability
21143| [800276] Apache Struts Version Detection
21144| [800271] Apache Struts Directory Traversal Vulnerability
21145| [800024] Apache Tomcat RemoteFilterValve Security Bypass Vulnerability
21146| [103333] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
21147| [103293] Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
21148| [103122] Apache Web Server ETag Header Information Disclosure Weakness
21149| [103074] Apache Continuum Cross Site Scripting Vulnerability
21150| [103073] Apache Continuum Detection
21151| [103053] Apache CouchDB Web Administration Interface Cross Site Scripting Vulnerability
21152| [101023] Apache Open For Business Weak Password security check
21153| [101020] Apache Open For Business HTML injection vulnerability
21154| [101019] Apache Open For Business service detection
21155| [100924] Apache Archiva Cross Site Request Forgery Vulnerability
21156| [100923] Apache Archiva Detection
21157| [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
21158| [100814] Apache Axis2 Document Type Declaration Processing Security Vulnerability
21159| [100813] Apache Axis2 Detection
21160| [100797] Apache Traffic Server Remote DNS Cache Poisoning Vulnerability
21161| [100795] Apache Derby Detection
21162| [100762] Apache CouchDB Cross Site Request Forgery Vulnerability
21163| [100725] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
21164| [100613] Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
21165| [100514] Apache Multiple Security Vulnerabilities
21166| [100211] Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
21167| [100172] Apache Web Server Configuration File Environment Variable Local Buffer Overflow Vulnerability
21168| [100171] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
21169| [100130] Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
21170| [72626] Debian Security Advisory DSA 2579-1 (apache2)
21171| [72612] FreeBSD Ports: apache22
21172| [71551] Gentoo Security Advisory GLSA 201206-25 (apache)
21173| [71550] Gentoo Security Advisory GLSA 201206-24 (apache tomcat)
21174| [71512] FreeBSD Ports: apache
21175| [71485] Debian Security Advisory DSA 2506-1 (libapache-mod-security)
21176| [71256] Debian Security Advisory DSA 2452-1 (apache2)
21177| [71238] Debian Security Advisory DSA 2436-1 (libapache2-mod-fcgid)
21178| [70737] FreeBSD Ports: apache
21179| [70724] Debian Security Advisory DSA 2405-1 (apache2)
21180| [70600] FreeBSD Ports: apache
21181| [70253] FreeBSD Ports: apache, apache-event, apache-itk, apache-peruser, apache-worker
21182| [70235] Debian Security Advisory DSA 2298-2 (apache2)
21183| [70233] Debian Security Advisory DSA 2298-1 (apache2)
21184| [69988] Debian Security Advisory DSA 2279-1 (libapache2-mod-authnz-external)
21185| [69338] Debian Security Advisory DSA 2202-1 (apache2)
21186| [67868] FreeBSD Ports: apache
21187| [66816] FreeBSD Ports: apache
21188| [66553] Mandriva Security Advisory MDVSA-2009:189-1 (apache-mod_auth_mysql)
21189| [66414] Mandriva Security Advisory MDVSA-2009:323 (apache)
21190| [66106] SuSE Security Advisory SUSE-SA:2009:050 (apache2,libapr1)
21191| [66081] SLES11: Security update for Apache 2
21192| [66074] SLES10: Security update for Apache 2
21193| [66070] SLES9: Security update for Apache 2
21194| [65998] SLES10: Security update for apache2-mod_python
21195| [65893] SLES10: Security update for Apache 2
21196| [65888] SLES10: Security update for Apache 2
21197| [65575] SLES9: Security update for apache2,apache2-prefork,apache2-worker
21198| [65510] SLES9: Security update for Apache 2
21199| [65472] SLES9: Security update for Apache
21200| [65467] SLES9: Security update for Apache
21201| [65450] SLES9: Security update for apache2
21202| [65390] SLES9: Security update for Apache2
21203| [65363] SLES9: Security update for Apache2
21204| [65309] SLES9: Security update for Apache and mod_ssl
21205| [65296] SLES9: Security update for webdav apache module
21206| [65283] SLES9: Security update for Apache2
21207| [65249] SLES9: Security update for Apache 2
21208| [65230] SLES9: Security update for Apache 2
21209| [65228] SLES9: Security update for Apache 2
21210| [65212] SLES9: Security update for apache2-mod_python
21211| [65209] SLES9: Security update for apache2-worker
21212| [65207] SLES9: Security update for Apache 2
21213| [65168] SLES9: Security update for apache2-mod_python
21214| [65142] SLES9: Security update for Apache2
21215| [65136] SLES9: Security update for Apache 2
21216| [65132] SLES9: Security update for apache
21217| [65131] SLES9: Security update for Apache 2 oes/CORE
21218| [65113] SLES9: Security update for apache2
21219| [65072] SLES9: Security update for apache and mod_ssl
21220| [65017] SLES9: Security update for Apache 2
21221| [64950] Mandrake Security Advisory MDVSA-2009:240 (apache)
21222| [64783] FreeBSD Ports: apache
21223| [64774] Ubuntu USN-802-2 (apache2)
21224| [64653] Ubuntu USN-813-2 (apache2)
21225| [64559] Debian Security Advisory DSA 1834-2 (apache2)
21226| [64532] Mandrake Security Advisory MDVSA-2009:189 (apache-mod_auth_mysql)
21227| [64527] Mandrake Security Advisory MDVSA-2009:184 (apache-mod_security)
21228| [64526] Mandrake Security Advisory MDVSA-2009:183 (apache-mod_security)
21229| [64500] Mandrake Security Advisory MDVSA-2009:168 (apache)
21230| [64443] Ubuntu USN-802-1 (apache2)
21231| [64426] Gentoo Security Advisory GLSA 200907-04 (apache)
21232| [64423] Debian Security Advisory DSA 1834-1 (apache2)
21233| [64391] Mandrake Security Advisory MDVSA-2009:149 (apache)
21234| [64377] Mandrake Security Advisory MDVSA-2009:124-1 (apache)
21235| [64251] Debian Security Advisory DSA 1816-1 (apache2)
21236| [64201] Ubuntu USN-787-1 (apache2)
21237| [64140] Mandrake Security Advisory MDVSA-2009:124 (apache)
21238| [64136] Mandrake Security Advisory MDVSA-2009:102 (apache)
21239| [63565] FreeBSD Ports: apache
21240| [63562] Ubuntu USN-731-1 (apache2)
21241| [61381] Gentoo Security Advisory GLSA 200807-06 (apache)
21242| [61185] FreeBSD Ports: apache
21243| [60582] Gentoo Security Advisory GLSA 200803-19 (apache)
21244| [60387] Slackware Advisory SSA:2008-045-02 apache
21245| [58826] FreeBSD Ports: apache-tomcat
21246| [58825] FreeBSD Ports: apache-tomcat
21247| [58804] FreeBSD Ports: apache
21248| [58745] Gentoo Security Advisory GLSA 200711-06 (apache)
21249| [58360] Debian Security Advisory DSA 1312-1 (libapache-mod-jk)
21250| [57851] Gentoo Security Advisory GLSA 200608-01 (apache)
21251| [57788] Debian Security Advisory DSA 1247-1 (libapache-mod-auth-kerb)
21252| [57335] Debian Security Advisory DSA 1167-1 (apache)
21253| [57201] Debian Security Advisory DSA 1131-1 (apache)
21254| [57200] Debian Security Advisory DSA 1132-1 (apache2)
21255| [57168] Slackware Advisory SSA:2006-209-01 Apache httpd
21256| [57145] FreeBSD Ports: apache
21257| [56731] Slackware Advisory SSA:2006-129-01 Apache httpd
21258| [56729] Slackware Advisory SSA:2006-130-01 Apache httpd redux
21259| [56246] Gentoo Security Advisory GLSA 200602-03 (Apache)
21260| [56212] Debian Security Advisory DSA 952-1 (libapache-auth-ldap)
21261| [56115] Debian Security Advisory DSA 935-1 (libapache2-mod-auth-pgsql)
21262| [56067] FreeBSD Ports: apache
21263| [55803] Slackware Advisory SSA:2005-310-04 apache
21264| [55519] Debian Security Advisory DSA 839-1 (apachetop)
21265| [55392] Gentoo Security Advisory GLSA 200509-12 (Apache)
21266| [55355] FreeBSD Ports: apache
21267| [55284] Debian Security Advisory DSA 807-1 (libapache-mod-ssl)
21268| [55261] Debian Security Advisory DSA 805-1 (apache2)
21269| [55259] Debian Security Advisory DSA 803-1 (apache)
21270| [55129] Gentoo Security Advisory GLSA 200508-15 (apache)
21271| [54739] Gentoo Security Advisory GLSA 200411-18 (apache)
21272| [54724] Gentoo Security Advisory GLSA 200411-03 (apache)
21273| [54712] Gentoo Security Advisory GLSA 200410-21 (apache)
21274| [54689] Gentoo Security Advisory GLSA 200409-33 (net=www/apache)
21275| [54677] Gentoo Security Advisory GLSA 200409-21 (apache)
21276| [54610] Gentoo Security Advisory GLSA 200407-03 (Apache)
21277| [54601] Gentoo Security Advisory GLSA 200406-16 (Apache)
21278| [54590] Gentoo Security Advisory GLSA 200406-05 (Apache)
21279| [54582] Gentoo Security Advisory GLSA 200405-22 (Apache)
21280| [54529] Gentoo Security Advisory GLSA 200403-04 (Apache)
21281| [54499] Gentoo Security Advisory GLSA 200310-04 (Apache)
21282| [54498] Gentoo Security Advisory GLSA 200310-03 (Apache)
21283| [54439] FreeBSD Ports: apache
21284| [53931] Slackware Advisory SSA:2004-133-01 apache
21285| [53903] Slackware Advisory SSA:2004-299-01 apache, mod_ssl, php
21286| [53902] Slackware Advisory SSA:2004-305-01 apache+mod_ssl
21287| [53878] Slackware Advisory SSA:2003-308-01 apache security update
21288| [53851] Debian Security Advisory DSA 135-1 (libapache-mod-ssl)
21289| [53849] Debian Security Advisory DSA 132-1 (apache-ssl)
21290| [53848] Debian Security Advisory DSA 131-1 (apache)
21291| [53784] Debian Security Advisory DSA 021-1 (apache)
21292| [53738] Debian Security Advisory DSA 195-1 (apache-perl)
21293| [53737] Debian Security Advisory DSA 188-1 (apache-ssl)
21294| [53735] Debian Security Advisory DSA 187-1 (apache)
21295| [53703] Debian Security Advisory DSA 532-1 (libapache-mod-ssl)
21296| [53577] Debian Security Advisory DSA 120-1 (libapache-mod-ssl, apache-ssl)
21297| [53568] Debian Security Advisory DSA 067-1 (apache,apache-ssl)
21298| [53519] Debian Security Advisory DSA 689-1 (libapache-mod-python)
21299| [53433] Debian Security Advisory DSA 181-1 (libapache-mod-ssl)
21300| [53282] Debian Security Advisory DSA 594-1 (apache)
21301| [53248] Debian Security Advisory DSA 558-1 (libapache-mod-dav)
21302| [53224] Debian Security Advisory DSA 532-2 (libapache-mod-ssl)
21303| [53215] Debian Security Advisory DSA 525-1 (apache)
21304| [53151] Debian Security Advisory DSA 452-1 (libapache-mod-python)
21305| [52529] FreeBSD Ports: apache+ssl
21306| [52501] FreeBSD Ports: apache
21307| [52461] FreeBSD Ports: apache
21308| [52390] FreeBSD Ports: apache
21309| [52389] FreeBSD Ports: apache
21310| [52388] FreeBSD Ports: apache
21311| [52383] FreeBSD Ports: apache
21312| [52339] FreeBSD Ports: apache+mod_ssl
21313| [52331] FreeBSD Ports: apache
21314| [52329] FreeBSD Ports: ru-apache+mod_ssl
21315| [52314] FreeBSD Ports: apache
21316| [52310] FreeBSD Ports: apache
21317| [15588] Detect Apache HTTPS
21318| [15555] Apache mod_proxy content-length buffer overflow
21319| [15554] Apache mod_include priviledge escalation
21320| [14771] Apache <= 1.3.33 htpasswd local overflow
21321| [14177] Apache mod_access rule bypass
21322| [13644] Apache mod_rootme Backdoor
21323| [12293] Apache Input Header Folding and mod_ssl ssl_io_filter_cleanup DoS Vulnerabilities
21324| [12280] Apache Connection Blocking Denial of Service
21325| [12239] Apache Error Log Escape Sequence Injection
21326| [12123] Apache Tomcat source.jsp malformed request information disclosure
21327| [12085] Apache Tomcat servlet/JSP container default files
21328| [11438] Apache Tomcat Directory Listing and File disclosure
21329| [11204] Apache Tomcat Default Accounts
21330| [11092] Apache 2.0.39 Win32 directory traversal
21331| [11046] Apache Tomcat TroubleShooter Servlet Installed
21332| [11042] Apache Tomcat DOS Device Name XSS
21333| [11041] Apache Tomcat /servlet Cross Site Scripting
21334| [10938] Apache Remote Command Execution via .bat files
21335| [10839] PHP.EXE / Apache Win32 Arbitrary File Reading Vulnerability
21336| [10773] MacOS X Finder reveals contents of Apache Web files
21337| [10766] Apache UserDir Sensitive Information Disclosure
21338| [10756] MacOS X Finder reveals contents of Apache Web directories
21339| [10752] Apache Auth Module SQL Insertion Attack
21340| [10704] Apache Directory Listing
21341| [10678] Apache /server-info accessible
21342| [10677] Apache /server-status accessible
21343| [10440] Check for Apache Multiple / vulnerability
21344|
21345| SecurityTracker - https://www.securitytracker.com:
21346| [1028865] Apache Struts Bugs Permit Remote Code Execution and URL Redirection Attacks
21347| [1028864] Apache Struts Wildcard Matching and Expression Evaluation Bugs Let Remote Users Execute Arbitrary Code
21348| [1028824] Apache mod_dav_svn URI Processing Flaw Lets Remote Users Deny Service
21349| [1028823] Apache Unspecified Flaw in mod_session_dbd Has Unspecified Impact
21350| [1028724] (HP Issues Fix for HP-UX) Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
21351| [1028722] (Red Hat Issues Fix for JBoss) Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
21352| [1028693] (Red Hat Issues Fix) Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
21353| [1028622] Apache Struts 'includeParams' Bugs Permit Remote Command Execution and Cross-Site Scripting Attacks
21354| [1028621] Apache Subversion Bugs Let Remote Authenticated Users Execute Arbitrary Commands and Deny Service
21355| [1028540] Apache mod_rewrite Input Validation Flaw Lets Remote Users Execute Arbitrary Commands
21356| [1028534] Apache Tomcat FORM Authenticator Lets Remote Users Conduct Session Fixation Attacks
21357| [1028533] Apache Tomcat Lack of Chunked Transfer Encoding Extension Size Limit Lets Remote Users Deny Service
21358| [1028532] Apache Tomcat AsyncListeners Bug May Disclose Information from One Request to Another User
21359| [1028515] Apache VCL Input Validation Flaw Lets Remote Authenticated Users Gain Elevated Privileges
21360| [1028457] Apache ActiveMQ Bugs Let Remote Users Conduct Cross-Site Scripting Attacks, Deny Service, and Obtain Potentially Sensitive Information
21361| [1028287] Apache CXF WSS4JInInterceptor Grants Service Access to Remote Users
21362| [1028286] Apache CXF WS-Security UsernameToken Processing Flaw Lets Remote Users Bypass Authentication
21363| [1028252] Apache Commons FileUpload Unsafe Temporary File Lets Local Users Gain Elevated Privileges
21364| [1028207] Apache Input Validation Bugs Permit Cross-Site Scripting Attacks
21365| [1027836] Apache Tomcat Connection Processing Bug Lets Remote Users Deny Service
21366| [1027834] Apache Tomcat Bug Lets Remote Users Bypass Cross-Site Request Forgery Prevention Filter
21367| [1027833] Apache Tomcat Bug Lets Remote Users Bypass Security Constraints
21368| [1027729] Apache Tomcat Header Processing Bug Lets Remote Users Deny Service
21369| [1027728] Apache Tomcat Lets Remote Users Conduct DIGEST Authentication Replay Attacks
21370| [1027554] Apache CXF Lets Remote Authenticated Users Execute Unauthorized SOAP Actions
21371| [1027508] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
21372| [1027421] Apache Web Server Bugs Permit Cross-Site Scripting and Information Disclosure Attacks
21373| [1027096] Apache Commons Compress BZip2CompressorOutputStream() Sorting Algorithm Lets Remote or Local Users Deny Service
21374| [1026932] Apache LD_LIBRARY_PATH Processing Lets Local Users Gain Elevated Privileges
21375| [1026928] Apache OFBiz Unspecified Flaw Lets Remote Users Execute Arbitrary Code
21376| [1026927] Apache OFBiz Input Validation Flaws Permit Cross-Site Scripting Attacks
21377| [1026847] Apache Traffic Server Host Header Processing Flaw Lets Remote Users Deny Service
21378| [1026846] Apache Wicket Discloses Hidden Application Files to Remote Users
21379| [1026839] Apache Wicket Input Validation Flaw in 'wicket:pageMapName' Parameter Permits Cross-Site Scripting Attacks
21380| [1026616] Apache Bugs Let Remote Users Deny Service and Obtain Cookie Data
21381| [1026575] Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
21382| [1026484] Apache Struts Bug Lets Remote Users Overwrite Files and Execute Arbitrary Code
21383| [1026477] Apache Tomcat Hash Table Collision Bug Lets Remote Users Deny Service
21384| [1026402] Apache Struts Conversion Error Lets Remote Users Inject Arbitrary Commands
21385| [1026353] Apache mod_proxy/mod_rewrite Bug Lets Remote Users Access Internal Servers
21386| [1026295] Apache Tomcat Lets Untrusted Web Applications Gain Elevated Privileges
21387| [1026267] Apache .htaccess File Integer Overflow Lets Local Users Execute Arbitrary Code
21388| [1026144] Apache mod_proxy Pattern Matching Bug Lets Remote Users Access Internal Servers
21389| [1026095] Apache Tomcat HTTP DIGEST Authentication Weaknesses Let Remote Users Conduct Bypass Attacks
21390| [1026054] Apache mod_proxy_ajp HTTP Processing Error Lets Remote Users Deny Service
21391| [1025993] Apache Tomcat AJP Protocol Processing Bug Lets Remote Users Bypass Authentication or Obtain Information
21392| [1025976] Apache Wicket Input Validation Flaw Permits Cross-Site Scripting Attacks
21393| [1025960] Apache httpd Byterange Filter Processing Error Lets Remote Users Deny Service
21394| [1025925] Apache Tomcat Commons Daemon jsvc Lets Local Users Gain Elevated Privileges
21395| [1025924] Apache Tomcat XML Validation Flaw Lets Applications Obtain Potentially Sensitive Information
21396| [1025788] Apache Tomcat Lets Malicious Applications Obtain Information and Deny Service
21397| [1025755] Apache Santuario Buffer Overflow Lets Remote Users Deny Service
21398| [1025712] Apache Tomcat Discloses Passwords to Local Users in Certain Cases
21399| [1025577] Apache Archiva Input Validation Hole Permits Cross-Site Scripting Attacks
21400| [1025576] Apache Archiva Request Validation Flaw Permits Cross-Site Request Forgery Attacks
21401| [1025527] Apache APR Library apr_fnmatch() Flaw Lets Remote Users Execute Arbitrary Code
21402| [1025303] Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
21403| [1025215] Apache Tomcat May Ignore @ServletSecurity Annotation Protections
21404| [1025066] Apache Continuum Input Validation Flaw Permits Cross-Site Request Forgery Attacks
21405| [1025065] Apache Continuum Input Validation Hole Permits Cross-Site Scripting Attacks
21406| [1025027] Apache Tomcat maxHttpHeaderSize Parsing Error Lets Remote Users Deny Service
21407| [1025026] Apache Tomcat Manager Input Validation Hole Permits Cross-Site Scripting Attacks
21408| [1025025] Apache Tomcat Security Manager Lets Local Users Bypass File Permissions
21409| [1024764] Apache Tomcat Manager Input Validation Hole in 'sessionList.jsp' Permits Cross-Site Scripting Attacks
21410| [1024417] Apache Traffic Server Insufficient Randomization Lets Remote Users Poison the DNS Cache
21411| [1024332] Apache mod_cache and mod_dav Request Processing Flaw Lets Remote Users Deny Service
21412| [1024180] Apache Tomcat 'Transfer-Encoding' Header Processing Flaw Lets Remote Users Deny Service and Obtain Potentially Sensitive Information
21413| [1024096] Apache mod_proxy_http May Return Results for a Different Request
21414| [1023942] Apache mod_proxy_ajp Error Condition Lets Remote Users Deny Service
21415| [1023941] Apache ap_read_request() Memory Error May Let Remote Users Access Potentially Sensitive Information
21416| [1023778] Apache ActiveMQ Input Validation Flaw Permits Cross-Site Scripting Attacks
21417| [1023701] Apache mod_isapi Error Processing Flaw May Let Remote Users Deny Service
21418| [1023533] Apache mod_proxy Integer Overflow May Let Remote Users Execute Arbitrary Code
21419| [1022988] Apache Solaris Support Code Bug Lets Remote Users Deny Service
21420| [1022529] Apache mod_deflate Connection State Bug Lets Remote Users Deny Service
21421| [1022509] Apache mod_proxy stream_reqbody_cl() Infinite Loop Lets Remote Users Deny Service
21422| [1022296] Apache IncludesNoExec Options Restrictions Can Be Bypass By Local Users
21423| [1022264] Apache mod_proxy_ajp Bug May Disclose Another User's Response Data
21424| [1022001] Apache Tomcat mod_jk May Disclose Responses to the Wrong User
21425| [1021988] mod_perl Input Validation Flaw in Apache::Status and Apache2::Status Permits Cross-Site Scripting Attacks
21426| [1021350] NetWare Bug Lets Remote Users Access the ApacheAdmin Console
21427| [1020635] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
21428| [1020520] Oracle WebLogic Apache Connector Lets Remote Users Execute Arbitrary Code
21429| [1020267] Apache mod_proxy Interim Response Process Bug Lets Remote Users Deny Service
21430| [1019784] Apache-SSL Certificate Processing Bug May Let Remote Users View Portions of Kernel Memory
21431| [1019256] Apache mod_negotiation Input Validation Hole Permits Cross-Site Scripting Attacks
21432| [1019194] Apache Input Validation Hole in Mod_AutoIndex When the Character Set is Undefined May Permit Cross-Site Scripting Attacks
21433| [1019185] Apache Input Validation Hole in mod_proxy_ftp Permits Cross-Site Scripting Attacks
21434| [1019154] Apache Input Validation Hole in mod_status Permits Cross-Site Scripting Attacks
21435| [1019093] Apache Input Validation Hole in mod_imap Permits Cross-Site Scripting Attacks
21436| [1019030] Apache Input Validation Hole in Default HTTP 413 Error Page Permits Cross-Site Scripting Attacks
21437| [1018633] Apache mod_proxy Bug Lets Remote Users Deny Service
21438| [1018304] Apache HTTPD scoreboard Protection Flaw Lets Local Users Terminate Arbitrary Processes
21439| [1018303] Apache HTTPD mod_cache May Let Remote Users Deny Service
21440| [1018302] Apache mod_status Input Validation Hole Permits Cross-Site Scripting Attacks
21441| [1018269] Apache Tomcat Input Validation Hole in Processing Accept-Language Header Permits Cross-Site Scripting Attacks
21442| [1017904] Apache suEXEC Bugs May Let Local Users Gain Elevated Privileges
21443| [1017719] Apache Tomcat JK Web Server Connector Buffer Overflow in map_uri_to_worker() Lets Remote Users Execute Arbitrary Code
21444| [1017062] Apache mod_tcl Format String Bug in set_var() Function May Let Remote Users Execute Arbitrary Code
21445| [1016601] Apache mod_rewrite Off-by-one Error Lets Remote Users Execute Arbitrary Code
21446| [1016576] Apache Tomcat Discloses Directory Listings to Remote Users
21447| [1015447] Apache mod_ssl Null Pointer Dereference May Let Remote Users Deny Service
21448| [1015344] Apache mod_imap Input Validation Flaw in Referer Field Lets Remote Users Conduct Cross-Site Scripting Attacks
21449| [1015093] Apache Memory Leak in MPM 'worker.c' Code May Let Remote Users Deny Service
21450| [1014996] ApacheTop Unsafe Temporary File May Let Local Users Gain Elevated Privileges
21451| [1014833] Apache ssl_hook_Access() Function May Fail to Verify Client Certificates
21452| [1014826] Apache Memory Leak in 'byterange filter' Lets Remote Users Deny Service
21453| [1014575] Apache mod_ssl Off-by-one Buffer Overflow in Processing CRLs May Let Remote Users Deny Service
21454| [1014323] Apache Chunked Transfer-Encoding and Content-Length Processing Lets Remote Users Smuggle HTTP Requests
21455| [1013156] Apache mod_python Publisher Handler Discloses Information to Remote Users
21456| [1012829] Apache mod_auth_radius radcpy() Integer Overflow Lets Remote Users Deny Service in Certain Cases
21457| [1012416] Apache on Apple OS X Lets Remote Users Bypass Apache File Handlers and Directly Access Files
21458| [1012415] Apache on Apple HFS+ Filesystems May Disclose '.DS_Store' Files to Remote Users
21459| [1012414] Apache mod_digest_apple Lets Remote Users Replay Authentication Credentials
21460| [1012083] Apache Web Server Error in Processing Requests With Many Space Characters Lets Remote Users Deny Service
21461| [1011783] Apache mod_include Buffer Overflow Lets Local Users Execute Arbitrary Code
21462| [1011557] Apache mod_ssl SSLCipherSuite Directive Can By Bypassed in Certain Cases
21463| [1011385] Apache Satsify Directive Error May Let Remote Users Access Restricted Resources
21464| [1011340] Apache SSL Connection Abort State Error Lets Remote Users Deny Service
21465| [1011303] Apache ap_resolve_env() Buffer Overflow in Reading Configuration Files May Let Local Users Gain Elevated Privileges
21466| [1011299] Apache IPv6 Address Parsing Flaw May Let Remote Users Deny Service
21467| [1011248] Apache mod_dav LOCK Method Error May Let Remote Users Deny Service
21468| [1011213] Apache mod_ssl Can Be Crashed By Remote Users When Reverse Proxying SSL Connections
21469| [1010674] Apache Can Be Crashed By PHP Code Invoking Nested Remote Sockets
21470| [1010599] Apache httpd Header Line Memory Allocation Lets Remote Users Crash the Server
21471| [1010462] Apache mod_proxy Buffer Overflow May Let Remote Users Execute Arbitrary Code
21472| [1010322] Apache mod_ssl Stack Overflow in ssl_util_uuencode_binary() May Let Remote Users Execute Arbitrary Code
21473| [1010270] cPanel Apache mod_phpsuexec Options Let Local Users Gain Elevated Privileges
21474| [1009934] Apache Web Server Has Buffer Overflow in ebcdic2ascii() on Older Processor Architectures
21475| [1009516] Apache mod_survey HTML Report Format Lets Remote Users Conduct Cross-Site Scripting Attacks
21476| [1009509] Apache mod_disk_cache Stores Authentication Credentials on Disk
21477| [1009495] Apache Web Server Socket Starvation Flaw May Let Remote Users Deny Service
21478| [1009417] GroupWise WebAccess With Apache on NetWare Has Configuration Flaw That May Grant Web Access to Remote Users
21479| [1009338] Apache mod_access Parsing Flaw May Fail to Enforce Allow/Deny Rules
21480| [1009337] Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon
21481| [1009182] Apache for Cygwin '..%5C' Input Validation Flaw Discloses Files to Remote Users
21482| [1008973] PHP May Apply Incorrect php_admin_* Settings To Requests for Apache Virtual Hosts
21483| [1008967] Apache-SSL 'SSLFakeBasicAuth' Lets Remote Users Forge Client Certificates to Be Authenticated
21484| [1008920] Apache mod_digest May Validate Replayed Client Responses
21485| [1008828] Apache mod_python String Processing Bug Still Lets Remote Users Crash the Web Server
21486| [1008822] Apache mod_perl File Descriptor Leak May Let Local Users Hijack the http and https Services
21487| [1008675] mod_auth_shadow Apache Module Authenticates Expired Passwords
21488| [1008559] Apache mod_php File Descriptor Leak May Let Local Users Hijack the https Service
21489| [1008335] Apache mod_python String Processing Bug Lets Remote Users Crash the Web Server
21490| [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
21491| [1008030] Apache mod_rewrite Contains a Buffer Overflow
21492| [1008029] Apache mod_alias Contains a Buffer Overflow
21493| [1008028] Apache mod_cgid May Disclose CGI Output to Another Client
21494| [1007995] Apache Cocoon Forms May Let Remote Users Execute Arbitrary Java Code on the System
21495| [1007993] Apache Cocoon 'view-source' Sample Script Discloses Files to Remote Users
21496| [1007823] Apache Web Server mod_cgi Error May Let Malicious CGI Scripts Crash the Web Service
21497| [1007664] Apache::Gallery Unsafe Temporary Files May Let Local Users Gain Apache Web Server Privileges
21498| [1007557] Apache Web Server Does Not Filter Terminal Escape Sequences From Log Files
21499| [1007230] Apache HTTP Server 'rotatelogs' Bug on Win32 and OS/2 May Cause the Logging to Stop
21500| [1007146] Apache HTTP Server FTP Proxy Bug May Cause Denial of Service Conditions
21501| [1007145] Apache 'accept()' Errors May Cause Denial of Service Conditions
21502| [1007144] Apache Web Server 'type-map' File Error Permits Local Denial of Service Attacks
21503| [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
21504| [1006864] Apache Web Server Can Be Crashed By Remote Users Via mod_dav Flaws and Also Via Basic Authentication
21505| [1006709] Apache mod_survey Input Validation Flaw Lets Remote Users Fill Up Disk Space
21506| [1006614] Apache mod_ntlm Buffer Overflow and Format String Flaw Let Remote Users Execute Arbitary Code
21507| [1006591] Apache mod_access_referer Module Null Pointer Dereference May Faciliate Denial of Service Attacks
21508| [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
21509| [1006021] Apache Tomcat Server URL Parsing Error May Disclose Otherwise Inaccessible Web Directory Listings and Files to Remote Users
21510| [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
21511| [1005962] Apache Web Server Path Parsing Flaw May Allow Remote Users to Execute Code in Certain Configurations
21512| [1005848] Apache 'printenv' Script Input Validation Bugs in Older Versions May Let Remote Users Conduct Cross-Site Scripting Attacks
21513| [1005765] Apache mod_jk Module Processing Bug When Used With Tomcat May Disclose Information to Remote Users or Crash
21514| [1005548] Apache mod_php Module May Allow Local Users to Gain Control of the Web Port
21515| [1005499] Apache Web Server (2.0.42) May Disclose CGI Source Code to Remote Users When Used With WebDAV
21516| [1005410] Apache Tomcat Java Servlet Engine Can Be Crashed Via Multiple Requests for DOS Device Names
21517| [1005351] Apache Web Server (1.3.x) Shared Memory Scoreboard Bug Lets Certain Local Users Issue Signals With Root Privileges
21518| [1005331] Apache Web Server (2.x) SSI Server Signature Filtering Hole Lets Remote Users Conduct Cross-Site Scripting Attacks
21519| [1005290] Apache Tomcat Java Server Default Servlet Returns JSP Source Code to Remote Users
21520| [1005285] Apache Web Server 'mod_dav' Has Null Pointer Bug That May Allow Remote Users to Cause Denial of Service Conditions
21521| [1005010] Apache Web Server (2.0) Has Unspecified Flaw That Allows Remote Users to Obtain Sensitive Data and Cause Denial of Service Conditions
21522| [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
21523| [1004745] Apache Tomcat Java Server Allows Cross-Site Scripting Attacks
21524| [1004636] Apache mod_ssl 'Off-by-One' Bug May Let Local Users Crash the Web Server or Possibly Execute Arbitrary Code
21525| [1004602] Apache Tomcat Java Server for Windows Can Be Crashed By Remote Users Sending Malicious Requests to Hang All Available Working Threads
21526| [1004586] Apache Tomcat Java Server May Disclose the Installation Path to Remote Users
21527| [1004555] Apache Web Server Chunked Encoding Flaw May Let Remote Users Execute Arbitrary Code on the Server
21528| [1004209] Apache 'mod_python' Python Language Interpreter Bug in Publisher Handler May Allow Remote Users to Modify Files on the System
21529| [1003874] Apache Web Server for Windows Has Batch File Processing Hole That Lets Remote Users Execute Commands on the System
21530| [1003767] 'mod_frontpage' Module for Apache Web Server Has Buffer Overlow in 'fpexec.c' That Allows Remote Users to Execute Arbitrary Code on the System with Root Privileges
21531| [1003723] Apache-SSL for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
21532| [1003664] 'mod_ssl' Security Package for Apache Web Server Has Buffer Overflow That Can Be Triggered By Remote Users
21533| [1003602] GNUJSP Java Server Pages Implementation Discloses Web Files and Source Code to Remote Users and Bypasses Apache Access Control Restrictions
21534| [1003465] PHP for Apache Web Server May Disclose Installation Path Information to Remote Users Making 'OPTIONS' Requests
21535| [1003451] Oracle Application Server PL/SQL Module for Apache Has Buffer Overflows That Allow Remote Users to Execute Arbitrary Code and Gain Access to the Server
21536| [1003131] Apache Web Server in Virtual Hosting Mode Can Be Crashed By a Local User Removing a Log Directory
21537| [1003104] PHP.EXE Windows CGI for Apache Web Server May Let Remote Users View Files on the Server Due to Configuration Error
21538| [1003008] Apache 'mod_bf' Module Lets Remote Users Execute Arbitrary Code
21539| [1002629] Apache suEXEC Wrapper Fails to Observe Minimum Group ID Security Settings in Certain Situations
21540| [1002542] Apache Web Server Virtual Hosting Split-Logfile Function Lets Remote Users Write Log Entries to Arbitrary Files on the System
21541| [1002400] Apache mod_gzip Module Has Buffer Overflow That Can Be Exploited By Local Users to Gain Elevated Privileges
21542| [1002303] Several 3rd Party Apache Authentication Modules Allow Remote Users to Execute Arbitrary Code to Gain Access to the System or Execute Stored Procedures to Obtain Arbitrary Database Information
21543| [1002188] Apache Web Server Discloses Internal IP Addresses to Remote Users in Certain Configurations
21544| [1001989] Apache Web Server May Disclose Directory Contents Even If an Index.html File is Present in the Directory
21545| [1001719] Apache Web Server on Mac OS X Client Fails to Enforce File and Directory Access Protections, Giving Remote Users Access to Restricted Pages
21546| [1001572] Apache Web Server on Microsoft Windows Platforms Allows Remote Users to Crash the Web Server
21547| [1001304] Apache Web Server for Windows Lets Remote Users Crash the Web Server Application
21548| [1001083] Apache Web Server May Display Directory Index Listings Even if Directory Listings Are Disabled
21549|
21550| OSVDB - http://www.osvdb.org:
21551| [96078] Apache CloudStack Infrastructure Menu Setup Network Multiple Field XSS
21552| [96077] Apache CloudStack Global Settings Multiple Field XSS
21553| [96076] Apache CloudStack Instances Menu Display Name Field XSS
21554| [96075] Apache CloudStack Instances Menu Add Instances Network Name Field XSS
21555| [96074] Apache CloudStack Instances Menu Add Instances Review Step Multiple Field XSS
21556| [96031] Apache HTTP Server suEXEC Symlink Arbitrary File Access
21557| [95888] Apache Archiva Single / Double Quote Character Handling XSS Weakness
21558| [95885] Apache Subversion mod_dav_svn Module Crafted HTTP Request Handling Remote DoS
21559| [95706] Apache OpenOffice.org (OOo) OOXML Document File XML Element Handling Memory Corruption
21560| [95704] Apache OpenOffice.org (OOo) DOC File PLCF Data Handling Memory Corruption
21561| [95603] Apache Continuum web/util/GenerateRecipentNotifier.java recipient Parameter XSS
21562| [95602] Apache Continuum web/action/notifier/JabberProjectNotifierEditAction-jabberProjectNotifierSave-validation.xml Multiple Parameter XSS
21563| [95601] Apache Continuum web/action/notifier/JabberGroupNotifierEditAction-jabberProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
21564| [95600] Apache Continuum web/action/ScheduleAction-saveSchedule-validation.xml Multiple Parameter XSS
21565| [95599] Apache Continuumweb/action/BuildDefinitionAction-saveBuildDefinition-validation.xml Multiple Parameter XSS
21566| [95598] Apache Continuum web/action/AddProjectAction-addProject-validation.xml Multiple Parameter XSS
21567| [95597] Apache Continuum web/action/ProjectEditAction-projectSave-validation.xml Multiple Parameter XSS
21568| [95596] Apache Continuum web/action/notifier/IrcGroupNotifierEditAction-ircProjectGroupNotifierSave-validation.xml Multiple Parameter XSS
21569| [95595] Apache Continuum web/action/notifier/IrcProjectNotifierEditAction-ircProjectNotifierSave-validation.xml Multiple Parameter XSS
21570| [95594] Apache Continuum web/action/ProjectGroupAction.java Multiple Parameter XSS
21571| [95593] Apache Continuum web/action/AddProjectGroupAction.java Multiple Parameter XSS
21572| [95592] Apache Continuum web/action/AddProjectAction.java Multiple Parameter XSS
21573| [95523] Apache OFBiz Webtools Application View Log Screen Unspecified XSS
21574| [95522] Apache OFBiz Nested Expression Evaluation Arbitrary UEL Function Execution
21575| [95521] Apache HTTP Server mod_session_dbd Session Saving Unspecified Issue
21576| [95498] Apache HTTP Server mod_dav.c Crafted MERGE Request Remote DoS
21577| [95406] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Arbitrary Site Redirect
21578| [95405] Apache Struts DefaultActionMapper Multiple Prefixing Parameters Remote Code Execution
21579| [95011] Apache CXF XML Parser SOAP Message Handling CPU Resource Exhaustion Remote DoS
21580| [94705] Apache Geronimo RMI Classloader Exposure Serialized Object Handling Remote Code Execution
21581| [94651] Apache Santuario (XML Security for C++) XML Signature CanonicalizationMethod Parameter Spoofing Weakness
21582| [94636] Apache Continuum workingCopy.action userDirectory Traversal Arbitrary File Access
21583| [94635] Apache Maven SCM SvnCommandlineUtils Process Listing Local Password Disclosure
21584| [94632] Apache Maven Wagon SSH (wagon-ssh) Host Verification Failure MitM Weakness
21585| [94625] Apache Santuario (XML Security for C++) XML Signature Reference Crafted XPointer Expression Handling Heap Buffer Overflow
21586| [94618] Apache Archiva /archiva/security/useredit.action username Parameter XSS
21587| [94617] Apache Archiva /archiva/security/roleedit.action name Parameter XSS
21588| [94616] Apache Archiva /archiva/security/userlist!show.action roleName Parameter XSS
21589| [94615] Apache Archiva /archiva/deleteArtifact!doDelete.action groupId Parameter XSS
21590| [94614] Apache Archiva /archiva/admin/addLegacyArtifactPath!commit.action legacyArtifactPath.path Parameter XSS
21591| [94613] Apache Archiva /archiva/admin/addRepository.action Multiple Parameter XSS
21592| [94612] Apache Archiva /archiva/admin/editAppearance.action Multiple Parameter XSS
21593| [94611] Apache Archiva /archiva/admin/addLegacyArtifactPath.action Multiple Parameter XSS
21594| [94610] Apache Archiva /archiva/admin/addNetworkProxy.action Multiple Parameter XSS
21595| [94403] Apache Santuario (XML Security for C++) InclusiveNamespace PrefixList Processing Heap Overflow
21596| [94402] Apache Santuario (XML Security for C++) HMAC-based XML Signature Processing DoS
21597| [94401] Apache Santuario (XML Security for C++) XPointer Evaluation Stack Overflow
21598| [94400] Apache Santuario (XML Security for C++) HMAC-Based XML Signature Reference Element Validation Spoofing Weakness
21599| [94279] Apache Qpid CA Certificate Validation Bypass
21600| [94275] Apache Solr JettySolrRunner.java Can Not Find Error Message XSS
21601| [94233] Apache OpenJPA Object Deserialization Arbitrary Executable Creation
21602| [94042] Apache Axis JAX-WS Java Unspecified Exposure
21603| [93969] Apache Struts OGNL Expression Handling Double Evaluation Error Remote Command Execution
21604| [93796] Apache Subversion Filename Handling FSFS Repository Corruption Remote DoS
21605| [93795] Apache Subversion svnserve Server Aborted Connection Message Handling Remote DoS
21606| [93794] Apache Subversion contrib/hook-scripts/check-mime-type.pl svnlook Hyphenated argv Argument Handling Remote DoS
21607| [93793] Apache Subversion contrib/hook-scripts/svn-keyword-check.pl Filename Handling Remote Command Execution
21608| [93646] Apache Struts Crafted Parameter Arbitrary OGNL Code Execution
21609| [93645] Apache Struts URL / Anchor Tag includeParams Attribute Remote Command Execution
21610| [93636] Apache Pig Multiple Physical Operator Memory Exhaustion Remote Remote DoS
21611| [93635] Apache Wink DTD (Document Type Definition) Expansion Data Parsing Information Disclosure
21612| [93605] RT Apache::Session::File Session Replay Reuse Information Disclosure
21613| [93599] Apache Derby SYSCS_UTIL.SYSCS_SET_DATABASE_PROPERTY Boot Password Manipulation Re-encryption Failure Password Corruption
21614| [93555] Apache Commons Codec Invalid Base32 String Information Tunneling Weakness
21615| [93554] Apache HBase bulkLoadHFiles() Method ACL Bypass
21616| [93543] JBoss Enterprise Application Platform org.apache.catalina.connector.Response.encodeURL() Method MitM jsessionid Disclosure
21617| [93542] Apache ManifoldCF (Connectors Framework) org.apache.manifoldcf.crawler.ExportConfiguration Class Configuration Export Password Disclosure
21618| [93541] Apache Solr json.wrf Callback XSS
21619| [93524] Apache Hadoop GetSecurityDescriptorControl() Function Absolute Security Descriptor Handling NULL Descriptor Weakness
21620| [93521] Apache jUDDI Security API Token Session Persistence Weakness
21621| [93520] Apache CloudStack Default SSL Key Weakness
21622| [93519] Apache Shindig /ifr Cross-site Arbitrary Gadget Invocation
21623| [93518] Apache Solr /admin/analysis.jsp name Parameter XSS
21624| [93517] Apache CloudStack setup-cloud-management /etc/sudoers Modification Local Privilege Escalation
21625| [93516] Apache CXF UsernameTokenInterceptor Nonce Caching Replay Weakness
21626| [93515] Apache HBase table.jsp name Parameter XSS
21627| [93514] Apache CloudStack Management Server Unauthenticated Remote JMX Connection Default Setting Weakness
21628| [93463] Apache Struts EL / OGNL Interpretation Unspecified Remote Code Execution
21629| [93462] Apache CXF WS-SecurityPolicy AlgorithmSuite Arbitrary Ciphertext Decryption Weakness
21630| [93401] Apache Hadoop core-site.xml Permission Weakness Local Alfredo Secret Disclosure
21631| [93400] Apache Hadoop Map/Reduce Job Log Directory Symlink Arbitrary File Mode Manipulation
21632| [93397] Apache Wicket Referrer HTTP Header Session ID Disclosure
21633| [93366] Apache HTTP Server modules/mappers/mod_rewrite.c do_rewritelog() Function Log File Terminal Escape Sequence Filtering Remote Command Execution
21634| [93254] Apache Tomcat AsyncListener Method Cross-session Information Disclosure
21635| [93253] Apache Tomcat Chunked Transfer Encoding Data Saturation Remote DoS
21636| [93252] Apache Tomcat FORM Authenticator Session Fixation
21637| [93172] Apache Camel camel/endpoints/ Endpoint XSS
21638| [93171] Apache Sling HtmlResponse Error Message XSS
21639| [93170] Apache Directory DelegatingAuthenticator MitM Spoofing Weakness
21640| [93169] Apache Wave AuthenticationServlet.java Session Fixation Weakness
21641| [93168] Apache Click ErrorReport.java id Parameter XSS
21642| [93167] Apache ActiveMQ JMSXUserId Spoofing Weakness
21643| [93166] Apache CXF Crafted Message Element Count Handling System Resource Exhaustion Remote DoS
21644| [93165] Apache CXF Crafted Message Element Level Handling System Resource Exhaustion Remote DoS
21645| [93164] Apache Harmony DatagramSocket Class connect Method CheckAccept() IP Blacklist Bypass
21646| [93163] Apache Hadoop Map/Reduce Daemon Symlink Arbitrary File Overwrite
21647| [93162] Apache VelocityStruts struts/ErrorsTool.getMsgs Error Message XSS
21648| [93161] Apache CouchDB Rewriter VM Atom Table Memory Exhaustion Remote DoS
21649| [93158] Apache Wicket BookmarkablePageLink Feature XSS CSRF
21650| [93157] Apache Struts UrlHelper.java s:url includeParams Functionality XSS
21651| [93156] Apache Tapestry Calendar Component datefield.js datefield Parameter XSS
21652| [93155] Apache Struts fielderror.ftl fielderror Parameter Error Message XSS
21653| [93154] Apache JSPWiki Edit.jsp createPages WikiPermission Bypass
21654| [93153] Apache PDFBox PDFXrefStreamParser Missing Element Handling PDF Parsing DoS
21655| [93152] Apache Hadoop HttpServer.java Multiple Function XSS
21656| [93151] Apache Shiro Search Filter userName Parameter LDAP Code Injection Weakness
21657| [93150] Apache Harmony java.net.SocketPermission Class boolean equals Function checkConnect() Weakness Host Name Retrieval
21658| [93149] Apache Harmony java.security.Provider Class void load Function checkSecurityAccess() Weakness
21659| [93148] Apache Harmony java.security.ProtectionDomain Class java.lang.String.toString() Function checkPermission() Weakness
21660| [93147] Apache Harmony java.net.URLConnection openConnection Function checkConnect Weakness Proxy Connection Permission Bypass
21661| [93146] Apache Harmony java.net.ServerSocket Class void implAccept Function checkAccept() Weakness SerSocket Subclass Creation
21662| [93145] Apache Qpid JMS Client Detached Session Frame Handling NULL Pointer Dereference Remote DoS
21663| [93144] Apache Solr Admin Command Execution CSRF
21664| [93009] Apache VCL XMLRPC API Unspecified Function Remote Privilege Escalation
21665| [93008] Apache VCL Web GUI Unspecified Remote Privilege Escalation
21666| [92997] Apache Commons Codec org.apache.commons.codec.net.URLCodec Fields Missing 'final' Thread-safety Unspecified Issue
21667| [92976] Apache ActiveMQ scheduled.jsp crontab Command XSS
21668| [92947] Apache Commons Codec org.apache.commons.codec.language.Soundex.US_ENGLISH_MAPPING Missing MS_PKGPROTECT Field Manipulation Unspecified Issue
21669| [92749] Apache CloudStack Predictable Hash Virtual Machine Console Console Access URL Generation
21670| [92748] Apache CloudStack VM Console Access Restriction Bypass
21671| [92709] Apache ActiveMQ Web Console Unauthenticated Remote Access
21672| [92708] Apache ActiveMQ Sample Web Application Broker Resource Consumption Remote DoS
21673| [92707] Apache ActiveMQ webapp/websocket/chat.js Subscribe Message XSS
21674| [92706] Apache ActiveMQ Debug Log Rendering XSS
21675| [92705] Apache ActiveMQ PortfolioPublishServlet.java refresh Parameter XSS
21676| [92270] Apache Tomcat Unspecified CSRF
21677| [92094] Apache Subversion mod_dav_svn Module Nonexistent URL Lock Request Handling NULL Pointer Dereference Remote DoS
21678| [92093] Apache Subversion mod_dav_svn Module Activity URL PROPFIND Request Handling NULL Pointer Dereference Remote DoS
21679| [92092] Apache Subversion mod_dav_svn Module Log REPORT Request Handling NULL Pointer Dereference Remote DoS
21680| [92091] Apache Subversion mod_dav_svn Module Node Property Handling Resource Exhaustion Remote DoS
21681| [92090] Apache Subversion mod_dav_svn Module Activity URL Lock Request Handling NULL Pointer Dereference Remote DoS
21682| [91774] Apache Commons Codec Unspecified Non-private Field Manipulation Weakness
21683| [91628] mod_ruid2 for Apache HTTP Server fchdir() Inherited File Descriptor chroot Restriction Bypass
21684| [91328] Apache Wicket $up$ Traversal Arbitrary File Access
21685| [91295] Apple Mac OS X Apache Unicode Character URI Handling Authentication Bypass
21686| [91235] Apache Rave /app/api/rpc/users/get User Object Hashed Password Remote Disclosure
21687| [91185] Munin Default Apache Configuration Permission Weakness Remote Information Disclosure
21688| [91173] Apache Wicket WebApplicationPath Constructor Bypass /WEB-INF/ Directory File Access
21689| [91172] Apache Wicket PackageResourceGuard File Extension Filter Bypass
21690| [91025] Apache Qpid qpid::framing::Buffer Class Multiple Method Out-of-bounds Access Remote DoS
21691| [91024] Apache Qpid federation_tag Attribute Handling Federated Interbroker Link Access Restriction Bypass
21692| [91023] Apache Qpid AMQP Type Decoder Exposure Array Size Value Handling Memory Consumption Remote DoS
21693| [91022] Apache Qpid qpid/cpp/include/qpid/framing/Buffer.h qpid::framing::Buffer::checkAvailable() Function Integer Overflow
21694| [90986] Apache Jena ARQ INSERT DATA Request Handling Overflow
21695| [90907] Apache Subversion mod_dav_svn / libsvn_fs svn_fs_file_length() Function MKACTIVITY / PROPFIND Option Request Handling Remote DoS
21696| [90906] Apache Commons FileUpload /tmp Storage Symlink Arbitrary File Overwrite
21697| [90864] Apache Batik 1xx Redirect Script Origin Restriction Bypass
21698| [90858] Apache Ant Malformed TAR File Handling Infinite Loop DoS
21699| [90852] Apache HTTP Server for Debian apachectl /var/lock Permission Weakness Symlink Directory Permission Manipulation
21700| [90804] Apache Commons CLI Path Subversion Local Privilege Escalation
21701| [90802] Apache Avro Recursive Schema Handling Infinite Recursion DoS
21702| [90592] Apache Batik ApplicationSecurityEnforcer.java Multiple Method Security Restriction Bypass
21703| [90591] Apache Batik XML External Entity (XXE) Data Parsing Arbitrary File Disclosure
21704| [90565] Apache Tomcat Log Directory Permission Weakness Local Information Disclosure
21705| [90564] Apache Maven / Maven Wagon SSL Certificate Validation MitM Spoofing Weakness
21706| [90557] Apache HTTP Server mod_proxy_balancer balancer-manager Interface Multiple Parameter XSS
21707| [90556] Apache HTTP Server Multiple Module Multiple Parameter XSS
21708| [90276] Apache Axis2 axis2.xml Plaintext Password Local Disclosure
21709| [90249] Apache Axiom ClassLoader XMLInputFactory / XMLOutputFactory Construction Unspecified Issue
21710| [90235] Apache Commons HttpClient Certificate Wildcard Matching Weakness
21711| [90079] Apache CXF WSS4JInInterceptor URIMappingInterceptor WS-Security SOAP Service Access Restriction Bypass
21712| [90078] Apache CXF WS-SecurityPolicy Enabled Plaintext UsernameTokens Handling Authentication Bypass
21713| [89453] Apache Open For Business Project (OFBiz) Screenlet.title Widget Attribute XSS
21714| [89452] Apache Open For Business Project (OFBiz) Image.alt Widget Attribute XSS
21715| [89294] Apache CouchDB Futon UI Browser-based Test Suite Query Parameter XSS
21716| [89293] Apache CouchDB Unspecified Traversal Arbitrary File Access
21717| [89275] Apache HTTP Server mod_proxy_ajp Module Expensive Request Parsing Remote DoS
21718| [89267] Apache CouchDB JSONP Callback Handling Unspecified XSS
21719| [89146] Apache CloudStack Master Server log4j.conf SSH Private Key / Plaintext Password Disclosure
21720| [88603] Apache OpenOffice.org (OOo) Unspecified Information Disclosure
21721| [88602] Apache OpenOffice.org (OOo) Unspecified Manifest-processing Issue
21722| [88601] Apache OpenOffice.org (OOo) Unspecified PowerPoint File Handling Issue
21723| [88285] Apache Tomcat Partial HTTP Request Saturation Remote DoS
21724| [88095] Apache Tomcat NIO Connector Terminated Connection Infinte Loop DoS
21725| [88094] Apache Tomcat FORM Authentication Crafted j_security_check Request Security Constraint Bypass
21726| [88093] Apache Tomcat Null Session Requst CSRF Prevention Filter Bypass
21727| [88043] IBM Tivoli Netcool/Reporter Apache CGI Unspecified Remote Command Execution
21728| [87580] Apache Tomcat DIGEST Authentication Session State Caching Authentication Bypass Weakness
21729| [87579] Apache Tomcat DIGEST Authentication Stale Nonce Verification Authentication Bypass Weakness
21730| [87477] Apache Tomcat Project Woodstock Service Error Page UTF-7 XSS Weakness
21731| [87227] Apache Tomcat InternalNioInputBuffer.java parseHeaders() Function Request Header Size Parsing Remote DoS
21732| [87223] Apache Tomcat DIGEST Authentication replay-countermeasure Functionality cnonce / cn Verification Authentication Bypass Weakness
21733| [87160] Apache Commons HttpClient X.509 Certificate Domain Name Matching MiTM Weakness
21734| [87159] Apache CXF X.509 Certificate Domain Name Matching MiTM Weakness
21735| [87150] Apache Axis / Axis2 X.509 Certificate Domain Name Matching MiTM Weakness
21736| [86902] Apache HTTP Server 3xx Redirect Internal IP Address Remote Disclosure
21737| [86901] Apache Tomcat Error Message Path Disclosure
21738| [86684] Apache CloudStack Unauthorized Arbitrary API Call Invocation
21739| [86556] Apache Open For Business Project (OFBiz) Unspecified Issue
21740| [86503] Visual Tools VS home/apache/DiskManager/cron/init_diskmgr Local Command Execution
21741| [86401] Apache ActiveMQ ResourceHandler Traversal Arbitrary File Access
21742| [86225] Apache Axis2 XML Signature Wrapping (XSW) Authentication Bypass
21743| [86206] Apache Axis2 Crafted SAML Assertion Signature Exclusion Attack Authentication Bypass
21744| [85722] Apache CXF SOAP Request Parsing Access Restriction Bypass
21745| [85704] Apache Qpid Incoming Client Connection Saturation Remote DoS
21746| [85474] Eucalyptus Apache Santuario (XML Security for Java) Library XML Signature Transform Handling DoS
21747| [85430] Apache mod_pagespeed Module Unspecified XSS
21748| [85429] Apache mod_pagespeed Module Hostname Verification Cross-host Resource Disclosure
21749| [85249] Apache Wicket Unspecified XSS
21750| [85236] Apache Hadoop conf/hadoop-env.sh Temporary File Symlink Arbitrary File Manipulation
21751| [85090] Apache HTTP Server mod_proxy_ajp.c mod_proxy_ajp Module Proxy Functionality Cross-client Information Disclosure
21752| [85089] Apache HTTP Server mod_proxy_http.c mod_proxy_http Module Cross-client Information Disclosure
21753| [85062] Apache Solr Autocomplete Module for Drupal Autocomplete Results XSS
21754| [85010] Apache Struts Token Handling Mechanism Token Name Configuration Parameter CSRF Weakness
21755| [85009] Apache Struts Request Parameter OGNL Expression Parsing Remote DoS
21756| [84911] libapache2-mod-rpaf X-Forward-For HTTP Header Parsing Remote DoS
21757| [84823] Apache HTTP Server Multiple Module Back End Server Error Handling HTTP Request Parsing Remote Information Disclosure
21758| [84818] Apache HTTP Server mod_negotiation Module mod_negotiation.c make_variant_list Function XSS
21759| [84562] Apache Qpid Broker Authentication Mechanism AMQP Client Shadow Connection NullAuthenticator Request Parsing Authentication Bypass
21760| [84458] Apache Libcloud SSL Certificate Validation MitM Spoofing Weakness
21761| [84279] PHP on Apache php_default_post_reader POST Request Handling Overflow DoS
21762| [84278] PHP w/ Apache PDO::ATTR_DEFAULT_FETCH_MODE / PDO::FETCH_CLASS DoS
21763| [84231] Apache Hadoop DataNodes Client BlockTokens Arbitrary Block Access
21764| [83943] Oracle Solaris Cluster Apache Tomcat Agent Subcomponent Unspecified Local Privilege Escalation
21765| [83939] Oracle Solaris Apache HTTP Server Subcomponent Unspecified Remote Information Disclosure
21766| [83685] svnauthcheck Apache HTTP Configuration File Permission Revocation Weakness
21767| [83682] Apache Sling POST Servlet @CopyFrom Operation HTTP Request Parsing Infinite Loop Remote DoS
21768| [83339] Apache Roller Blogger Roll Unspecified XSS
21769| [83270] Apache Roller Unspecified Admin Action CSRF
21770| [82782] Apache CXF WS-SecurityPolicy 1.1 SupportingToken Policy Bypass
21771| [82781] Apache CXF WS-SecurityPolicy Supporting Token Children Specification Token Signing Verification Weakness
21772| [82611] cPanel Apache Piped Log Configuration Log Message Formatting Traversal Arbitrary File Creation
21773| [82436] MapServer for Windows Bundled Apache / PHP Configuration Local File Inclusion
21774| [82215] PHP sapi/cgi/cgi_main.c apache_request_headers Function HTTP Header Handling Remote Overflow
21775| [82161] Apache Commons Compress bzip2 File Compression BZip2CompressorOutputStream Class File Handling Remote DoS
21776| [81965] Apache Batik Squiggle SVG Browser JAR File Arbitrary Code Execution
21777| [81790] Apache POI src/org/apache/poi/hwpf/model/UnhandledDataStructure.java UnhandledDataStructure() constructor Length Attribute CDF / CFBF File Handling Remote DoS
21778| [81660] Apache Qpid Credential Checking Cluster Authentication Bypass
21779| [81511] Apache for Debian /usr/share/doc HTTP Request Parsing Local Script Execution
21780| [81359] Apache HTTP Server LD_LIBRARY_PATH Variable Local Privilege Escalation
21781| [81349] Apache Open For Business Project (OFBiz) Webslinger Component Unspecified XSS
21782| [81348] Apache Open For Business Project (OFBiz) Content IDs / Map-Keys Unspecified XSS
21783| [81347] Apache Open For Business Project (OFBiz) Parameter Arrays Unspecified XSS
21784| [81346] Apache Open For Business Project (OFBiz) checkoutProcess.js getServerError() Function Unspecified XSS
21785| [81196] Apache Open For Business Project (OFBiz) FlexibleStringExpander Nested Script String Parsing Remote Code Execution
21786| [80981] Apache Hadoop Kerberos/MapReduce Security Feature User Impersonation Weakness
21787| [80571] Apache Traffic Server Host HTTP Header Parsing Remote Overflow
21788| [80547] Apache Struts XSLTResult.java File Upload Arbitrary Command Execution
21789| [80360] AskApache Password Protector Plugin for WordPress Error Page $_SERVER Superglobal XSS
21790| [80349] Apache HTTP Server mod_fcgid Module fcgid_spawn_ctl.c FcgidMaxProcessesPerClass Virtual Host Directive HTTP Request Parsing Remote DoS
21791| [80301] Apache Wicket /resources/ Absolute Path Arbitrary File Access
21792| [80300] Apache Wicket wicket:pageMapName Parameter XSS
21793| [79478] Apache Solr Extension for TYPO3 Unspecified XSS
21794| [79002] Apache MyFaces javax.faces.resource In Parameter Traversal Arbitrary File Access
21795| [78994] Apache Struts struts-examples/upload/upload-submit.do name Parameter XSS
21796| [78993] Apache Struts struts-cookbook/processDyna.do message Parameter XSS
21797| [78992] Apache Struts struts-cookbook/processSimple.do message Parameter XSS
21798| [78991] Apache Struts struts2-rest-showcase/orders clientName Parameter XSS
21799| [78990] Apache Struts struts2-showcase/person/editPerson.action Multiple Parameter XSS
21800| [78932] Apache APR Hash Collision Form Parameter Parsing Remote DoS
21801| [78903] Apache CXF SOAP Request Parsing WS-Security UsernameToken Policy Bypass
21802| [78600] Apache Tomcat HTTP DIGEST Authentication DigestAuthenticator.java Catalina Weakness Security Bypass
21803| [78599] Apache Tomcat HTTP DIGEST Authentication Realm Value Parsing Security Bypass
21804| [78598] Apache Tomcat HTTP DIGEST Authentication qop Value Parsing Security Bypass
21805| [78573] Apache Tomcat Parameter Saturation CPU Consumption Remote DoS
21806| [78556] Apache HTTP Server Status Code 400 Default Error Response httpOnly Cookie Disclosure
21807| [78555] Apache HTTP Server Threaded MPM %{cookiename}C Log Format String Cookie Handling Remote DoS
21808| [78501] Apache Struts ParameterInterceptor Class OGNL Expression Parsing Remote Command Execution
21809| [78331] Apache Tomcat Request Object Recycling Information Disclosure
21810| [78293] Apache HTTP Server Scoreboard Invalid Free Operation Local Security Bypass
21811| [78277] Apache Struts ExceptionDelegator Component Parameter Parsing Remote Code Execution
21812| [78276] Apache Struts DebuggingInterceptor Component Developer Mode Unspecified Remote Command Execution
21813| [78113] Apache Tomcat Hash Collision Form Parameter Parsing Remote DoS
21814| [78112] Apache Geronimo Hash Collision Form Parameter Parsing Remote DoS
21815| [78109] Apache Struts ParameterInterceptor Traversal Arbitrary File Overwrite
21816| [78108] Apache Struts CookieInterceptor Cookie Name Handling Remote Command Execution
21817| [77593] Apache Struts Conversion Error OGNL Expression Injection
21818| [77496] Apache ActiveMQ Failover Mechanism Openwire Request Parsing Remote DoS
21819| [77444] Apache HTTP Server mod_proxy Mdule Web Request HTTP/0.9 Protocol URL Parsing Proxy Remote Security Bypass
21820| [77374] Apache MyFaces Java Bean includeViewParameters Parsing EL Expression Security Weakness
21821| [77310] Apache HTTP Server mod_proxy Reverse Proxy Mode Security Bypass Weakness (2011-4317)
21822| [77234] Apache HTTP Server on cygwin Encoded Traversal Arbitrary File Access
21823| [77012] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Memory Consumption DoS
21824| [76944] Apache Tomcat Manager Application Servlets Access Restriction Bypass
21825| [76744] Apache HTTP Server server/utils.c ap_pregsub() Function htaccess File Handling Local Overflow
21826| [76189] Apache Tomcat HTTP DIGEST Authentication Weakness
21827| [76079] Apache HTTP Server mod_proxy Mdule Web Request URL Parsing Proxy Remote Security Bypass (2011-3368)
21828| [76072] Apache JServ jserv.conf jserv-status Handler jserv/ URI Request Parsing Local Information Disclosure
21829| [75807] Apache HTTP Server Incomplete Header Connection Saturation Remote DoS
21830| [75647] Apache HTTP Server mod_proxy_ajp Module mod_proxy_balancer HTTP Request Remote DoS
21831| [75376] Apache Libcloud SSL Certificate Validation MitM Server Spoofing Weakness
21832| [74853] Domain Technologie Control /etc/apache2/apache2.conf File Permissions Weakness dtcdaemons User Password Disclosure
21833| [74818] Apache Tomcat AJP Message Injection Authentication Bypass
21834| [74725] Apache Wicket Multi Window Support Unspecified XSS
21835| [74721] Apache HTTP Server ByteRange Filter Memory Exhaustion Remote DoS
21836| [74541] Apache Commons Daemon Jsvc Permissions Weakness Arbitrary File Access
21837| [74535] Apache Tomcat XML Parser Cross-application Multiple File Manipulation
21838| [74447] Apache Struts XWork Nonexistent Method s:submit Element Internal Java Class Remote Path Disclosure
21839| [74262] Apache HTTP Server Multi-Processing Module itk.c Configuration Merger mpm-itk root UID / GID Remote Privilege Escalation
21840| [74120] Apache HTTP Server mod_authnz_external mysql/mysql-auth.pl user Field SQL Injection
21841| [73920] Oracle Secure Backup /apache/htdocts/php/common.php username Parameter Remote Code Execution
21842| [73798] Apache Tomcat sendfile Request Start / Endpoint Parsing Local DoS
21843| [73797] Apache Tomcat sendfile Request Attribute Validation Weakness Local Access Restriction Bypass
21844| [73776] Apache Tomcat HTTP BIO Connector HTTP Pipelining Cross-user Remote Response Access
21845| [73644] Apache XML Security Signature Key Parsing Overflow DoS
21846| [73600] Apache Struts javatemplates Plugin Component Handlers .action URI Multiple Parameter XSS
21847| [73462] Apache Rampart/C util/rampart_timestamp_token.c rampart_timestamp_token_validate Function Expired Token Remote Access Restriction Bypass
21848| [73429] Apache Tomcat JMX MemoryUserDatabase Local Password Disclosure
21849| [73384] Apache HTTP Server mod_rewrite PCRE Resource Exhaustion DoS
21850| [73383] Apache HTTP Server Portable Runtime (APR) Library apr_fnmatch() Infinite Loop Remote DoS
21851| [73378] IBM WebSphere Application Server (WAS) JavaServer Pages org.apache.jasper.runtime.JspWriterImpl.response JSP Page Application Restart Remote DoS
21852| [73247] Apache Subversion mod_dav_svn File Permission Weakness Information Disclosure
21853| [73246] Apache Subversion mod_dav_svn Path-based Access Control Rule Handling Remote DoS
21854| [73245] Apache Subversion mod_dav_svn Baselined Resource Request Handling Remote DoS
21855| [73154] Apache Archiva Multiple Unspecified CSRF
21856| [73153] Apache Archiva /archiva/admin/deleteNetworkProxy!confirm.action proxyid Parameter XSS
21857| [72407] Apache Tomcat @ServletSecurity Initial Load Annotation Security Constraint Bypass Information Disclosure
21858| [72238] Apache Struts Action / Method Names <
21859| [71647] Apache HttpComponents HttpClient Proxy-Authorization Credentials Remote Disclosure
21860| [71558] Apache Tomcat SecurityManager ServletContext Attribute Traversal Arbitrary File Manipulation
21861| [71557] Apache Tomcat HTML Manager Multiple XSS
21862| [71075] Apache Archiva User Management Page XSS
21863| [71027] Apache Tomcat @ServletSecurity Annotation Security Constraint Bypass Information Disclosure
21864| [70925] Apache Continuum Project Pages Unspecified XSS (2011-0533)
21865| [70924] Apache Continuum Multiple Admin Function CSRF
21866| [70809] Apache Tomcat NIO HTTP Connector Request Line Processing DoS
21867| [70734] Apache CouchDB Request / Cookie Handling Unspecified XSS
21868| [70585] Oracle Fusion Middleware Oracle HTTP Server Apache Plugin Unspecified Remote Issue
21869| [70333] Apache Subversion rev_hunt.c blame Command Multiple Memory Leak Remote DoS
21870| [70332] Apache Subversion Apache HTTP Server mod_dav_svn repos.c walk FunctionSVNParentPath Collection Remote DoS
21871| [69659] Apache Archiva Admin Authentication Weakness Privilege Escalation
21872| [69520] Apache Archiva Administrator Credential Manipulation CSRF
21873| [69512] Apache Tomcat Set-Cookie Header HTTPOnly Flag Session Hijacking Weakness
21874| [69456] Apache Tomcat Manager manager/html/sessions Multiple Parameter XSS
21875| [69275] Apache mod_fcgid Module fcgid_bucket.c fcgid_header_bucket_read() Function Remote Overflow
21876| [69067] Apache Shiro URI Path Security Traversal Information Disclosure
21877| [68815] Apache MyFaces shared/util/StateUtils.java View State MAC Weakness Cryptographic Padding Remote View State Modification
21878| [68670] Apache Qpid C++ Broker Component broker/SessionAdapter.cpp SessionAdapter::ExchangeHandlerImpl::checkAlternate Function Exchange Alternate Remote DoS
21879| [68669] Apache Qpid cluster/Cluster.cpp Cluster::deliveredEvent Function Invalid AMQP Data Remote DoS
21880| [68662] Apache Axis2 dswsbobje.war Module Admin Account Default Password
21881| [68531] Apache Qpid qpidd sys/ssl/SslSocket.cpp Incomplete SSL Handshake Remote DoS
21882| [68327] Apache APR-util buckets/apr_brigade.c apr_brigade_split_line() Function Memory Consumption DoS
21883| [68314] Apache XML-RPC SAX Parser External Entity Information Disclosure
21884| [67964] Apache Traffic Server Transaction ID / Source Port Randomization Weakness DNS Cache Poisoning
21885| [67846] SUSE Lifecycle Management Server on SUSE Linux Enterprise apache2-slms Parameter Quoting CSRF
21886| [67294] Apache CXF XML SOAP Message Crafted Document Type Declaration Remote DoS
21887| [67240] Apache CouchDB Installation Page Direct Request Arbitrary JavaScript Code Execution CSRF
21888| [67205] Apache Derby BUILTIN Authentication Password Hash Generation Algorithm SHA-1 Transformation Password Substitution
21889| [66745] Apache HTTP Server Multiple Modules Pathless Request Remote DoS
21890| [66319] Apache Tomcat Crafted Transfer-Encoding Header Handling Buffer Recycling Remote DoS
21891| [66280] Apache Struts XWork ParameterInterceptor Server-Side Object Remote Code Execution
21892| [66226] Apache Axis2 Admin Interface Cookie Session Fixation
21893| [65697] Apache Axis2 / Java SOAP Message DTD Rejection Weakness Arbitrary File Access
21894| [65654] Apache HTTP Server mod_proxy_http mod_proxy_http.c Timeout Detection Weakness HTTP Request Response Disclosure
21895| [65429] Apache MyFaces Unencrypted ViewState Serialized View Object Manipulation Arbitrary Expression Language (EL) Statement Execution
21896| [65054] Apache ActiveMQ Jetty Error Handler XSS
21897| [64844] Apache Axis2/Java axis2/axis2-admin/engagingglobally modules Parameter XSS
21898| [64522] Apache Open For Business Project (OFBiz) ecommerce/control/contactus Multiple Parameter XSS
21899| [64521] Apache Open For Business Project (OFBiz) Web Tools Section entityName Parameter XSS
21900| [64520] Apache Open For Business Project (OFBiz) ecommerce/control/ViewBlogArticle contentId Parameter XSS
21901| [64519] Apache Open For Business Project (OFBiz) Control Servlet URI XSS
21902| [64518] Apache Open For Business Project (OFBiz) Show Portal Page Section start Parameter XSS
21903| [64517] Apache Open For Business Project (OFBiz) View Profile Section partyId Parameter XSS
21904| [64516] Apache Open For Business Project (OFBiz) Export Product Listing Section productStoreId Parameter XSS
21905| [64307] Apache Tomcat Web Application Manager/Host Manager CSRF
21906| [64056] mod_auth_shadow for Apache HTTP Server wait() Function Authentication Bypass
21907| [64023] Apache Tomcat WWW-Authenticate Header Local Host Information Disclosure
21908| [64020] Apache ActiveMQ Jetty ResourceHandler Crafted Request JSP File Source Disclosure
21909| [63895] Apache HTTP Server mod_headers Unspecified Issue
21910| [63368] Apache ActiveMQ createDestination.action JMSDestination Parameter CSRF
21911| [63367] Apache ActiveMQ createDestination.action JMSDestination Parameter XSS
21912| [63350] Apache CouchDB Hash Verification Algorithm Predictable Execution Time Weakness
21913| [63140] Apache Thrift Service Malformed Data Remote DoS
21914| [62676] Apache HTTP Server mod_proxy_ajp Module Crafted Request Remote DoS
21915| [62675] Apache HTTP Server Multi-Processing Module (MPM) Subrequest Header Handling Cross-thread Information Disclosure
21916| [62674] Apache HTTP Server mod_isapi Module Unloading Crafted Request Remote DoS
21917| [62231] Apache HTTP Server Logging Format Weakness Crafted DNS Response IP Address Spoofing
21918| [62230] Apache HTTP Server Crafted DNS Response Inverse Lookup Log Corruption XSS
21919| [62054] Apache Tomcat WAR Filename Traversal Work-directory File Deletion
21920| [62053] Apache Tomcat Autodeployment Process appBase File HTTP Request Authentication Bypass
21921| [62052] Apache Tomcat WAR File Traversal Arbitrary File Overwrite
21922| [62009] Apache HTTP Server src/modules/proxy/proxy_util.c mod_proxy ap_proxy_send_fb() Function Overflow
21923| [61379] Apache River Outrigger Entry Storage Saturation Memory Exhaustion DoS
21924| [61378] Apache Hadoop Map/Reduce JobTracker Memory Consumption DoS
21925| [61377] Apache Commons Modeler Multiple Mutable Static Fields Weakness
21926| [61376] Apache Rampart wsse:security Tag Signature Value Checking Weakness
21927| [60687] Apache C++ Standard Library (STDCXX) strxfrm() Function Overflow
21928| [60680] Apache Hadoop JobHistory Job Name Manipulation Weakness
21929| [60679] Apache ODE DeploymentWebService OMElement zipPart CRLF Injection
21930| [60678] Apache Roller Comment Email Notification Manipulation DoS
21931| [60677] Apache CouchDB Unspecified Document Handling Remote DoS
21932| [60428] Sun Java Plug-in org.apache.crimson.tree.XmlDocument Class reateXmlDocument Method Floppy Drive Access Bypass
21933| [60413] mod_throttle for Apache Shared Memory File Manipulation Local Privilege Escalation
21934| [60412] Sun Java Plug-in org.apache.xalan.processor.XSLProcessorVersion Class Unsigned Applet Variable Sharing Privilege Escalation
21935| [60396] Apache HTTP Server on OpenBSD Multipart MIME Boundary Remote Information Disclosure
21936| [60395] Apache HTTP Server on OpenBSD ETag HTTP Header Remote Information Disclosure
21937| [60232] PHP on Apache php.exe Direct Request Remote DoS
21938| [60176] Apache Tomcat Windows Installer Admin Default Password
21939| [60016] Apache HTTP Server on HP Secure OS for Linux HTTP Request Handling Unspecified Issue
21940| [59979] Apache HTTP Server on Apple Mac OS X HTTP TRACE Method Unspecified Client XSS
21941| [59969] Apache HTTP Server mod_ssl SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection
21942| [59944] Apache Hadoop jobhistory.jsp XSS
21943| [59374] Apache Solr Search Extension for TYPO3 Unspecified XSS
21944| [59022] Apache Shindig ConcatProxyServlet HTTP Header Response Splitting
21945| [59021] Apache Cocoon X-Cocoon-Version Header Remote Information Disclosure
21946| [59020] Apache Tapestry HTTPS Session Cookie Secure Flag Weakness
21947| [59019] Apache mod_python Cookie Salting Weakness
21948| [59018] Apache Harmony Error Message Handling Overflow
21949| [59013] Apache Derby SYSCS_EXPORT_TABLE Arbitrary File Overwrite
21950| [59012] Apache Derby Driver Auto-loading Non-deterministic Startup Weakness
21951| [59011] Apache JSPWiki Page Attachment Change Note Function XSS
21952| [59010] Apache Solr get-file.jsp XSS
21953| [59009] Apache Solr action.jsp XSS
21954| [59008] Apache Solr analysis.jsp XSS
21955| [59007] Apache Solr schema.jsp Multiple Parameter XSS
21956| [59006] Apache Beehive select / checkbox Tag XSS
21957| [59005] Apache Beehive jpfScopeID Global Parameter XSS
21958| [59004] Apache Beehive Error Message XSS
21959| [59003] Apache HttpClient POST Request Handling Memory Consumption DoS
21960| [59002] Apache Jetspeed default-page.psml URI XSS
21961| [59001] Apache Axis2 xsd Parameter Traversal Arbitrary File Disclosure
21962| [59000] Apache CXF Unsigned Message Policy Bypass
21963| [58999] Apache WSS4J CallbackHandler Plaintext Password Validation Weakness
21964| [58998] Apache OpenJPA persistence.xml Cleartext Password Local Disclosure
21965| [58997] Apache OpenEJB openejb.xml Cleartext Password Local Disclosure
21966| [58996] Apache Hadoop Map/Reduce LinuxTaskController File Group Ownership Weakness
21967| [58995] Apache Hadoop Map/Reduce Task Ownership Weakness
21968| [58994] Apache Hadoop Map/Reduce DistributedCache Localized File Permission Weakness
21969| [58993] Apache Hadoop browseBlock.jsp XSS
21970| [58991] Apache Hadoop browseDirectory.jsp XSS
21971| [58990] Apache Hadoop Map/Reduce HTTP TaskTrackers User Data Remote Disclosure
21972| [58989] Apache Hadoop Sqoop Process Listing Local Cleartext Password Disclosure
21973| [58988] Apache Hadoop Chukwa HICC Portal Unspecified XSS
21974| [58987] Apache Hadoop Map/Reduce TaskTracker User File Permission Weakness
21975| [58986] Apache Qpid Encrypted Message Handling Remote Overflow DoS
21976| [58985] Apache Qpid Process Listing Local Cleartext Password Disclosure
21977| [58984] Apache Jackrabbit Content Repository (JCR) Default Account Privilege Access Weakness
21978| [58983] Apache Jackrabbit Content Repository (JCR) NamespaceRegistry API Registration Method Race Condition
21979| [58982] Apache Synapse Proxy Service Security Policy Mismatch Weakness
21980| [58981] Apache Geronimo TomcatGeronimoRealm Security Context Persistence Weakness
21981| [58980] Apache Geronimo LDAP Realm Configuration Restart Reversion Weakness
21982| [58979] Apache MyFaces Tomahawk ExtensionsPhaseListener HTML Injection Information Disclosure
21983| [58978] Apache MyFaces Trinidad LocaleInfoScriptlet XSS
21984| [58977] Apache Open For Business Project (OFBiz) Multiple Default Accounts
21985| [58976] Apache Open For Business Project (OFBiz) URI passThru Parameter XSS
21986| [58975] Apache Open For Business Project (OFBiz) PARTYMGR_CREATE/UPDATE Permission Arbitrary User Password Modification
21987| [58974] Apache Sling /apps Script User Session Management Access Weakness
21988| [58973] Apache Tuscany Crafted SOAP Request Access Restriction Bypass
21989| [58931] Apache Geronimo Cookie Parameters Validation Weakness
21990| [58930] Apache Xalan-C++ XPath Handling Remote DoS
21991| [58879] Apache Portable Runtime (APR-util) poll/unix/port.c Event Port Backend Pollset Feature Remote DoS
21992| [58837] Apache Commons Net FTPSClient CipherSuites / Protocols Mutable Object Unspecified Data Security Issue
21993| [58813] Apache MyFaces Trinidad tr:table / HTML Comment Handling DoS
21994| [58812] Apache Open For Business Project (OFBiz) JSESSIONID Session Hijacking Weakness
21995| [58811] Apache Open For Business Project (OFBiz) /catalog/control/EditProductConfigItem configItemId Parameter XSS
21996| [58810] Apache Open For Business Project (OFBiz) /catalog/control/EditProdCatalo prodCatalogId Parameter XSS
21997| [58809] Apache Open For Business Project (OFBiz) /partymgr/control/viewprofile partyId Parameter XSS
21998| [58808] Apache Open For Business Project (OFBiz) /catalog/control/createProduct internalName Parameter XSS
21999| [58807] Apache Open For Business Project (OFBiz) Multiple Unspecified CSRF
22000| [58806] Apache FtpServer MINA Logging Filter Cleartext Credential Local Disclosure
22001| [58805] Apache Derby Unauthenticated Database / Admin Access
22002| [58804] Apache Wicket Header Contribution Unspecified Issue
22003| [58803] Apache Wicket Session Fixation
22004| [58802] Apache Directory Server (ApacheDS) userPassword Attribute Search Password Disclosure
22005| [58801] Apache ActiveMQ Stomp Client Credential Validation Bypass
22006| [58800] Apache Tapestry (context)/servicestatus Internal Service Information Disclosure
22007| [58799] Apache Tapestry Logging Cleartext Password Disclosure
22008| [58798] Apache Jetspeed pipeline Parameter pipeline-map Policy Bypass
22009| [58797] Apache Jetspeed Password Policy Multiple Weaknesses
22010| [58796] Apache Jetspeed Unsalted Password Storage Weakness
22011| [58795] Apache Rampart Crafted SOAP Header Authentication Bypass
22012| [58794] Apache Roller Admin Protocol (RAP) Malformed Header Authentication Bypass
22013| [58793] Apache Hadoop Map/Reduce mapred.system.dir Permission Weakness Job Manipulation
22014| [58792] Apache Shindig gadgets.rpc iframe RPC Call Validation Weakness
22015| [58791] Apache Synapse synapse.properties Cleartext Credential Local Disclosure
22016| [58790] Apache WSS4J SOAP Message UsernameToken Remote Password Disclosure
22017| [58789] Apache WSS4J SOAP Header Malformed UsernameToken Authentication Bypass
22018| [58776] Apache JSPWiki PreviewContent.jsp Edited Text XSS
22019| [58775] Apache JSPWiki preview.jsp action Parameter XSS
22020| [58774] Apache JSPWiki Edit.jsp Multiple Parameter XSS
22021| [58773] Apache JSPWiki Accept-Language Header Multiple Script language Parameter XSS
22022| [58772] Apache JSPWiki EditorManager.java editor Parameter XSS
22023| [58771] Apache JSPWiki GroupContent.jsp Multiple Parameter XSS
22024| [58770] Apache JSPWiki Group.jsp group Parameter XSS
22025| [58769] Apache JSPWiki Database Connection Termination DoS Weakness
22026| [58768] Apache JSPWiki Attachment Servlet nextpage Parameter Arbitrary Site Redirect
22027| [58766] Apache JSPWiki /admin/SecurityConfig.jsp Direct Request Information Disclosure
22028| [58765] Apache JSPWiki Spam Filter UniqueID RNG Weakness
22029| [58764] Apache JSPWiki Edit.jsp Multiple Parameter XSS
22030| [58763] Apache JSPWiki Include Tag Multiple Script XSS
22031| [58762] Apache JSPWiki Multiple .java Tags pageContext Parameter XSS
22032| [58761] Apache JSPWiki Wiki.jsp skin Parameter XSS
22033| [58760] Apache Commons VFS Exception Error Message Cleartext Credential Disclosure
22034| [58759] Apache Jackrabbit Content Repository (JCR) UUID System.currentTimeMillis() RNG Weakness
22035| [58758] Apache River GrantPermission Policy Manipulation Privilege Escalation
22036| [58757] Apache WS-Commons Java2 StaXUtils Multiple Unspecified Minor Issues
22037| [58756] Apache WSS4J WSHandler Client Certificate Signature Validation Weakness
22038| [58755] Apache Harmony DRLVM Non-public Class Member Access
22039| [58754] Apache Harmony File.createTempFile() Temporary File Creation Prediction Weakness
22040| [58751] Apache Geronimo GeronimoIdentityResolver Subject Handling Multiple Issues
22041| [58750] Apache MyFaces Trinidad Generated HTML Information Disclosure
22042| [58749] Apache MyFaces Trinidad Database Access Error Message Information Disclosure
22043| [58748] Apache MyFaces Trinidad Image Resource Loader Traversal Arbitrary Image Access
22044| [58747] Apache MyFaces Trinidad Error Message User Entered Data Disclosure Weakness
22045| [58746] Apache Axis2 JAX-WS Java2 WSDL4J Unspecified Issue
22046| [58744] Apache Wicket Crafted File Upload Disk Space Exhaustion DoS
22047| [58743] Apache Wicket wicket.util.crypt.SunJceCrypt Encryption Reversion Weakness
22048| [58742] Apache Rampart PolicyBasedValiadtor HttpsToken Endpoint Connection Weakness
22049| [58741] Apache Rampart WSSecSignature / WSSecEncryptedKey KeyIdentifierType Validation Weakness
22050| [58740] Apache Rampart TransportBinding Message Payload Cleartext Disclosure
22051| [58739] Apache Open For Business Project (OFBiz) Unsalted Password Storage Weakness
22052| [58738] Apache Open For Business Project (OFBiz) orderId Parameter Arbitrary Order Access
22053| [58737] Apache mod_python w/ mod_python.publisher index.py Underscore Prefixed Variable Disclosure
22054| [58735] Apache Open For Business Project (OFBiz) /ecommerce/control/keywordsearch SEARCH_STRING Parameter XSS
22055| [58734] Apache Torque Log File Cleartext Credential Local Disclosure
22056| [58733] Apache Axis2 doGet Implementation Authentication Bypass Service State Manipulation
22057| [58732] Apache MyFaces UIInput.validate() Null Value Validation Bypass Weakness
22058| [58731] Apache MyFaces /faces/* Prefix Mapping Authentication Bypass
22059| [58725] Apache Tapestry Basic String ACL Bypass Weakness
22060| [58724] Apache Roller Logout Functionality Failure Session Persistence
22061| [58723] Apache Roller User Profile / Admin Page Cleartext Password Disclosure
22062| [58722] Apache Derby Connection URL Encryption Method Reversion Weakness
22063| [58721] Apache Geronimo on Tomcat Security-constraint Resource ACL Bypass
22064| [58720] Apache Geronimo Explicit Servlet Mapping Access Bypass Weakness
22065| [58719] Apache Geronimo Keystore Unprivileged Service Disable DoS
22066| [58718] Apache Geronimo Deployment Plans Remote Password Disclosure
22067| [58717] Apache Jetspeed Portlet Application Edit Access Restriction Bypass
22068| [58716] Apache Jetspeed PSML Management Cached Constraint Authentication Weakness
22069| [58707] Apache WSS4J Crafted PasswordDigest Request Authentication Bypass
22070| [58706] Apache HttpClient Pre-emptive Authorization Remote Credential Disclosure
22071| [58705] Apache Directory Server (ApacheDS) User Passwords Cleartext Disclosure
22072| [58704] Apache Directory Server (ApacheDS) Non-existent User LDAP Bind Remote DoS
22073| [58703] Apache Geronimo Debug Console Unauthenticated Remote Information Disclosure
22074| [58702] Apache Directory Server (ApacheDS) Persistent LDAP Anonymous Bind Weakness
22075| [58701] Apache Jetspeed User Admin Portlet Unpassworded Account Creation Weakness
22076| [58700] Apache MyFaces /faces/* Path Handling Remote Overflow DoS
22077| [58699] Apache MyFaces Disable Property Client Side Manipulation Privilege Escalation
22078| [58698] Apache Roller Remember Me Functionality Cleartext Password Disclosure
22079| [58697] Apache XalanJ2 org.apache.xalan.xsltc.runtime.CallFunction Class Unspecified Issue
22080| [58696] Apache Tapestry Encoded Traversal Arbitrary File Access
22081| [58695] Apache Jetspeed Unauthenticated PSML Tags / Admin Folder Access
22082| [58694] Apache Geronimo Deploy Tool Process List Local Credential Disclosure
22083| [58693] Apache Derby service.properties File Encryption Key Information Disclosure
22084| [58692] Apache Geronimo Default Security Realm Login Brute Force Weakness
22085| [58689] Apache Roller Retrieve Last 5 Post Feature Unauthorized Blog Post Manipulation
22086| [58688] Apache Xalan-Java (XalanJ2) Static Variables Multiple Unspecified Issues
22087| [58687] Apache Axis Invalid wsdl Request XSS
22088| [58686] Apache Cocoon Temporary File Creation Unspecified Race Condition
22089| [58685] Apache Velocity Template Designer Privileged Code Execution
22090| [58684] Apache Jetspeed controls.Customize Action Security Check Bypass
22091| [58675] Apache Open For Business Project (OFBiz) eCommerce/ordermgr Multiple Field XSS
22092| [58674] Apache Open For Business Project (OFBiz) ecommerce/control/login Multiple Field XSS
22093| [58673] Apache Open For Business Project (OFBiz) ecommerce/control/viewprofile Multiple Field XSS
22094| [58672] Apache Open For Business Project (OFBiz) POS Input Panel Cleartext Password Disclosure
22095| [58671] Apache Axis2 JMS Signed Message Crafted WS-Security Header Security Bypass
22096| [58670] Apache Jetspeed JetspeedTool.getPortletFromRegistry Portlet Security Validation Failure
22097| [58669] Apache Jetspeed LDAP Cleartext Passwords Disclosure
22098| [58668] Apache Axis External Entity (XXE) Data Parsing Privilege Escalation
22099| [58667] Apache Roller Database Cleartext Passwords Disclosure
22100| [58666] Apache Xerces-C++ UTF-8 Transcoder Overlong Code Handling Unspecified Issue
22101| [58665] Apache Jetspeed Turbine: Cross-user Privileged Action Execution
22102| [58664] Apache Jetspeed EditAccount.vm Password Modification Weakness
22103| [58663] Apache Jetspeed Role Parameter Arbitrary Portlet Disclosure
22104| [58662] Apache Axis JWS Page Generated .class File Direct Request Information Disclosure
22105| [58661] Apache Jetspeed user-form.vm Password Reset Cleartext Disclosure
22106| [58660] Apache WSS4J checkReceiverResults Function Crafted SOAP Request Authentication Bypass
22107| [58658] Apache Rampart Crafted SOAP Request Security Verification Bypass
22108| [57882] Apache HTTP Server mod_proxy_ftp Authorization HTTP Header Arbitrary FTP Command Injection
22109| [57851] Apache HTTP Server mod_proxy_ftp EPSV Command NULL Dereference Remote DoS
22110| [56984] Apache Xerces2 Java Malformed XML Input DoS
22111| [56903] Apache ODE (Orchestration Director Engine) Process Deployment Web Service Traversal Arbitrary File Manipulation
22112| [56859] Apache Xerces-C++ Multiple Sub-project XML Nested DTD Structures Parsing Recursion Error DoS
22113| [56766] Apache Portable Runtime (APR-util) memory/unix/apr_pools.c Relocatable Memory Block Aligning Overflow
22114| [56765] Apache Portable Runtime (APR-util) misc/apr_rmm.c Multiple Function Overflows
22115| [56517] Apache HTTP Server File Descriptor Leak Arbitrary Local File Append
22116| [56443] PTK Unspecified Apache Sub-process Arbitrary Command Execution
22117| [56414] Apache Tiles Duplicate Expression Language (EL) Expression Evaluation XSS
22118| [55814] mod_NTLM for Apache HTTP Server ap_log_rerror() Function Remote Format String
22119| [55813] mod_NTLM for Apache HTTP Server log() Function Remote Overflow
22120| [55782] Apache HTTP Server mod_deflate Module Aborted Connection DoS
22121| [55553] Apache HTTP Server mod_proxy Module mod_proxy_http.c stream_reqbody_cl Function CPU Consumption DoS
22122| [55059] Apache APR-util strmatch/apr_strmatch.c apr_strmatch_precompile Function Crafted Input Remote DoS
22123| [55058] Apache APR-util apr_brigade_vprintf Function Crafted Input Off-by-one Remote DoS
22124| [55057] Apache APR-util xml/apr_xml.c apr_xml_* Interface Expat XML Parser Crafted XML Document Remote DoS
22125| [55056] Apache Tomcat Cross-application TLD File Manipulation
22126| [55055] Apache Tomcat Illegal URL Encoded Password Request Username Enumeration
22127| [55054] Apache Tomcat Java AJP Connector mod_jk Load Balancing Worker Malformed Header Remote DoS
22128| [55053] Apache Tomcat Crafted Request Security Restraint Bypass Arbitrary Content Access
22129| [54733] Apache HTTP Server AllowOverride Directive .htaccess Options Bypass
22130| [54713] razorCMS Security Manager apache User Account Unspecified File Permission Weakness Issue
22131| [54589] Apache Jserv Nonexistent JSP Request XSS
22132| [54122] Apache Struts s:a / s:url Tag href Element XSS
22133| [54093] Apache ActiveMQ Web Console JMS Message XSS
22134| [53932] Apache Geronimo Multiple Admin Function CSRF
22135| [53931] Apache Geronimo /console/portal/Server/Monitoring Multiple Parameter XSS
22136| [53930] Apache Geronimo /console/portal/ URI XSS
22137| [53929] Apache Geronimo on Windows Security/Keystores Portlet Traversal Arbitrary File Upload
22138| [53928] Apache Geronimo on Windows Embedded DB/DB Manager Portlet Traversal Arbitrary File Upload
22139| [53927] Apache Geronimo on Windows Services/Repository Portlet Traversal Arbitrary File Upload
22140| [53921] Apache HTTP Server mod_proxy_ajp Cross Thread/Session Information Disclosure
22141| [53766] Oracle BEA WebLogic Server Plug-ins for Apache Certificate Handling Remote Overflow
22142| [53574] PHP on Apache .htaccess mbstring.func_overload Setting Cross Hosted Site Behavior Modification
22143| [53381] Apache Tomcat JK Connector Content-Length Header Cross-user Information Disclosure
22144| [53380] Apache Struts Unspecified XSS
22145| [53289] Apache mod_perl Apache::Status /perl-status Unspecified XSS
22146| [53186] Apache HTTP Server htpasswd Predictable Salt Weakness
22147| [52899] Apache Tomcat Examples Web Application Calendar Application jsp/cal/cal2.jsp time Parameter XSS
22148| [52407] Apache Tomcat doRead Method POST Content Information Disclosure
22149| [51923] Apache HTTP Server mod-auth-mysql Module mod_auth_mysql.c Multibyte Character Encoding SQL Injection
22150| [51613] Apache HTTP Server Third-party Module Child Process File Descriptor Leak
22151| [51612] Apache HTTP Server Internal Redirect Handling Infinite Loop DoS
22152| [51468] Apache Jackrabbit Content Repository (JCR) swr.jsp q Parameter XSS
22153| [51467] Apache Jackrabbit Content Repository (JCR) search.jsp q Parameter XSS
22154| [51151] Apache Roller Search Function q Parameter XSS
22155| [50482] PHP with Apache php_value Order Unspecified Issue
22156| [50475] Novell NetWare ApacheAdmin Console Unauthenticated Access
22157| [49734] Apache Struts DefaultStaticContentLoader Class Traversal Arbitrary File Access
22158| [49733] Apache Struts FilterDispatcher Class Traversal Arbitrary File Access
22159| [49283] Oracle BEA WebLogic Server Plugins for Apache Remote Transfer-Encoding Overflow
22160| [49062] Apache Tomcat Cross-thread Concurrent Request Variable Overwrite Information Disclosure
22161| [48847] ModSecurity (mod_security) Transformation Caching Unspecified Apache DoS
22162| [48788] Apache Xerces-C++ XML Schema maxOccurs Value XML File Handling DoS
22163| [47474] Apache HTTP Server mod_proxy_ftp Directory Component Wildcard Character XSS
22164| [47464] Apache Tomcat allowLinking / UTF-8 Traversal Arbitrary File Access
22165| [47463] Apache Tomcat RequestDispatcher Traversal Arbitrary File Access
22166| [47462] Apache Tomcat HttpServletResponse.sendError Method Message Argument XSS
22167| [47096] Oracle Weblogic Apache Connector POST Request Overflow
22168| [46382] Frontend Filemanager (air_filemanager) Extension for TYPO3 on Apache Unspecified Arbitrary Code Execution
22169| [46285] TYPO3 on Apache Crafted Filename Upload Arbitrary Command Execution
22170| [46085] Apache HTTP Server mod_proxy ap_proxy_http_process_response() Function Interim Response Forwarding Remote DoS
22171| [45905] Apache Tomcat Host Manager host-manager/html/add name Parameter XSS
22172| [45879] Ragnarok Online Control Panel on Apache Crafted Traversal Authentication Bypass
22173| [45742] Apache HTTP Server on Novell Unspecified Request Directive Internal IP Disclosure
22174| [45740] Apache Derby DropSchemaNode Bind Phase Arbitrary Scheme Statement Dropping
22175| [45599] Apache Derby Lock Table Statement Privilege Requirement Bypass Arbitrary Table Lock
22176| [45585] Apache Derby ACCSEC Command RDBNAM Parameter Cleartext Credential Disclosure
22177| [45584] Apache Derby DatabaseMetaData.getURL Function Cleartext Credential Disclosure
22178| [45420] Apache HTTP Server 403 Error Page UTF-7 Encoded XSS
22179| [44728] PHP Toolkit on Gentoo Linux Interpretation Conflict Apache HTTP Server Local DoS
22180| [44618] Oracle JSP Apache/Jserv Path Translation Traversal Arbitrary JSP File Execution
22181| [44159] Apache HTTP Server Remote Virtual Host Name Disclosure
22182| [43997] Apache-SSL ExpandCert() Function Certificate Handling Arbitrary Environment Variables Manipulation
22183| [43994] suPHP for Apache (mod_suphp) Directory Symlink Local Privilege Escalation
22184| [43993] suPHP for Apache (mod_suphp) Owner Mode Race Condition Symlink Local Privilege Escalation
22185| [43663] Apache HTTP Server Mixed Platform AddType Directive Crafted Request PHP Source Disclosure
22186| [43658] AuthCAS Module (AuthCAS.pm) for Apache HTTP Server SESSION_COOKIE_NAME SQL Injection
22187| [43452] Apache Tomcat HTTP Request Smuggling
22188| [43309] Apache Geronimo LoginModule Login Method Bypass
22189| [43290] Apache JSPWiki Entry Page Attachment Unrestricted File Upload
22190| [43259] Apache HTTP Server on Windows mod_proxy_balancer URL Handling Remote Memory Corruption
22191| [43224] Apache Geronimo on SuSE Linux init Script Symlink Unspecified File/Directory Access
22192| [43189] Apache mod_jk2 Host Header Multiple Fields Remote Overflow
22193| [42937] Apache HTTP Server mod_proxy_balancer balancer-manager Unspecified CSRF
22194| [42341] MOD_PLSQL for Apache Unspecified URL SQL Injection
22195| [42340] MOD_PLSQL for Apache CGI Environment Handling Unspecified Overflow
22196| [42214] Apache HTTP Server mod_proxy_ftp UTF-7 Encoded XSS
22197| [42091] Apache Maven Site Plugin Installation Permission Weakness
22198| [42089] Apache Maven .m2/settings.xml Cleartext Password Disclosure
22199| [42088] Apache Maven Defined Repo Process Listing Password Disclosure
22200| [42087] Apache Maven Site Plugin SSH Deployment Permission Setting Weakness
22201| [42036] Apache HTTP Server MS-DOS Device Request Host OS Disclosure
22202| [41891] BEA WebLogic Apache Beehive NetUI Page Flow Unspecified XSS
22203| [41436] Apache Tomcat Native APR Connector Duplicate Request Issue
22204| [41435] Apache Tomcat %5C Cookie Handling Session ID Disclosure
22205| [41434] Apache Tomcat Exception Handling Subsequent Request Information Disclosure
22206| [41400] LimeSurvey save.php Apache Log File PHP Code Injection
22207| [41029] Apache Tomcat Calendar Examples Application cal2.jsp Multiple Parameter CSRF
22208| [41019] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload XSS
22209| [41018] Apache HTTP Server mod_negotiation Module Multi-Line Filename Upload CRLF
22210| [40853] Apache Tomcat SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) JSESSIONIDSSO Cookie Security Weakness
22211| [40264] Apache HTTP Server mod_proxy_balancer balancer_handler Function bb Variable Remote DoS
22212| [40263] Apache HTTP Server mod_proxy_balancer balancer-manager Multiple Parameter XSS
22213| [40262] Apache HTTP Server mod_status refresh XSS
22214| [39833] Apache Tomcat JULI Logging Component catalina.policy Security Bypass
22215| [39251] Coppermine Photo Gallery on Apache Multiple File Extension Upload Arbitrary Code Execution
22216| [39166] Apache Tomcat on Windows caseSensitive Attribute Mixed Case Request JSP Source Disclosure
22217| [39134] Apache mod_imagemap Module Imagemap Unspecified XSS
22218| [39133] Apache mod_imap Module Imagemap File Unspecified XSS
22219| [39035] Apache Tomcat examples/servlet/CookieExample Multiple Parameter XSS
22220| [39003] Apache HTTP Server HTTP Method Header Request Entity Too Large XSS
22221| [39000] Apache Tomcat SendMailServlet sendmail.jsp mailfrom Parameter XSS
22222| [38939] Apache HTTP Server Prefork MPM Module Array Modification Local DoS
22223| [38673] Apache Jakarta Slide WebDAV SYSTEM Request Traversal Arbitrary File Access
22224| [38662] Apache Geronimo SQLLoginModule Nonexistent User Authentication Bypass
22225| [38661] Apache Geronimo MEJB Unspecified Authentication Bypass
22226| [38641] Apache HTTP Server mod_mem_cache recall_headers Function Information Disclosure
22227| [38640] Apache HTTP Server suexec Document Root Unauthorized Operations
22228| [38639] Apache HTTP Server suexec Multiple Symlink Privilege Escalation
22229| [38636] Apache HTTP Server mod_autoindex.c P Variable UTF-7 Charset XSS
22230| [38513] BEA WebLogic Server Proxy Plug-in for Apache Protocol Error Handling Remote DoS
22231| [38187] Apache Geronimo / Tomcat WebDAV XML SYSTEM Tag Arbitrary File Access
22232| [37079] Apache HTTP Server mod_cache cache_util.c Malformed Cache-Control Header DoS
22233| [37071] Apache Tomcat Cookie Handling Session ID Disclosure
22234| [37070] Apache Tomcat Cookie Handling Quote Delimiter Session ID Disclosure
22235| [37052] Apache HTTP Server mod_status mod_status.c Unspecified XSS
22236| [37051] Apache HTTP Server mod_proxy modules/proxy/proxy_util.c Crafted Header Remote DoS
22237| [37050] Apache HTTP Server Prefork MPM Module Crafted Code Sequence Local DoS
22238| [36417] Apache Tomcat Host Manager Servlet html/add Action aliases Parameter XSS
22239| [36377] Apache MyFaces Tomahawk JSF Application autoscroll Multiple Script XSS
22240| [36080] Apache Tomcat JSP Examples Crafted URI XSS
22241| [36079] Apache Tomcat Manager Uploaded Filename XSS
22242| [34888] Apache Tomcat Example Calendar Application cal2.jsp time Parameter XSS
22243| [34887] Apache Tomcat implicit-objects.jsp Crafted Header XSS
22244| [34885] Apache Tomcat on IIS Servlet Engine MS-DOS Device Request DoS
22245| [34884] Apache Tomcat on Windows Nonexistent Resource Request Path Disclosure
22246| [34883] Apache Tomcat Crafted JSP File Request Path Disclosure
22247| [34882] Apache Tomcat Default SSL Ciphersuite Configuration Weakness
22248| [34881] Apache Tomcat Malformed Accept-Language Header XSS
22249| [34880] Apache Tomcat HTTP/1.1 Connector NULL Byte Request JSP Source Disclosure
22250| [34879] Apache Tomcat examples/jsp2/jspx/textRotate.jspx XSS
22251| [34878] Apache Tomcat examples/jsp2/el/implicit-objects.jsp XSS
22252| [34877] Apache Tomcat JK Web Server Connector (mod_jk) Double Encoded Traversal Arbitrary File Access
22253| [34876] Apache HTTP Server ScriptAlias CGI Source Disclosure
22254| [34875] Apache Tomcat appdev/sample/web/hello.jsp Multiple Parameter XSS
22255| [34874] Apache Tomcat AJP Connector mod_jk ajp_process_callback Remote Memory Disclosure
22256| [34873] Apache Stats Variable Extraction _REQUEST Ssuperglobal Array Overwrite
22257| [34872] Apache HTTP Server suexec User/Group Combination Weakness Local Privilege Escalation
22258| [34769] Apache Tomcat w/ Proxy Module Double Encoded Traversal Arbitrary File Access
22259| [34541] mod_perl for Apache HTTP Server RegistryCooker.pm PATH_INFO Crafted URI Remote DoS
22260| [34540] mod_perl for Apache HTTP Server PerlRun.pm PATH_INFO Crafted URI Remote DoS
22261| [34398] Apache Tomcat mod_jk Invalid Chunked Encoded Body Information Disclosure
22262| [34154] Apache Axis Nonexistent Java Web Service Path Disclosure
22263| [33855] Apache Tomcat JK Web Server Connector mod_jk.so Long URI Worker Map Remote Overflow
22264| [33816] Apache HTTP Server on Debian Linux TTY Local Privilege Escalation
22265| [33456] Apache HTTP Server Crafted TCP Connection Range Header DoS
22266| [33346] Avaya Multiple Products Apache Tomcat Port Weakness
22267| [32979] Apache Java Mail Enterprise Server (JAMES) Phoenix/MX4J Interface Arbitrary User Creation
22268| [32978] Apache Java Mail Enterprise Server (JAMES) POP3Server Log File Plaintext Password Disclosure
22269| [32724] Apache mod_python _filter_read Freed Memory Disclosure
22270| [32723] Apache Tomcat semicolon Crafted Filename Request Forced Directory Listing
22271| [32396] Apache Open For Business Project (OFBiz) Ecommerce Component Forum Implementation Message Body XSS
22272| [32395] Apache Open For Business Project (OFBiz) Ecommerce Component Form Field Manipulation Privilege Escalation
22273| [30354] Linux Subversion libapache2-svn Search Path Subversion Local Privilege Escalation
22274| [29603] PHP ini_restore() Apache httpd.conf Options Bypass
22275| [29536] Apache Tcl mod_tcl set_var Function Remote Format String
22276| [28919] Apache Roller Weblogger Blog Comment Multiple Field XSS
22277| [28130] PHP with Apache Mixed Case Method Limit Directive Bypass
22278| [27913] Apache HTTP Server on Windows mod_alias URL Validation Canonicalization CGI Source Disclosure
22279| [27588] Apache HTTP Server mod_rewrite LDAP Protocol URL Handling Overflow
22280| [27487] Apache HTTP Server Crafted Expect Header Cross Domain HTML Injection
22281| [26935] FCKeditor on Apache connector.php Crafted File Extension Arbitrary File Upload
22282| [26572] Apache Java Mail Enterprise Server (JAMES) MAIL Command Overflow DoS
22283| [25909] Drupal on Apache files Directory File Upload Arbitrary Code Execution
22284| [24825] Oracle ModPL/SQL for Apache Unspecified Remote HTTP Issue
22285| [24365] Apache Struts Multiple Function Error Message XSS
22286| [24364] Apache Struts getMultipartRequestHandler() Function Crafted Request DoS
22287| [24363] Apache Struts org.apache.struts.taglib.html.Constants.CANCEL Validation Bypass
22288| [24103] Pubcookie Apache mod_pubcookie Unspecified XSS
22289| [23906] Apache mod_python for Apache HTTP Server FileSession Privileged Local Command Execution
22290| [23905] Apache Log4net LocalSyslogAppender Format String Memory Corruption DoS
22291| [23198] Apache WSS4J Library SOAP Signature Verification Bypass
22292| [23124] Generic Apache Request Library (libapreq) apreq_parse_* Functions Remote DoS
22293| [22652] mod_php for Apache HTTP Server Crafted import_request_variables Function DoS
22294| [22475] PHP w/ Apache PDO::FETCH_CLASS __set() Function DoS
22295| [22473] PHP w/ Apache2 Crafted PDOStatement DoS
22296| [22459] Apache Geronimo Error Page XSS
22297| [22458] Apache Tomcat / Geronimo Sample Script cal2.jsp time Parameter XSS
22298| [22301] auth_ldap for Apache HTTP Server auth_ldap_log_reason() Function Remote Format String
22299| [22261] Apache HTTP Server mod_ssl ssl_hook_Access Error Handling DoS
22300| [22259] mod_auth_pgsql for Apache HTTP Server Log Function Format String
22301| [21736] Apache Java Mail Enterprise Server (JAMES) Spooler retrieve Function DoS
22302| [21705] Apache HTTP Server mod_imap Image Map Referer XSS
22303| [21021] Apache Struts Error Message XSS
22304| [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
22305| [20491] PHP mod_php apache2handler SAPI Crafted .htaccess DoS
22306| [20462] Apache HTTP Server worker.c MPM Memory Exhaustion DoS
22307| [20439] Apache Tomcat Directory Listing Saturation DoS
22308| [20373] Apache Tomcat on HP Secure OS for Linux Unspecified Servlet Access Issue
22309| [20285] Apache HTTP Server Log File Control Character Injection
22310| [20242] Apache HTTP Server mod_usertrack Predictable Session ID Generation
22311| [20209] Brainf*ck Module (mod_bf) for Apache HTTP Server Local Overflow
22312| [20033] Apache Tomcat MS-DOS Device Request Error Message Path Disclosure
22313| [19883] apachetop atop.debug Symlink Arbitrary File Overwrite
22314| [19863] mod_auth_shadow for Apache HTTP Server require group Authentication Bypass
22315| [19855] Apache HTTP Server ErrorDocument Directive .htaccess Bypass
22316| [19821] Apache Tomcat Malformed Post Request Information Disclosure
22317| [19769] Apache HTTP Server Double-reverse DNS Lookup Spoofing
22318| [19188] Apache HTTP Server mod_ssl SSLVerifyClient Per-location Context Restriction Bypass
22319| [19137] Apache HTTP Server on Red Hat Linux Double Slash GET Request Forced Directory Listing
22320| [19136] Apache on Mandrake Linux Arbitrary Directory Forced Listing
22321| [18977] Apache HTTP Server Crafted HTTP Range Header DoS
22322| [18389] Ragnarok Online Control Panel Apache Authentication Bypass
22323| [18286] Apache HTTP Server mod_ssl ssl_callback_SSLVerify_CRL( ) Function Overflow
22324| [18233] Apache HTTP Server htdigest user Variable Overfow
22325| [17738] Apache HTTP Server HTTP Request Smuggling
22326| [16586] Apache HTTP Server Win32 GET Overflow DoS
22327| [15889] Apache HTTP Server mod_cgid Threaded MPM CGI Output Misdirection
22328| [14896] mod_dav for Apache HTTP Server Remote Null Dereference Child Process Termination
22329| [14879] Apache HTTP Server ap_log_rerror Function Error Message Path Disclosure
22330| [14770] Apache Tomcat AJP12 Protocol Malformed Packet Remote DoS
22331| [14597] Apache Tomcat IntegerOverflow.jsp Test JSP Script Path Disclosure
22332| [14596] Apache Tomcat pageSession.jsp Test JSP Script Path Disclosure
22333| [14595] Apache Tomcat pageLanguage.jsp Test JSP Script Path Disclosure
22334| [14594] Apache Tomcat pageIsThreadSafe.jsp Test JSP Script Path Disclosure
22335| [14593] Apache Tomcat pageIsErrorPage.jsp Test JSP Script Path Disclosure
22336| [14592] Apache Tomcat pageInvalid.jsp Test JSP Script Path Disclosure
22337| [14591] Apache Tomcat pageExtends.jsp Test JSP Script Path Disclosure
22338| [14590] Apache Tomcat pageDouble.jsp Test JSP Script Path Disclosure
22339| [14589] Apache Tomcat pageAutoFlush.jsp Test JSP Script Path Disclosure
22340| [14588] Apache Tomcat extends2.jsp Test JSP Script Path Disclosure
22341| [14587] Apache Tomcat extends1.jsp Test JSP Script Path Disclosure
22342| [14586] Apache Tomcat comments.jsp Test JSP Script Path Disclosure
22343| [14585] Apache Tomcat buffer4.jsp Test JSP Script Path Disclosure
22344| [14584] Apache Tomcat buffer3.jsp Test JSP Script Path Disclosure
22345| [14583] Apache Tomcat buffer2.jsp Test JSP Script Path Disclosure
22346| [14582] Apache Tomcat buffer1.jsp Test JSP Script Path Disclosure
22347| [14581] Apache Tomcat pageImport2.jsp Test JSP Script Path Disclosure
22348| [14580] Apache Tomcat pageInfo.jsp Test JSP Script Path Disclosure
22349| [14410] mod_frontpage for Apache HTTP Server fpexec Remote Overflow
22350| [14044] Apache Batik Squiggle Browser with Rhino Scripting Engine Unspecified File System Access
22351| [13737] mod_access_referer for Apache HTTP Server Malformed Referer DoS
22352| [13711] Apache mod_python publisher.py Traversal Arbitrary Object Information Disclosure
22353| [13640] mod_auth_any for Apache HTTP Server on Red Hat Linux Metacharacter Command Execution
22354| [13304] Apache Tomcat realPath.jsp Path Disclosure
22355| [13303] Apache Tomcat source.jsp Arbitrary Directory Listing
22356| [13087] Apache HTTP Server mod_log_forensic check_forensic Symlink Arbitrary File Creation / Overwrite
22357| [12849] mod_auth_radius for Apache HTTP Server radcpy() Function Overflow DoS
22358| [12848] Apache HTTP Server htdigest realm Variable Overflow
22359| [12721] Apache Tomcat examples/jsp2/el/functions.jsp XSS
22360| [12720] mod_dosevasive for Apache HTTP Server Symlink Arbitrary File Create/Overwrite
22361| [12558] Apache HTTP Server IPv6 FTP Proxy Socket Failure DoS
22362| [12557] Apache HTTP Server prefork MPM accept Error DoS
22363| [12233] Apache Tomcat MS-DOS Device Name Request DoS
22364| [12232] Apache Tomcat with JDK Arbitrary Directory/Source Disclosure
22365| [12231] Apache Tomcat web.xml Arbitrary File Access
22366| [12193] Apache HTTP Server on Mac OS X File Handler Bypass
22367| [12192] Apache HTTP Server on Mac OS X Unauthorized .ht and .DS_Store File Access
22368| [12178] Apache Jakarta Lucene results.jsp XSS
22369| [12176] mod_digest_apple for Apache HTTP Server on Mac OS X Authentication Replay
22370| [11391] Apache HTTP Server Header Parsing Space Saturation DoS
22371| [11003] Apache HTTP Server mod_include get_tag() Function Local Overflow
22372| [10976] mod_mylo for Apache HTTP Server mylo_log Logging Function HTTP GET Overflow
22373| [10637] Apache HTTP Server mod_ssl SSLCipherSuite Access Restriction Bypass
22374| [10546] Macromedia JRun4 mod_jrun Apache Module Remote Overflow
22375| [10471] Apache Xerces-C++ XML Parser DoS
22376| [10218] Apache HTTP Server Satisfy Directive Access Control Bypass
22377| [10068] Apache HTTP Server htpasswd Local Overflow
22378| [10049] mod_cplusplus For Apache HTTP Server Unspecified Overflow
22379| [9994] Apache HTTP Server apr-util IPV6 Parsing DoS
22380| [9991] Apache HTTP Server ap_resolve_env Environment Variable Local Overflow
22381| [9948] mod_dav for Apache HTTP Server LOCK Request DoS
22382| [9742] Apache HTTP Server mod_ssl char_buffer_read Function Reverse Proxy DoS
22383| [9718] Apache HTTP Server Win32 Single Dot Append Arbitrary File Access
22384| [9717] Apache HTTP Server mod_cookies Cookie Overflow
22385| [9716] Apache::Gallery Gallery.pm Inline::C Predictable Filename Code Execution
22386| [9715] Apache HTTP Server rotatelogs Control Characters Over Pipe DoS
22387| [9714] Apache Authentication Module Threaded MPM DoS
22388| [9713] Apache HTTP Server on OS2 filestat.c Device Name Request DoS
22389| [9712] Apache HTTP Server Multiple Linefeed Request Memory Consumption DoS
22390| [9711] Apache HTTP Server Access Log Terminal Escape Sequence Injection
22391| [9710] Apache HTTP Server on Windows Illegal Character Default Script Mapping Bypass
22392| [9709] Apache HTTP Server on Windows MS-DOS Device Name HTTP Post Code Execution
22393| [9708] Apache HTTP Server on Windows MS-DOS Device Name DoS
22394| [9707] Apache HTTP Server Duplicate MIME Header Saturation DoS
22395| [9706] Apache Web Server Multiple MIME Header Saturation Remote DoS
22396| [9705] Apache Tomcat Invoker/Default Servlet Source Disclosure
22397| [9702] Apache HTTP Server CGI/WebDAV HTTP POST Request Source Disclosure
22398| [9701] Apache HTTP Server for Windows Multiple Slash Forced Directory Listing
22399| [9700] Apache HTTP Server mod_autoindex Multiple Slash Request Forced Directory Listing
22400| [9699] Apache HTTP Server mod_dir Multiple Slash Request Forced Directory Listing
22401| [9698] Apache HTTP Server mod_negotiation Multiple Slash Request Forced Directory Listing
22402| [9697] Apache HTTP Server htdigest Local Symlink Arbitrary File Overwrite
22403| [9696] Apache HTTP Server htpasswd Local Symlink Arbitrary File Overwrite
22404| [9695] Apache Tomcat SnoopServlet Servlet Information Disclosure
22405| [9694] PHP3 on Apache HTTP Server Encoded Traversal Arbitrary File Access
22406| [9693] mod_auth_pgsql_sys for Apache HTTP Server User Name SQL Injection
22407| [9692] Apache HTTP Server mod_vhost_alias Mass Virtual Hosting Arbitrary File Access
22408| [9691] Apache HTTP Server mod_rewrite Mass Virtual Hosting Arbitrary File Access
22409| [9690] Apache HTTP Server mod_vhost_alias CGI Program Source Disclosure
22410| [9689] Trustix httpsd for Apache-SSL Permission Weakness Privilege Escalation
22411| [9688] Apache HTTP Server mod_proxy Malformed FTP Command DoS
22412| [9687] Apache::AuthenSmb smbval SMB Authentication Library Multiple Overflows
22413| [9686] Apache::AuthenSmb smbvalid SMB Authentication Library Multiple Overflows
22414| [9523] Apache HTTP Server mod_ssl Aborted Connection DoS
22415| [9459] Oracle PL/SQL (mod_plsql) Apache Module Help Page Request Remote Overflow
22416| [9208] Apache Tomcat .jsp Encoded Newline XSS
22417| [9204] Apache Tomcat ROOT Application XSS
22418| [9203] Apache Tomcat examples Application XSS
22419| [9068] Apache HTTP Server mod_userdir User Account Information Disclosure
22420| [8773] Apache Tomcat Catalina org.apache.catalina.servlets.DefaultServlet Source Code Disclosure
22421| [8772] Apache Tomcat Catalina org.apache.catalina.connector.http DoS
22422| [7943] Apache HTTP Server mod_ssl sslkeys File Disclosure
22423| [7942] Apache HTTP Server mod_ssl Default Pass Phrase
22424| [7941] Apache HTTP Server mod_ssl Encrypted Private Key File Descriptor Leak
22425| [7935] Apache HTTP Server mod_ssl ssl_gcache Race Conditions
22426| [7934] Apache HTTP Server mod_ssl SSLSessionCache File Content Disclosure
22427| [7933] Apache HTTP Server mod_ssl SSLMutex File Content Disclosure
22428| [7932] Apache HTTP Server mod_ssl mkcert.sh File Creation Permission Weakness
22429| [7931] Apache HTTP Server mod_ssl X.509 Client Certificate Authentication Bypass
22430| [7930] Apache HTTP Server mod_ssl ssl_expr_eval_func_file() Overflow
22431| [7929] Apache HTTP Server mod_ssl ssl_engine_log.c mod_proxy Hook Function Remote Format String
22432| [7611] Apache HTTP Server mod_alias Local Overflow
22433| [7394] Apache Tomcat mod_jk Invalid Transfer-Encoding Chunked Field DoS
22434| [7203] Apache Tomcat source.jsp Traversal Arbitrary File Access
22435| [7039] Apache HTTP Server on Mac OS X HFS+ File System Access Bypass
22436| [6882] Apache mod_python Malformed Query String Variant DoS
22437| [6839] Apache HTTP Server mod_proxy Content-Length Overflow
22438| [6630] Apache Tomcat Java Server Pages (JSP) Engine WPrinterJob() DoS
22439| [6472] Apache HTTP Server mod_ssl ssl_util_uuencode_binary Remote Overflow
22440| [5821] Apache HTTP Server Multiple / GET Remote Overflow DoS
22441| [5580] Apache Tomcat Servlet Malformed URL JSP Source Disclosure
22442| [5552] Apache HTTP Server split-logfile Arbitrary .log File Overwrite
22443| [5526] Apache Tomcat Long .JSP URI Path Disclosure
22444| [5278] Apache Tomcat web.xml Restriction Bypass
22445| [5051] Apache Tomcat Null Character DoS
22446| [4973] Apache Tomcat servlet Mapping XSS
22447| [4650] mod_gzip for Apache HTTP Server Debug Mode Printf Stack Overflow
22448| [4649] mod_gzip for Apache HTTP Server Debug Mode Format String Overflow
22449| [4648] mod_gzip for Apache HTTP Server Debug Mode Race Condition
22450| [4568] mod_survey For Apache ENV Tags SQL Injection
22451| [4553] Apache HTTP Server ApacheBench Overflow DoS
22452| [4552] Apache HTTP Server Shared Memory Scoreboard DoS
22453| [4446] Apache HTTP Server mod_disk_cache Stores Credentials
22454| [4383] Apache HTTP Server Socket Race Condition DoS
22455| [4382] Apache HTTP Server Log Entry Terminal Escape Sequence Injection
22456| [4340] Apache Portable Runtime (APR) apr_psprintf DoS
22457| [4232] Apache Cocoon DatabaseAuthenticatorAction SQL Injection
22458| [4231] Apache Cocoon Error Page Server Path Disclosure
22459| [4182] Apache HTTP Server mod_ssl Plain HTTP Request DoS
22460| [4181] Apache HTTP Server mod_access IP Address Netmask Rule Bypass
22461| [4075] Apache HTTP Sever on Windows .var File Request Path Disclosure
22462| [4037] Apache HTTP Server on Cygwin Encoded GET Request Arbitrary File Access
22463| [3877] Apache-SSL SSLVerifyClient SSLFakeBasicAuth Client Certificate Forgery
22464| [3819] Apache HTTP Server mod_digest Cross Realm Credential Replay
22465| [3322] mod_php for Apache HTTP Server Process Hijack
22466| [3215] mod_php for Apache HTTP Server File Descriptor Leakage
22467| [2885] Apache mod_python Malformed Query String DoS
22468| [2749] Apache Cocoon view-source Sample File Traversal Arbitrary File Access
22469| [2733] Apache HTTP Server mod_rewrite Local Overflow
22470| [2672] Apache HTTP Server mod_ssl SSLCipherSuite Ciphersuite Downgrade Weakness
22471| [2613] Apache HTTP Server mod_cgi stderr Output Handling Local DoS
22472| [2149] Apache::Gallery Privilege Escalation
22473| [2107] Apache HTTP Server mod_ssl Host: Header XSS
22474| [1926] Apache HTTP Server mod_rewrite Crafted URI Rule Bypass
22475| [1833] Apache HTTP Server Multiple Slash GET Request DoS
22476| [1577] Apache HTTP Server mod_rewrite RewriteRule Expansion Arbitrary File Access
22477| [872] Apache Tomcat Multiple Default Accounts
22478| [862] Apache HTTP Server SSI Error Page XSS
22479| [859] Apache HTTP Server Win32 Crafted Traversal Arbitrary File Access
22480| [849] Apache Tomcat TroubleShooter Servlet Information Disclosure
22481| [845] Apache Tomcat MSDOS Device XSS
22482| [844] Apache Tomcat Java Servlet Error Page XSS
22483| [842] Apache HTTP Server mod_ssl ssl_compat_directive Function Overflow
22484| [838] Apache HTTP Server Chunked Encoding Remote Overflow
22485| [827] PHP4 for Apache on Windows php.exe Malformed Request Path Disclosure
22486| [775] Apache mod_python Module Importing Privilege Function Execution
22487| [769] Apache HTTP Server Win32 DOS Batch File Arbitrary Command Execution
22488| [756] Apache HTTP Server mod_ssl i2d_SSL_SESSION Function SSL Client Certificate Overflow
22489| [701] Apache HTTP Server Win32 ScriptAlias php.exe Arbitrary File Access
22490| [674] Apache Tomcat Nonexistent File Error Message Path Disclosure
22491| [637] Apache HTTP Server UserDir Directive Username Enumeration
22492| [623] mod_auth_pgsql for Apache HTTP Server User Name SQL Injection
22493| [582] Apache HTTP Server Multiviews Feature Arbitrary Directory Listing
22494| [562] Apache HTTP Server mod_info /server-info Information Disclosure
22495| [561] Apache Web Servers mod_status /server-status Information Disclosure
22496| [417] Apache HTTP Server on SuSE Linux /doc/packages Remote Information Disclosure
22497| [410] mod_perl for Apache HTTP Server /perl/ Directory Listing
22498| [404] Apache HTTP Server on SuSE Linux WebDAV PROPFIND Arbitrary Directory Listing
22499| [402] Apache HTTP Server on SuSE Linux cgi-bin-sdb Request Script Source Disclosure
22500| [379] Apache ASP module Apache::ASP source.asp Example File Arbitrary File Creation
22501| [377] Apache Tomcat Snoop Servlet Remote Information Disclosure
22502| [376] Apache Tomcat contextAdmin Arbitrary File Access
22503| [342] Apache HTTP Server for Windows Multiple Forward Slash Directory Listing
22504| [222] Apache HTTP Server test-cgi Arbitrary File Access
22505| [143] Apache HTTP Server printenv.pl Multiple Method CGI XSS
22506| [48] Apache HTTP Server on Debian /usr/doc Directory Information Disclosure
22507|_
22508Device type: storage-misc|general purpose
22509Running (JUST GUESSING): HP embedded (86%), Sun Solaris 9|10 (86%), Sun OpenSolaris (86%)
22510OS CPE: cpe:/h:hp:p2000_g3 cpe:/o:sun:sunos:5.9 cpe:/o:sun:sunos:5.10 cpe:/o:sun:opensolaris
22511Aggressive OS guesses: HP P2000 G3 NAS device (86%), Sun Solaris 9 or 10, or OpenSolaris 2009.06 snv_111b (86%), Sun Solaris 10 (85%)
22512No exact OS matches for host (test conditions non-ideal).
22513Uptime guess: 28.805 days (since Sat Dec 21 09:35:25 2019)
22514Network Distance: 25 hops
22515TCP Sequence Prediction: Difficulty=159 (Good luck!)
22516IP ID Sequence Generation: Incremental
22517
22518TRACEROUTE (using port 587/tcp)
22519HOP RTT ADDRESS
225201 37.68 ms 10.253.204.1
225212 71.64 ms 104.245.145.177
225223 71.72 ms te0-0-2-1.225.nr11.b010988-1.yyz02.atlas.cogentco.com (38.104.156.9)
225234 71.75 ms te0-0-0-1.agr14.yyz02.atlas.cogentco.com (154.24.54.41)
225245 71.73 ms te0-9-1-9.ccr31.yyz02.atlas.cogentco.com (154.54.43.161)
225256 71.78 ms be2993.ccr21.cle04.atlas.cogentco.com (154.54.31.225)
225267 71.81 ms be2717.ccr41.ord01.atlas.cogentco.com (154.54.6.221)
225278 71.83 ms be2831.ccr21.mci01.atlas.cogentco.com (154.54.42.165)
225289 111.24 ms be3035.ccr21.den01.atlas.cogentco.com (154.54.5.89)
2252910 111.36 ms be3037.ccr21.slc01.atlas.cogentco.com (154.54.41.145)
2253011 100.83 ms be3109.ccr21.sfo01.atlas.cogentco.com (154.54.44.137)
2253112 95.20 ms be3669.ccr41.sjc03.atlas.cogentco.com (154.54.43.10)
2253213 124.43 ms 38.88.224.178
2253314 124.44 ms 111.87.3.109
2253415 262.76 ms oteACS002.int-gw.kddi.ne.jp (106.187.13.17)
2253516 225.88 ms 27.85.224.158
2253617 262.78 ms 125.29.26.58
2253718 262.77 ms 133.208.191.139
2253819 261.85 ms 133.208.55.50
2253920 261.80 ms unused-133-130-015-097.interq.or.jp (133.130.15.97)
2254021 262.24 ms unused-133-130-013-018.interq.or.jp (133.130.13.18)
2254122 250.86 ms g-o-p-2w-a18-1-e-1-10.interq.or.jp (157.7.40.130)
2254223 292.48 ms unused-157-007-038-082.interq.or.jp (157.7.38.82)
2254324 ...
2254425 221.66 ms www18.gmoserver.jp (133.130.64.112)
22545
22546NSE: Script Post-scanning.
22547Initiating NSE at 04:54
22548Completed NSE at 04:54, 0.00s elapsed
22549Initiating NSE at 04:54
22550Completed NSE at 04:54, 0.00s elapsed
22551#######################################################################################################################################
22552Starting Nmap 7.80 ( https://nmap.org ) at 2020-01-19 04:54 EST
22553NSE: Loaded 47 scripts for scanning.
22554NSE: Script Pre-scanning.
22555Initiating NSE at 04:54
22556Completed NSE at 04:54, 0.00s elapsed
22557Initiating NSE at 04:54
22558Completed NSE at 04:54, 0.00s elapsed
22559Initiating Parallel DNS resolution of 1 host. at 04:54
22560Completed Parallel DNS resolution of 1 host. at 04:54, 0.02s elapsed
22561Initiating UDP Scan at 04:54
22562Scanning www18.gmoserver.jp (133.130.64.112) [15 ports]
22563Completed UDP Scan at 04:54, 2.02s elapsed (15 total ports)
22564Initiating Service scan at 04:54
22565Scanning 13 services on www18.gmoserver.jp (133.130.64.112)
22566Service scan Timing: About 7.69% done; ETC: 05:16 (0:19:36 remaining)
22567Completed Service scan at 04:56, 102.58s elapsed (13 services on 1 host)
22568Initiating OS detection (try #1) against www18.gmoserver.jp (133.130.64.112)
22569Retrying OS detection (try #2) against www18.gmoserver.jp (133.130.64.112)
22570Initiating Traceroute at 04:56
22571Completed Traceroute at 04:56, 7.05s elapsed
22572Initiating Parallel DNS resolution of 1 host. at 04:56
22573Completed Parallel DNS resolution of 1 host. at 04:56, 0.00s elapsed
22574NSE: Script scanning 133.130.64.112.
22575Initiating NSE at 04:56
22576Completed NSE at 04:56, 7.29s elapsed
22577Initiating NSE at 04:56
22578Completed NSE at 04:56, 1.35s elapsed
22579Nmap scan report for www18.gmoserver.jp (133.130.64.112)
22580Host is up (0.18s latency).
22581
22582PORT STATE SERVICE VERSION
2258353/udp open|filtered domain
2258467/udp open|filtered dhcps
2258568/udp open|filtered dhcpc
2258669/udp open|filtered tftp
2258788/udp open|filtered kerberos-sec
22588123/udp open|filtered ntp
22589137/udp filtered netbios-ns
22590138/udp filtered netbios-dgm
22591139/udp open|filtered netbios-ssn
22592161/udp open|filtered snmp
22593162/udp open|filtered snmptrap
22594389/udp open|filtered ldap
22595500/udp open|filtered isakmp
22596|_ike-version: ERROR: Script execution failed (use -d to debug)
22597520/udp open|filtered route
225982049/udp open|filtered nfs
22599Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
22600Aggressive OS guesses: Foundry FastIron 400 switch (98%), Brocade ICX 6610 switch (96%), Foundry Networks FES2402 switch, ServerIron 4G proxy server, or ServerIron GT EGx2 load balancer (96%), Foundry Networks ServerIron switch (96%), HP ProCurve 9304m or 9308m switch (96%), Brocade TurboIron 24X or ICX6550 switch (96%), Brocade Layer 2 switch (96%), Foundry BigIron RX switch (IronWare 2.2.1) (96%), Foundry BigIron RX switch, NetIron MLX switch, or NetIron 4000 XMR switch (IronWare 2.2.1 - 3.6.0) (96%), Foundry FastIron switch (4802, FESX, GS 648P, X448, or II Plus) (IronWare) (96%)
22601No exact OS matches for host (test conditions non-ideal).
22602
22603TRACEROUTE (using port 138/udp)
22604HOP RTT ADDRESS
226051 29.91 ms 10.253.204.1
226062 ... 3
226074 29.36 ms 10.253.204.1
226085 91.87 ms 10.253.204.1
226096 91.87 ms 10.253.204.1
226107 91.86 ms 10.253.204.1
226118 91.85 ms 10.253.204.1
226129 61.87 ms 10.253.204.1
2261310 30.07 ms 10.253.204.1
2261411 ... 18
2261519 29.56 ms 10.253.204.1
2261620 29.05 ms 10.253.204.1
2261721 ... 28
2261829 30.09 ms 10.253.204.1
2261930 29.44 ms 10.253.204.1
22620
22621NSE: Script Post-scanning.
22622Initiating NSE at 04:56
22623Completed NSE at 04:56, 0.00s elapsed
22624Initiating NSE at 04:56
22625Completed NSE at 04:56, 0.00s elapsed
22626Read data files from: /usr/bin/../share/nmap
22627OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
22628Nmap done: 1 IP address (1 host up) scanned in 126.92 seconds
22629 Raw packets sent: 125 (7.728KB) | Rcvd: 44 (3.388KB)
22630#######################################################################################################################################
22631 Anonymous JTSEC #OpWhales Full Recon #20