Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2012-01-08 CVE-2012-0392 Unspecified vulnerability in Apache Struts
The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
network
apache
6.8
2012-01-08 CVE-2012-0391 Improper Input Validation vulnerability in Apache Struts
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
network
apache CWE-20
critical
9.3
2012-01-05 CVE-2011-4905 Resource Management Errors vulnerability in Apache Activemq
Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
network
low complexity
apache CWE-399
5.0
2011-12-27 CVE-2007-6750 Resource Management Errors vulnerability in Apache Http Server
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
network
low complexity
apache CWE-399
5.0
2011-11-11 CVE-2011-3376 Permissions, Privileges, and Access Controls vulnerability in Apache Tomcat
org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
local
apache CWE-264
4.4
2011-11-08 CVE-2011-4415 Improper Input Validation vulnerability in Apache Http Server
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
local
high complexity
apache CWE-20
1.2
2011-10-05 CVE-2000-1247 Configuration vulnerability in Apache Jserv 1.1.2
The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
local
low complexity
apache CWE-16
2.1
2011-08-29 CVE-2011-2712 Cross-Site Scripting vulnerability in Apache Wicket
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
network
high complexity
apache CWE-79
2.6
2011-07-07 CVE-2011-1498 Information Exposure vulnerability in Apache Httpclient 4.0/4.0.1/4.1
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
network
apache CWE-200
4.3
2011-06-06 CVE-2011-1921 Permissions, Privileges, and Access Controls vulnerability in Apache Subversion
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.
network
apache CWE-264
4.3