Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2003-02-07 CVE-2003-0045 Denial-Of-Service vulnerability in Tomcat
Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.
network
low complexity
apache
5.0
2003-02-07 CVE-2003-0044 Cross-Site Scripting vulnerability in Apache Tomcat Example Web Application
Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.
network
apache
6.8
2003-02-07 CVE-2003-0043 Unspecified vulnerability in Apache Tomcat
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
network
low complexity
apache
5.0
2003-02-07 CVE-2003-0042 Unspecified vulnerability in Apache Tomcat
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-2272 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apache Http Server and Tomcat
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
network
low complexity
apache CWE-119
7.8
2002-12-31 CVE-2002-2103 Unspecified vulnerability in Apache Http Server
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-2029 Remote File Disclosure vulnerability in Apache Win32 PHP.EXE
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
network
low complexity
apache
7.5
2002-12-31 CVE-2002-2012 Unspecified vulnerability in Apache Http Server 1.3.19
Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-2007 Information Disclosure vulnerability in Apache Tomcat 3.2.3/3.2.4
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-1850 Improper Locking vulnerability in Apache Http Server 2.0.39/2.0.40
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
network
low complexity
apache CWE-667
7.5