Vulnerabilities > Apache > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-10 CVE-2020-35452 Out-of-bounds Write vulnerability in multiple products
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest.
network
low complexity
apache debian fedoraproject oracle CWE-787
7.3
2021-06-10 CVE-2021-26690 NULL Pointer Dereference vulnerability in multiple products
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service
network
low complexity
apache debian fedoraproject oracle CWE-476
7.5
2021-05-27 CVE-2020-17514 Unspecified vulnerability in Apache Fineract
Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method.
network
high complexity
apache
7.4
2021-05-25 CVE-2021-23937 Information Exposure vulnerability in Apache Wicket
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized.
network
low complexity
apache CWE-200
7.5
2021-05-14 CVE-2021-27737 Unspecified vulnerability in Apache Traffic Server 9.0.0
Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.
network
low complexity
apache
7.5
2021-05-04 CVE-2021-31164 Injection vulnerability in Apache Unomi
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
network
low complexity
apache CWE-74
7.5
2021-04-27 CVE-2021-30638 Incorrect Authorization vulnerability in Apache Tapestry
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL.
network
low complexity
apache CWE-863
7.5
2021-04-27 CVE-2020-17517 Missing Authentication for Critical Function vulnerability in Apache Ozone 0.4.2/0.5.0/1.0.0
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default.
network
low complexity
apache CWE-306
7.5
2021-04-21 CVE-2020-23922 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in giflib through 5.1.4.
local
low complexity
giflib-project apache CWE-125
7.1
2021-04-15 CVE-2021-30245 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Apache Openoffice
The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks.
network
low complexity
apache CWE-610
8.8