CVEs (57)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache CanonicalDebian+2 more11Agile Engineering Data Management Debian LinuxHyperion Infrastructure Technology+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more |
3Netapp OracleRedhat188Access Manager Active Iq Unified ManagerAgile Engineering Data Management+185 moreJun 17, 2026 Nov 8, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can r...Show more |
2Apache Oracle27Application Testing Suite Banking Enterprise OriginationsBanking Enterprise Product Manufacturing+24 moreJun 17, 2026 Oct 23, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from intern...Show more |
2Apache Oracle8Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+5 moreJun 17, 2026 Sep 26, 2019 N/A· v4 7.2 HIGH· v3 6.0 MEDIUM· v2 In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL...Show more |
2Apache Oracle6Communications Element Manager Enterprise Manager Ops CenterHttp Server+3 moreJun 17, 2026 Sep 26, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown. |
12Apache AppleCanonical+9 more23Clustered Data Ontap Communications Element ManagerDebian Linux+20 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they...Show more |
6Apache CanonicalFedoraproject+3 more11Communications Session Report Manager Communications Session Route ManagerEnterprise Manager Ops Center+8 moreJun 17, 2026 Jun 11, 2019 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the fir...Show more |
2Apache Oracle37Agile Engineering Data Management Agile Product Lifecycle ManagementApplication Testing Suite+34 moreJun 17, 2026 May 1, 2019 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legac...Show more |
8Apache CanonicalDebian+5 more27Communications Session Report Manager Communications Session Route ManagerDebian Linux+24 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) cou...Show more |
2Apache Oracle5Enterprise Manager Ops Center Hospitality Guest AccessHttp Server+2 moreJun 17, 2026 Jan 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only trigge...Show more |
7Apache CanonicalDebian+4 more12Debian Linux Enterprise Manager Ops CenterFedora+9 moreNov 21, 2024 Jan 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. Thi...Show more |
6Apache CanonicalDebian+3 more15Communications Application Session Controller Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Oct 4, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially craf...Show more |
5Apache CanonicalNetapp+2 more9Enterprise Linux Enterprise Manager Ops CenterHospitality Guest Access+6 moreNov 21, 2024 Sep 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2...Show more |
3Apache DebianOracle38Agile Engineering Data Management Agile Product Lifecycle ManagementApplication Testing Suite+35 moreJun 17, 2026 Aug 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. |
4Apache CanonicalDebian+1 more21Batik Business IntelligenceCommunications Diameter Signaling Router+18 moreJun 17, 2026 May 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was t...Show more |
6Apache CanonicalDebian+3 more58Active Iq Unified Manager Agile PlmCommunications Instant Messaging Server+55 moreApr 21, 2026 Oct 4, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal...Show more |
4Apache NetappOracle+1 more79Api Gateway Application Testing SuiteAutovue Vuelink Integration+76 moreMay 13, 2026 Apr 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, c...Show more |