Apache
apache
3,377 CVEs • 392 products
Products (392)
Click to collapseToggle
Products (392)
Click to collapse
CVEs (3,377)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Oracle33Agile Plm Agile Product Lifecycle ManagementAnt+30 moreAug 25, 2026 Jul 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds usi...Show more |
3Apache NetappOracle34Active Iq Unified Manager Banking ApisBanking Digital Experience+31 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle27Active Iq Unified Manager Banking ApisBanking Digital Experience+24 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle24Active Iq Unified Manager Banking Digital ExperienceBanking Enterprise Default Management+21 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of servi...Show more |
3Apache NetappOracle26Active Iq Unified Manager Banking Digital ExperienceBanking Enterprise Default Management+23 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that us...Show more |
4Apache DebianMcafee+1 more23Agile Plm Agile Product Lifecycle ManagementCommunications Cloud Native Core Policy+20 moreAug 25, 2026 Jul 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used...Show more |
3Apache DebianOracle7Communications Cloud Native Core Policy Communications Diameter Signaling RouterCommunications Pricing Design Center+4 moreJun 17, 2026 Jul 12, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache...Show more |
3Apache McafeeOracle3Big Data Spatial And Graph Epolicy OrchestratorTomcatJun 17, 2026 Jul 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated...Show more |
2Apache Oracle9Banking Payments Banking Trade FinanceBanking Treasury Management+6 moreJun 17, 2026 Jul 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and late...Show more |
A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects Apache Jena Fuseki from version 2.0.0 to version 4.0.0 (inclusive). |
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the loca...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected beha...Show more |
5Apache DebianFedoraproject+2 more6Communications Messaging Server Debian LinuxFedora+3 moreJun 17, 2026 Jun 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. |
2Apache Oracle5Business Intelligence Communications Element ManagerCommunications Messaging Server+2 moreJun 17, 2026 Jun 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This...Show more |
2Apache Qos3Chainsaw Log4jReload4jJun 17, 2026 Jun 16, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. |