Apache
apache
3,377 CVEs • 392 products
Products (392)
Click to collapseToggle
Products (392)
Click to collapse
CVEs (3,377)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restri...Show more |
3Apache FedoraprojectOracle7Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Supply Chain Finance+4 moreJun 17, 2026 Jun 12, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. |
3Apache FedoraprojectOracle12Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Supply Chain Finance+9 moreJun 17, 2026 Jun 12, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' |
5Apache DebianFedoraproject+2 more8Cloud Backup Debian LinuxEnterprise Manager Ops Center+5 moreJun 17, 2026 Jun 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could cre...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of...Show more |
3Apache McafeeNetapp3Cloud Backup Epolicy OrchestratorHttp ServerJun 17, 2026 Jun 10, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows |
3Apache FedoraprojectOracle5Enterprise Manager Ops Center FedoraHttp Server+2 moreJun 17, 2026 Jun 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent reques...Show more |
In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was u...Show more |
2Apache Dpgaspar2Airflow Flask AppbuilderJun 17, 2026 Jun 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing t...Show more |
Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right...Show more |
Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When...Show more |
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are handled by the GenericFilter which will find the service and method speci...Show more |
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Prov...Show more |
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability. |
Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a man in the middle attack could be successful. |
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an att...Show more |
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized....Show more |