CVE-2018-11784
- EPSS 82.62%
- Published 04.10.2018 13:29:00
- Last modified 21.11.2024 03:44:01
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause...
CVE-2018-11763
- EPSS 17.4%
- Published 25.09.2018 21:29:00
- Last modified 21.11.2024 03:43:58
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitiga...
CVE-2018-8032
- EPSS 2.34%
- Published 02.08.2018 13:29:00
- Last modified 08.05.2025 18:13:51
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
CVE-2018-1304
- EPSS 1.79%
- Published 28.02.2018 20:29:00
- Last modified 21.11.2024 03:59:35
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definiti...
CVE-2017-9788
- EPSS 47.95%
- Published 13.07.2017 16:29:00
- Last modified 20.04.2025 01:37:25
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial ke...
CVE-2017-7668
- EPSS 65.46%
- Published 20.06.2017 01:29:00
- Last modified 20.04.2025 01:37:25
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacke...
CVE-2017-3167
- EPSS 9.44%
- Published 20.06.2017 01:29:00
- Last modified 20.04.2025 01:37:25
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
CVE-2016-5580
- EPSS 0.5%
- Published 25.10.2016 14:30:50
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.7 and 5.2 allows remote authenticated users to affect confidentiality and availability via vectors through Web Services.
- EPSS 5.24%
- Published 21.07.2016 10:14:47
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 4.63, 4.71, and 5.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to OpenSSL.
- EPSS 0.71%
- Published 21.01.2016 03:00:49
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.2 allows remote attackers to affect availability via vectors related to SGD Core.