5
CVE-2008-5676
- EPSS 1.47%
- Veröffentlicht 19.12.2008 01:52:58
- Zuletzt bearbeitet 16.06.2026 23:00:46
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Breach ≫ Modsecurity Version <= 2.5.0
Breach ≫ Modsecurity Version <= 2.5.5
Breach ≫ Modsecurity Version2.5.1
Breach ≫ Modsecurity Version2.5.2
Breach ≫ Modsecurity Version2.5.3
Breach ≫ Modsecurity Version2.5.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.47% | 0.704 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
http://blog.modsecurity.org/2008/08/transformation.html
http://freshmeat.net/projects/modsecurity/?branch_id=34901&release_id=282329
http://secunia.com/advisories/32146
http://www.vupen.com/english/advisories/2008/2795
https://exchange.xforce.ibmcloud.com/vulnerabilities/45770