CVE-2023-32342
- EPSS 0.1%
- Veröffentlicht 30.05.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:03:09
IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vu...
CVE-2023-26281
- EPSS 0.07%
- Veröffentlicht 01.03.2023 08:15:14
- Zuletzt bearbeitet 21.11.2024 07:51:03
IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. IBM X-Force ID: 248296.
- EPSS 4.6%
- Veröffentlicht 15.09.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remot...
- EPSS 6.95%
- Veröffentlicht 20.12.2012 12:02:19
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors.
CVE-2011-1360
- EPSS 0.17%
- Veröffentlicht 28.10.2011 02:49:52
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified doc...
- EPSS 86.82%
- Veröffentlicht 05.03.2010 19:30:00
- Zuletzt bearbeitet 24.07.2025 17:43:53
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an...
- EPSS 0.8%
- Veröffentlicht 23.11.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
- EPSS 21.04%
- Veröffentlicht 06.08.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes...
CVE-2004-0493
- EPSS 89.5%
- Veröffentlicht 06.08.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header...
CVE-2004-1082
- EPSS 5.47%
- Veröffentlicht 03.02.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.