Haproxy

Haproxy

42 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.59%
  • Veröffentlicht 12.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:53

An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaus...

  • EPSS 4.35%
  • Veröffentlicht 12.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:52

An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-...

  • EPSS 3.01%
  • Veröffentlicht 21.09.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:29

A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.

  • EPSS 3.02%
  • Veröffentlicht 25.05.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:25

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check...

  • EPSS 8.43%
  • Veröffentlicht 09.05.2018 07:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:58

An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked against the bufsize. The max_frame_size only applies to outgoing traffic and not to incoming, so if ...

  • EPSS 2.01%
  • Veröffentlicht 22.08.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.

  • EPSS 42.82%
  • Veröffentlicht 30.06.2016 17:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impact via unknown vectors.

  • EPSS 4.27%
  • Veröffentlicht 06.07.2015 15:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of pre...

Exploit
  • EPSS 3.81%
  • Veröffentlicht 30.09.2014 14:55:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash) via a large stream of data, which triggers a buffer overflow and an out...

  • EPSS 3.52%
  • Veröffentlicht 19.08.2013 13:07:58
  • Zuletzt bearbeitet 29.04.2026 01:13:23

HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP hea...