CVE-2018-1301
- EPSS 6.3%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:59:34
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to tri...
CVE-2018-1283
- EPSS 3.76%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:59:32
In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION...
CVE-2017-15715
- EPSS 94.17%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:15:04
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some...
CVE-2017-15710
- EPSS 11.7%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:15:03
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If th...
CVE-2018-2638
- EPSS 0.75%
- Published 18.01.2018 02:29:20
- Last modified 21.11.2024 04:04:07
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multipl...
CVE-2018-2627
- EPSS 0.51%
- Published 18.01.2018 02:29:20
- Last modified 06.05.2025 15:15:55
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure ...
CVE-2018-2581
- EPSS 0.49%
- Published 18.01.2018 02:29:18
- Last modified 21.11.2024 04:03:58
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multip...