CVE-2014-0117
- EPSS 60.03%
- Veröffentlicht 20.07.2014 11:12:48
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
CVE-2014-0118
- EPSS 48.88%
- Veröffentlicht 20.07.2014 11:12:48
- Zuletzt bearbeitet 12.04.2025 10:46:40
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted req...
CVE-2014-0226
- EPSS 73.42%
- Veröffentlicht 20.07.2014 11:12:48
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a cr...
- EPSS 36.22%
- Veröffentlicht 20.07.2014 11:12:48
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
- EPSS 75.57%
- Veröffentlicht 15.04.2014 10:55:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...
- EPSS 47.14%
- Veröffentlicht 18.03.2014 05:18:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) v...
- EPSS 47.4%
- Veröffentlicht 18.03.2014 05:18:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handl...
CVE-2013-2249
- EPSS 33.66%
- Veröffentlicht 23.07.2013 17:20:43
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote at...
CVE-2013-1896
- EPSS 38.56%
- Veröffentlicht 10.07.2013 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for han...
CVE-2013-1862
- EPSS 41.76%
- Veröffentlicht 10.06.2013 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containi...