- EPSS 47.14%
- Veröffentlicht 18.03.2014 05:18:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) v...
- EPSS 47.4%
- Veröffentlicht 18.03.2014 05:18:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handl...
CVE-2013-2249
- EPSS 33.66%
- Veröffentlicht 23.07.2013 17:20:43
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote at...
CVE-2013-1896
- EPSS 38.56%
- Veröffentlicht 10.07.2013 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for han...
CVE-2013-1862
- EPSS 41.76%
- Veröffentlicht 10.06.2013 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containi...
CVE-2012-3499
- EPSS 8.41%
- Veröffentlicht 26.02.2013 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagema...
CVE-2012-4558
- EPSS 28.24%
- Veröffentlicht 26.02.2013 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remo...
- EPSS 29.07%
- Veröffentlicht 30.11.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an...
CVE-2012-2687
- EPSS 4.5%
- Veröffentlicht 22.08.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to in...
CVE-2012-3502
- EPSS 3.79%
- Veröffentlicht 22.08.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end c...