- EPSS 83.77%
- Veröffentlicht 27.12.2011 18:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
CVE-2011-3639
- EPSS 14.88%
- Veröffentlicht 30.11.2011 04:05:58
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration ...
CVE-2011-4317
- EPSS 84.29%
- Veröffentlicht 30.11.2011 04:05:58
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern ma...
CVE-2011-3607
- EPSS 0.4%
- Veröffentlicht 08.11.2011 11:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted S...
CVE-2011-4415
- EPSS 0.65%
- Veröffentlicht 08.11.2011 11:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to caus...
- EPSS 79.13%
- Veröffentlicht 05.10.2011 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, wh...
CVE-2011-3348
- EPSS 37.04%
- Veröffentlicht 20.09.2011 05:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP r...
CVE-2011-3192
- EPSS 92.84%
- Veröffentlicht 29.08.2011 15:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as e...
CVE-2011-1928
- EPSS 14.39%
- Veröffentlicht 24.05.2011 23:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecifie...
CVE-2011-0419
- EPSS 56.21%
- Veröffentlicht 16.05.2011 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...