CVE-2011-3348
- EPSS 37.04%
- Veröffentlicht 20.09.2011 05:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP r...
CVE-2011-3192
- EPSS 92.7%
- Veröffentlicht 29.08.2011 15:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as e...
CVE-2011-1928
- EPSS 14.39%
- Veröffentlicht 24.05.2011 23:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecifie...
CVE-2011-0419
- EPSS 57.92%
- Veröffentlicht 16.05.2011 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...
- EPSS 25.11%
- Veröffentlicht 04.10.2010 21:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote ...
- EPSS 2.08%
- Veröffentlicht 05.08.2010 18:17:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive resp...
- EPSS 19.15%
- Veröffentlicht 28.07.2010 20:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
- EPSS 8.54%
- Veröffentlicht 18.06.2010 16:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows rem...
- EPSS 86.82%
- Veröffentlicht 05.03.2010 19:30:00
- Zuletzt bearbeitet 24.07.2025 17:43:53
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an...
CVE-2010-0434
- EPSS 2.55%
- Veröffentlicht 05.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, wh...