CVE-2009-1891
- EPSS 18.81%
- Veröffentlicht 10.07.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
CVE-2009-1890
- EPSS 21.52%
- Veröffentlicht 05.07.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which al...
CVE-2009-0023
- EPSS 15.65%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2)...
CVE-2009-1955
- EPSS 3.66%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via ...
CVE-2009-1956
- EPSS 4.27%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
CVE-2009-1195
- EPSS 0.19%
- Veröffentlicht 28.05.2009 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Opti...
- EPSS 12%
- Veröffentlicht 23.04.2009 17:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
CVE-2008-2939
- EPSS 76.09%
- Veröffentlicht 06.08.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary we...
- EPSS 2.09%
- Veröffentlicht 13.06.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service...
CVE-2008-2168
- EPSS 50.39%
- Veröffentlicht 13.05.2008 21:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.