CVE-2007-3303
- EPSS 0.06%
- Veröffentlicht 20.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creati...
CVE-2007-3304
- EPSS 0.21%
- Veröffentlicht 20.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the m...
- EPSS 11.46%
- Veröffentlicht 04.06.2007 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentiall...
CVE-2007-1742
- EPSS 0.17%
- Veröffentlicht 13.04.2007 17:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated u...
CVE-2007-1743
- EPSS 0.16%
- Veröffentlicht 13.04.2007 17:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the...
CVE-2007-1741
- EPSS 0.09%
- Veröffentlicht 13.04.2007 16:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE...
- EPSS 86.12%
- Veröffentlicht 16.03.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence...
CVE-2007-0086
- EPSS 3.18%
- Veröffentlicht 05.01.2007 18:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOT...
CVE-2006-4154
- EPSS 32.79%
- Veröffentlicht 16.10.2006 19:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core...
CVE-2006-4110
- EPSS 17.32%
- Veröffentlicht 14.08.2006 20:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file...