CVE-2007-6203
- EPSS 72.21%
- Veröffentlicht 03.12.2007 22:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using w...
CVE-2007-4465
- EPSS 4.44%
- Veröffentlicht 14.09.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using t...
- EPSS 22.13%
- Veröffentlicht 23.08.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffe...
CVE-2006-5752
- EPSS 14.88%
- Veröffentlicht 27.06.2007 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...
- EPSS 32.3%
- Veröffentlicht 27.06.2007 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with...
CVE-2007-3303
- EPSS 0.08%
- Veröffentlicht 20.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creati...
CVE-2007-3304
- EPSS 0.09%
- Veröffentlicht 20.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the m...
- EPSS 9.01%
- Veröffentlicht 04.06.2007 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentiall...
CVE-2007-1742
- EPSS 0.17%
- Veröffentlicht 13.04.2007 17:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated u...
CVE-2007-1743
- EPSS 0.17%
- Veröffentlicht 13.04.2007 17:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the...