- EPSS 20.8%
- Veröffentlicht 25.10.2005 17:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused f...
- EPSS 15.08%
- Veröffentlicht 06.09.2005 23:03:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass inten...
- EPSS 61.79%
- Veröffentlicht 30.08.2005 11:45:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
- EPSS 4.27%
- Veröffentlicht 05.08.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one...
CVE-2005-2088
- EPSS 54.29%
- Veröffentlicht 05.07.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfe...
CVE-2005-1344
- EPSS 12.89%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to...
CVE-2004-0940
- EPSS 3.68%
- Veröffentlicht 09.02.2005 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
- EPSS 76.94%
- Veröffentlicht 09.02.2005 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
CVE-2004-0811
- EPSS 4.07%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
CVE-2004-1387
- EPSS 0.26%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.