Apache

Traffic Server

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.23%
  • Veröffentlicht 30.10.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers ...

  • EPSS 0.39%
  • Veröffentlicht 30.10.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.

  • EPSS 1.9%
  • Veröffentlicht 13.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.

  • EPSS 1.89%
  • Veröffentlicht 13.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.

  • EPSS 1.46%
  • Veröffentlicht 17.04.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.

  • EPSS 1.81%
  • Veröffentlicht 17.04.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.

  • EPSS 2.71%
  • Veröffentlicht 13.01.2015 11:59:29
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.

  • EPSS 1.27%
  • Veröffentlicht 22.08.2014 14:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

  • EPSS 1.91%
  • Veröffentlicht 26.03.2012 14:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.

  • EPSS 1.21%
  • Veröffentlicht 13.09.2010 21:00:28
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attacker...