CVE-2017-7671
- EPSS 4.27%
- Veröffentlicht 27.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:25
There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.
CVE-2017-5660
- EPSS 2.58%
- Veröffentlicht 27.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:28:07
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.
CVE-2015-3249
- EPSS 4.23%
- Veröffentlicht 30.10.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers ...
CVE-2014-3624
- EPSS 0.39%
- Veröffentlicht 30.10.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
- EPSS 1.9%
- Veröffentlicht 13.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.
- EPSS 1.89%
- Veröffentlicht 13.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.
CVE-2017-5659
- EPSS 1.97%
- Veröffentlicht 17.04.2017 18:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.
CVE-2016-5396
- EPSS 1.81%
- Veröffentlicht 17.04.2017 18:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
- EPSS 2.71%
- Veröffentlicht 13.01.2015 11:59:29
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.
- EPSS 1.27%
- Veröffentlicht 22.08.2014 14:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.