CVE-2014-8109
- EPSS 17.55%
- Published 29.12.2014 23:59:00
- Last modified 12.04.2025 10:46:40
mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows rem...
- EPSS 3.87%
- Published 10.10.2014 10:55:07
- Last modified 12.04.2025 10:46:40
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP...
CVE-2014-0226
- EPSS 73.42%
- Published 20.07.2014 11:12:48
- Last modified 12.04.2025 10:46:40
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a cr...
- EPSS 75.57%
- Published 15.04.2014 10:55:11
- Last modified 12.04.2025 10:46:40
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...
CVE-2014-1490
- EPSS 1.05%
- Published 06.02.2014 05:44:25
- Last modified 11.04.2025 00:51:21
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to ca...
CVE-2014-1491
- EPSS 0.61%
- Published 06.02.2014 05:44:25
- Last modified 11.04.2025 00:51:21
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellma...
CVE-2013-1620
- EPSS 0.81%
- Published 08.02.2013 19:55:01
- Last modified 11.04.2025 00:51:21
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct di...