CVE-2018-2561
- EPSS 2.26%
- Published 18.01.2018 02:29:17
- Last modified 21.11.2024 04:03:56
Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allow...
- EPSS 0.37%
- Published 21.07.2016 10:12:36
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.9 and 12.1.3.0 allows remote attackers to affect confidentiality via vectors related to SSL/TLS Module.
CVE-2016-0671
- EPSS 0.25%
- Published 21.04.2016 10:59:34
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 12.1.2.0 allows remote attackers to affect confidentiality via vectors related to OSSL Module.
CVE-2015-3195
- EPSS 3.48%
- Published 06.12.2015 20:59:05
- Last modified 12.04.2025 10:46:40
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to ob...
- EPSS 52.59%
- Published 01.04.2015 02:00:35
- Last modified 12.04.2025 10:46:40
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial ...
CVE-2014-0226
- EPSS 73.42%
- Published 20.07.2014 11:12:48
- Last modified 12.04.2025 10:46:40
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a cr...
- EPSS 75.57%
- Published 15.04.2014 10:55:11
- Last modified 12.04.2025 10:46:40
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...
- EPSS 47.14%
- Published 18.03.2014 05:18:18
- Last modified 12.04.2025 10:46:40
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) v...
- EPSS 47.4%
- Published 18.03.2014 05:18:18
- Last modified 12.04.2025 10:46:40
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handl...
CVE-2013-1862
- EPSS 41.76%
- Published 10.06.2013 17:55:01
- Last modified 11.04.2025 00:51:21
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containi...