Oracle

HTTP Server

103 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.26%
  • Veröffentlicht 18.01.2018 02:29:17
  • Zuletzt bearbeitet 21.11.2024 04:03:56

Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allow...

  • EPSS 0.37%
  • Veröffentlicht 21.07.2016 10:12:36
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.9 and 12.1.3.0 allows remote attackers to affect confidentiality via vectors related to SSL/TLS Module.

  • EPSS 0.25%
  • Veröffentlicht 21.04.2016 10:59:34
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 12.1.2.0 allows remote attackers to affect confidentiality via vectors related to OSSL Module.

  • EPSS 3.48%
  • Veröffentlicht 06.12.2015 20:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to ob...

  • EPSS 52.59%
  • Veröffentlicht 01.04.2015 02:00:35
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial ...

Exploit
  • EPSS 73.42%
  • Veröffentlicht 20.07.2014 11:12:48
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a cr...

Exploit
  • EPSS 75.57%
  • Veröffentlicht 15.04.2014 10:55:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...

  • EPSS 47.14%
  • Veröffentlicht 18.03.2014 05:18:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) v...

  • EPSS 47.4%
  • Veröffentlicht 18.03.2014 05:18:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handl...

  • EPSS 41.76%
  • Veröffentlicht 10.06.2013 17:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containi...