Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown

CVE-2004-0492

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
0
Attacker Value
Unknown

CVE-2004-2035

Disclosure Date: May 26, 2004 (last updated February 22, 2025)
MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.
0
Attacker Value
Unknown

CVE-2003-0993

Disclosure Date: March 29, 2004 (last updated February 22, 2025)
mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown

CVE-2004-1082

Disclosure Date: February 03, 2004 (last updated February 22, 2025)
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
0
Attacker Value
Unknown

CVE-2003-1418

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).
0
Attacker Value
Unknown

CVE-2003-0542

Disclosure Date: November 03, 2003 (last updated February 22, 2025)
Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
0
Attacker Value
Unknown

CVE-2002-2272

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
0
Attacker Value
Unknown

CVE-2002-1658

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
0
Attacker Value
Unknown

CVE-2002-2103

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
0
Attacker Value
Unknown

CVE-2002-2029

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
0