Show filters
128 Total Results
Displaying 121-128 of 128
Sort by:
Attacker Value
Unknown
CVE-2016-8743
Disclosure Date: July 27, 2017 (last updated November 08, 2023)
Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.
0
Attacker Value
Unknown
CVE-2015-7703
Disclosure Date: July 24, 2017 (last updated November 26, 2024)
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.
0
Attacker Value
Unknown
CVE-2017-7947
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line.
0
Attacker Value
Unknown
CVE-2017-7668
Disclosure Date: June 20, 2017 (last updated November 08, 2023)
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.
0
Attacker Value
Unknown
CVE-2017-5988
Disclosure Date: April 10, 2017 (last updated November 26, 2024)
NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-2518
Disclosure Date: January 30, 2017 (last updated November 25, 2024)
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
0
Attacker Value
Unknown
CVE-2015-7977
Disclosure Date: January 30, 2017 (last updated November 25, 2024)
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
0
Attacker Value
Unknown
CVE-2015-7974
Disclosure Date: January 26, 2016 (last updated November 25, 2024)
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
0