Show filters
871 Total Results
Displaying 181-190 of 871
Sort by:
Attacker Value
Unknown

CVE-2022-28994

Disclosure Date: April 29, 2022 (last updated February 23, 2025)
Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.
Attacker Value
Unknown

CVE-2021-41945

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
Attacker Value
Unknown

CVE-2022-24863

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2.6 an attacker may perform a denial of service attack consisting of memory exhaustion on the host system. The cause of the memory exhaustion is down to improper handling of http methods. Users are advised to upgrade. Users unable to upgrade may to restrict the path prefix to the "GET" method as a workaround.
Attacker Value
Unknown

CVE-2022-28380

Disclosure Date: April 03, 2022 (last updated February 23, 2025)
The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is used.
Attacker Value
Unknown

CVE-2020-25691

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2022-21221

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue impacts Windows users only.
Attacker Value
Unknown

CVE-2022-0430

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.
Attacker Value
Unknown

CVE-2022-22719

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
Attacker Value
Unknown

CVE-2022-22721

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
Attacker Value
Unknown

CVE-2022-23943

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.