Show filters
73 Total Results
Displaying 21-30 of 73
Sort by:
Attacker Value
Unknown

CVE-2009-3560

Disclosure Date: December 04, 2009 (last updated November 02, 2023)
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
0
Attacker Value
Unknown

CVE-2009-3720

Disclosure Date: November 03, 2009 (last updated February 22, 2024)
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
0
Attacker Value
Unknown

CVE-2008-2168

Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
0
Attacker Value
Unknown

CVE-2007-6203

Disclosure Date: December 03, 2007 (last updated October 04, 2023)
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
0
Attacker Value
Unknown

CVE-2007-3303

Disclosure Date: June 20, 2007 (last updated October 04, 2023)
Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
0
Attacker Value
Unknown

CVE-2007-3008

Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
0
Attacker Value
Unknown

CVE-2007-3009

Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.
0
Attacker Value
Unknown

CVE-2007-0548

Disclosure Date: January 29, 2007 (last updated October 04, 2023)
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects.
0
Attacker Value
Unknown

CVE-2006-6675

Disclosure Date: December 21, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in Welcome web-app.
0
Attacker Value
Unknown

CVE-2006-4154

Disclosure Date: October 16, 2006 (last updated October 04, 2023)
Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
0