Show filters
486 Total Results
Displaying 211-220 of 486
Sort by:
Attacker Value
Unknown

CVE-2014-0231

Disclosure Date: July 20, 2014 (last updated November 01, 2023)
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
0
Attacker Value
Unknown

CVE-2014-3523

Disclosure Date: July 20, 2014 (last updated October 05, 2023)
Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
0
Attacker Value
Unknown

CVE-2013-5704

Disclosure Date: April 15, 2014 (last updated October 05, 2023)
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
0
Attacker Value
Unknown

CVE-2014-0098

Disclosure Date: March 18, 2014 (last updated October 05, 2023)
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
0
Attacker Value
Unknown

CVE-2013-6438

Disclosure Date: March 18, 2014 (last updated October 05, 2023)
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
0
Attacker Value
Unknown

CVE-2013-3922

Disclosure Date: November 25, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.
0
Attacker Value
Unknown

CVE-2013-2249

Disclosure Date: July 23, 2013 (last updated October 05, 2023)
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2013-1896

Disclosure Date: July 10, 2013 (last updated October 05, 2023)
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
0
Attacker Value
Unknown

CVE-2013-1862

Disclosure Date: June 10, 2013 (last updated October 05, 2023)
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown

CVE-2013-2566

Disclosure Date: March 15, 2013 (last updated October 22, 2024)
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
0