Show filters
486 Total Results
Displaying 261-270 of 486
Sort by:
Attacker Value
Unknown

CVE-2009-1890

Disclosure Date: July 05, 2009 (last updated October 04, 2023)
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
0
Attacker Value
Unknown

CVE-2009-1956

Disclosure Date: June 08, 2009 (last updated October 04, 2023)
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
0
Attacker Value
Unknown

CVE-2009-0023

Disclosure Date: June 08, 2009 (last updated February 03, 2024)
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
0
Attacker Value
Unknown

CVE-2009-1955

Disclosure Date: June 08, 2009 (last updated February 03, 2024)
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
Attacker Value
Unknown

CVE-2009-1195

Disclosure Date: May 28, 2009 (last updated February 16, 2024)
The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
0
Attacker Value
Unknown

CVE-2009-1191

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
0
Attacker Value
Unknown

CVE-2008-2939

Disclosure Date: August 06, 2008 (last updated January 20, 2024)
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
0
Attacker Value
Unknown

CVE-2008-2614

Disclosure Date: July 15, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.3.3 has unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2008-2364

Disclosure Date: June 13, 2008 (last updated October 04, 2023)
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
0
Attacker Value
Unknown

CVE-2008-2168

Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
0