Show filters
486 Total Results
Displaying 291-300 of 486
Sort by:
Attacker Value
Unknown

CVE-2007-3847

Disclosure Date: August 23, 2007 (last updated October 04, 2023)
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
0
Attacker Value
Unknown

CVE-2007-1863

Disclosure Date: June 27, 2007 (last updated February 16, 2024)
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
0
Attacker Value
Unknown

CVE-2006-5752

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
0
Attacker Value
Unknown

CVE-2007-3340

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a large number of requests for nonexistent pages.
0
Attacker Value
Unknown

CVE-2007-3327

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
httpsv.exe in HTTP Server 1.6.2 allows remote attackers to obtain sensitive information (script source code) via a URI with a trailing %20 (encoded space).
0
Attacker Value
Unknown

CVE-2007-3303

Disclosure Date: June 20, 2007 (last updated October 04, 2023)
Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
0
Attacker Value
Unknown

CVE-2007-3304

Disclosure Date: June 20, 2007 (last updated October 04, 2023)
Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
0
Attacker Value
Unknown

CVE-2007-3159

Disclosure Date: June 11, 2007 (last updated October 04, 2023)
http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Length HTTP header.
0
Attacker Value
Unknown

CVE-2007-1862

Disclosure Date: June 04, 2007 (last updated October 04, 2023)
The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
0
Attacker Value
Unknown

CVE-2007-3008

Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
0