Show filters
73 Total Results
Displaying 31-40 of 73
Sort by:
Attacker Value
Unknown
CVE-2006-4110
Disclosure Date: August 14, 2006 (last updated October 04, 2023)
Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
0
Attacker Value
Unknown
CVE-2006-3918
Disclosure Date: July 28, 2006 (last updated October 04, 2023)
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
0
Attacker Value
Unknown
CVE-2005-3357
Disclosure Date: December 31, 2005 (last updated October 04, 2023)
mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
0
Attacker Value
Unknown
CVE-2005-2728
Disclosure Date: August 30, 2005 (last updated October 04, 2023)
The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
0
Attacker Value
Unknown
CVE-2005-1344
Disclosure Date: May 02, 2005 (last updated October 04, 2023)
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
0
Attacker Value
Unknown
CVE-2004-0940
Disclosure Date: February 09, 2005 (last updated February 02, 2024)
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
0
Attacker Value
Unknown
CVE-2004-0811
Disclosure Date: December 31, 2004 (last updated October 04, 2023)
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
0
Attacker Value
Unknown
CVE-2004-0263
Disclosure Date: November 23, 2004 (last updated October 04, 2023)
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2004-0885
Disclosure Date: November 03, 2004 (last updated October 04, 2023)
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
0
Attacker Value
Unknown
CVE-2004-0809
Disclosure Date: September 16, 2004 (last updated October 04, 2023)
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
0