Show filters
486 Total Results
Displaying 31-40 of 486
Sort by:
Attacker Value
Unknown
CVE-2024-39943
Disclosure Date: July 04, 2024 (last updated July 09, 2024)
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
0
Attacker Value
Unknown
CVE-2024-39884
Disclosure Date: July 04, 2024 (last updated July 04, 2024)
A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users are recommended to upgrade to version 2.4.61, which fixes this issue.
0
Attacker Value
Unknown
CVE-2024-39573
Disclosure Date: July 01, 2024 (last updated July 02, 2024)
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
0
Attacker Value
Unknown
CVE-2024-38477
Disclosure Date: July 01, 2024 (last updated August 22, 2024)
null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
0
Attacker Value
Unknown
CVE-2024-38476
Disclosure Date: July 01, 2024 (last updated August 22, 2024)
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
0
Attacker Value
Unknown
CVE-2024-38474
Disclosure Date: July 01, 2024 (last updated August 22, 2024)
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
0
Attacker Value
Unknown
CVE-2024-38473
Disclosure Date: July 01, 2024 (last updated July 02, 2024)
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
0
Attacker Value
Unknown
CVE-2024-38472
Disclosure Date: July 01, 2024 (last updated November 18, 2024)
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content
Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
0
Attacker Value
Unknown
CVE-2024-36387
Disclosure Date: July 01, 2024 (last updated July 02, 2024)
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
0
Attacker Value
Unknown
CVE-2024-20991
Disclosure Date: April 16, 2024 (last updated January 05, 2025)
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
0