Show filters
486 Total Results
Displaying 301-310 of 486
Sort by:
Attacker Value
Unknown
CVE-2007-3009
Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.
0
Attacker Value
Unknown
CVE-2007-2367
Disclosure Date: April 30, 2007 (last updated October 04, 2023)
Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit) via a long directory name in the URI.
0
Attacker Value
Unknown
CVE-2007-2315
Disclosure Date: April 26, 2007 (last updated October 04, 2023)
MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections.
0
Attacker Value
Unknown
CVE-2007-1742
Disclosure Date: April 13, 2007 (last updated November 08, 2023)
suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
0
Attacker Value
Unknown
CVE-2007-1743
Disclosure Date: April 13, 2007 (last updated November 08, 2023)
suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
0
Attacker Value
Unknown
CVE-2007-1741
Disclosure Date: April 13, 2007 (last updated October 04, 2023)
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
0
Attacker Value
Unknown
CVE-2007-0450
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
0
Attacker Value
Unknown
CVE-2006-6969
Disclosure Date: February 07, 2007 (last updated October 04, 2023)
Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.
0
Attacker Value
Unknown
CVE-2007-0548
Disclosure Date: January 29, 2007 (last updated October 04, 2023)
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects.
0
Attacker Value
Unknown
CVE-2007-0279
Disclosure Date: January 17, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.
0