Show filters
871 Total Results
Displaying 321-330 of 871
Sort by:
Attacker Value
Unknown

CVE-2019-5457

Disclosure Date: July 30, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.
Attacker Value
Unknown

CVE-2019-2751

Disclosure Date: July 23, 2019 (last updated November 27, 2024)
Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OHS Config MBeans). Supported versions that are affected are 12.1.3.0.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
0
Attacker Value
Unknown

CVE-2019-1010206

Disclosure Date: July 23, 2019 (last updated November 27, 2024)
OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing.
Attacker Value
Unknown

CVE-2019-5447

Disclosure Date: July 15, 2019 (last updated November 27, 2024)
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
Attacker Value
Unknown

CVE-2019-5443

Disclosure Date: July 02, 2019 (last updated November 27, 2024)
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
Attacker Value
Unknown

CVE-2018-20843

Disclosure Date: June 24, 2019 (last updated November 08, 2023)
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
Attacker Value
Unknown

CVE-2019-0197

Disclosure Date: June 11, 2019 (last updated November 08, 2023)
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.
Attacker Value
Unknown

CVE-2019-0196

Disclosure Date: June 11, 2019 (last updated November 08, 2023)
A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.
0
Attacker Value
Unknown

CVE-2019-0220

Disclosure Date: June 11, 2019 (last updated November 08, 2023)
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.
0
Attacker Value
Unknown

CVE-2019-12198

Disclosure Date: May 20, 2019 (last updated November 27, 2024)
In GoHttp through 2017-07-25, there is a stack-based buffer over-read via a long User-Agent header.
0