Show filters
486 Total Results
Displaying 381-390 of 486
Sort by:
Attacker Value
Unknown
CVE-2003-1418
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).
0
Attacker Value
Unknown
CVE-2003-0542
Disclosure Date: November 03, 2003 (last updated February 22, 2025)
Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
0
Attacker Value
Unknown
CVE-2003-0789
Disclosure Date: November 03, 2003 (last updated October 03, 2023)
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
0
Attacker Value
Unknown
CVE-2003-0460
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
0
Attacker Value
Unknown
CVE-2003-0254
Disclosure Date: August 18, 2003 (last updated February 22, 2025)
Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
0
Attacker Value
Unknown
CVE-2003-0192
Disclosure Date: August 18, 2003 (last updated February 22, 2025)
Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
0
Attacker Value
Unknown
CVE-2003-0253
Disclosure Date: August 18, 2003 (last updated February 22, 2025)
The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
0
Attacker Value
Unknown
CVE-2003-0245
Disclosure Date: June 09, 2003 (last updated February 22, 2025)
Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
0
Attacker Value
Unknown
CVE-2003-0189
Disclosure Date: June 09, 2003 (last updated February 22, 2025)
The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
0
Attacker Value
Unknown
CVE-2003-0134
Disclosure Date: April 11, 2003 (last updated February 22, 2025)
Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.
0