Show filters
95 Total Results
Displaying 41-50 of 95
Sort by:
Attacker Value
Unknown

CVE-2021-32565

Disclosure Date: June 29, 2021 (last updated November 28, 2024)
Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
Attacker Value
Unknown

CVE-2021-27577

Disclosure Date: June 29, 2021 (last updated November 28, 2024)
Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
Attacker Value
Unknown

CVE-2021-27737

Disclosure Date: May 14, 2021 (last updated November 08, 2023)
Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.
Attacker Value
Unknown

CVE-2020-17509

Disclosure Date: January 11, 2021 (last updated November 28, 2024)
ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
Attacker Value
Unknown

CVE-2020-17508

Disclosure Date: January 11, 2021 (last updated November 28, 2024)
The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
Attacker Value
Unknown

CVE-2020-9494

Disclosure Date: June 24, 2020 (last updated February 21, 2025)
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
Attacker Value
Unknown

CVE-2020-9481

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
Attacker Value
Unknown

CVE-2019-17559

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
Attacker Value
Unknown

CVE-2019-17565

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
Attacker Value
Unknown

CVE-2020-1944

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.