Show filters
95 Total Results
Displaying 41-50 of 95
Sort by:
Attacker Value
Unknown
CVE-2021-32565
Disclosure Date: June 29, 2021 (last updated November 28, 2024)
Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
0
Attacker Value
Unknown
CVE-2021-27577
Disclosure Date: June 29, 2021 (last updated November 28, 2024)
Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
0
Attacker Value
Unknown
CVE-2021-27737
Disclosure Date: May 14, 2021 (last updated November 08, 2023)
Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.
0
Attacker Value
Unknown
CVE-2020-17509
Disclosure Date: January 11, 2021 (last updated November 28, 2024)
ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
0
Attacker Value
Unknown
CVE-2020-17508
Disclosure Date: January 11, 2021 (last updated November 28, 2024)
The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
0
Attacker Value
Unknown
CVE-2020-9494
Disclosure Date: June 24, 2020 (last updated February 21, 2025)
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
0
Attacker Value
Unknown
CVE-2020-9481
Disclosure Date: April 27, 2020 (last updated February 21, 2025)
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
0
Attacker Value
Unknown
CVE-2019-17559
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
0
Attacker Value
Unknown
CVE-2019-17565
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
0
Attacker Value
Unknown
CVE-2020-1944
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
0