Show filters
486 Total Results
Displaying 471-480 of 486
Sort by:
Attacker Value
Unknown
CVE-1999-1053
Disclosure Date: September 13, 1999 (last updated February 22, 2025)
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
0
Attacker Value
Unknown
CVE-1999-0926
Disclosure Date: September 03, 1999 (last updated February 22, 2025)
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
0
Attacker Value
Unknown
CVE-2000-1206
Disclosure Date: August 20, 1999 (last updated February 22, 2025)
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
0
Attacker Value
Unknown
CVE-1999-0929
Disclosure Date: June 16, 1999 (last updated February 22, 2025)
Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.
0
Attacker Value
Unknown
CVE-1999-1237
Disclosure Date: June 06, 1999 (last updated February 22, 2025)
Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
0
Attacker Value
Unknown
CVE-1999-1412
Disclosure Date: June 03, 1999 (last updated October 03, 2023)
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
0
Attacker Value
Unknown
CVE-1999-0678
Disclosure Date: January 17, 1999 (last updated February 22, 2025)
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
0
Attacker Value
Unknown
CVE-1999-1199
Disclosure Date: August 07, 1998 (last updated February 22, 2025)
Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
0
Attacker Value
Unknown
CVE-1999-0107
Disclosure Date: December 30, 1997 (last updated February 22, 2025)
Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
0
Attacker Value
Unknown
CVE-1999-1125
Disclosure Date: September 19, 1997 (last updated February 22, 2025)
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.
0