Show filters
871 Total Results
Displaying 51-60 of 871
Sort by:
Attacker Value
Unknown

CVE-2024-39573

Disclosure Date: July 01, 2024 (last updated July 02, 2024)
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
0
Attacker Value
Unknown

CVE-2024-38477

Disclosure Date: July 01, 2024 (last updated August 22, 2024)
null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Attacker Value
Unknown

CVE-2024-38476

Disclosure Date: July 01, 2024 (last updated August 22, 2024)
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Attacker Value
Unknown

CVE-2024-38474

Disclosure Date: July 01, 2024 (last updated August 22, 2024)
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
Attacker Value
Unknown

CVE-2024-38473

Disclosure Date: July 01, 2024 (last updated July 02, 2024)
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
0
Attacker Value
Unknown

CVE-2024-38472

Disclosure Date: July 01, 2024 (last updated November 18, 2024)
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
0
Attacker Value
Unknown

CVE-2024-36387

Disclosure Date: July 01, 2024 (last updated July 02, 2024)
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
0
Attacker Value
Unknown

CVE-2024-6104

Disclosure Date: June 24, 2024 (last updated June 27, 2024)
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.
Attacker Value
Unknown

CVE-2018-25103

Disclosure Date: June 17, 2024 (last updated June 18, 2024)
There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.
0
Attacker Value
Unknown

CVE-2024-36129

Disclosure Date: June 05, 2024 (last updated June 19, 2024)
The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.