Show filters
486 Total Results
Displaying 71-80 of 486
Sort by:
Attacker Value
Unknown

CVE-2022-28615

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.
Attacker Value
Unknown

CVE-2022-28614

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'ap_rputs' function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue.
Attacker Value
Unknown

CVE-2022-28330

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
Attacker Value
Unknown

CVE-2022-26377

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
Attacker Value
Unknown

CVE-2021-40668

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write.
Attacker Value
Unknown

CVE-2020-26185

Disclosure Date: May 31, 2022 (last updated October 07, 2023)
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.
Attacker Value
Unknown

CVE-2020-26184

Disclosure Date: May 31, 2022 (last updated October 07, 2023)
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
Attacker Value
Unknown

CVE-2022-28994

Disclosure Date: April 29, 2022 (last updated October 07, 2023)
Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.
Attacker Value
Unknown

CVE-2022-22719

Disclosure Date: March 14, 2022 (last updated November 08, 2023)
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
Attacker Value
Unknown

CVE-2022-22721

Disclosure Date: March 14, 2022 (last updated November 08, 2023)
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.