Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2007-6750
Disclosure Date: December 27, 2011 (last updated October 04, 2023)
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
0
Attacker Value
Unknown
CVE-2010-1623
Disclosure Date: October 04, 2010 (last updated October 04, 2023)
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
0
Attacker Value
Unknown
CVE-2009-0023
Disclosure Date: June 08, 2009 (last updated February 03, 2024)
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
0
Attacker Value
Unknown
CVE-2004-2213
Disclosure Date: December 31, 2004 (last updated October 04, 2023)
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.
0
Attacker Value
Unknown
CVE-2004-2317
Disclosure Date: December 31, 2004 (last updated October 04, 2023)
Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access.
0
Attacker Value
Unknown
CVE-2004-0263
Disclosure Date: November 23, 2004 (last updated October 04, 2023)
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2004-0173
Disclosure Date: April 15, 2004 (last updated October 03, 2023)
Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
0
Attacker Value
Unknown
CVE-2000-0913
Disclosure Date: December 19, 2000 (last updated October 03, 2023)
mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
0
Attacker Value
Unknown
CVE-1999-0107
Disclosure Date: December 30, 1997 (last updated October 03, 2023)
Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
0
Attacker Value
Unknown
CVE-1999-0071
Disclosure Date: September 01, 1997 (last updated October 03, 2023)
Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
0