CVE-2007-1349
|
PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
Published:
March 29, 2007; 08:19:00 PM -04:00
|
V2: 4.3 MEDIUM
|
CVE-2007-0086
|
** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.
Published:
January 05, 2007; 01:28:00 PM -05:00
|
V2: 7.8 HIGH
|
CVE-2006-4154
|
Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
Published:
October 16, 2006; 03:07:00 PM -04:00
|
V2: 6.8 MEDIUM
|
CVE-2005-3357
|
mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
Published:
December 31, 2005; 12:00:00 AM -05:00
|
V2: 5.4 MEDIUM
|
CVE-2005-3352
|
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
Published:
December 13, 2005; 03:03:00 PM -05:00
|
V2: 4.3 MEDIUM
|
CVE-2005-2700
|
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Published:
September 06, 2005; 07:03:00 PM -04:00
|
V2: 10.0 HIGH
|
CVE-2005-2728
|
The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
Published:
August 30, 2005; 07:45:00 AM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2005-1268
|
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
Published:
August 05, 2005; 12:00:00 AM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2004-0942
|
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
Published:
February 09, 2005; 12:00:00 AM -05:00
|
V2: 5.0 MEDIUM
|
CVE-2004-2343
|
** DISPUTED ** Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument.
Published:
December 31, 2004; 12:00:00 AM -05:00
|
V2: 7.2 HIGH
|
CVE-2004-0263
|
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
Published:
November 23, 2004; 12:00:00 AM -05:00
|
V2: 5.0 MEDIUM
|
CVE-2004-0885
|
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
Published:
November 03, 2004; 12:00:00 AM -05:00
|
V2: 7.5 HIGH
|
CVE-2004-0747
|
Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
Published:
October 20, 2004; 12:00:00 AM -04:00
|
V2: 4.6 MEDIUM
|
CVE-2004-0748
|
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
Published:
October 20, 2004; 12:00:00 AM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2004-0751
|
The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
Published:
October 20, 2004; 12:00:00 AM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2004-0786
|
The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
Published:
October 20, 2004; 12:00:00 AM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2004-0488
|
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
Published:
July 07, 2004; 12:00:00 AM -04:00
|
V2: 7.5 HIGH
|
CVE-2004-0174
|
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
Published:
May 04, 2004; 12:00:00 AM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2004-0113
|
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
Published:
March 29, 2004; 12:00:00 AM -05:00
|
V2: 5.0 MEDIUM
|
CVE-2004-1834
|
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
Published:
March 20, 2004; 12:00:00 AM -05:00
|
V2: 2.1 LOW
|