Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-46292

Опубликовано: 09 окт. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trustwave:modsecurity:3.0.12:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00576
Низкий

7.5 High

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

CVSS3: 3.7
redhat
больше 1 года назад

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

CVSS3: 7.5
debian
больше 1 года назад

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a D ...

CVSS3: 7.5
github
больше 1 года назад

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter.

EPSS

Процентиль: 68%
0.00576
Низкий

7.5 High

CVSS3

Дефекты

CWE-120