Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

oracle-oval логотип

ELSA-2020-1725

больше 6 лет назад

ELSA-2020-1725: haproxy security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2019-19330

больше 6 лет назад

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2019-19330

больше 6 лет назад

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2019-19330

больше 6 лет назад

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-19330

больше 6 лет назад

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-18277

почти 7 лет назад

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2019-18277

почти 7 лет назад

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2019-18277

почти 7 лет назад

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2019-18277

почти 7 лет назад

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages fea ...

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-x4px-pm9c-vmjm

около 4 лет назад

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2020-02041

больше 6 лет назад

Уязвимость серверного программного обеспечения HAProxy, связанная с неправильным выполнением очистки HTTP-заголовков при преобразовании из HTTP/2 в HTTP/1, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2645-1

больше 6 лет назад

Security update for haproxy

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2019:2626-1

больше 6 лет назад

Security update for haproxy

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2019:3288-1

больше 6 лет назад

Security update for haproxy

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2019:3126-1

больше 6 лет назад

Security update for haproxy

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2019:3125-1

больше 6 лет назад

Security update for haproxy

EPSS: Средний
github логотип

GHSA-7r84-r685-grmg

около 4 лет назад

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2023-07810

почти 7 лет назад

Уязвимость серверного программного обеспечения HAProxy, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-1725

ELSA-2020-1725: haproxy security, bug fix, and enhancement update (MODERATE)

больше 6 лет назад
ubuntu логотип
CVE-2019-19330

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

CVSS3: 9.8
4%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-19330

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

CVSS3: 5.9
4%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-19330

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

CVSS3: 9.8
4%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-19330

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, ...

CVSS3: 9.8
4%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-18277

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

CVSS3: 7.5
10%
Средний
почти 7 лет назад
redhat логотип
CVE-2019-18277

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

CVSS3: 6.5
10%
Средний
почти 7 лет назад
nvd логотип
CVE-2019-18277

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

CVSS3: 7.5
10%
Средний
почти 7 лет назад
debian логотип
CVE-2019-18277

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages fea ...

CVSS3: 7.5
10%
Средний
почти 7 лет назад
github логотип
GHSA-x4px-pm9c-vmjm

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
fstec логотип
BDU:2020-02041

Уязвимость серверного программного обеспечения HAProxy, связанная с неправильным выполнением очистки HTTP-заголовков при преобразовании из HTTP/2 в HTTP/1, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
4%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2645-1

Security update for haproxy

10%
Средний
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2626-1

Security update for haproxy

10%
Средний
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:3288-1

Security update for haproxy

10%
Средний
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:3126-1

Security update for haproxy

10%
Средний
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:3125-1

Security update for haproxy

10%
Средний
больше 6 лет назад
github логотип
GHSA-7r84-r685-grmg

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

CVSS3: 7.5
10%
Средний
около 4 лет назад
fstec логотип
BDU:2023-07810

Уязвимость серверного программного обеспечения HAProxy, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
10%
Средний
почти 7 лет назад

Уязвимостей на страницу