Логотип exploitDog
bind:CVE-2024-40725
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-40725

Количество 12

Количество 12

ubuntu логотип

CVE-2024-40725

11 месяцев назад

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.

CVSS3: 5.3
EPSS: Средний
redhat логотип

CVE-2024-40725

11 месяцев назад

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2024-40725

11 месяцев назад

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.

CVSS3: 5.3
EPSS: Средний
msrc логотип

CVE-2024-40725

11 месяцев назад

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2024-40725

11 месяцев назад

A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4 ...

CVSS3: 5.3
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:3864-1

8 месяцев назад

Security update for apache2

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:3750-1

8 месяцев назад

Security update for apache2

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:3742-1

8 месяцев назад

Security update for apache2

EPSS: Средний
github логотип

GHSA-x749-289q-pg9q

11 месяцев назад

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.

CVSS3: 5.3
EPSS: Средний
fstec логотип

BDU:2024-05741

12 месяцев назад

Уязвимость ядра веб-сервера Apache HTTP Server, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
EPSS: Средний
fstec логотип

BDU:2024-05368

11 месяцев назад

Уязвимость модуля mod_rewrite веб-сервера Apache HTTP Server, позволяющая нарушителю получить несанкционированный доступ к устройству путём подделки запросов от имени сервера

CVSS3: 10
EPSS: Низкий
redos логотип

ROS-20240812-15

10 месяцев назад

Множественные уязвимости httpd

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-40725

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.

CVSS3: 5.3
25%
Средний
11 месяцев назад
redhat логотип
CVE-2024-40725

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.

CVSS3: 7.5
25%
Средний
11 месяцев назад
nvd логотип
CVE-2024-40725

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.

CVSS3: 5.3
25%
Средний
11 месяцев назад
msrc логотип
CVSS3: 5.3
25%
Средний
11 месяцев назад
debian логотип
CVE-2024-40725

A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4 ...

CVSS3: 5.3
25%
Средний
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3864-1

Security update for apache2

25%
Средний
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3750-1

Security update for apache2

25%
Средний
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3742-1

Security update for apache2

25%
Средний
8 месяцев назад
github логотип
GHSA-x749-289q-pg9q

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.

CVSS3: 5.3
25%
Средний
11 месяцев назад
fstec логотип
BDU:2024-05741

Уязвимость ядра веб-сервера Apache HTTP Server, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
25%
Средний
12 месяцев назад
fstec логотип
BDU:2024-05368

Уязвимость модуля mod_rewrite веб-сервера Apache HTTP Server, позволяющая нарушителю получить несанкционированный доступ к устройству путём подделки запросов от имени сервера

CVSS3: 10
0%
Низкий
11 месяцев назад
redos логотип
ROS-20240812-15

Множественные уязвимости httpd

CVSS3: 7.5
10 месяцев назад

Уязвимостей на страницу