Количество 58
Количество 58
GHSA-92ww-hwmg-qq7p
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
BDU:2021-06393
Уязвимость HTTP-сервера Apache, связанная с подделкой запросов на стороне сервера, позволяющая нарушителю провести SSRF-атаку
openSUSE-SU-2022:0091-1
Security update for apache2
SUSE-SU-2022:0440-1
Security update for apache2
SUSE-SU-2022:0119-1
Security update for apache2
SUSE-SU-2022:0091-2
Security update for apache2
SUSE-SU-2022:0091-1
Security update for apache2
SUSE-SU-2022:0065-1
Security update for apache2
CVE-2020-35452
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
CVE-2020-35452
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
CVE-2020-35452
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
CVE-2020-35452
mod_auth_digest possible stack overflow by one nul byte
CVE-2020-35452
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest ...
CVE-2021-33193
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
CVE-2021-33193
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
CVE-2021-33193
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
CVE-2021-33193
Request splitting via HTTP/2 method injection and mod_proxy
CVE-2021-33193
A crafted method sent through HTTP/2 will bypass validation and be for ...
ROS-20211223-04
Множественные уязвимости HTTP-сервера Apache
ALT-PU-2021-3637
ALT-PU-2021-3637: package `apache2` update to version 2.4.52-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-92ww-hwmg-qq7p A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included). | CVSS3: 8.2 | 82% Высокий | больше 4 лет назад | |
BDU:2021-06393 Уязвимость HTTP-сервера Apache, связанная с подделкой запросов на стороне сервера, позволяющая нарушителю провести SSRF-атаку | CVSS3: 7.2 | 82% Высокий | почти 5 лет назад | |
openSUSE-SU-2022:0091-1 Security update for apache2 | больше 4 лет назад | |||
SUSE-SU-2022:0440-1 Security update for apache2 | больше 4 лет назад | |||
SUSE-SU-2022:0119-1 Security update for apache2 | больше 4 лет назад | |||
SUSE-SU-2022:0091-2 Security update for apache2 | больше 4 лет назад | |||
SUSE-SU-2022:0091-1 Security update for apache2 | больше 4 лет назад | |||
SUSE-SU-2022:0065-1 Security update for apache2 | больше 4 лет назад | |||
CVE-2020-35452 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow | CVSS3: 7.3 | 55% Средний | больше 5 лет назад | |
CVE-2020-35452 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow | CVSS3: 7.3 | 55% Средний | больше 5 лет назад | |
CVE-2020-35452 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow | CVSS3: 7.3 | 55% Средний | больше 5 лет назад | |
CVE-2020-35452 mod_auth_digest possible stack overflow by one nul byte | CVSS3: 7.3 | 55% Средний | больше 5 лет назад | |
CVE-2020-35452 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest ... | CVSS3: 7.3 | 55% Средний | больше 5 лет назад | |
CVE-2021-33193 A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. | CVSS3: 7.5 | 46% Средний | около 5 лет назад | |
CVE-2021-33193 A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. | CVSS3: 7.5 | 46% Средний | около 5 лет назад | |
CVE-2021-33193 A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. | CVSS3: 7.5 | 46% Средний | около 5 лет назад | |
CVE-2021-33193 Request splitting via HTTP/2 method injection and mod_proxy | CVSS3: 7.5 | 46% Средний | около 5 лет назад | |
CVE-2021-33193 A crafted method sent through HTTP/2 will bypass validation and be for ... | CVSS3: 7.5 | 46% Средний | около 5 лет назад | |
ROS-20211223-04 Множественные уязвимости HTTP-сервера Apache | почти 5 лет назад | |||
ALT-PU-2021-3637 ALT-PU-2021-3637: package `apache2` update to version 2.4.52-alt1 | CVSS3: 10 | больше 4 лет назад |
Уязвимостей на страницу