Логотип exploitDog
bind:"CVE-2009-0023" OR bind:"CVE-2009-1955" OR bind:"CVE-2009-1956"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2009-0023" OR bind:"CVE-2009-1955" OR bind:"CVE-2009-1956"

Количество 16

Количество 16

oracle-oval логотип

ELSA-2009-1107

около 16 лет назад

ELSA-2009-1107: apr-util security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2009-0023

около 16 лет назад

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2009-0023

около 16 лет назад

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2009-0023

около 16 лет назад

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2009-0023

около 16 лет назад

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apa ...

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-8jp8-5574-2q6q

около 3 лет назад

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

EPSS: Средний
ubuntu логотип

CVE-2009-1956

около 16 лет назад

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2009-1956

около 16 лет назад

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-1956

около 16 лет назад

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2009-1956

около 16 лет назад

Off-by-one error in the apr_brigade_vprintf function in Apache APR-uti ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2009-1955

около 16 лет назад

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2009-1955

около 16 лет назад

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-1955

около 16 лет назад

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2009-1955

около 16 лет назад

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Ap ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hfr6-pxvf-frf7

около 3 лет назад

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wj9-j34x-wjxp

около 3 лет назад

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2009-1107

ELSA-2009-1107: apr-util security update (MODERATE)

около 16 лет назад
ubuntu логотип
CVE-2009-0023

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

CVSS2: 4.3
10%
Средний
около 16 лет назад
redhat логотип
CVE-2009-0023

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

CVSS2: 4.3
10%
Средний
около 16 лет назад
nvd логотип
CVE-2009-0023

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

CVSS2: 4.3
10%
Средний
около 16 лет назад
debian логотип
CVE-2009-0023

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apa ...

CVSS2: 4.3
10%
Средний
около 16 лет назад
github логотип
GHSA-8jp8-5574-2q6q

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

10%
Средний
около 3 лет назад
ubuntu логотип
CVE-2009-1956

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

CVSS2: 6.4
4%
Низкий
около 16 лет назад
redhat логотип
CVE-2009-1956

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

CVSS2: 4.3
4%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-1956

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

CVSS2: 6.4
4%
Низкий
около 16 лет назад
debian логотип
CVE-2009-1956

Off-by-one error in the apr_brigade_vprintf function in Apache APR-uti ...

CVSS2: 6.4
4%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-1955

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

CVSS3: 7.5
4%
Низкий
около 16 лет назад
redhat логотип
CVE-2009-1955

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

CVSS2: 5
4%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-1955

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

CVSS3: 7.5
4%
Низкий
около 16 лет назад
debian логотип
CVE-2009-1955

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Ap ...

CVSS3: 7.5
4%
Низкий
около 16 лет назад
github логотип
GHSA-hfr6-pxvf-frf7

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

CVSS3: 7.5
4%
Низкий
около 3 лет назад
github логотип
GHSA-4wj9-j34x-wjxp

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

4%
Низкий
около 3 лет назад

Уязвимостей на страницу