Логотип exploitDog
bind:"CVE-2015-3185" OR bind:"CVE-2015-3183"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2015-3185" OR bind:"CVE-2015-3183"

Количество 18

Количество 18

oracle-oval логотип

ELSA-2015-1667

около 10 лет назад

ELSA-2015-1667: httpd security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1851-1

около 10 лет назад

Security update for apache2

EPSS: Низкий
oracle-oval логотип

ELSA-2015-1666

почти 10 лет назад

ELSA-2015-1666: httpd24-httpd security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2015-3185

больше 10 лет назад

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2015-3185

больше 10 лет назад

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS3: 3.7
EPSS: Средний
nvd логотип

CVE-2015-3185

больше 10 лет назад

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2015-3185

больше 10 лет назад

The ap_some_auth_required function in server/request.c in the Apache H ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2015-3183

больше 10 лет назад

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2015-3183

больше 10 лет назад

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

CVSS3: 3.7
EPSS: Средний
nvd логотип

CVE-2015-3183

больше 10 лет назад

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2015-3183

больше 10 лет назад

The chunked transfer coding implementation in the Apache HTTP Server b ...

CVSS2: 5
EPSS: Средний
github логотип

GHSA-5fv4-m5x3-j32p

больше 3 лет назад

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

EPSS: Средний
fstec логотип

BDU:2015-10929

больше 10 лет назад

Уязвимость веб-сервера Apache HTTP Server, позволяющая нарушителю обойти существующие ограничения доступа

CVSS2: 4.3
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2015:1885-2

около 10 лет назад

Security update for apache2

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2015:1885-1

около 10 лет назад

Security update for apache2

EPSS: Средний
github логотип

GHSA-892q-vvcr-v6j5

больше 3 лет назад

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

EPSS: Средний
oracle-oval логотип

ELSA-2015-1668

около 10 лет назад

ELSA-2015-1668: httpd security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2015-10928

больше 10 лет назад

Уязвимость веб-сервера Apache HTTP Server, позволяющая нарушителю передавать скрытые http-запросы

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2015-1667

ELSA-2015-1667: httpd security update (MODERATE)

около 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:1851-1

Security update for apache2

около 10 лет назад
oracle-oval логотип
ELSA-2015-1666

ELSA-2015-1666: httpd24-httpd security update (MODERATE)

почти 10 лет назад
ubuntu логотип
CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS2: 4.3
10%
Средний
больше 10 лет назад
redhat логотип
CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS3: 3.7
10%
Средний
больше 10 лет назад
nvd логотип
CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS2: 4.3
10%
Средний
больше 10 лет назад
debian логотип
CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache H ...

CVSS2: 4.3
10%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2015-3183

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

CVSS2: 5
38%
Средний
больше 10 лет назад
redhat логотип
CVE-2015-3183

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

CVSS3: 3.7
38%
Средний
больше 10 лет назад
nvd логотип
CVE-2015-3183

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

CVSS2: 5
38%
Средний
больше 10 лет назад
debian логотип
CVE-2015-3183

The chunked transfer coding implementation in the Apache HTTP Server b ...

CVSS2: 5
38%
Средний
больше 10 лет назад
github логотип
GHSA-5fv4-m5x3-j32p

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

10%
Средний
больше 3 лет назад
fstec логотип
BDU:2015-10929

Уязвимость веб-сервера Apache HTTP Server, позволяющая нарушителю обойти существующие ограничения доступа

CVSS2: 4.3
10%
Средний
больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:1885-2

Security update for apache2

38%
Средний
около 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:1885-1

Security update for apache2

38%
Средний
около 10 лет назад
github логотип
GHSA-892q-vvcr-v6j5

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

38%
Средний
больше 3 лет назад
oracle-oval логотип
ELSA-2015-1668

ELSA-2015-1668: httpd security update (MODERATE)

около 10 лет назад
fstec логотип
BDU:2015-10928

Уязвимость веб-сервера Apache HTTP Server, позволяющая нарушителю передавать скрытые http-запросы

CVSS2: 5
38%
Средний
больше 10 лет назад

Уязвимостей на страницу