Search CVE reports


Toggle filters

241 – 250 of 318 results


CVE-2011-1928

Medium priority
Fixed

The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does...

2 affected packages

apache2, apr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2
apr
Show less packages

CVE-2011-0419

Medium priority
Fixed

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD...

2 affected packages

apache2, apr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2
apr
Show less packages

CVE-2011-1176

Medium priority

Some fixes available 3 of 4

The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but...

2 affected packages

apache2, apache2-mpm-itk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2
apache2-mpm-itk
Show less packages

CVE-2010-3872

Medium priority

Some fixes available 4 of 5

A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an...

1 affected package

libapache2-mod-fcgid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-fcgid
Show less packages

CVE-2010-1623

Medium priority

Some fixes available 6 of 7

Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other...

2 affected packages

apache2, apr-util

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2
apr-util
Show less packages

CVE-2010-2791

Low priority
Ignored

mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a...

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2
Show less packages

CVE-2010-1452

Low priority

Some fixes available 4 of 5

The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2
Show less packages

CVE-2010-2068

Medium priority
Not affected

mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect...

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2
Show less packages

CVE-2010-1151

Medium priority
Ignored

Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper...

1 affected package

libapache2-mod-auth-shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-auth-shadow
Show less packages

CVE-2010-0425

Low priority
Not affected

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling...

1 affected package

apache2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2
Show less packages