Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Traffic Server HIGH 7.5
CVE-2019-9513EPSS 82%

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request strea…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9514EPSS 83%

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and s…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9515EPSS 87%

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS f…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
HTTP Server HIGH 7.5
CVE-2019-9517EPSS 28%

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens th…

Fix: 2.4.40+
Fix from $1,950 2019-08-13
Traffic Server MEDIUM 6.5
CVE-2019-9516EPSS 56%

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with …

Fix: after 8.0.3
Fix from $1,600 2019-08-13
Tomcat HIGH 7.5
CVE-2019-0199EPSS 73%

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also…

Fix: after 9.0.14
Fix from $1,950 2019-04-10
HTTP Server MEDIUM 5.3
CVE-2018-17189EPSS 20%

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unn…

Mitigation only
Fix from $1,600 2019-01-30
Traffic Server MEDIUM 5.3
CVE-2018-8005EPSS 7%

When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance pro…

Fix: after 7.1.3
Fix from $1,600 2018-08-29
HTTP Server HIGH 7.5
CVE-2018-1333EPSS 17%

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of serv…

Fix: after 2.4.30
Fix from $1,950 2018-06-18
Artemis HIGH 7.5
CVE-2017-12174EPSS 6%

It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when rec…

Fix: 2.4.0+
Fix from $1,950 2018-03-07
Qpid Broker J HIGH 7.5
CVE-2017-15701

In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remo…

Fix: after 6.1.4
Fix from $1,950 2017-12-01
Subversion MEDIUM 6.5
CVE-2016-8734EPSS 6%

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack…

Mitigation only
Fix from $1,600 2017-10-16
Zookeeper HIGH 7.5
CVE-2017-5637EPSS 73%

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which lead…

Mitigation only
Fix from $1,950 2017-10-10
Openmeetings HIGH 7.5
CVE-2017-7684

Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files…

Mitigation only
Fix from $1,950 2017-07-17
Traffic Control HIGH 7.5
CVE-2017-7670

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connec…

Fix: after 1.8.0
Fix from $1,950 2017-07-10
Ws Xmlrpc MEDIUM 6.5
CVE-2016-5004EPSS 6%

The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource …

No fix yet
Fix from $1,600 2017-06-06
HTTP Server HIGH 7.8
CVE-2011-3192EPSS 99%

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of ser…

Fix: 2.0.65 / 2.2.20+
Fix from $1,950 2011-08-29
HTTP Server HIGH 7.1
CVE-2009-1891EPSS 17%

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is clo…

Fix: 2.0.64 / 2.2.12+
Fix from $1,950 2009-07-10
HTTP Server HIGH 7.1
CVE-2009-1890EPSS 16%

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured…

Fix: 2.2.12+
Fix from $1,950 2009-07-05
HTTP Server HIGH 7.8
CVE-2007-0086EPSS 10%

The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ…

Mitigation only
Fix from $1,950 2007-01-05