Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2019-9513EPSS 82% Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request strea… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9514EPSS 83% Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and s… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9515EPSS 87% Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS f… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9517EPSS 28% Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens th… HTTP Server 2.4.40+ Fix from $1,9502019-08-13 MEDIUM 6.5 CVE-2019-9516EPSS 56% Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with … Traffic Server after 8.0.3 Fix from $1,6002019-08-13 HIGH 7.5 CVE-2019-0199EPSS 73% The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also… Tomcat after 9.0.14 Fix from $1,9502019-04-10 MEDIUM 5.3 CVE-2018-17189EPSS 20% In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unn… HTTP Server Mitigation only Fix from $1,6002019-01-30 MEDIUM 5.3 CVE-2018-8005EPSS 7% When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance pro… Traffic Server after 7.1.3 Fix from $1,6002018-08-29 HIGH 7.5 CVE-2018-1333EPSS 17% By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of serv… HTTP Server after 2.4.30 Fix from $1,9502018-06-18 HIGH 7.5 CVE-2017-12174EPSS 6% It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when rec… Artemis 2.4.0+ Fix from $1,9502018-03-07 HIGH 7.5 CVE-2017-15701 In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remo… Qpid Broker J after 6.1.4 Fix from $1,9502017-12-01 MEDIUM 6.5 CVE-2016-8734EPSS 6% Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack… Subversion Mitigation only Fix from $1,6002017-10-16 HIGH 7.5 CVE-2017-5637EPSS 73% Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which lead… Zookeeper Mitigation only Fix from $1,9502017-10-10 HIGH 7.5 CVE-2017-7684 Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files… Openmeetings Mitigation only Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-7670 The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connec… Traffic Control after 1.8.0 Fix from $1,9502017-07-10 MEDIUM 6.5 CVE-2016-5004EPSS 6% The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource … Ws Xmlrpc No fix yet Fix from $1,6002017-06-06 HIGH 7.8 CVE-2011-3192EPSS 99% The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of ser… HTTP Server 2.0.65 / 2.2.20+ Fix from $1,9502011-08-29 HIGH 7.1 CVE-2009-1891EPSS 17% The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is clo… HTTP Server 2.0.64 / 2.2.12+ Fix from $1,9502009-07-10 HIGH 7.1 CVE-2009-1890EPSS 16% The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured… HTTP Server 2.2.12+ Fix from $1,9502009-07-05 HIGH 7.8 CVE-2007-0086EPSS 10% The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ… HTTP Server Mitigation only Fix from $1,9502007-01-05