Search CVE reports
331 – 340 of 44355 results
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
[Unknown description]
1 affected package
librabbitmq
| Package | 20.04 LTS |
|---|---|
| librabbitmq | Needs evaluation |
[Unknown description]
1 affected package
librabbitmq
| Package | 20.04 LTS |
|---|---|
| librabbitmq | Needs evaluation |