Apache / Apache Traffic Server
95 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-38161 | Not validating origin TLS certificate | HIGH | 8.1 | Nov 3, 2021 |
| CVE-2021-37149 | Request Smuggling - multiple attacks | HIGH | 7.5 | Nov 3, 2021 |
| CVE-2021-37148 | Request Smuggling - transfer encoding validation | HIGH | 7.5 | Nov 3, 2021 |
| CVE-2021-37147 | Request Smuggling - LF line ending | HIGH | 7.5 | Nov 3, 2021 |
| CVE-2021-35474 | Dynamic stack buffer overflow in cachekey plugin | CRITICAL | 9.8 | Jun 30, 2021 |
| CVE-2021-32567 | Reading HTTP/2 frames too many times | HIGH | 7.5 | Jun 30, 2021 |
| CVE-2021-32566 | Specific sequence of HTTP/2 frames can cause ATS to crash | HIGH | 7.5 | Jun 30, 2021 |
| CVE-2021-32565 | HTTP Request Smuggling, content length with invalid charters | HIGH | 7.5 | Jun 29, 2021 |
| CVE-2021-27577 | Incorrect handling of url fragment leads to cache poisoning | HIGH | 7.5 | Jun 29, 2021 |
| CVE-2020-9494 | Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to… | HIGH | 7.5 | Jun 24, 2020 |
| CVE-2018-11783 | sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't… | HIGH | 7.5 | Mar 7, 2019 |
| CVE-2018-8040 | Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffi… | MEDIUM | 5.3 | Aug 29, 2018 |
| CVE-2018-8022 | A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.… | HIGH | 7.5 | Aug 29, 2018 |
| CVE-2018-8005 | When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with… | MEDIUM | 5.3 | Aug 29, 2018 |
| CVE-2018-8004 | There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects ver… | MEDIUM | 6.5 | Aug 29, 2018 |
| CVE-2018-1318 | Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.… | HIGH | 7.5 | Aug 29, 2018 |
| CVE-2017-7671 | There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the s… | HIGH | 7.5 | Feb 27, 2018 |
| CVE-2017-5660 | There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when in… | HIGH | 8.6 | Feb 27, 2018 |
| CVE-2017-5659 | Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding. | HIGH | 7.5 | Apr 17, 2017 |
| CVE-2016-5396 | Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack. | HIGH | 7.5 | Apr 17, 2017 |
Showing 76 to 95 of 95 CVEs