Trustwave / Modsecurity
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-47947 | ModSecurity Has Possible DoS Vulnerability | HIGH | 7.5 | May 21, 2025 |
| CVE-2025-27110 | Libmodsecurity3 has possible bypass of encoded HTML entities | HIGH | 7.9 | Feb 25, 2025 |
| CVE-2024-46292 | mod_security: denial of service via name paramter | HIGH | 7.5 | Oct 9, 2024 |
| CVE-2023-24021 | modsecurity: lacking the complete content in FILES_TMP_CONTENT leads to web application firewall bypass | HIGH | 7.5 | Jan 20, 2023 |
| CVE-2022-48279 | mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass | HIGH | 7.5 | Jan 20, 2023 |
| CVE-2021-42717 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web serv… | HIGH | 7.5 | Dec 7, 2021 |
| CVE-2013-5705 | mod_security: bypass of intended rules via chunked requests | MEDIUM | 5.0 | Apr 15, 2014 |
| CVE-2013-2765 | The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, a… | MEDIUM | 5.0 | Jul 15, 2013 |
| CVE-2013-1915 | ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory… | HIGH | 7.5 | Apr 25, 2013 |
| CVE-2012-4528 | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application,… | MEDIUM | 5.0 | Dec 28, 2012 |
| CVE-2012-2751 | ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Dispositi… | MEDIUM | 4.3 | Jul 22, 2012 |
| CVE-2009-5031 | ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perfor… | MEDIUM | 4.3 | Jul 22, 2012 |
| CVE-2009-1903 | The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF fi… | MEDIUM | 4.3 | Jun 3, 2009 |
| CVE-2009-1902 | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a m… | MEDIUM | 5.0 | Jun 3, 2009 |
Showing 1 to 14 of 14 CVEs