Search CVE reports
301 – 310 of 44358 results
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |
The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are...
1 affected package
trafficserver
| Package | 20.04 LTS |
|---|---|
| trafficserver | Needs evaluation |