45.60.14.1

Regular View Raw Data
Last Seen: 2024-04-25
Tags:
cdn

GeneralInformation

Hostnames assurance-cliniques.fr
assuranceauto-titulaire.com
www.assuranceauto-titulaire.com
assuranceauto-titulaire.fr
www.assuranceauto-titulaire.fr
districover.fr
garanties-en-or.com
www.garanties-en-or.com
garanties-en-or.fr
www.garanties-en-or.fr
garanties-or.fr
www.garanties-or.fr
garanties-pannemecanique.com
www.garanties-pannemecanique.com
garanties-pannemecanique.fr
www.garanties-pannemecanique.fr
garanties-top.com
www.garanties-top.com
garantiespannemecanique.com
www.garantiespannemecanique.com
garantip-top.com
www.garantip-top.com
garantip-top.fr
www.garantip-top.fr
garantiptop.com
www.garantiptop.com
grassavoye-montagne.com
www.grassavoye-montagne.com
grassavoye-yachting.com
int.grassavoye-yachting.com
rct.grassavoye-yachting.com
www.grassavoye-yachting.com
extranet-adp.grassavoye.com
gsmart.grassavoye.com
particuliers.grassavoye.fr
grassavoye.hr
www.grassavoye.hr
gsc-nsa.com
www.gsc-nsa.com
gsc-nsa.fr
www.gsc-nsa.fr
gsnsa.com
www.gsnsa.com
imperva.com
jerouletranquille.com
www.jerouletranquille.com
jerouletranquille.fr
www.jerouletranquille.fr
locassist.fr
www.locassist.fr
maprotectionauto.fr
www.maprotectionauto.fr
monreflexesante.com
www.monreflexesante.com
myacquire.co.uk
mypensiontools.co.uk
test.mypensiontools.co.uk
www.mypensiontools.co.uk
nsa-garanties.com
www.nsa-garanties.com
nsa-gsc.com
bosch.nsa-gsc.com
club.nsa-gsc.com
drom.nsa-gsc.com
espaceclient.nsa-gsc.com
factures.nsa-gsc.com
garanties.nsa-gsc.com
nsa.nsa-gsc.com
portugal.nsa-gsc.com
stat.nsa-gsc.com
www.nsa-gsc.com
nsa-portugal.com
www.nsa-portugal.com
temeris.fr
trusteeprinciples.ie
www.trusteeprinciples.ie
willis-online.de
www.willis-online.de
willis.com.ar
aena.willis.es
cmaservices.willis.es
cotizadorvida.willis.es
michelin.willis.es
pwc.willis.es
swissport.willis.es
willcred.willis.es
willflex.willis.es
willview.willis.es
willviewdemo.willis.es
willisautocare.es
www.willisautocare.es
willispersonallines.com
www.willispersonallines.com
benefitsbroker.willistowerswatson.com
dcobs.willistowerswatson.com
mybenflexdemo-cat.willistowerswatson.com
willplatine.net
witiwi.fr
wtw-healthandbenefits.co.uk
www.wtw-healthandbenefits.co.uk
wtwbrandcentral.com
www.wtwbrandcentral.com
benefits4u.wtwindiainsurancebrokers.com
cardclaims.wtwindiainsurancebrokers.com
claims.wtwindiainsurancebrokers.com
enrolmentapi.wtwindiainsurancebrokers.com
lsm.wtwindiainsurancebrokers.com
wtwnetworks.com
Domains assurance-cliniques.fr assuranceauto-titulaire.com assuranceauto-titulaire.fr districover.fr garanties-en-or.com garanties-en-or.fr garanties-or.fr garanties-pannemecanique.com garanties-pannemecanique.fr garanties-top.com garantiespannemecanique.com garantip-top.com garantip-top.fr garantiptop.com grassavoye-montagne.com grassavoye-yachting.com grassavoye.com grassavoye.fr grassavoye.hr gsc-nsa.com gsc-nsa.fr gsnsa.com imperva.com jerouletranquille.com jerouletranquille.fr locassist.fr maprotectionauto.fr monreflexesante.com myacquire.co.uk mypensiontools.co.uk nsa-garanties.com nsa-gsc.com nsa-portugal.com temeris.fr trusteeprinciples.ie willis-online.de willis.com.ar willis.es willisautocare.es willispersonallines.com willistowerswatson.com willplatine.net witiwi.fr wtw-healthandbenefits.co.uk wtwbrandcentral.com wtwindiainsurancebrokers.com wtwnetworks.com 
Country United States
City Redwood City
Organization Incapsula Inc
ISP Incapsula Inc
ASN AS19551

Vulnerabilities

Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.

CVE-2023-45802 When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close, all resources were reclaimed, but the process might run out of memory before that. This was found by the reporter during testing of CVE-2023-44487 (HTTP/2 Rapid Reset Exploit) with their own test client. During "normal" HTTP/2 use, the probability to hit this bug is very low. The kept memory would not become noticeable before the connection closes or times out. Users are recommended to upgrade to version 2.4.58, which fixes the issue.
CVE-2023-31122 Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
CVE-2023-25690 Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For example, something like: RewriteEngine on RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P] ProxyPassReverse /here/ http://example.com:8080/ Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.
CVE-2022-37436 Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
CVE-2022-36760 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.
CVE-2022-31813 7.5Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
CVE-2022-30556 5.0Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
CVE-2022-29404 5.0In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.
CVE-2022-28615 6.4Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.
CVE-2022-28614 5.0The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'ap_rputs' function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue.
CVE-2022-28330 5.0Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
CVE-2022-26377 5.0Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
CVE-2022-23943 7.5Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
CVE-2022-22721 5.8If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
CVE-2022-22720 7.5Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
CVE-2022-22719 5.0A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
CVE-2021-44790 7.5A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
CVE-2021-44224 6.4A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
CVE-2021-40438 6.8A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-39275 7.5ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-34798 5.0Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-33193 5.0A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
CVE-2021-32792 4.3mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using `OIDCPreservePost On`.
CVE-2021-32791 4.3mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encryption in mod_auth_openidc uses a static IV and AAD. It is important to fix because this creates a static nonce and since aes-gcm is a stream cipher, this can lead to known cryptographic issues, since the same key is being reused. From 2.4.9 onwards this has been patched to use dynamic values through usage of cjose AES encryption routines.
CVE-2021-32786 5.8mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs the same way as most browsers do. As a result, this function can be bypassed and leads to an Open Redirect vulnerability in the logout functionality. This bug has been fixed in version 2.4.9 by replacing any backslash of the URL to redirect with slashes to address a particular breaking change between the different specifications (RFC2396 / RFC3986 and WHATWG). As a workaround, this vulnerability can be mitigated by configuring `mod_auth_openidc` to only allow redirection whose destination matches a given regular expression.
CVE-2021-32785 4.3mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured to use an unencrypted Redis cache (`OIDCCacheEncrypt off`, `OIDCSessionType server-cache`, `OIDCCacheType redis`), `mod_auth_openidc` wrongly performed argument interpolation before passing Redis requests to `hiredis`, which would perform it again and lead to an uncontrolled format string bug. Initial assessment shows that this bug does not appear to allow gaining arbitrary code execution, but can reliably provoke a denial of service by repeatedly crashing the Apache workers. This bug has been corrected in version 2.4.9 by performing argument interpolation only once, using the `hiredis` API. As a workaround, this vulnerability can be mitigated by setting `OIDCCacheEncrypt` to `on`, as cache keys are cryptographically hashed before use when this option is enabled.
CVE-2021-26691 7.5In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
CVE-2021-26690 5.0Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service
CVE-2020-9490 5.0Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
CVE-2020-35452 6.8Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
CVE-2020-1934 5.0In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
CVE-2020-1927 5.8In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
CVE-2020-13938 2.1Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
CVE-2020-11993 4.3Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
CVE-2019-9517 7.8Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.
CVE-2019-17567 5.0Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
CVE-2019-10098 5.8In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.
CVE-2019-10092 4.3In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
CVE-2019-10082 6.4In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.
CVE-2019-10081 5.0HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
CVE-2019-0220 5.0A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.
CVE-2019-0217 6.0In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
CVE-2019-0211 7.2In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
CVE-2019-0196 5.0A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.
CVE-2018-17199 5.0In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.
CVE-2018-17189 5.0In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.
CVE-2018-1333 5.0By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
CVE-2018-1312 6.8In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
CVE-2018-1303 5.0A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_disk is not concerned by this vulnerability.
CVE-2018-1302 4.3When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.
CVE-2018-1301 4.3A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.
CVE-2018-1283 3.5In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the Apache HTTP Server to pass HTTP header fields, per CGI specifications.
CVE-2018-11763 4.3In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
CVE-2017-15715 6.8In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.
CVE-2017-15710 5.0In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example, 'en-US' is truncated to 'en'). A header value of less than two characters forces an out of bound write of one NUL byte to a memory location that is not part of the string. In the worst case, quite unlikely, the process would crash which could be used as a Denial of Service attack. In the more likely case, this memory is already reserved for future use and the issue has no effect at all.
CVE-2013-4365 7.5Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.
CVE-2013-2765 5.0The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
CVE-2013-0942 4.3Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-0941 2.1EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
CVE-2012-4360 4.3Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2012-4001 5.0The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.
CVE-2012-3526 5.0The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.
CVE-2011-2688 7.5SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
CVE-2011-1176 4.3The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
CVE-2009-2299 5.0The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.
CVE-2009-0796 2.6Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.
CVE-2007-4723 7.5Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
CVE-2006-20001 A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.
-2093156931 | 2024-04-18T23:55:44.611887
  
25 / tcp
1771575257 | 2024-04-19T18:40:40.844220
  
43 / tcp
-1693655905 | 2024-04-25T00:13:43.274670
  
80 / tcp
-1795488266 | 2024-04-23T05:19:53.782617
  
81 / tcp
-1171833262 | 2024-04-22T03:27:13.279684
  
82 / tcp
1924251052 | 2024-04-20T06:32:36.328203
  
83 / tcp
1677146003 | 2024-04-13T01:23:03.502039
  
84 / tcp
353398977 | 2024-04-20T09:58:26.879048
  
88 / tcp
308005696 | 2024-04-10T20:51:25.464878
  
389 / tcp
-1693655905 | 2024-04-25T17:27:07.228570
  
443 / tcp
111923240 | 2024-04-19T15:13:26.340151
  
444 / tcp
-331810113 | 2024-04-10T07:40:56.541639
  
465 / tcp
-586239866 | 2024-04-20T18:36:53.808620
  
554 / tcp
-699968005 | 2024-04-21T22:58:33.767731
  
587 / tcp
-1755819616 | 2024-04-22T05:58:14.011488
  
631 / tcp
-555376046 | 2024-04-12T03:24:24.230464
  
636 / tcp
-825738567 | 2024-04-23T01:13:40.552715
  
1024 / tcp
-352359561 | 2024-04-13T18:07:47.709972
  
1177 / tcp
-1766118545 | 2024-04-23T20:39:39.954598
  
1234 / tcp
887423418 | 2024-04-24T02:07:46.439871
  
1337 / tcp
766229962 | 2024-04-22T17:45:42.569724
  
1400 / tcp
1762516980 | 2024-04-18T20:14:30.795638
  
1433 / tcp
-72940978 | 2024-04-24T00:05:05.896180
  
1521 / tcp
-1159873608 | 2024-04-04T03:05:09.350369
  
1935 / tcp
-1177005144 | 2024-04-23T07:31:48.997794
  
2000 / tcp
162995522 | 2024-04-18T17:01:07.505690
  
2082 / tcp
1366108056 | 2024-04-24T11:14:28.226027
  
2083 / tcp
585721043 | 2024-04-17T03:19:23.579674
  
2086 / tcp
-512226431 | 2024-04-21T03:24:16.281853
  
2222 / tcp
68752080 | 2024-04-23T03:57:37.921433
  
2345 / tcp
19296869 | 2024-04-20T22:00:28.294814
  
2375 / tcp
-475917560 | 2024-04-24T01:36:51.520741
  
2376 / tcp
1834935251 | 2024-04-21T20:16:41.179962
  
2404 / tcp
1731526872 | 2024-04-01T16:17:39.565611
  
2480 / tcp
-581521059 | 2024-04-21T04:10:54.760084
  
2628 / tcp
523057393 | 2024-04-23T22:44:29.629057
  
2761 / tcp
-1763052809 | 2024-04-14T06:57:46.197801
  
2762 / tcp
1081220183 | 2024-04-12T02:51:13.387392
  
3000 / tcp
-298522230 | 2024-04-25T03:24:20.725280
  
3001 / tcp
1839396302 | 2024-04-09T14:20:49.151532
  
3050 / tcp
1620543855 | 2024-04-22T05:49:02.921316
  
3268 / tcp
1394780664 | 2024-04-25T11:03:54.812345
  
3269 / tcp
-1457358908 | 2024-04-17T01:47:10.962487
  
3299 / tcp
522279934 | 2024-04-16T07:41:16.390507
  
3389 / tcp
-769001314 | 2024-04-05T08:29:07.547352
  
3790 / tcp
448827670 | 2024-04-25T19:07:22.435503
  
4000 / tcp
1779496720 | 2024-04-23T06:18:34.264308
  
4022 / tcp
86740853 | 2024-03-30T11:53:36.509727
  
4040 / tcp
0 | 2024-04-03T22:47:12.916597
  
4064 / tcp
-1756131656 | 2024-04-14T21:55:17.488786
  
4443 / tcp
1022144060 | 2024-04-17T18:52:34.050802
  
4444 / tcp
294102026 | 2024-04-05T09:19:28.036462
  
4567 / tcp
607973063 | 2024-04-18T02:24:07.388447
  
4848 / tcp
1978440992 | 2024-04-16T11:05:07.348109
  
4911 / tcp
1948933787 | 2024-04-19T11:45:15.478990
  
5000 / tcp
-1762756149 | 2024-04-19T06:24:08.057005
  
5001 / tcp
-538687225 | 2024-04-23T21:07:09.442538
  
5005 / tcp
1806531263 | 2024-04-08T08:34:03.061732
  
5006 / tcp
-23346447 | 2024-04-20T06:09:43.022678
  
5007 / tcp
-1640826441 | 2024-04-23T14:55:27.835087
  
5009 / tcp
423691746 | 2024-04-25T01:18:35.083509
  
5010 / tcp
-177058778 | 2024-04-19T01:00:19.955545
  
5201 / tcp
-13798855 | 2024-04-18T12:46:13.653308
  
5222 / tcp
1355655345 | 2024-04-24T23:26:17.382615
  
5555 / tcp
-2125765555 | 2024-04-25T17:15:24.998674
  
5560 / tcp
327985493 | 2024-04-21T17:29:16.908763
  
5601 / tcp
563756331 | 2024-04-10T13:15:29.301386
  
5672 / tcp
1211885467 | 2024-04-05T08:28:07.630451
  
5900 / tcp
1770113720 | 2024-04-04T17:03:47.203666
  
5985 / tcp
-1850166948 | 2024-04-20T20:08:15.961349
  
5986 / tcp
-113918633 | 2024-04-16T12:37:05.085790
  
6000 / tcp
231249070 | 2024-04-17T07:57:54.937596
  
6001 / tcp
217822435 | 2024-04-10T02:40:58.025170
  
6080 / tcp
1356048911 | 2024-04-10T09:50:59.276111
  
6443 / tcp
-1628182661 | 2024-04-11T05:10:22.553097
  
7001 / tcp
1513729351 | 2024-04-17T15:54:21.876753
  
7071 / tcp
2001633342 | 2024-04-21T20:53:46.926105
  
7171 / tcp
1648863231 | 2024-04-24T06:11:53.182134
  
7443 / tcp
1212518490 | 2024-04-15T10:16:56.415440
  
7474 / tcp
93739692 | 2024-04-22T04:02:17.058792
  
7547 / tcp
1721071207 | 2024-04-25T07:50:11.757733
  
7548 / tcp
432601589 | 2024-04-21T13:44:24.633112
  
7777 / tcp
1723738841 | 2024-04-10T00:10:35.194236
  
7779 / tcp
-1721520675 | 2024-04-25T10:37:48.770125
  
8000 / tcp
1459943853 | 2024-04-17T10:22:42.193392
  
8001 / tcp
610854839 | 2024-04-21T03:23:51.132591
  
8008 / tcp
948285469 | 2024-04-05T14:01:21.243001
  
8009 / tcp
1047731667 | 2024-04-21T11:45:01.026770
  
8010 / tcp
-1554982625 | 2024-04-21T20:36:47.072709
  
8060 / tcp
-31799983 | 2024-04-14T23:28:08.398533
  
8069 / tcp
165685652 | 2024-04-25T06:18:50.429653
  
8080 / tcp
-1539296416 | 2024-04-21T22:12:04.963614
  
8081 / tcp
-1263133618 | 2024-04-19T02:03:08.973229
  
8083 / tcp
1001460249 | 2024-04-20T03:34:39.984217
  
8085 / tcp
930479524 | 2024-04-21T02:21:27.733755
  
8086 / tcp
113296599 | 2024-04-20T12:15:09.820657
  
8089 / tcp
1189793803 | 2024-04-25T02:14:58.637845
  
8090 / tcp
175220277 | 2024-04-23T16:54:15.287376
  
8098 / tcp
-574249848 | 2024-04-21T07:32:54.750074
  
8112 / tcp
-492734715 | 2024-04-22T05:29:07.274137
  
8123 / tcp
-1843666523 | 2024-04-18T06:56:45.427659
  
8126 / tcp
189905119 | 2024-04-23T22:35:16.372543
  
8139 / tcp
-1203326789 | 2024-04-10T13:22:40.416416
  
8140 / tcp
422634456 | 2024-04-23T08:56:03.198704
  
8200 / tcp
-811665466 | 2024-04-24T23:54:50.561538
  
8443 / tcp
1029011066 | 2024-04-02T00:01:09.587205
  
8800 / tcp
-316630925 | 2024-04-21T18:02:40.993377
  
8834 / tcp
-1621781132 | 2024-04-17T14:30:46.832862
  
8888 / tcp
559746457 | 2024-04-24T01:35:11.195284
  
8889 / tcp
-1610929557 | 2024-04-24T22:02:43.468643
  
9000 / tcp
-39979236 | 2024-04-21T06:30:48.742289
  
9001 / tcp
922568027 | 2024-04-17T03:46:53.516808
  
9002 / tcp
1388656873 | 2024-04-16T20:11:39.955258
  
9009 / tcp
449798049 | 2024-04-25T04:04:50.462045
  
9080 / tcp
2052608018 | 2024-04-05T11:52:41.193078
  
9090 / tcp
-374790731 | 2024-04-25T11:41:27.650803
  
9091 / tcp
-1669259265 | 2024-04-19T19:46:45.889029
  
9095 / tcp
-491581985 | 2024-04-25T18:09:19.131824
  
9100 / tcp
-1669992727 | 2024-04-23T10:51:38.043593
  
9200 / tcp
-1110219693 | 2024-04-04T20:24:55.628014
  
9306 / tcp
-2022898999 | 2024-04-21T19:02:42.134786
  
9443 / tcp
-1039147114 | 2024-04-17T12:30:16.879415
  
9943 / tcp
1001012969 | 2024-04-13T18:05:00.403269
  
9998 / tcp
-1011738117 | 2024-04-22T00:50:25.727507
  
9999 / tcp
1922799251 | 2024-04-15T20:13:14.530043
  
10000 / tcp
744982792 | 2024-04-19T07:11:10.830388
  
10001 / tcp
-2067028711 | 2024-04-22T03:07:25.544626
  
10134 / tcp
-668022742 | 2024-04-19T06:17:24.163809
  
10443 / tcp
-582751806 | 2024-04-21T22:01:42.160401
  
12345 / tcp
-793655477 | 2024-04-23T17:10:51.677975
  
13579 / tcp
-54081746 | 2024-04-25T17:42:39.036309
  
14265 / tcp
-1934238323 | 2024-04-25T13:17:23.514280
  
16010 / tcp
374533492 | 2024-04-03T07:06:25.541401
  
16030 / tcp
-1605189174 | 2024-04-10T12:17:08.993171
  
20000 / tcp
-730024178 | 2024-04-22T17:02:31.120914
  
31337 / tcp
-149440159 | 2024-04-25T08:53:07.432514
  
50000 / tcp
-769368833 | 2024-04-12T15:45:56.662821
  
55000 / tcp
737868495 | 2024-04-25T05:25:12.092027
  
55443 / tcp
1625947710 | 2024-04-24T02:03:29.858078
  
60001 / tcp



Contact Us

Shodan ® - All rights reserved