56.705 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Ricerca: proxy
385 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-1999-1293 | HIGH 10.0 | apache http_server mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core. | 4,0% | — |
| CVE-2017-6157 | HIGH 8.1 | f5 big-ip_access_policy_manager In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.5.0 - 11.5.4, virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS prof | 4,0% | — |
| CVE-2011-4968 | MED 4.8 | debian debian_linux nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM) | 4,0% | — |
| CVE-2007-6423 | HIGH 7.8 | apache http_server Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue | 3,9% | — |
| CVE-2007-1196 | HIGH 9.3 | citrix presentation_server_client Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers. | 3,8% | — |
| CVE-2017-0305 | CRIT 9.8 | f5 ssl_intercept_iapp F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deploy | 3,8% | — |
| CVE-2017-5636 | CRIT 9.8 | apache nifi In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a repl | 3,6% | — |
| CVE-2007-4291 | HIGH 7.1 | cisco ios Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service via (1) a malformed MGCP packet, which causes a device hang, aka CSCsf08998; a malformed H.323 packet, which causes a device crash, as identified by (2) CSCsi60004 with Proxy Unre | 3,2% | — |
| CVE-2024-38477 | HIGH 7.5 | apache http_server null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | 3,2% | — |
| CVE-2021-45884 | HIGH 7.5 | brave brave In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additional DNS requests are issued outside of the proxying extension using the system's DNS settings, resulting in infor | 3,1% | — |
| CVE-2009-2057 | MED 5.8 | microsoft ie Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying t | 3,0% | — |
| CVE-2015-1775 | MED 5.5 | apache ambari Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call. | 3,0% | — |
| CVE-2021-29725 | HIGH 7.5 | ibm secure_external_authentication_server IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. | 2,9% | — |
| CVE-2019-1687 | HIGH 7.5 | cisco adaptive_security_appliance_software A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a de | 2,9% | — |
| CVE-2020-10110 | MED 5.3 | citrix gateway_firmware Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and | 2,7% | — |
| CVE-2023-46589 | HIGH 7.5 | apache tomcat Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that ex | 2,7% | — |
| CVE-2011-0395 | HIGH 7.8 | cisco adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.20), 8.1 before 8.1(2.48), 8.2 before 8.2(3), and 8.3 before 8.3(2.1), when the RIP protocol and the Cisco Phone Proxy functionality are configured, allow remote attack | 2,6% | — |
| CVE-2018-5527 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled can force the Traffic Management Microkernel (tmm) to leak memory. | 2,6% | — |
| CVE-2009-2863 | HIGH 7.1 | cisco ios Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227. | 2,5% | — |
| CVE-2018-11764 | HIGH 8.8 | apache hadoop Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured. | 2,4% | — |
| CVE-2013-4686 | HIGH 7.1 | juniper junos The kernel in Juniper Junos 10.4 before 10.4R14, 11.4 before 11.4R8, 11.4X27 before 11.4X27.43, 12.1 before 12.1R6, 12.1X44 before 12.1X44-D20, 12.2 before 12.2R4, and 12.3 before 12.3R2, in certain VLAN configurations with unrestricted arp-resp and proxy-arp | 2,3% | — |
| CVE-2012-0335 | MED 5.0 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut through a firewall, which allows remote attackers to obtain sensitive information via a connection at | 2,2% | — |
| CVE-2016-1000104 | HIGH 8.8 | apache mod_fcgid A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. | 2,2% | — |
| CVE-2023-33141 | HIGH 7.5 | microsoft yet_another_reverse_proxy Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability | 2,2% | — |
| CVE-2018-0007 | CRIT 9.8 | juniper junos An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may be able to cause a Junos device to enter an improper boundary check condition allowing a memory corruption to | 2,2% | — |