Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Traffic Server
Total 65 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-5659 1 Apache 1 Traffic Server 2023-12-10 5.0 MEDIUM 7.5 HIGH
Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.
CVE-2014-3525 1 Apache 1 Traffic Server 2023-12-10 10.0 HIGH N/A
Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.
CVE-2014-10022 1 Apache 1 Traffic Server 2023-12-10 5.0 MEDIUM N/A
Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.
CVE-2012-0256 1 Apache 1 Traffic Server 2023-12-10 5.0 MEDIUM N/A
Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
CVE-2010-2952 1 Apache 1 Traffic Server 2023-12-10 4.3 MEDIUM N/A
Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.