Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
akka-http vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2020-28452
This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package com.softwaremill.akka-http-session:core_2.11; the package com.softwaremill.akka-http-session:core_2.13 from 0 and before 0.6.1. CSRF protection can be bypassed...
Softwaremill Akka-http-session
6.4
CVSSv2
CVE-2021-23339
This affects all versions of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers....
Lightbend Akka-http -
5
CVSSv2
CVE-2017-1000118
Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service...
Akka Http Server
7.8
CVSSv2
CVE-2018-16131
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb....
Lightbend Akka Http
6.8
CVSSv2
CVE-2020-7780
This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by...
Softwaremill Akka-http-session
9.3
CVSSv2
CVE-2017-1000034
Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem....
Akka Akka
Akka Akka 2.5
1 Github repository available
6.4
CVSSv2
CVE-2018-16115
Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error. A random number generator is used in Akka Remoting for TLS (both classic and Artery Remoting). Akka allows configuration of custom random number generators. For historical...
Lightbend Akka
6.8
CVSSv2
CVE-2010-0010
Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size...
Apache Http Server 0.8.11
Apache Http Server 0.8.14
Apache Http Server 1.0
Apache Http Server 1.0.3
Apache Http Server 1.0.5
Apache Http Server 1.1
Apache Http Server 1.2
Apache Http Server 1.2.4
Apache Http Server 1.2.5
Apache Http Server 1.2.6
Apache Http Server 1.3
Apache Http Server 1.3.0
Apache Http Server 1.3.1
Apache Http Server 1.3.2
Apache Http Server 1.3.3
Apache Http Server 1.3.4
Apache Http Server 1.3.10
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.13
Apache Http Server 1.3.14
Apache Http Server 1.3.15
Apache Http Server 1.3.17
Apache Http Server 1.3.18
Apache Http Server 1.3.19
Apache Http Server 1.3.20
Apache Http Server 1.3.22
Apache Http Server 1.3.23
Apache Http Server 1.3.24
Apache Http Server 1.3.25
Apache Http Server 1.3.26
Apache Http Server 1.3.27
Apache Http Server 1.3.28
Apache Http Server 1.3.29
Apache Http Server 1.3.30
Apache Http Server 1.3.31
Apache Http Server 1.3.32
Apache Http Server 1.3.33
Apache Http Server 1.3.34
Apache Http Server 1.3.35
Apache Http Server 1.3.36
Apache Http Server 1.3.37
Apache Http Server 1.3.38
Apache Http Server 1.3.39
Apache Http Server 1.3.40
Apache Http Server
4.3
CVSSv2
CVE-2016-4975
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache...
Apache Http Server 2.2.0
Apache Http Server 2.2.2
Apache Http Server 2.2.3
Apache Http Server 2.2.4
Apache Http Server 2.2.6
Apache Http Server 2.2.8
Apache Http Server 2.2.9
Apache Http Server 2.2.10
Apache Http Server 2.2.11
Apache Http Server 2.2.12
Apache Http Server 2.2.13
Apache Http Server 2.2.14
Apache Http Server 2.2.15
Apache Http Server 2.2.16
Apache Http Server 2.2.17
Apache Http Server 2.2.18
Apache Http Server 2.2.19
Apache Http Server 2.2.20
Apache Http Server 2.2.21
Apache Http Server 2.2.22
Apache Http Server 2.2.23
Apache Http Server 2.2.24
Apache Http Server 2.2.25
Apache Http Server 2.2.26
Apache Http Server 2.2.27
Apache Http Server 2.2.29
Apache Http Server 2.2.31
Apache Http Server 2.4.1
Apache Http Server 2.4.2
Apache Http Server 2.4.3
Apache Http Server 2.4.4
Apache Http Server 2.4.6
Apache Http Server 2.4.7
Apache Http Server 2.4.9
Apache Http Server 2.4.10
Apache Http Server 2.4.12
Apache Http Server 2.4.16
Apache Http Server 2.4.17
Apache Http Server 2.4.18
Apache Http Server 2.4.20
Apache Http Server 2.4.23
5
CVSSv2
CVE-2004-0263
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information....
Apache Http Server 1.0
Apache Http Server 1.0.2
Apache Http Server 1.0.3
Apache Http Server 1.0.5
Apache Http Server 1.1
Apache Http Server 1.1.1
Apache Http Server 1.2
Apache Http Server 1.2.5
Apache Http Server 1.3
Apache Http Server 1.3.1
Apache Http Server 1.3.3
Apache Http Server 1.3.4
Apache Http Server 1.3.6
Apache Http Server 1.3.7
Apache Http Server 1.3.9
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.14
Apache Http Server 1.3.17
Apache Http Server 1.3.18
Apache Http Server 1.3.19
Apache Http Server 1.3.20
Apache Http Server 1.3.22
Apache Http Server 1.3.23
Apache Http Server 1.3.24
Apache Http Server 1.3.25
Apache Http Server 1.3.26
Apache Http Server 1.3.27
Apache Http Server 1.3.28
Apache Http Server 1.3.29
Apache Http Server 2.0
Apache Http Server 2.0.9
Apache Http Server 2.0.28
Apache Http Server 2.0.32
Apache Http Server 2.0.35
Apache Http Server 2.0.36
Apache Http Server 2.0.37
Apache Http Server 2.0.38
Apache Http Server 2.0.39
Apache Http Server 2.0.40
Apache Http Server 2.0.41
Apache Http Server 2.0.42
Apache Http Server 2.0.43
Apache Http Server 2.0.44
Apache Http Server 2.0.45
Apache Http Server 2.0.46
Apache Http Server 2.0.47
Apache Http Server 2.0.48
Ibm Http Server 1.3.19
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
unspecified
buffer overflow
CVE-2021-0404
microsoft
race condition
CVE-2021-23965
CVE-2021-21298
CVE-2021-24093
CVE-2021-21724
CVE-2021-25281
.net
1
2
3
4
5
NEXT »