4.3
CVSSv2

CVE-2005-3751

Published: 22/11/2005 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

HTTP request smuggling vulnerability in Pound prior to 1.9.4 allows remote malicious users to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apsis pound

Vendor Advisories

Debian Bug report logs - #888786 pound: CVE-2016-10711 Package: src:pound; Maintainer for src:pound is Carsten Leonhardt <leo@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 29 Jan 2018 22:00:02 UTC Severity: important Tags: patch, security, upstream Found in version pound/26-6 Fixed i ...
Two vulnerabilities have been discovered in Pound, a reverse proxy and load balancer for HTTP The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-1391: Overly long HTTP Host: headers may trigger a buffer overflow in the add_port() function, which may lead to the execution of arbitrary code ...