Skip to main content

Vendor/product archive

oracle / instantis_enterprisetrack CVEs

Beta · best-effort

52 CVEs tagged to oracle / instantis_enterprisetrack10 Critical, 28 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2021-44790

Published Dec 20, 2021

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an expl…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2021-44224

Published Dec 20, 2021

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy d…

CVSS 8.2 · High
evidence mentions
2
Buzz score
17.5

CVE-2021-42013

Published Oct 7, 2021

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the director…

CVSS 9.8 · Critical
evidence mentions
19
Buzz score
79.0
KEV listedPublic PoC observed

CVE-2021-39275

Published Sep 16, 2021

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 52 CVEsPage 1 of 3