Skip to main content

Vendor archive

trustwave CVEs

Beta · best-effort

18 CVEs tagged to vendor trustwave2 Critical, 7 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2025-47947

Published May 21, 2025

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of servi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27110

Published Feb 25, 2025

Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46292

Published Oct 9, 2024

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Su…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2727

Published Feb 19, 2020

The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18001

Published Dec 31, 2017

Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain re…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-5705

Published Apr 15, 2014

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encodin…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5031

Published Jul 22, 2012

ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1906

Published May 5, 2011

Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0756

Published May 5, 2011

The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by u…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1903

Published Jun 3, 2009

The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1