Skip to main content

CWE archive

CWE-444 CVEs

Programmatic archive

354 CVEs tagged with CWE-44464 Critical, 125 High, 149 Medium, 16 Low, 0 Unrated.

CVE-2020-28361

Published Nov 18, 2020

Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allows a bypass of a header-removal protection mechanism via whi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7764

Published Nov 8, 2020

This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11993

Published Aug 7, 2020

Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong con…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-19326

Published Jul 15, 2020

Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through m…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15049

Published Jun 30, 2020

An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache.…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-20866

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address in an IP packet header, for obtaining IP address information…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21245

Published Jun 15, 2020

Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7671

Published Jun 10, 2020

goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7670

Published Jun 10, 2020

agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. HTTP pipelining issues and request smuggling atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7659

Published Jun 1, 2020

reel through 0.6.1 allows Request Smuggling attacks due to incorrect Content-Length and Transfer encoding header parsing. It is possible to conduct HTTP request smuggling attacks…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10719

Published May 26, 2020

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advanta…

CVSS 6.5 · Medium

CVE-2020-7658

Published May 22, 2020

meinheld prior to 1.0.2 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfe…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7655

Published May 21, 2020

netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Transfer encoding header p…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11506

Published Apr 22, 2020

An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11505

Published Apr 22, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7611

Published Mar 30, 2020

All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating req…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 276-300 of 354 CVEsPage 12 of 15