Skip to main content

Vendor archive

haproxy CVEs

Beta · best-effort

35 CVEs tagged to vendor haproxy3 Critical, 21 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2018-11469

Published May 25, 2018

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure v…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10184

Published May 9, 2018

An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked against the bufsize. The max_…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2102

Published Aug 22, 2017

HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5360

Published Jun 30, 2016

HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have un…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3281

Published Jul 6, 2015

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attacker…

CVSS 5.0 · Medium

CVE-2014-6269

Published Sep 30, 2014

Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1912

Published Apr 10, 2013

Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2942

Published May 27, 2012

Buffer overflow in the trash buffer in the header capture functionality in HAProxy before 1.4.21, when global.tune.bufsize is set to a value greater than the default and header re…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-35 of 35 CVEsPage 2 of 2