Vulnerabilities > Modsecurity

DATE CVE VULNERABILITY TITLE RISK
2019-07-09 CVE-2019-13464 Unrestricted Upload of File with Dangerous Type vulnerability in Modsecurity Owasp Modsecurity Core Rule SET 3.0.2
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2.
network
low complexity
modsecurity CWE-434
5.0
2019-04-21 CVE-2019-11391 Resource Exhaustion vulnerability in Modsecurity Owasp Modsecurity Core Rule SET 3.0.0/3.0.2/3.1.0
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0.
network
low complexity
modsecurity CWE-400
5.3
2019-04-21 CVE-2019-11390 Resource Exhaustion vulnerability in Modsecurity Owasp Modsecurity Core Rule SET 3.0.0/3.0.2/3.1.0
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0.
network
low complexity
modsecurity CWE-400
5.3
2019-04-21 CVE-2019-11389 Resource Exhaustion vulnerability in Modsecurity Owasp Modsecurity Core Rule SET 3.0.0/3.0.2/3.1.0
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0.
network
low complexity
modsecurity CWE-400
5.3
2019-04-21 CVE-2019-11388 Resource Exhaustion vulnerability in Modsecurity Owasp Modsecurity Core Rule SET 3.0.0/3.0.2/3.1.0
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0.
network
low complexity
modsecurity CWE-400
5.3
2019-04-21 CVE-2019-11387 Resource Exhaustion vulnerability in Modsecurity Owasp Modsecurity Core Rule SET 3.0.0/3.0.2/3.1.0
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0.
4.3
2013-07-15 CVE-2013-2765 Null Pointer Dereference vulnerability in multiple products
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
network
low complexity
modsecurity opensuse CWE-476
5.0