cbcvebase.

Apache Traffic Server vulnerabilities

82 known vulnerabilities affecting apache/traffic_server.

Total CVEs
82
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH56MEDIUM14

Vulnerabilities

Page 4 of 5
CVE-2022-47185P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.7≥ 9.0.0, ≤ 9.2.12023-08-09
CVE-2022-47185 [HIGH] CWE-20 CVE-2022-47185: Improper input validation vulnerability on the range header in Apache Software Foundation Apache Tra Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
nvd
CVE-2022-32749P3HIGHCVSS 7.5≥ 8.0.0, < 8.1.6≥ 9.0.0, < 9.1.42022-12-19
CVE-2022-32749 [HIGH] CWE-754 CVE-2022-32749: Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traf Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.
nvd
CVE-2014-3525P3CRITICALCVSS 10.0v2.0.0v2.0.1+32 more2014-08-22
CVE-2014-3525 [CRITICAL] CVE-2014-3525: Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x be Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.
nvd
CVE-2020-9494P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.10+1 more2020-06-24
CVE-2020-9494 [HIGH] CWE-770 CVE-2020-9494: Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain t Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
nvd
CVE-2018-8004P3MEDIUMCVSS 6.5≥ 6.0.0, ≤ 6.2.2≥ 7.0.0, ≤ 7.1.32018-08-29
CVE-2018-8004 [MEDIUM] CWE-444 CVE-2018-8004: There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
nvd
CVE-2024-50305P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.62024-11-14
CVE-2024-50305 [HIGH] CWE-20 CVE-2024-50305: Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affe Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
nvd
CVE-2024-38311P3MEDIUMCVSS 6.3≥ 9.0.0, < 9.2.9≥ 10.0.0, < 10.0.42025-03-06
CVE-2024-38311 [MEDIUM] CWE-20 CVE-2024-38311: Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.
nvd
CVE-2024-56195P3MEDIUMCVSS 6.3≥ 9.0.0, < 9.2.9≥ 10.0.0, < 10.0.42025-03-06
CVE-2024-56195 [MEDIUM] CWE-284 CVE-2024-56195: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.
nvd
CVE-2024-56196P3MEDIUMCVSS 6.3≥ 10.0.0, < 10.0.42025-03-06
CVE-2024-56196 [MEDIUM] CWE-284 CVE-2024-56196: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.
nvd
CVE-2016-5396P3HIGHCVSS 7.5v6.0.0v6.1.0+2 more2017-04-17
CVE-2016-5396 [HIGH] CWE-399 CVE-2016-5396: Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack. Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
nvd
CVE-2017-7671P3HIGHCVSS 7.5≥ 5.2.0, ≤ 5.3.2≤ 6.2.0+1 more2018-02-27
CVE-2017-7671 [HIGH] CWE-20 CVE-2017-7671: There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, a There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.
nvd
CVE-2020-9481P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.9+1 more2020-04-27
CVE-2020-9481 [HIGH] CWE-400 CVE-2020-9481: Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read at Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
nvd
CVE-2018-8040P3MEDIUMCVSS 5.3≥ 6.0.0, ≤ 6.2.2≥ 7.0.0, ≤ 7.1.32018-08-29
CVE-2018-8040 [MEDIUM] CWE-668 CVE-2018-8040: Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versio
nvd
CVE-2017-5659P4HIGHCVSS 7.5≤ 6.2.02017-04-17
CVE-2017-5659 [HIGH] CWE-20 CVE-2017-5659: Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content len Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.
nvd
CVE-2018-8005P4MEDIUMCVSS 5.3≥ 6.0.0, ≤ 6.2.2≥ 7.0.0, ≤ 7.1.32018-08-29
CVE-2018-8005 [MEDIUM] CWE-400 CVE-2018-8005: When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with large objects in cache. This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x users should upgrade to 6.2.3 or later versions and 7.x users should upgr
nvd
CVE-2018-9481P4MEDIUMCVSS 6.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, < 7.1.10+1 more2024-11-20
CVE-2018-9481 [MEDIUM] CWE-190 CVE-2018-9481: In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-40743P4MEDIUMCVSS 6.1≥ 8.0.0, ≤ 8.1.5≥ 9.0.0, ≤ 9.1.32022-12-19
CVE-2022-40743 [MEDIUM] CWE-79 CVE-2022-40743: Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache T Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.
nvd
CVE-2014-10022P4MEDIUMCVSS 5.0≤ 5.1.12015-01-13
CVE-2014-10022 [MEDIUM] CWE-119 CVE-2014-10022: Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecif Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.
nvd
CVE-2022-37392P4MEDIUMCVSS 5.3≥ 8.0.0, < 8.1.6≥ 9.0.0, < 9.1.42022-12-19
CVE-2022-37392 [MEDIUM] CWE-754 CVE-2022-37392: Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apach Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2012-0256P4MEDIUMCVSS 5.0v2.0.0v2.0.1+17 more2012-03-26
CVE-2012-0256 [MEDIUM] CWE-119 CVE-2012-0256: Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
nvd
Apache Traffic Server vulnerabilities | cvebase