Varnish.Projects.Linpro Varnish vulnerabilities
2 known vulnerabilities affecting varnish.projects.linpro/varnish.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2009-2936HIGHCVSS 7.5PoCv0.9v0.9.1+15 more2010-04-05
CVE-2009-2936 [HIGH] CWE-287 CVE-2009-2936: The Command Line Interface (aka Server CLI or administration interface) in the master process in the
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containin
nvd
CVE-2009-4488CRITICALCVSS 9.8PoCv2.0.62010-01-13
CVE-2009-4488 [CRITICAL] CWE-20 CVE-2009-4488: Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might all
Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. NOTE: the vendor disputes the significance of this report, stating tha
nvd