Search CVE reports


Toggle filters

11 – 20 of 21 results


CVE-2020-11653

Low priority

Some fixes available 1 of 2

An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Fixed Not affected
Show less packages

CVE-2019-20637

Medium priority

Some fixes available 2 of 3

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Fixed Fixed
Show less packages

CVE-2019-15892

Medium priority
Ignored

An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Not affected
Show less packages

CVE-2017-8807

Low priority

Some fixes available 1 of 3

vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Not affected Not affected
Show less packages

CVE-2017-12425

Medium priority
Fixed

An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish
Show less packages

CVE-2015-8852

Medium priority

Some fixes available 1 of 2

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return)...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish
Show less packages

CVE-2013-4484

Medium priority
Ignored

Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI.

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish
Show less packages

CVE-2013-4090

Medium priority
Not affected

Varnish HTTP cache before 3.0.4: ACL bug

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected
Show less packages

CVE-2013-0345

Medium priority
Ignored

varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ directory and the log files in the directory, which allows local users to obtain sensitive information by reading the files. NOTE: some of these details are...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish
Show less packages

CVE-2009-4488

Negligible priority
Ignored

Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish
Show less packages