← Back

Traffic Server

traffic_server

Vendor: Apache • 82 CVEs

CVEs (82)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Traffic Server
Apr 29, 2026
Mar 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
1Apache
1Traffic Server
Apr 29, 2026
Sep 13, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier...Show more
Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.Show less