Trustwave
trustwave
18 CVEs • 4 products
Products (4)
Click to collapseToggle
Products (4)
Click to collapse
CVEs (18)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable release...Show more |
Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exist...Show more |
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. A...Show more |
2Debian Trustwave2Debian Linux ModsecurityJun 17, 2026 Jan 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_...Show more |
3Debian OwaspTrustwave3Debian Linux ModsecurityModsecurityJun 17, 2026 Jan 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent c...Show more |
5Debian F5Oracle+2 more6Debian Linux Http ServerModsecurity+3 moreJun 17, 2026 Dec 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a modera...Show more |
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection. |
1Trustwave 1Secure Web Gateway May 13, 2026 Dec 31, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey param...Show more |
2Debian Trustwave2Debian Linux ModsecurityMay 6, 2026 Apr 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header. |
2Opensuse Trustwave2Modsecurity OpensuseApr 29, 2026 Jul 15, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraModsecurity+1 moreApr 29, 2026 Apr 25, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjun...Show more |
3Fedoraproject OpensuseTrustwave3Fedora ModsecurityOpensuseApr 29, 2026 Dec 28, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes th...Show more |
4Debian OpensuseOracle+1 more4Debian Linux Http ServerModsecurity+1 moreApr 29, 2026 Jul 22, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type...Show more |
2Opensuse Trustwave2Modsecurity OpensuseApr 29, 2026 Jul 22, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks vi...Show more |
Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event collection table via requests to the manag...Show more |
The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote console GUI to connect to...Show more |
2Fedoraproject Trustwave2Fedora ModsecurityApr 23, 2026 Jun 3, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method. |
2Fedoraproject Trustwave2Fedora ModsecurityApr 23, 2026 Jun 3, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer derefe...Show more |