<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 09:08:00 +0000</lastBuildDate>
    <item>
      <title>CVE-2017-15715</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2017-15715</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache HTTP Server&lt;/p&gt;
&lt;p&gt;In Apache httpd 2.4.0 to 2.4.29, the expression specified in &amp;lt;FilesMatch&amp;gt; could match &amp;#39;$&amp;#39; to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache HTTP Server&lt;/p&gt;
&lt;p&gt;In Apache httpd 2.4.0 to 2.4.29, the expression specified in &amp;lt;FilesMatch&amp;gt; could match &amp;#39;$&amp;#39; to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2017-15715</guid>
    </item>
    <item>
      <title>USN-3627-1 — apache2 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-3627-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: apache2, Ubuntu:16.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Alex Nichols and Jakob Hirsch discovered that the Apache HTTP Server
mod_authnz_ldap module incorrectly handled missing charset encoding
headers. A remote attacker could possibly use this issue to cause the
server to crash, resulting in a denial of service. (CVE-2017-15710)&lt;/p&gt;
&lt;p&gt;Elar Lang discovered that the Apache HTTP Server incorrectly handled
certain characters specified in &amp;lt;FilesMatch&amp;gt;. A remote attacker could
possibly use this issue to upload certain files, contrary to expectations.
(CVE-2017-15715)&lt;/p&gt;
&lt;p&gt;It was discovered that the Apache HTTP Server mod_session module
incorrectly handled certain headers. A remote attacker could possibly use
this issue to influence session data. (CVE-2018-1283)&lt;/p&gt;
&lt;p&gt;Robert Swiecki discovered that the Apache HTTP Server incorrectly handled
certain requests. A remote attacker could possibly use this issue to cause
the server to crash, leading to a denial of service. (CVE-2018-1301)&lt;/p&gt;
&lt;p&gt;Robert Swiecki discovered that the Apache HTTP Server mod_cache_socache
module incorrectly handled certain headers. A remote attacker could
possibly use this issue to cause the server to crash, leading to a denial
of service. (CVE-2018-1303)&lt;/p&gt;
&lt;p&gt;Nicolas Daniels discovered that the Apache HTTP Server incorrectly
generated the nonce when creating HTTP Digest authentication challenges.
A remote attacker could possibly use this issue to replay HTTP requests
across a cluster of servers. (CVE-2018-1312)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: apache2, Ubuntu:16.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Alex Nichols and Jakob Hirsch discovered that the Apache HTTP Server
mod_authnz_ldap module incorrectly handled missing charset encoding
headers. A remote attacker could possibly use this issue to cause the
server to crash, resulting in a denial of service. (CVE-2017-15710)&lt;/p&gt;
&lt;p&gt;Elar Lang discovered that the Apache HTTP Server incorrectly handled
certain characters specified in &amp;lt;FilesMatch&amp;gt;. A remote attacker could
possibly use this issue to upload certain files, contrary to expectations.
(CVE-2017-15715)&lt;/p&gt;
&lt;p&gt;It was discovered that the Apache HTTP Server mod_session module
incorrectly handled certain headers. A remote attacker could possibly use
this issue to influence session data. (CVE-2018-1283)&lt;/p&gt;
&lt;p&gt;Robert Swiecki discovered that the Apache HTTP Server incorrectly handled
certain requests. A remote attacker could possibly use this issue to cause
the server to crash, leading to a denial of service. (CVE-2018-1301)&lt;/p&gt;
&lt;p&gt;Robert Swiecki discovered that the Apache HTTP Server mod_cache_socache
module incorrectly handled certain headers. A remote attacker could
possibly use this issue to cause the server to crash, leading to a denial
of service. (CVE-2018-1303)&lt;/p&gt;
&lt;p&gt;Nicolas Daniels discovered that the Apache HTTP Server incorrectly
generated the nonce when creating HTTP Digest authentication challenges.
A remote attacker could possibly use this issue to replay HTTP requests
across a cluster of servers. (CVE-2018-1312)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-3627-1</guid>
    </item>
  </channel>
</rss>
