Zero-day Vulnerability Database

Change view

Zero-day vulnerabilities discovered: 2

Denial of service in Apache HTTP Server
CVE-2011-3192

Resource exhaustion

The vulnerability allows a remote attacker to cause DoS conditions on the target system.

The weakness exists due to an error in the ByteRange filter when processing malicious requests in Apache HTTP server. A remote attacker can send a specially crafted HTTP request containing an overly large Range header, exhaust all available memory resources and trigger the application to crash.

Successful exploitation of the vulnerability results in denial service on the vulnerable system.

Note: the vulnerability was being actively exploited.
i

The vulnerability is known as "Apache Killer".

Software: Apache HTTP Server

The vulnerability is known as "Apache Killer".

Denial of service in Apache Subversion
CVE-2011-1752

Null pointer dereference

The vulnerability allows a remote attacker to cause DoS conditions on the target system.

The weakness exists due to NULL pointer dereference in the mod_dav_svn module when processing baselined WebDAV resources. A remote attacker can create a specially crafted request, send it to the victim and cause the Subversion server to crash.

Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Note: the vulnerability was being actively exploited.
i

The vulnerability was discovered by Joe Schaefer.

Software: Subversion

The vulnerability was discovered by Joe Schaefer.