Search CVE reports


Toggle filters

11 – 20 of 25 results


CVE-2022-38150

Medium priority
Not affected

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-23959

Medium priority

Some fixes available 4 of 13

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Needs evaluation Fixed Fixed Fixed
Show less packages

CVE-2021-36740

Medium priority

Some fixes available 2 of 4

Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Fixed Not affected
Show less packages

CVE-2021-28543

Medium priority
Not affected

Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is...

1 affected package

varnish-modules

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish-modules Not in release Not affected
Show less packages

CVE-2020-11653

Low priority

Some fixes available 1 of 2

An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Fixed Not affected
Show less packages

CVE-2019-20637

Medium priority

Some fixes available 2 of 3

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Fixed Fixed
Show less packages

CVE-2013-4090

Medium priority
Not affected

Varnish HTTP cache before 3.0.4: ACL bug

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected
Show less packages

CVE-2019-15892

Medium priority
Ignored

An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Not affected
Show less packages

CVE-2017-8807

Low priority

Some fixes available 1 of 3

vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Not affected Not affected
Show less packages

CVE-2017-12425

Medium priority
Fixed

An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish
Show less packages