modwsgi records
4 published records for vendor modwsgi.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-254 7PK - Security Features1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-348 Use of Less Trusted Source1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2014-0242Proof of concept | mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Contmodwsgi · mod wsgi · CWE-200 | High7.5 | — | 8.5% | Dec 9, 2019 |
30Monitor | CVE-2022-2255No exploit | A vulnerability was found in mod_wsgi.modwsgi · mod wsgi · CWE-348 | High7.5 | — | 0.9% | Aug 25, 2022 |
27Monitor | CVE-2014-8583No exploit | mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, whmodwsgi · mod wsgi · CWE-254 | Medium6.9 | — | 0.4% | Dec 16, 2014 |
24Monitor | CVE-2014-0240No exploit | The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on modwsgi · mod wsgi · CWE-264 | Medium6.2 | — | 0.4% | May 27, 2014 |
- CVE-2014-024233Monitor
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Cont
HighCVSS 7.5Proof of conceptEPSS 9%modwsgi · mod wsgiDec 9, 2019
- CVE-2022-225530Monitor
A vulnerability was found in mod_wsgi.
HighCVSS 7.5No exploitEPSS 1%modwsgi · mod wsgiAug 25, 2022
- CVE-2014-858327Monitor
mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, wh
MediumCVSS 6.9No exploitEPSS 0%modwsgi · mod wsgiDec 16, 2014
- CVE-2014-024024Monitor
The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on
MediumCVSS 6.2No exploitEPSS 0%modwsgi · mod wsgiMay 27, 2014