Skip to content
Noroxi

trustwave records

18 published records for vendor trustwave.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
61.1%
Median publish → KEV
No record has entered KEV

All records

18 records
  • Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorize

    CriticalCVSS 9.8Proof of conceptEPSS 14%

    trustwave · secure web gatewayDec 31, 2017

  • The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.

    CriticalCVSS 9.8No exploitEPSS 2%

    trustwave · mailmarshalFeb 19, 2020

  • CVE-2013-1915
    31Monitor

    ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servi

    HighCVSS 7.5No exploitEPSS 4%

    trustwave · modsecurityApr 25, 2013

  • ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.

    HighCVSS 7.5Proof of conceptEPSS 3%

    owasp · modsecurityDec 7, 2021

  • Libmodsecurity3 has possible bypass of encoded HTML entities

    HighCVSS 7.9No exploitEPSS 0%

    trustwave · modsecurityFeb 25, 2025

  • In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firew

    HighCVSS 7.5No exploitEPSS 1%

    owasp · modsecurityJan 20, 2023

  • Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over

    HighCVSS 7.5No exploitEPSS 1%

    trustwave · modsecurityJan 20, 2023

  • A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name para

    HighCVSS 7.5No exploitEPSS 1%

    trustwave · modsecurityOct 9, 2024

  • ModSecurity Has Possible DoS Vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    trustwave · modsecurityMay 21, 2025

  • CVE-2009-1902
    24Monitor

    The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapo

    MediumCVSS 5.0Proof of conceptEPSS 14%

    trustwave · modsecurityJun 3, 2009

  • CVE-2013-2765
    24Monitor

    The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereferenc

    MediumCVSS 5.0Proof of conceptEPSS 14%

    apache · http serverJul 15, 2013

  • CVE-2012-4528
    24Monitor

    The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to

    MediumCVSS 5.0Proof of conceptEPSS 13%

    trustwave · modsecurityDec 28, 2012

  • CVE-2013-5705
    21Monitor

    apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalize

    MediumCVSS 5.0No exploitEPSS 3%

    trustwave · modsecurityApr 15, 2014

  • CVE-2011-1906
    20Monitor

    Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier f

    MediumCVSS 5.0No exploitEPSS 1%

    trustwave · webdefendMay 5, 2011

  • CVE-2011-0756
    20Monitor

    The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote att

    MediumCVSS 5.0No exploitEPSS 1%

    trustwave · webdefendMay 4, 2011

  • CVE-2012-2751
    18Monitor

    ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in th

    MediumCVSS 4.3No exploitEPSS 3%

    trustwave · modsecurityJul 22, 2012

  • CVE-2009-1903
    18Monitor

    The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a r

    MediumCVSS 4.3No exploitEPSS 3%

    trustwave · modsecurityJun 3, 2009

  • CVE-2009-5031
    18Monitor

    ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filteri

    MediumCVSS 4.3No exploitEPSS 3%

    trustwave · modsecurityJul 22, 2012