varnish-cache records
7 published records for vendor varnish-cache.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 85.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-190 Integer Overflow or Wraparound1
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer1
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')1
- CWE-476 NULL Pointer Dereference1
- CWE-617 Reachable Assertion1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2017-8807No exploit | vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to ovarnish-cache · varnish · CWE-119 | Critical9.1 | — | 4.1% | Nov 15, 2017 |
31Monitor | CVE-2017-12425No exploit | An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2.varnish-cache · varnish · CWE-190 | High7.5 | — | 2.4% | Aug 4, 2017 |
31Monitor | CVE-2020-11653No exploit | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2.varnish-cache · varnish cache · CWE-617 | High7.5 | — | 2.2% | Apr 8, 2020 |
31Monitor | CVE-2019-20637No exploit | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.varnish-cache · varnish cache · CWE-212 | High7.5 | — | 1.8% | Apr 8, 2020 |
30Monitor | CVE-2021-28543No exploit | Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations.varnish-cache · varnish-modules · CWE-476 | High7.5 | — | 1.5% | Mar 16, 2021 |
26Monitor | CVE-2021-36740No exploit | Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST requevarnish-cache · varnish cache · CWE-444 | Medium6.5 | — | 1.6% | Jul 14, 2021 |
21Monitor | CVE-2013-4484No exploit | Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET requevarnish-cache · varnish · CWE-119 | Medium5.0 | — | 3.2% | Oct 31, 2013 |
- CVE-2017-880737Monitor
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to o
CriticalCVSS 9.1No exploitEPSS 4%varnish-cache · varnishNov 15, 2017
- CVE-2017-1242531Monitor
An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2.
HighCVSS 7.5No exploitEPSS 2%varnish-cache · varnishAug 4, 2017
- CVE-2020-1165331Monitor
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2.
HighCVSS 7.5No exploitEPSS 2%varnish-cache · varnish cacheApr 8, 2020
- CVE-2019-2063731Monitor
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.
HighCVSS 7.5No exploitEPSS 2%varnish-cache · varnish cacheApr 8, 2020
- CVE-2021-2854330Monitor
Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations.
HighCVSS 7.5No exploitEPSS 1%varnish-cache · varnish-modulesMar 16, 2021
- CVE-2021-3674026Monitor
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST reque
MediumCVSS 6.5No exploitEPSS 2%varnish-cache · varnish cacheJul 14, 2021
- CVE-2013-448421Monitor
Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET reque
MediumCVSS 5.0No exploitEPSS 3%varnish-cache · varnishOct 31, 2013