CVE-2009-2299
Published Jul 2, 2009
Last updated 4 years ago
Overview
- Description
- The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:hyperguard_web_application_firewall_project:hyperguard_web_application_firewall:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1807EA11-DBA6-4364-899B-F62D6DE88057", "versionEndExcluding": "2.5.5-11635" }, { "criteria": "cpe:2.3:a:hyperguard_web_application_firewall_project:hyperguard_web_application_firewall:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7AD94D69-DD65-4C4B-A0D9-BAE8B4461869", "versionEndExcluding": "3.0.3-11636", "versionStartIncluding": "3.0" }, { "criteria": "cpe:2.3:a:hyperguard_web_application_firewall_project:hyperguard_web_application_firewall:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78A4B7DB-F76E-422F-B6FD-23560E828BAF", "versionEndExcluding": "3.1.1-11637", "versionStartIncluding": "3.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5A6CD1F4-4C0E-4989-A2B3-DC086E8E80A3" } ], "operator": "OR" } ], "operator": "AND" } ]