VendorsApsispoundall versions
Vulnerabilities

Apsis Pound

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2016-10711
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
Published 2018-01-29 · Modified
9.8EPSS 0.028
CVE-2018-21245
Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.
Published 2020-06-15 · Modified
9.1EPSS 0.011
CVE-2004-2026
Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.
Published 2005-05-10 · Modified
7.51 PoCEPSS 0.066
CVE-2005-1391
Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP header.
Published 2005-05-02 · Modified
7.5EPSS 0.061
CVE-2005-3751
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers.
Published 2005-11-22 · Modified
4.3EPSS 0.015