CVE-2003-1054
MEDIUM 5.0EPSS 7.1%
mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 7.12% chance of exploitation in the next 30 days, 94th percentile
- Published
- 2005-01-19
- Updated
- 2024-08-08