← back
CVE-2011-3192observed exploitation

CVE-2011-3192

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 99%
from disclosure to weapon0 days
Published on NVDAug 29
1st PoCAug 19
metasploitAug 19
VulnCheckAug 24
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesVulnCheck
11 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
1 product
Red Hat Directory Server 8
none_available: Affected
Fixed
18 products (405 components)
Red Hat Enterprise Linux AS version 4 · Red Hat Enterprise Linux Desktop version 4 · Red Hat Enterprise Linux ES version 4 · Red Hat Enterprise Linux WS version 4 · RHEL Desktop Workstation (v. 5 client) · and others 13
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.