VYPR

mod_wsgi

by Apache

CVEs (2)

  • CVE-2014-0242HigDec 9, 2019
    risk 0.52cvss 7.5epss 0.09

    mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.

  • CVE-2014-8583Dec 16, 2014
    risk 0.00cvss epss 0.00

    mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors.