Tomas Hoger

2 exploits Active since Jul 2010
CVE-2011-3639 EXPLOITDB text WRITEUP
Apache HTTP Server <2.0.64, <2.2.18 - SSRF
The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
CVE-2010-2482 EXPLOITDB text WORKING POC
libtiff < 3.9.4 - Denial of Service via Invalid td_stripbytecount Field
LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.