CVE-2013-2765 describes a denial-of-service vulnerability in ModSecurity module versions prior to 2.7.4 for the Apache HTTP Server. Attackers can trigger a NULL pointer dereference, process crash, and disk consumption by sending a POST request with a large body and a specially crafted Content-Type header. This vulnerability has a CVSS score of 5.0 (medium severity), indicating a low attack complexity and potential for partial availability impact. While there is no evidence of active exploitation or inclusion in the KEV catalog, a public exploit (EDB-25852) exists, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.7.4CPE matchmatch criteria | cpe:2.3:a:trustwave:modsecurity:*:*:*:*:*:*:*:* | ||
11.4CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:* | ||
12.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.