Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Traffic Server
Total 121 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-2952 1 Apache 1 Traffic Server 2026-06-16 4.3 MEDIUM N/A
Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.