Apache Http Server vulnerabilities
323 known vulnerabilities affecting apache/http_server.
Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13
Vulnerabilities
Page 11 of 17
CVE-2014-0117P4MEDIUMCVSS 4.3v2.4.6v2.4.7+2 more2014-07-20
CVE-2014-0117 [MEDIUM] CWE-20 CVE-2014-0117: The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled,
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
nvd
CVE-2010-0408P3MEDIUMCVSS 5.0v2.2v2.2.0+10 more2010-03-05
CVE-2010-0408 [MEDIUM] CVE-2010-0408: The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.
The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appr
nvd
CVE-2003-0542P4HIGHCVSS 7.2v1.3v1.3.1+34 more2003-11-03
CVE-2003-0542 [HIGH] CWE-119 CVE-2003-0542: Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29
Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
nvd
CVE-2024-24795P3MEDIUMCVSS 6.3≥ 2.4.0, < 2.4.592024-04-04
CVE-2024-24795 [MEDIUM] CWE-113 CVE-2024-24795: HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.
Users are recommended to upgrade to version 2.4.59, which fixes this issue.
nvd
CVE-2016-1546P3MEDIUMCVSS 5.9v2.4.17v2.4.182016-07-06
CVE-2016-1546 [MEDIUM] CWE-399 CVE-2016-1546: The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of si
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
nvd
CVE-2004-1082P4HIGHCVSS 7.5v1.3v1.3.1+20 more2004-02-03
CVE-2004-1082 [HIGH] CVE-2004-1082: mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
nvd
CVE-2020-11985P3MEDIUMCVSS 5.3≥ 2.4.1, ≤ 2.4.232020-08-07
CVE-2020-11985 [MEDIUM] CWE-345 CVE-2020-11985: IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxyi
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
nvd
CVE-2008-2939P4MEDIUMCVSS 4.3≤ 2.0.63≥ 2.2.0, ≤ 2.2.92008-08-06
CVE-2008-2939 [MEDIUM] CWE-79 CVE-2008-2939: Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
nvd
CVE-2015-0228P4MEDIUMCVSS 5.0≤ 2.4.122015-03-08
CVE-2015-0228 [MEDIUM] CWE-20 CVE-2015-0228: The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server thr
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
nvd
CVE-2009-3560P4MEDIUMCVSS 5.0≥ 2.0.35, < 2.0.64≥ 2.2.0, < 2.2.172009-12-04
CVE-2009-3560 [MEDIUM] CVE-2009-3560: The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than C
nvd
CVE-2003-0789P4CRITICALCVSS 10.0≥ 2.0.35, < 2.0.482003-11-03
CVE-2003-0789 [CRITICAL] CVE-2003-0789: mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect p
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
nvd
CVE-2011-4415P4LOWCVSS 1.2PoCv2.0v2.0.9+51 more2011-11-08
CVE-2011-4415 [LOW] CVE-2011-4415: The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x th
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvI
nvd
CVE-2009-3720P4MEDIUMCVSS 5.0≥ 2.0.35, < 2.0.64≥ 2.2.0, < 2.2.172009-11-03
CVE-2009-3720 [MEDIUM] CVE-2009-3720: The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXM
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
nvd
CVE-2007-5000P4MEDIUMCVSS 4.3≥ 1.3.0, ≤ 1.3.39≥ 2.0.35, ≤ 2.0.61+1 more2007-12-13
CVE-2007-5000 [MEDIUM] CWE-79 CVE-2007-5000: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2004-0811P4HIGHCVSS 7.5v2.0.512004-12-31
CVE-2004-0811 [HIGH] CVE-2004-0811: Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
nvd
CVE-2010-0434P4MEDIUMCVSS 4.3≥ 2.0.35, < 2.0.64≥ 2.2.0, < 2.2.152010-03-05
CVE-2010-0434 [MEDIUM] CWE-200 CVE-2010-0434: The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, whe
The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers ac
nvd
CVE-2012-4558P4MEDIUMCVSS 4.3v2.2v2.2.0+25 more2013-02-26
CVE-2012-4558 [MEDIUM] CWE-79 CVE-2012-4558: Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager
Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
nvd
CVE-2000-0868P4MEDIUMCVSS 5.0v1.3.122000-11-14
CVE-2000-0868 [MEDIUM] CVE-2000-0868: The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
nvd
CVE-2004-0174P4HIGHCVSS 7.5≤ 2.0.492004-05-04
CVE-2004-0174 [HIGH] CWE-667 CVE-2004-0174: Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certai
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
nvd
CVE-2012-4557P4MEDIUMCVSS 5.0v2.2.12v2.2.13+8 more2012-11-30
CVE-2012-4557 [MEDIUM] CWE-399 CVE-2012-4557: The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into a
The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
nvd