Apache Http Server vulnerabilities

299 known vulnerabilities affecting apache/http_server.

Total CVEs
299
CISA KEV
5
actively exploited
Public exploits
66
Exploited in wild
7
Severity breakdown
CRITICAL33HIGH95MEDIUM158LOW13

Vulnerabilities

Page 11 of 15
CVE-2006-4154MEDIUMCVSS 6.8v2.0v2.0.9+38 more2006-10-16
CVE-2006-4154 [MEDIUM] CVE-2006-4154: Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attack Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
nvd
CVE-2006-4110MEDIUMCVSS 4.3PoCv2.0.58v2.2.2+1 more2006-08-14
CVE-2006-4110 [MEDIUM] CVE-2006-4110: Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs v Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
nvd
CVE-2006-3747HIGHCVSS 7.6PoC≥ 1.3.28, < 1.3.37≥ 2.0.46, < 2.0.59+1 more2006-07-28
CVE-2006-3747 [HIGH] CWE-189 CVE-2006-3747: Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certa
nvd
CVE-2006-3918MEDIUMCVSS 4.3PoC≥ 1.3.3, < 1.3.352006-07-28
CVE-2006-3918 [MEDIUM] CWE-79 CVE-2006-3918: http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HT http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client comp
nvd
CVE-2005-3357MEDIUMCVSS 5.4v2.0v2.0.9+23 more2005-12-31
CVE-2005-3357 [MEDIUM] CWE-399 CVE-2005-3357: mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a cust mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
nvd
CVE-2005-3352MEDIUMCVSS 4.3fixed in 1.3.35≥ 2.0, < 2.0.56+1 more2005-12-13
CVE-2005-3352 [MEDIUM] CWE-79 CVE-2005-3352: Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev an Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
nvd
CVE-2005-2970MEDIUMCVSS 5.0≥ 2.0.36, < 2.0.552005-10-25
CVE-2005-2970 [MEDIUM] CWE-770 CVE-2005-2970: Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attac Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
nvd
CVE-2005-2700CRITICALCVSS 10.0≥ 2.0.35, < 2.0.552005-09-06
CVE-2005-2700 [CRITICAL] CVE-2005-2700: ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global vi ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
nvd
CVE-2005-2728MEDIUMCVSS 5.0v2.0v2.0.9+21 more2005-08-30
CVE-2005-2728 [MEDIUM] CVE-2005-2728: The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of servi The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
nvd
CVE-2005-1268MEDIUMCVSS 5.0≥ 2.0.35, ≤ 2.0.542005-08-05
CVE-2005-1268 [MEDIUM] CWE-193 CVE-2005-1268: Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, w Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
nvd
CVE-2005-2088MEDIUMCVSS 4.3≥ 2.0.35, < 2.0.552005-07-05
CVE-2005-2088 [MEDIUM] CWE-444 CVE-2005-2088: The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and f
nvd
CVE-2005-1344HIGHCVSS 7.5PoCv2.0.522005-05-02
CVE-2005-1344 [HIGH] CVE-2005-1344: Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a lon Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerab
nvd
CVE-2004-0940HIGHCVSS 7.8PoC≥ 1.3, ≤ 1.3.322005-02-09
CVE-2004-0940 [HIGH] CWE-131 CVE-2004-0940: Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
nvd
CVE-2004-0942MEDIUMCVSS 5.0PoC≤ 2.0.522005-02-09
CVE-2004-0942 [MEDIUM] CVE-2004-0942: Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consum Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
nvd
CVE-2004-2343HIGHCVSS 7.2≤ 2.0.472004-12-31
CVE-2004-2343 [HIGH] CVE-2004-2343: Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as s Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privilege
nvd
CVE-2004-0811HIGHCVSS 7.5v2.0.512004-12-31
CVE-2004-0811 [HIGH] CVE-2004-0811: Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
nvd
CVE-2004-1387LOWCVSS 2.1v1.3.312004-12-31
CVE-2004-1387 [LOW] CVE-2004-1387: The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create a The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
nvd
CVE-2004-0263MEDIUMCVSS 5.0v1.0v1.0.2+46 more2004-11-23
CVE-2004-0263 [MEDIUM] CVE-2004-0263: PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual host PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
nvd
CVE-2004-0885HIGHCVSS 7.5v2.0.35v2.0.36+16 more2004-11-03
CVE-2004-0885 [HIGH] CVE-2004-0885: The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in dir The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
nvd
CVE-2004-0747HIGHCVSS 7.8≥ 2.0.35, < 2.0.512004-10-20
CVE-2004-0747 [HIGH] CWE-131 CVE-2004-0747: Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .hta Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
nvd