cbcvebase.

Apache Http Server vulnerabilities

310 known vulnerabilities affecting apache/http_server.

Total CVEs
310
CISA KEV
5
actively exploited
Public exploits
69
Exploited in wild
7
Severity breakdown
CRITICAL35HIGH100MEDIUM162LOW13

Vulnerabilities

Page 13 of 16
CVE-2003-0993HIGHCVSS 7.5v1.3v1.3.1+20 more2004-03-29
CVE-2003-0993 [HIGH] CVE-2003-0993: mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
nvd
CVE-2004-0113MEDIUMCVSS 5.0v2.0.35v2.0.36+12 more2004-03-29
CVE-2004-0113 [MEDIUM] CVE-2004-0113: Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to caus Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
nvd
CVE-2004-1834LOWCVSS 2.1v2.0v2.0.9+17 more2004-03-20
CVE-2004-1834 [LOW] CVE-2004-1834: mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication informat mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
nvd
CVE-2003-0987HIGHCVSS 7.5≤ 1.3.302004-03-03
CVE-2003-0987 [HIGH] CVE-2003-0987: mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
nvd
CVE-2004-1082HIGHCVSS 7.5v1.3v1.3.1+20 more2004-02-03
CVE-2004-1082 [HIGH] CVE-2004-1082: mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
nvd
CVE-2003-1307MEDIUMCVSS 4.3PoCv2.0v2.0.9+17 more2003-12-31
CVE-2003-1307 [MEDIUM] CVE-2003-1307: The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The op
nvd
CVE-2003-1418MEDIUMCVSS 4.3v1.3.22v1.3.23+4 more2003-12-31
CVE-2003-1418 [MEDIUM] CWE-200 CVE-2003-1418: Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive info Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).
nvd
CVE-2003-0789CRITICALCVSS 10.0≥ 2.0.35, < 2.0.482003-11-03
CVE-2003-0789 [CRITICAL] CVE-2003-0789: mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect p mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
nvd
CVE-2003-0542HIGHCVSS 7.2v1.3v1.3.1+34 more2003-11-03
CVE-2003-0542 [HIGH] CWE-119 CVE-2003-0542: Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
nvd
CVE-2003-0460MEDIUMCVSS 5.0≤ 1.3.272003-08-27
CVE-2003-0460 [MEDIUM] CVE-2003-0460: The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly igno The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
nvd
CVE-2003-0192MEDIUMCVSS 6.4v2.0v2.0.28+13 more2003-08-18
CVE-2003-0192 [MEDIUM] CVE-2003-0192: Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "cert Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
nvd
CVE-2003-0253MEDIUMCVSS 5.0v2.0v2.0.28+13 more2003-08-18
CVE-2003-0253 [MEDIUM] CVE-2003-0253: The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
nvd
CVE-2003-0254MEDIUMCVSS 5.0v2.0v2.0.28+13 more2003-08-18
CVE-2003-0254 [MEDIUM] CVE-2003-0254: Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
nvd
CVE-2003-0245MEDIUMCVSS 5.0PoCv2.0.37v2.0.38+7 more2003-06-09
CVE-2003-0245 [MEDIUM] CVE-2003-0245: Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2 Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
nvd
CVE-2003-0189MEDIUMCVSS 5.0v2.0.40v2.0.41+4 more2003-06-09
CVE-2003-0189 [MEDIUM] CVE-2003-0189: The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
nvd
CVE-2003-0134MEDIUMCVSS 5.0v2.0v2.0.9+13 more2003-04-11
CVE-2003-0134 [MEDIUM] CVE-2003-0134: Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows u Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.
nvd
CVE-2003-0132MEDIUMCVSS 5.0PoC≥ 2.0.0, ≤ 2.0.442003-04-11
CVE-2003-0132 [MEDIUM] CWE-772 CVE-2003-0132: A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (mem A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.
nvd
CVE-2003-0083MEDIUMCVSS 5.0PoC≥ 1.3.0, < 1.3.26≥ 2.0.0, < 2.0.462003-04-02
CVE-2003-0083 [MEDIUM] CVE-2003-0083: Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequen Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
nvd
CVE-2003-0020MEDIUMCVSS 5.0PoC≥ 1.3.0, < 1.3.31≥ 2.0.0, < 2.0.492003-03-18
CVE-2003-0020 [MEDIUM] CVE-2003-0020: Apache does not filter terminal escape sequences from its error logs, which could make it easier for Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
nvd
CVE-2003-0016HIGHCVSS 7.5v2.0.36v2.0.37+6 more2003-02-07
CVE-2003-0016 [HIGH] CVE-2003-0016: Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote a Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
nvd