Apache Http Server vulnerabilities
299 known vulnerabilities affecting apache/http_server.
Total CVEs
299
CISA KEV
5
actively exploited
Public exploits
66
Exploited in wild
7
Severity breakdown
CRITICAL33HIGH95MEDIUM158LOW13
Vulnerabilities
Page 15 of 15
CVE-2001-0131LOWCVSS 3.3v1.3.14v2.02001-03-12
CVE-2001-0131 [LOW] CWE-59 CVE-2001-0131: htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2001-0042MEDIUMCVSS 5.0PoCv1.32001-02-16
CVE-2001-0042 [MEDIUM] CVE-2001-0042: PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (do
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
nvd
CVE-2000-0913MEDIUMCVSS 5.0v0.8.11v0.8.14+8 more2000-12-19
CVE-2000-0913 [MEDIUM] CVE-2000-0913: mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a Rewrit
mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
nvd
CVE-2000-0868MEDIUMCVSS 5.0v1.3.122000-11-14
CVE-2000-0868 [MEDIUM] CVE-2000-0868: The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
nvd
CVE-2000-0869MEDIUMCVSS 5.0PoCv1.3.122000-11-14
CVE-2000-0869 [MEDIUM] CVE-2000-0869: The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote att
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
nvd
CVE-2000-1204MEDIUMCVSS 5.0v1.3.9v1.3.11+1 more2000-10-13
CVE-2000-1204 [MEDIUM] CVE-2000-1204: Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allo
Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
nvd
CVE-2000-0505MEDIUMCVSS 5.0PoCv1.3.6v1.3.9+2 more2000-05-31
CVE-2000-0505 [MEDIUM] CVE-2000-0505: The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory content
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
nvd
CVE-2000-1205MEDIUMCVSS 4.3v1.3.0v1.3.1+10 more2000-02-01
CVE-2000-1205 [MEDIUM] CWE-79 CVE-2000-1205: Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execut
Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various message
nvd
CVE-1999-1293CRITICALCVSS 10.0≤ 1.2.51999-12-31
CVE-1999-1293 [CRITICAL] CVE-1999-1293: mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malfo
mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
nvd
CVE-1999-1053HIGHCVSS 7.5PoCv1.3.91999-09-13
CVE-1999-1053 [HIGH] CVE-1999-1053: guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separator
guestbook.pl cleanses user-inserted SSI commands by removing text between "" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
nvd
CVE-1999-0926CRITICALCVSS 10.0PoCv1.2.51999-09-03
CVE-1999-0926 [CRITICAL] CVE-1999-0926: Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
nvd
CVE-2000-1206MEDIUMCVSS 5.0v1.3.9v1.3.101999-08-20
CVE-2000-1206 [MEDIUM] CVE-2000-1206: Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewr
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
nvd
CVE-1999-1199CRITICALCVSS 10.0≤ 1.3.11998-08-07
CVE-1999-1199 [CRITICAL] CVE-1999-1199: Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource e
Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
nvd
CVE-1999-0107MEDIUMCVSS 5.0PoCv0.8.11v0.8.14+7 more1997-12-30
CVE-1999-0107 [MEDIUM] CVE-1999-0107: Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service wi
Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
nvd
CVE-1999-0071HIGHCVSS 7.5v1.1.11997-09-01
CVE-1999-0071 [HIGH] CVE-1999-0071: Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
nvd
CVE-1999-0236HIGHCVSS 7.5PoCfixed in 1.01997-01-01
CVE-1999-0236 [HIGH] CVE-1999-0236: ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
nvd
CVE-1999-0045HIGHCVSS 7.5PoCv0.8.11v0.8.14+5 more1996-12-10
CVE-1999-0045 [HIGH] CVE-1999-0045: List of arbitrary files on Web host via nph-test-cgi script.
List of arbitrary files on Web host via nph-test-cgi script.
nvd
CVE-1999-0070MEDIUMCVSS 5.0PoCfixed in 1.3.01996-04-01
CVE-1999-0070 [MEDIUM] CVE-1999-0070: test-cgi program allows an attacker to list files on the server.
test-cgi program allows an attacker to list files on the server.
nvd
CVE-1999-0067CRITICALCVSS 10.0v1.0.31996-03-20
CVE-1999-0067 [CRITICAL] CWE-78 CVE-1999-0067: phf CGI program allows remote command execution through shell metacharacters.
phf CGI program allows remote command execution through shell metacharacters.
nvd
← Previous15 / 15