Apache Http Server vulnerabilities
323 known vulnerabilities affecting apache/http_server.
Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13
Vulnerabilities
Page 15 of 17
CVE-2016-8612P4MEDIUMCVSS 4.3fixed in 2.4.232018-03-09
CVE-2016-8612 [MEDIUM] CWE-20 CVE-2016-8612: Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Valida
Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.
nvd
CVE-2005-2970P4MEDIUMCVSS 5.0≥ 2.0.36, < 2.0.552005-10-25
CVE-2005-2970 [MEDIUM] CWE-770 CVE-2005-2970: Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attac
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
nvd
CVE-2008-0005P4MEDIUMCVSS 4.3≥ 2.0.35, < 2.0.63≥ 2.2.0, < 2.2.82008-01-12
CVE-2008-0005 [MEDIUM] CWE-79 CVE-2008-0005: mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
nvd
CVE-2001-0729P4MEDIUMCVSS 5.0v1.3.202001-10-30
CVE-2001-0729 [MEDIUM] CVE-2001-0729: Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list d
Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
nvd
CVE-2004-0113P4MEDIUMCVSS 5.0v2.0.35v2.0.36+12 more2004-03-29
CVE-2004-0113 [MEDIUM] CVE-2004-0113: Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to caus
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
nvd
CVE-2000-1205P4MEDIUMCVSS 4.3v1.3.0v1.3.1+10 more2000-02-01
CVE-2000-1205 [MEDIUM] CWE-79 CVE-2000-1205: Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execut
Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various message
nvd
CVE-2007-1741P4MEDIUMCVSS 6.2v2.2.32007-04-13
CVE-2007-1741 [MEDIUM] CWE-362 CVE-2007-1741: Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file va
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks descr
nvd
CVE-2003-0253P4MEDIUMCVSS 5.0v2.0v2.0.28+13 more2003-08-18
CVE-2003-0253 [MEDIUM] CVE-2003-0253: The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which
The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
nvd
CVE-2007-3304P4MEDIUMCVSS 4.7≥ 1.3.0, < 1.3.39≥ 2.0.0, < 2.0.61+1 more2007-06-20
CVE-2007-3304 [MEDIUM] CVE-2007-3304: Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a de
Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
nvd
CVE-2009-1195P4MEDIUMCVSS 4.9v2.2.0v2.2.1+7 more2009-05-28
CVE-2009-1195 [MEDIUM] CWE-16 CVE-2009-1195: The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEX
The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
nvd
CVE-2002-2103P4MEDIUMCVSS 5.0v1.3.9v1.3.11+11 more2002-12-31
CVE-2002-2103 [MEDIUM] CVE-2002-2103: Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse look
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
nvd
CVE-2002-2012P4MEDIUMCVSS 5.0v1.3.192002-12-31
CVE-2002-2012 [MEDIUM] CVE-2002-2012: Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers
Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
nvd
CVE-2001-1342P4MEDIUMCVSS 5.0v1.3.12v1.3.14+5 more2001-05-12
CVE-2001-1342 [MEDIUM] CVE-2001-1342: Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of servic
Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
nvd
CVE-2003-0017P4MEDIUMCVSS 5.0v2.0.36v2.0.37+6 more2003-02-07
CVE-2003-0017 [MEDIUM] CVE-2003-0017: Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an
Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.
nvd
CVE-2005-2728P4MEDIUMCVSS 5.0v2.0v2.0.9+21 more2005-08-30
CVE-2005-2728 [MEDIUM] CVE-2005-2728: The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of servi
The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
nvd
CVE-2003-1580P4MEDIUMCVSS 4.3v2.0.442010-02-05
CVE-2003-1580 [MEDIUM] CWE-189 CVE-2003-1580: The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a loggin
The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123
nvd
CVE-2003-0460P4MEDIUMCVSS 5.0≤ 1.3.272003-08-27
CVE-2003-0460 [MEDIUM] CVE-2003-0460: The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly igno
The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
nvd
CVE-2002-1593P4MEDIUMCVSS 5.0v2.0v2.0.28+8 more2002-09-25
CVE-2002-1593 [MEDIUM] CVE-2002-1593: mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote at
mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.
nvd
CVE-2001-1072P4MEDIUMCVSS 5.0v1.3.14v1.3.17+1 more2001-08-31
CVE-2001-1072 [MEDIUM] CVE-2001-1072: Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules
Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
nvd
CVE-2003-0254P4MEDIUMCVSS 5.0v2.0v2.0.28+13 more2003-08-18
CVE-2003-0254 [MEDIUM] CVE-2003-0254: Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service
Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
nvd