Apache Http Server vulnerabilities
323 known vulnerabilities affecting apache/http_server.
Total CVEs
323
CISA KEV
5
actively exploited
Public exploits
70
Exploited in wild
22
Severity breakdown
CRITICAL38HIGH107MEDIUM165LOW13
Vulnerabilities
Page 17 of 17
CVE-2004-1387P4LOWCVSS 2.1v1.3.312004-12-31
CVE-2004-1387 [LOW] CVE-2004-1387: The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create a
The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
nvd
CVE-2002-1233P4LOWCVSS 2.6v1.3.17v1.3.18+8 more2002-11-04
CVE-2002-1233 [LOW] CVE-2002-1233: A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2
A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability
nvd
CVE-2001-1534P4LOWCVSS 2.1≥ 1.3.11, ≤ 1.3.202001-12-31
CVE-2001-1534 [LOW] CWE-384 CVE-2001-1534: mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information i
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
nvd
← Previous17 / 17