cbcvebase.

Apache Http Server vulnerabilities

310 known vulnerabilities affecting apache/http_server.

Total CVEs
310
CISA KEV
5
actively exploited
Public exploits
69
Exploited in wild
7
Severity breakdown
CRITICAL35HIGH100MEDIUM162LOW13

Vulnerabilities

Page 8 of 16
CVE-2014-0098MEDIUMCVSS 5.0≥ 2.2.0, < 2.2.27≥ 2.4.1, < 2.4.92014-03-18
CVE-2014-0098 [MEDIUM] CVE-2014-0098: The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server b The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
nvd
CVE-2013-6438MEDIUMCVSS 5.0≥ 2.2.0, < 2.2.27≥ 2.4.1, < 2.4.92014-03-18
CVE-2013-6438 [MEDIUM] CVE-2013-6438: The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
nvd
CVE-2013-2249HIGHCVSS 7.5≥ 2.4.1, ≤ 2.4.42013-07-23
CVE-2013-2249 [HIGH] CVE-2013-2249: mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
nvd
CVE-2013-1896MEDIUMCVSS 4.3≥ 2.2.0, < 2.2.25≥ 2.4.1, < 2.4.62013-07-10
CVE-2013-1896 [MEDIUM] CVE-2013-1896: mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
nvd
CVE-2013-1862MEDIUMCVSS 5.1≥ 2.0.0, < 2.0.65≥ 2.2.0, < 2.2.252013-06-10
CVE-2013-1862 [MEDIUM] CVE-2013-1862: mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
nvd
CVE-2012-3499MEDIUMCVSS 4.3v2.2v2.2.0+25 more2013-02-26
CVE-2012-3499 [MEDIUM] CWE-79 CVE-2012-3499: Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-de Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
nvd
CVE-2012-4558MEDIUMCVSS 4.3v2.2v2.2.0+25 more2013-02-26
CVE-2012-4558 [MEDIUM] CWE-79 CVE-2012-4558: Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
nvd
CVE-2012-4557MEDIUMCVSS 5.0v2.2.12v2.2.13+8 more2012-11-30
CVE-2012-4557 [MEDIUM] CWE-399 CVE-2012-4557: The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into a The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
nvd
CVE-2012-3502MEDIUMCVSS 4.3v2.4.0v2.4.1+1 more2012-08-22
CVE-2012-3502 [MEDIUM] CWE-200 CVE-2012-3502: The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances
nvd
CVE-2012-2687LOWCVSS 2.6v2.2.0v2.2.1+23 more2012-08-22
CVE-2012-2687 [LOW] CWE-79 CVE-2012-2687: Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotia Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction o
nvd
CVE-2012-0883MEDIUMCVSS 6.9≥ 2.2.0, < 2.2.23v2.4.12012-04-18
CVE-2012-0883 [MEDIUM] CVE-2012-0883: envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
nvd
CVE-2012-0053MEDIUMCVSS 4.3PoC≥ 2.0.0, < 2.0.65≥ 2.2.0, < 2.2.222012-01-28
CVE-2012-0053 [MEDIUM] CVE-2012-0053: protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header informat protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
nvd
CVE-2012-0021LOWCVSS 2.6v2.2.17v2.2.18+3 more2012-01-28
CVE-2012-0021 [LOW] CWE-20 CVE-2012-0021: The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2 The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
nvd
CVE-2012-0031MEDIUMCVSS 4.6PoC≥ 2.0.0, < 2.0.65≥ 2.2.0, < 2.2.222012-01-18
CVE-2012-0031 [MEDIUM] CVE-2012-0031: scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
nvd
CVE-2007-6750MEDIUMCVSS 5.0≤ 2.2.14v1.0+113 more2011-12-27
CVE-2007-6750 [MEDIUM] CWE-399 CVE-2007-6750: The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outa The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
nvd
CVE-2011-3639MEDIUMCVSS 4.3PoCv2.0.11v2.0.12+65 more2011-11-30
CVE-2011-3639 [MEDIUM] CVE-2011-3639: The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when th The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 pr
nvd
CVE-2011-4317MEDIUMCVSS 4.3PoCv1.3v1.3.0+96 more2011-11-30
CVE-2011-4317 [MEDIUM] CVE-2011-4317: The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers
nvd
CVE-2011-3607MEDIUMCVSS 4.4PoCv2.0v2.0.9+51 more2011-11-08
CVE-2011-3607 [MEDIUM] CWE-189 CVE-2011-3607: Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer ov
nvd
CVE-2011-4415LOWCVSS 1.2PoCv2.0v2.0.9+51 more2011-11-08
CVE-2011-4415 [LOW] CVE-2011-4415: The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x th The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvI
nvd
CVE-2011-3368MEDIUMCVSS 5.0PoCv1.3v1.3.0+96 more2011-10-05
CVE-2011-3368 [MEDIUM] CWE-20 CVE-2011-3368: The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initi
nvd