cbcvebase.

Debian Apache2 vulnerabilities

215 known vulnerabilities affecting debian/apache2.

Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52

Vulnerabilities

Page 1 of 11
CVE-2021-42013P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in apache2 2.4.51-1 (bookworm)2021
CVE-2021-42013 [CRITICAL] CVE-2021-42013: apache2 - It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was in... It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If
debian
CVE-2021-41773P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in apache2 2.4.50-1 (bookworm)2021
CVE-2021-41773 [CRITICAL] CVE-2021-41773: apache2 - A flaw was found in a change made to path normalization in Apache HTTP Server 2.... A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI sc
debian
CVE-2021-40438P1CRITICALCVSS 9.0KEVPoCRansomwarefixed in apache2 2.4.49-1 (bookworm)2021
CVE-2021-40438 [CRITICAL] CVE-2021-40438: apache2 - A crafted request uri-path can cause mod_proxy to forward the request to an orig... A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. Scope: local bookworm: resolved (fixed in 2.4.49-1) bullseye: resolved (fixed in 2.4.51-1~deb11u1) forky: resolved (fixed in 2.4.49-1) sid: resolved (fixed in 2.4.49-1) trixie: resolved (f
debian
CVE-2024-38475P1CRITICALCVSS 9.1KEVPoCfixed in apache2 2.4.61-1~deb12u1 (bookworm)2024
CVE-2024-38475 [CRITICAL] CVE-2024-38475: apache2 - Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earl... Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variab
debian
CVE-2019-0211P1HIGHCVSS 7.8KEVPoCRansomwarefixed in apache2 2.4.38-3 (bookworm)2019
CVE-2019-0211 [HIGH] CVE-2019-0211: apache2 - In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or p... In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
debian
CVE-2023-25690P1CRITICALCVSS 9.8ExploitedPoCfixed in apache2 2.4.56-1 (bookworm)2023
CVE-2023-25690 [CRITICAL] CVE-2023-25690: apache2 - Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.5... Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the pr
debian
CVE-2020-11984P1CRITICALCVSS 9.8ExploitedPoCfixed in apache2 2.4.46-1 (bookworm)2020
CVE-2020-11984 [CRITICAL] CVE-2020-11984: apache2 - Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible... Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE Scope: local bookworm: resolved (fixed in 2.4.46-1) bullseye: resolved (fixed in 2.4.46-1) forky: resolved (fixed in 2.4.46-1) sid: resolved (fixed in 2.4.46-1) trixie: resolved (fixed in 2.4.46-1)
debian
CVE-2009-3555P1MEDIUMCVSS 5.8ExploitedPoCfixed in apache2 2.2.14-2 (bookworm)2009
CVE-2009-3555 [MEDIUM] CVE-2009-3555: apache2 - The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Micr... The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate reneg
debian
CVE-2017-9798P1HIGHCVSS 7.5ExploitedPoCRansomwarefixed in apache2 2.4.27-6 (bookworm)2017
CVE-2017-9798 [HIGH] CVE-2017-9798: apache2 - Apache httpd allows remote attackers to read secret data from process memory if ... Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secre
debian
CVE-2002-0392P1HIGHCVSS 7.5ExploitedPoCfixed in apache2 2.0.37 (bookworm)2002
CVE-2002-0392 [HIGH] CVE-2002-0392: apache2 - Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attacker... Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. Scope: local bookworm: resolved (fixed in 2.0.37) bullseye: resolved (fixed in 2.0.37) forky: resolved (fixed in 2.0.37) sid: resolved (fixed in
debian
CVE-2017-15715P1HIGHCVSS 8.1ExploitedPoCfixed in apache2 2.4.33-1 (bookworm)2017
CVE-2017-15715 [HIGH] CVE-2017-15715: apache2 - In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could ... In Apache httpd 2.4.0 to 2.4.29, the expression specified in could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename. Scope: local bookworm: resolved (fixe
debian
CVE-2016-0736P1HIGHCVSS 7.5ExploitedPoCRansomwarefixed in apache2 2.4.25-1 (bookworm)2016
CVE-2016-0736 [HIGH] CVE-2016-0736: apache2 - In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encryptin... In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC. Scope: local bookworm: resolved (fix
debian
CVE-2019-10098P2MEDIUMCVSS 6.1ExploitedPoCfixed in apache2 2.4.41-1 (bookworm)2019
CVE-2019-10098 [MEDIUM] CVE-2019-10098: apache2 - In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite tha... In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL. Scope: local bookworm: resolved (fixed in 2.4.41-1) bullseye: resolved (fixed in 2.4.41-1) forky: resolved (fixed in 2.4.41-1) sid: resolved (fix
debian
CVE-2011-3192P2HIGHCVSS 7.8ExploitedPoCfixed in apache2 2.2.19-2 (bookworm)2011
CVE-2011-3192 [HIGH] CVE-2011-3192: apache2 - The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and ... The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086. Scope: local bookworm: resolved (fixe
debian
CVE-2018-8011P2HIGHCVSS 7.5ExploitedPoCfixed in apache2 2.4.34-1 (bookworm)2018
CVE-2018-8011 [HIGH] CVE-2018-8011: apache2 - By specially crafting HTTP requests, the mod_md challenge handler would derefere... By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33). Scope: local bookworm: resolved (fixed in 2.4.34-1) bullseye: resolved (fixed in 2.4.34-1) forky: resolved (fixed in 2.4.34-1) sid: resolv
debian
CVE-2017-9788P1CRITICALCVSS 9.1Exploitedfixed in apache2 2.4.27-1 (bookworm)2017
CVE-2017-9788 [CRITICAL] CVE-2017-9788: apache2 - In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in ... In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leadi
debian
CVE-2018-1303P2HIGHCVSS 7.5Exploitedfixed in apache2 2.4.33-1 (bookworm)2018
CVE-2018-1303 [HIGH] CVE-2018-1303: apache2 - A specially crafted HTTP request header could have crashed the Apache HTTP Serve... A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_dis
debian
CVE-2019-0190P2HIGHCVSS 7.5Exploitedfixed in apache2 2.4.38-1 (bookworm)2019
CVE-2019-0190 [HIGH] CVE-2019-0190: apache2 - A bug exists in the way mod_ssl handled client renegotiations. A remote attacker... A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation at
debian
CVE-2019-10097P2HIGHCVSS 7.2Exploitedfixed in apache2 2.4.41-1 (bookworm)2019
CVE-2019-10097 [HIGH] CVE-2019-10097: apache2 - In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a t... In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients. Scope: local bookworm: resolved
debian
CVE-2017-7659P2HIGHCVSS 7.5Exploitedfixed in apache2 2.4.25-4 (bookworm)2017
CVE-2017-7659 [HIGH] CVE-2017-7659: apache2 - A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Se... A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process. Scope: local bookworm: resolved (fixed in 2.4.25-4) bullseye: resolved (fixed in 2.4.25-4) forky: resolved (fixed in 2.4.25-4) sid: resolved (fixed in 2.4.25-4) trixie: resolved (fixed in 2.4.25-4)
debian
1 / 11Next →
Debian Apache2 vulnerabilities | cvebase