cbcvebase.

Debian Apache2 vulnerabilities

215 known vulnerabilities affecting debian/apache2.

Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52

Vulnerabilities

Page 10 of 11
CVE-2005-3357P4LOWCVSS 5.4fixed in apache2 2.0.55-4 (bookworm)2005
CVE-2005-3357 [MEDIUM] CVE-2005-3357: apache2 - mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with acces... mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 2.0.55-4) bullseye: resolved (fixed in 2.0.55-4
debian
CVE-2005-2088P4MEDIUMCVSS 4.3fixed in apache2 2.0.54-5 (bookworm)2005
CVE-2005-2088 [MEDIUM] CVE-2005-2088: apache2 - The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an... The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the bod
debian
CVE-2013-4352P4LOWCVSS 4.3fixed in apache2 2.4.7-1 (bookworm)2013
CVE-2013-4352 [MEDIUM] CVE-2013-4352: apache2 - The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache ... The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger a missing hostname value. Scope: local bookworm: resolved (fixed in 2.4.7-1) bulls
debian
CVE-2004-0786P4MEDIUMCVSS 5.0fixed in apache2 2.0.51 (bookworm)2004
CVE-2004-0786 [MEDIUM] CVE-2004-0786: apache2 - The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earl... The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool. Scope: local bookworm: resolved (fixed in 2.0.51) bullseye: resolved (fixed in 2.0.51) forky: resolved (fixed in 2.0.51) sid: resolved (f
debian
CVE-2004-0747P4HIGHCVSS 7.8fixed in apache2 2.0.51 (bookworm)2004
CVE-2004-0747 [HIGH] CVE-2004-0747: apache2 - Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache p... Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables. Scope: local bookworm: resolved (fixed in 2.0.51) bullseye: resolved (fixed in 2.0.51) forky: resolved (fixed in 2.0.51) sid: resolved (fixed in 2.0.51) trixie: resolved (fixed in 2.0.51)
debian
CVE-2007-6420P4LOWCVSS 4.3fixed in apache2 2.2.9-1 (bookworm)2007
CVE-2007-6420 [MEDIUM] CVE-2007-6420: apache2 - Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_p... Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors. Scope: local bookworm: resolved (fixed in 2.2.9-1) bullseye: resolved (fixed in 2.2.9-1) forky: resolved (fixed in 2.2.9-1) sid: resolved (fixed in 2.2.9-1) trixie: resolved (fi
debian
CVE-2007-3847P4LOWCVSS 5.0fixed in apache2 2.2.6-1 (bookworm)2007
CVE-2007-3847 [MEDIUM] CVE-2007-3847: apache2 - The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0... The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read. Scope: local bookworm: resolved (fixed in 2.2.6-1) bullseye: resolved (fixed in 2.2.6-1) forky: resolved
debian
CVE-2008-2364P4LOWCVSS 5.0fixed in apache2 2.2.9-1 (bookworm)2008
CVE-2008-2364 [MEDIUM] CVE-2008-2364: apache2 - The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy... The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses. Scope: local bookworm: resolved (fixed in 2.2.9-1) bull
debian
CVE-2019-0197P4MEDIUMCVSS 4.2fixed in apache2 2.4.38-3 (bookworm)2019
CVE-2019-0197 [MEDIUM] CVE-2019-0197: apache2 - A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 wa... A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https:
debian
CVE-2004-0809P4MEDIUMCVSS 5.0fixed in apache2 2.0.51-1 (bookworm)2004
CVE-2004-0809 [MEDIUM] CVE-2004-0809: apache2 - The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause... The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access. Scope: local bookworm: resolved (fixed in 2.0.51-1) bullseye: resolved (fixed in 2.0.51-1) forky: resolved (fixed in 2.0.51-1) sid: resolved (fixed in 2.
debian
CVE-2005-1268P4LOWCVSS 5.0fixed in apache2 2.0.54-5 (bookworm)2005
CVE-2005-1268 [MEDIUM] CVE-2005-1268: apache2 - Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification c... Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte. Scope: local bookworm: resolved (fixed in 2.0.54-5) bullseye: resolved (fixed in 2.0.54-5) forky: resolved
debian
CVE-2007-1863P4LOWCVSS 5.0fixed in apache2 2.2.4-1 (bookworm)2007
CVE-2007-1863 [MEDIUM] CVE-2007-1863: apache2 - cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching... cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value. Scope: local bo
debian
CVE-2012-2687P4LOWCVSS 2.6fixed in apache2 2.2.22-8 (bookworm)2012
CVE-2012-2687 [LOW] CVE-2012-2687: apache2 - Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list fun... Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant li
debian
CVE-2008-1678P4MEDIUMCVSS 5.0fixed in apache2 2.2.8-4 (bookworm)2008
CVE-2008-1678 [MEDIUM] CVE-2008-1678: apache2 - Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl... Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm. Scope: local bookworm: resolved (fixed
debian
CVE-2005-2970P4LOWCVSS 5.0fixed in apache2 2.0.55-1 (bookworm)2005
CVE-2005-2970 [MEDIUM] CVE-2005-2970: apache2 - Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances,... Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections. Scope: local bookworm: resolved (fixed in 2.0.55-1) bullseye: resolved (fixed in 2.0.55-1) forky
debian
CVE-2008-0005P4LOWCVSS 4.3fixed in apache2 2.2.8-1 (bookworm)2008
CVE-2008-0005 [MEDIUM] CVE-2008-0005: apache2 - mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3... mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding. Scope: local bookworm: resolved (fixed in 2.2.8-1) bullseye: resolved (fixed in 2.2.8-1) forky: resolved (fixed in 2.2.8-1) sid: resolved (fix
debian
CVE-2004-0113P4MEDIUMCVSS 5.0fixed in apache2 2.0.52 (bookworm)2004
CVE-2004-0113 [MEDIUM] CVE-2004-0113: apache2 - Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remo... Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server. Scope: local bookworm: resolved (fixed in 2.0.52) bullseye: resolved (fixed in 2.0.52) forky: resolved (fixed in 2.0.52) sid: resolved (fixed in 2.0.52) trixie
debian
CVE-2007-1741P4LOWCVSS 6.2fixed in apache2 2.2.8-5 (bookworm)2007
CVE-2007-1741 [MEDIUM] CVE-2007-1741: apache2 - Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between d... Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an
debian
CVE-2003-0253P4MEDIUMCVSS 5.0fixed in apache2 2.0.47 (bookworm)2003
CVE-2003-0253 [MEDIUM] CVE-2003-0253: apache2 - The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain error... The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service. Scope: local bookworm: resolved (fixed in 2.0.47) bullseye: resolved (fixed in 2.0.47) forky: resolved (fixed in 2.0.47) sid: resolved (fixed in 2.0.47) trixie: resolved (fixed in 2.0.47)
debian
CVE-2007-3304P4LOWCVSS 4.7fixed in apache2 2.2.4-2 (bookworm)2007
CVE-2007-3304 [MEDIUM] CVE-2007-3304: apache2 - Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local... Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer." Scope: local bookworm: resolved (fixed in 2.2.4-2) bullseye: resolved (fixed in 2
debian
Debian Apache2 vulnerabilities | cvebase