cbcvebase.

Debian Apache2 vulnerabilities

215 known vulnerabilities affecting debian/apache2.

Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52

Vulnerabilities

Page 11 of 11
CVE-2009-1195P4LOWCVSS 4.9fixed in apache2 2.2.11-6 (bookworm)2009
CVE-2009-1195 [MEDIUM] CVE-2009-1195: apache2 - The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle ... The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file. Scope: local bookworm: r
debian
CVE-2005-2728P4MEDIUMCVSS 5.0fixed in apache2 2.0.54-5 (bookworm)2005
CVE-2005-2728 [MEDIUM] CVE-2005-2728: apache2 - The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cau... The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field. Scope: local bookworm: resolved (fixed in 2.0.54-5) bullseye: resolved (fixed in 2.0.54-5) forky: resolved (fixed in 2.0.54-5) sid: resolved (fixed in 2.0.54-5) trixie: resolved (fixed in 2.0.54-5)
debian
CVE-2002-1593P4MEDIUMCVSS 5.0fixed in apache2 2.0.42 (bookworm)2002
CVE-2002-1593 [MEDIUM] CVE-2002-1593: apache2 - mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which... mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module. Scope: local bookworm: resolved (fixed in 2.0.42) bullseye: resolved (fixed in 2.0.42) forky: resolved (fixed in 2.0.42) sid:
debian
CVE-2003-0254P4MEDIUMCVSS 5.0fixed in apache2 2.0.47 (bookworm)2003
CVE-2003-0254 [MEDIUM] CVE-2003-0254: apache2 - Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause ... Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket. Scope: local bookworm: resolved (fixed in 2.0.47) bullseye: resolved (fixed in 2.0.47) forky: resolved (fixed in 2.0.47) sid: resolved (fixed in 2.0.47) trixie: resolved (fixe
debian
CVE-2003-0134P4MEDIUMCVSS 5.0fixed in apache2 2.0.46 (bookworm)2003
CVE-2003-0134 [MEDIUM] CVE-2003-0134: apache2 - Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 thro... Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names. Scope: local bookworm: resolved (fixed in 2.0.46) bullseye: resolved (fixed in 2.0.46) forky: resolved (fixed in 2.0.46) sid: resolved (fixed in 2.0.46) trixie: resolved (fixed in 2.0.
debian
CVE-2003-0192P4MEDIUMCVSS 6.4fixed in apache2 2.0.47 (bookworm)2003
CVE-2003-0192 [MEDIUM] CVE-2003-0192: apache2 - Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not p... Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite. Scope: local bookworm: resolved (fixed in 2.0.47) bullseye: resolved (f
debian
CVE-2009-3094P4LOWCVSS 2.6fixed in apache2 2.2.13-2 (bookworm)2009
CVE-2009-3094 [LOW] CVE-2009-3094: apache2 - The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_... The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command. Scope: local bookworm: resolved (fixed in 2.2.13-2) bullseye: resolved (fixed in 2.2.13-
debian
CVE-2007-6422P4LOWCVSS 4.0fixed in apache2 2.2.8-1 (bookworm)2007
CVE-2007-6422 [MEDIUM] CVE-2007-6422: apache2 - The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.... The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable. Scope: local bookworm: resolved (fixed in 2.2.8-1) bullseye: resolved (fixed in 2.2.8-1) forky: resolved (f
debian
CVE-2007-6421P4LOWCVSS 3.5fixed in apache2 2.2.8-1 (bookworm)2007
CVE-2007-6421 [LOW] CVE-2007-6421: apache2 - Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balanc... Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL. Scope: local bookworm: resolved (fixed in 2.2.8-1) bullseye: resolved (fixed in 2.2.8-1) forky: resolved (fixed in 2.
debian
CVE-2013-1048P4MEDIUMCVSS 4.6≤ 2.2.16-6≤ 2.2.22-122013-03-06
CVE-2013-1048 [MEDIUM] CWE-264 CVE-2013-1048: The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
nvdosvdebian
CVE-2002-1592P4MEDIUMCVSS 5.0fixed in apache2 2.0.36 (bookworm)2002
CVE-2002-1592 [MEDIUM] CVE-2002-1592: apache2 - The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application e... The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information. Scope: local bookworm: resolved (fixed in 2.0.36) bullseye: resolved (fixed in 2.0.36) forky: resolved (fixed in 2.0.36) sid: r
debian
CVE-2012-4929P4LOWCVSS 2.6fixed in apache2 2.2.22-12 (bookworm)2012
CVE-2012-4929 [LOW] CVE-2012-4929: apache2 - The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt,... The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potenti
debian
CVE-2012-0216P4LOWCVSS 4.4fixed in apache2 2.2.22-4 (bookworm)2012
CVE-2012-0216 [MEDIUM] CVE-2012-0216: apache2 - The default configuration of the apache2 package in Debian GNU/Linux squeeze bef... The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vector
debian
CVE-2004-1834P4LOWCVSS 2.1fixed in apache2 2.0.53-1 (bookworm)2004
CVE-2004-1834 [LOW] CVE-2004-1834: apache2 - mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including aut... mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information. Scope: local bookworm: resolved (fixed in 2.0.53-1) bullseye: resolved (fixed in 2.0.53-1) forky: resolved (fixed in 2.0.53-1) sid: resolved (fixed in 2.0.53-1) trixie: resolved (fixed in
debian
CVE-2007-1742P4LOWCVSS 3.7fixed in apache2 2.2.8-5 (bookworm)2007
CVE-2007-1742 [LOW] CVE-2007-1742: apache2 - suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifyi... suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the ven
debian
Debian Apache2 vulnerabilities | cvebase