Debian Apache2 vulnerabilities

242 known vulnerabilities affecting debian/apache2.

Total CVEs
242
CISA KEV
5
actively exploited
Public exploits
49
Exploited in wild
7
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW79

Vulnerabilities

Page 12 of 13
CVE-2003-0134MEDIUMCVSS 5.0fixed in apache2 2.0.46 (bookworm)2003
CVE-2003-0134 [MEDIUM] CVE-2003-0134: apache2 - Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 thro... Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names. Scope: local bookworm: resolved (fixed in 2.0.46) bullseye: resolved (fixed in 2.0.46) forky: resolved (fixed in 2.0.46) sid: resolved (fixed in 2.0.46) trixie: resolved (fixed in 2.0.
debian
CVE-2003-0083MEDIUMCVSS 5.0PoCfixed in apache2 2.0.46 (bookworm)2003
CVE-2003-0083 [MEDIUM] CVE-2003-0083: apache2 - Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter te... Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020. Scope: local bookworm: resolved (fixed in 2.0.46)
debian
CVE-2003-0189MEDIUMCVSS 5.0fixed in apache2 2.0.46 (bookworm)2003
CVE-2003-0189 [MEDIUM] CVE-2003-0189: apache2 - The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not prop... The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used. Scope: local bookworm: resolved (fixed in 2.0.46) bullseye: resol
debian
CVE-2003-0254MEDIUMCVSS 5.0fixed in apache2 2.0.47 (bookworm)2003
CVE-2003-0254 [MEDIUM] CVE-2003-0254: apache2 - Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause ... Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket. Scope: local bookworm: resolved (fixed in 2.0.47) bullseye: resolved (fixed in 2.0.47) forky: resolved (fixed in 2.0.47) sid: resolved (fixed in 2.0.47) trixie: resolved (fixe
debian
CVE-2003-0245MEDIUMCVSS 5.0PoCfixed in apache2 2.0.46 (bookworm)2003
CVE-2003-0245 [MEDIUM] CVE-2003-0245: apache2 - Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) ... Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors. Scope: local bookworm: resolved (fixed in 2.0.46) bullseye
debian
CVE-2003-0253MEDIUMCVSS 5.0fixed in apache2 2.0.47 (bookworm)2003
CVE-2003-0253 [MEDIUM] CVE-2003-0253: apache2 - The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain error... The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service. Scope: local bookworm: resolved (fixed in 2.0.47) bullseye: resolved (fixed in 2.0.47) forky: resolved (fixed in 2.0.47) sid: resolved (fixed in 2.0.47) trixie: resolved (fixed in 2.0.47)
debian
CVE-2003-0192MEDIUMCVSS 6.4fixed in apache2 2.0.47 (bookworm)2003
CVE-2003-0192 [MEDIUM] CVE-2003-0192: apache2 - Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not p... Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite. Scope: local bookworm: resolved (fixed in 2.0.47) bullseye: resolved (f
debian
CVE-2003-0132MEDIUMCVSS 5.0PoCfixed in apache2 2.0.45 (bookworm)2003
CVE-2003-0132 [MEDIUM] CVE-2003-0132: apache2 - A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a de... A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed. Scope: local bookworm: resolved (fixed in 2.0.45) bullseye: resolved (fixed in 2.0.45) forky: resolved (fixed in 2.0.45) sid: resolved (fixed in 2.0.4
debian
CVE-2003-0020MEDIUMCVSS 5.0PoCfixed in apache2 2.0.49 (bookworm)2003
CVE-2003-0020 [MEDIUM] CVE-2003-0020: apache2 - Apache does not filter terminal escape sequences from its error logs, which coul... Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences. Scope: local bookworm: resolved (fixed in 2.0.49) bullseye: resolved (fixed in 2.0.49) forky: resolved (fixed in 2.0.49) sid: resolved (fixed in 2.0.49
debian
CVE-2003-1138LOWCVSS 5.0PoC2003
CVE-2003-1138 [MEDIUM] CVE-2003-1138: apache2 - The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, a... The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//). Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2003-1581LOWCVSS 2.62003
CVE-2003-1581 [LOW] CVE-2003-1581: apache2 - The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addr... The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue. Scope: local bookworm: open bullseye: open forky: op
debian
CVE-2003-1580LOWCVSS 4.32003
CVE-2003-1580 [MEDIUM] CVE-2003-1580: apache2 - The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addr... The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, re
debian
CVE-2003-1307LOWCVSS 4.3PoC2003
CVE-2003-1307 [MEDIUM] CVE-2003-1307: apache2 - The mod_php module for the Apache HTTP Server allows local users with write acce... The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened fi
debian
CVE-2002-1850HIGHCVSS 7.5PoCfixed in apache2 2.0.42-1 (bookworm)2002
CVE-2002-1850 [HIGH] CVE-2002-1850: apache2 - mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attac... mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script. Scope: local bookworm: resolved (fixed in 2.0.42-1) bullseye: resolved (fixed in 2.0.42
debian
CVE-2002-0661HIGHCVSS 7.5PoCfixed in apache2 2.0.40 (bookworm)2002
CVE-2002-0661 [HIGH] CVE-2002-0661: apache2 - Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, ... Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters. Scope: local bookworm: resolved (fixed in 2.0.40) bullseye: resolved (fixed in 2.0.40) forky: resolved (fixed in 2.0.40) sid: resolved (fixed in
debian
CVE-2002-0392HIGHCVSS 7.5PoCfixed in apache2 2.0.37 (bookworm)2002
CVE-2002-0392 [HIGH] CVE-2002-0392: apache2 - Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attacker... Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. Scope: local bookworm: resolved (fixed in 2.0.37) bullseye: resolved (fixed in 2.0.37) forky: resolved (fixed in 2.0.37) sid: resolved (fixed in
debian
CVE-2002-1593MEDIUMCVSS 5.0fixed in apache2 2.0.42 (bookworm)2002
CVE-2002-1593 [MEDIUM] CVE-2002-1593: apache2 - mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which... mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module. Scope: local bookworm: resolved (fixed in 2.0.42) bullseye: resolved (fixed in 2.0.42) forky: resolved (fixed in 2.0.42) sid:
debian
CVE-2002-0654MEDIUMCVSS 5.0PoCfixed in apache2 2.0.40 (bookworm)2002
CVE-2002-0654 [MEDIUM] CVE-2002-0654: apache2 - Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers t... Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked. Scope: local bookworm: resolved (fixed in 2.0.40) bullseye: res
debian
CVE-2002-1592MEDIUMCVSS 5.0fixed in apache2 2.0.36 (bookworm)2002
CVE-2002-1592 [MEDIUM] CVE-2002-1592: apache2 - The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application e... The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information. Scope: local bookworm: resolved (fixed in 2.0.36) bullseye: resolved (fixed in 2.0.36) forky: resolved (fixed in 2.0.36) sid: r
debian
CVE-2002-0840MEDIUMCVSS 6.8PoCfixed in apache2 2.0.43-1 (bookworm)2002
CVE-2002-0840 [MEDIUM] CVE-2002-0840: apache2 - Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0... Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157. Scope: local bookworm: resolved (fixed
debian