Debian Apache2 vulnerabilities
215 known vulnerabilities affecting debian/apache2.
Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52
Vulnerabilities
Page 2 of 11
CVE-2017-7668P2HIGHCVSS 7.5Exploitedfixed in apache2 2.4.25-4 (bookworm)2017
CVE-2017-7668 [HIGH] CVE-2017-7668: apache2 - The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduc...
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.
Scope: local
book
debian
CVE-2018-11763P2MEDIUMCVSS 5.9Exploitedfixed in apache2 2.4.35-1 (bookworm)2018
CVE-2018-11763 [MEDIUM] CVE-2018-11763: apache2 - In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS fr...
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
Scope: local
bookworm: resolved (fixed in 2.4.35-1)
bullseye: resolved (fixed
debian
CVE-2021-44790P1CRITICALCVSS 9.8PoCfixed in apache2 2.4.52-1 (bookworm)2021
CVE-2021-44790 [CRITICAL] CVE-2021-44790: apache2 - A carefully crafted request body can cause a buffer overflow in the mod_lua mult...
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
Scope: local
bookworm: resolved (fixed in 2.4.52-1)
bullseye
debian
CVE-2006-3747P2MEDIUMCVSS 7.6PoCfixed in apache2 2.0.55-4.1 (bookworm)2006
CVE-2006-3747 [HIGH] CVE-2006-3747: apache2 - Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite)...
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rul
debian
CVE-2014-0226P2MEDIUMCVSS 6.8PoCfixed in apache2 2.4.10-1 (bookworm)2014
CVE-2014-0226 [MEDIUM] CVE-2014-0226: apache2 - Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 ...
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_
debian
CVE-2016-8740P2HIGHCVSS 7.5PoCfixed in apache2 2.4.25-1 (bookworm)2016
CVE-2016-8740 [HIGH] CVE-2016-8740: apache2 - The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the P...
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.
Scope: local
bookworm: resolved (fixed in 2.4.25-1)
bullseye: resolved (
debian
CVE-2024-38473P2HIGHCVSS 8.1PoCfixed in apache2 2.4.61-1~deb12u1 (bookworm)2024
CVE-2024-38473 [HIGH] CVE-2024-38473: apache2 - Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows re...
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Scope: local
bookworm: resolved (fixed in 2.4.61-1~deb12u1)
bullseye: resolved (fixed
debian
CVE-2011-3368P3MEDIUMCVSS 5.0PoCfixed in apache2 2.2.21-2 (bookworm)2011
CVE-2011-3368 [MEDIUM] CVE-2011-3368: apache2 - The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x throu...
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign)
debian
CVE-2019-10092P3MEDIUMCVSS 6.1PoCfixed in apache2 2.4.41-1 (bookworm)2019
CVE-2019-10092 [MEDIUM] CVE-2019-10092: apache2 - In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was rep...
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Er
debian
CVE-2002-0661P3HIGHCVSS 7.5PoCfixed in apache2 2.0.40 (bookworm)2002
CVE-2002-0661 [HIGH] CVE-2002-0661: apache2 - Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, ...
Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
Scope: local
bookworm: resolved (fixed in 2.0.40)
bullseye: resolved (fixed in 2.0.40)
forky: resolved (fixed in 2.0.40)
sid: resolved (fixed in
debian
CVE-2021-26691P2CRITICALCVSS 9.8fixed in apache2 2.4.46-6 (bookworm)2021
CVE-2021-26691 [CRITICAL] CVE-2021-26691: apache2 - In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader...
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
Scope: local
bookworm: resolved (fixed in 2.4.46-6)
bullseye: resolved (fixed in 2.4.46-6)
forky: resolved (fixed in 2.4.46-6)
sid: resolved (fixed in 2.4.46-6)
trixie: resolved (fixed in 2.4.46-6)
debian
CVE-2022-23943P2CRITICALCVSS 9.8fixed in apache2 2.4.53-1 (bookworm)2022
CVE-2022-23943 [CRITICAL] CVE-2022-23943: apache2 - Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an att...
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
Scope: local
bookworm: resolved (fixed in 2.4.53-1)
bullseye: resolved (fixed in 2.4.53-1~deb11u1)
forky: resolved (fixed in 2.4.53-1)
sid
debian
CVE-2004-0493P3MEDIUMCVSS 6.4PoCfixed in apache2 2.0.50-1 (bookworm)2004
CVE-2004-0493 [MEDIUM] CVE-2004-0493: apache2 - The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attac...
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
Scope: local
bookworm: resolved (fixed in 2.0.50-1)
bullseye: re
debian
CVE-2021-44224P2HIGHCVSS 8.2fixed in apache2 2.4.52-1 (bookworm)2021
CVE-2021-44224 [HIGH] CVE-2021-44224: apache2 - A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can...
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (include
debian
CVE-2011-4317P3MEDIUMCVSS 5.0PoCfixed in apache2 2.2.21-3 (bookworm)2011
CVE-2011-4317 [MEDIUM] CVE-2011-4317: apache2 - The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x throu...
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a m
debian
CVE-2012-0053P3LOWCVSS 4.3PoCfixed in apache2 2.2.22-1 (bookworm)2012
CVE-2012-0053 [MEDIUM] CVE-2012-0053: apache2 - protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly rest...
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
Scope: local
bookworm: resolved (f
debian
CVE-2020-9490P2HIGHCVSS 7.5fixed in apache2 2.4.46-1 (bookworm)2020
CVE-2020-9490 [HIGH] CVE-2020-9490: apache2 - Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the ...
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
Scope: local
bookworm: resolved (fixed in 2.4.46-1)
debian
CVE-2021-39275P2CRITICALCVSS 9.8fixed in apache2 2.4.49-1 (bookworm)2021
CVE-2021-39275 [CRITICAL] CVE-2021-39275: apache2 - ap_escape_quotes() may write beyond the end of a buffer when given malicious inp...
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
Scope: local
bookworm: resolved (fixed in 2.4.49-1)
bullseye: resolved (fixed in 2.4.51-1~deb11u1)
forky: resolved (fixed
debian
CVE-2022-30522P2HIGHCVSS 7.5fixed in apache2 2.4.54-1 (bookworm)2022
CVE-2022-30522 [HIGH] CVE-2022-30522: apache2 - If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in...
If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.
Scope: local
bookworm: resolved (fixed in 2.4.54-1)
bullseye: resolved (fixed in 2.4.54-1~deb11u1)
forky: resolved (fixed in 2.4.54-1)
sid: resolved (fixed
debian
CVE-2024-38476P2CRITICALCVSS 9.8fixed in apache2 2.4.61-1~deb12u1 (bookworm)2024
CVE-2024-38476 [CRITICAL] CVE-2024-38476: apache2 - Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to...
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Scope: local
bookworm: resolved (fixed in 2.4.61-1~deb12u1)
bullseye: reso
debian