Debian Apache2 vulnerabilities
215 known vulnerabilities affecting debian/apache2.
Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52
Vulnerabilities
Page 3 of 11
CVE-2024-27316P3HIGHCVSS 7.5fixed in apache2 2.4.59-1~deb12u1 (bookworm)2024
CVE-2024-27316 [HIGH] CVE-2024-27316: apache2 - HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 ...
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Scope: local
bookworm: resolved (fixed in 2.4.59-1~deb12u1)
bullseye: resolved (fixed in 2.4.59-1~deb11u1)
forky: resolved (fixed in 2.4.59-1)
sid: resolved
debian
CVE-2011-3639P3MEDIUMCVSS 5.0PoCfixed in apache2 2.2.18-1 (bookworm)2011
CVE-2011-3639 [MEDIUM] CVE-2011-3639: apache2 - The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x be...
The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol
debian
CVE-2023-43622P2HIGHCVSS 7.5fixed in apache2 2.4.59-1~deb12u1 (bookworm)2023
CVE-2023-43622 [HIGH] CVE-2023-43622: apache2 - An attacker, opening a HTTP/2 connection with an initial window size of 0, was a...
An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern. This has been fixed in version 2.4.58, so that such connection are terminated properly after t
debian
CVE-2022-22720P2CRITICALCVSS 9.8fixed in apache2 2.4.53-1 (bookworm)2022
CVE-2022-22720 [CRITICAL] CVE-2022-22720: apache2 - Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when err...
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
Scope: local
bookworm: resolved (fixed in 2.4.53-1)
bullseye: resolved (fixed in 2.4.53-1~deb11u1)
forky: resolved (fixed in 2.4.53-1)
sid: resolved (fixed in 2.4.53-1)
trixie: resolved (fi
debian
CVE-2022-22721P2CRITICALCVSS 9.1fixed in apache2 2.4.53-1 (bookworm)2022
CVE-2022-22721 [CRITICAL] CVE-2022-22721: apache2 - If LimitXMLRequestBody is set to allow request bodies larger than 350MB (default...
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
Scope: local
bookworm: resolved (fixed in 2.4.53-1)
bullseye: resolved (fixed in 2.4.53-1~deb11u1)
forky: resolved (fixed in 2.4.5
debian
CVE-2022-22719P2HIGHCVSS 7.5fixed in apache2 2.4.53-1 (bookworm)2022
CVE-2022-22719 [HIGH] CVE-2022-22719: apache2 - A carefully crafted request body can cause a read to a random memory area which ...
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
Scope: local
bookworm: resolved (fixed in 2.4.53-1)
bullseye: resolved (fixed in 2.4.53-1~deb11u1)
forky: resolved (fixed in 2.4.53-1)
sid: resolved (fixed in 2.4.53-1)
trixie: resolved (fixed in
debian
CVE-2016-4975P3LOWCVSS 6.1PoCfixed in apache2 2.4.25-1 (bookworm)2016
CVE-2016-4975 [MEDIUM] CVE-2016-4975: apache2 - Possible CRLF injection allowing HTTP response splitting attacks for sites which...
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.
debian
CVE-2005-1344P3HIGHCVSS 7.5PoCfixed in apache2 2.0.54-3 (bookworm)2005
CVE-2005-1344 [HIGH] CVE-2005-1344: apache2 - Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbi...
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
debian
CVE-2021-36160P2HIGHCVSS 7.5fixed in apache2 2.4.49-1 (bookworm)2021
CVE-2021-36160 [HIGH] CVE-2021-36160: apache2 - A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the...
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
Scope: local
bookworm: resolved (fixed in 2.4.49-1)
bullseye: resolved (fixed in 2.4.51-1~deb11u1)
forky: resolved (fixed in 2.4.49-1)
sid: resolved (fixed in 2.4.49-1)
trixie:
debian
CVE-2020-35452P2HIGHCVSS 7.3fixed in apache2 2.4.46-6 (bookworm)2020
CVE-2020-35452 [HIGH] CVE-2020-35452: apache2 - Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can...
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a singl
debian
CVE-2016-5387P3HIGHCVSS 8.1fixed in apache2 2.4.23-2 (bookworm)2016
CVE-2016-5387 [HIGH] CVE-2016-5387: apache2 - The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and theref...
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "htt
debian
CVE-2004-0751P3MEDIUMCVSS 5.0PoCfixed in apache2 2.0.50-11 (bookworm)2004
CVE-2004-0751 [MEDIUM] CVE-2004-0751: apache2 - The char_buffer_read function in the mod_ssl module for Apache 2.x, when using r...
The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
Scope: local
bookworm: resolved (fixed in 2.0.50-11)
bullseye: resolved (fixed in 2.0.50-11)
forky: resolved (fixed in 2.0.50-11)
sid: resolved (fixed in 2.0.50-11)
trixie: resolv
debian
CVE-2017-3167P2CRITICALCVSS 9.8fixed in apache2 2.4.25-4 (bookworm)2017
CVE-2017-3167 [CRITICAL] CVE-2017-3167: apache2 - In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_b...
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
Scope: local
bookworm: resolved (fixed in 2.4.25-4)
bullseye: resolved (fixed in 2.4.25-4)
forky: resolved (fixed in 2.4.25-4)
sid: resolved (fixed in 2.4.2
debian
CVE-2002-0840P4MEDIUMCVSS 6.8PoCfixed in apache2 2.0.43-1 (bookworm)2002
CVE-2002-0840 [MEDIUM] CVE-2002-0840: apache2 - Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0...
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
Scope: local
bookworm: resolved (fixed
debian
CVE-2021-34798P3HIGHCVSS 7.5fixed in apache2 2.4.49-1 (bookworm)2021
CVE-2021-34798 [HIGH] CVE-2021-34798: apache2 - Malformed requests may cause the server to dereference a NULL pointer. This issu...
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
Scope: local
bookworm: resolved (fixed in 2.4.49-1)
bullseye: resolved (fixed in 2.4.51-1~deb11u1)
forky: resolved (fixed in 2.4.49-1)
sid: resolved (fixed in 2.4.49-1)
trixie: resolved (fixed in 2.4.49-1)
debian
CVE-2018-1312P2CRITICALCVSS 9.8fixed in apache2 2.4.33-1 (bookworm)2018
CVE-2018-1312 [CRITICAL] CVE-2018-1312: apache2 - In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication c...
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
Scope: local
bookworm:
debian
CVE-2017-7679P3CRITICALCVSS 9.8fixed in apache2 2.4.25-4 (bookworm)2017
CVE-2017-7679 [CRITICAL] CVE-2017-7679: apache2 - In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read o...
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
Scope: local
bookworm: resolved (fixed in 2.4.25-4)
bullseye: resolved (fixed in 2.4.25-4)
forky: resolved (fixed in 2.4.25-4)
sid: resolved (fixed in 2.4.25-4)
trixie: resolved (fixed in 2.4.25-4)
debian
CVE-2021-26690P3HIGHCVSS 7.5fixed in apache2 2.4.46-6 (bookworm)2021
CVE-2021-26690 [HIGH] CVE-2021-26690: apache2 - Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header ha...
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service
Scope: local
bookworm: resolved (fixed in 2.4.46-6)
bullseye: resolved (fixed in 2.4.46-6)
forky: resolved (fixed in 2.4.46-6)
sid: resolved (fixed in 2.4.46-6)
trixie: resolved (
debian
CVE-2020-11993P3HIGHCVSS 7.5fixed in apache2 2.4.46-1 (bookworm)2020
CVE-2020-11993 [HIGH] CVE-2020-11993: apache2 - Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for th...
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
Scope: local
bookworm: resolved (
debian
CVE-2021-33193P3HIGHCVSS 7.5fixed in apache2 2.4.48-4 (bookworm)2021
CVE-2021-33193 [HIGH] CVE-2021-33193: apache2 - A crafted method sent through HTTP/2 will bypass validation and be forwarded by ...
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
Scope: local
bookworm: resolved (fixed in 2.4.48-4)
bullseye: resolved (fixed in 2.4.48-3.1+deb11u1)
forky: resolved (fixed in 2.4.48-4)
sid: resolved (fixed in 2.4.
debian