Debian Apache2 vulnerabilities
215 known vulnerabilities affecting debian/apache2.
Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52
Vulnerabilities
Page 4 of 11
CVE-2003-0245P3MEDIUMCVSS 5.0PoCfixed in apache2 2.0.46 (bookworm)2003
CVE-2003-0245 [MEDIUM] CVE-2003-0245: apache2 - Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) ...
Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
Scope: local
bookworm: resolved (fixed in 2.0.46)
bullseye
debian
CVE-2024-39573P3HIGHCVSS 7.5fixed in apache2 2.4.61-1~deb12u1 (bookworm)2024
CVE-2024-39573 [HIGH] CVE-2024-39573: apache2 - Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an...
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Scope: local
bookworm: resolved (fixed in 2.4.61-1~deb12u1)
bullseye: resolved (fixed in 2.4.61-1~deb11u1)
forky: res
debian
CVE-2021-31618P3HIGHCVSS 7.5fixed in apache2 2.4.46-5 (bookworm)2021
CVE-2021-31618 [HIGH] CVE-2021-31618: apache2 - Apache HTTP Server protocol handler for the HTTP/2 protocol checks received requ...
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully ini
debian
CVE-2006-3918P4LOWCVSS 4.3PoCfixed in apache2 2.0.55-4.1 (bookworm)2006
CVE-2006-3918 [MEDIUM] CVE-2006-3918: apache2 - http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0....
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that ca
debian
CVE-2008-0455P4LOWCVSS 4.3PoCfixed in apache2 2.2.22-8 (bookworm)2008
CVE-2008-0455 [MEDIUM] CVE-2008-0455: apache2 - Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Ap...
Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extensio
debian
CVE-2003-0132P4MEDIUMCVSS 5.0PoCfixed in apache2 2.0.45 (bookworm)2003
CVE-2003-0132 [MEDIUM] CVE-2003-0132: apache2 - A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a de...
A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.
Scope: local
bookworm: resolved (fixed in 2.0.45)
bullseye: resolved (fixed in 2.0.45)
forky: resolved (fixed in 2.0.45)
sid: resolved (fixed in 2.0.4
debian
CVE-2007-6203P4LOWCVSS 4.3PoCfixed in apache2 2.2.6-3 (bookworm)2007
CVE-2007-6203 [MEDIUM] CVE-2007-6203: apache2 - Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier h...
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an in
debian
CVE-2020-13950P3HIGHCVSS 7.5fixed in apache2 2.4.46-6 (bookworm)2020
CVE-2020-13950 [HIGH] CVE-2020-13950: apache2 - Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash...
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service
Scope: local
bookworm: resolved (fixed in 2.4.46-6)
bullseye: resolved (fixed in 2.4.46-6)
forky: resolved (fixed in 2.4.46-6)
sid: resolved
debian
CVE-2016-4979P3HIGHCVSS 7.5fixed in apache2 2.4.23-1 (bookworm)2016
CVE-2016-4979 [HIGH] CVE-2016-4979: apache2 - The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are ena...
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.
Scope:
debian
CVE-2022-31813P3CRITICALCVSS 9.8fixed in apache2 2.4.54-1 (bookworm)2022
CVE-2022-31813 [CRITICAL] CVE-2022-31813: apache2 - Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to ...
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
Scope: local
bookworm: resolved (fixed in 2.4.54-1)
bullseye: resolved (fixed in 2.4.54-1~deb11u1)
forky: resolved (fixe
debian
CVE-2024-38474P3CRITICALCVSS 9.8fixed in apache2 2.4.61-1~deb12u1 (bookworm)2024
CVE-2024-38474 [CRITICAL] CVE-2024-38474: apache2 - Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earl...
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRule
debian
CVE-2017-3169P3CRITICALCVSS 9.8fixed in apache2 2.4.25-4 (bookworm)2017
CVE-2017-3169 [CRITICAL] CVE-2017-3169: apache2 - In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may derefer...
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
Scope: local
bookworm: resolved (fixed in 2.4.25-4)
bullseye: resolved (fixed in 2.4.25-4)
forky: resolved (fixed in 2.4.25-4)
sid: resolved (fixed in 2.4.25-4)
trixi
debian
CVE-2019-17567P3MEDIUMCVSS 5.3fixed in apache2 2.4.48-2 (bookworm)2019
CVE-2019-17567 [MEDIUM] CVE-2019-17567: apache2 - Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an ...
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
Scope: local
bookworm: res
debian
CVE-2008-2168P4LOWCVSS 4.3PoCfixed in apache2 2.2.8-1 (bookworm)2008
CVE-2008-2168 [MEDIUM] CVE-2008-2168: apache2 - Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remo...
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
Scope: local
bookworm: resolved (fixed in 2.2.8-1)
bullseye: resolved (fixed in 2.2.8-1)
forky: resolved (fixed in 2.2.8-1)
sid: resolved
debian
CVE-2021-41524P3HIGHCVSS 7.5fixed in apache2 2.4.50-1 (bookworm)2021
CVE-2021-41524 [HIGH] CVE-2021-41524: apache2 - While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected duri...
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
Scope: local
bookworm: resolved (fixed in 2.4.50-1)
bullseye: resolved
debian
CVE-2019-0217P3HIGHCVSS 7.5fixed in apache2 2.4.38-3 (bookworm)2019
CVE-2019-0217 [HIGH] CVE-2019-0217: apache2 - In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth...
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
Scope: local
bookworm: resolved (fixed in 2.4.38-3)
bullseye: resolved (fixed in 2.4.38-3)
forky: resolved (fixed in
debian
CVE-2002-1850P3HIGHCVSS 7.5PoCfixed in apache2 2.0.42-1 (bookworm)2002
CVE-2002-1850 [HIGH] CVE-2002-1850: apache2 - mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attac...
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
Scope: local
bookworm: resolved (fixed in 2.0.42-1)
bullseye: resolved (fixed in 2.0.42
debian
CVE-2015-3183P3MEDIUMCVSS 5.0fixed in apache2 2.4.16-1 (bookworm)2015
CVE-2015-3183 [MEDIUM] CVE-2015-3183: apache2 - The chunked transfer coding implementation in the Apache HTTP Server before 2.4....
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.
Scope: local
bookworm: resolve
debian
CVE-2022-26377P3HIGHCVSS 7.5fixed in apache2 2.4.54-1 (bookworm)2022
CVE-2022-26377 [HIGH] CVE-2022-26377: apache2 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab...
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
Scope: local
bookworm: resolved (fixed in 2.4.54-1)
bullseye: res
debian
CVE-2004-0942P4MEDIUMCVSS 5.0PoCfixed in apache2 2.0.52-2 (bookworm)2004
CVE-2004-0942 [MEDIUM] CVE-2004-0942: apache2 - Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of...
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
Scope: local
bookworm: resolved (fixed in 2.0.52-2)
bullseye: resolved (fixed in 2.0.52-2)
forky: resolved (fixed in 2.0.52-2)
sid: resolved (fixed in
debian