cbcvebase.

Debian Apache2 vulnerabilities

215 known vulnerabilities affecting debian/apache2.

Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52

Vulnerabilities

Page 5 of 11
CVE-2019-10082P3CRITICALCVSS 9.1fixed in apache2 2.4.41-1 (bookworm)2019
CVE-2019-10082 [CRITICAL] CVE-2019-10082: apache2 - In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 sess... In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown. Scope: local bookworm: resolved (fixed in 2.4.41-1) bullseye: resolved (fixed in 2.4.41-1) forky: resolved (fixed in 2.4.41-1) sid: resolved (fixed in 2.4.41-1) trixie: resolved (fixed in 2.4.41-
debian
CVE-2013-5704P3MEDIUMCVSS 5.0fixed in apache2 2.4.10-2 (bookworm)2013
CVE-2013-5704 [MEDIUM] CVE-2013-5704: apache2 - The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers ... The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such." Scope: local bookworm: resolved (fixed in 2.4.10-2) bullseye: resolved (fixed in 2.4.1
debian
CVE-2025-23048P3CRITICALCVSS 9.1fixed in apache2 2.4.65-1~deb12u1 (bookworm)2025
CVE-2025-23048 [CRITICAL] CVE-2025-23048: apache2 - In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, a... In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertif
debian
CVE-2019-9517P3HIGHCVSS 7.5fixed in apache2 2.4.41-1 (bookworm)2019
CVE-2019-9517 [HIGH] CVE-2019-9517: apache2 - Some HTTP/2 implementations are vulnerable to unconstrained interal data bufferi... Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a larg
debian
CVE-2005-2700P3MEDIUMCVSS 10.0fixed in apache2 2.0.54-5 (bookworm)2005
CVE-2005-2700 [CRITICAL] CVE-2005-2700: apache2 - ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient option... ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions. Scope: local bookworm: resolved (fixed in 2.0.54-5) bullseye: resolved (fixed in 2.0.54-5)
debian
CVE-2022-36760P3CRITICALCVSS 9.0fixed in apache2 2.4.55-1 (bookworm)2022
CVE-2022-36760 [CRITICAL] CVE-2022-36760: apache2 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab... Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions. Scope: local bookworm: resolved (fixed in 2.4.55-1) bullseye:
debian
CVE-2019-0215P3HIGHCVSS 7.5fixed in apache2 2.4.38-3 (bookworm)2019
CVE-2019-0215 [HIGH] CVE-2019-0215: apache2 - In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when usin... In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions. Scope: local bookworm: resolved (fixed in 2.4.38-3) bullseye: resolved (fixed in 2.4.38-3) forky: resolved (fixed in 2.4.38-3) sid: resolved (fixed in 2.4.38-3) tr
debian
CVE-2025-58098P3HIGHCVSS 8.3fixed in apache2 2.4.66-1~deb12u1 (bookworm)2025
CVE-2025-58098 [HIGH] CVE-2025-58098: apache2 - Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled an... Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue. Scope: local bookworm: resolved (fixed in 2.4.66-1~deb12u1) bu
debian
CVE-2004-0488P3HIGHCVSS 7.5fixed in apache2 2.0.50-1 (bookworm)2004
CVE-2004-0488 [HIGH] CVE-2004-0488: apache2 - Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util... Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN. Scope: local bookworm: resolved (fixed in 2.0.50-1) bullseye: resolved (fixed in 2.0.50-1) forky: resolved (fixed
debian
CVE-2022-28615P3CRITICALCVSS 9.1fixed in apache2 2.4.54-1 (bookworm)2022
CVE-2022-28615 [CRITICAL] CVE-2022-28615: apache2 - Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a... Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected. Scope: local bookworm:
debian
CVE-2007-6750P3MEDIUMCVSS 5.0fixed in apache2 2.2.15-3 (bookworm)2007
CVE-2007-6750 [MEDIUM] CVE-2007-6750: apache2 - The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of ... The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15. Scope: local bookworm: resolved (fixed in 2.2.15-3) bullseye: resolved (fixed in 2.2.15-3) forky: resolved (fixed in 2.2.15-3) sid:
debian
CVE-2020-1927P3LOWCVSS 6.1fixed in apache2 2.4.43-1 (bookworm)2020
CVE-2020-1927 [MEDIUM] CVE-2020-1927: apache2 - In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite tha... In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL. Scope: local bookworm: resolved (fixed in 2.4.43-1) bullseye: resolved (fixed in 2.4.43-1) forky: resolved (fixed in 2.4.43-1) sid: resolved (fi
debian
CVE-2020-1934P3LOWCVSS 5.3fixed in apache2 2.4.43-1 (bookworm)2020
CVE-2020-1934 [MEDIUM] CVE-2020-1934: apache2 - In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memor... In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. Scope: local bookworm: resolved (fixed in 2.4.43-1) bullseye: resolved (fixed in 2.4.43-1) forky: resolved (fixed in 2.4.43-1) sid: resolved (fixed in 2.4.43-1) trixie: resolved (fixed in 2.4.43-1)
debian
CVE-2002-0654P4MEDIUMCVSS 5.0PoCfixed in apache2 2.0.40 (bookworm)2002
CVE-2002-0654 [MEDIUM] CVE-2002-0654: apache2 - Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers t... Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked. Scope: local bookworm: resolved (fixed in 2.0.40) bullseye: res
debian
CVE-2018-17199P3LOWCVSS 7.5fixed in apache2 2.4.38-1 (bookworm)2018
CVE-2018-17199 [HIGH] CVE-2018-17199: apache2 - In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the sessi... In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded. Scope: local bookworm: resolved (fixed in 2.4.38-1) bullseye: resolved (fixed in 2.4.38-1) forky: resolve
debian
CVE-2011-3607P4MEDIUMCVSS 4.4PoCfixed in apache2 2.2.21-4 (bookworm)2011
CVE-2011-3607 [MEDIUM] CVE-2011-3607: apache2 - Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP ... Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow. Scope:
debian
CVE-2022-37436P3MEDIUMCVSS 5.3fixed in apache2 2.4.55-1 (bookworm)2022
CVE-2022-37436 [MEDIUM] CVE-2022-37436: apache2 - Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response h... Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client. Scope: local bookworm: resolved (fixed in 2.4.55-1) bullseye: resolved (fixed in 2.4.56-1~deb11
debian
CVE-2016-2161P3HIGHCVSS 7.5fixed in apache2 2.4.25-1 (bookworm)2016
CVE-2016-2161 [HIGH] CVE-2016-2161: apache2 - In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_dige... In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests. Scope: local bookworm: resolved (fixed in 2.4.25-1) bullseye: resolved (fixed in 2.4.25-1) forky: resolved (fixed in 2.4.25-1) sid: resolved (fixed in 2.4.25-1) trixie: resolved (fi
debian
CVE-2017-15710P3HIGHCVSS 7.5fixed in apache2 2.4.33-1 (bookworm)2017
CVE-2017-15710 [HIGH] CVE-2017-15710: apache2 - In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_auth... In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two ch
debian
CVE-2021-30641P3MEDIUMCVSS 5.3fixed in apache2 2.4.46-6 (bookworm)2021
CVE-2021-30641 [MEDIUM] CVE-2021-30641: apache2 - Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with '... Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' Scope: local bookworm: resolved (fixed in 2.4.46-6) bullseye: resolved (fixed in 2.4.46-6) forky: resolved (fixed in 2.4.46-6) sid: resolved (fixed in 2.4.46-6) trixie: resolved (fixed in 2.4.46-6)
debian
Debian Apache2 vulnerabilities | cvebase