cbcvebase.

Debian Apache2 vulnerabilities

215 known vulnerabilities affecting debian/apache2.

Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52

Vulnerabilities

Page 6 of 11
CVE-2016-8743P3HIGHCVSS 7.5fixed in apache2 2.4.25-1 (bookworm)2016
CVE-2016-8743 [HIGH] CVE-2016-8743: apache2 - Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in t... Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI
debian
CVE-2019-10081P3HIGHCVSS 7.5fixed in apache2 2.4.41-1 (bookworm)2019
CVE-2019-10081 [HIGH] CVE-2019-10081: apache2 - HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H... HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client. Scope: local bookworm: resolved (fixed in 2.4.41-1) bullseye: resolved (fixed in 2
debian
CVE-2018-1333P3HIGHCVSS 7.5fixed in apache2 2.4.34-1 (bookworm)2018
CVE-2018-1333 [HIGH] CVE-2018-1333: apache2 - By specially crafting HTTP/2 requests, workers would be allocated 60 seconds lon... By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33). Scope: local bookworm: resolved (fixed in 2.4.34-1) bullseye: resolved (fixed in 2.4.34-1) forky: resolved (fixed in 2.4.34-1) sid: resolved (fixed
debian
CVE-2003-0083P4MEDIUMCVSS 5.0PoCfixed in apache2 2.0.46 (bookworm)2003
CVE-2003-0083 [MEDIUM] CVE-2003-0083: apache2 - Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter te... Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020. Scope: local bookworm: resolved (fixed in 2.0.46)
debian
CVE-2024-38477P3HIGHCVSS 7.5fixed in apache2 2.4.61-1~deb12u1 (bookworm)2024
CVE-2024-38477 [HIGH] CVE-2024-38477: apache2 - null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier a... null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Scope: local bookworm: resolved (fixed in 2.4.61-1~deb12u1) bullseye: resolved (fixed in 2.4.61-1~deb11u1) forky: resolved (fixed in 2.4.60-1) sid: r
debian
CVE-2025-53020P3HIGHCVSS 7.5fixed in apache2 2.4.65-1~deb12u1 (bookworm)2025
CVE-2025-53020 [HIGH] CVE-2025-53020: apache2 - Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Ser... Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue. Scope: local bookworm: resolved (fixed in 2.4.65-1~deb12u1) bullseye: resolved (fixed in 2.4.65-1~deb11u1) forky: resolved (fixed in 2.4.64-1)
debian
CVE-2023-38709P3HIGHCVSS 7.3fixed in apache2 2.4.59-1~deb12u1 (bookworm)2023
CVE-2023-38709 [HIGH] CVE-2023-38709: apache2 - Faulty input validation in the core of Apache allows malicious or exploitable ba... Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. Scope: local bookworm: resolved (fixed in 2.4.59-1~deb12u1) bullseye: resolved (fixed in 2.4.59-1~deb11u1) forky: resolved (fixed in 2.4.59-1) sid: resolved (fixed in 2.4.59-1) trixie
debian
CVE-2013-1862P3LOWCVSS 5.1fixed in apache2 2.4.1-1 (bookworm)2013
CVE-2013-1862 [MEDIUM] CVE-2013-1862: apache2 - mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2... mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator. Scope: local bookworm: resolved (fixed in 2.4.1-1) bullseye: resolved (
debian
CVE-2024-43394P3LOWCVSS 7.5fixed in apache2 2.4.65-1~deb11u1 (bullseye)2024
CVE-2024-43394 [HIGH] CVE-2024-43394: apache2 - Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to po... Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.63. Note: The Apache HTTP Server Project will be setting a higher bar for accepting vulnerability repo
debian
CVE-2024-43204P3HIGHCVSS 7.5fixed in apache2 2.4.65-1~deb12u1 (bookworm)2024
CVE-2024-43204 [HIGH] CVE-2024-43204: apache2 - SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outb... SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header with a value provided in the HTTP request. Users are recommended to upgrade to version 2.4.64 which fixes this
debian
CVE-2022-30556P3HIGHCVSS 7.5fixed in apache2 2.4.54-1 (bookworm)2022
CVE-2022-30556 [HIGH] CVE-2022-30556: apache2 - Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling... Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer. Scope: local bookworm: resolved (fixed in 2.4.54-1) bullseye: resolved (fixed in 2.4.54-1~deb11u1) forky: resolved (fixed in 2.4.54-1) sid: resolved (fixed in 2.4.54-1) trixie: resolved (fixed in 2.4.54-1)
debian
CVE-2013-2249P3HIGHCVSS 7.5fixed in apache2 2.4.6-1 (bookworm)2013
CVE-2013-2249 [HIGH] CVE-2013-2249: apache2 - mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before... mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (
debian
CVE-2024-47252P3HIGHCVSS 7.5fixed in apache2 2.4.65-1~deb12u1 (bookworm)2024
CVE-2024-47252 [HIGH] CVE-2024-47252: apache2 - Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4... Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed
debian
CVE-2025-55753P3HIGHCVSS 7.5fixed in apache2 2.4.66-1~deb12u1 (bookworm)2025
CVE-2025-55753 [HIGH] CVE-2025-55753: apache2 - An integer overflow in the case of failed ACME certificate renewal leads, after ... An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version
debian
CVE-2015-3185P3MEDIUMCVSS 4.3fixed in apache2 2.4.16-1 (bookworm)2015
CVE-2015-3185 [MEDIUM] CVE-2015-3185: apache2 - The ap_some_auth_required function in server/request.c in the Apache HTTP Server... The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a modul
debian
CVE-2003-0020P4MEDIUMCVSS 5.0PoCfixed in apache2 2.0.49 (bookworm)2003
CVE-2003-0020 [MEDIUM] CVE-2003-0020: apache2 - Apache does not filter terminal escape sequences from its error logs, which coul... Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences. Scope: local bookworm: resolved (fixed in 2.0.49) bullseye: resolved (fixed in 2.0.49) forky: resolved (fixed in 2.0.49) sid: resolved (fixed in 2.0.49
debian
CVE-2007-6388P4LOWCVSS 4.3fixed in apache2 2.2.8-1 (bookworm)2007
CVE-2007-6388 [MEDIUM] CVE-2007-6388: apache2 - Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server... Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 2.2.8-1) bullseye: resolved (fixed in 2.2.8-1)
debian
CVE-2025-49812P3HIGHCVSS 7.4fixed in apache2 2.4.65-1~deb12u1 (bookworm)2025
CVE-2025-49812 [HIGH] CVE-2025-49812: apache2 - In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63,... In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade
debian
CVE-2024-42516P3HIGHCVSS 7.3fixed in apache2 2.4.65-1~deb12u1 (bookworm)2024
CVE-2024-42516 [HIGH] CVE-2024-42516: apache2 - HTTP response splitting in the core of Apache HTTP Server allows an attacker who... HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrad
debian
CVE-2005-3352P4LOWCVSS 4.3fixed in apache2 2.0.55-4 (bookworm)2005
CVE-2005-3352 [MEDIUM] CVE-2005-3352: apache2 - Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd ... Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps. Scope: local bookworm: resolved (fixed in 2.0.55-4) bullseye: resolved (fixed in 2.0.55-4) forky: resolved (fixed in 2.0.55-4)
debian
Debian Apache2 vulnerabilities | cvebase