cbcvebase.

Debian Apache2 vulnerabilities

215 known vulnerabilities affecting debian/apache2.

Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52

Vulnerabilities

Page 7 of 11
CVE-2023-31122P3HIGHCVSS 7.5fixed in apache2 2.4.59-1~deb12u1 (bookworm)2023
CVE-2023-31122 [HIGH] CVE-2023-31122: apache2 - Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue a... Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57. Scope: local bookworm: resolved (fixed in 2.4.59-1~deb12u1) bullseye: resolved (fixed in 2.4.59-1~deb11u1) forky: resolved (fixed in 2.4.58-1) sid: resolved (fixed in 2.4.58-1) trixie: resolved (fixed in 2.4.58-1)
debian
CVE-2019-0196P3MEDIUMCVSS 5.3fixed in apache2 2.4.38-3 (bookworm)2019
CVE-2019-0196 [MEDIUM] CVE-2019-0196: apache2 - A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed n... A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly. Scope: local bookworm: resolved (fixed in 2.4.38-3) bullseye: resolved (fixed in 2.4.38-3) forky: resolve
debian
CVE-2014-0231P3MEDIUMCVSS 5.0fixed in apache2 2.4.10-1 (bookworm)2014
CVE-2014-0231 [MEDIUM] CVE-2014-0231: apache2 - The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a time... The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor. Scope: local bookworm: resolved (fixed in 2.4.10-1) bullseye: resolved (fixed in 2.4.10-1) forky: resolved (fixed in 2
debian
CVE-2025-49630P3HIGHCVSS 7.5fixed in apache2 2.4.65-1~deb12u1 (bookworm)2025
CVE-2025-49630 [HIGH] CVE-2025-49630: apache2 - In certain proxy configurations, a denial of service attack against Apache HTTP ... In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on". Scope: local bookworm: resolved (fixed in 2.4.65-1~
debian
CVE-2012-0031P4LOWCVSS 4.6PoCfixed in apache2 2.2.22-1 (bookworm)2012
CVE-2012-0031 [MEDIUM] CVE-2012-0031: apache2 - scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local user... scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function. Scope: local bookworm: resolved (fixed in 2.2.22-1) bullse
debian
CVE-2022-29404P3HIGHCVSS 7.5fixed in apache2 2.4.54-1 (bookworm)2022
CVE-2022-29404 [HIGH] CVE-2022-29404: apache2 - In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script th... In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. Scope: local bookworm: resolved (fixed in 2.4.54-1) bullseye: resolved (fixed in 2.4.54-1~deb11u1) forky: resolved (fixed in 2.4.54-1) sid: resolved (fixed in 2.4.54-1) trixie: resolved
debian
CVE-2018-1301P3MEDIUMCVSS 5.9fixed in apache2 2.4.33-1 (bookworm)2018
CVE-2018-1301 [MEDIUM] CVE-2018-1301: apache2 - A specially crafted request could have crashed the Apache HTTP Server prior to v... A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage. Scope: loc
debian
CVE-2023-27522P3HIGHCVSS 7.5fixed in apache2 2.4.56-1 (bookworm)2023
CVE-2023-27522 [HIGH] CVE-2023-27522: apache2 - HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi.... HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. Scope: local bookworm: resolved (fixed in 2.4.56-1) bullseye: resolved (fixed in 2.4.56-1~deb11u1) forky: resolved
debian
CVE-2014-8109P3MEDIUMCVSS 4.3fixed in apache2 2.4.10-9 (bookworm)2014
CVE-2014-8109 [MEDIUM] CVE-2014-8109: apache2 - mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x throug... mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require dir
debian
CVE-2018-17189P3LOWCVSS 5.3fixed in apache2 2.4.38-1 (bookworm)2018
CVE-2018-17189 [MEDIUM] CVE-2018-17189: apache2 - In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a ... In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections. Scope: local bookworm: resolved (fixed in 2.4.38-1) bullseye: resolved (fixed in 2.4.38-1) forky: r
debian
CVE-2014-0118P3MEDIUMCVSS 4.3fixed in apache2 2.4.10-1 (bookworm)2014
CVE-2014-0118 [MEDIUM] CVE-2014-0118: apache2 - The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the... The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size. Scope: local bookworm: resolved (fixed in 2.4.10-1) bullseye: resol
debian
CVE-2006-20001P3HIGHCVSS 7.5fixed in apache2 2.4.55-1 (bookworm)2006
CVE-2006-20001 [HIGH] CVE-2006-20001: apache2 - A carefully crafted If: request header can cause a memory read, or write of a si... A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier. Scope: local bookworm: resolved (fixed in 2.4.55-1) bullseye: resolved (fixed in 2.4.56-1~deb11u1) forky: resolv
debian
CVE-2009-1890P3MEDIUMCVSS 7.1fixed in apache2 2.2.11-7 (bookworm)2009
CVE-2009-1890 [HIGH] CVE-2009-1890: apache2 - The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in th... The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests. Scope: local bookworm: resolv
debian
CVE-2025-65082P3MEDIUMCVSS 6.5fixed in apache2 2.4.66-1~deb12u1 (bookworm)2025
CVE-2025-65082 [MEDIUM] CVE-2025-65082: apache2 - Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in A... Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes
debian
CVE-2013-6438P3MEDIUMCVSS 5.0fixed in apache2 2.4.9-1 (bookworm)2013
CVE-2013-6438 [MEDIUM] CVE-2013-6438: apache2 - The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apach... The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request. Scope: local bookworm: resolved (fixed in 2.4.9-1) bullseye: resolved (fixed in 2.4.9-
debian
CVE-2019-0220P3MEDIUMCVSS 5.3fixed in apache2 2.4.38-3 (bookworm)2019
CVE-2019-0220 [MEDIUM] CVE-2019-0220: apache2 - A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path c... A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them. Scope: local bookworm: resolved (fixed i
debian
CVE-2009-3095P3LOWCVSS 5.0fixed in apache2 2.2.13-2 (bookworm)2009
CVE-2009-3095 [MEDIUM] CVE-2009-3095: apache2 - The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to by... The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. Scope: local bookworm: resolved (fixed in 2.2.1
debian
CVE-2009-1891P3MEDIUMCVSS 7.1fixed in apache2 2.2.11-7 (bookworm)2009
CVE-2009-1891 [HIGH] CVE-2009-1891: apache2 - The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files... The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption). Scope: local bookworm: resolved (fixed in 2.2.11-7) bullseye: resolved (fixed in 2.2.11-7) forky: resolved (fixed in 2.2.11-7) sid: resolv
debian
CVE-2018-1302P3MEDIUMCVSS 5.9fixed in apache2 2.4.33-1 (bookworm)2018
CVE-2018-1302 [MEDIUM] CVE-2018-1302: apache2 - When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server ... When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is cla
debian
CVE-2004-0885P3HIGHCVSS 7.5fixed in apache2 2.0.52-2 (bookworm)2004
CVE-2004-0885 [HIGH] CVE-2004-0885: apache2 - The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSui... The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration. Scope: local bookworm: resolved (fixed in 2.0.52-2) bullseye: resolved (fixed in 2.0.52-2) forky: resolved (fix
debian
Debian Apache2 vulnerabilities | cvebase