cbcvebase.

Debian Apache2 vulnerabilities

215 known vulnerabilities affecting debian/apache2.

Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52

Vulnerabilities

Page 8 of 11
CVE-2013-1896P3LOWCVSS 4.3fixed in apache2 2.4.6-1 (bookworm)2013
CVE-2013-1896 [MEDIUM] CVE-2013-1896: apache2 - mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine wh... mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI. Scope: local bookwo
debian
CVE-2014-0098P3MEDIUMCVSS 5.0fixed in apache2 2.4.9-1 (bookworm)2014
CVE-2014-0098 [MEDIUM] CVE-2014-0098: apache2 - The log_cookie function in mod_log_config.c in the mod_log_config module in the ... The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation. Scope: local bookworm: resolved (fixed in 2.4.9-1) bullseye: resolved (fixed in 2.4.9-1) forky:
debian
CVE-2018-1283P3MEDIUMCVSS 5.3fixed in apache2 2.4.33-1 (bookworm)2018
CVE-2018-1283 [MEDIUM] CVE-2018-1283: apache2 - In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its s... In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the Apache H
debian
CVE-2025-54090P3LOWCVSS 6.3fixed in apache2 2.4.65-1 (forky)2025
CVE-2025-54090 [MEDIUM] CVE-2025-54090: apache2 - A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests e... A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 2.4.65-1) sid: resolved (fixed in 2.4.65-1) trixie: resolved (fixed in 2.4.65-1)
debian
CVE-2014-0117P4MEDIUMCVSS 4.3fixed in apache2 2.4.10-1 (bookworm)2014
CVE-2014-0117 [MEDIUM] CVE-2014-0117: apache2 - The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a rever... The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header. Scope: local bookworm: resolved (fixed in 2.4.10-1) bullseye: resolved (fixed in 2.4.10-1) forky: resolved (fixed in 2.4.10-1) sid: resolved (fixed in 2.4
debian
CVE-2010-0408P3LOWCVSS 5.0fixed in apache2 2.2.15-1 (bookworm)2010
CVE-2010-0408 [MEDIUM] CVE-2010-0408: apache2 - The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apa... The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate
debian
CVE-2011-4415P4LOWCVSS 4.4PoCfixed in apache2 2.4.1-1 (bookworm)2011
CVE-2011-4415 [MEDIUM] CVE-2011-4415: apache2 - The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through... The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf di
debian
CVE-2003-0542P4HIGHCVSS 7.2fixed in apache2 2.0.48 (bookworm)2003
CVE-2003-0542 [HIGH] CVE-2003-0542: apache2 - Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for A... Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures. Scope: local bookworm: resolved (fixed in 2.0.48) bullseye: resolved (fixed in 2.0.48) forky: resolved (fixed
debian
CVE-2024-24795P3MEDIUMCVSS 6.3fixed in apache2 2.4.59-1~deb12u1 (bookworm)2024
CVE-2024-24795 [MEDIUM] CVE-2024-24795: apache2 - HTTP Response splitting in multiple modules in Apache HTTP Server allows an atta... HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue. Scope: local bookworm: resolved (fixed in 2.4.59-1~deb12u1) bullseye: resolved (fixed in 2.4.
debian
CVE-2016-1546P3MEDIUMCVSS 5.9fixed in apache2 2.4.20-1 (bookworm)2016
CVE-2016-1546 [MEDIUM] CVE-2016-1546: apache2 - The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not li... The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows. Scope: local bookworm: resolved (fixed in 2.4.20-1) bullseye: resolved (fixed in 2.4.20-1
debian
CVE-2020-11985P3MEDIUMCVSS 5.3fixed in apache2 2.4.25-1 (bookworm)2020
CVE-2020-11985 [MEDIUM] CVE-2020-11985: apache2 - IP address spoofing when proxying using mod_remoteip and mod_rewrite For configu... IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020. Scope: local bookworm: reso
debian
CVE-2008-2939P4LOWCVSS 4.3fixed in apache2 2.2.9-7 (bookworm)2008
CVE-2008-2939 [MEDIUM] CVE-2008-2939: apache2 - Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp mod... Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI. Scope: local bookworm:
debian
CVE-2015-0228P4LOWCVSS 5.0fixed in apache2 2.4.10-10 (bookworm)2015
CVE-2015-0228 [MEDIUM] CVE-2015-0228: apache2 - The lua_websocket_read function in lua_request.c in the mod_lua module in the Ap... The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function. Scope: local bookworm: resolved (fixed in 2.4.10-10) bullseye: resolved (fixed in 2.4
debian
CVE-2003-0789P4CRITICALCVSS 10.0fixed in apache2 2.0.48 (bookworm)2003
CVE-2003-0789 [CRITICAL] CVE-2003-0789: apache2 - mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly h... mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client. Scope: local bookworm: resolved (fixed in 2.0.48) bullseye: resolved (fixed in 2.0.48) forky: resolved (fixed in 2.0.48) sid: resolved (fixed in 2.0.48) trixie: resolved (fixed i
debian
CVE-2007-5000P4LOWCVSS 4.3fixed in apache2 2.2.8-1 (bookworm)2007
CVE-2007-5000 [MEDIUM] CVE-2007-5000: apache2 - Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apach... Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 2.2.8-1) bullseye:
debian
CVE-2004-0811P4HIGHCVSS 7.5fixed in apache2 2.0.52 (bookworm)2004
CVE-2004-0811 [HIGH] CVE-2004-0811: apache2 - Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy dire... Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration. Scope: local bookworm: resolved (fixed in 2.0.52) bullseye: resolved (fixed in 2.0.52) forky: resolved (fixed in 2.0.52) sid: resolved (fixed in 2.0.52) trix
debian
CVE-2010-0434P4MEDIUMCVSS 4.3fixed in apache2 2.2.15-1 (bookworm)2010
CVE-2010-0434 [MEDIUM] CVE-2010-0434: apache2 - The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.... The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory
debian
CVE-2012-4558P4LOWCVSS 4.3fixed in apache2 2.2.22-13 (bookworm)2012
CVE-2012-4558 [MEDIUM] CVE-2012-4558: apache2 - Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler func... Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string. Scope: local bookworm: resolved (fixed in 2.
debian
CVE-2012-4557P4MEDIUMCVSS 5.0fixed in apache2 2.2.22-1 (bookworm)2012
CVE-2012-4557 [MEDIUM] CVE-2012-4557: apache2 - The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places ... The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request. Scope: local bookworm: resolved (fixed in 2.2.22-1) bullseye: resolved (fixed in 2.2.22-1) forky:
debian
CVE-2007-4465P4MEDIUMCVSS 6.1fixed in apache2 2.2.6-1 (bookworm)2007
CVE-2007-4465 [MEDIUM] CVE-2007-4465: apache2 - Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP S... Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to p
debian
Debian Apache2 vulnerabilities | cvebase