Debian Apache2 vulnerabilities
215 known vulnerabilities affecting debian/apache2.
Total CVEs
215
CISA KEV
5
actively exploited
Public exploits
45
Exploited in wild
22
Severity breakdown
CRITICAL25HIGH66MEDIUM72LOW52
Vulnerabilities
Page 9 of 11
CVE-2010-1452P4LOWCVSS 5.0fixed in apache2 2.2.16-1 (bookworm)2010
CVE-2010-1452 [MEDIUM] CVE-2010-1452: apache2 - The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before...
The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
Scope: local
bookworm: resolved (fixed in 2.2.16-1)
bullseye: resolved (fixed in 2.2.16-1)
forky: resolved (fixed in 2.2.16-1)
sid: resolved (fixed in 2.2.16-1)
trixie: resolved (
debian
CVE-2023-45802P4HIGHCVSS 7.5fixed in apache2 2.4.59-1~deb12u1 (bookworm)2023
CVE-2023-45802 [HIGH] CVE-2023-45802: apache2 - When a HTTP/2 stream was reset (RST frame) by a client, there was a time window ...
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close, all res
debian
CVE-2011-3348P4MEDIUMCVSS 4.3fixed in apache2 2.2.21-1 (bookworm)2011
CVE-2011-3348 [MEDIUM] CVE-2011-3348: apache2 - The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with...
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
Scope: local
bookworm: resolved (fixed in 2.2.21-1)
bullseye: resolved (fixed in 2.2.21-1)
forky: resolved (fi
debian
CVE-2024-40725P4MEDIUMCVSS 6.2fixed in apache2 2.4.62-1~deb12u1 (bookworm)2024
CVE-2024-40725 [MEDIUM] CVE-2024-40725: apache2 - A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignor...
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. U
debian
CVE-2012-3499P4LOWCVSS 4.3fixed in apache2 2.2.22-13 (bookworm)2012
CVE-2012-3499 [MEDIUM] CVE-2012-3499: apache2 - Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2....
Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2010-1623P4MEDIUMCVSS 5.0fixed in apache2 2.2.16-3 (bookworm)2010
CVE-2010-1623 [MEDIUM] CVE-2010-1623: apache2 - Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in t...
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an A
debian
CVE-2010-2791P4LOWCVSS 5.0fixed in apache2 2.2.9-10 (bookworm)2010
CVE-2010-2791 [MEDIUM] CVE-2010-2791: apache2 - mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not c...
mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same
debian
CVE-2025-66200P4MEDIUMCVSS 5.4fixed in apache2 2.4.66-1~deb12u1 (bookworm)2025
CVE-2025-66200 [MEDIUM] CVE-2025-66200: apache2 - mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTT...
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Scope: l
debian
CVE-2009-1191P4LOWCVSS 5.0fixed in apache2 2.2.11-4 (bookworm)2009
CVE-2009-1191 [MEDIUM] CVE-2009-1191: apache2 - mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 all...
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
Scope: local
bookworm: resolved (fixed in 2.2.11-4)
bullseye: resolved (fixed in 2.2.11-4)
forky: resolved (fixed in 2.2.11-4)
sid: r
debian
CVE-2022-28614P4MEDIUMCVSS 5.3fixed in apache2 2.4.54-1 (bookworm)2022
CVE-2022-28614 [MEDIUM] CVE-2022-28614: apache2 - The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unint...
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'ap_rputs' function and may pass it a very large (INT_
debian
CVE-2014-3581P4MEDIUMCVSS 5.0fixed in apache2 2.4.10-3 (bookworm)2014
CVE-2014-3581 [MEDIUM] CVE-2014-3581: apache2 - The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_ca...
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.
Scope: local
bookworm: resolved (fixed in 2.4.10-3)
bullseye: resolved (fixed in 2.4.10-3)
forky
debian
CVE-2012-0021P4LOWCVSS 2.6fixed in apache2 2.2.22-1 (bookworm)2012
CVE-2012-0021 [LOW] CVE-2012-0021: apache2 - The log_cookie function in mod_log_config.c in the mod_log_config module in the ...
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
Scope: local
bookworm: resolved (fixed in 2.2.22-1
debian
CVE-2003-0189P4MEDIUMCVSS 5.0fixed in apache2 2.0.46 (bookworm)2003
CVE-2003-0189 [MEDIUM] CVE-2003-0189: apache2 - The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not prop...
The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
Scope: local
bookworm: resolved (fixed in 2.0.46)
bullseye: resol
debian
CVE-2006-5752P4LOWCVSS 4.3fixed in apache2 2.2.4-2 (bookworm)2006
CVE-2006-5752 [MEDIUM] CVE-2006-5752: apache2 - Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status modul...
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not s
debian
CVE-2014-3583P4LOWCVSS 5.0fixed in apache2 2.4.10-8 (bookworm)2014
CVE-2014-3583 [MEDIUM] CVE-2014-3583: apache2 - The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in ...
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
Scope: local
bookworm: resolved (fixed in 2.4.10-8)
bullseye: resolved (fixed in 2.4.10-8)
forky: resolved (fixed in 2.4.10-8)
sid: reso
debian
CVE-2024-39884P4LOWCVSS 6.2fixed in apache2 2.4.61-1 (bullseye)2024
CVE-2024-39884 [MEDIUM] CVE-2024-39884: apache2 - A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the le...
A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended
debian
CVE-2002-1156P4MEDIUMCVSS 5.0fixed in apache2 2.0.43 (bookworm)2002
CVE-2002-1156 [MEDIUM] CVE-2002-1156: apache2 - Apache 2.0.42 allows remote attackers to view the source code of a CGI script vi...
Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
Scope: local
bookworm: resolved (fixed in 2.0.43)
bullseye: resolved (fixed in 2.0.43)
forky: resolved (fixed in 2.0.43)
sid: resolved (fixed in 2.0.43)
trixie: resolved (fixed in 2.0.43)
debian
CVE-2011-1176P4MEDIUMCVSS 4.3fixed in apache2 2.2.17-2 (bookworm)2011
CVE-2011-1176 [MEDIUM] CVE-2011-1176: apache2 - The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Proc...
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
Scope
debian
CVE-2004-0748P4MEDIUMCVSS 5.0fixed in apache2 2.0.51 (bookworm)2004
CVE-2004-0748 [MEDIUM] CVE-2004-0748: apache2 - mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial o...
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
Scope: local
bookworm: resolved (fixed in 2.0.51)
bullseye: resolved (fixed in 2.0.51)
forky: resolved (fixed in 2.0.51)
sid: resolved (fixed in 2.0.51)
trixi
debian
CVE-2024-36387P4MEDIUMCVSS 5.4fixed in apache2 2.4.61-1~deb12u1 (bookworm)2024
CVE-2024-36387 [MEDIUM] CVE-2024-36387: apache2 - Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a N...
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
Scope: local
bookworm: resolved (fixed in 2.4.61-1~deb12u1)
bullseye: resolved (fixed in 2.4.61-1~deb11u1)
forky: resolved (fixed in 2.4.60-1)
sid: resolved (fixed in 2.4.60-1)
trixie: resolved (f
debian