Msrc Azl3 Httpd 2.4.61-1 On Azure Linux 3.0 vulnerabilities

7 known vulnerabilities affecting msrc/azl3_httpd_2.4.61-1_on_azure_linux_3.0.

Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2024-38473HIGHCVSS 8.1PoC2024-07-09
CVE-2024-38473 [HIGH] CWE-116 Apache HTTP Server proxy encoding problem Apache HTTP Server proxy encoding problem FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Micro
msrc
CVE-2024-39884MEDIUMCVSS 6.22024-07-09
CVE-2024-39884 [MEDIUM] Apache HTTP Server: source code disclosure with handlers configured via AddType Apache HTTP Server: source code disclosure with handlers configured via AddType FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions
msrc
CVE-2024-40725MEDIUMCVSS 5.32024-07-09
CVE-2024-40725 [MEDIUM] CWE-668 Apache HTTP Server: source code disclosure with handlers configured via AddType Apache HTTP Server: source code disclosure with handlers configured via AddType FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure
msrc
CVE-2024-36387MEDIUMCVSS 5.42024-07-09
CVE-2024-36387 [MEDIUM] CWE-476 Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2 Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2 FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source li
msrc
CVE-2023-38709HIGHCVSS 7.32024-04-09
CVE-2023-38709 [HIGH] CWE-1284 Apache HTTP Server: HTTP response splitting Apache HTTP Server: HTTP response splitting FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed.
msrc
CVE-2024-27316HIGHCVSS 7.52024-04-09
CVE-2024-27316 [HIGH] CWE-770 Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most sec
msrc
CVE-2024-24795MEDIUMCVSS 6.32024-04-09
CVE-2024-24795 [MEDIUM] CWE-113 Apache HTTP Server: HTTP Response Splitting in multiple modules Apache HTTP Server: HTTP Response Splitting in multiple modules FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libr
msrc