Msrc Cm1 Httpd 2.4.46-5 On Cbl Mariner 1.0 vulnerabilities

8 known vulnerabilities affecting msrc/cm1_httpd_2.4.46-5_on_cbl_mariner_1.0.

Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2021-26691CRITICALCVSS 9.82021-06-08
CVE-2021-26691 [CRITICAL] CWE-787 Apache HTTP Server mod_session response handling heap overflow Apache HTTP Server mod_session response handling heap overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libr
msrc
CVE-2021-26690HIGHCVSS 7.52021-06-08
CVE-2021-26690 [HIGH] CWE-476 mod_session NULL pointer dereference mod_session NULL pointer dereference FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is co
msrc
CVE-2020-35452HIGHCVSS 7.32021-06-08
CVE-2020-35452 [HIGH] CWE-787 mod_auth_digest possible stack overflow by one nul byte mod_auth_digest possible stack overflow by one nul byte FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which t
msrc
CVE-2020-13950HIGHCVSS 7.52021-06-08
CVE-2020-13950 [HIGH] CWE-476 mod_proxy_http NULL pointer dereference mod_proxy_http NULL pointer dereference FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft
msrc
CVE-2021-30641MEDIUMCVSS 5.32021-06-08
CVE-2021-30641 [MEDIUM] Unexpected URL matching with 'MergeSlashes OFF' Unexpected URL matching with 'MergeSlashes OFF' FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed.
msrc
CVE-2020-11984CRITICALCVSS 9.8PoC2020-08-11
CVE-2020-11984 [CRITICAL] CWE-120 Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and
msrc
CVE-2020-11993HIGHCVSS 7.52020-08-11
CVE-2020-11993 [HIGH] CWE-444 Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns logging statements were made on the wrong connection causing concur Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns logging statements were made on the wrong connection causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above
msrc
CVE-2020-9490HIGHCVSS 7.52020-08-11
CVE-2020-9490 [HIGH] CWE-444 Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resour Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mi
msrc