CVE-2024-38473
- EPSS 87.86%
- Veröffentlicht 01.07.2024 19:15:04
- Zuletzt bearbeitet 01.07.2025 20:25:09
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version ...
CVE-2024-38472
- EPSS 90.49%
- Veröffentlicht 01.07.2024 19:15:04
- Zuletzt bearbeitet 01.07.2025 20:24:46
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations t...
CVE-2024-36387
- EPSS 0.15%
- Veröffentlicht 01.07.2024 19:15:03
- Zuletzt bearbeitet 06.11.2025 22:26:05
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
CVE-2024-6387
- EPSS 54.14%
- Veröffentlicht 01.07.2024 13:15:06
- Zuletzt bearbeitet 30.09.2025 13:52:23
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to aut...
CVE-2024-27316
- EPSS 89.12%
- Veröffentlicht 04.04.2024 20:15:08
- Zuletzt bearbeitet 04.11.2025 22:15:59
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
CVE-2024-24795
- EPSS 1.22%
- Veröffentlicht 04.04.2024 20:15:08
- Zuletzt bearbeitet 30.06.2025 12:55:47
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, ...
CVE-2023-38709
- EPSS 4.36%
- Veröffentlicht 04.04.2024 20:15:08
- Zuletzt bearbeitet 04.11.2025 22:15:53
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
CVE-2024-2004
- EPSS 0.91%
- Veröffentlicht 27.03.2024 08:15:41
- Zuletzt bearbeitet 30.07.2025 19:42:14
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to c...
CVE-2024-28757
- EPSS 0.91%
- Veröffentlicht 10.03.2024 05:15:06
- Zuletzt bearbeitet 04.11.2025 22:15:59
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
CVE-2023-4408
- EPSS 0.27%
- Veröffentlicht 13.02.2024 14:15:45
- Zuletzt bearbeitet 14.03.2025 17:15:40
The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` insta...