Apache

Apache Http Server

19 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.19%
  • Published 01.07.2024 19:15:05
  • Last modified 01.07.2025 20:25:56

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Warning Media report
  • EPSS 93.75%
  • Published 01.07.2024 19:15:04
  • Last modified 02.05.2025 15:43:59

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resultin...

  • EPSS 87.11%
  • Published 01.07.2024 19:15:04
  • Last modified 01.07.2025 20:25:09

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version ...

  • EPSS 89.75%
  • Published 01.07.2024 19:15:04
  • Last modified 01.07.2025 20:24:46

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations t...

  • EPSS 0.13%
  • Published 01.07.2024 19:15:03
  • Last modified 10.07.2025 22:13:43

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

  • EPSS 1.22%
  • Published 04.04.2024 20:15:08
  • Last modified 30.06.2025 12:55:47

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, ...

  • EPSS 5.8%
  • Published 04.04.2024 20:15:08
  • Last modified 30.06.2025 12:59:08

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.

  • EPSS 0.52%
  • Published 20.04.2010 16:30:00
  • Last modified 11.04.2025 00:51:21

Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validatio...

  • EPSS 0.47%
  • Published 01.01.1999 05:00:00
  • Last modified 03.04.2025 01:03:51

A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.