CVE-2018-1283
- EPSS 3.76%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:59:32
In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION...
CVE-2018-1301
- EPSS 6.3%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:59:34
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to tri...
CVE-2018-1302
- EPSS 8.12%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:59:34
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard t...
CVE-2018-1303
- EPSS 36.12%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:59:34
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of ...
CVE-2018-1312
- EPSS 9.08%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:59:36
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication con...
CVE-2016-8612
- EPSS 1.56%
- Published 09.03.2018 20:29:00
- Last modified 21.11.2024 02:59:40
Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.
CVE-2017-9798
- EPSS 93.98%
- Published 18.09.2017 15:29:00
- Last modified 20.04.2025 01:37:25
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2...
CVE-2016-0736
- EPSS 31.84%
- Published 27.07.2017 21:29:00
- Last modified 20.04.2025 01:37:25
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated en...
CVE-2016-2161
- EPSS 39.61%
- Published 27.07.2017 21:29:00
- Last modified 20.04.2025 01:37:25
In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
CVE-2016-8743
- EPSS 8.41%
- Published 27.07.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in...