CVE-2016-1546
- EPSS 40.82%
- Published 06.07.2016 14:59:01
- Last modified 12.04.2025 10:46:40
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via mo...
CVE-2015-3185
- EPSS 10.32%
- Published 20.07.2015 23:59:03
- Last modified 12.04.2025 10:46:40
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote...
- EPSS 38.1%
- Published 20.07.2015 23:59:02
- Last modified 12.04.2025 10:46:40
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large c...
- EPSS 12.98%
- Published 20.07.2015 23:59:00
- Last modified 12.04.2025 10:46:40
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending...
- EPSS 18.72%
- Published 08.03.2015 02:59:00
- Last modified 12.04.2025 10:46:40
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script ha...
CVE-2014-8109
- EPSS 17.55%
- Published 29.12.2014 23:59:00
- Last modified 12.04.2025 10:46:40
mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows rem...
- EPSS 19.79%
- Published 15.12.2014 18:59:02
- Last modified 12.04.2025 10:46:40
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
- EPSS 3.87%
- Published 10.10.2014 10:55:07
- Last modified 12.04.2025 10:46:40
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP...
- EPSS 35.24%
- Published 20.07.2014 11:12:50
- Last modified 12.04.2025 10:46:40
Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a denial of service (memory con...
CVE-2013-4352
- EPSS 18.66%
- Published 20.07.2014 11:12:48
- Last modified 12.04.2025 10:46:40
The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and dae...