Apache

HTTP Server

301 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 60.03%
  • Published 20.07.2014 11:12:48
  • Last modified 12.04.2025 10:46:40

The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.

  • EPSS 48.88%
  • Published 20.07.2014 11:12:48
  • Last modified 12.04.2025 10:46:40

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted req...

Exploit
  • EPSS 73.42%
  • Published 20.07.2014 11:12:48
  • Last modified 12.04.2025 10:46:40

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a cr...

  • EPSS 36.22%
  • Published 20.07.2014 11:12:48
  • Last modified 12.04.2025 10:46:40

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

Exploit
  • EPSS 75.57%
  • Published 15.04.2014 10:55:11
  • Last modified 12.04.2025 10:46:40

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...

  • EPSS 47.14%
  • Published 18.03.2014 05:18:18
  • Last modified 12.04.2025 10:46:40

The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) v...

  • EPSS 47.4%
  • Published 18.03.2014 05:18:18
  • Last modified 12.04.2025 10:46:40

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handl...

Exploit
  • EPSS 33.66%
  • Published 23.07.2013 17:20:43
  • Last modified 11.04.2025 00:51:21

mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote at...

Exploit
  • EPSS 38.56%
  • Published 10.07.2013 20:55:01
  • Last modified 11.04.2025 00:51:21

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for han...

  • EPSS 41.76%
  • Published 10.06.2013 17:55:01
  • Last modified 11.04.2025 00:51:21

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containi...