Apache

HTTP Server

301 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 20.06.2007 22:30:00
  • Last modified 09.04.2025 00:30:58

Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creati...

Exploit
  • EPSS 0.21%
  • Published 20.06.2007 22:30:00
  • Last modified 09.04.2025 00:30:58

Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the m...

  • EPSS 11.46%
  • Published 04.06.2007 23:30:00
  • Last modified 09.04.2025 00:30:58

The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentiall...

  • EPSS 0.17%
  • Published 13.04.2007 17:19:00
  • Last modified 09.04.2025 00:30:58

suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated u...

  • EPSS 0.16%
  • Published 13.04.2007 17:19:00
  • Last modified 09.04.2025 00:30:58

suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the...

  • EPSS 0.09%
  • Published 13.04.2007 16:19:00
  • Last modified 09.04.2025 00:30:58

Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE...

  • EPSS 86.12%
  • Published 16.03.2007 22:19:00
  • Last modified 09.04.2025 00:30:58

Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence...

  • EPSS 3.18%
  • Published 05.01.2007 18:28:00
  • Last modified 09.04.2025 00:30:58

The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOT...

  • EPSS 32.79%
  • Published 16.10.2006 19:07:00
  • Last modified 09.04.2025 00:30:58

Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core...

Exploit
  • EPSS 17.32%
  • Published 14.08.2006 20:04:00
  • Last modified 03.04.2025 01:03:51

Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file...