- EPSS 48.36%
- Published 20.10.2004 04:00:00
- Last modified 03.04.2025 01:03:51
The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
- EPSS 14.84%
- Published 16.09.2004 04:00:00
- Last modified 03.04.2025 01:03:51
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
- EPSS 21.04%
- Published 06.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes...
CVE-2004-0493
- EPSS 89.5%
- Published 06.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header...
CVE-2004-0488
- EPSS 57.1%
- Published 07.07.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subje...
CVE-2004-0174
- EPSS 19.12%
- Published 04.05.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listeni...
- EPSS 44.93%
- Published 15.04.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
CVE-2003-0993
- EPSS 5.03%
- Published 29.03.2004 05:00:00
- Last modified 03.04.2025 01:03:51
mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
- EPSS 19.96%
- Published 29.03.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
CVE-2004-1834
- EPSS 0.21%
- Published 20.03.2004 05:00:00
- Last modified 03.04.2025 01:03:51
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.