Apache

HTTP Server

301 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 48.36%
  • Published 20.10.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.

Exploit
  • EPSS 14.84%
  • Published 16.09.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.

  • EPSS 21.04%
  • Published 06.08.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes...

Exploit
  • EPSS 89.5%
  • Published 06.08.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header...

  • EPSS 57.1%
  • Published 07.07.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subje...

  • EPSS 19.12%
  • Published 04.05.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listeni...

Exploit
  • EPSS 44.93%
  • Published 15.04.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

  • EPSS 5.03%
  • Published 29.03.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.

  • EPSS 19.96%
  • Published 29.03.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.

Exploit
  • EPSS 0.21%
  • Published 20.03.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.