Apache

HTTP Server

301 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 40.82%
  • Veröffentlicht 06.07.2016 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via mo...

  • EPSS 10.32%
  • Veröffentlicht 20.07.2015 23:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote...

  • EPSS 38.1%
  • Veröffentlicht 20.07.2015 23:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large c...

  • EPSS 12.98%
  • Veröffentlicht 20.07.2015 23:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending...

  • EPSS 18.72%
  • Veröffentlicht 08.03.2015 02:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script ha...

  • EPSS 17.55%
  • Veröffentlicht 29.12.2014 23:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows rem...

  • EPSS 19.79%
  • Veröffentlicht 15.12.2014 18:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.

  • EPSS 3.87%
  • Veröffentlicht 10.10.2014 10:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP...

  • EPSS 35.24%
  • Veröffentlicht 20.07.2014 11:12:50
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a denial of service (memory con...

  • EPSS 18.66%
  • Veröffentlicht 20.07.2014 11:12:48
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and dae...