Apache

HTTP Server

306 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 15.83%
  • Veröffentlicht 29.12.2014 23:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows rem...

  • EPSS 19.79%
  • Veröffentlicht 15.12.2014 18:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.

  • EPSS 4.88%
  • Veröffentlicht 10.10.2014 10:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP...

  • EPSS 35.24%
  • Veröffentlicht 20.07.2014 11:12:50
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a denial of service (memory con...

  • EPSS 24.35%
  • Veröffentlicht 20.07.2014 11:12:48
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and dae...

  • EPSS 57%
  • Veröffentlicht 20.07.2014 11:12:48
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.

  • EPSS 41.33%
  • Veröffentlicht 20.07.2014 11:12:48
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted req...

Exploit
  • EPSS 75.44%
  • Veröffentlicht 20.07.2014 11:12:48
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a cr...

  • EPSS 44.15%
  • Veröffentlicht 20.07.2014 11:12:48
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

Exploit
  • EPSS 69.44%
  • Veröffentlicht 15.04.2014 10:55:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...