Apache

HTTP Server

306 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 18.81%
  • Veröffentlicht 10.07.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).

  • EPSS 21.52%
  • Veröffentlicht 05.07.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which al...

  • EPSS 15.65%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2)...

Exploit
  • EPSS 3.66%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via ...

Exploit
  • EPSS 4.27%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 28.05.2009 20:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Opti...

  • EPSS 12%
  • Veröffentlicht 23.04.2009 17:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.

  • EPSS 76.09%
  • Veröffentlicht 06.08.2008 18:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary we...

  • EPSS 2.09%
  • Veröffentlicht 13.06.2008 18:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service...

Exploit
  • EPSS 50.39%
  • Veröffentlicht 13.05.2008 21:20:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.