Apache

HTTP Server

317 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.04%
  • Veröffentlicht 08.09.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as...

Exploit
  • EPSS 18.85%
  • Veröffentlicht 10.07.2009 15:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).

  • EPSS 37.87%
  • Veröffentlicht 05.07.2009 16:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which al...

  • EPSS 14.79%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2)...

Exploit
  • EPSS 2.33%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via ...

Exploit
  • EPSS 5.42%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 28.05.2009 20:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Opti...

  • EPSS 12%
  • Veröffentlicht 23.04.2009 17:30:01
  • Zuletzt bearbeitet 23.04.2026 00:35:47

mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.

  • EPSS 64.56%
  • Veröffentlicht 06.08.2008 18:41:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary we...

  • EPSS 2.21%
  • Veröffentlicht 13.06.2008 18:41:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service...