Apache

HTTP Server

306 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.7%
  • Veröffentlicht 01.02.2000 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error...

  • EPSS 1.34%
  • Veröffentlicht 31.12.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.

  • EPSS 1.29%
  • Veröffentlicht 12.12.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.

Exploit
  • EPSS 90.68%
  • Veröffentlicht 13.09.1999 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allo...

Exploit
  • EPSS 8.55%
  • Veröffentlicht 03.09.1999 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.

  • EPSS 3.08%
  • Veröffentlicht 20.08.1999 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.

  • EPSS 2.72%
  • Veröffentlicht 06.06.1999 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspec...

  • EPSS 25.17%
  • Veröffentlicht 03.06.1999 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

  • EPSS 20.45%
  • Veröffentlicht 17.01.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

  • EPSS 5.12%
  • Veröffentlicht 07.08.1998 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.