VYPR
Unrated severityNVD Advisory· Published May 12, 2001· Updated Apr 16, 2026

CVE-2001-1342

CVE-2001-1342

Description

Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.

Affected products

7
  • cpe:2.3:a:apache:http_server:1.3.12:*:win32:*:*:*:*:*+ 6 more
    • cpe:2.3:a:apache:http_server:1.3.12:*:win32:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:1.3.14:*:win32:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:1.3.15:*:win32:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:1.3.16:*:win32:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:1.3.17:*:win32:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:1.3.18:*:win32:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:1.3.19:*:win32:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

12

News mentions

0

No linked articles in our index yet.