VYPR

Apache HTTP Server

by CPanel

CVEs (7)

  • CVE-2016-10786MedAug 6, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).

  • CVE-2018-20885MedAug 1, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).

  • CVE-2016-10796LowAug 6, 2019
    risk 0.21cvss 3.3epss 0.00

    cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).

  • CVE-2017-18429LowAug 2, 2019
    risk 0.21cvss 3.3epss 0.00

    In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).

  • CVE-2017-18424LowAug 2, 2019
    risk 0.21cvss 3.3epss 0.00

    In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).

  • CVE-2018-20932LowAug 1, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).

  • CVE-2017-18412LowAug 2, 2019
    risk 0.16cvss 2.5epss 0.00

    cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).