VYPR

HTTP Server

by Apache

Source repositories

CVEs (346)

  • CVE-1999-1412Jun 3, 1999
    risk 0.06cvss —epss 0.36

    A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

  • CVE-1999-0678Jan 17, 1999
    risk 0.06cvss —epss 0.31

    A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

  • CVE-2013-5704Apr 15, 2014
    risk 0.05cvss —epss 0.56

    The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as…

  • CVE-2011-0419May 16, 2011
    risk 0.05cvss —epss 0.30

    Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris…

  • CVE-2002-2029Dec 31, 2002
    risk 0.05cvss —epss 0.23

    PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

  • CVE-1999-0448Jan 1, 1999
    risk 0.05cvss —epss 0.25

    IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

  • CVE-1999-0107Dec 30, 1997
    risk 0.05cvss —epss 0.20

    Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.

  • CVE-1999-0045Dec 10, 1996
    risk 0.05cvss —epss 0.26

    List of arbitrary files on Web host via nph-test-cgi script.

  • CVE-2021-33193HigAug 16, 2021
    risk 0.04cvss 7.5epss 0.46

    A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

  • CVE-2014-0231Jul 20, 2014
    risk 0.04cvss —epss 0.44

    The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

  • CVE-2010-0425Mar 5, 2010
    risk 0.04cvss —epss 0.94

    modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which…

  • CVE-2004-0173Apr 15, 2004
    risk 0.04cvss —epss 0.16

    Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

  • CVE-2002-2272Dec 31, 2002
    risk 0.04cvss —epss 0.10

    Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.

  • CVE-2001-0042Feb 16, 2001
    risk 0.04cvss —epss 0.10

    PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.

  • CVE-2000-1016Dec 11, 2000
    risk 0.04cvss —epss 0.08

    The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.

  • CVE-2000-0868Nov 14, 2000
    risk 0.04cvss —epss 0.45

    The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.

  • CVE-1999-0926Sep 3, 1999
    risk 0.04cvss —epss 0.09

    Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.

  • CVE-2014-0118Jul 20, 2014
    risk 0.03cvss —epss 0.37

    The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses…

  • CVE-2014-0117Jul 20, 2014
    risk 0.03cvss —epss 0.36

    The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.

  • CVE-2012-0053Jan 28, 2012
    risk 0.03cvss —epss 0.82

    protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2)…

Page 10 of 18