VYPR

HTTP Server

by Apache

Source repositories

CVEs (346)

  • CVE-2003-0460Aug 27, 2003
    risk 0.01cvss —epss 0.13

    The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.

  • CVE-2003-0254Aug 18, 2003
    risk 0.01cvss —epss 0.09

    Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.

  • CVE-2003-0253Aug 18, 2003
    risk 0.01cvss —epss 0.09

    The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.

  • CVE-2003-0189Jun 9, 2003
    risk 0.01cvss —epss 0.15

    The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when…

  • CVE-2003-0083Apr 2, 2003
    risk 0.01cvss —epss 0.17

    Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a…

  • CVE-2003-0020Mar 18, 2003
    risk 0.01cvss —epss 0.16

    Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.

  • CVE-2003-0016Feb 7, 2003
    risk 0.01cvss —epss 0.18

    Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.

  • CVE-2003-0017Feb 7, 2003
    risk 0.01cvss —epss 0.06

    Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.

  • CVE-2002-1157Nov 4, 2002
    risk 0.01cvss —epss 0.10

    Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is…

  • CVE-2002-1156Oct 11, 2002
    risk 0.01cvss —epss 0.15

    Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.

  • CVE-2002-1593Sep 25, 2002
    risk 0.01cvss —epss 0.07

    mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.

  • CVE-2002-0240May 29, 2002
    risk 0.01cvss —epss 0.07

    PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.

  • CVE-2002-0249May 29, 2002
    risk 0.01cvss —epss 0.07

    PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.

  • CVE-2002-1592May 6, 2002
    risk 0.01cvss —epss 0.12

    The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.

  • CVE-2001-1449Nov 28, 2001
    risk 0.01cvss —epss 0.08

    The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.

  • CVE-2001-0729Oct 30, 2001
    risk 0.01cvss —epss 0.07

    Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.

  • CVE-2001-0730Oct 30, 2001
    risk 0.01cvss —epss 0.12

    split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.

  • CVE-2001-1342May 12, 2001
    risk 0.01cvss —epss 0.12

    Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.

  • CVE-2000-1204Oct 13, 2000
    risk 0.01cvss —epss 0.10

    Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.

  • CVE-1999-1237Jun 6, 1999
    risk 0.01cvss —epss 0.08

    Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.

Page 14 of 18