VYPR

HTTP Server

by Apache

Source repositories

CVEs (341)

  • CVE-2024-39573Jul 1, 2024
    risk 0.00cvss epss 0.35

    Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

  • CVE-2024-38477Jul 1, 2024
    risk 0.00cvss epss 0.03

    null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

  • CVE-2024-38476Jul 1, 2024
    risk 0.00cvss epss 0.42

    Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes…

  • CVE-2024-38474Jul 1, 2024
    risk 0.00cvss epss 0.02

    Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users…

  • CVE-2024-36387Jul 1, 2024
    risk 0.00cvss epss 0.02

    Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

  • CVE-2024-24795Apr 4, 2024
    risk 0.00cvss epss 0.03

    HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

  • CVE-2023-38709Apr 4, 2024
    risk 0.00cvss epss 0.04

    Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.

  • CVE-2023-31122Oct 23, 2023
    risk 0.00cvss epss 0.03

    Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.

  • CVE-2023-45802Oct 23, 2023
    risk 0.00cvss epss 0.03

    When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy…

  • CVE-2023-27522Mar 7, 2023
    risk 0.00cvss epss 0.02

    HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.

  • CVE-2022-37436Jan 17, 2023
    risk 0.00cvss epss 0.58

    Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.

  • CVE-2022-36760Jan 17, 2023
    risk 0.00cvss epss 0.02

    Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version…

  • CVE-2006-20001Jan 17, 2023
    risk 0.00cvss epss 0.04

    A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.

  • CVE-2022-31813Jun 8, 2022
    risk 0.00cvss epss 0.03

    Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

  • CVE-2022-30556Jun 8, 2022
    risk 0.00cvss epss 0.05

    Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.

  • CVE-2022-29404Jun 8, 2022
    risk 0.00cvss epss 0.06

    In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.

  • CVE-2022-28615Jun 8, 2022
    risk 0.00cvss epss 0.06

    Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua…

  • CVE-2022-28614Jun 8, 2022
    risk 0.00cvss epss 0.04

    The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from…

  • CVE-2022-28330Jun 8, 2022
    risk 0.00cvss epss 0.03

    Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

  • CVE-2021-41524Oct 5, 2021
    risk 0.00cvss epss 0.25

    While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is…

Page 14 of 18