VYPR

Apache HTTP Server

by Novell

Source repositories

CVEs (8)

  • CVE-2023-38709HigApr 4, 2024
    risk 0.41cvss 7.3epss 0.04

    Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.

  • CVE-2003-0460Aug 27, 2003
    risk 0.01cvss epss 0.13

    The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.

  • CVE-2002-1592May 6, 2002
    risk 0.01cvss epss 0.12

    The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.

  • CVE-2007-1862Jun 4, 2007
    risk 0.00cvss epss 0.06

    The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.

  • CVE-2006-6675Dec 21, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in Welcome web-app.

  • CVE-2004-1834Mar 20, 2004
    risk 0.00cvss epss 0.04

    mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.

  • CVE-2002-1658Dec 31, 2002
    risk 0.00cvss epss 0.01

    Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of…

  • CVE-1999-1293Dec 31, 1999
    risk 0.00cvss epss 0.04

    mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.