Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2000-0913

Published Dec 19, 2000

mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0868

Published Nov 14, 2000

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0869

Published Nov 14, 2000

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0759

Published Oct 20, 2000

Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the phy…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0760

Published Oct 20, 2000

The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1204

Published Oct 13, 2000

Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin d…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0672

Published Jul 20, 2000

The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administr…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0505

Published May 31, 2000

The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-1205

Published Feb 1, 2000

Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), whi…

CVSS 4.3 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-1293

Published Dec 31, 1999

mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1053

Published Sep 13, 1999

guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.p…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0926

Published Sep 3, 1999

Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-1206

Published Aug 20, 1999

Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve ar…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-1237

Published Jun 6, 1999

Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary comm…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1412

Published Jun 3, 1999

A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CG…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0678

Published Jan 17, 1999

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

CVSS 5.0 · Medium
Buzz score
10.0
Public PoC observedOTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 3,126-3,142 of 3,142 CVEsPage 126 of 126