Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,282 CVEs tagged to vendor apache587 Critical, 1,195 High, 1,400 Medium, 98 Low, 2 Unrated.

CVE-2004-0747

Published Oct 20, 2004

Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0748

Published Oct 20, 2004

mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child proc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0751

Published Oct 20, 2004

The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentatio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0786

Published Oct 20, 2004

The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0809

Published Sep 16, 2004

The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location t…

CVSS 5.0 · Medium

CVE-2004-0174

Published May 4, 2004

Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0173

Published Apr 15, 2004

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0993

Published Mar 29, 2004

mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2004-0113

Published Mar 29, 2004

Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL p…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2004-1834

Published Mar 20, 2004

mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive informat…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0987

Published Mar 3, 2004

mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2004-0096

Published Mar 3, 2004

Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1082

Published Feb 3, 2004

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

CVSS 7.5 · High

CVE-2003-1172

Published Dec 31, 2003

Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1307

Published Dec 31, 2003

The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descripto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1418

Published Dec 31, 2003

Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0973

Published Dec 15, 2003

Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0866

Published Nov 17, 2003

The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow th…

CVSS 5.0 · Medium
Buzz score
12.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2003-0542

Published Nov 3, 2003

Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (cra…

CVSS 7.2 · High
Buzz score
12.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2003-0789

Published Nov 3, 2003

mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1567

Published Oct 6, 2003

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,176-3,200 of 3,282 CVEsPage 128 of 132