Skip to main content

Vendor/product archive

ibm / http_server CVEs

Beta · best-effort

22 CVEs tagged to ibm / http_server5 Critical, 9 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-9170

Published May 26, 2026

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-32342

Published May 30, 2023

IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large num…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4947

Published Sep 15, 2015

Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, a…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5955

Published Dec 20, 2012

Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1360

Published Oct 28, 2011

Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0263

Published Nov 23, 2004

PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1082

Published Feb 3, 2004

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

CVSS 7.5 · High

CVE-2002-1822

Published Dec 31, 2002

IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a reque…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0122

Published Mar 13, 2001

Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of se…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1168

Published Jan 9, 2001

IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0505

Published May 31, 2000

The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1