Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HTTP Server HIGH 7.8
CVE-2004-0747

Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expans…

Fix: 2.0.51+
Fix from $1,950 2004-10-20
HTTP Server MEDIUM 5.0
CVE-2004-0748EPSS 25%

mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way th…

Fix: 2.0.51+
Fix from $1,600 2004-10-20
HTTP Server MEDIUM 5.0
CVE-2004-0751EPSS 72%

The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a …

Fix: 2.0.51+
Fix from $1,600 2004-10-20
HTTP Server MEDIUM 5.0
CVE-2004-0786EPSS 22%

The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child proces…

Fix: 2.0.51+
Fix from $1,600 2004-10-20
HTTP Server MEDIUM 5.0
CVE-2004-0809EPSS 15%

The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of …

Fix: 2.0.51+
Fix from $1,600 2004-09-16
HTTP Server HIGH 10.0
CVE-2004-0492EPSS 34%

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process cra…

Patch available
Fix from $1,950 2004-08-06
HTTP Server HIGH 7.5
CVE-2004-0488EPSS 38%

Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuin…

Fix: 2.0.50+
Fix from $1,950 2004-07-07
HTTP Server HIGH 7.5
CVE-2004-0174EPSS 12%

Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a d…

Fix: after 2.0.49
Fix from $1,950 2004-05-04
HTTP Server MEDIUM 5.0
CVE-2004-0173EPSS 16%

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to rea…

Patch available
Fix from $1,600 2004-04-15
HTTP Server HIGH 7.5
CVE-2003-0993EPSS 11%

mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without…

Patch available
Fix from $1,950 2004-03-29
HTTP Server MEDIUM 5.0
CVE-2004-0113EPSS 11%

Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via pl…

Patch available
Fix from $1,600 2004-03-29
HTTP Server HIGH 7.5
CVE-2003-0987EPSS 6%

mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.

Fix: after 1.3.30
Fix from $1,950 2004-03-03
Mod Python MEDIUM 5.0
CVE-2004-0096

Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of…

Patch available
Fix from $1,600 2004-03-03
HTTP Server HIGH 7.5
CVE-2004-1082EPSS 8%

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attacke…

Patch available
Fix from $1,950 2004-02-03
Cocoon MEDIUM 5.0
CVE-2003-1172EPSS 31%

Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access a…

Patch available
Fix from $1,600 2003-12-31
Mod Python MEDIUM 5.0
CVE-2003-0973EPSS 5%

Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) vi…

Patch available
Fix from $1,600 2003-12-15
Tomcat MEDIUM 5.0
CVE-2003-0866EPSS 33%

The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several …

Patch available
Fix from $1,600 2003-11-17
HTTP Server HIGH 10.0
CVE-2003-0789EPSS 12%

mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output…

Fix: 2.0.48+
Fix from $1,950 2003-11-03
HTTP Server HIGH 7.2
CVE-2003-0542EPSS 13%

Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to …

Patch available
Fix from $1,950 2003-11-03
Tomcat MEDIUM 6.8
CVE-2002-1567EPSS 27%

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL wit…

No fix yet
Fix from $1,600 2003-10-06
HTTP Server MEDIUM 5.0
CVE-2003-0460EPSS 13%

The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received o…

Fix: after 1.3.27
Fix from $1,600 2003-08-27
HTTP Server MEDIUM 6.4
CVE-2003-0192EPSS 6%

Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and…

Patch available
Fix from $1,600 2003-08-18
HTTP Server MEDIUM 5.0
CVE-2003-0253EPSS 9%

The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.

Patch available
Fix from $1,600 2003-08-18
HTTP Server MEDIUM 5.0
CVE-2003-0254EPSS 9%

Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP p…

Patch available
Fix from $1,600 2003-08-18
HTTP Server MEDIUM 5.0
CVE-2003-0189EPSS 15%

The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions,…

Patch available
Fix from $1,600 2003-06-09
HTTP Server MEDIUM 5.0
CVE-2003-0245EPSS 63%

Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to c…

Patch available
Fix from $1,600 2003-06-09
HTTP Server MEDIUM 5.0
CVE-2003-0132EPSS 87%

A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed cha…

Fix: after 2.0.44
Fix from $1,600 2003-04-11
HTTP Server MEDIUM 5.0
CVE-2003-0134EPSS 6%

Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via…

Patch available
Fix from $1,600 2003-04-11
HTTP Server MEDIUM 5.0
CVE-2003-0083EPSS 17%

Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it eas…

Fix: 1.3.26 / 2.0.46+
Fix from $1,600 2003-04-02
HTTP Server MEDIUM 5.0
CVE-2003-0020EPSS 16%

Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into termina…

Fix: 1.3.31 / 2.0.49+
Fix from $1,600 2003-03-18