CVEs (330)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache AppleCanonical5Http Server Mac Os XMac Os X Server+2 moreMay 6, 2026 Jul 20, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authenticatio...Show more |
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, rel...Show more |
3Apache AppleOracle5Http Server LinuxMac Os X+2 moreMay 6, 2026 Jul 20, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference...Show more |
4Apache AppleCanonical+1 more5Http Server Mac Os XMac Os X Server+2 moreMay 6, 2026 Mar 8, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Pi...Show more |
4Apache CanonicalFedoraproject+1 more4Enterprise Manager Ops Center FedoraHttp Server+1 moreMay 6, 2026 Dec 29, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within differ...Show more |
3Apache AppleCanonical4Http Server Mac Os XOs X Server+1 moreMay 6, 2026 Dec 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long respon...Show more |
4Apache CanonicalOracle+1 more9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Oct 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and applic...Show more |
Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a...Show more |
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read fr...Show more |
4Apache DebianOracle+1 more6Debian Linux Enterprise Manager Ops CenterHttp Server+3 moreMay 6, 2026 Jul 20, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or ex...Show more |
3Apache DebianRedhat3Debian Linux Http ServerJboss Enterprise Application PlatformMay 6, 2026 Jul 20, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resourc...Show more |
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header. |
The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NU...Show more |
5Apache AppleCanonical+2 more15Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+12 moreMay 6, 2026 Apr 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the...Show more |
3Apache CanonicalOracle4Http Server Http ServerSecure Global Desktop+1 moreMay 6, 2026 Mar 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted coo...Show more |
3Apache CanonicalOracle3Http Server Http ServerUbuntu LinuxMay 6, 2026 Mar 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a deni...Show more |
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has un...Show more |
4Apache CanonicalOpensuse+1 more9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreApr 29, 2026 Jul 10, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which...Show more |
5Apache CanonicalOpensuse+2 more10Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+7 moreApr 29, 2026 Jun 10, 2013 N/A· v4 N/A· v3 5.1 MEDIUM· v2 mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary command...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and...Show more |