← Back

Http Server

http_server

Vendor: Apache • 330 CVEs

CVEs (330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Apache
HpOpenpkg+3 more
6Hp Ux
Http ServerOpenpkg+3 more
Apr 16, 2026
Feb 9, 2005
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a lengt...Show more
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.Show less
1Apache
1Http Server
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
7.2 HIGH· v2
Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has...Show more
Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocumentShow less
1Apache
1Http Server
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
2.1 LOW· v2
The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
1Apache
1Http Server
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
2Apache
Ibm
2Http Server
Http Server
Apr 16, 2026
Nov 23, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to o...Show more
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.Show less
1Apache
1Http Server
Apr 16, 2026
Nov 3, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allo...Show more
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.Show less
1Apache
1Http Server
Apr 16, 2026
Oct 20, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP...Show more
The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.Show less
1Apache
1Http Server
Apr 16, 2026
Oct 20, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
1Apache
1Http Server
Apr 16, 2026
Oct 20, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
1Apache
1Http Server
Apr 16, 2026
Oct 20, 2004
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
8Apache
DebianGentoo+5 more
12Debian Linux
Enterprise LinuxEnterprise Linux Desktop+9 more
Apr 16, 2026
Sep 16, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
5Apache
AvayaGentoo+2 more
8Converged Communications Server
Http ServerHttp Server+5 more
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 6...Show more
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.Show less
5Apache
HpIbm+2 more
7Http Server
Http ServerOpenbsd+4 more
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length H...Show more
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.Show less
3Apache
DebianRedhat
4Debian Linux
Enterprise Linux ServerEnterprise Linux Workstation+1 more
Apr 16, 2026
Jul 7, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client...Show more
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.Show less
1Apache
1Http Server
Apr 16, 2026
May 4, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connectio...Show more
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."Show less
1Apache
1Http Server
Apr 16, 2026
Apr 15, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backsla...Show more
Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.Show less
1Apache
1Http Server
Apr 16, 2026
Mar 29, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
1Apache
1Http Server
Apr 16, 2026
Mar 29, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended acces...Show more
mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.Show less
1Apache
1Http Server
Apr 16, 2026
Mar 20, 2004
N/A· v4
N/A· v3
2.1 LOW· v2
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
1Apache
1Http Server
Apr 16, 2026
Mar 3, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.