← Back

Http Server

http_server

Vendor: Apache • 330 CVEs

CVEs (330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Http Server
Apr 16, 2026
Jun 6, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long...Show more
Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.Show less
2Apache
Apple
2Http Server
Macos
Apr 16, 2026
Jun 3, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large numbe...Show more
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.Show less
1Apache
1Http Server
Apr 16, 2026
Jan 17, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
1Apache
1Http Server
Apr 16, 2026
Aug 7, 1998
N/A· v4
N/A· v3
10.0 HIGH· v2
Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.
1Apache
1Http Server
Apr 16, 2026
Dec 30, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.
1Apache
1Http Server
Apr 16, 2026
Sep 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
2Apache
Illinois
2Http Server
Ncsa Httpd
Apr 16, 2026
Jan 1, 1997
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
2Apache
Netscape
4Commerce Server
Communications ServerEnterprise Server+1 more
Apr 16, 2026
Dec 10, 1996
N/A· v4
N/A· v3
7.5 HIGH· v2
List of arbitrary files on Web host via nph-test-cgi script.
1Apache
1Http Server
Apr 16, 2026
Apr 1, 1996
N/A· v4
N/A· v3
5.0 MEDIUM· v2
test-cgi program allows an attacker to list files on the server.
2Apache
Ncsa
2Http Server
Ncsa Httpd
Apr 16, 2026
Mar 20, 1996
N/A· v4
N/A· v3
10.0 HIGH· v2
phf CGI program allows remote command execution through shell metacharacters.