CVEs (330)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apache BroadcomDebian+3 more13Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+10 moreJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). |
8Apache BroadcomDebian+5 more18Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+15 moreJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. |
5Apache DebianFedoraproject+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Aug 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restri...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' |
5Apache DebianFedoraproject+2 more8Cloud Backup Debian LinuxEnterprise Manager Ops Center+5 moreJun 17, 2026 Jun 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could cre...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of...Show more |
3Apache McafeeNetapp3Cloud Backup Epolicy OrchestratorHttp ServerJun 17, 2026 Jun 10, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows |
3Apache FedoraprojectOracle5Enterprise Manager Ops Center FedoraHttp Server+2 moreJun 17, 2026 Jun 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent reques...Show more |
7Apache CanonicalDebian+4 more25Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+22 moreJun 17, 2026 Aug 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more |
7Apache CanonicalDebian+4 more13Clustered Data Ontap Communications Element ManagerCommunications Session Report Manager+10 moreJun 17, 2026 Aug 7, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory...Show more |
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts...Show more |
7Apache CanonicalDebian+4 more13Clustered Data Ontap Communications Element ManagerCommunications Session Report Manager+10 moreJun 17, 2026 Aug 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
8Apache BroadcomCanonical+5 more14Brocade Fabric Operating System Communications Element ManagerCommunications Session Report Manager+11 moreJun 17, 2026 Apr 2, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request U...Show more |
6Apache CanonicalDebian+3 more11Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+8 moreJun 17, 2026 Apr 1, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. |
2Apache Oracle8Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+5 moreJun 17, 2026 Sep 26, 2019 N/A· v4 7.2 HIGH· v3 6.0 MEDIUM· v2 In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL...Show more |
8Apache CanonicalDebian+5 more10Clustered Data Ontap Communications Element ManagerDebian Linux+7 moreJun 17, 2026 Sep 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of...Show more |
2Apache Oracle6Communications Element Manager Enterprise Manager Ops CenterHttp Server+3 moreJun 17, 2026 Sep 26, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown. |