Apache
apache
3,116 CVEs • 384 products
Products (384)
Click to collapseToggle
Products (384)
Click to collapse
CVEs (3,116)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages...Show more |
mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core. |
The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL. |
2Apache Matt Wright2Http Server Matt Wright GuestbookApr 16, 2026 Sep 13, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly oth...Show more |
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. |
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files. |
Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long...Show more |
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large numbe...Show more |
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server. |
Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability. |
Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. |
Apache httpd cookie buffer overflow for versions 1.1.1 and earlier. |
2Apache Illinois2Http Server Ncsa HttpdApr 16, 2026 Jan 1, 1997 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. |
2Apache Netscape4Commerce Server Communications ServerEnterprise Server+1 moreApr 16, 2026 Dec 10, 1996 N/A· v4 N/A· v3 7.5 HIGH· v2 List of arbitrary files on Web host via nph-test-cgi script. |
test-cgi program allows an attacker to list files on the server. |
phf CGI program allows remote command execution through shell metacharacters. |