VendorsApachehttp_serverall versions
Vulnerabilities

Apache HTTP Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

351CVEs
CVE-2016-0736
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.
Published 2017-07-27 · Modified
7.51 PoCEPSS 0.490
CVE-2021-33193
Request splitting via HTTP/2 method injection and mod_proxy
Published 2021-08-16 · Analyzed
7.5EPSS 0.462
CVE-2004-0488
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
Published 2004-05-28 · Modified
7.5EPSS 0.377
CVE-2024-39573
Apache HTTP Server: mod_rewrite proxy handler substitution
Published 2024-07-01 · Modified
7.5EPSS 0.372
CVE-2026-49975
Apache HTTP Server: mod_http2 denial of service
Published 2026-06-08 · Modified
7.5EPSS 0.343
CVE-2005-1344
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
Published 2005-04-27 · Modified
7.52 PoCEPSS 0.291
CVE-1999-0045
List of arbitrary files on Web host via nph-test-cgi script.
Published 1999-09-29 · Modified
7.51 PoCEPSS 0.260
CVE-1999-0236
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
Published 1999-09-29 · Modified
7.51 PoCEPSS 0.258
CVE-2021-41524
null pointer dereference in h2 fuzzing
Published 2021-10-05 · Modified
7.5EPSS 0.252
CVE-2002-2029
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
Published 2005-07-14 · Modified
7.51 PoCEPSS 0.231
CVE-2002-0843
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
Published 2002-10-05 · Modified
7.5EPSS 0.214
CVE-2022-26377
mod_proxy_ajp: Possible request smuggling
Published 2022-06-08 · Analyzed
7.5EPSS 0.211
CVE-2016-2161
In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
Published 2017-07-27 · Modified
7.5EPSS 0.210
CVE-2018-17199
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.
Published 2019-01-30 · Modified
7.5EPSS 0.202
CVE-2016-4979
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.
Published 2016-07-06 · Modified
7.5EPSS 0.188
CVE-2003-0016
Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
Published 2004-09-01 · Modified
7.5EPSS 0.178
CVE-2019-0217
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
Published 2019-04-08 · Modified
7.5EPSS 0.174
CVE-2002-1850
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
Published 2005-06-28 · Modified
7.51 PoCEPSS 0.174
CVE-2018-1333
DoS for HTTP/2 connections by crafted requests
Published 2018-06-18 · Modified
7.5EPSS 0.171
CVE-2017-15710
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example, 'en-US' is truncated to 'en'). A header value of less than two characters forces an out of bound write of one NUL byte to a memory location that is not part of the string. In the worst case, quite unlikely, the process would crash which could be used as a Denial of Service attack. In the more likely case, this memory is already reserved for future use and the issue has no effect at all.
Published 2018-03-26 · Modified
7.5EPSS 0.171
CVE-2019-10081
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
Published 2019-08-15 · Modified
7.5EPSS 0.146
CVE-2013-2249
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
Published 2013-07-23 · Modified
7.5EPSS 0.143
CVE-2009-2699
The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
Published 2009-10-13 · Modified
7.5EPSS 0.142
CVE-2004-0885
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
Published 2004-10-16 · Modified
7.5EPSS 0.138
CVE-2016-8743
Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.
Published 2017-07-27 · Modified
7.5EPSS 0.133
CVE-2013-4365
Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.
Published 2013-10-17 · Modified
7.5EPSS 0.132
CVE-2004-0174
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
Published 2004-03-25 · Modified
7.5EPSS 0.115
CVE-2003-0993
mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
Published 2004-09-01 · Modified
7.5EPSS 0.108
CVE-2019-0215
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
Published 2019-04-08 · Modified
7.5EPSS 0.107
CVE-2017-9789
When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
Published 2017-07-13 · Modified
7.5EPSS 0.096
CVE-2001-1449
The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
Published 2005-04-21 · Modified
7.5EPSS 0.078
CVE-2004-0811
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
Published 2004-09-24 · Modified
7.5EPSS 0.076
CVE-2004-1082
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
Published 2005-04-21 · Modified
7.5EPSS 0.076
CVE-2022-29404
Denial of service in mod_lua r:parsebody
Published 2022-06-08 · Modified
7.5EPSS 0.062
CVE-2007-4723
Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
Published 2007-09-05 · Modified
7.5EPSS 0.059
CVE-2011-2688
SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
Published 2011-07-28 · Modified
7.5EPSS 0.057
CVE-2003-0987
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
Published 2004-02-03 · Modified
7.5EPSS 0.056
CVE-2022-30556
Information Disclosure in mod_lua with websockets
Published 2022-06-08 · Analyzed
7.5EPSS 0.051
CVE-2025-53020
Apache HTTP Server: HTTP/2 DoS by Memory Increase
Published 2025-07-10 · Modified
7.5EPSS 0.048
CVE-2002-0257
Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.
Published 2002-05-03 · Modified
7.5EPSS 0.040
← Prev3 / 9Next →