VendorsApachehttp_server2.2.26
Vulnerabilities

Apache HTTP Server 2.2.26

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-3169
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
Published 2017-06-20 · Modified
9.8EPSS 0.200
CVE-2016-4975
mod_userdir CRLF injection
Published 2018-08-14 · Modified
6.1EPSS 0.198
CVE-2013-5704
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
Published 2014-04-15 · Modified
5.0EPSS 0.563