VendorsApachehttp_server2.4.21
Vulnerabilities

Apache HTTP Server 2.4.21

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2016-8740
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.
Published 2016-12-05 · Modified
7.51 PoCEPSS 0.791
CVE-2016-0736
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.
Published 2017-07-27 · Modified
7.51 PoCEPSS 0.490
CVE-2016-2161
In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
Published 2017-07-27 · Modified
7.5EPSS 0.210