VendorsIBMhttp_serverall versions
Vulnerabilities

IBM HTTP Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2010-0425
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
Published 2010-03-05 · Analyzed
10.02 PoCEPSS 0.942
CVE-2004-0492
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
Published 2004-06-23 · Modified
10.0EPSS 0.336
CVE-2012-5955
Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors.
Published 2012-12-20 · Modified
10.0EPSS 0.044
CVE-2026-9170
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Modified
9.8EPSS 0.009
CVE-2026-8855
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
9.8EPSS 0.008
CVE-2026-8856
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
9.1EPSS 0.003
CVE-2015-4947
Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.
Published 2015-09-15 · Modified
9.0EPSS 0.079
CVE-2026-8834
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
8.0EPSS 0.003
CVE-2004-1082
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
Published 2005-04-21 · Modified
7.5EPSS 0.076
CVE-2000-1168
IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
Published 2000-12-19 · Modified
7.5EPSS 0.019
CVE-2023-26281
IBM HTTP Server denial of service
Published 2023-02-28 · Modified
7.5EPSS 0.011
CVE-2023-32342
IBM GSKit information disclosure
Published 2023-05-30 · Modified
7.5EPSS 0.009
CVE-2026-8854
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
7.5EPSS 0.005
CVE-2026-8850
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
7.5EPSS 0.005
CVE-2026-8852
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
7.5EPSS 0.003
CVE-2026-8835
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
7.3EPSS 0.003
CVE-2004-0493
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
Published 2004-06-30 · Modified
6.42 PoCEPSS 0.848
CVE-2000-0505
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.467
CVE-2004-0263
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
Published 2004-09-01 · Modified
5.0EPSS 0.039
CVE-2001-0122
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
Published 2002-03-09 · Modified
5.01 PoCEPSS 0.033
CVE-2002-1822
IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).
Published 2005-06-28 · Modified
5.0EPSS 0.021
CVE-2011-1360
Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified documentation files in (1) manual/ibm/ and (2) htdocs/*/manual/ibm/.
Published 2011-10-28 · Modified
4.3EPSS 0.017