Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache http server 2.4.18 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2016-4979
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by...
Apache Http Server 2.4.18
Apache Http Server 2.4.20
Apache Http Server 2.4.19
5 Github repositories available
5
CVSSv2
CVE-2016-8740
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in...
Apache Http Server 2.4.22
Apache Http Server 2.4.21
Apache Http Server 2.4.17
Apache Http Server 2.4.23
Apache Http Server 2.4.20
Apache Http Server 2.4.19
Apache Http Server 2.4.18
1 EDB exploit available
5 Github repositories available
4.3
CVSSv2
CVE-2016-1546
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows....
Apache Http Server 2.4.17
Apache Http Server 2.4.18
3 Github repositories available
5
CVSSv2
CVE-2017-9798
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through...
Apache Http Server 2.4.0
Apache Http Server 2.4.9
Apache Http Server 2.4.10
Apache Http Server 2.4.26
Apache Http Server 2.4.27
Apache Http Server 2.4.6
Apache Http Server 2.4.7
Apache Http Server 2.4.23
Apache Http Server 2.4.25
Apache Http Server 2.4.3
Apache Http Server 2.4.4
Apache Http Server 2.4.17
Apache Http Server 2.4.18
Apache Http Server 2.4.20
Apache Http Server 2.4.1
Apache Http Server 2.4.2
Apache Http Server 2.4.12
Apache Http Server 2.4.16
Apache Http Server
Debian Debian Linux 7.0
Debian Debian Linux 9.0
Debian Debian Linux 8.0
1 EDB exploit available
1 Metasploit module available
24 Github repositories available
1 Article available
7.5
CVSSv2
CVE-2017-3169
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port....
Apache Http Server 2.2.2
Apache Http Server 2.2.3
Apache Http Server 2.2.17
Apache Http Server 2.2.18
Apache Http Server 2.2.26
Apache Http Server 2.2.27
Apache Http Server 2.4.10
Apache Http Server 2.4.12
Apache Http Server 2.2.11
Apache Http Server 2.2.12
Apache Http Server 2.2.19
Apache Http Server 2.2.20
Apache Http Server 2.2.29
Apache Http Server 2.2.30
Apache Http Server 2.4.16
Apache Http Server 2.4.17
Apache Http Server 2.2.13
Apache Http Server 2.2.14
Apache Http Server 2.2.21
Apache Http Server 2.2.22
Apache Http Server 2.2.31
Apache Http Server 2.2.32
Apache Http Server 2.4.18
Apache Http Server 2.4.20
Apache Http Server 2.2.0
Apache Http Server 2.2.15
Apache Http Server 2.2.16
Apache Http Server 2.2.23
Apache Http Server 2.2.24
Apache Http Server 2.2.25
Apache Http Server 2.4.1
Apache Http Server 2.4.2
Apache Http Server 2.4.23
Apache Http Server 2.4.25
13 Github repositories available
4.3
CVSSv2
CVE-2016-4975
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache...
Apache Http Server 2.2.3
Apache Http Server 2.2.4
Apache Http Server 2.2.14
Apache Http Server 2.2.15
Apache Http Server 2.2.22
Apache Http Server 2.2.23
Apache Http Server 2.4.23
Apache Http Server 2.4.20
Apache Http Server 2.4.18
Apache Http Server 2.4.6
Apache Http Server 2.4.4
Apache Http Server 2.2.10
Apache Http Server 2.2.11
Apache Http Server 2.2.18
Apache Http Server 2.2.19
Apache Http Server 2.2.26
Apache Http Server 2.2.27
Apache Http Server 2.4.12
Apache Http Server 2.4.10
Apache Http Server 2.4.1
Apache Http Server 2.2.6
Apache Http Server 2.2.8
Apache Http Server 2.2.9
Apache Http Server 2.2.16
Apache Http Server 2.2.17
Apache Http Server 2.2.24
Apache Http Server 2.2.25
Apache Http Server 2.4.17
Apache Http Server 2.4.16
Apache Http Server 2.4.3
Apache Http Server 2.4.2
Apache Http Server 2.2.0
Apache Http Server 2.2.2
Apache Http Server 2.2.12
Apache Http Server 2.2.13
Apache Http Server 2.2.20
Apache Http Server 2.2.21
Apache Http Server 2.2.29
Apache Http Server 2.2.31
Apache Http Server 2.4.9
Apache Http Server 2.4.7
12 Github repositories available
5
CVSSv2
CVE-2017-15710
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not...
Apache Http Server 2.4.29
Apache Http Server 2.4.28
Apache Http Server 2.4.27
Apache Http Server 2.4.3
Apache Http Server 2.4.2
Apache Http Server 2.4.1
Apache Http Server 2.4.26
Apache Http Server 2.4.23
Apache Http Server 2.4.9
Apache Http Server 2.4.6
Apache Http Server 2.4.18
Apache Http Server 2.4.17
Apache Http Server 2.4.16
Apache Http Server 2.4.12
Apache Http Server 2.4.25
Apache Http Server 2.4.20
Apache Http Server 2.4.10
Apache Http Server 2.4.7
Apache Http Server 2.4.4
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Debian Debian Linux 9.0
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 17.10
Netapp Storage Automation Store -
Netapp Storagegrid -
Netapp Clustered Data Ontap -
Netapp Santricity Cloud Connector -
Redhat Enterprise Linux 7.4
Redhat Enterprise Linux 7.6
Redhat Enterprise Linux 6.0
Redhat Enterprise Linux 7.0
Redhat Enterprise Linux 7.5
22 Github repositories available
6.8
CVSSv2
CVE-2018-1312
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests...
Apache Http Server 2.4.1
Apache Http Server 2.4.20
Apache Http Server 2.4.6
Apache Http Server 2.4.12
Apache Http Server 2.4.3
Apache Http Server 2.4.23
Apache Http Server 2.4.4
Apache Http Server 2.4.10
Apache Http Server 2.4.7
Apache Http Server 2.4.2
Apache Http Server 2.4.9
Apache Http Server 2.4.16
Apache Http Server 2.4.17
Apache Http Server 2.4.18
Apache Http Server 2.4.25
Apache Http Server 2.4.26
Apache Http Server 2.4.27
Apache Http Server 2.4.28
Apache Http Server 2.4.29
Canonical Ubuntu Linux 17.10
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 12.04
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Debian Debian Linux 9.0
Netapp Cloud Backup -
Netapp Storagegrid -
Netapp Clustered Data Ontap -
Redhat Jboss Core Services 1.0
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux Workstation 7.0
Redhat Enterprise Linux Server 7.0
Redhat Enterprise Linux Server Tus 7.6
Redhat Enterprise Linux Server Aus 7.6
Redhat Enterprise Linux Eus 7.6
24 Github repositories available
5
CVSSv2
CVE-2018-17189
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections....
Apache Http Server 2.4.17
Apache Http Server 2.4.18
Apache Http Server 2.4.20
Apache Http Server 2.4.23
Apache Http Server 2.4.25
Apache Http Server 2.4.26
Apache Http Server 2.4.27
Apache Http Server 2.4.28
Apache Http Server 2.4.29
Apache Http Server 2.4.30
Apache Http Server 2.4.33
Apache Http Server 2.4.34
Apache Http Server 2.4.35
Apache Http Server 2.4.37
Netapp Santricity Cloud Connector -
Netapp Storage Automation Store -
Fedoraproject Fedora 28
Fedoraproject Fedora 29
Debian Debian Linux 9.0
Oracle Enterprise Manager Ops Center 12.3.3
Oracle Hospitality Guest Access 4.2.0
Oracle Hospitality Guest Access 4.2.1
Oracle Instantis Enterprisetrack 17.1
Oracle Instantis Enterprisetrack 17.2
Oracle Instantis Enterprisetrack 17.3
Oracle Retail Xstore Point Of Service 7.0
Oracle Retail Xstore Point Of Service 7.1
Oracle Sun Zfs Storage Appliance Kit 8.8.6
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 18.10
Redhat Jboss Core Services 1.0
7 Github repositories available
5
CVSSv2
CVE-2018-1333
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33)....
Apache Http Server 2.4.33
Apache Http Server
Redhat Jboss Core Services 1.0
Canonical Ubuntu Linux 18.04
Netapp Storage Automation Store -
Netapp Cloud Backup -
9 Github repositories available
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
wireless
SQL
CVE-2023-1454
overflow
CVE-2022-48425
CVE-2023-25064
CVE-2023-28107
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »