Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache http server 2.4.7 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-0117
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header....
Apache Http Server 2.4.6
Apache Http Server 2.4.9
Apache Http Server 2.4.7
Apache Http Server 2.4.8
Apple Mac Os X
1 Github repository available
7.5
CVSSv3
CVE-2016-0736
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it...
Apache Http Server 2.4.0
Apache Http Server 2.4.1
Apache Http Server 2.4.10
Apache Http Server 2.4.12
Apache Http Server 2.4.6
Apache Http Server 2.4.7
Apache Http Server 2.4.20
Apache Http Server 2.4.21
Apache Http Server 2.4.8
Apache Http Server 2.4.9
Apache Http Server 2.4.22
Apache Http Server 2.4.23
Apache Http Server 2.4.2
Apache Http Server 2.4.3
Apache Http Server 2.4.14
Apache Http Server 2.4.16
Apache Http Server 2.4.19
1 EDB exploit available
1 Github repository available
7.5
CVSSv3
CVE-2016-2161
In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests....
Apache Http Server 2.4.23
Apache Http Server 2.4.12
Apache Http Server 2.4.10
Apache Http Server 2.4.0
Apache Http Server 2.4.16
Apache Http Server 2.4.14
Apache Http Server 2.4.3
Apache Http Server 2.4.2
Apache Http Server 2.4.1
Apache Http Server 2.4.22
Apache Http Server 2.4.21
Apache Http Server 2.4.9
Apache Http Server 2.4.8
Apache Http Server 2.4.20
Apache Http Server 2.4.19
Apache Http Server 2.4.7
Apache Http Server 2.4.6
1 Github repository available
7.5
CVSSv3
CVE-2017-9798
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through...
Apache Http Server 2.4.0
Apache Http Server 2.4.9
Apache Http Server 2.4.10
Apache Http Server 2.4.26
Apache Http Server 2.4.27
Apache Http Server 2.4.6
Apache Http Server 2.4.7
Apache Http Server 2.4.23
Apache Http Server 2.4.25
Apache Http Server 2.4.3
Apache Http Server 2.4.4
Apache Http Server 2.4.17
Apache Http Server 2.4.18
Apache Http Server 2.4.20
Apache Http Server 2.4.1
Apache Http Server 2.4.2
Apache Http Server 2.4.12
Apache Http Server 2.4.16
Apache Http Server
Debian Debian Linux 7.0
Debian Debian Linux 9.0
Debian Debian Linux 8.0
1 EDB exploit available
1 Metasploit module available
32 Github repositories available
1 Article available
NA
CVE-2014-0231
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor....
Apache Http Server 2.4.2
Apache Http Server 2.4.3
Apache Http Server -
Apache Http Server 2.2.6
Apache Http Server 2.2.14
Apache Http Server 2.2.15
Apache Http Server 2.2.22
Apache Http Server 2.2.23
Apache Http Server
Apache Http Server 2.4.7
Apache Http Server 2.2.0
Apache Http Server 2.2.10
Apache Http Server 2.2.11
Apache Http Server 2.2.18
Apache Http Server 2.2.19
Apache Http Server 2.2.26
Apache Http Server 2.2.27
Apache Http Server 2.4.8
Apache Http Server 2.4.1
Apache Http Server 2.2.2
Apache Http Server 2.2.3
Apache Http Server 2.2.4
Apache Http Server 2.2.12
Apache Http Server 2.2.13
Apache Http Server 2.2.20
Apache Http Server 2.2.21
Apache Http Server 2.4.4
Apache Http Server 2.4.6
Apache Http Server 2.2.8
Apache Http Server 2.2.9
Apache Http Server 2.2.16
Apache Http Server 2.2.17
Apache Http Server 2.2.24
Apache Http Server 2.2.25
16 Github repositories available
6.1
CVSSv3
CVE-2016-4975
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache...
Apache Http Server 2.2.3
Apache Http Server 2.2.4
Apache Http Server 2.2.14
Apache Http Server 2.2.15
Apache Http Server 2.2.22
Apache Http Server 2.2.23
Apache Http Server 2.4.23
Apache Http Server 2.4.20
Apache Http Server 2.4.18
Apache Http Server 2.4.6
Apache Http Server 2.4.4
Apache Http Server 2.2.10
Apache Http Server 2.2.11
Apache Http Server 2.2.18
Apache Http Server 2.2.19
Apache Http Server 2.2.26
Apache Http Server 2.2.27
Apache Http Server 2.4.12
Apache Http Server 2.4.10
Apache Http Server 2.4.1
Apache Http Server 2.2.6
Apache Http Server 2.2.8
Apache Http Server 2.2.9
Apache Http Server 2.2.16
Apache Http Server 2.2.17
Apache Http Server 2.2.24
Apache Http Server 2.2.25
Apache Http Server 2.4.17
Apache Http Server 2.4.16
Apache Http Server 2.4.3
Apache Http Server 2.4.2
Apache Http Server 2.2.0
Apache Http Server 2.2.2
Apache Http Server 2.2.12
Apache Http Server 2.2.13
Apache Http Server 2.2.20
Apache Http Server 2.2.21
Apache Http Server 2.2.29
Apache Http Server 2.2.31
Apache Http Server 2.4.9
Apache Http Server 2.4.7
16 Github repositories available
NA
CVE-2015-3185
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended...
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 15.04
Canonical Ubuntu Linux 14.04
Apache Http Server 2.4.12
Apache Http Server 2.4.13
Apache Http Server 2.4.9
Apache Http Server 2.4.2
Apache Http Server 2.4.3
Apache Http Server 2.4.0
Apache Http Server 2.4.4
Apache Http Server 2.4.6
Apache Http Server 2.4.1
Apache Http Server 2.4.10
Apache Http Server 2.4.7
Apache Http Server 2.4.8
Apple Mac Os X Server 5.0.3
Apple Xcode 7.0
Apple Mac Os X 10.10.4
1 Github repository available
NA
CVE-2014-8109
mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass...
Apache Http Server 2.4.1
Apache Http Server 2.4.6
Apache Http Server 2.4.3
Apache Http Server 2.4.4
Apache Http Server 2.4.10
Apache Http Server 2.4.7
Apache Http Server 2.4.2
Apache Http Server 2.4.9
Canonical Ubuntu Linux 14.10
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 10.04
Canonical Ubuntu Linux 12.04
Fedoraproject Fedora 21
Oracle Enterprise Manager Ops Center 12.2.1
Oracle Enterprise Manager Ops Center 12.3.0
Oracle Enterprise Manager Ops Center 12.2.0
Oracle Enterprise Manager Ops Center
2 Github repositories available
7.5
CVSSv3
CVE-2017-15710
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not...
Apache Http Server 2.4.29
Apache Http Server 2.4.28
Apache Http Server 2.4.27
Apache Http Server 2.4.3
Apache Http Server 2.4.2
Apache Http Server 2.4.1
Apache Http Server 2.4.26
Apache Http Server 2.4.23
Apache Http Server 2.4.9
Apache Http Server 2.4.6
Apache Http Server 2.4.18
Apache Http Server 2.4.17
Apache Http Server 2.4.16
Apache Http Server 2.4.12
Apache Http Server 2.4.25
Apache Http Server 2.4.20
Apache Http Server 2.4.10
Apache Http Server 2.4.7
Apache Http Server 2.4.4
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Debian Debian Linux 9.0
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 17.10
Netapp Storage Automation Store -
Netapp Storagegrid -
Netapp Clustered Data Ontap -
Netapp Santricity Cloud Connector -
Redhat Enterprise Linux 7.4
Redhat Enterprise Linux 7.6
Redhat Enterprise Linux 6.0
Redhat Enterprise Linux 7.0
Redhat Enterprise Linux 7.5
24 Github repositories available
9.8
CVSSv3
CVE-2018-1312
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests...
Apache Http Server 2.4.1
Apache Http Server 2.4.20
Apache Http Server 2.4.6
Apache Http Server 2.4.12
Apache Http Server 2.4.3
Apache Http Server 2.4.23
Apache Http Server 2.4.4
Apache Http Server 2.4.10
Apache Http Server 2.4.7
Apache Http Server 2.4.2
Apache Http Server 2.4.9
Apache Http Server 2.4.16
Apache Http Server 2.4.17
Apache Http Server 2.4.18
Apache Http Server 2.4.25
Apache Http Server 2.4.26
Apache Http Server 2.4.27
Apache Http Server 2.4.28
Apache Http Server 2.4.29
Canonical Ubuntu Linux 17.10
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 12.04
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Debian Debian Linux 9.0
Netapp Cloud Backup -
Netapp Storagegrid -
Netapp Clustered Data Ontap -
Redhat Jboss Core Services 1.0
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux Workstation 7.0
Redhat Enterprise Linux Server 7.0
Redhat Enterprise Linux Server Tus 7.6
Redhat Enterprise Linux Server Aus 7.6
Redhat Enterprise Linux Eus 7.6
26 Github repositories available
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
seacms
CVE-2023-28393
remote code execution
authentication bypass
open redirect
acymailing
CVE-2023-43339
CVE-2023-3664
openstack
popup builder
CVE-2023-21987
CVE-2023-21991
CVE-2023-3550
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »