Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache http server 1.3.14 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2001-1072
Apache with mod_rewrite enabled on most UNIX systems allows remote malicious users to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
Apache Http Server 1.3.14
Apache Http Server 1.3.17
Apache Http Server 1.3.19
9.8
CVSSv3
CVE-2001-0766
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote malicious users to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
Apache Http Server 1.3.14
1 EDB exploit
5
CVSSv2
CVE-2001-0925
The default installation of Apache prior to 1.3.19 allows remote malicious users to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2)...
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.14
Apache Http Server 1.3.17
Debian Debian Linux 2.2
4 EDB exploits
3.3
CVSSv2
CVE-2001-0131
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
Apache Http Server 1.3.14
Apache Http Server 2.0
Debian Debian Linux 2.2
5
CVSSv2
CVE-2001-1342
Apache prior to 1.3.20 on Windows and OS/2 systems allows remote malicious users to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
Apache Http Server 1.3.12
Apache Http Server 1.3.14
Apache Http Server 1.3.15
Apache Http Server 1.3.16
Apache Http Server 1.3.17
Apache Http Server 1.3.18
Apache Http Server 1.3.19
7.5
CVSSv2
CVE-2002-2029
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote malicious users to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.13
Apache Http Server 1.3.14
Apache Http Server 1.3.15
Apache Http Server 1.3.16
Apache Http Server 1.3.17
Apache Http Server 1.3.18
Apache Http Server 1.3.19
Apache Http Server 1.3.20
1 EDB exploit
5
CVSSv2
CVE-2002-2103
Apache prior to 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote malicious users to hide the original source of activities.
Apache Http Server 1.3.9
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.13
Apache Http Server 1.3.14
Apache Http Server 1.3.15
Apache Http Server 1.3.16
Apache Http Server 1.3.17
Apache Http Server 1.3.18
Apache Http Server 1.3.19
Apache Http Server 1.3.20
Apache Http Server 1.3.22
4.6
CVSSv2
CVE-2002-1658
Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow malicious users to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation ...
Apache Http Server 1.3.1
Apache Http Server 1.3.3
Apache Http Server 1.3.4
Apache Http Server 1.3.6
Apache Http Server 1.3.9
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.14
Apache Http Server 1.3.17
Apache Http Server 1.3.18
Apache Http Server 1.3.19
Apache Http Server 1.3.20
7.5
CVSSv2
CVE-2003-0993
mod_access in Apache 1.3 prior to 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote malicious users to bypass intended access restrictions.
Apache Http Server 1.3
Apache Http Server 1.3.1
Apache Http Server 1.3.3
Apache Http Server 1.3.4
Apache Http Server 1.3.6
Apache Http Server 1.3.7
Apache Http Server 1.3.9
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.14
Apache Http Server 1.3.17
Apache Http Server 1.3.18
7.5
CVSSv2
CVE-2001-1449
The default installation of Apache prior to 1.3.19 on Mandrake Linux 7.1 up to and including 8.0 and Linux Corporate Server 1.0.1 allows remote malicious users to list the directory index of arbitrary web directories.
Apache Http Server 1.3
Apache Http Server 1.3.1
Apache Http Server 1.3.3
Apache Http Server 1.3.4
Apache Http Server 1.3.6
Apache Http Server 1.3.9
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.14
Apache Http Server 1.3.17
Apache Http Server 1.3.18
Mandrakesoft Mandrake Single Network Firewall 7.2
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
CVE-2024-6437
CVE-2024-47517
CVE-2024-9131
CVE-2025-0283
insecure direct object reference
CVE-2024-49113
reflected XSS
firmware
CVE-2024-54847
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »