Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown

CVE-2005-2728

Disclosure Date: August 30, 2005 (last updated October 04, 2023)
The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
0
Attacker Value
Unknown

CVE-2004-0263

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2004-1834

Disclosure Date: March 20, 2004 (last updated February 22, 2025)
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
0
Attacker Value
Unknown

CVE-2003-1307

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP.
0
Attacker Value
Unknown

CVE-2003-0542

Disclosure Date: November 03, 2003 (last updated February 22, 2025)
Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
0
Attacker Value
Unknown

CVE-2003-0254

Disclosure Date: August 18, 2003 (last updated February 22, 2025)
Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.
0
Attacker Value
Unknown

CVE-2003-0192

Disclosure Date: August 18, 2003 (last updated February 22, 2025)
Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
0
Attacker Value
Unknown

CVE-2003-0253

Disclosure Date: August 18, 2003 (last updated February 22, 2025)
The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.
0
Attacker Value
Unknown

CVE-2003-0134

Disclosure Date: April 11, 2003 (last updated February 22, 2025)
Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.
0
Attacker Value
Unknown

CVE-2002-0840

Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
0