Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Apache HTTP Server Number Of NVD 283 CRITICAL 22 HIGH 92 MEDIUM 156 LOW 13
URL https://httpd.apache.org/
Explanation It is the most widely used web server software in the world, and is used for everything from large commercial sites to home servers. It is also referred to simply as Apache.

The above text is excerpted from "https://ja.wikipedia.org/wiki/Apache_HTTP_Server".

It has become one of the open source combinations called LAMP (Linux, Apache, MySQL [MariaDB], PHP).
Tag
  • Apache License v2.0
  • オープンソース

Add Information URL
No Type Name URL
1 https://httpd.apache.org/download.cgi

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
241 Apache HTTP Server 2.4 2.4.66 Dec. 4, 2025 Feb. 21, 2012 19 33 33 1
242 Apache HTTP Server 2.0 2.0.65 July 10, 2013 April 6, 2002 July 10, 2013 8 28 72 5
243 Apache HTTP Server 2.3 2.3.9 7 9 8 0
244 Apache HTTP Server 2.2 2.2.9 11 20 68 7
245 Apache HTTP Server 2.1 2.1.9 8 9 12 0
246 Apache HTTP Server 2.0 2.0.9 8 21 53 4
247 Apache HTTP Server 12.2 12.2.1.3.0 0 0 0 0
248 Apache HTTP Server 12.1 12.1.3.0.0 0 0 0 0
249 Apache HTTP Server 11.1 11.1.1.9.0 0 0 0 0
250 Apache HTTP Server 1.99 1.99 8 11 11 0
251 Apache HTTP Server 1.4 1.4.0 8 11 11 0
252 Apache HTTP Server 1.3 1.3.9 9 27 42 3
253 Apache HTTP Server 1.2 1.2.9 8 16 18 0
254 Apache HTTP Server 1.15 1.15.17 8 12 11 0
255 Apache HTTP Server 1.1 1.1.1 8 18 19 0
256 Apache HTTP Server 1.0 1.0.5 8 17 19 0
257 Apache HTTP Server 0.8 0.8.14 8 16 18 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
241 -
5.0
MEDIUM Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled. NVD-CWE-Other
CVE-2002-1156 cpe:2.3:a:apache:http_server:2.0.42:* 2023-11-7 10:55
2002-10-11
Show GitHub Exploit DB Packet Storm
242 -
5.0
MEDIUM mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumpti… NVD-CWE-Other
CVE-2002-1593 cpe:2.3:a:apache:http_server:2.0:*
cpe:2.3:a:apache:http_server:2.0.41:*
cpe:2.3:a:apache:http_server:2.0.40:*
2023-11-7 10:56
2002-09-25
Show GitHub Exploit DB Packet Storm
243 -
5.0
MEDIUM Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resultin… NVD-CWE-Other
CVE-2002-0654 cpe:2.3:a:apache:http_server:2.0:*
cpe:2.3:a:apache:http_server:2.0.39:*
cpe:2.3:a:apache:http_server:2.0.38:*
2023-11-7 10:55
2002-09-5
Show GitHub Exploit DB Packet Storm
244 -
7.5
HIGH Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing … NVD-CWE-Other
CVE-2002-0661 cpe:2.3:a:apache:http_server:2.0:*
cpe:2.3:a:apache:http_server:2.0.39:*
cpe:2.3:a:apache:http_server:2.0.38:*
2023-11-7 10:55
2002-08-12
Show GitHub Exploit DB Packet Storm
245 -
7.5
HIGH Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache … NVD-CWE-noinfo
CVE-2002-0392 cpe:2.3:a:apache:http_server:*:* 2.0.0
1.2.2
2.0.36
1.3.24


2023-11-7 10:55
2002-07-3
Show GitHub Exploit DB Packet Storm
246 -
5.0
MEDIUM PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reve… NVD-CWE-Other
CVE-2002-0240 cpe:2.3:a:apache:http_server:2.0.28:beta 2016-10-18 11:17
2002-05-29
Show GitHub Exploit DB Packet Storm
247 -
5.0
MEDIUM PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /12… NVD-CWE-Other
CVE-2002-0249 cpe:2.3:a:apache:http_server:2.0.28:beta 2016-10-18 11:17
2002-05-29
Show GitHub Exploit DB Packet Storm
248 -
7.5
HIGH Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4… NVD-CWE-Other
CVE-2002-0257 cpe:2.3:a:apache:http_server:1.3.22:*
cpe:2.3:a:apache:http_server:1.3.20:*
cpe:2.3:a:apache:http_server:1.3.19:*…
2016-10-18 11:17
2002-05-29
Show GitHub Exploit DB Packet Storm
249 -
5.0
MEDIUM The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote a… NVD-CWE-Other
CVE-2002-1592 cpe:2.3:a:apache:http_server:2.0:*
cpe:2.3:a:apache:http_server:2.0.35:*
cpe:2.3:a:apache:http_server:2.0.32:*
2023-11-7 10:56
2002-05-6
Show GitHub Exploit DB Packet Storm
250 -
7.5
HIGH Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat)… CWE-78
OS Command 
CVE-2002-0061 cpe:2.3:a:apache:http_server:*:*
2.0.0


1.3.24
2.0.34
2024-01-27 05:01
2002-03-21
Show GitHub Exploit DB Packet Storm