|
41
|
7.5
5.0
|
HIGH
Network
|
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, le…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-13950
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.41
|
2.4.46
|
|
|
2024-11-21 14:02
2021-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
5.5
2.1
|
MEDIUM
Local
|
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
|
CWE-862
Missing Authorization
|
CVE-2020-13938
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
2.4.46
|
|
|
2024-11-21 14:02
2021-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
5.3
5.0
|
MEDIUM
Network
|
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing …
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-17567
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.6
|
2.4.46
|
|
|
2024-11-21 13:32
2021-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
7.3
6.8
|
HIGH
Network
|
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35452
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
2.4.46
|
|
|
2024-11-21 14:27
2021-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
7.5
5.0
|
HIGH
Network
|
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resou…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-9490
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.20
|
|
|
2.4.46
|
2024-11-21 14:40
2020-08-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
7.5
4.3
|
HIGH
Network
|
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing con…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-11993
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.20
|
2.4.43
|
|
|
2024-11-21 13:59
2020-08-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
5.3
4.3
|
MEDIUM
Network
|
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for lo…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-11985
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.1
|
2.4.23
|
|
|
2024-11-21 13:59
2020-08-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
9.8
7.5
|
CRITICAL
Network
|
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-11984
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.32
|
2.4.43
|
|
|
2024-11-21 13:59
2020-08-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
6.1
5.8
|
MEDIUM
Network
|
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL…
|
CWE-601
Open Redirect
|
CVE-2020-1927
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
2.4.41
|
|
|
2024-11-21 14:11
2020-04-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
5.3
5.0
|
MEDIUM
Network
|
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-1934
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
2.4.41
|
|
|
2024-11-21 14:11
2020-04-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|