Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Apache HTTP Server Number Of NVD 283 CRITICAL 22 HIGH 92 MEDIUM 156 LOW 13
URL https://httpd.apache.org/
Explanation It is the most widely used web server software in the world, and is used for everything from large commercial sites to home servers. It is also referred to simply as Apache.

The above text is excerpted from "https://ja.wikipedia.org/wiki/Apache_HTTP_Server".

It has become one of the open source combinations called LAMP (Linux, Apache, MySQL [MariaDB], PHP).
Tag
  • Apache License v2.0
  • オープンソース

Add Information URL
No Type Name URL
1 https://httpd.apache.org/download.cgi

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
41 Apache HTTP Server 2.4 2.4.66 Dec. 4, 2025 Feb. 21, 2012 19 33 33 1
42 Apache HTTP Server 2.0 2.0.65 July 10, 2013 April 6, 2002 July 10, 2013 8 28 72 5
43 Apache HTTP Server 2.3 2.3.9 7 9 8 0
44 Apache HTTP Server 2.2 2.2.9 11 20 68 7
45 Apache HTTP Server 2.1 2.1.9 8 9 12 0
46 Apache HTTP Server 2.0 2.0.9 8 21 53 4
47 Apache HTTP Server 12.2 12.2.1.3.0 0 0 0 0
48 Apache HTTP Server 12.1 12.1.3.0.0 0 0 0 0
49 Apache HTTP Server 11.1 11.1.1.9.0 0 0 0 0
50 Apache HTTP Server 1.99 1.99 8 11 11 0
51 Apache HTTP Server 1.4 1.4.0 8 11 11 0
52 Apache HTTP Server 1.3 1.3.9 9 27 42 3
53 Apache HTTP Server 1.2 1.2.9 8 16 18 0
54 Apache HTTP Server 1.15 1.15.17 8 12 11 0
55 Apache HTTP Server 1.1 1.1.1 8 18 19 0
56 Apache HTTP Server 1.0 1.0.5 8 17 19 0
57 Apache HTTP Server 0.8 0.8.14 8 16 18 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
41 7.5
5.0
HIGH
Network
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, le… CWE-476
 NULL Pointer Dereference
CVE-2020-13950 cpe:2.3:a:apache:http_server:*:* 2.4.41 2.4.46 2024-11-21 14:02
2021-06-10
Show GitHub Exploit DB Packet Storm
42 5.5
2.1
MEDIUM
Local
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows CWE-862
 Missing Authorization
CVE-2020-13938 cpe:2.3:a:apache:http_server:*:* 2.4.0 2.4.46 2024-11-21 14:02
2021-06-10
Show GitHub Exploit DB Packet Storm
43 5.3
5.0
MEDIUM
Network
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing … CWE-444
HTTP Request Smuggling
CVE-2019-17567 cpe:2.3:a:apache:http_server:*:* 2.4.6 2.4.46 2024-11-21 13:32
2021-06-10
Show GitHub Exploit DB Packet Storm
44 7.3
6.8
HIGH
Network
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP … CWE-787
 Out-of-bounds Write
CVE-2020-35452 cpe:2.3:a:apache:http_server:*:* 2.4.0 2.4.46 2024-11-21 14:27
2021-06-10
Show GitHub Exploit DB Packet Storm
45 7.5
5.0
HIGH
Network
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resou… CWE-444
HTTP Request Smuggling
CVE-2020-9490 cpe:2.3:a:apache:http_server:*:* 2.4.20 2.4.46 2024-11-21 14:40
2020-08-8
Show GitHub Exploit DB Packet Storm
46 7.5
4.3
HIGH
Network
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing con… CWE-444
HTTP Request Smuggling
CVE-2020-11993 cpe:2.3:a:apache:http_server:*:* 2.4.20 2.4.43 2024-11-21 13:59
2020-08-8
Show GitHub Exploit DB Packet Storm
47 5.3
4.3
MEDIUM
Network
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for lo… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2020-11985 cpe:2.3:a:apache:http_server:*:* 2.4.1 2.4.23 2024-11-21 13:59
2020-08-8
Show GitHub Exploit DB Packet Storm
48 9.8
7.5
CRITICAL
Network
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE CWE-120
Classic Buffer Overflow
CVE-2020-11984 cpe:2.3:a:apache:http_server:*:* 2.4.32 2.4.43 2024-11-21 13:59
2020-08-8
Show GitHub Exploit DB Packet Storm
49 6.1
5.8
MEDIUM
Network
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL… CWE-601
Open Redirect
CVE-2020-1927 cpe:2.3:a:apache:http_server:*:* 2.4.0 2.4.41 2024-11-21 14:11
2020-04-2
Show GitHub Exploit DB Packet Storm
50 5.3
5.0
MEDIUM
Network
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. CWE-908
 Use of Uninitialized Resource
CVE-2020-1934 cpe:2.3:a:apache:http_server:*:* 2.4.0 2.4.41 2024-11-21 14:11
2020-04-2
Show GitHub Exploit DB Packet Storm