Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Apache Http Server
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-3581 1 Apache 1 Apache Http Server 2021-06-06 5.0 MEDIUM N/A
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.
CVE-2009-1191 1 Apache 1 Apache Http Server 2021-06-06 5.0 MEDIUM N/A
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
CVE-2010-1151 1 Apache 1 Apache Http Server 2010-05-27 6.8 MEDIUM N/A
Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.