Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-1387 Local Security vulnerability in Apache Http Server 1.3.31
The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
local
low complexity
apache
2.1
2004-11-23 CVE-2004-0263 PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
network
low complexity
apache ibm
5.0
2004-10-20 CVE-2004-0747 Incorrect Calculation of Buffer Size vulnerability in Apache Http Server
Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
local
low complexity
apache CWE-131
7.8
2004-05-04 CVE-2004-0174 Improper Locking vulnerability in Apache Http Server
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
network
low complexity
apache CWE-667
7.5
2004-04-15 CVE-2004-0173 Directory Traversal vulnerability in Apache Cygwin
Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
network
low complexity
apache
5.0
2004-03-03 CVE-2004-0096 Unspecified vulnerability in Apache MOD Python 2.7.9
Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.
network
low complexity
apache
5.0
2004-02-03 CVE-2004-1082 mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
network
low complexity
apache apple avaya hp ibm openbsd sco sun
7.5
2003-12-31 CVE-2003-1418 Information Exposure vulnerability in Apache Http Server
Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).
network
apache CWE-200
4.3
2003-12-31 CVE-2003-1172 Directory Traversal vulnerability in Apache Cocoon 2.1/2.1.2/2.2
Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a ..
network
low complexity
apache
5.0
2003-12-15 CVE-2003-0973 Unspecified vulnerability in Apache MOD Python
Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.
network
low complexity
apache
5.0