Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2001-12-31 CVE-2001-1556 Remote Security vulnerability in Apache
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
network
low complexity
apache
5.0
2001-12-31 CVE-2001-1534 Session Fixation vulnerability in Apache Http Server
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
local
low complexity
apache CWE-384
2.1
2001-12-06 CVE-2001-0829 Cross-Site Scripting vulnerability in Apache Tomcat 3.2.1
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
network
high complexity
apache
5.1
2001-11-28 CVE-2001-1449 Remote Security vulnerability in Apache
The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
network
low complexity
apache mandrakesoft
7.5
2001-10-18 CVE-2001-0766 Improper Handling of Case Sensitivity vulnerability in Apache Http Server 1.3.14
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
network
low complexity
apache CWE-178
critical
9.8
2001-08-31 CVE-2001-1072 Unspecified vulnerability in Apache Http Server 1.3.14/1.3.17/1.3.19
Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
network
low complexity
apache
5.0
2001-08-02 CVE-2001-0590 Unspecified vulnerability in Apache Tomcat
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e.
network
low complexity
apache
5.0
2001-03-12 CVE-2001-0131 htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
local
high complexity
apache immunix redhat
1.2
2001-02-16 CVE-2001-0042 Unspecified vulnerability in Apache Http Server 1.3
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified ..
network
low complexity
apache
5.0
2000-11-14 CVE-2000-0869 The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
network
low complexity
apache suse
5.0