Apache 2.0

Status EOLSupport 2002-04 – 2013-07Latest 2.0.65Vulnerabilities 97← All Apache versions
Critical 10.0
2003-10-30< 2.0.48

security flaw

Critical 10.0
2005-09-06< 2.0.55

security flaw

Critical 10.0
2010-03-05≥ 2.0.37 and ≤ 2.0.63

Critical 9.8 Unfixed
2018-03-26≤ 2.0.65

httpd: Weak Digest auth nonce generation in mod_auth_digest

High 7.8
2004-09-17≥ 2.0.35 and ≤ 2.0.50

security flaw

High 7.8
2011-08-29< 2.0.65

httpd: multiple ranges DoS

High 7.6
2006-07-28< 2.0.59

High 7.5 Unfixed
0000-00-00≤ 2.0.65

Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled

High 7.5 Unfixed
2009-01-22≤ 2.0.65

mod_auth_mysql: character encoding SQL injection flaw

High 7.5
2005-04-27= 2.0.52

High 7.5 Unfixed
2018-03-26≥ 2.0.23 and ≤ 2.0.65

httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values

High 7.5
2003-04-02< 2.0.34

High 7.5
2005-06-28≥ 2.0.39 and ≤ 2.0.40

High 7.5
2003-04-02< 2.0.37

security flaw

High 7.5
2002-08-10< 2.0.40

High 7.5
2004-09-01< 2.0.44

High 7.5
2004-03-25< 2.0.49

security flaw

High 7.5
2004-05-28< 2.0.50

mod_ssl ssl_util_uuencode_binary CA issue

High 7.5
2004-09-24< 2.0.52

High 7.5
2004-10-16< 2.0.53

mod_ssl SSLCipherSuite bypass

High 7.4 Unfixed
2025-07-10≤ 2.0.65

Apache HTTP Server: mod_ssl TLS upgrade attack

High 7.2
2005-08-16≤ 2.0.47

High 7.2
2003-10-30< 2.0.48

security flaw

High 7.1
2009-07-10≥ 2.0.35 and < 2.0.64

httpd: possible temporary DoS (CPU consumption) in mod_deflate

Medium 6.8
2006-10-16≤ 2.0.58

Medium 6.8
2004-09-01< 2.0.43

security flaw

Medium 6.4
2003-07-10< 2.0.47

security flaw

Medium 6.4
2004-06-30< 2.0.50

security flaw

Medium 6.1
2007-09-14< 2.0.61

mod_autoindex XSS

Medium 5.4
2006-01-06< 2.0.58

security flaw

Medium 5.1
2013-06-10< 2.0.65

httpd: mod_rewrite allows terminal escape sequences to be written to the log file

Medium 5.0
2004-09-01≤ 2.0.48

Medium 5.0
2004-09-01≤ 2.0.48

Medium 5.0
2002-05-03= 2.0.28

Medium 5.0
2002-05-03= 2.0.28

Medium 5.0
2011-12-27≤ 2.0.63

httpd: Apache Slowloris denial of service

Medium 5.0
2005-03-13< 2.0.36

Medium 5.0
2002-08-20< 2.0.40

Medium 5.0
2005-03-13< 2.0.42

Medium 5.0
2004-09-01< 2.0.43

Medium 5.0
2004-09-01< 2.0.44

Medium 5.0
2003-04-03< 2.0.45

security flaw

Medium 5.0
2003-05-30≥ 2.0.37 and < 2.0.46

security flaw

Medium 5.0
2003-05-30≥ 2.0.40 and ≤ 2.0.45

security flaw

Medium 5.0
2003-04-03< 2.0.46

Medium 5.0
2003-03-28< 2.0.46

security flaw

Medium 5.0
2003-07-10< 2.0.47

security flaw

Medium 5.0
2003-07-10< 2.0.47

security flaw

Medium 5.0
2004-09-01< 2.0.49

security flaw

Medium 5.0
2004-09-01< 2.0.49

security flaw

Medium 5.0
2004-09-17< 2.0.51

security flaw

Medium 5.0
2004-09-17< 2.0.51

security flaw

Medium 5.0
2004-09-10< 2.0.51

security flaw

Medium 5.0
2004-09-10< 2.0.51

security flaw

Medium 5.0
2004-11-04< 2.0.53

security flaw

Medium 5.0
2005-10-25< 2.0.55

security flaw

Medium 5.0
2005-08-29< 2.0.55

security flaw

Medium 5.0
2005-08-05< 2.0.55

security flaw

Medium 5.0
2007-08-23≥ 2.0.35 and < 2.0.61

httpd: out of bounds read

Medium 5.0
2007-06-27< 2.0.61

httpd mod_cache segfault

Medium 5.0
2010-10-04≥ 2.0.35 and < 2.0.64

apr-util: high memory consumption in apr_brigade_split_line()

Medium 5.0
2010-07-28≥ 2.0.35 and < 2.0.64

mod_dav: DoS (httpd child process crash) by parsing URI structure with missing path segments

Medium 5.0
2009-11-03≥ 2.0.35 and < 2.0.64

expat: buffer over-read and crash on XML with malformed UTF-8 sequences

Medium 5.0
2009-12-04≥ 2.0.35 and < 2.0.64

expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences

Medium 5.0
2009-09-08≥ 2.0.35 and < 2.0.64

httpd: mod_proxy_ftp FTP command injection via Authorization HTTP header

Medium 5.0
2008-06-13≥ 2.0.35 and < 2.0.64

httpd: mod_proxy_http DoS via excessive interim responses from the origin server

Medium 5.0
2011-10-05< 2.0.65

httpd: reverse web proxy vulnerability

Medium 4.9
2007-06-20= 2.0.59

Medium 4.7
2007-06-20< 2.0.61

httpd scoreboard lack of PID protection

Medium 4.6
2012-01-18< 2.0.65

httpd: possible crash on shutdown due to flaw in scoreboard handling

Medium 4.4
2011-11-08≤ 2.0.64

httpd: ap_pregsub Integer overflow to buffer overflow

Medium 4.3
2006-10-23≤ 2.0.48

Medium 4.3
2006-08-14= 2.0.58

Medium 4.3
2007-12-03≥ 2.0.46 and ≤ 2.0.59

httpd: Garbage before http method name is not escaped in a reply in case of errorneous request

Medium 4.3
2008-05-13≤ 2.0.61

httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page

Medium 4.3
2010-02-05= 2.0.44

Medium 4.3
2011-11-30≥ 2.0.11 and ≤ 2.0.64

httpd: http 0.9 request bypass of the reverse proxy vulnerability CVE-2011-3368 fix

Medium 4.3
2011-11-30≤ 2.0.64

httpd: uri scheme bypass of the reverse proxy vulnerability CVE-2011-3368 fix

Medium 4.3
2005-06-30≥ 2.0.35 and ≤ 2.0.54

security flaw

Medium 4.3
2005-12-13< 2.0.56

httpd cross-site scripting flaw in mod_imap

Medium 4.3
2007-06-27< 2.0.61

httpd mod_status XSS

Medium 4.3
2008-01-12< 2.0.63

mod_proxy_ftp XSS

Medium 4.3
2008-01-08< 2.0.62

apache mod_status cross-site scripting

Medium 4.3
2007-12-13< 2.0.63

httpd: mod_imagemap XSS

Medium 4.3
2010-03-05≥ 2.0.35 and < 2.0.64

httpd: request header information leak

Medium 4.3
2008-08-06< 2.0.64

httpd: mod_proxy_ftp globbing XSS

Medium 4.3
2012-01-28< 2.0.65

httpd: cookie exposure due to error responses

Medium 4.3
2011-05-16≤ 2.0.65

apr: unconstrained recursion in apr_fnmatch

Low 3.3
2005-07-14< 2.0.49

httpd: log files contain information directly supplied by clients and does not filter or quote control characters

Low 2.9
2001-02-14< 2.0.0

httpd: allows local users to overwrite arbitrary files via a symlink attack

Low 2.6
2008-01-25≤ 2.0.61

httpd: mod_negotiation CRLF injection via untrusted file names in directories with MultiViews enabled

Low 2.6
2010-02-05= 2.0.44

httpd: Injection of arbitrary text into log files when DNS resolution is enabled

Low 2.6
2009-09-08≥ 2.0.35 and < 2.0.64

httpd: NULL pointer defer in mod_proxy_ftp caused by crafted EPSV and PASV reply

Low 2.1
2005-05-10< 2.0.53

security flaw

Low 1.2
2011-11-08≤ 2.0.64

httpd: SetEnvIf resource exhaustion

N/A
2005-08-22< 2.0.55

N/A
2009-08-06< 2.0.64