Apache 2.2
httpd: Weak Digest auth nonce generation in mod_auth_digest
httpd: mod_mime buffer overread
httpd: mod_ssl NULL pointer dereference
httpd: ap_get_basic_auth_pw() authentication bypass
httpd: Uninitialized memory reflection in mod_auth_digest
HTTPD: sets environmental variable based on user supplied Proxy request header
httpd: multiple ranges DoS
Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled
mod_auth_mysql: character encoding SQL injection flaw
httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values
apr-util billion laughs attack
(apr): Improper pollset feature error handling on Solaris - DoS (hang)
httpd: Apache HTTP Request Parsing Whitespace Defects
httpd: ap_find_token() buffer overread
httpd: Use-after-free by limiting unregistered HTTP method (Optionsbleed)
Apache HTTP Server: mod_ssl TLS upgrade attack
httpd: possible temporary DoS (CPU consumption) in mod_deflate
httpd: mod_proxy reverse proxy DoS (infinite loop)
httpd: insecure handling of LD_LIBRARY_PATH in envvars
httpd: mod_status heap-based buffer overflow
httpd: # character matches all IPs
apr-util single NULL byte buffer overflow
mod_autoindex XSS
mod_userdir CRLF injection
TLS: MITM attacks via session renegotiation
security flaw
httpd: mod_rewrite allows terminal escape sequences to be written to the log file
httpd: Apache Slowloris denial of service
httpd: bypass of mod_headers rules via chunked requests
httpd: out of bounds read
httpd mod_cache segfault
httpd: mod_proxy_http DoS via excessive interim responses from the origin server
httpd: Reverse proxy sends wrong responses after time-outs
httpd mod_proxy_ajp information disclosure
httpd: mod_proxy_ftp FTP command injection via Authorization HTTP header
httpd: mod_proxy_ajp remote temporary DoS
(mod_proxy): Sensitive response disclosure due improper handling of timeouts
mod_dav: DoS (httpd child process crash) by parsing URI structure with missing path segments
apr-util: high memory consumption in apr_brigade_split_line()
expat: buffer over-read and crash on XML with malformed UTF-8 sequences
expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
httpd: mod_proxy_ajp worker moved to error state when timeout exceeded
httpd: reverse web proxy vulnerability
httpd: mod_log_config does not properly handle logging certain cookies resulting in DoS
httpd: mod_dav denial of service via crafted DAV WRITE request
httpd: mod_cgid denial of service
httpd: AllowOverride Options=IncludesNoExec allows Options Includes
httpd scoreboard lack of PID protection
httpd: possible crash on shutdown due to flaw in scoreboard handling
httpd: ap_pregsub Integer overflow to buffer overflow
When document is on smbfs, a trailing backslash at the end of file name bypasses content type match
httpd: mod_negotiation XSS via untrusted file names in directories with MultiViews enabled
httpd: Garbage before http method name is not escaped in a reply in case of errorneous request
httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page
apr: DoS flaw in apr_fnmatch() due to fix for CVE-2011-0419
httpd: http 0.9 request bypass of the reverse proxy vulnerability CVE-2011-3368 fix
httpd cross-site scripting flaw in mod_imap
httpd mod_status XSS
mod_proxy_ftp XSS
apache mod_status cross-site scripting
httpd: mod_imagemap XSS
mod_proxy_balancer: mod_proxy_balancer CSRF
httpd: mod_proxy_ftp globbing XSS
apr-util heap buffer underwrite
httpd: request header information leak
apr: unconstrained recursion in apr_fnmatch
httpd: mod_proxy_ajp remote temporary DoS
httpd: cookie exposure due to error responses
httpd: uri scheme bypass of the reverse proxy vulnerability CVE-2011-3368 fix
httpd: XSS flaw in mod_proxy_balancer manager interface
httpd: multiple XSS flaws due to unescaped hostnames
httpd: mod_dav DoS (httpd child process crash) via a URI MERGE request with source URI not handled by mod_dav
httpd: mod_deflate denial of service
httpd mod_proxy_balancer crash
httpd: HTTP request smuggling attack against chunked request parser
httpd mod_proxy_balancer cross-site scripting
httpd: mod_negotiation CRLF injection via untrusted file names in directories with MultiViews enabled
httpd: NULL pointer defer in mod_proxy_ftp caused by crafted EPSV and PASV reply
httpd: NULL pointer dereference crash in mod_log_config
httpd: mod_negotiation XSS via untrusted file names in directories with MultiViews enabled
httpd: SetEnvIf resource exhaustion