|
1
|
7.5
-
|
HIGH
Network
|
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP Server: from 2.4.17 …
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-49975
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.17
|
|
|
2.4.68
|
2026-06-11 04:36
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
7.3
-
|
HIGH
Network
|
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
|
CWE-416
Use After Free
|
CVE-2026-48913
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.55
|
|
|
2.4.68
|
2026-06-11 04:31
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
9.8
-
|
CRITICAL
Network
|
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to…
|
CWE-124
Buffer Underflow
|
CVE-2026-44631
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
|
|
2.4.68
|
2026-06-11 13:01
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
7.3
-
|
HIGH
Network
|
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: f…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-44186
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
|
|
2.4.68
|
2026-06-11 13:01
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
7.3
-
|
HIGH
Network
|
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are rec…
|
CWE-126
Buffer Over-read
|
CVE-2026-44185
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
|
|
2.4.68
|
2026-06-11 13:01
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
5.5
-
|
MEDIUM
Local
|
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
This issue affects Apache HTT…
|
CWE-269
Improper Privilege Management
|
CVE-2026-44119
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
|
|
2.4.68
|
2026-06-11 13:01
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
6.5
-
|
MEDIUM
Network
|
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-43951
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
2.4.67
|
|
|
2026-06-11 13:00
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
7.5
-
|
HIGH
Network
|
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are re…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-42536
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
|
|
2.4.68
|
2026-06-10 00:55
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
9.1
-
|
CRITICAL
Network
|
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
User…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2026-42535
|
cpe:2.3:a:apache:http_server:*:*
|
|
|
|
2.4.68
|
2026-06-10 01:00
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
7.5
-
|
HIGH
Network
|
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-34356
|
cpe:2.3:a:apache:http_server:*:*
|
2.4.0
|
|
|
2.4.68
|
2026-06-10 01:17
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|