Known vulnerabilities in Apache HTTP Server 2.4.42 - page 2

Version: 2.4.42
Software CPE: cpe:2.3:a:apache_foundation:apache_http_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 83
Public exploits: 14
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apache HTTP Server version 2.4.42 Apache HTTP Server 2.4.42 is affected by 83 vulnerabilities: 2 critical, 13 high, 53 medium, 15 low Critical High Medium Low

Vulnerabilities (83)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU129540 - Out-of-bounds read
CVE-2026-34059
CWE-125 Medium
No
No
2.4.67 04.05.2026 SB2026050479
SB2026050772
SB2026051240
and 24 more
#VU129548 - Heap-based Buffer Overflow
CVE-2026-28780
CWE-122 High
No
No
2.4.67 04.05.2026 SB2026050479
SB2026050772
SB2026051101
and 24 more
#VU129549 - Improper Access Control
CVE-2026-24072
CWE-284 Low
No
No
2.4.67 04.05.2026 SB2026050479
SB2026050772
SB2026051240
and 18 more
#VU119150 - Integer overflow
CVE-2025-55753
CWE-190 Low
No
No
2.4.66 04.12.2025 SB2025120441
SB2025121923
SB2025121940
and 31 more
#VU119149 - Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
CVE-2025-58098
CWE-97 Low
Public exploit available
No
2.4.66 04.12.2025 SB2025120441
SB2025121923
SB2025121940
and 46 more
#VU119148 - Server-Side Request Forgery (SSRF)
CVE-2025-59775
CWE-918 Medium
No
No
2.4.66 04.12.2025 SB2025120441
SB2026010820
SB20260114117
and 10 more
#VU119147 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-65082
CWE-74 Low
No
No
2.4.66 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 32 more
#VU119146 - Improper input validation
CVE-2025-66200
CWE-20 Low
No
No
2.4.66 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 30 more
#VU112734 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2024-42516
CWE-113 Low
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 33 more
#VU112733 - Server-Side Request Forgery (SSRF)
CVE-2024-43204
CWE-918 Low
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 27 more
#VU112732 - Server-Side Request Forgery (SSRF)
CVE-2024-43394
CWE-918 Medium
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071710
SB2025072111
and 7 more
#VU112731 - Improper Encoding or Escaping of Output
CVE-2024-47252
CWE-116 High
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 34 more
#VU112730 - Security Features
CVE-2025-23048
CWE-254 Medium
Public exploit available
No
2.4.64 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 29 more
#VU112729 - Resource Management Errors
CVE-2025-49630
CWE-399 Medium
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 26 more
#VU112728 - Cryptographic Issues
CVE-2025-49812
CWE-310 Medium
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 34 more
#VU112727 - Resource Management Errors
CVE-2025-53020
CWE-399 Medium
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071201
SB2025071202
and 17 more
#VU94503 - Server-Side Request Forgery (SSRF)
CVE-2024-40898
CWE-918 High
Public exploit available
No
2.4.62 17.07.2024 SB20240717136
SB2024071896
SB2024081362
and 13 more
#VU93542 - Improper input validation
CVE-2024-38475
CWE-20 Critical
Public exploit available
No
2.4.60 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 54 more
#VU93540 - Improper input validation
CVE-2024-38473
CWE-20 Medium
Public exploit available
No
2.4.60 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 47 more
#VU93539 - Server-Side Request Forgery (SSRF)
CVE-2024-38472
CWE-918 Medium
Public exploit available
No
2.4.60 01.07.2024 SB2024070155
SB20240702144
SB2024081362
and 11 more


Showing elements 21 - 40 out of 83