Known vulnerabilities in apache2 (Debian package)
Vendor:
Debian
Software:
apache2 (Debian package)
Software CPE:
cpe:2.3:o:debian:apache2_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
58
Public exploits:
12
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.4.67-1~deb13u3
2.4.67-1~deb12u3
2.4.67-1~deb13u2
2.4.67-1~deb12u2
2.4.61-1~deb12u1
2.4.61-1~deb11u1
2.4.59-1~deb12u1
2.4.59-1~deb11u1
2.4.56-1~deb11u1
2.4.52-1~deb11u21
2.4.52-1~deb11u2
2.4.38-3+deb10u7
2.4.51-1~deb11u1
2.4.38-3+deb10u6
2.4.38-3+deb10u5
2.4.43-1+b1
2.4.46-2
2.4.46-1~bpo9+1
2.4.46-1~bpo10+1
2.4.38-3+deb10u4
2.4.46
2.4.46-1
2.2.15-5+b100
2.2.22-4+b1
2.4.6-3+b3
2.4.10-1+b1
2.4.17-2+b1
2.4.17-2+b2
2.4.23-7+b1
2.4.33-1+b1
2.4.33-3+b1
2.4.43-1~bpo9+1
2.4.43-1~bpo10+1
2.4.43
2.4.41
2.4.38
2.4.25
2.4.10
2.4.43-1
2.4.41-5
2.4.41-4
2.4.41-3
2.4.41-2
2.4.25-3+deb9u9
2.4.38-3+deb10u2
2.4.38-3+deb10u3
2.4.10-10+deb8u16
2.4.10-10+deb8u15
2.4.25-3+deb9u8
2.4.38-3+deb10u1
2.4.39-2
2.4.41-1~bpo10+1
2.4.41-1
2.4.39-1
2.4.38-3
2.4.10-10+deb8u14
2.4.25-3+deb9u7
2.4.38-2
2.4.38-1
2.4.10-10+deb8u13
2.4.25-3+deb9u6
2.4.37-1
2.4.35-1
2.0.54-5sarge1
2.0.54-5sarge2
2.0.55-4.2
2.2.3-4+etch1
2.2.3-4+etch2
2.2.3-4+etch3
2.2.3-4+etch4
2.2.3-4+etch5
2.2.3-4+etch6
2.2.3-4+etch8
2.2.3-4+etch9
2.2.3-4+etch10
2.2.3-4+etch11
2.2.8-4~lenny1
2.2.9-10+lenny1
2.2.9-10+lenny2
2.2.9-10+lenny3
2.2.9-10+lenny4
2.2.9-10+lenny5
2.2.9-10+lenny6
2.2.9-10+lenny7
2.2.9-10+lenny8
2.2.9-10+lenny9
2.2.9-10+lenny10
2.2.9-10+lenny11
2.2.9-10+lenny12
2.2.11-3+hurdfr1
2.2.16-4~bpo50+1
2.2.16-6~bpo50+1
2.2.16-6+squeeze1~bpo50+1
2.2.16-6+squeeze2~bpo50+1
2.2.16-6+squeeze4~bpo50+1
2.2.22-13+deb7u7
2.2.22-13+deb7u8
2.2.22-13+deb7u9
2.2.22-13+deb7u10
2.2.22-13+deb7u11
2.2.22-13+deb7u12
2.2.22-13+deb7u13
2.4.34-1
2.4.33-3
2.4.33-2
2.4.33-1
2.4.29-2
2.4.29-1
2.4.27-6
2.4.27-5
2.4.27-4
2.4.27-3
2.4.27-2
2.4.27-1
2.4.25-4
2.4.25-3+deb9u5
2.4.25-3+deb9u4
2.4.25-3+deb9u3
2.4.25-3+deb9u2
2.4.25-3+deb9u1
2.4.25-3
2.4.25-2
2.4.25-1
2.4.23-8
2.4.23-7
2.4.23-6
2.4.23-5
2.4.23-4
2.4.23-3
2.4.23-2
2.4.23-1
2.4.20-2
2.4.20-1
2.4.18-2
2.4.18-1
2.4.17-3
2.4.17-2
2.4.17-1
2.4.16-3
2.4.16-2
2.4.16-1
2.4.12-2
2.4.12-1
2.4.10-11
2.4.10-10+deb8u12
2.4.10-10+deb8u11
2.4.10-10+deb8u10
2.4.10-10+deb8u9
2.4.10-10+deb8u8
2.4.10-10+deb8u7
2.4.10-10+deb8u6
2.4.10-10+deb8u5
2.4.10-10+deb8u4
2.4.10-10+deb8u3
2.4.10-10+deb8u2
2.4.10-10+deb8u1
2.4.10-10
2.4.10-9
2.4.10-8
2.4.10-7
2.4.10-6
2.4.10-5
2.4.10-4
2.4.10-3
2.4.10-2
2.4.10-1
2.4.9-2
2.4.9-1
2.4.7-1
2.4.6-3
2.4.6-2
2.4.6-1
2.4.4-6
2.4.4-5
2.4.4-4
2.4.4-3
2.4.4-2
2.4.4-1
2.4.2-2
2.4.2-1
2.4.1-3
2.4.1-2
2.4.1-1
2.2.22-13+deb7u6
2.2.22-13+deb7u5
2.2.22-13+deb7u4
2.2.22-13+deb7u3
2.2.22-13+deb7u2
2.2.22-13+deb7u1
2.2.22-13
2.2.22-12
2.2.22-11
2.2.22-10
2.2.22-9
2.2.22-8
2.2.22-7
2.2.22-6
2.2.22-5
2.2.22-4
2.2.22-3
2.2.22-2
2.2.22-1
2.2.21-5
2.2.21-4
2.2.21-3
2.2.21-2
2.2.21-1
2.2.20-1
2.2.19-2
2.2.19-1
2.2.17-3
2.2.17-2
2.2.17-1
2.2.16-6+squeeze15
2.2.16-6+squeeze14
2.2.16-6+squeeze13
2.2.16-6+squeeze12
2.2.16-6+squeeze11
2.2.16-6+squeeze10
2.2.16-6+squeeze8
2.2.16-6+squeeze7
2.2.16-6+squeeze6
2.2.16-6+squeeze5
2.2.16-6+squeeze4
2.2.16-6+squeeze3
2.2.16-6+squeeze2
2.2.16-6+squeeze1
2.2.16-6
2.2.16-5
2.2.16-4
2.2.16-3
2.2.16-2
2.2.16-1
2.2.15-6
2.2.15-5
2.2.15-4
2.2.15-3
2.2.15-2
2.2.15-1
2.2.14-7
2.2.14-6
2.2.14-5
2.2.14-4
2.2.14-3
2.2.14-2
2.2.14-1
2.2.13-2
2.2.13-1
2.2.12-1
2.2.11-7
2.2.11-6
2.2.11-5
2.2.11-4
2.2.11-3
2.2.11-2
2.2.11-1
2.2.9-11
2.2.9-10
2.2.9-9
2.2.9-8
2.2.9-7
2.2.9-6
2.2.9-5
2.2.9-4
2.2.9-3
2.2.9-2
2.2.9-1
2.2.8-5
2.2.8-4
2.2.8-3
2.2.8-2
2.2.8-1
2.2.6-3
2.2.6-2
2.2.6-1
2.2.4-3
2.2.4-2
2.2.4-1
2.2.3-5
2.2.3-4
2.2.3-3.3
2.2.3-3.2
2.2.3-3.1
2.2.3-3
2.2.3-2
2.2.3-1
2.2.3-1~exp.r170
2.0.55-4.1
2.2.0-1
2.0.55-4
2.0.55-3
2.0.55-2
2.0.55-1
2.0.54-5ubuntu2
2.0.54-5ubuntu1
2.0.54-5
2.0.54-4
2.0.54-3
2.0.54-2
2.0.54-1
2.0.53-5ubuntu5
2.0.53-5ubuntu4
2.0.53-5ubuntu3
2.0.53-5ubuntu2
2.0.53-5ubuntu1
2.0.53-5
2.0.53-4
2.0.53-3
2.0.53-2
2.0.53-1
2.0.52-3
2.0.52-2
2.0.52-1
2.0.51-2
2.0.51-1
2.0.50-12
2.0.50-11
2.0.50-10
2.0.50-9
2.0.50-8
2.0.50-7
2.0.50-6
2.0.50-5
2.0.50-4
2.0.50-3
2.0.50-2
2.0.50-1
2.0.49-1
2.0.48-8
2.0.48-7
2.0.48-6
2.0.48-5
2.0.48-4
2.0.48-3
2.0.48-2
2.0.48-1
2.0.47-2
2.0.47-1
2.0.46-3
2.0.46-2
2.0.46-1
2.0.45-3
2.0.45-2
2.0.45-1
2.0.44-6
2.0.44-5
2.0.44-4
2.0.44-3
2.0.44-2
2.0.44-1
2.0.43-1
2.0.42-2
2.0.42-1
2.0.40-1
2.0.39+cvs.1028741220-2
2.0.39+cvs.1028741220-1
2.0.39+cvs.1027964860-1
2.0.39-1
2.0.37-2
2.0.37-1
2.0.37+cvs.JCW_PRE2_2037-1
2.0.36-2
2.0.36-1
2.0.35+cvs.20020420-1
2.0.35-2
2.0.35-1
2.0.34+retag-1
2.0.34-1
2.0.33-1
2.0.32+cvs.20020228-1
2.0.32-1
2.0.31+cvs.20020217-1
2.0.31+cvs.20020207-1
2.0.28-3
2.0.28-2
2.0.28-1
2.0.26+cvs.20011028-2
2.0.26+cvs.20011028-1
2.0.26+cvs.20011023-1
2.0.26-1
2.0.25+cvs.20011001-1
2.0.25+cvs.20010923-1
2.0.25+cvs.20010908-1
2.0.24-2
2.0.24-1
2.0.23-2
2.0.23-1
2.0.22-2
2.0.22-1
2.0.20-2
2.0.20-1
2.0.18-1
Vulnerabilities (58)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU133362 - Resource exhaustion CVE-2026-49975 |
CWE-400 | High | 2.4.67-1~deb12u3, 2.4.67-1~deb13u3 | 04.06.2026 |
SB2026060491 SB2026060492 SB2026060493 and 30 more |
||
| #VU129540 - Out-of-bounds read CVE-2026-34059 |
CWE-125 | Medium | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 27 more |
||
| #VU129541 - Out-of-bounds read CVE-2026-34032 |
CWE-125 | Medium | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 27 more |
||
| #VU129542 - Out-of-bounds read CVE-2026-33857 |
CWE-125 | Medium | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 27 more |
||
| #VU129543 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2026-33523 |
CWE-113 | Medium | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 19 more |
||
| #VU129544 - NULL Pointer Dereference CVE-2026-33007 |
CWE-476 | Medium | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB20260513119 and 19 more |
||
| #VU129545 - Information Exposure Through Timing Discrepancy CVE-2026-33006 |
CWE-208 | High | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB20260513119 and 11 more |
||
| #VU129546 - NULL Pointer Dereference CVE-2026-29169 |
CWE-476 | Medium | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB20260513119 and 16 more |
||
| #VU129547 - Allocation of Resources Without Limits or Throttling CVE-2026-29168 |
CWE-770 | Medium | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051103 and 17 more |
||
| #VU129548 - Heap-based Buffer Overflow CVE-2026-28780 |
CWE-122 | High | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051101 and 27 more |
||
| #VU129549 - Improper Access Control CVE-2026-24072 |
CWE-284 | Low | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 19 more |
||
| #VU129550 - Double Free CVE-2026-23918 |
CWE-415 | High | 2.4.67-1~deb12u2, 2.4.67-1~deb13u2 | 04.05.2026 |
SB2026050479 SB2026050772 SB20260513119 and 11 more |
||
| #VU93545 - Server-Side Request Forgery (SSRF) CVE-2024-39573 |
CWE-918 | Medium | 2.4.61-1~deb11u1, 2.4.61-1~deb12u1 | 01.07.2024 |
SB2024070155 SB20240702144 SB2024070402 and 46 more |
||
| #VU93544 - Improper input validation CVE-2024-38477 |
CWE-20 | Medium | 2.4.61-1~deb11u1, 2.4.61-1~deb12u1 | 01.07.2024 |
SB2024070155 SB20240702144 SB2024070402 and 58 more |
||
| #VU93543 - Server-Side Request Forgery (SSRF) CVE-2024-38476 |
CWE-918 | High | 2.4.61-1~deb11u1, 2.4.61-1~deb12u1 | 01.07.2024 |
SB2024070155 SB20240702144 SB2024070402 and 61 more |
||
| #VU93542 - Improper input validation CVE-2024-38475 |
CWE-20 | Critical | 2.4.61-1~deb11u1, 2.4.61-1~deb12u1 | 01.07.2024 |
SB2024070155 SB20240702144 SB2024070402 and 54 more |
||
| #VU93541 - Improper input validation CVE-2024-38474 |
CWE-20 | Medium | 2.4.61-1~deb11u1, 2.4.61-1~deb12u1 | 01.07.2024 |
SB2024070155 SB20240702144 SB2024070402 and 57 more |
||
| #VU93540 - Improper input validation CVE-2024-38473 |
CWE-20 | Medium | 2.4.61-1~deb11u1, 2.4.61-1~deb12u1 | 01.07.2024 |
SB2024070155 SB20240702144 SB2024070402 and 47 more |
||
| #VU93538 - NULL Pointer Dereference CVE-2024-36387 |
CWE-476 | Medium | 2.4.61-1~deb11u1, 2.4.61-1~deb12u1 | 01.07.2024 |
SB2024070155 SB20240702144 SB2024070890 and 18 more |
||
| #VU82248 - Out-of-bounds read CVE-2023-31122 |
CWE-125 | Medium | 2.4.59-1~deb11u1, 2.4.59-1~deb12u1 | 19.10.2023 |
SB2023101942 SB2023101960 SB2023102101 and 43 more |
Showing elements 1 - 20 out of 58