Known vulnerabilities in httpd-filesystem - page 2

Vendor: OpenAnolis
Software CPE: cpe:2.3:o:openanolis:httpd-filesystem:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 67
Public exploits: 14
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting httpd-filesystem httpd-filesystem is affected by 67 known vulnerabilities: 2 critical, 11 high, 41 medium, 13 low Critical High Medium Low

Vulnerabilities (67)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU129548 - Heap-based Buffer Overflow
CVE-2026-28780
CWE-122 High
No
No
2.4.37-655.0.1, 2.4.67-1 04.05.2026 SB2026050479
SB2026050772
SB2026051101
and 27 more
#VU119150 - Integer overflow
CVE-2025-55753
CWE-190 Low
No
No
2.4.37-655.0.1, 2.4.66-1 04.12.2025 SB2025120441
SB2025121923
SB2025121940
and 32 more
#VU119149 - Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
CVE-2025-58098
CWE-97 Low
Available
No
2.4.37-655.0.1, 2.4.66-1 04.12.2025 SB2025120441
SB2025121923
SB2025121940
and 47 more
#VU119147 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-65082
CWE-74 Low
No
No
2.4.37-655.0.1 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 33 more
#VU119146 - Improper input validation
CVE-2025-66200
CWE-20 Low
No
No
2.4.37-655.0.1 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 31 more
#VU112734 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2024-42516
CWE-113 Low
No
No
2.4.37-655.0.1, 2.4.62-3 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 37 more
#VU112733 - Server-Side Request Forgery (SSRF)
CVE-2024-43204
CWE-918 Low
No
No
2.4.37-655.0.1, 2.4.64-1 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 29 more
#VU112731 - Improper Encoding or Escaping of Output
CVE-2024-47252
CWE-116 High
No
No
2.4.37-655.0.1, 2.4.64-1 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 35 more
#VU112730 - Security Features
CVE-2025-23048
CWE-254 Medium
Available
No
2.4.37-655.0.1 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 30 more
#VU112729 - Resource Management Errors
CVE-2025-49630
CWE-399 Medium
No
No
2.4.37-655.0.1, 2.4.64-1 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 27 more
#VU112728 - Cryptographic Issues
CVE-2025-49812
CWE-310 Medium
No
No
2.4.37-655.0.1, 2.4.62-3 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 35 more
#VU112727 - Resource Management Errors
CVE-2025-53020
CWE-399 Medium
No
No
2.4.37-655.0.1, 2.4.64-1 10.07.2025 SB2025071040
SB2025071201
SB2025071202
and 20 more
#VU94504 - Exposure of sensitive information to an unauthorized actor
CVE-2024-40725
CWE-200 Medium
Available
No
2.4.62-1 17.07.2024 SB20240717136
SB2024071854
SB2024071896
and 22 more
#VU94503 - Server-Side Request Forgery (SSRF)
CVE-2024-40898
CWE-918 High
Available
No
2.4.62-1 17.07.2024 SB20240717136
SB2024071896
SB2024081362
and 13 more
#VU93729 - Exposure of sensitive information to an unauthorized actor
CVE-2024-39884
CWE-200 Medium
No
No
2.4.62-1 03.07.2024 SB2024070342
SB2024070401
SB2024070890
and 21 more
#VU93542 - Improper input validation
CVE-2024-38475
CWE-20 Critical
Available
No
2.4.37-65.0.1, 2.4.62-1 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 54 more
#VU93541 - Improper input validation
CVE-2024-38474
CWE-20 Medium
No
No
2.4.37-65.0.1, 2.4.62-1 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 57 more
#VU93540 - Improper input validation
CVE-2024-38473
CWE-20 Medium
Available
No
2.4.37-65.0.1, 2.4.62-1 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 47 more
#VU93539 - Server-Side Request Forgery (SSRF)
CVE-2024-38472
CWE-918 Medium
Available
No
2.4.62-1 01.07.2024 SB2024070155
SB20240702144
SB2024081362
and 11 more
#VU93538 - NULL Pointer Dereference
CVE-2024-36387
CWE-476 Medium
No
No
2.4.62-1 01.07.2024 SB2024070155
SB20240702144
SB2024070890
and 18 more


Showing elements 21 - 40 out of 67