Known vulnerabilities in mod_proxy_html
Vendor:
OpenAnolis
Software:
mod_proxy_html
Software CPE:
cpe:2.3:o:openanolis:mod_proxy_html:*:*:*:*:*:anolis_os:*:*
Website:
https://openanolis.cn/
Total vulnerabilities:
67
Public exploits:
14
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (67)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU133897 - Use After Free CVE-2026-48913 |
CWE-416 | High | 2.4.37-655.0.1 | 08.06.2026 |
SB2026060493 SB20260624100 SB20260624101 and 17 more |
||
| #VU133898 - Out-of-bounds write CVE-2026-44631 |
CWE-787 | Low | 2.4.37-655.0.1, 2.4.68-1 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 21 more |
||
| #VU133899 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2026-44186 |
CWE-835 | Medium | 2.4.37-655.0.1 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 21 more |
||
| #VU133900 - Out-of-bounds read CVE-2026-44185 |
CWE-125 | Medium | 2.4.37-655.0.1 | 08.06.2026 |
SB2026060493 SB2026063082 SB2026070144 and 13 more |
||
| #VU133901 - Improper Privilege Management CVE-2026-44119 |
CWE-269 | Low | 2.4.37-655.0.1, 2.4.68-1 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 15 more |
||
| #VU133902 - Out-of-bounds read CVE-2026-43951 |
CWE-125 | Medium | 2.4.37-655.0.1 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 23 more |
||
| #VU133903 - Heap-based Buffer Overflow CVE-2026-42536 |
CWE-122 | High | 2.4.37-655.0.1 | 08.06.2026 |
SB2026060493 SB20260624100 SB20260624101 and 17 more |
||
| #VU133904 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-42535 |
CWE-22 | Low | 2.4.37-655.0.1, 2.4.68-1 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 15 more |
||
| #VU133905 - Heap-based Buffer Overflow CVE-2026-34356 |
CWE-122 | High | 2.4.37-655.0.1 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 20 more |
||
| #VU133906 - Buffer overflow CVE-2026-34355 |
CWE-120 | Medium | 2.4.37-655.0.1 | 08.06.2026 |
SB2026060493 SB20260624100 SB20260624101 and 17 more |
||
| #VU133907 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-29170 |
CWE-79 | Medium | 2.4.37-655.0.1, 2.4.68-1 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 14 more |
||
| #VU133908 - Use After Free CVE-2026-29167 |
CWE-416 | Low | 2.4.37-655.0.1 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 20 more |
||
| #VU133362 - Resource exhaustion CVE-2026-49975 |
CWE-400 | High | 2.4.37-655.0.1 | 04.06.2026 |
SB2026060491 SB2026060492 SB2026060493 and 30 more |
||
| #VU129540 - Out-of-bounds read CVE-2026-34059 |
CWE-125 | Medium | 2.4.37-655.0.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 27 more |
||
| #VU129541 - Out-of-bounds read CVE-2026-34032 |
CWE-125 | Medium | 2.4.37-655.0.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 28 more |
||
| #VU129542 - Out-of-bounds read CVE-2026-33857 |
CWE-125 | Medium | 2.4.37-655.0.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 28 more |
||
| #VU129544 - NULL Pointer Dereference CVE-2026-33007 |
CWE-476 | Medium | 2.4.37-655.0.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB20260513119 and 20 more |
||
| #VU129546 - NULL Pointer Dereference CVE-2026-29169 |
CWE-476 | Medium | 2.4.37-655.0.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB20260513119 and 16 more |
||
| #VU129549 - Improper Access Control CVE-2026-24072 |
CWE-284 | Low | 2.4.37-655.0.1, 2.4.67-1 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 20 more |
||
| #VU129550 - Double Free CVE-2026-23918 |
CWE-415 | High | 2.4.67-1 | 04.05.2026 |
SB2026050479 SB2026050772 SB20260513119 and 11 more |
Showing elements 1 - 20 out of 67