Known vulnerabilities in httpd24-httpd (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:httpd24-httpd_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 25
Public exploits: 7
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting httpd24-httpd (Red Hat package) httpd24-httpd (Red Hat package) is affected by 25 known vulnerabilities: 1 critical, 4 high, 17 medium, 3 low Critical High Medium Low

Vulnerabilities (25)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73107 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-25690
CWE-113 Medium
Available
No
2.4.34-23.el7.6 07.03.2023 SB2023030731
SB2023030862
SB2023030942
and 54 more
#VU64089 - Improper Authentication
CVE-2022-31813
CWE-287 Medium
No
No
2.4.34-23.el7.5 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 49 more
#VU64088 - Out-of-bounds read
CVE-2022-30556
CWE-125 Medium
No
No
2.4.34-23.el7.5 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 31 more
#VU64086 - Resource exhaustion
CVE-2022-30522
CWE-400 Medium
No
No
2.4.34-23.el7.5 08.06.2022 SB2022060817
SB2022060901
SB2022061723
and 31 more
#VU64085 - Improper input validation
CVE-2022-29404
CWE-20 Medium
No
No
2.4.34-23.el7.5 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 30 more
#VU64083 - Out-of-bounds read
CVE-2022-28615
CWE-125 Low
No
No
2.4.34-23.el7.5 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 41 more
#VU64081 - Out-of-bounds read
CVE-2022-28614
CWE-125 Low
No
No
2.4.34-23.el7.5 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 36 more
#VU64078 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-26377
CWE-444 Medium
Available
No
2.4.34-23.el7.5 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 39 more
#VU61287 - Improper input validation
CVE-2022-22719
CWE-20 Medium
No
No
2.4.34-23.el7.5 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 32 more
#VU61285 - Integer overflow
CVE-2022-22721
CWE-190 High
No
No
2.4.34-23.el7.5 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 39 more
#VU61284 - Out-of-bounds write
CVE-2022-23943
CWE-787 High
No
No
2.4.34-23.el7.5 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 34 more
#VU59057 - Server-Side Request Forgery (SSRF)
CVE-2021-44224
CWE-918 Medium
No
No
2.4.34-23.el7.5 20.12.2021 SB2021122005
SB2021122021
SB2021122709
and 33 more
#VU59056 - Memory corruption
CVE-2021-44790
CWE-119 Critical
Available
No
2.4.34-23.el7.1 20.12.2021 SB2021122005
SB2021122021
SB2022010513
and 50 more
#VU56681 - NULL Pointer Dereference
CVE-2021-34798
CWE-476 Medium
No
No
2.4.34-23.el7.5 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 44 more
#VU56680 - Out-of-bounds read
CVE-2021-36160
CWE-125 Medium
No
No
2.4.34-23.el7.5 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 22 more
#VU56679 - Memory corruption
CVE-2021-39275
CWE-119 Medium
No
No
2.4.34-23.el7.5 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 44 more
#VU56678 - Server-Side Request Forgery (SSRF)
CVE-2021-40438
CWE-918 High
Available
Exploited
2.4.34-23.el7.5 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 42 more
#VU56474 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-33193
CWE-444 Medium
No
No
2.4.34-23.el7.5 13.09.2021 SB2021091317
SB2021091707
SB2021092301
and 24 more
#VU35854 - Resource Management Errors
CVE-2020-11993
CWE-399 Medium
No
No
2.4.34-22.el7 08.08.2020 SB2020080806
SB2020080807
SB2020082904
and 15 more
#VU35713 - Memory corruption
CVE-2020-11984
CWE-119 High
Available
No
2.4.34-22.el7 08.08.2020 SB2020080806
SB2020080807
SB2020082904
and 22 more


Showing elements 1 - 20 out of 25