Known vulnerabilities in httpd (Red Hat package)
Vendor:
Red Hat Inc.
Software:
httpd (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:httpd_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
63
Public exploits:
12
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.4.62-13.el9_8.6
2.4.63-1.el10_0.4
2.4.63-13.el10_2.4
2.4.63-13.el10_2.1
2.4.63-1.el10_0.3
2.4.57-11.el9_4.4
2.4.53-11.el9_2.14
2.4.51-7.el9_0.11
2.4.6-99.el7_9.7
2.2.15-71.el6_10.2
2.4.62-7.el9_7.3
2.4.63-4.el10_1.3
2.4.63-1.el10_0.2
2.2.15-71.el6_10.1
2.4.6-90.el7_7.6
2.4.6-99.el7_9.6
2.4.57-11.el9_4.3
2.4.53-11.el9_2.13
2.4.51-7.el9_0.10
2.4.6-40.el7_2.6
2.4.6-40.el7_2.4
2.4.62-1.el9
2.4.6-99.el7_9.3
2.4.6-90.el7_7.5
2.4.51-7.el9_0.8
2.4.53-11.el9_2.11
2.4.57-11.el9_4.1
2.4.53-11.el9_2.10
2.4.6-90.el7_7.4
2.4.51-7.el9_0.7
2.4.53-11.el9_2.8
2.4.57-11.el9_4
2.4.53-11.el9_2.6
2.4.6-31.el7_1.1
2.2.3-63.el5_8.1
2.2.15-15.el6_2.1
2.2.3-53.el5_7.3
2.2.15-9.el6_1.3
2.2.3-45.el5_6.2
2.2.3-43.el5_5.3
2.2.3-31.el5_4.4
2.2.3-31.el5_4.2
2.2.3-22.el5_3.2
2.2.3-22.el5_3.1
2.2.3-11.el5_2.4
2.2.3-11.el5_1.3
2.0.59-1.el4s1.10
2.0.59-1.el4s1.7
2.4.57-8.el9
2.4.57-5.el9
2.4.51-7.el9_0.4
2.4.53-7.el9_1.5
2.4.6-98.el7_9.7
2.4.53-7.el9_1.1
2.4.53-7.el9
2.4.6-89.el7_6.4
2.4.6-45.el7_3.8
2.4.6-67.el7_4.9
2.4.6-90.el7_7.3
2.2.15-70.el6_10
2.4.6-97.el7_9.5
2.4.6-40.el7_2.7
2.4.6-45.el7_3.6
2.4.6-67.el7_4.7
2.4.6-89.el7_6.2
2.4.6-90.el7_7.1
2.4.6-97.el7_9.1
2.4.6-95.el7
2.4.6-40.el7
2.4.6-93.el7
2.4.6-90.el7
2.2.26-57.ep6.el6
2.2.3-7.el5
2.2.3-11.el5
2.2.4-7.el5s2
2.2.4-9.el5s2
2.2.8-1.el5s2
2.2.10-1.el5s2
2.2.10-4.ep5.el5
2.2.11-2.el5s2
2.2.10-10.ep5.el5
2.2.11-3.el5s2
2.2.13-2.el5s2
2.2.10-11.ep5.el5
2.2.14-1.2.1.ep5.el5
2.2.14-1.2.6.jdk6.ep5.el5
2.2.17-11.1.ep5.el5
2.2.17-11.2.ep5.el6
2.2.17-14.1.ep5.el5
2.2.17-13.2.ep5.el6
2.2.13-3.el5s2
2.2.17-15.4.ep5.el5
2.2.17-15.4.ep5.el6
2.2.3-74.el5
2.2.3-78.el5_9
2.2.22-23.ep6.el5
2.2.22-23.ep6.el6
2.2.3-82.el5_9
2.2.22-25.ep6.el5
2.2.22-25.ep6.el6
2.2.3-85.el5_10
2.2.22-27.ep6.el5
2.2.22-27.ep6.el6
2.2.3-87.el5_10
2.4.6-18.el7_0
2.2.26-35.ep6.el6
2.2.26-35.ep6.el5
2.4.6-31.el7
2.2.26-38.ep6.el6
2.2.26-41.ep6.el5
2.2.26-41.ep6.el6
2.2.3-92.el5_11
2.2.26-54.ep6.el6
2.2.15-69.el6
2.2.15-60.el6_9
2.2.15-59.el6
2.2.15-56.el6_8
2.2.15-55.el6_8
2.2.15-54.el6_8
2.2.15-53.el6
2.2.15-47.el6_7
2.2.15-45.el6
2.2.15-39.el6
2.2.15-31.el6_5
2.2.15-30.el6_5
2.2.15-29.el6_4
2.2.15-28.el6_4
2.2.15-26.el6
2.2.15-15.el6_2
2.2.15-15.el6
2.2.15-9.el6_1
2.2.15-9.el6
2.2.15-5.el6
Vulnerabilities (63)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU133898 - Out-of-bounds write CVE-2026-44631 |
CWE-787 | Low | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.4 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 16 more |
||
| #VU133900 - Out-of-bounds read CVE-2026-44185 |
CWE-125 | Medium | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.4 | 08.06.2026 |
SB2026060493 SB2026063082 SB2026070144 and 9 more |
||
| #VU133903 - Heap-based Buffer Overflow CVE-2026-42536 |
CWE-122 | High | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.4 | 08.06.2026 |
SB2026060493 SB20260624100 SB20260624101 and 13 more |
||
| #VU133905 - Heap-based Buffer Overflow CVE-2026-34356 |
CWE-122 | High | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.4 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 15 more |
||
| #VU133906 - Buffer overflow CVE-2026-34355 |
CWE-120 | Medium | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.4 | 08.06.2026 |
SB2026060493 SB20260624100 SB20260624101 and 13 more |
||
| #VU133908 - Use After Free CVE-2026-29167 |
CWE-416 | Low | 2.4.62-13.el9_8.6 | 08.06.2026 |
SB2026060493 SB2026062422 SB20260624100 and 12 more |
||
| #VU129540 - Out-of-bounds read CVE-2026-34059 |
CWE-125 | Medium | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 25 more |
||
| #VU129541 - Out-of-bounds read CVE-2026-34032 |
CWE-125 | Medium | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 25 more |
||
| #VU129542 - Out-of-bounds read CVE-2026-33857 |
CWE-125 | Medium | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051240 and 25 more |
||
| #VU129544 - NULL Pointer Dereference CVE-2026-33007 |
CWE-476 | Medium | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB20260513119 and 17 more |
||
| #VU129546 - NULL Pointer Dereference CVE-2026-29169 |
CWE-476 | Medium | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.4 | 04.05.2026 |
SB2026050479 SB2026050772 SB20260513119 and 14 more |
||
| #VU129548 - Heap-based Buffer Overflow CVE-2026-28780 |
CWE-122 | High | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.1 | 04.05.2026 |
SB2026050479 SB2026050772 SB2026051101 and 25 more |
||
| #VU119149 - Improper Neutralization of Server-Side Includes (SSI) Within a Web Page CVE-2025-58098 |
CWE-97 | Low | 2.2.15-71.el6_10.2, 2.4.6-99.el7_9.7, 2.4.51-7.el9_0.11, 2.4.53-11.el9_2.14, 2.4.57-11.el9_4.4, 2.4.62-7.el9_7.3, 2.4.63-1.el10_0.3, 2.4.63-4.el10_1.3 | 04.12.2025 |
SB2025120441 SB2025121923 SB2025121940 and 47 more |
||
| #VU119147 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CVE-2025-65082 |
CWE-74 | Low | 2.4.62-7.el9_7.3, 2.4.63-4.el10_1.3 | 04.12.2025 |
SB2025120441 SB2025121923 SB2025122202 and 33 more |
||
| #VU119146 - Improper input validation CVE-2025-66200 |
CWE-20 | Low | 2.4.62-7.el9_7.3, 2.4.63-4.el10_1.3 | 04.12.2025 |
SB2025120441 SB2025121923 SB2025122202 and 31 more |
||
| #VU112734 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2024-42516 |
CWE-113 | Low | 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.4 | 10.07.2025 |
SB2025071040 SB2025071710 SB2025071764 and 34 more |
||
| #VU112731 - Improper Encoding or Escaping of Output CVE-2024-47252 |
CWE-116 | High | 2.4.6-99.el7_9.6, 2.4.51-7.el9_0.10, 2.4.53-11.el9_2.13, 2.4.57-11.el9_4.3, 2.4.63-1.el10_0.2 | 10.07.2025 |
SB2025071040 SB2025071764 SB2025072111 and 35 more |
||
| #VU112730 - Security Features CVE-2025-23048 |
CWE-254 | Medium | 2.4.51-7.el9_0.10, 2.4.53-11.el9_2.13, 2.4.57-11.el9_4.3, 2.4.63-1.el10_0.2 | 10.07.2025 |
SB2025071040 SB2025071764 SB2025072111 and 30 more |
||
| #VU112728 - Cryptographic Issues CVE-2025-49812 |
CWE-310 | Medium | 2.2.15-71.el6_10.1, 2.4.6-90.el7_7.6, 2.4.6-99.el7_9.6, 2.4.51-7.el9_0.10, 2.4.53-11.el9_2.13, 2.4.57-11.el9_4.3, 2.4.63-1.el10_0.2 | 10.07.2025 |
SB2025071040 SB2025071764 SB2025072111 and 35 more |
||
| #VU88151 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2023-38709 |
CWE-113 | Medium | 2.4.62-1.el9, 2.4.63-1.el10_0.4, 2.4.63-13.el10_2.4 | 04.04.2024 |
SB2024040458 SB2024040502 SB2024040903 and 62 more |
Showing elements 1 - 20 out of 63