Known vulnerabilities in httpd (Red Hat package) - page 2

Software CPE: cpe:2.3:o:red_hat:httpd_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 63
Public exploits: 12
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting httpd (Red Hat package) httpd (Red Hat package) is affected by 63 known vulnerabilities: 2 critical, 8 high, 40 medium, 13 low Critical High Medium Low

Vulnerabilities (63)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU93545 - Server-Side Request Forgery (SSRF)
CVE-2024-39573
CWE-918 Medium
No
No
2.4.53-11.el9_2.10, 2.4.57-11.el9_4 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 46 more
#VU93544 - Improper input validation
CVE-2024-38477
CWE-20 Medium
No
No
2.4.6-90.el7_7.4, 2.4.51-7.el9_0.7, 2.4.53-11.el9_2.8, 2.4.57-11.el9_4 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 58 more
#VU93543 - Server-Side Request Forgery (SSRF)
CVE-2024-38476
CWE-918 High
No
No
2.4.6-90.el7_7.5, 2.4.6-99.el7_9.3, 2.4.51-7.el9_0.8, 2.4.53-11.el9_2.11, 2.4.57-11.el9_4.1 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 61 more
#VU93542 - Improper input validation
CVE-2024-38475
CWE-20 Critical
Available
No
2.4.6-90.el7_7.4, 2.4.51-7.el9_0.7, 2.4.53-11.el9_2.8, 2.4.57-11.el9_4 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 54 more
#VU93541 - Improper input validation
CVE-2024-38474
CWE-20 Medium
No
No
2.4.6-90.el7_7.4, 2.4.51-7.el9_0.7, 2.4.53-11.el9_2.8, 2.4.57-11.el9_4 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 57 more
#VU93540 - Improper input validation
CVE-2024-38473
CWE-20 Medium
Available
No
2.4.53-11.el9_2.10, 2.4.57-11.el9_4 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 47 more
#VU88152 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2024-24795
CWE-113 Medium
No
No
2.4.62-1.el9 04.04.2024 SB2024040458
SB2024040502
SB2024040903
and 38 more
#VU82248 - Out-of-bounds read
CVE-2023-31122
CWE-125 Medium
No
No
2.4.57-8.el9 19.10.2023 SB2023101942
SB2023101960
SB2023102101
and 43 more
#VU73107 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-25690
CWE-113 Medium
Available
No
2.4.6-98.el7_9.7, 2.4.51-7.el9_0.4, 2.4.53-7.el9_1.5, 2.4.57-5.el9 07.03.2023 SB2023030731
SB2023030862
SB2023030942
and 54 more
#VU73106 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-27522
CWE-113 Medium
No
No
2.4.53-11.el9_2.6, 2.4.57-5.el9 07.03.2023 SB2023030731
SB2023030862
SB2023030942
and 33 more
#VU71243 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2022-37436
CWE-113 Medium
No
No
2.4.53-7.el9_1.1 17.01.2023 SB2023011740
SB2023011805
SB2023012728
and 33 more
#VU71242 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-36760
CWE-444 Medium
No
No
2.4.53-7.el9_1.1 17.01.2023 SB2023011740
SB2023011805
SB2023012728
and 33 more
#VU71241 - Memory corruption
CVE-2006-20001
CWE-119 Medium
No
No
2.4.53-7.el9_1.1 17.01.2023 SB2023011740
SB2023011805
SB2023012728
and 28 more
#VU64086 - Resource exhaustion
CVE-2022-30522
CWE-400 Medium
No
No
2.4.53-7.el9 08.06.2022 SB2022060817
SB2022060901
SB2022061723
and 31 more
#VU64085 - Improper input validation
CVE-2022-29404
CWE-20 Medium
No
No
2.4.53-7.el9 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 30 more
#VU64083 - Out-of-bounds read
CVE-2022-28615
CWE-125 Low
No
No
2.4.53-7.el9 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 41 more
#VU64081 - Out-of-bounds read
CVE-2022-28614
CWE-125 Low
No
No
2.4.53-7.el9 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 36 more
#VU61287 - Improper input validation
CVE-2022-22719
CWE-20 Medium
No
No
2.4.53-7.el9 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 32 more
#VU61285 - Integer overflow
CVE-2022-22721
CWE-190 High
No
No
2.4.53-7.el9 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 39 more
#VU61284 - Out-of-bounds write
CVE-2022-23943
CWE-787 High
No
No
2.4.53-7.el9 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 34 more


Showing elements 21 - 40 out of 63