Known vulnerabilities in httpd (Red Hat package) - page 3

Software CPE: cpe:2.3:o:red_hat:httpd_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 63
Public exploits: 12
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting httpd (Red Hat package) httpd (Red Hat package) is affected by 63 known vulnerabilities: 2 critical, 8 high, 40 medium, 13 low Critical High Medium Low

Vulnerabilities (63)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU64089 - Improper Authentication
CVE-2022-31813
CWE-287 Medium
No
No
2.4.53-7.el9 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 49 more
#VU64088 - Out-of-bounds read
CVE-2022-30556
CWE-125 Medium
No
No
2.4.53-7.el9 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 31 more
#VU64078 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-26377
CWE-444 Medium
Available
No
2.4.53-7.el9 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 39 more
#VU61286 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-22720
CWE-444 Medium
No
No
2.2.15-70.el6_10, 2.4.6-45.el7_3.8, 2.4.6-67.el7_4.9, 2.4.6-89.el7_6.4, 2.4.6-90.el7_7.3, 2.4.6-97.el7_9.5 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 56 more
#VU59056 - Memory corruption
CVE-2021-44790
CWE-119 Critical
Available
No
2.4.6-45.el7_3.8, 2.4.6-67.el7_4.9, 2.4.6-89.el7_6.4, 2.4.6-90.el7_7.3 20.12.2021 SB2021122005
SB2021122021
SB2022010513
and 50 more
#VU56678 - Server-Side Request Forgery (SSRF)
CVE-2021-40438
CWE-918 High
Available
Exploited
2.4.6-40.el7_2.7, 2.4.6-45.el7_3.6, 2.4.6-67.el7_4.7, 2.4.6-89.el7_6.2, 2.4.6-90.el7_7.1, 2.4.6-97.el7_9.1 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 42 more
#VU35776 - Improper input validation
CVE-2020-11985
CWE-20 Medium
No
No
2.4.6-40.el7 08.08.2020 SB2020080805
SB2020080807
SB2020090925
and 2 more
#VU26528 - Use of Uninitialized Variable
CVE-2020-1934
CWE-457 Medium
No
No
2.4.6-95.el7 02.04.2020 SB2020040204
SB2020041511
SB2020050202
and 20 more
#VU26527 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2020-1927
CWE-601 Medium
No
No
2.4.6-95.el7 02.04.2020 SB2020040204
SB2020041511
SB2020050202
and 17 more
#VU20374 - Improper input validation
CVE-2019-10098
CWE-20 Medium
Available
No
2.4.6-95.el7 23.08.2019 SB2019082303
SB2019082610
SB2019090202
and 19 more
#VU17178 - Improper Access Control
CVE-2018-17199
CWE-284 Low
No
No
2.4.6-93.el7 23.01.2019 SB2019012307
SB2019012308
SB2019012508
and 18 more
#VU11284 - Permissions, Privileges, and Access Controls
CVE-2017-15715
CWE-264 Low
No
No
2.4.6-95.el7 27.03.2018 SB2018032703
SB2018040401
SB2018040502
and 13 more
#VU11283 - Out-of-bounds write
CVE-2017-15710
CWE-787 Medium
No
No
2.4.6-93.el7 27.03.2018 SB2018032703
SB2018040401
SB2018040502
and 13 more
#VU11282 - Improper input validation
CVE-2018-1283
CWE-20 Low
No
No
2.4.6-95.el7 27.03.2018 SB2018032703
SB2018040401
SB2018040502
and 12 more
#VU11281 - Out-of-bounds read
CVE-2018-1301
CWE-125 Medium
No
No
2.4.6-93.el7 27.03.2018 SB2018032703
SB2018040401
SB2018040502
and 13 more
#VU11280 - Out-of-bounds read
CVE-2018-1303
CWE-125 Medium
No
No
2.4.6-95.el7 27.03.2018 SB2018032703
SB2018040401
SB2018040502
and 12 more
#VU7517 - Exposure of sensitive information to an unauthorized actor
CVE-2017-9788
CWE-200 Low
No
No
2.4.6-40.el7_2.6 13.07.2017 SB2017062001
SB2017071403
SB2017071307
and 17 more
#VU7119 - Out-of-bounds read
CVE-2017-7679
CWE-125 Medium
Available
No
2.4.6-40.el7_2.6 20.06.2017 SB2017062001
SB2017062807
SB2017063012
and 26 more
#VU7116 - Authentication Bypass Issues
CVE-2017-3169
CWE-592 Medium
Available
No
2.4.6-40.el7_2.6 20.06.2017 SB2017062001
SB2017062807
SB2017063012
and 26 more
#VU7117 - Out-of-bounds read
CVE-2017-7668
CWE-125 Medium
No
No
2.4.6-40.el7_2.6 20.06.2017 SB2017062001
SB2017062807
SB2017063012
and 17 more


Showing elements 41 - 60 out of 63