Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
552 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 9.1% | — | Apache Http Server | 18/8/2003 | 16/6/2026 | The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service. | |
| Modificada | Media (6.4) | 6.0% | — | Apache Http Server | 18/8/2003 | 16/6/2026 | Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite. | |
| Modificada | Media (5) | 9.2% | — | Apache Http Server | 18/8/2003 | 16/6/2026 | Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket. | |
| Modificada | Media (5) | 63% | 💥 Exploit | Apache Http Server | 9/6/2003 | 16/6/2026 | Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors. | |
| Modificada | Media (5) | 15% | — | Apache Http Server | 9/6/2003 | 16/6/2026 | The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used. | |
| Modificada | Media (5) | 87% | 💥 Exploit | Apache Http Server | 11/4/2003 | 16/6/2026 | A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed. | |
| Modificada | Media (5) | 6.0% | — | Apache Http Server | 11/4/2003 | 16/6/2026 | Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names. | |
| Modificada | Media (5) | 17% | — | Apache Http Server | 2/4/2003 | 16/6/2026 | Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020. | |
| Modificada | Media (5) | 16% | — | Apache Http Server | 18/3/2003 | 16/6/2026 | Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences. | |
| Modificada | Media (5) | 6.4% | — | Apache Http Server | 7/2/2003 | 16/6/2026 | Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served. | |
| Modificada | Alta (7.5) | 18% | — | Apache Http Server | 7/2/2003 | 16/6/2026 | Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names. | |
| Modificada | Media (4.6) | 1.1% | — | Apache Http Server | 31/12/2002 | 16/6/2026 | Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed… | |
| Modificada | Alta (7.8) | 9.7% | 💥 Exploit | Apache Http ServerApache Tomcat | 31/12/2002 | 16/6/2026 | Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values. | |
| Modificada | Alta (9.4) | 52% | 💥 Exploit | Netdave Webster Http Server | 31/12/2002 | 16/6/2026 | Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL. | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Apache Http Server | 31/12/2002 | 16/6/2026 | mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script. | |
| Modificada | Media (6.4) | 2.2% | — | Wasd Http Server | 31/12/2002 | 16/6/2026 | Format string vulnerability in PerlRTE_example1.pl in WASD 7.1, 7.2.0 through 7.2.3, and 8.0.0 allows remote attackers to execute arbitrary commands or crash the server via format strings in the $name variable. | |
| Modificada | Media (4.3) | 1.0% | — | Webster Http Server | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Webster HTTP Server allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Lonerunner Zeroo Http Server | 31/12/2002 | 16/6/2026 | Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary code via a long HTTP request. | |
| Modificada | Media (5) | 6.1% | — | Apache Http Server | 31/12/2002 | 16/6/2026 | Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities. | |
| Modificada | Media (5) | 6.0% | — | Apache Http Server | 31/12/2002 | 16/6/2026 | Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request. | |
| Modificada | Alta (7.5) | 23% | 💥 Exploit | Apache Http Server | 31/12/2002 | 16/6/2026 | PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Zeroo Http Server | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request. | |
| Modificada | Media (5) | 2.1% | — | IBM Http Server | 31/12/2002 | 16/6/2026 | IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP). | |
| Modificada | Alta (9.4) | 2.0% | — | Webster Http Server | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Baja (2.6) | 0.56% | — | Apache Http Server | 4/11/2002 | 16/6/2026 | A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2)… |