apache2 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the apache2 package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Improper Encoding or Escaping of Output

<2.4.18-2ubuntu3.17+esm13
  • M
NULL Pointer Dereference

<2.4.18-2ubuntu3.17+esm13
  • M
CVE-2024-38476

<2.4.18-2ubuntu3.17+esm13
  • M
Improper Encoding or Escaping of Output

<2.4.18-2ubuntu3.17+esm13
  • M
CVE-2023-38709

<2.4.18-2ubuntu3.17+esm12
  • M
Allocation of Resources Without Limits or Throttling

<2.4.18-2ubuntu3.17+esm12
  • M
CVE-2024-24795

<2.4.18-2ubuntu3.17+esm12
  • L
Out-of-bounds Read

<2.4.18-2ubuntu3.17+esm11
  • M
HTTP Request Smuggling

<2.4.18-2ubuntu3.17+esm10
  • M
Out-of-bounds Write

<2.4.18-2ubuntu3.17+esm8
  • M
HTTP Response Splitting

<2.4.18-2ubuntu3.17+esm9
  • M
HTTP Request Smuggling

<2.4.18-2ubuntu3.17+esm8
  • M
HTTP Request Smuggling

<2.4.18-2ubuntu3.17+esm6
  • M
Allocation of Resources Without Limits or Throttling

<2.4.18-2ubuntu3.17+esm6
  • M
Allocation of Resources Without Limits or Throttling

<2.4.18-2ubuntu3.17+esm7
  • M
Insufficient Verification of Data Authenticity

<2.4.18-2ubuntu3.17+esm6
  • M
CVE-2022-30556

<2.4.18-2ubuntu3.17+esm6
  • M
Integer Overflow or Wraparound

<2.4.18-2ubuntu3.17+esm6
  • L
Integer Overflow or Wraparound

<2.4.18-2ubuntu3.17+esm6
  • M
Improper Initialization

<2.4.18-2ubuntu3.17+esm5
  • L
Integer Overflow or Wraparound

<2.4.18-2ubuntu3.17+esm5
  • M
HTTP Request Smuggling

<2.4.18-2ubuntu3.17+esm5
  • M
Out-of-bounds Write

<2.4.18-2ubuntu3.17+esm5
  • M
NULL Pointer Dereference

<2.4.18-2ubuntu3.17+esm4
  • M
Out-of-bounds Write

<2.4.18-2ubuntu3.17+esm4
  • M
Server-Side Request Forgery (SSRF)

<2.4.18-2ubuntu3.17+esm3
  • M
Buffer Overflow

<2.4.18-2ubuntu3.17+esm2
  • M
NULL Pointer Dereference

<2.4.18-2ubuntu3.17+esm2
  • M
HTTP Request Smuggling

*
  • M
NULL Pointer Dereference

<2.4.18-2ubuntu3.17+esm1
  • M
Out-of-bounds Write

<2.4.18-2ubuntu3.17+esm1
  • M
CVE-2021-30641

<2.4.18-2ubuntu3.17+esm1
  • L
Out-of-bounds Write

<2.4.18-2ubuntu3.17+esm1
  • L
Insufficient Verification of Data Authenticity

<2.4.18-2ubuntu3.15
  • L
Open Redirect

<2.4.18-2ubuntu3.17
  • L
Use of Uninitialized Resource

<2.4.18-2ubuntu3.17
  • L
Open Redirect

<2.4.18-2ubuntu3.12
  • L
Cross-site Scripting (XSS)

<2.4.18-2ubuntu3.12
  • H
Use After Free

<2.4.18-2ubuntu3.10
  • M
Race Condition

<2.4.18-2ubuntu3.10
  • L
Use of Incorrectly-Resolved Name or Reference

<2.4.18-2ubuntu3.10
  • L
Session Fixation

<2.4.18-2ubuntu3.10
  • L
CRLF Injection

<2.4.18-2ubuntu3.2
  • L
Improper Authentication

<2.4.18-2ubuntu3.8
  • L
Out-of-bounds Write

<2.4.18-2ubuntu3.8
  • L
CVE-2018-1283

<2.4.18-2ubuntu3.8
  • L
Out-of-bounds Read

<2.4.18-2ubuntu3.8
  • L
Out-of-Bounds

<2.4.18-2ubuntu3.8
  • L
Improper Input Validation

<2.4.18-2ubuntu3.8
  • M
Use After Free

<2.4.18-2ubuntu3.5
  • M
Cryptographic Issues

<2.4.18-2ubuntu3.2
  • M
Improper Data Handling

<2.4.18-2ubuntu3.2
  • L
Improper Input Validation

<2.4.18-2ubuntu3.2
  • M
Information Exposure

<2.4.18-2ubuntu3.4
  • M
Improper Input Validation

<2.4.18-2ubuntu3.3
  • M
Improper Authentication

<2.4.18-2ubuntu3.3
  • M
NULL Pointer Dereference

<2.4.18-2ubuntu3.3
  • L
Out-of-Bounds

<2.4.18-2ubuntu3.3
  • M
Improper Access Control

<2.4.18-2ubuntu3.1