apache2

Direct Vulnerabilities

Known vulnerabilities in the apache2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Buffer Underflow

<2.4.58-1ubuntu8.15
  • M
Use After Free

<2.4.58-1ubuntu8.15
  • M
Cross-site Scripting (XSS)

<2.4.58-1ubuntu8.15
  • M
Buffer Over-read

<2.4.58-1ubuntu8.15
  • M
Out-of-bounds Read

<2.4.58-1ubuntu8.15
  • M
Improper Privilege Management

<2.4.58-1ubuntu8.15
  • M
Heap-based Buffer Overflow

<2.4.58-1ubuntu8.15
  • M
Heap-based Buffer Overflow

<2.4.58-1ubuntu8.15
  • M
Exposure of Resource to Wrong Sphere

<2.4.58-1ubuntu8.15
  • M
Heap-based Buffer Overflow

<2.4.58-1ubuntu8.15
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.4.58-1ubuntu8.15
  • M
Use After Free

<2.4.58-1ubuntu8.15
  • M
Uncontrolled Memory Allocation

<2.4.58-1ubuntu8.13
  • L
Out-of-bounds Read

<2.4.58-1ubuntu8.12
  • L
Out-of-bounds Read

<2.4.58-1ubuntu8.12
  • L
Buffer Over-read

<2.4.58-1ubuntu8.12
  • L
Allocation of Resources Without Limits or Throttling

<2.4.58-1ubuntu8.12
  • L
NULL Pointer Dereference

<2.4.58-1ubuntu8.12
  • L
Information Exposure

<2.4.58-1ubuntu8.12
  • L
CVE-2026-33523

<2.4.58-1ubuntu8.12
  • L
NULL Pointer Dereference

<2.4.58-1ubuntu8.12
  • L
Heap-based Buffer Overflow

<2.4.58-1ubuntu8.12
  • M
Improper Privilege Management

<2.4.58-1ubuntu8.12
  • L
Improper Neutralization

<2.4.58-1ubuntu8.10
  • M
Information Exposure

<2.4.58-1ubuntu8.10
  • L
Integer Overflow or Wraparound

<2.4.58-1ubuntu8.10
  • M
CVE-2025-66200

<2.4.58-1ubuntu8.10
  • M
Server-Side Request Forgery (SSRF)

<2.4.58-1ubuntu8.7
  • M
Improper Neutralization

<2.4.58-1ubuntu8.7
  • M
Improper Input Validation

<2.4.58-1ubuntu8.7
  • M
Improper Access Control

<2.4.58-1ubuntu8.7
  • M
Reachable Assertion

<2.4.58-1ubuntu8.7
  • M
Improper Authentication

<2.4.58-1ubuntu8.7
  • M
Memory Leak

<2.4.58-1ubuntu8.7
  • M
CVE-2024-40725

<2.4.58-1ubuntu8.4
  • M
Improper Encoding or Escaping of Output

<2.4.58-1ubuntu8.8
  • M
NULL Pointer Dereference

<2.4.58-1ubuntu8.2
  • M
CVE-2024-39884

<2.4.58-1ubuntu8.2
  • M
Improper Encoding or Escaping of Output

<2.4.58-1ubuntu8.2
  • H
Improper Encoding or Escaping of Output

<2.4.58-1ubuntu8.2
  • M
NULL Pointer Dereference

<2.4.58-1ubuntu8.2
  • M
CVE-2024-38476

<2.4.58-1ubuntu8.2
  • M
Improper Input Validation

<2.4.58-1ubuntu8.2
  • L
Open Redirect

<2.4.41-1ubuntu1
  • M
HTTP Request Smuggling

<2.4.55-1ubuntu1
  • M
HTTP Response Splitting

<2.4.55-1ubuntu1
  • M
HTTP Request Smuggling

<2.4.55-1ubuntu2
  • M
CVE-2023-38709

<2.4.58-1ubuntu8.1
  • M
Improper Resource Shutdown or Release

<2.4.58-1ubuntu1
  • M
Out-of-bounds Write

<2.4.55-1ubuntu1
  • M
CVE-2024-24795

<2.4.58-1ubuntu8.1
  • M
Allocation of Resources Without Limits or Throttling

<2.4.58-1ubuntu8.1