Search CVE reports


Toggle filters

1 – 10 of 196 results

Status is adjusted based on your filters.


CVE-2025-54090

Medium priority
Not affected

A bug in Apache HTTP Server 2.4.64 results in all “RewriteCond expr ...” tests evaluating as “true”. Users are recommended to upgrade to version 2.4.65, which fixes the issue.

1 affected package

apache2

Package 14.04 LTS
apache2 Not affected
Show less packages

CVE-2025-53020

Medium priority
Not affected

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.

1 affected package

apache2

Package 14.04 LTS
apache2 Not affected
Show less packages

CVE-2025-49812

Medium priority
Needs evaluation

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using...

1 affected package

apache2

Package 14.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2025-49630

Medium priority
Not affected

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a...

1 affected package

apache2

Package 14.04 LTS
apache2 Not affected
Show less packages

CVE-2025-23048

Medium priority
Needs evaluation

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for...

1 affected package

apache2

Package 14.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2024-8176

Medium priority
Needs evaluation

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to...

23 affected packages

apache2, apr-util, cmake, ghostscript, texlive-bin...

Package 14.04 LTS
apache2 Not affected
apr-util Not affected
cmake
ghostscript
texlive-bin
xmlrpc-c Needs evaluation
vnc4 Needs evaluation
wbxml2
swish-e
insighttoolkit4
cadaver
gdcm Not affected
ayttm
cableswig
coin3 Needs evaluation
matanza
tdom
vtk Needs evaluation
smart
firefox
thunderbird
libxmltok
expat Ignored
Show all 23 packages Show less packages

CVE-2024-50602

Medium priority

Some fixes available 1 of 5

An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.

23 affected packages

apache2, apr-util, cmake, ghostscript, texlive-bin...

Package 14.04 LTS
apache2 Not affected
apr-util Not affected
cmake
ghostscript
texlive-bin
xmlrpc-c Needs evaluation
vnc4 Needs evaluation
wbxml2
swish-e
insighttoolkit4
expat Fixed
cadaver
gdcm Not affected
ayttm
cableswig
coin3 Needs evaluation
matanza
tdom
vtk Needs evaluation
smart
firefox
thunderbird
libxmltok
Show all 23 packages Show less packages

CVE-2024-47252

Medium priority
Needs evaluation

Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where...

1 affected package

apache2

Package 14.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2024-45492

Medium priority

Some fixes available 1 of 5

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

23 affected packages

tdom, apache2, apr-util, cmake, ghostscript...

Package 14.04 LTS
tdom
apache2 Not affected
apr-util Not affected
cmake
ghostscript
texlive-bin
xmlrpc-c Needs evaluation
vnc4 Needs evaluation
wbxml2
swish-e
insighttoolkit4
cadaver
gdcm Not affected
ayttm
cableswig
coin3 Needs evaluation
matanza
vtk Needs evaluation
smart
firefox
thunderbird
libxmltok
expat Fixed
Show all 23 packages Show less packages

CVE-2024-45491

Medium priority

Some fixes available 1 of 5

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

23 affected packages

apache2, apr-util, cmake, ghostscript, texlive-bin...

Package 14.04 LTS
apache2 Not affected
apr-util Not affected
cmake
ghostscript
texlive-bin
xmlrpc-c Needs evaluation
vnc4 Needs evaluation
wbxml2
swish-e
insighttoolkit4
cadaver
gdcm Not affected
ayttm
cableswig
coin3 Needs evaluation
matanza
tdom
vtk Needs evaluation
smart
firefox
thunderbird
libxmltok
expat Fixed
Show all 23 packages Show less packages