Shortened for this page: results: 3 of 25 shown; results[].configurations[].nodes[].cpe_match: first 10 items; results[].enrichment.cpe: first 10 items; results[].enrichment.cwe[].capec_id: first 10 items; results[].references: first 10 items
{
"page": 1,
"page_size": 25,
"result_count": 351,
"results": [
{
"id": "CVE-2011-4415",
"source_identifier": "user@mitre.org",
"published": "2011-11-08T11:55:05Z",
"last_modified": "2026-06-16T23:34:53Z",
"status": "Modified",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the \"len +=\" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607."
},
{
"lang": "es",
"value": "La función ap_pregsub en server/util.c en el servidor HTTP Apache v2.0.x hasta la 2.0.64 y la v2.2.x hasta la v2.2.21, cuando el módulo mod_setenvif está activado, no limita el tamaño de los valores de las variables de entorno, lo que permite a usuarios locales causar una denegación de servicio (consumo de memoria o puntero a NULL) a través de un archivo de tipo .htaccess que incluye una directiva SetEnvIf modificada, junto con un encabezado de solicitud HTTP manipulado, relacionado con (1) la declarción \"len + =\" y (2) con la llamada a la funcion apr_pcalloc, una vulnerabilidad diferente a CVE-2011-3607."
}
],
"references": [
{
"url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://www.gossamer-threads.com/lists/apache/dev/403775",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://www.halfdog.net/Security/2011/ApacheModSetEnvIfIntegerOverflow/",
"source": "user@mitre.org",
"tags": [
"Exploit",
"Patch"
]
},
{
"url": "http://www.halfdog.net/Security/2011/ApacheModSetEnvIfIntegerOverflow/DemoExploit.html",
"source": "user@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
},
{
"url": "http://www.gossamer-threads.com/lists/apache/dev/403775",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
},
{
"url": "http://www.halfdog.net/Security/2011/ApacheModSetEnvIfIntegerOverflow/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Patch"
]
},
{
"url": "http://www.halfdog.net/Security/2011/ApacheModSetEnvIfIntegerOverflow/DemoExploit.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit"
]
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:L/AC:H/Au:N/C:N/I:N/A:P",
"access_vector": "LOCAL",
"access_complexity": "HIGH",
"authentication": "NONE",
"confidentiality_impact": "NONE",
"integrity_impact": "NONE",
"availability_impact": "PARTIAL",
"base_score": 1.2,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "LOW",
"exploitability_score": 1.9,
"impact_score": 2.9,
"ac_insuf_info": false,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*",
"match_criteria_id": "163A6EF6-7D3F-4B1F-9E03-A8C86562CC3D",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:*",
"match_criteria_id": "154566FB-0D1A-4DC2-AFE6-49DE93850951",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*",
"match_criteria_id": "EB477AFB-EA39-4892-B772-586CF6D2D235",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:*",
"match_criteria_id": "5C4962BB-0E61-4788-B582-21F05CD33AD3",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*",
"match_criteria_id": "B35906CD-038E-4243-8A95-F0A3A43F06F7",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.32:beta:*:*:*:*:*:*",
"match_criteria_id": "1C3E2656-8071-40DA-9480-AC13010A9D09",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.34:beta:*:*:*:*:*:*",
"match_criteria_id": "7C649D2F-A633-456E-899C-6253FDE9A626",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:*",
"match_criteria_id": "B940BB85-03F5-46D7-8DC9-2E1E228D3D98",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:*",
"match_criteria_id": "82139FFA-2779-4732-AFA5-4E6E19775899",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:*",
"match_criteria_id": "B7F717E6-BACD-4C8A-A9C5-516ADA6FEE6C",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:*",
"match_criteria_id": "67AD11FB-529C-404E-A13B-284F145322B8",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.1:*:*:*:*:*:*:*",
"match_criteria_id": "733D62FE-180A-4AE8-9DBF-DA1DC18C1932",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:*",
"match_criteria_id": "CCBBB7FE-35FC-4515-8393-5145339FCE4D",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:*",
"match_criteria_id": "F519633F-AB68-495A-B85E-FD41F9F752CA",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:*",
"match_criteria_id": "A894BED6-C97D-4DA4-A13D-9CB2B3306BC5",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.6:*:*:*:*:*:*:*",
"match_criteria_id": "34A847D1-5AD5-4EFD-B165-7602AFC1E656",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.8:*:*:*:*:*:*:*",
"match_criteria_id": "9AF3A0F5-4E5C-4278-9927-1F94F25CCAFC",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.9:*:*:*:*:*:*:*",
"match_criteria_id": "AB63EBE5-CF14-491E-ABA5-67116DFE3E5B",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.10:*:*:*:*:*:*:*",
"match_criteria_id": "8C2A33DE-F55F-4FD8-BB00-9C1E006CA65C",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.2.11:*:*:*:*:*:*:*",
"match_criteria_id": "B1CF6394-95D9-42AF-A442-385EFF9CEFE1",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": null,
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0",
"affected_versions_last": "2.0"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.9",
"affected_versions_last": "2.0.9"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.28",
"affected_versions_last": "2.0.28"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.28",
"affected_versions_last": "2.0.28"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.32",
"affected_versions_last": "2.0.32"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.32:beta:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.32",
"affected_versions_last": "2.0.32"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.34:beta:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.34",
"affected_versions_last": "2.0.34"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.35",
"affected_versions_last": "2.0.35"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.36",
"affected_versions_last": "2.0.36"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.37",
"affected_versions_last": "2.0.37"
}
],
"cwe": [
{
"id": 20,
"owasptop10_2021": "A03 Injection",
"name": "Improper Input Validation",
"description": "The product receives input or data, but it does\n not validate or incorrectly validates that the input has the\n properties that are required to process the data safely and\n correctly.",
"capec_id": [
3,
7,
8,
9,
10,
13,
14,
22,
23,
24
],
"scope": [
"Availability",
"Confidentiality",
"Integrity"
],
"impact": [
"DoS: Crash, Exit, or Restart",
"DoS: Resource Consumption (CPU)",
"DoS: Resource Consumption (Memory)",
"Execute Unauthorized Code or Commands",
"Modify Memory",
"Read Files or Directories",
"Read Memory"
],
"detection_method": [
"Architecture or Design Review",
"Automated Static Analysis",
"Automated Static Analysis - Binary or Bytecode",
"Automated Static Analysis - Source Code",
"Dynamic Analysis with Automated Results Interpretation",
"Dynamic Analysis with Manual Results Interpretation",
"Fuzzing",
"Manual Static Analysis",
"Manual Static Analysis - Binary or Bytecode",
"Manual Static Analysis - Source Code"
]
}
],
"epss_score": {
"epss": 0.031,
"percentile": 0.87196,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:L/AC:H/Au:N/C:N/I:N/A:P",
"attack_vector": "LOCAL",
"attack_complexity": "HIGH",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "NONE",
"vulnerable_system_integrity": "NONE",
"vulnerable_system_availability": "PARTIAL",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 1.2,
"base_severity": "LOW"
}
}
}
},
{
"id": "CVE-2013-0941",
"source_identifier": "user@emc.com",
"published": "2013-05-22T13:29:45Z",
"last_modified": "2026-06-16T23:50:23Z",
"status": "Modified",
"evaluator_comment": "Per: http://archives.neohapsis.com/archives/bugtraq/2013-05/att-0064/ESA-2013-029.txt\r\n\r\n\"RSA SecurID Sensitive Information Disclosure Vulnerability\"",
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data."
},
{
"lang": "es",
"value": "La API de autenticación de EMC RSA anterior a v8.1 SP1, RSA Web Agent anterior a v5.3.5 para Apache Web Server, RSA Web Agent anterior a v5.3.5 para IIS, RSA PAM Agent anterior a v7.0, y RSA Agent anterior a v6.1.4 para Microsoft Windows utiliza un algoritmo de cifrado inadecuado y una clave débil para el mantenimiento de los datos almacenados en el nodo secreto para la API de autenticación SecurID, permitiendo a usuarios locales obtener información sensible mediante ataques criptográficos de estos datos."
}
],
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2013-05/0064.html",
"source": "user@emc.com",
"tags": null
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2013-05/0064.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"access_vector": "LOCAL",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "PARTIAL",
"integrity_impact": "NONE",
"availability_impact": "NONE",
"base_score": 2.1,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "LOW",
"exploitability_score": 3.9,
"impact_score": 2.9,
"ac_insuf_info": false,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:rsa:authentication_api:*:*:*:*:*:*:*:*",
"match_criteria_id": "106A85E9-6CC3-4FEF-B4DC-E2324FCA2EC4",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "8.1",
"version_end_excluding": null
}
]
}
]
},
{
"operator": "AND",
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:rsa:securid_web_agent:*:*:*:*:*:*:*:*",
"match_criteria_id": "085DCA9D-174A-4B6E-984B-E870E6B466FC",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "5.3.4",
"version_end_excluding": null
}
]
},
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": false,
"criteria": "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
"match_criteria_id": "5A6CD1F4-4C0E-4989-A2B3-DC086E8E80A3",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": "AND",
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:rsa:securid_web_agent:*:*:*:*:*:*:*:*",
"match_criteria_id": "085DCA9D-174A-4B6E-984B-E870E6B466FC",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "5.3.4",
"version_end_excluding": null
}
]
},
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": false,
"criteria": "cpe:2.3:a:microsoft:internet_information_server:*:*:*:*:*:*:*:*",
"match_criteria_id": "CE9D333C-76E2-4BD9-B98B-5CB96363AB89",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:rsa:pluggable_authentication_module_agent:*:*:*:*:*:*:*:*",
"match_criteria_id": "923ED08F-368E-46EC-AAF4-6B1B924B4280",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "6.0",
"version_end_excluding": null
}
]
}
]
},
{
"operator": "AND",
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:rsa:authentication_agent:*:*:*:*:*:*:*:*",
"match_criteria_id": "653BDB04-670F-4E57-A3AA-AE56162F28DB",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "6.1.3",
"version_end_excluding": null
}
]
},
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": false,
"criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
"match_criteria_id": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": null,
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:a:rsa:authentication_api:*:*:*:*:*:*:*:*",
"vendor": "rsa",
"product": "authentication_api",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "8.1",
"version_end_excluding": null,
"affected_versions_first": "8.1",
"affected_versions_last": "8.1"
},
{
"criteria": "cpe:2.3:a:rsa:securid_web_agent:*:*:*:*:*:*:*:*",
"vendor": "rsa",
"product": "securid_web_agent",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "5.3.4",
"version_end_excluding": null,
"affected_versions_first": "5",
"affected_versions_last": "5.3.4"
},
{
"criteria": "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": false,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.8.11",
"affected_versions_last": "12.2.1.3.0"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_information_server:*:*:*:*:*:*:*:*",
"vendor": "microsoft",
"product": "internet_information_server",
"product_type": "a",
"vulnerable": false,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "1.0",
"affected_versions_last": "10.0"
},
{
"criteria": "cpe:2.3:a:rsa:pluggable_authentication_module_agent:*:*:*:*:*:*:*:*",
"vendor": "rsa",
"product": "pluggable_authentication_module_agent",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "6.0",
"version_end_excluding": null,
"affected_versions_first": "6.0",
"affected_versions_last": "6.0"
},
{
"criteria": "cpe:2.3:a:rsa:authentication_agent:*:*:*:*:*:*:*:*",
"vendor": "rsa",
"product": "authentication_agent",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "6.1.3",
"version_end_excluding": null,
"affected_versions_first": "6.1.3",
"affected_versions_last": "6.1.3"
},
{
"criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
"vendor": "microsoft",
"product": "windows",
"product_type": "o",
"vulnerable": false,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "server_2008",
"affected_versions_last": "2000"
}
],
"cwe": null,
"epss_score": {
"epss": 0.01263,
"percentile": 0.68429,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"attack_vector": "LOCAL",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "PARTIAL",
"vulnerable_system_integrity": "NONE",
"vulnerable_system_availability": "NONE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 2.1,
"base_severity": "LOW"
}
}
}
},
{
"id": "CVE-2004-1834",
"source_identifier": "user@mitre.org",
"published": "2004-03-20T05:00:00Z",
"last_modified": "2026-06-16T22:08:29Z",
"status": "Modified",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information."
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=107981737322495&w=2",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://secunia.com/advisories/11176",
"source": "user@mitre.org",
"tags": [
"Exploit",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/19072",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://securitytracker.com/id?1009509",
"source": "user@mitre.org",
"tags": [
"Exploit",
"Vendor Advisory"
]
},
{
"url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://www.osvdb.org/4446",
"source": "user@mitre.org",
"tags": [
"Exploit",
"Vendor Advisory"
]
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2004-562.html",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://www.securityfocus.com/bid/9933",
"source": "user@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.vupen.com/english/advisories/2006/0789",
"source": "user@mitre.org",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"access_vector": "LOCAL",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "PARTIAL",
"integrity_impact": "NONE",
"availability_impact": "NONE",
"base_score": 2.1,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "LOW",
"exploitability_score": 3.9,
"impact_score": 2.9,
"ac_insuf_info": false,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*",
"match_criteria_id": "163A6EF6-7D3F-4B1F-9E03-A8C86562CC3D",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:*",
"match_criteria_id": "154566FB-0D1A-4DC2-AFE6-49DE93850951",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*",
"match_criteria_id": "EB477AFB-EA39-4892-B772-586CF6D2D235",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:*",
"match_criteria_id": "5C4962BB-0E61-4788-B582-21F05CD33AD3",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*",
"match_criteria_id": "B35906CD-038E-4243-8A95-F0A3A43F06F7",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:*",
"match_criteria_id": "B940BB85-03F5-46D7-8DC9-2E1E228D3D98",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:*",
"match_criteria_id": "82139FFA-2779-4732-AFA5-4E6E19775899",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:*",
"match_criteria_id": "B7F717E6-BACD-4C8A-A9C5-516ADA6FEE6C",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:*",
"match_criteria_id": "08AB120B-2FEC-4EB3-9777-135D81E809AA",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:*",
"match_criteria_id": "1C7FF669-12E0-4A73-BBA7-250D109148C5",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": [
{
"organization": "Apache",
"comment": "Fixed in Apache HTTP Server 2.0.53:\nhttp://httpd.apache.org/security/vulnerabilities_20.html",
"last_modified": "2008-07-02T00:00:00Z"
}
],
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0",
"affected_versions_last": "2.0"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.9",
"affected_versions_last": "2.0.9"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.28",
"affected_versions_last": "2.0.28"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.28",
"affected_versions_last": "2.0.28"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.32",
"affected_versions_last": "2.0.32"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.35",
"affected_versions_last": "2.0.35"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.36",
"affected_versions_last": "2.0.36"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.37",
"affected_versions_last": "2.0.37"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.38",
"affected_versions_last": "2.0.38"
},
{
"criteria": "cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:*",
"vendor": "apache",
"product": "http_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0.39",
"affected_versions_last": "2.0.39"
}
],
"cwe": null,
"epss_score": {
"epss": 0.035,
"percentile": 0.88662,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"attack_vector": "LOCAL",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "PARTIAL",
"vulnerable_system_integrity": "NONE",
"vulnerable_system_availability": "NONE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 2.1,
"base_severity": "LOW"
}
}
}
}
]
}