← All CVEs

CVE-2006-3747

high · 7.6

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

7.6
CVSS
96.6%
EPSS (exploit prob.)
100th
EPSS percentile
2006-07-28
Published

AV:N/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
apachehttp_server>= 1.3.28, < 1.3.37
apachehttp_server>= 2.0.46, < 2.0.59
apachehttp_server>= 2.2.0, < 2.2.3
canonicalubuntu_linux5.04
canonicalubuntu_linux5.10
canonicalubuntu_linux6.06
debiandebian_linux3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-3747