← All CVEs

CVE-2010-0010

medium · 6.8

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.

6.8
CVSS
43.4%
EPSS (exploit prob.)
99th
EPSS percentile
2010-02-02
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
apachehttp_server<= 1.3.41
apachehttp_server0.8.11
apachehttp_server0.8.14
apachehttp_server1.0
apachehttp_server1.0.3
apachehttp_server1.0.5
apachehttp_server1.1
apachehttp_server1.2
apachehttp_server1.2.4
apachehttp_server1.2.5
apachehttp_server1.2.6
apachehttp_server1.3
apachehttp_server1.3.0
apachehttp_server1.3.1
apachehttp_server1.3.2
apachehttp_server1.3.3
apachehttp_server1.3.4
apachehttp_server1.3.10
apachehttp_server1.3.11
apachehttp_server1.3.12
apachehttp_server1.3.13
apachehttp_server1.3.14
apachehttp_server1.3.15
apachehttp_server1.3.17
apachehttp_server1.3.18
apachehttp_server1.3.19
apachehttp_server1.3.20
apachehttp_server1.3.22
apachehttp_server1.3.23
apachehttp_server1.3.24
apachehttp_server1.3.25
apachehttp_server1.3.26
apachehttp_server1.3.27
apachehttp_server1.3.28
apachehttp_server1.3.29
apachehttp_server1.3.30
apachehttp_server1.3.31
apachehttp_server1.3.32
apachehttp_server1.3.33
apachehttp_server1.3.34

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-0010