Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-13950
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service
Exploit prediction scoring system (EPSS) score
EPSS Score
0.17
EPSS Ranking
94.6%
CVSS Severity
CVSS v3 Score
7.5
CVSS v2 Score
5.0
References
http://httpd.apache.org/security/vulnerabilities_24.html
http://www.openwall.com/lists/oss-security/2021/06/10/4
https://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org%3E
https://lists.apache.org/thread.html/rbe197409ae4a58b629fb792d1aed541ccbbf865121a80e1c5938d223%40%3Cannounce.httpd.apache.org%3E
https://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3E
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/
https://security.gentoo.org/glsa/202107-38
https://security.netapp.com/advisory/ntap-20210702-0001/
https://www.oracle.com/security-alerts/cpuoct2021.html
http://httpd.apache.org/security/vulnerabilities_24.html
http://www.openwall.com/lists/oss-security/2021/06/10/4
https://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org%3E
https://lists.apache.org/thread.html/rbe197409ae4a58b629fb792d1aed541ccbbf865121a80e1c5938d223%40%3Cannounce.httpd.apache.org%3E
https://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3E
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/
https://security.gentoo.org/glsa/202107-38
https://security.netapp.com/advisory/ntap-20210702-0001/
https://www.oracle.com/security-alerts/cpuoct2021.html
Products affected by CVE-2020-13950
Apache
»
Http Server
»
Version:
2.4.41
cpe:2.3:a:apache:http_server:2.4.41
Apache
»
Http Server
»
Version:
2.4.42
cpe:2.3:a:apache:http_server:2.4.42
Apache
»
Http Server
»
Version:
2.4.43
cpe:2.3:a:apache:http_server:2.4.43
Apache
»
Http Server
»
Version:
2.4.44
cpe:2.3:a:apache:http_server:2.4.44
Apache
»
Http Server
»
Version:
2.4.45
cpe:2.3:a:apache:http_server:2.4.45
Apache
»
Http Server
»
Version:
2.4.46
cpe:2.3:a:apache:http_server:2.4.46
Oracle
»
Enterprise Manager Ops Center
»
Version:
12.4.0.0
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0
Oracle
»
Instantis Enterprisetrack
»
Version:
17.1
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1
Oracle
»
Instantis Enterprisetrack
»
Version:
17.2
cpe:2.3:a:oracle:instantis_enterprisetrack:17.2
Oracle
»
Instantis Enterprisetrack
»
Version:
17.3
cpe:2.3:a:oracle:instantis_enterprisetrack:17.3
Oracle
»
Zfs Storage Appliance Kit
»
Version:
8.8
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8
Debian
»
Debian Linux
»
Version:
10.0
cpe:2.3:o:debian:debian_linux:10.0
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Fedoraproject
»
Fedora
»
Version:
34
cpe:2.3:o:fedoraproject:fedora:34
Fedoraproject
»
Fedora
»
Version:
35
cpe:2.3:o:fedoraproject:fedora:35
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved