CVE-2006-20001

Apache HTTP Server: mod_dav out of bounds read, or write of zero byte

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.


We have discovered 1,125,568 live websites that are affected by CVE-2006-20001.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains1,125,568 live websites (40% of Apache install base)
Vulnerable Versions
  • from 2.4 through 2.4.54
Vulnerable Versions Count46 versions ( 39% of all versions)


Common Weakness Enumeration

CWE-787 Out-of-bounds Write



Details

  • Published - Jan 17, 2023
  • Updated - Feb 13, 2025

Website Distribution by Country

Number of websites using CVE-2006-20001
United States347,464 websites



Germany119,920 websites
France67,100 websites
Japan45,551 websites
Russia44,216 websites
Italy39,967 websites
Netherlands38,147 websites
Singapore32,019 websites
GB30,709 websites
Czech Republic29,791 websites

Website Distribution by TLD

Number of websites using CVE-2006-20001
.com423,409 websites
.de70,545 websites
.org53,139 websites
.net44,433 websites
.ru38,982 websites
.it36,308 websites
.nl28,917 websites
.cz24,852 websites
.fr22,164 websites
.pl20,690 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2006-20001

Top websites that are affected by CVE-2006-20001. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*********.net United States***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
******************.com United States*,***
****.*********.net GB*,***
*******.org United States*,***
****.com United States*,***
See full domain list

FAQ

CVE-2006-20001 is Out-of-bounds Write in Apache
A total of 1,125,568 websites have been identified as vulnerable to CVE-2006-20001, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2006-20001 vulnerability.
Apache versions up to and including 2.4.54 are vulnerable to CVE-2006-20001.