The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
We have discovered 189,435 live websites that are affected by CVE-2010-0434.
Product | |
Category | Web Servers |
Vulnerable Domains | 189,435 live websites (6.00% of Apache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 66 versions ( 44.90% of all versions) |
![]() | 20,678 websites |
![]() | 97,875 websites |
![]() | 15,418 websites |
![]() | 11,069 websites |
![]() | 4,305 websites |
![]() | 3,643 websites |
![]() | 3,133 websites |
![]() | 2,312 websites |
![]() | 2,265 websites |
![]() | 2,198 websites |
.com | 108,704 websites |
.de | 13,399 websites |
.info | 8,096 websites |
.net | 6,507 websites |
.org | 4,868 websites |
.cn | 3,594 websites |
.jp | 3,016 websites |
.ru | 2,773 websites |
.cz | 1,983 websites |
.co.jp | 1,908 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.********.de | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
****.**********.com | ![]() | *,*** | |
*****.**********.com | ![]() | *,*** | |
*****.***.tw | ![]() | *,*** | |
*******.****************.com | ![]() | *,*** | |
*******.**********.com | ![]() | *,*** | |
***.************.de | ![]() | *,*** | |
******.****.br | ![]() | *,*** | |
**********.***.com | ![]() | *,*** |
FAQ