CVE-2010-0434

The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.


We have discovered 189,435 live websites that are affected by CVE-2010-0434.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains189,435 live websites (6.00% of Apache install base)
Vulnerable Versions
  • from 0 before 2.2.15
Vulnerable Versions Count66 versions ( 44.90% of all versions)



Details

  • Published - Mar 6, 2010
  • Updated - Aug 7, 2024

CVE-2010-0434 usage by Country

United States20,678 websites



Taiwan97,875 websites
Germany15,418 websites
Japan11,069 websites
Singapore4,305 websites
France3,643 websites
Russia3,133 websites
Czech Republic2,312 websites
Austria2,265 websites
Italy2,198 websites

CVE-2010-0434 usage by TLD

.com108,704 websites
.de13,399 websites
.info8,096 websites
.net6,507 websites
.org4,868 websites
.cn3,594 websites
.jp3,016 websites
.ru2,773 websites
.cz1,983 websites
.co.jp1,908 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2010-0434

Top websites that are affected by CVE-2010-0434. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.********.de Germany*,***
**********.com United States*,***
****.**********.com United States*,***
*****.**********.com United States*,***
*****.***.tw Taiwan*,***
*******.****************.com United States*,***
*******.**********.com United States*,***
***.************.de Germany*,***
******.****.br Brazil*,***
**********.***.com United States*,***
See full domain list

FAQ

A total of 189,435 websites have been identified as vulnerable to CVE-2010-0434, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2010-0434 vulnerability.
Apache versions before 2.2.15 are vulnerable to CVE-2010-0434.
Version 2.2.15 of Apache addresses the CVE-2010-0434 security vulnerability.

References