CVE-2014-3581

The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.


We have discovered 625,072 live websites that are affected by CVE-2014-3581.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains625,072 live websites (25% of Apache install base)
Vulnerable Versions
  • from 0 through 2.4.11
Vulnerable Versions Count71 versions ( 58% of all versions)



Details

  • Published - Oct 10, 2014
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2014-3581
United States146,991 websites



Taiwan108,369 websites
Germany50,525 websites
Japan40,419 websites
Netherlands24,947 websites
Russia24,944 websites
France24,228 websites
Singapore16,823 websites
Czech Republic16,399 websites
Italy15,495 websites

Website Distribution by TLD

Number of websites using CVE-2014-3581
.com286,390 websites
.de36,366 websites
.net24,922 websites
.ru21,293 websites
.org20,976 websites
.nl18,616 websites
.cz13,406 websites
.it12,539 websites
.info11,949 websites
.jp11,608 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2014-3581

Top websites that are affected by CVE-2014-3581. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
******************.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
******.****************.com United States*,***
*.******.***.***.br Brazil*,***
See full domain list

FAQ

A total of 625,072 websites have been identified as vulnerable to CVE-2014-3581, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2014-3581 vulnerability.
Apache versions up to and including 2.4.11 are vulnerable to CVE-2014-3581.

References