CVE-2014-3583

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.


We have discovered 869,017 live websites that are affected by CVE-2014-3583.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains869,017 live websites (27.54% of Apache install base)
Vulnerable Versions
  • from 0 before 2.4.10
Vulnerable Versions Count97 versions ( 65.99% of all versions)



Details

  • Published - Dec 16, 2014
  • Updated - Aug 6, 2024

CVE-2014-3583 usage by Country

United States261,130 websites



Taiwan109,190 websites
Germany71,574 websites
Japan53,695 websites
Netherlands37,791 websites
Russia34,778 websites
France28,856 websites
Singapore23,322 websites
GB19,835 websites
Czech Republic18,527 websites

CVE-2014-3583 usage by TLD

.com384,706 websites
.de53,085 websites
.net36,174 websites
.org30,637 websites
.ru30,485 websites
.nl27,575 websites
.jp16,208 websites
.cz15,067 websites
.info14,501 websites
.it13,757 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2014-3583

Top websites that are affected by CVE-2014-3583. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
*********.*************.se United States***
********.*********.com Singapore*,***
******************.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
See full domain list

FAQ

A total of 869,017 websites have been identified as vulnerable to CVE-2014-3583, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2014-3583 vulnerability.
Apache versions before 2.4.10 are vulnerable to CVE-2014-3583.
Version 2.4.10 of Apache addresses the CVE-2014-3583 security vulnerability.

References