The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
We have discovered 714,233 live websites that are affected by CVE-2014-3583.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 714,233 live websites (26% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 70 versions ( 59% of all versions) |
| 177,264 websites | |
| 108,588 websites | |
| 57,551 websites | |
| 46,318 websites | |
| 29,318 websites | |
| 28,966 websites | |
| 28,917 websites | |
| 18,602 websites | |
| 17,954 websites | |
| 16,945 websites |
| .com | 318,365 websites |
| .de | 40,927 websites |
| .net | 28,903 websites |
| .ru | 24,987 websites |
| .org | 24,784 websites |
| .nl | 20,898 websites |
| .cz | 15,170 websites |
| .it | 14,678 websites |
| .jp | 13,393 websites |
| .info | 12,438 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***********.com | *** | ||
| ******************.com | *,*** | ||
| *********.******.net | *,*** | ||
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| ****.**.pl | *,*** | ||
| ******.com | *,*** | ||
| ********.********.de | *,*** | ||
| ******.****************.com | *,*** | ||
| *.******.***.***.br | *,*** |