CVE-2014-3583

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.


We have discovered 714,233 live websites that are affected by CVE-2014-3583.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains714,233 live websites (26% of Apache install base)
Vulnerable Versions
  • from 0 through 2.4.10
Vulnerable Versions Count70 versions ( 59% of all versions)



Details

  • Published - Dec 16, 2014
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2014-3583
United States177,264 websites



Taiwan108,588 websites
Germany57,551 websites
Japan46,318 websites
France29,318 websites
Russia28,966 websites
Netherlands28,917 websites
Czech Republic18,602 websites
Singapore17,954 websites
Italy16,945 websites

Website Distribution by TLD

Number of websites using CVE-2014-3583
.com318,365 websites
.de40,927 websites
.net28,903 websites
.ru24,987 websites
.org24,784 websites
.nl20,898 websites
.cz15,170 websites
.it14,678 websites
.jp13,393 websites
.info12,438 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2014-3583

Top websites that are affected by CVE-2014-3583. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
******************.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
******.****************.com United States*,***
*.******.***.***.br Brazil*,***
See full domain list

FAQ

A total of 714,233 websites have been identified as vulnerable to CVE-2014-3583, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2014-3583 vulnerability.
Apache versions up to and including 2.4.10 are vulnerable to CVE-2014-3583.

References