CVE-2015-0253

The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400 directive specifying a local URI.


We have discovered 610,257 live websites that are affected by CVE-2015-0253.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains610,257 live websites (24% of Apache install base)
Vulnerable Versions
  • from 0 through 2.4.12
Vulnerable Versions Count72 versions ( 59% of all versions)



Details

  • Published - Jul 20, 2015
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2015-0253
United States145,259 websites



Taiwan107,325 websites
Germany49,462 websites
Japan39,779 websites
Netherlands25,065 websites
Russia24,476 websites
France23,648 websites
Czech Republic16,117 websites
Italy15,248 websites
Korea, South14,210 websites

Website Distribution by TLD

Number of websites using CVE-2015-0253
.com281,592 websites
.de35,504 websites
.net24,600 websites
.ru20,895 websites
.org20,440 websites
.nl18,669 websites
.cz13,151 websites
.it12,311 websites
.info11,921 websites
.jp11,366 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2015-0253

Top websites that are affected by CVE-2015-0253. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
******************.com United States*,***
*******.**.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
******.****************.com United States*,***
See full domain list

FAQ

A total of 610,257 websites have been identified as vulnerable to CVE-2015-0253, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2015-0253 vulnerability.
Apache versions up to and including 2.4.12 are vulnerable to CVE-2015-0253.

References