A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.
We have discovered 1,266,713 live websites that are affected by CVE-2018-1301.
Product | |
Category | Web Servers |
Vulnerable Domains | 1,266,713 live websites (40.15% of Apache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 115 versions ( 78.23% of all versions) |
![]() | 369,437 websites |
![]() | 134,514 websites |
![]() | 110,086 websites |
![]() | 69,675 websites |
![]() | 56,421 websites |
![]() | 52,343 websites |
![]() | 46,729 websites |
![]() | 36,077 websites |
![]() | 35,112 websites |
![]() | 27,475 websites |
.com | 515,290 websites |
.de | 92,784 websites |
.net | 52,143 websites |
.org | 50,100 websites |
.ru | 45,598 websites |
.nl | 33,721 websites |
.cz | 29,556 websites |
.it | 26,263 websites |
.fr | 20,334 websites |
.co.uk | 19,297 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***********.com | ![]() | *** | |
*********.*************.se | ![]() | *** | |
***********.org | ![]() | *** | |
*********.net | ![]() | *** | |
********.*********.com | ![]() | *,*** | |
***.****.us | ![]() | *,*** | |
******************.com | ![]() | *,*** | |
*********.******.net | ![]() | *,*** | |
****.com | ![]() | *,*** | |
********.com | ![]() | *,*** |
FAQ