Skip to content

CVE-2014-0226

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.7544 (75.4%)
Percentile: 98.9%
EPSS: 2026-05-06

Affects

apache:http_serverdebian:debian_linuxredhat:jboss_enterprise_application_platformredhat:enterprise_linuxoracle:enterprise_manager_ops_centeroracle:http_serveroracle:secure_global_desktop

Technical description

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

Published: 7/20/2014, 11:12:48 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam