Skip to content

CVE-2014-0226

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.7544 (75.4%)
Percentil: 98.9%
EPSS: 2026-05-06

Afecta

apache:http_serverdebian:debian_linuxredhat:jboss_enterprise_application_platformredhat:enterprise_linuxoracle:enterprise_manager_ops_centeroracle:http_serveroracle:secure_global_desktop

Descripción técnica

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.

Publicada: 20/7/2014, 11:12:48
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo