Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-29170 2 Apache, Apache Software Foundation 2 Http Server, Apache Http Server 2026-06-09 6.1 Medium
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
CVE-2026-29169 2 Apache, Apache Software Foundation 2 Http Server, Apache Http Server 2026-05-05 7.5 High
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.