CVE-2002-0392

Apache HTTP Server < 1.3.24 - Denial of Service

Title source: rule

Description

Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows_x86
https://www.exploit-db.com/exploits/16782
exploitdb WORKING POC VERIFIED
by Gobbles Security · cremotemultiple
https://www.exploit-db.com/exploits/21560
exploitdb WORKING POC VERIFIED
by Gobbles Security · cremotemultiple
https://www.exploit-db.com/exploits/21559
metasploit WORKING POC GOOD
by hdm, jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/apache_chunked.rb

References (45)

... and 25 more

Scores

EPSS 0.5389
EPSS Percentile 98.0%

Details

Status published
Products (2)
apache/http_server 1.2.2 - 1.3.24
debian/debian_linux 2.2
Published Jul 03, 2002
Tracked Since Feb 18, 2026