CVE-2006-20001

HIGH

Apache HTTP Server < 2.4.55 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.

Exploits (1)

nomisec STUB
by r1az4r · poc
https://github.com/r1az4r/CVE-2006-20001

References (3)

Core 3
Core References
Release Notes, Vendor Advisory vendor-advisory
https://httpd.apache.org/security/vulnerabilities_24.html

Scores

CVSS v3 7.5
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (1)
apache/http_server < 2.4.55
Published Jan 17, 2023
Tracked Since Feb 18, 2026