CVE-2018-8011
HIGH EXPLOITED NUCLEIApache HTTP Server <2.4.34 - Use After Free
Title source: llmDescription
By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).
Nuclei Templates (1)
Apache HTTP Server - NULL Pointer Dereference
HIGHVERIFIEDby daffainfo
Shodan:
cpe:"cpe:2.3:a:apache:http_server"
References (15)
Scores
CVSS v3
7.5
EPSS
0.8201
EPSS Percentile
99.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
VulnCheck KEV
2022-02-22
CWE
CWE-476
Status
published
Products (2)
apache/http_server
2.4.33
netapp/cloud_backup
Published
Jul 18, 2018
Tracked Since
Feb 18, 2026