296,843
Total vulnerabilities in the database
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
| Software | From | Fixed in | 
|---|---|---|
| apache / http_server | 1.3.23 | 1.3.23.x | 
| apache / http_server | 1.3.16 | 1.3.16.x | 
| apache / http_server | 1.3.19 | 1.3.19.x | 
| apache / http_server | 1.3.20 | 1.3.20.x | 
| apache / http_server | 1.3.13 | 1.3.13.x | 
| apache / http_server | 1.3.18 | 1.3.18.x | 
| apache / http_server | 1.3.12 | 1.3.12.x | 
| apache / http_server | 1.3.17 | 1.3.17.x | 
| apache / http_server | 1.3.9 | 1.3.9.x | 
| apache / http_server | 1.3.15 | 1.3.15.x | 
| apache / http_server | 1.3.14 | 1.3.14.x | 
| apache / http_server | 1.3.22 | 1.3.22.x | 
| apache / http_server | 1.3.11 | 1.3.11.x |