CVE-2014-3583 is a denial-of-service vulnerability affecting the mod_proxy_fcgi module in Apache HTTP Server versions 2.4.10, as well as products from Apple and Canonical. Remote FastCGI servers can trigger a buffer over-read and daemon crash by sending excessively long response headers. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring no authentication and having low attack complexity, leading to potential availability impact. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV entry, despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.9.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.9.5:*:*:*:*:*:*:* | ||
10.10.0CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.10.0:*:*:*:*:*:*:* | ||
10.10.1CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.10.1:*:*:*:*:*:*:* | ||
10.10.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.10.2:*:*:*:*:*:*:* | ||
10.10.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.10.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_proxy_fcgi handle_headers() buffer over read
Oct 12, 2014Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project