CVE-2004-0113 describes a memory leak vulnerability in the mod_ssl component of Apache HTTP Server versions prior to 2.0.49. This flaw allows remote attackers to trigger a denial of service by sending plain HTTP requests to an SSL-enabled port, leading to excessive memory consumption. With a CVSS score of 5.0, it is a low-complexity attack requiring no authentication, resulting in partial availability impact. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, suggesting limited attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.35CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:* | ||
2.0.36CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:* | ||
2.0.37CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:* | ||
2.0.38CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:* | ||
2.0.39CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.