Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2005-2728

18
FAUCET Score

CVE-2005-2728 describes a denial-of-service vulnerability in Apache HTTP Server versions prior to 2.0.54. This flaw allows remote attackers to exhaust server memory by sending an HTTP request with a large Range header field, affecting the byte-range filter. The vulnerability has a CVSS score of 5.0 (medium severity) with a low attack complexity and no authentication required, leading to potential availability impact. While it has a high FAUCET Risk Score, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this older CVE.

Impacted Technologies

VendorProductVersion(s)CPE
2.0CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*
2.0.9CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:*
2.0.28CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*
2.0.28CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:*
2.0.32CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
10.98%
Probability of exploitation in next 30 days
EPSS Percentile
95.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1098 is in the 95th percentile among its peer group of 23,705 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: httpd-0:2.0.46-46.3.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: httpd-0:2.0.52-12.2.ent
View patch

Vendor Advisories (1)

redhatCVE-2005-2728Moderate

security flaw

Jul 7, 2004

References

patches.sgi.com / support/free/security/advisories/20060101-01-U
issues.apache.org / bugzilla/show_bug.cgi
PatchVendor Advisory
lists.trustix.org / pipermail/tsl-announce/2005-October/000354.html
secunia.com / advisories/16559
Vendor Advisory
secunia.com / advisories/16705
secunia.com / advisories/16714
secunia.com / advisories/16743
secunia.com / advisories/16746
secunia.com / advisories/16753
secunia.com / advisories/16754
secunia.com / advisories/16769
secunia.com / advisories/16789
secunia.com / advisories/16956
secunia.com / advisories/17036
secunia.com / advisories/17288
secunia.com / advisories/17600
secunia.com / advisories/17831
secunia.com / advisories/17923
secunia.com / advisories/18161
secunia.com / advisories/18333
secunia.com / advisories/18517
secunia.com / advisories/19072
securityreason.com / securityalert/604
exchange.xforce.ibmcloud.com / vulnerabilities/22006
lists.apache.org / thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10017
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1246
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1727
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A760
sunsolve.sun.com / search/document.do
support.avaya.com / elmodocs2/security/ASA-2006-081.htm
debian.org / security/2005/dsa-805
gentoo.org / security/en/glsa/glsa-200508-15.xml
PatchVendor Advisory
mandriva.com / security/advisories
novell.com / linux/security/advisories/2005_51_apache2.html
novell.com / linux/security/advisories/2005_52_apache2.html
redhat.com / support/errata/RHSA-2005-608.html
securityfocus.com / archive/1/428138/100/0/threaded
securityfocus.com / bid/14660
Patch
ubuntu.com / usn/usn-177-1
vupen.com / english/advisories/2006/0789