Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2005-3357

24
FAUCET Score

CVE-2005-3357 describes a denial-of-service vulnerability affecting Apache HTTP Server versions 2.0 up to 2.0.55 when mod_ssl is configured with specific settings. A remote attacker can trigger a NULL pointer dereference and crash the application by sending a non-SSL request to an SSL port under these conditions. The vulnerability has a CVSS score of 5.4, indicating a medium severity with high attack complexity and a complete impact on availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
2.0CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*
2.0.9CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:*
2.0.28CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*
2.0.28CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:*
2.0.32CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.4MEDIUM

AV:N/AC:H/Au:N/C:N/I:N/A:C

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
24.29%
Probability of exploitation in next 30 days
EPSS Percentile
97.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.2429 is in the 98th percentile among its peer group of 19,956 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: httpd-0:2.0.46-56.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: httpd-0:2.0.52-22.ent
View patch

Vendor Advisories (1)

redhatCVE-2005-3357Low

security flaw

Dec 5, 2005

References

patches.sgi.com / support/free/security/advisories/20060101-01-U
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
issues.apache.org / bugzilla/show_bug.cgi
lists.apple.com / archives/security-announce/2008//May/msg00001.html
lists.suse.de / archive/suse-security-announce/2006-Feb/0008.html
Vendor Advisory
marc.info
rhn.redhat.com / errata/RHSA-2006-0159.html
PatchVendor Advisory
secunia.com / advisories/18307
PatchVendor Advisory
secunia.com / advisories/18333
PatchVendor Advisory
secunia.com / advisories/18339
PatchVendor Advisory
secunia.com / advisories/18340
PatchVendor Advisory
secunia.com / advisories/18429
PatchVendor Advisory
secunia.com / advisories/18517
PatchVendor Advisory
secunia.com / advisories/18585
PatchVendor Advisory
secunia.com / advisories/18743
PatchVendor Advisory
secunia.com / advisories/19012
Vendor Advisory
secunia.com / advisories/21848
Vendor Advisory
secunia.com / advisories/22233
Vendor Advisory
secunia.com / advisories/22368
Vendor Advisory
secunia.com / advisories/22523
Vendor Advisory
secunia.com / advisories/22669
Vendor Advisory
secunia.com / advisories/22992
Vendor Advisory
secunia.com / advisories/23260
Vendor Advisory
secunia.com / advisories/29849
Vendor Advisory
secunia.com / advisories/30430
Vendor Advisory
securitytracker.com / id
lists.apache.org / thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
lists.opensuse.org / opensuse-security-announce/2006-09/msg00016.html
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11467
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
support.avaya.com / elmodocs2/security/ASA-2006-250.htm
svn.apache.org / viewcvs
www14.software.ibm.com / webapp/set2/subscriptions/pqvcmjd
gentoo.org / security/en/glsa/glsa-200602-03.xml
PatchVendor Advisory
redhat.com / archives/fedora-announce-list/2006-January/msg00060.html
Patch
securityfocus.com / archive/1/425399/100/0/threaded
securityfocus.com / archive/1/445206/100/0/threaded
securityfocus.com / archive/1/450315/100/0/threaded
securityfocus.com / bid/16152
trustix.org / errata/2005/0074
PatchVendor Advisory
ubuntulinux.org / usn/usn-241-1
us-cert.gov / cas/techalerts/TA08-150A.html
US Government Resource
vupen.com / english/advisories/2006/0056
Vendor Advisory
vupen.com / english/advisories/2006/3920
vupen.com / english/advisories/2006/3995
Vendor Advisory
vupen.com / english/advisories/2006/4207
Vendor Advisory
vupen.com / english/advisories/2006/4300
Vendor Advisory
vupen.com / english/advisories/2006/4868
Vendor Advisory
vupen.com / english/advisories/2008/1246/references
Vendor Advisory
vupen.com / english/advisories/2008/1697
Vendor Advisory