CVE-2007-6750 describes a denial-of-service vulnerability affecting Apache HTTP Server versions 1.x and 2.x, allowing remote attackers to cause a daemon outage through partial HTTP requests. This vulnerability, famously exploited by the Slowloris attack, stems from the absence of the mod_reqtimeout module in versions prior to 2.2.15. With a CVSS score of 5.0 and a FAUCET Risk Score of 98/100, it presents a moderate to high risk due to its low attack complexity and potential for system unavailability. While not on CISA's KEV list, a Metasploit module exists for the Slowloris attack, indicating readily available exploit code, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.14CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.0:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.0.2:*:*:*:*:*:*:* | ||
1.0.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.0.3:*:*:*:*:*:*:* | ||
1.0.5CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.