Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-0253

25
FAUCET Score

CVE-2015-0253 describes a denial-of-service vulnerability in Apache HTTP Server 2.4.12, also affecting Apple and Oracle products. An uninitialized protocol structure member in the read_request_line function can be triggered by a specially crafted request lacking a method, leading to a NULL pointer dereference and process crash. Rated with a CVSS score of 5.0, this vulnerability has a low attack complexity and requires no authentication, but its impact is limited to availability (denial of service). The FAUCET Risk Score is 43/100, indicating a moderate risk. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low overall attention to this particular CVE.

Impacted Technologies

VendorProductVersion(s)CPE
2.4.12CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.4.12:*:*:*:*:*:*:*
10.10.4CPE matchmatch criteria
cpe:2.3:o:apple:mac_os_x:10.10.4:*:*:*:*:*:*:*
5.0.3CPE matchmatch criteria
cpe:2.3:o:apple:mac_os_x_server:5.0.3:*:*:*:*:*:*:*
7CPE matchmatch criteria
cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*
11.3CPE matchmatch criteria
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
14.73%
Probability of exploitation in next 30 days
EPSS Percentile
96.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1473 is in the 96th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

apachepatch availablevia llm_extracted
Fixed in: 2.4
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: httpd24-httpd-0:2.4.12-4.el6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSFixed in: httpd24-httpd-0:2.4.12-4.el6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSFixed in: httpd24-httpd-0:2.4.12-4.el6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: httpd24-httpd-0:2.4.12-6.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSFixed in: httpd24-httpd-0:2.4.12-6.el7.1
View patch

Vendor Advisories (4)

apachellm-apache-f398f8ed28802aa3LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Mar 2, 2026
apachellm-apache-a7a91ec4c0e9421dHIGH

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Dec 10, 2025
redhatCVE-2015-0253Low

httpd: NULL pointer dereference crash with ErrorDocument 400 pointing to a local URL-path

Jul 15, 2015
apachellm-apache-684e4d0003611bd4LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

References

httpd.apache.org / security/vulnerabilities_24.html
Vendor Advisory
lists.apple.com / archives/security-announce/2015/Aug/msg00001.html
Mailing List
lists.apple.com / archives/security-announce/2015/Sep/msg00004.html
Mailing List
rhn.redhat.com / errata/RHSA-2015-1666.html
bz.apache.org / bugzilla/show_bug.cgi
Issue Tracking
github.com / apache/httpd/commit/6a974059190b8a0c7e499f4ab12fe108127099cb
github.com / apache/httpd/commit/be0f5335e3e73eb63253b050fdc23f252f5c8ae3
lists.apache.org / thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
support.apple.com / HT205219
Third Party Advisory
support.apple.com / kb/HT205031
Third Party Advisory
apache.org / dist/httpd/CHANGES_2.4
Release NotesVendor Advisory
oracle.com / technetwork/topics/security/bulletinoct2015-2511968.html
Third Party Advisory
oracle.com / technetwork/topics/security/linuxbulletinjan2016-2867209.html
Third Party Advisory
securityfocus.com / bid/75964
securitytracker.com / id/1032967