CVE-2015-0253 describes a denial-of-service vulnerability in Apache HTTP Server 2.4.12, also affecting Apple and Oracle products. An uninitialized protocol structure member in the read_request_line function can be triggered by a specially crafted request lacking a method, leading to a NULL pointer dereference and process crash. Rated with a CVSS score of 5.0, this vulnerability has a low attack complexity and requires no authentication, but its impact is limited to availability (denial of service). The FAUCET Risk Score is 43/100, indicating a moderate risk. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low overall attention to this particular CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.12CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.12:*:*:*:*:*:*:* | ||
10.10.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.10.4:*:*:*:*:*:*:* | ||
5.0.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x_server:5.0.3:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: NULL pointer dereference crash with ErrorDocument 400 pointing to a local URL-path
Jul 15, 2015Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project