Mod_ssl is an Apache module that provides TLS/SSL encryption capabilities to the widely deployed Apache HTTP Server, occupying a foundational role in web server security infrastructure. The module's limited disclosure history centers on the cryptographic and protocol-handling context characteristic of TLS implementations, with recorded issues spanning general classification categories; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mod Ssl over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0082HIGH The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which | Mar 15, 2002 | 7.5 | 51 | NO | YES |
CVE-2002-0653HIGH Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute ar | Jul 11, 2002 | 7.8 | 29 | NO | YES |
CVE-2004-0700HIGH Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arb | Jul 27, 2004 | 7.5 | 26 | NO | NO |
CVE-2002-1157HIGH Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute scri | Nov 4, 2002 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mod Ssl.
Media articles that mention a CVE ID that affects a product developed by Mod Ssl — matched by CVE ID, not by vendor name.