Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Modssl

First CVE: Mar 15, 2002Active for: 24 yearsTotal CVEs: 4

Modssl develops mod_ssl, an Apache module providing TLS/SSL encryption for HTTP traffic, and operates as a focused component within the broader Apache ecosystem. The observed vulnerability signal centers on off-by-one errors, a boundary-condition weakness class that recurs in parsing and buffer-management logic inherent to cryptographic protocol implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
Bottom 1%
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Modssl over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2002
24 years ago
Most Recent CVE
Jul 27, 2004
8,032 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2002-0082HIGH
The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which
Mar 15, 20027.551NOYES
CVE-2002-0653HIGH
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute ar
Jul 11, 20027.829NOYES
CVE-2004-0700HIGH
Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arb
Jul 27, 20047.526NONO
CVE-2002-1157HIGH
Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute scri
Nov 4, 20027.523NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
100%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
High
Attack Vector
Local1 (25.0%)
Network0 (0.0%)
Unknown3 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (25.0%)
High0 (0.0%)
Unknown3 (75.0%)
User Interaction
None1 (25.0%)
Unknown3 (75.0%)
Required0 (0.0%)
Privileges Required
Low1 (25.0%)
High0 (0.0%)
None0 (0.0%)
Unknown3 (75.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
50.0% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Modssl.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Modssl — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Modssl's Products

View all 1 CNAs →

Top CWEs