Modssl develops mod_ssl, an Apache module providing TLS/SSL encryption for HTTP traffic, and operates as a focused component within the broader Apache ecosystem. The observed vulnerability signal centers on off-by-one errors, a boundary-condition weakness class that recurs in parsing and buffer-management logic inherent to cryptographic protocol implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Modssl over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0082HIGH The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which | Mar 15, 2002 | 7.5 | 51 | NO | YES |
CVE-2002-0653HIGH Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute ar | Jul 11, 2002 | 7.8 | 29 | NO | YES |
CVE-2004-0700HIGH Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arb | Jul 27, 2004 | 7.5 | 26 | NO | NO |
CVE-2002-1157HIGH Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute scri | Nov 4, 2002 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Modssl.
Media articles that mention a CVE ID that affects a product developed by Modssl — matched by CVE ID, not by vendor name.