Mod Ssl
Vendor:
First CVE: Mar 15, 2002 · Active for 24 years
4
Total CVEs
Bottom 1%
2.0
Avg CVEs / Year
Bottom 1%
7.6
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mod Ssl over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2002
24 years ago
Most Recent CVE
Jul 27, 2004
8,032 days ago
CVE Severity & Scoring
Mod Ssl4 CVEs
100%
All CVEs352,101 CVEs
45%
40%
11%
High
Attack Vector
Local1 (25.0%)
Network0 (0.0%)
Unknown3 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (25.0%)
High0 (0.0%)
Unknown3 (75.0%)
User Interaction
None1 (25.0%)
Unknown3 (75.0%)
Required0 (0.0%)
Privileges Required
Low1 (25.0%)
High0 (0.0%)
None0 (0.0%)
Unknown3 (75.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0082HIGH The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which | Mar 15, 2002 | 7.5 | 51 | NO | YES |
CVE-2002-0653HIGH Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute ar | Jul 11, 2002 | 7.8 | 29 | NO | YES |
CVE-2004-0700HIGH Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arb | Jul 27, 2004 | 7.5 | 26 | NO | NO |
CVE-2002-1157HIGH Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute scri | Nov 4, 2002 | 7.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
50.0% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Mod Ssl
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.8.9 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.8 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.7 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.6 | 2 | 7.5 | 17.8% | 0 | 1 |
| 2.8.5.2 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.5.1 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.5 | 2 | 7.5 | 17.8% | 0 | 1 |
| 2.8.4 | 2 | 7.5 | 17.8% | 0 | 1 |
| 2.8.3 | 2 | 7.5 | 17.8% | 0 | 1 |
| 2.8.2 | 2 | 7.5 | 17.8% | 0 | 1 |
| 2.8.18 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.17 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.16 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.15 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.14 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.1.2 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.12 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.10 | 1 | 7.5 | 5.8% | 0 | 0 |
| 2.8.1 | 2 | 7.5 | 17.8% | 0 | 1 |
| 2.8.0 | 1 | 7.5 | 5.8% | 0 | 0 |