← Vulnerability feed

Vulnerability record · CVE-2007-1863 · published 27 June 2007

CVE-2007-1863: Apple mac os x server vulnerability

Apple · Mac Os X Server

cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.

5.0 CVSS 2.0 Medium EPSS 12% · top 4.1%
5.0CVSS 2.0 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
130References
16 Jun 2026Last modified by NVD

Description

cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=186219 Third Party Advisory
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244658 Issue Tracking
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795 Broken Link
http://httpd.apache.org/security/vulnerabilities_20.html Vendor Advisory
http://httpd.apache.org/security/vulnerabilities_22.html Vendor Advisory
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html Third Party Advisory
http://lists.vmware.com/pipermail/security-announce/2009/000062.html Third Party AdvisoryVDB Entry
http://osvdb.org/37079 Broken Link
http://rhn.redhat.com/errata/RHSA-2007-0534.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2007-0556.html Third Party AdvisoryVDB Entry
http://secunia.com/advisories/25830 Broken Link
http://secunia.com/advisories/25873 Broken Link
http://secunia.com/advisories/25920 Broken Link
http://secunia.com/advisories/26273 Broken Link
http://secunia.com/advisories/26443 Broken Link
http://secunia.com/advisories/26508 Broken Link
http://secunia.com/advisories/26822 Broken Link
http://secunia.com/advisories/26842 Broken Link
http://secunia.com/advisories/26993 Broken Link
http://secunia.com/advisories/27037 Broken Link
http://secunia.com/advisories/27563 Broken Link
http://secunia.com/advisories/27732 Broken Link
http://secunia.com/advisories/28606 Broken Link
http://secunia.com/advisories/30430 Broken Link
http://security.gentoo.org/glsa/glsa-200711-06.xml Third Party Advisory
http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm Third Party Advisory
http://svn.apache.org/viewvc?view=rev&revision=535617 Third Party Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1PK49355 Third Party Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702 Third Party Advisory
http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2007:140 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2007:141 Third Party Advisory
http://www.novell.com/linux/security/advisories/2007_61_apache2.html Broken Link
http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html Mailing ListThird Party Advisory
http://www.redhat.com/support/errata/RHSA-2007-0557.html Broken Link
http://www.securityfocus.com/archive/1/505990/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/24649 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1018303 Third Party AdvisoryVDB Entry
http://www.trustix.org/errata/2007/0026/ Broken Link
http://www.ubuntu.com/usn/usn-499-1 Third Party AdvisoryVDB Entry

Track CVE-2007-1863 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed7.8CVE-2019-0211Apache HTTP Server scoreboard use-after-free local privilege escalationApache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-p…KEVEPSS 65%analysed10.0CVE-2015-5911Apple mac os x server vulnerabilityMultiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML…EPSS 2.0%10.0CVE-2010-0055Apple mac os x vulnerabilityxar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers to have an unspecified impact via a modified packa…EPSS 2.0%10.0CVE-2010-0508Apple mac os x vulnerabilityMail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mail account, which has unspecified impact and attac…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2007-1863), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.