Vulnerability

CVE-2010-0010

MEDIUM 6.8

CVE-2010-0010 is a medium-severity vulnerability (CVSS v2 6.8). As of 2026-10-09, 1 796 hosts in our data show software it affects on an open service in at least 15 countries.

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.

Published
2010-02-02
Last modified
2026-06-16
CVSS score
6.8 CVSS v2
CVSS vector (v2)
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploit likelihood (EPSS)
43.4% in the next 30 days (higher than 99% of CVEs)

Exposure in our data

1 796 hosts

Hosts whose banner shows an affected software version on a service open at their latest check.

Not counted: 132 hosts with this CVE only from an older observation.

Not counted: 42 hosts where the software version is too vague to tell (only a major release).

Not counted: 105 more on distribution builds that may be patched (the distribution may have backported the fix without changing the version).

17 more hosts had it earlier (the software version has since changed or the service is gone).

Counted 2026-10-09 08:20 UTC

By country

Japan JP532
United States US258
Germany DE196
South Korea KR104
Finland FI81
Italy IT68
Russia RU64
Spain ES63
France FR59
Taiwan TW48
Sweden SE36
Netherlands NL20
China CN18
Austria AT16
India IN16

Affected software seen

http_server 1.3.31299
http_server 1.3.41221
http_server 0.6.5212
http_server 1.3.33194
http_server 1.3.29149
http_server 1.3.37145
http_server 1.3.3499
http_server 1.3.2793
http_server 1.3.3969
http_server 1.3.2665
http_server 1.3.2349
http_server 1.2.634