Vulnerability
CVE-2010-0010
CVE-2010-0010 is a medium-severity vulnerability (CVSS v2 6.8). As of 2026-10-09, 1 796 hosts in our data show software it affects on an open service in at least 15 countries.
Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
- Published
- 2010-02-02
- Last modified
- 2026-06-16
- CVSS score
- 6.8 CVSS v2
- CVSS vector (v2)
- AV:N/AC:M/Au:N/C:P/I:P/A:P
- Exploit likelihood (EPSS)
- 43.4% in the next 30 days (higher than 99% of CVEs)
Exposure in our data
1 796 hosts
Hosts whose banner shows an affected software version on a service open at their latest check.
Not counted: 132 hosts with this CVE only from an older observation.
Not counted: 42 hosts where the software version is too vague to tell (only a major release).
Not counted: 105 more on distribution builds that may be patched (the distribution may have backported the fix without changing the version).
17 more hosts had it earlier (the software version has since changed or the service is gone).
Counted 2026-10-09 08:20 UTC
By country
| Japan JP | 532 |
| United States US | 258 |
| Germany DE | 196 |
| South Korea KR | 104 |
| Finland FI | 81 |
| Italy IT | 68 |
| Russia RU | 64 |
| Spain ES | 63 |
| France FR | 59 |
| Taiwan TW | 48 |
| Sweden SE | 36 |
| Netherlands NL | 20 |
| China CN | 18 |
| Austria AT | 16 |
| India IN | 16 |
Affected software seen
| http_server 1.3.31 | 299 |
| http_server 1.3.41 | 221 |
| http_server 0.6.5 | 212 |
| http_server 1.3.33 | 194 |
| http_server 1.3.29 | 149 |
| http_server 1.3.37 | 145 |
| http_server 1.3.34 | 99 |
| http_server 1.3.27 | 93 |
| http_server 1.3.39 | 69 |
| http_server 1.3.26 | 65 |
| http_server 1.3.23 | 49 |
| http_server 1.2.6 | 34 |