CVE-2007-6750
Last modified
CVE-2007-6750 is a vulnerability of currently unknown severity. The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.. EPSS estimates a 71.63% chance of exploitation in the next 30 days.
Description
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Http Server | <= 2.2.14 | — |
| Apache | Http Server | 1.0 | — |
| Apache | Http Server | 1.0.2 | — |
| Apache | Http Server | 1.0.3 | — |
| Apache | Http Server | 1.0.5 | — |
| Apache | Http Server | 1.1 | — |
| Apache | Http Server | 1.1.1 | — |
| Apache | Http Server | 1.2 | — |
| Apache | Http Server | 1.2.4 | — |
| Apache | Http Server | 1.2.5 | — |
| Apache | Http Server | 1.2.6 | — |
| Apache | Http Server | 1.2.9 | — |
| Apache | Http Server | 1.3 | — |
| Apache | Http Server | 1.3.0 | — |
| Apache | Http Server | 1.3.1 | — |
| Apache | Http Server | 1.3.1.1 | — |
| Apache | Http Server | 1.3.2 | — |
| Apache | Http Server | 1.3.3 | — |
| Apache | Http Server | 1.3.4 | — |
| Apache | Http Server | 1.3.5 | — |
| Apache | Http Server | 1.3.6 | — |
| Apache | Http Server | 1.3.7 | — |
| Apache | Http Server | 1.3.8 | — |
| Apache | Http Server | 1.3.9 | — |
| Apache | Http Server | 1.3.10 | — |
| Apache | Http Server | 1.3.11 | — |
| Apache | Http Server | 1.3.12 | — |
| Apache | Http Server | 1.3.13 | — |
| Apache | Http Server | 1.3.14 | — |
| Apache | Http Server | 1.3.15 | — |
| Apache | Http Server | 1.3.16 | — |
| Apache | Http Server | 1.3.17 | — |
| Apache | Http Server | 1.3.18 | — |
| Apache | Http Server | 1.3.19 | — |
| Apache | Http Server | 1.3.20 | — |
| Apache | Http Server | 1.3.22 | — |
| Apache | Http Server | 1.3.23 | — |
| Apache | Http Server | 1.3.24 | — |
| Apache | Http Server | 1.3.25 | — |
| Apache | Http Server | 1.3.26 | — |
| Apache | Http Server | 1.3.27 | — |
| Apache | Http Server | 1.3.28 | — |
| Apache | Http Server | 1.3.29 | — |
| Apache | Http Server | 1.3.30 | — |
| Apache | Http Server | 1.3.31 | — |
| Apache | Http Server | 1.3.32 | — |
| Apache | Http Server | 1.3.33 | — |
| Apache | Http Server | 1.3.34 | — |
| Apache | Http Server | 1.3.35 | — |
| Apache | Http Server | 1.3.36 | — |
Showing 50 of 115 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6750?
How severe is CVE-2007-6750?
How do I fix CVE-2007-6750?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6744Flexera Macrovision InstallShield before 2008 sends a digita…
- CVE-2007-6745clamav 0.91.2 suffers from a floating point exception when u…9.8
- CVE-2007-6746telepathy-idle before 0.1.15 does not verify (1) that the is…
- CVE-2007-6747Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-6748Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-6749Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-6751Cross-site scripting (XSS) vulnerability in the MailForm plu…
- CVE-2007-6752Cross-site request forgery (CSRF) vulnerability in Drupal 7.…
- CVE-2007-6753Untrusted search path vulnerability in Shell32.dll in Micros…
- CVE-2007-6754The ipalloc function in libc/stdlib/malloc.c in jemalloc in …
- CVE-2007-6755The NIST SP 800-90A default statement of the Dual Elliptic C…
- CVE-2007-6756ZOLL Defibrillator / Monitor M Series, E Series, and R Serie…
Are you affected by CVE-2007-6750?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
