peter bassill · operator
$ cve CVE-2012-0031 JSON

CVE-2012-0031 EXPLOIT

4.6
MEDIUM · CVSS 2.0 · EPSS 2.8% (pctl 86)

Patch early

A public exploit exists.

Description

scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.

Scoring

CVSS4.6 (MEDIUM, v2.0)
VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS2.8% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published2012-01-18
Last modified2026-06-16

Affected (13)

VendorProduct
apachehttp server
debiandebian linux
opensuseopensuse
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux workstation
redhatjboss enterprise web server
redhatstorage
suselinux enterprise server
suselinux enterprise software development kit

Public exploits

SourceTitleDate
exploit-dbApache 2.2 - Scoreboard Invalid Free On Shutdown2012-01-11

References

→ the Explorer  ·  watch your stack  ·  NVD