CVE-2009-3094
lowCVSS v3 Base Score
2.6
AV:N/AC:H/Au:N/C:N/I:N/A:P
EPSS Score
2.8%
Exploitation probability in 30 days
Top 14% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Confidentiality
None
Integrity
None
Availability
P
Published: September 8, 2009 (6092 days ago)
Last Modified: April 23, 2026
Vendor: Apache
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
CWE
CWE-476Affected Products
apache http serverfedoraproject fedoradebian debian linux