A crafted request uri-path can cause modproxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
A flaw was discovered where the XMLRPC client implementation in Apache XMLRPC, performed deserialization of the server-side exception serialized in the faultCause attribute of XMLRPC error response messages. A malicious or compromised XMLRPC server could possibly use this flaw to execute arbitrary code with the privileges of an application using the Apache XMLRPC client library.
apachemodphp. Multiple issues were addressed by updating to PHP version 7.3.11.
Fixed bug (Out-of-bounds read in iconv.c:phpiconvmimedecode() due to integer overflow) (CVE-2019-11039).
Fixed bug (heap-buffer-overflow on phpjpgget16) (CVE-2019-11040).
Fixed bug (Heap-buffer-overflow in estrndup via exifprocessIFDTAG) (CVE-2019-11036).
Fixed bug (Heap-buffer-overflow in exifiifaddvalue). (CVE-2019-11035)
Fixed bug (Heap-buffer-overflow in phpifdget32s). (CVE-2019-11034)