Back

CVE-1999-1199

Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.

Published: Aug 7, 1998 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
apache http_server *

GitHub Security Advisory GHSA-chf5-9cm8-37j4

Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service ...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 5.12%

Top 10% most likely to be exploited

Threat Score 41.5 / 100

Data Sources

NVD EPSS GitHub