Skip to main content

Vendor/product archive

apache / portable_runtime CVEs

Beta · best-effort

9 CVEs tagged to apache / portable_runtime3 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-49582

Published Aug 26, 2024

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24963

Published Jan 31, 2023

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12613

Published Oct 24, 2017

When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be acce…

CVSS 7.1 · High

CVE-2012-0840

Published Feb 10, 2012

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which all…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2412

Published Aug 6, 2009

Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a de…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1