CVE-2025-49506
- EPSS 0.29%
- Veröffentlicht 06.08.2026 14:33:12
- Zuletzt bearbeitet 07.08.2026 19:44:52
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt()...
CVE-2026-32327
- EPSS 0.35%
- Veröffentlicht 06.08.2026 14:32:43
- Zuletzt bearbeitet 07.08.2026 19:49:33
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which f...
CVE-2026-34191
- EPSS 0.28%
- Veröffentlicht 06.08.2026 14:32:24
- Zuletzt bearbeitet 07.08.2026 19:49:59
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
CVE-2026-34501
- EPSS 0.36%
- Veröffentlicht 06.08.2026 14:31:48
- Zuletzt bearbeitet 07.08.2026 19:55:22
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
CVE-2026-34502
- EPSS 0.36%
- Veröffentlicht 06.08.2026 14:31:07
- Zuletzt bearbeitet 07.08.2026 19:58:31
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
CVE-2011-1928
- EPSS 10.32%
- Veröffentlicht 24.05.2011 23:55:03
- Zuletzt bearbeitet 16.06.2026 23:30:24
The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecifie...
- EPSS 20.17%
- Veröffentlicht 04.10.2010 21:00:03
- Zuletzt bearbeitet 16.06.2026 23:18:43
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote ...
- EPSS 13.78%
- Veröffentlicht 06.08.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:23
Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code ...
CVE-2009-0023
- EPSS 8.53%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 16.06.2026 23:04:06
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2)...
CVE-2009-1955
- EPSS 52.99%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 16.06.2026 23:08:25
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via ...