threat
engine
.sh
Back
·
··:··
Home
/
Product
/
apache portable runtime
Product
apache portable runtime
9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-49582
>= 0.9.0 and < 1.7.5
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared m
5.5
MEDIUM
CVE-2022-28331
<= 1.7.0
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This
9.8
CRITICAL
CVE-2022-24963
all versions
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write
9.8
CRITICAL
CVE-2021-35940
all versions
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-1261
7.1
HIGH
CVE-2017-12613
< 1.7.0
When apr_time_exp
() or apr_os_exp_time
() functions are invoked with an invalid month field value in Apache Portable Runtime APR
7.1
HIGH
CVE-2012-0840
<= 1.4.5
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability
CVE-2011-0419
< 1.4.3
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before
CVE-2009-2699
< 1.3.9
The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.
7.5
HIGH
CVE-2009-2412
all versions
Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin