Apache / Apr-Util
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-49506 | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack | HIGH | 7.5 | Aug 6, 2026 |
| CVE-2026-32327 | Apache Portable Runtime Utility: apr-util XML stack recursion crash | CRITICAL | 9.1 | Aug 6, 2026 |
| CVE-2026-34191 | Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle | CRITICAL | 9.1 | Aug 6, 2026 |
| CVE-2026-34501 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client | HIGH | 7.5 | Aug 6, 2026 |
| CVE-2026-34502 | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client | HIGH | 7.5 | Aug 6, 2026 |
| CVE-2011-1928 | apr: DoS flaw in apr_fnmatch() due to fix for CVE-2011-0419 | MEDIUM | 4.3 | May 24, 2011 |
| CVE-2010-1623 | apr-util: high memory consumption in apr_brigade_split_line() | MEDIUM | 5.0 | Oct 4, 2010 |
| CVE-2009-2412 | apr-util: Integer overflows in memory pool (apr) and relocatable memory (apr-util) management | HIGH | 10.0 | Aug 6, 2009 |
| CVE-2009-1956 | apr-util single NULL byte buffer overflow | MEDIUM | 6.4 | Jun 6, 2009 |
| CVE-2009-1955 | apr-util billion laughs attack | HIGH | 7.5 | Jun 6, 2009 |
| CVE-2009-0023 | apr-util heap buffer underwrite | MEDIUM | 4.3 | Jun 6, 2009 |
Showing 1 to 11 of 11 CVEs