cbcvebase.

Apache Apr-Util vulnerabilities

13 known vulnerabilities affecting apache/apr-util.

Total CVEs
13
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2009-1955P3HIGHCVSS 7.5PoCfixed in 1.3.72009-06-08
CVE-2009-1955 [HIGH] CWE-776 CVE-2009-1955: The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFI
nvdosv
CVE-2026-34191P2CRITICALCVSS 9.1≥ 1.6.0, ≤ 1.6.32026-08-06
CVE-2026-34191 [CRITICAL] CWE-89 CVE-2026-34191: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
nvd
CVE-2026-32327P3CRITICALCVSS 9.1fixed in 1.6.42026-08-06
CVE-2026-32327 [CRITICAL] CWE-674 CVE-2026-32327: A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library co A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
nvd
CVE-2009-2412P3CRITICALCVSS 10.0v0.9.1v0.9.2+21 more2009-08-06
CVE-2009-2412 [CRITICAL] CWE-189 CVE-2009-2412: Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Util Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memor
nvdosv
CVE-2026-34502P3HIGHCVSS 7.5≥ 1.3.0, ≤ 1.6.32026-08-06
CVE-2026-34502 [HIGH] CWE-122 CVE-2026-34502: Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This i Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
nvd
CVE-2026-34501P3HIGHCVSS 7.5≥ 1.6.0, < 1.6.42026-08-06
CVE-2026-34501 [HIGH] CWE-122 CVE-2026-34501: Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issu Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
nvd
CVE-2025-49506P3HIGHCVSS 7.5≥ 1.2.0, < 1.6.42026-08-06
CVE-2025-49506 [HIGH] CWE-208 CVE-2025-49506: APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with re APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which
nvd
CVE-2022-25147P4MEDIUMCVSS 6.5≥ 0, < 1.6.1-5+deb11u1≥ 0, < 1.6.3-12023-01-31
CVE-2022-25147 [MEDIUM] CVE-2022-25147: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
osv
CVE-2010-1623P4MEDIUMCVSS 5.0≤ 1.3.9v0.9.1+41 more2010-10-04
CVE-2010-1623 [MEDIUM] CWE-119 CVE-2010-1623: Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable R Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the dest
nvdosv
CVE-2009-1956P4MEDIUMCVSS 6.4≤ 1.3.42009-06-08
CVE-2009-1956 [MEDIUM] CWE-189 CVE-2009-1956: Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian p Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
nvdosv
CVE-2009-0023P4MEDIUMCVSS 4.3≤ 1.3.4v0.9.1+19 more2009-06-08
CVE-2009-0023 [MEDIUM] CWE-119 CVE-2009-0023: The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allo The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 mod
nvdosv
CVE-2011-1928P4MEDIUMCVSS 4.3v1.4.3v1.4.42011-05-24
CVE-2011-1928 [MEDIUM] CVE-2011-1928: The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1 The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ conf
nvd
CVE-2017-12618P4MEDIUMCVSS 4.7≥ 0, < 1.6.1-12017-10-24
CVE-2017-12618 [MEDIUM] CVE-2017-12618: Apache Portable Runtime Utility (APR-util) 1 Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
osv
Apache Apr-Util vulnerabilities | cvebase