Portable Runtime
Vendor:
First CVE: Aug 6, 2009 · Active for 16 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Portable Runtime over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2009
16 years ago
Most Recent CVE
Aug 26, 2024
697 days ago
CVE Severity & Scoring
Portable Runtime9 CVEs
33%
44%
22%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (33.3%)
Network3 (33.3%)
Unknown3 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (66.7%)
High0 (0.0%)
Unknown3 (33.3%)
User Interaction
None6 (66.7%)
Unknown3 (33.3%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None3 (33.3%)
Unknown3 (33.3%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0840MEDIUM tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allo | Feb 10, 2012 | 5.0 | 51 | NO | YES |
CVE-2011-0419MEDIUM Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, a | May 16, 2011 | 4.3 | 43 | NO | YES |
CVE-2009-2412HIGH Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a den | Aug 6, 2009 | 10.0 | 38 | NO | NO |
CVE-2022-24963CRITICAL Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer.
This issue affects Apac | Jan 31, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-28331CRITICAL On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow. | Jan 31, 2023 | 9.8 | 30 | NO | NO |
CVE-2009-2699HIGH The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 | Oct 13, 2009 | 7.5 | 30 | NO | NO |
CVE-2021-35940HIGH An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward | Aug 23, 2021 | 7.1 | 25 | NO | NO |
CVE-2017-12613HIGH When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be acces | Oct 24, 2017 | 7.1 | 24 | NO | NO |
CVE-2023-49582MEDIUM Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive ap | Aug 26, 2024 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Portable Runtime
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.7.0 | 2 | 8.4 | 1.3% | 0 | 0 |
| 1.4.4 | 1 | 5.0 | 43.4% | 0 | 1 |
| 1.4.3 | 1 | 5.0 | 43.4% | 0 | 1 |
| 1.4.2 | 1 | 5.0 | 43.4% | 0 | 1 |
| 1.4.1 | 1 | 5.0 | 43.4% | 0 | 1 |
| 1.4.0 | 1 | 5.0 | 43.4% | 0 | 1 |
| 1.3.9 | 1 | 5.0 | 43.4% | 0 | 1 |
| 1.3.8 | 2 | 7.5 | 28.6% | 0 | 1 |
| 1.3.7 | 2 | 7.5 | 28.6% | 0 | 1 |
| 1.3.6-dev | 2 | 7.5 | 28.6% | 0 | 1 |
| 1.3.6 | 2 | 7.5 | 28.6% | 0 | 1 |
| 1.3.5 | 2 | 7.5 | 28.6% | 0 | 1 |
| 1.3.4-dev | 2 | 7.5 | 28.6% | 0 | 1 |
| 1.3.4 | 2 | 7.5 | 28.6% | 0 | 1 |
| 1.3.3 | 2 | 7.5 | 28.6% | 0 | 1 |
| 1.3.2 | 2 | 7.5 | 28.6% | 0 | 1 |
| 1.3.13 | 1 | 5.0 | 43.4% | 0 | 1 |
| 1.3.12 | 1 | 5.0 | 43.4% | 0 | 1 |
| 1.3.11 | 1 | 5.0 | 43.4% | 0 | 1 |
| 1.3.10 | 1 | 5.0 | 43.4% | 0 | 1 |