Portable Runtime

Vendor:

First CVE: Aug 6, 2009 · Active for 16 years

9
Total CVEs
More Total CVEs than 86% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Portable Runtime over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2009
16 years ago
Most Recent CVE
Aug 26, 2024
697 days ago

CVE Severity & Scoring

Portable Runtime9 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local3 (33.3%)
Network3 (33.3%)
Unknown3 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (66.7%)
High0 (0.0%)
Unknown3 (33.3%)
User Interaction
None6 (66.7%)
Unknown3 (33.3%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None3 (33.3%)
Unknown3 (33.3%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allo
Feb 10, 20125.051NOYES
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, a
May 16, 20114.343NOYES
Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a den
Aug 6, 200910.038NONO
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apac
Jan 31, 20239.831NONO
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.
Jan 31, 20239.830NONO
The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14
Oct 13, 20097.530NONO
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward
Aug 23, 20217.125NONO
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be acces
Oct 24, 20177.124NONO
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive ap
Aug 26, 20245.519NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Portable Runtime

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.7.028.41.3%00
1.4.415.043.4%01
1.4.315.043.4%01
1.4.215.043.4%01
1.4.115.043.4%01
1.4.015.043.4%01
1.3.915.043.4%01
1.3.827.528.6%01
1.3.727.528.6%01
1.3.6-dev27.528.6%01
1.3.627.528.6%01
1.3.527.528.6%01
1.3.4-dev27.528.6%01
1.3.427.528.6%01
1.3.327.528.6%01
1.3.227.528.6%01
1.3.1315.043.4%01
1.3.1215.043.4%01
1.3.1115.043.4%01
1.3.1015.043.4%01