Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 32

Количество 32

rocky логотип

RLSA-2026:66392

10 дней назад

Moderate: apr-util security update

EPSS: Низкий
rocky логотип

RLSA-2026:66341

10 дней назад

Moderate: apr-util security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-66392-0

12 дней назад

ELSA-2026-66392-0: apr-util security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-66341-0

12 дней назад

ELSA-2026-66341-0: apr-util security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21672-1

25 дней назад

Security update for apr-util

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3938-1

19 дней назад

Security update for apr-util

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3937-1

19 дней назад

Security update for apr-util

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3905-1

21 день назад

Security update for libapr-util1

EPSS: Низкий
ubuntu логотип

CVE-2025-49506

около 2 месяцев назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-49506

около 2 месяцев назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2025-49506

около 2 месяцев назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-49506

около 1 месяца назад

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-49506

около 2 месяцев назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-73wm-47mq-62r5

около 2 месяцев назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-32327

около 2 месяцев назад

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-32327

около 2 месяцев назад

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2026-32327

около 2 месяцев назад

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2026-32327

около 2 месяцев назад

Apache Portable Runtime Utility: apr-util XML stack recursion crash

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-32327

около 2 месяцев назад

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-qfxp-vc85-jg39

около 2 месяцев назад

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:66392

Moderate: apr-util security update

10 дней назад
rocky логотип
RLSA-2026:66341

Moderate: apr-util security update

10 дней назад
oracle-oval логотип
ELSA-2026-66392-0

ELSA-2026-66392-0: apr-util security update (MODERATE)

12 дней назад
oracle-oval логотип
ELSA-2026-66341-0

ELSA-2026-66341-0: apr-util security update (MODERATE)

12 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21672-1

Security update for apr-util

25 дней назад
suse-cvrf логотип
SUSE-SU-2026:3938-1

Security update for apr-util

19 дней назад
suse-cvrf логотип
SUSE-SU-2026:3937-1

Security update for apr-util

19 дней назад
suse-cvrf логотип
SUSE-SU-2026:3905-1

Security update for libapr-util1

21 день назад
ubuntu логотип
CVE-2025-49506

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2025-49506

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-49506

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2025-49506

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-49506

APR-util versions 1.6.3 (and earlier) function apr_password_validate() ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-73wm-47mq-62r5

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 6.2
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-32327

Apache Portable Runtime Utility: apr-util XML stack recursion crash

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ...

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-qfxp-vc85-jg39

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу