<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:26:56.691088+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:7711</id>
    <title>ALSA-2023:7711 — Moderate: apr security update</title>
    <updated>2026-10-03T13:26:57.029497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: apr, AlmaLinux:9: apr-devel</p>
<p>The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and other projects. It provides a free library of C data structures and routines.</p>
<p>Security Fix(es):</p>
<p>* apr: integer overflow/wraparound in apr_encode (CVE-2022-24963)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:7711"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00850</id>
    <title>bdu:2024-00850</title>
    <updated>2026-10-03T13:26:57.029561+00:00</updated>
    <content>bdu:2024-00850</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-24963</id>
    <title>Withdrawn: BELL-CVE-2022-24963 — CVE-2022-24963 does not affect BellSoft software</title>
    <updated>2026-10-03T13:26:57.029580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-24963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apr-2022-24963</id>
    <title>BIT-apr-2022-24963 — Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions</title>
    <updated>2026-10-03T13:26:57.029596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apr</p>
<p>Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime (APR) version 1.7.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apr-2022-24963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2023-57672</id>
    <title>cnvd-2023-57672</title>
    <updated>2026-10-03T13:26:57.029627+00:00</updated>
    <content>cnvd-2023-57672</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2023-57672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-225624</id>
    <title>EUVD-2026-225624</title>
    <updated>2026-10-03T13:26:57.029640+00:00</updated>
    <content>EUVD-2026-225624</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-225624"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24963</id>
    <title>fkie_cve-2022-24963</title>
    <updated>2026-10-03T13:26:57.029651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime (APR) version 1.7.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6rr3-mpxq-hv4x</id>
    <title>GHSA-6rr3-mpxq-hv4x</title>
    <updated>2026-10-03T13:26:57.029672+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6rr3-mpxq-hv4x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24963</id>
    <title>gsd-2022-24963</title>
    <updated>2026-10-03T13:26:57.029685+00:00</updated>
    <content>gsd-2022-24963</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-24963</id>
    <title>msrc_CVE-2022-24963 — Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions</title>
    <updated>2026-10-03T13:26:57.029696+00:00</updated>
    <content>msrc_CVE-2022-24963</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-24963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1095</id>
    <title>OESA-2023-1095 — apr security update</title>
    <updated>2026-10-03T13:26:57.029711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: apr</p>
<p>The mission of the Apache Portable Runtime (APR) project is to create and maintain software libraries that provide a predictable and consistent interface to underlying platform-specific implementations. The primary goal is to provide an API to which software developers may code and be assured of predictable if not identical behaviour regardless of the platform on which their software is built, relieving them of the need to code special-case conditions to work around or take advantage of platform-specific deficiencies or features.

Security Fix(es):

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.(CVE-2022-24963)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12655-1</id>
    <title>openSUSE-SU-2024:12655-1 — apr-devel-1.7.2-1.1 on GA media</title>
    <updated>2026-10-03T13:26:57.029735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apr-devel-1.7.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12655-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:4629</id>
    <title>RHSA-2023:4629 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 security update</title>
    <updated>2026-10-03T13:26:57.029752+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apr: integer overflow/wraparound in apr_encode httpd: mod_proxy_ajp: Possible request smuggling httpd: mod_proxy: HTTP response splitting mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass modsecurity: lacking the complete content in FILES_TMP_CONTENT leads to web application firewall bypass httpd: mod_proxy_uwsgi HTTP response splitting curl: use after free in SSH sha256 fingerprint check curl: IDN wildcard match may lead to Improper Cerificate Validation curl: more POST-after-PUT confusion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:4629"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24963</id>
    <title>UBUNTU-CVE-2022-24963</title>
    <updated>2026-10-03T13:26:57.029784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: apr</p>
<p>Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0245</id>
    <title>WID-SEC-W-2023-0245 — Apache Portable Runtime (APR): Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:26:57.029801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Apache Portable Runtime (APR) ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0245"/>
  </entry>
</feed>
