<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:48:54 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:7711 — Moderate: apr security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:7711</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: apr, AlmaLinux:9: apr-devel&lt;/p&gt;
&lt;p&gt;The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and other projects. It provides a free library of C data structures and routines.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* apr: integer overflow/wraparound in apr_encode (CVE-2022-24963)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: apr, AlmaLinux:9: apr-devel&lt;/p&gt;
&lt;p&gt;The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and other projects. It provides a free library of C data structures and routines.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* apr: integer overflow/wraparound in apr_encode (CVE-2022-24963)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:7711</guid>
    </item>
    <item>
      <title>bdu:2024-00850</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00850</link>
      <description>bdu:2024-00850</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00850</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-24963 — CVE-2022-24963 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-24963</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-24963</guid>
    </item>
    <item>
      <title>BIT-apr-2022-24963 — Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apr-2022-24963</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apr&lt;/p&gt;
&lt;p&gt;Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime (APR) version 1.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apr&lt;/p&gt;
&lt;p&gt;Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime (APR) version 1.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apr-2022-24963</guid>
    </item>
    <item>
      <title>cnvd-2023-57672</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-57672</link>
      <description>cnvd-2023-57672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-57672</guid>
    </item>
    <item>
      <title>EUVD-2026-225624</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-225624</link>
      <description>EUVD-2026-225624</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-225624</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24963</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24963</link>
      <description>&lt;p&gt;Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime (APR) version 1.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime (APR) version 1.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24963</guid>
    </item>
    <item>
      <title>GHSA-6rr3-mpxq-hv4x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6rr3-mpxq-hv4x</link>
      <description>&lt;p&gt;Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6rr3-mpxq-hv4x</guid>
    </item>
    <item>
      <title>gsd-2022-24963</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24963</link>
      <description>gsd-2022-24963</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24963</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-24963 — Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-24963</link>
      <description>msrc_CVE-2022-24963</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-24963</guid>
    </item>
    <item>
      <title>OESA-2023-1095 — apr security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1095</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: apr&lt;/p&gt;
&lt;p&gt;The mission of the Apache Portable Runtime (APR) project is to create and maintain software libraries that provide a predictable and consistent interface to underlying platform-specific implementations. The primary goal is to provide an API to which software developers may code and be assured of predictable if not identical behaviour regardless of the platform on which their software is built, relieving them of the need to code special-case conditions to work around or take advantage of platform-specific deficiencies or features.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.(CVE-2022-24963)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: apr&lt;/p&gt;
&lt;p&gt;The mission of the Apache Portable Runtime (APR) project is to create and maintain software libraries that provide a predictable and consistent interface to underlying platform-specific implementations. The primary goal is to provide an API to which software developers may code and be assured of predictable if not identical behaviour regardless of the platform on which their software is built, relieving them of the need to code special-case conditions to work around or take advantage of platform-specific deficiencies or features.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.(CVE-2022-24963)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1095</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12655-1 — apr-devel-1.7.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12655-1</link>
      <description>&lt;p&gt;apr-devel-1.7.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apr-devel-1.7.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12655-1</guid>
    </item>
    <item>
      <title>RHSA-2023:4629 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4629</link>
      <description>&lt;p&gt;apr: integer overflow/wraparound in apr_encode httpd: mod_proxy_ajp: Possible request smuggling httpd: mod_proxy: HTTP response splitting mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass modsecurity: lacking the complete content in FILES_TMP_CONTENT leads to web application firewall bypass httpd: mod_proxy_uwsgi HTTP response splitting curl: use after free in SSH sha256 fingerprint check curl: IDN wildcard match may lead to Improper Cerificate Validation curl: more POST-after-PUT confusion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apr: integer overflow/wraparound in apr_encode httpd: mod_proxy_ajp: Possible request smuggling httpd: mod_proxy: HTTP response splitting mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass modsecurity: lacking the complete content in FILES_TMP_CONTENT leads to web application firewall bypass httpd: mod_proxy_uwsgi HTTP response splitting curl: use after free in SSH sha256 fingerprint check curl: IDN wildcard match may lead to Improper Cerificate Validation curl: more POST-after-PUT confusion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4629</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-24963</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24963</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: apr&lt;/p&gt;
&lt;p&gt;Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: apr&lt;/p&gt;
&lt;p&gt;Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24963</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0245 — Apache Portable Runtime (APR): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0245</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Apache Portable Runtime (APR) ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Apache Portable Runtime (APR) ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0245</guid>
    </item>
  </channel>
</rss>
