VYPR

Libapreq2

by Apache

CVEs (4)

  • CVE-2022-22728HigAug 25, 2022
    risk 0.49cvss 7.5epss 0.05

    A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

  • CVE-2019-12412HigNov 19, 2020
    risk 0.49cvss 7.5epss 0.04

    A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

  • CVE-2009-0023Jun 8, 2009
    risk 0.00cvss epss 0.09

    The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive…

  • CVE-2006-0042Feb 18, 2006
    risk 0.00cvss epss 0.06

    Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers to cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational…