VULNERABILITY INTELLIGENCE

CVE-2012-0840

CVSS score5 MEDIUM
EPSS probability42.14%
CISA KEVNot currently listed
Published2012-02-10
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:N/I:N/A:P

Description

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Weakness classification

  • CWE-20: Improper Input Validation

Primary references