VULNERABILITY INTELLIGENCE
CVE-2012-0840
CVSS score5 MEDIUM
EPSS probability42.14%
CISA KEVNot currently listed
Published2012-02-10
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Description
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
Weakness classification
- CWE-20: Improper Input Validation