← All CVEs

CVE-2009-2699

high · 7.5

The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.

7.5
CVSS
14.2%
EPSS (exploit prob.)
96th
EPSS percentile
2009-10-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-667

Affected products

VendorProductAffected versions
apachehttp_server>= 2.2.0, < 2.2.14
apacheportable_runtime< 1.3.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-2699