296,843
Total vulnerabilities in the database
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.
| Software | From | Fixed in | 
|---|---|---|
| apache / http_server | 2.4.0 | 2.4.37.x | 
| debian / debian_linux | 8.0 | 8.0.x | 
| debian / debian_linux | 9.0 | 9.0.x | 
| canonical / ubuntu_linux | 16.04 | 16.04.x | 
| canonical / ubuntu_linux | 14.04 | 14.04.x | 
| canonical / ubuntu_linux | 18.04 | 18.04.x | 
| canonical / ubuntu_linux | 18.10 | 18.10.x | 
| oracle / enterprise_manager_ops_center | 12.3.3 | 12.3.3.x |