Total vulnerabilities in the database
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
Software | From | Fixed in |
---|---|---|
fedoraproject / fedora | 34 | 34.x |
fedoraproject / fedora | 35 | 35.x |
debian / debian_linux | 9.0 | 9.0.x |
debian / debian_linux | 10.0 | 10.0.x |
debian / debian_linux | 11.0 | 11.0.x |
oracle / http_server | 12.2.1.3.0 | 12.2.1.3.0.x |
oracle / instantis_enterprisetrack | 17.1 | 17.1.x |
oracle / instantis_enterprisetrack | 17.2 | 17.2.x |
oracle / instantis_enterprisetrack | 17.3 | 17.3.x |
oracle / http_server | 12.2.1.4.0 | 12.2.1.4.0.x |
oracle / zfs_storage_appliance_kit | 8.8 | 8.8.x |
siemens / sinema_server | 14.0 | 14.0.x |
siemens / sinec_nms | - | - |
apache / http_server | - | 2.4.49 |