Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2022-22721

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

  • Published: Mar 14, 2022
  • Updated: Apr 14, 2023
  • CVE: CVE-2022-22721
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.1
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 5.8
  • AV:N/AC:M/Au:N/C:N/I:P/A:P

CWEs:

Software From Fixed in
apache / http_server - 2.4.52.x
fedoraproject / fedora 34 34.x
fedoraproject / fedora 35 35.x
fedoraproject / fedora 36 36.x
debian / debian_linux 9.0 9.0.x
oracle / http_server 12.2.1.3.0 12.2.1.3.0.x
oracle / http_server 12.2.1.4.0 12.2.1.4.0.x
oracle / enterprise_manager_ops_center 12.4.0.0 12.4.0.0.x
oracle / zfs_storage_appliance_kit 8.8 8.8.x
apple / mac_os_x 10.15 10.15.7
apple / mac_os_x 10.15.7-security_update_2020-001 10.15.7-security_update_2020-001.x
apple / mac_os_x 10.15.7-security_update_2021-001 10.15.7-security_update_2021-001.x
apple / mac_os_x 10.15.7-security_update_2021-002 10.15.7-security_update_2021-002.x
apple / mac_os_x 10.15.7-security_update_2021-003 10.15.7-security_update_2021-003.x
apple / mac_os_x 10.15.7-security_update_2021-004 10.15.7-security_update_2021-004.x
apple / mac_os_x 10.15.7-security_update_2021-005 10.15.7-security_update_2021-005.x
apple / mac_os_x 10.15.7-security_update_2021-006 10.15.7-security_update_2021-006.x
apple / mac_os_x 10.15.7-security_update_2021-008 10.15.7-security_update_2021-008.x
apple / mac_os_x 10.15.7-security_update_2021-007 10.15.7-security_update_2021-007.x
apple / mac_os_x 10.15.7-security_update_2022-002 10.15.7-security_update_2022-002.x
apple / mac_os_x 10.15.7-security_update_2022-001 10.15.7-security_update_2022-001.x
apple / macos 11.0 11.6.6
apple / mac_os_x 10.15.7-security_update_2022-003 10.15.7-security_update_2022-003.x
apple / macos 12.0 12.4