Vulnerabilities > CVE-2022-28331 - Unspecified vulnerability in Apache Portable Runtime

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
apache
critical

Summary

On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.

Vulnerable Configurations

Part Description Count
Application
Apache
71
OS
Microsoft
1