More than two years after the disclosure of the HeartBleed bug, 200,000 services are still affected. Most of the vulnerable installations are located in the United States (42,032), followed by Korea (15,380) and China (14,116) The most affected product is Apache HTTP Server (httpd), in particular versions 2.2.22 and 2.15. The bug is a serious flaw in the popular OpenSSL library that allows an attacker to reveal up to 64kB of memory to a connected client or server.”]
Source: https://securityaffairs.co/wordpress/55594/hacking/heartbleed-vulnerability-devices.html

