Skip to content
Noroxi

dena records

21 published records for vendor dena.

Researcher profile

Entered KEV
1 · 4.8%
Weaponized
1 · 4.8%
Pre-auth RCE
3
With a fix record
28.6%
Median publish → KEV
0 days

All records

21 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via un

    CriticalCVSS 9.8No exploitEPSS 4%

    dena · h2oJun 26, 2018

  • Picotls is a TLS protocol library that allows users select different crypto backends based on their use case.

    CriticalCVSS 9.8No exploitEPSS 0%

    dena · picotlsOct 11, 2024

  • CVE-2016-7835
    37Monitor

    Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and

    CriticalCVSS 9.1No exploitEPSS 2%

    dena · h2oJun 9, 2017

  • H2O vulnerable to read from uninitialized pointer in the reverse proxy handler

    HighCVSS 8.2No exploitEPSS 1%

    dena · h2oApr 27, 2023

  • CVE-2016-4817
    31Monitor

    lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to caus

    HighCVSS 7.5No exploitEPSS 4%

    dena · h2oJun 18, 2016

  • H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.

    HighCVSS 7.5No exploitEPSS 4%

    dena · h2oDec 22, 2017

  • H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.

    HighCVSS 7.5No exploitEPSS 4%

    dena · h2oDec 22, 2017

  • Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.

    HighCVSS 7.5No exploitEPSS 3%

    dena · h2oDec 22, 2017

  • CVE-2016-4864
    31Monitor

    H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string spec

    HighCVSS 7.5No exploitEPSS 2%

    dena · h2oMay 12, 2017

  • h2o QUIC state exhaustion DoS

    HighCVSS 7.5No exploitEPSS 1%

    dena · h2oDec 12, 2023

  • H2O assertion failure when HTTP/3 requests are cancelled

    HighCVSS 7.5No exploitEPSS 1%

    dena · h2oOct 11, 2024

  • Quicly assertion failures

    HighCVSS 7.5No exploitEPSS 1%

    dena · quiclyOct 11, 2024

  • H2O alllows bypassing address-based access control with 0-RTT

    HighCVSS 7.5No exploitEPSS 0%

    dena · h2oOct 11, 2024

  • H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.

    MediumCVSS 6.5No exploitEPSS 2%

    dena · h2oDec 22, 2017

  • h2o vulnerable to TLS session resumption misdirection

    MediumCVSS 6.7No exploitEPSS 0%

    dena · h2oDec 12, 2023

  • Unititialized memory access in h2o

    MediumCVSS 5.9Proof of conceptEPSS 3%

    dena · h2oFeb 1, 2022

  • CVE-2015-5638
    17Monitor

    Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote at

    MediumCVSS 4.3No exploitEPSS 2%

    dena · h20Sep 20, 2015

  • H2O ignores headers configuration directives

    MediumCVSS 4.3No exploitEPSS 0%

    dena · h2oOct 11, 2024

  • CVE-2016-1133
    14Monitor

    CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote

    LowCVSS 3.7No exploitEPSS 1%

    dena · h2oJan 16, 2016

  • 'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may allow an attacker to e

    LowCVSS 3.7No exploitEPSS 0%

    dena · mobaoku-auction \& flea marketJun 14, 2022