dena records
21 published records for vendor dena.
Researcher profile
- Entered KEV
- 1 · 4.8%
- Weaponized
- 1 · 4.8%
- Pre-auth RCE
- 3
- With a fix record
- 28.6%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-617 Reachable Assertion2
- CWE-20 Improper Input Validation2
- CWE-284 Improper Access Control1
- CWE-295 Improper Certificate Validation1
- CWE-347 Improper Verification of Cryptographic Signature1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
40Plan | CVE-2018-0608No exploit | Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via undena · h2o · CWE-119 | Critical9.8 | — | 3.8% | Jun 26, 2018 |
39Monitor | CVE-2024-45402No exploit | Picotls is a TLS protocol library that allows users select different crypto backends based on their use case.dena · picotls · CWE-415 | Critical9.8 | — | 0.5% | Oct 11, 2024 |
37Monitor | CVE-2016-7835No exploit | Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys anddena · h2o · CWE-416 | Critical9.1 | — | 2.2% | Jun 9, 2017 |
32Monitor | CVE-2023-30847No exploit | H2O vulnerable to read from uninitialized pointer in the reverse proxy handlerdena · h2o · CWE-824 | High8.2 | — | 0.9% | Apr 27, 2023 |
31Monitor | CVE-2016-4817No exploit | lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to causdena · h2o | High7.5 | — | 4.4% | Jun 18, 2016 |
31Monitor | CVE-2017-10908No exploit | H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.dena · h2o · CWE-20 | High7.5 | — | 3.6% | Dec 22, 2017 |
31Monitor | CVE-2017-10868No exploit | H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.dena · h2o · CWE-20 | High7.5 | — | 3.5% | Dec 22, 2017 |
31Monitor | CVE-2017-10869No exploit | Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.dena · h2o · CWE-119 | High7.5 | — | 2.7% | Dec 22, 2017 |
31Monitor | CVE-2016-4864No exploit | H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specdena · h2o · CWE-134 | High7.5 | — | 1.8% | May 12, 2017 |
30Monitor | CVE-2023-50247No exploit | h2o QUIC state exhaustion DoSdena · h2o · CWE-770 | High7.5 | — | 0.9% | Dec 12, 2023 |
30Monitor | CVE-2024-45403No exploit | H2O assertion failure when HTTP/3 requests are cancelleddena · h2o · CWE-617 | High7.5 | — | 0.7% | Oct 11, 2024 |
30Monitor | CVE-2024-45396No exploit | Quicly assertion failuresdena · quicly · CWE-617 | High7.5 | — | 0.6% | Oct 11, 2024 |
30Monitor | CVE-2024-45397No exploit | H2O alllows bypassing address-based access control with 0-RTTdena · h2o · CWE-284 | High7.5 | — | 0.4% | Oct 11, 2024 |
27Monitor | CVE-2017-10872No exploit | H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.dena · h2o · CWE-118 | Medium6.5 | — | 1.9% | Dec 22, 2017 |
26Monitor | CVE-2023-41337No exploit | h2o vulnerable to TLS session resumption misdirectiondena · h2o · CWE-347 | Medium6.7 | — | 0.2% | Dec 12, 2023 |
24Monitor | CVE-2021-43848Proof of concept | Unititialized memory access in h2odena · h2o · CWE-908 | Medium5.9 | — | 2.7% | Feb 1, 2022 |
17Monitor | CVE-2015-5638No exploit | Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote atdena · h20 · CWE-22 | Medium4.3 | — | 1.7% | Sep 20, 2015 |
17Monitor | CVE-2024-25622No exploit | H2O ignores headers configuration directivesdena · h2o · CWE-670 | Medium4.3 | — | 0.5% | Oct 11, 2024 |
14Monitor | CVE-2016-1133No exploit | CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remotedena · h2o | Low3.7 | — | 1.5% | Jan 16, 2016 |
14Monitor | CVE-2022-29482No exploit | 'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may allow an attacker to edena · mobaoku-auction \& flea market · CWE-295 | Low3.7 | — | 0.4% | Jun 14, 2022 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2018-060840Plan
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via un
CriticalCVSS 9.8No exploitEPSS 4%dena · h2oJun 26, 2018
- CVE-2024-4540239Monitor
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case.
CriticalCVSS 9.8No exploitEPSS 0%dena · picotlsOct 11, 2024
- CVE-2016-783537Monitor
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and
CriticalCVSS 9.1No exploitEPSS 2%dena · h2oJun 9, 2017
- CVE-2023-3084732Monitor
H2O vulnerable to read from uninitialized pointer in the reverse proxy handler
HighCVSS 8.2No exploitEPSS 1%dena · h2oApr 27, 2023
- CVE-2016-481731Monitor
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to caus
HighCVSS 7.5No exploitEPSS 4%dena · h2oJun 18, 2016
- CVE-2017-1090831Monitor
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
HighCVSS 7.5No exploitEPSS 4%dena · h2oDec 22, 2017
- CVE-2017-1086831Monitor
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
HighCVSS 7.5No exploitEPSS 4%dena · h2oDec 22, 2017
- CVE-2017-1086931Monitor
Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.
HighCVSS 7.5No exploitEPSS 3%dena · h2oDec 22, 2017
- CVE-2016-486431Monitor
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string spec
HighCVSS 7.5No exploitEPSS 2%dena · h2oMay 12, 2017
- CVE-2023-5024730Monitor
h2o QUIC state exhaustion DoS
HighCVSS 7.5No exploitEPSS 1%dena · h2oDec 12, 2023
- CVE-2024-4540330Monitor
H2O assertion failure when HTTP/3 requests are cancelled
HighCVSS 7.5No exploitEPSS 1%dena · h2oOct 11, 2024
- CVE-2024-4539630Monitor
Quicly assertion failures
HighCVSS 7.5No exploitEPSS 1%dena · quiclyOct 11, 2024
- CVE-2024-4539730Monitor
H2O alllows bypassing address-based access control with 0-RTT
HighCVSS 7.5No exploitEPSS 0%dena · h2oOct 11, 2024
- CVE-2017-1087227Monitor
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.
MediumCVSS 6.5No exploitEPSS 2%dena · h2oDec 22, 2017
- CVE-2023-4133726Monitor
h2o vulnerable to TLS session resumption misdirection
MediumCVSS 6.7No exploitEPSS 0%dena · h2oDec 12, 2023
- CVE-2021-4384824Monitor
Unititialized memory access in h2o
MediumCVSS 5.9Proof of conceptEPSS 3%dena · h2oFeb 1, 2022
- CVE-2015-563817Monitor
Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote at
MediumCVSS 4.3No exploitEPSS 2%dena · h20Sep 20, 2015
- CVE-2024-2562217Monitor
H2O ignores headers configuration directives
MediumCVSS 4.3No exploitEPSS 0%dena · h2oOct 11, 2024
- CVE-2016-113314Monitor
CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote
LowCVSS 3.7No exploitEPSS 1%dena · h2oJan 16, 2016
- CVE-2022-2948214Monitor
'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may allow an attacker to e
LowCVSS 3.7No exploitEPSS 0%dena · mobaoku-auction \& flea marketJun 14, 2022