Записи dena
21 опубликованных записей вендора dena.
Профиль для исследователя
- Попали в KEV
- 1 · 4,8 %
- С эксплойтом
- 1 · 4,8 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 28,6 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-617 Reachable Assertion2
- CWE-20 Improper Input Validation2
- CWE-284 Improper Access Control1
- CWE-295 Improper Certificate Validation1
- CWE-347 Improper Verification of Cryptographic Signature1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
40В плане | CVE-2018-0608Эксплойта нет | Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via undena · h2o · CWE-119 | Критическая9,8 | — | 3,8 % | 26 июн. 2018 г. |
39Наблюдать | CVE-2024-45402Эксплойта нет | Picotls is a TLS protocol library that allows users select different crypto backends based on their use case.dena · picotls · CWE-415 | Критическая9,8 | — | 0,5 % | 11 окт. 2024 г. |
37Наблюдать | CVE-2016-7835Эксплойта нет | Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys anddena · h2o · CWE-416 | Критическая9,1 | — | 2,2 % | 9 июн. 2017 г. |
32Наблюдать | CVE-2023-30847Эксплойта нет | H2O vulnerable to read from uninitialized pointer in the reverse proxy handlerdena · h2o · CWE-824 | Высокая8,2 | — | 0,9 % | 27 апр. 2023 г. |
31Наблюдать | CVE-2016-4817Эксплойта нет | lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to causdena · h2o | Высокая7,5 | — | 4,4 % | 18 июн. 2016 г. |
31Наблюдать | CVE-2017-10908Эксплойта нет | H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.dena · h2o · CWE-20 | Высокая7,5 | — | 3,6 % | 22 дек. 2017 г. |
31Наблюдать | CVE-2017-10868Эксплойта нет | H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.dena · h2o · CWE-20 | Высокая7,5 | — | 3,5 % | 22 дек. 2017 г. |
31Наблюдать | CVE-2017-10869Эксплойта нет | Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.dena · h2o · CWE-119 | Высокая7,5 | — | 2,7 % | 22 дек. 2017 г. |
31Наблюдать | CVE-2016-4864Эксплойта нет | H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specdena · h2o · CWE-134 | Высокая7,5 | — | 1,8 % | 12 мая 2017 г. |
30Наблюдать | CVE-2023-50247Эксплойта нет | h2o QUIC state exhaustion DoSdena · h2o · CWE-770 | Высокая7,5 | — | 0,9 % | 12 дек. 2023 г. |
30Наблюдать | CVE-2024-45403Эксплойта нет | H2O assertion failure when HTTP/3 requests are cancelleddena · h2o · CWE-617 | Высокая7,5 | — | 0,7 % | 11 окт. 2024 г. |
30Наблюдать | CVE-2024-45396Эксплойта нет | Quicly assertion failuresdena · quicly · CWE-617 | Высокая7,5 | — | 0,6 % | 11 окт. 2024 г. |
30Наблюдать | CVE-2024-45397Эксплойта нет | H2O alllows bypassing address-based access control with 0-RTTdena · h2o · CWE-284 | Высокая7,5 | — | 0,4 % | 11 окт. 2024 г. |
27Наблюдать | CVE-2017-10872Эксплойта нет | H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.dena · h2o · CWE-118 | Средняя6,5 | — | 1,9 % | 22 дек. 2017 г. |
26Наблюдать | CVE-2023-41337Эксплойта нет | h2o vulnerable to TLS session resumption misdirectiondena · h2o · CWE-347 | Средняя6,7 | — | 0,2 % | 12 дек. 2023 г. |
24Наблюдать | CVE-2021-43848Proof of concept | Unititialized memory access in h2odena · h2o · CWE-908 | Средняя5,9 | — | 2,7 % | 1 февр. 2022 г. |
17Наблюдать | CVE-2015-5638Эксплойта нет | Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote atdena · h20 · CWE-22 | Средняя4,3 | — | 1,7 % | 20 сент. 2015 г. |
17Наблюдать | CVE-2024-25622Эксплойта нет | H2O ignores headers configuration directivesdena · h2o · CWE-670 | Средняя4,3 | — | 0,5 % | 11 окт. 2024 г. |
14Наблюдать | CVE-2016-1133Эксплойта нет | CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remotedena · h2o | Низкая3,7 | — | 1,5 % | 16 янв. 2016 г. |
14Наблюдать | CVE-2022-29482Эксплойта нет | 'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may allow an attacker to edena · mobaoku-auction \& flea market · CWE-295 | Низкая3,7 | — | 0,4 % | 14 июн. 2022 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2018-060840В плане
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via un
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %dena · h2o26 июн. 2018 г.
- CVE-2024-4540239Наблюдать
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %dena · picotls11 окт. 2024 г.
- CVE-2016-783537Наблюдать
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %dena · h2o9 июн. 2017 г.
- CVE-2023-3084732Наблюдать
H2O vulnerable to read from uninitialized pointer in the reverse proxy handler
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %dena · h2o27 апр. 2023 г.
- CVE-2016-481731Наблюдать
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to caus
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %dena · h2o18 июн. 2016 г.
- CVE-2017-1090831Наблюдать
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %dena · h2o22 дек. 2017 г.
- CVE-2017-1086831Наблюдать
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %dena · h2o22 дек. 2017 г.
- CVE-2017-1086931Наблюдать
Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %dena · h2o22 дек. 2017 г.
- CVE-2016-486431Наблюдать
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string spec
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dena · h2o12 мая 2017 г.
- CVE-2023-5024730Наблюдать
h2o QUIC state exhaustion DoS
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dena · h2o12 дек. 2023 г.
- CVE-2024-4540330Наблюдать
H2O assertion failure when HTTP/3 requests are cancelled
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dena · h2o11 окт. 2024 г.
- CVE-2024-4539630Наблюдать
Quicly assertion failures
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dena · quicly11 окт. 2024 г.
- CVE-2024-4539730Наблюдать
H2O alllows bypassing address-based access control with 0-RTT
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %dena · h2o11 окт. 2024 г.
- CVE-2017-1087227Наблюдать
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %dena · h2o22 дек. 2017 г.
- CVE-2023-4133726Наблюдать
h2o vulnerable to TLS session resumption misdirection
СредняяCVSS 6,7Эксплойта нетEPSS 0 %dena · h2o12 дек. 2023 г.
- CVE-2021-4384824Наблюдать
Unititialized memory access in h2o
СредняяCVSS 5,9Proof of conceptEPSS 3 %dena · h2o1 февр. 2022 г.
- CVE-2015-563817Наблюдать
Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote at
СредняяCVSS 4,3Эксплойта нетEPSS 2 %dena · h2020 сент. 2015 г.
- CVE-2024-2562217Наблюдать
H2O ignores headers configuration directives
СредняяCVSS 4,3Эксплойта нетEPSS 0 %dena · h2o11 окт. 2024 г.
- CVE-2016-113314Наблюдать
CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote
НизкаяCVSS 3,7Эксплойта нетEPSS 1 %dena · h2o16 янв. 2016 г.
- CVE-2022-2948214Наблюдать
'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may allow an attacker to e
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %dena · mobaoku-auction \& flea market14 июн. 2022 г.