dena kayıtları
dena üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %4,8
- Silahlaştırılmış
- 1 · %4,8
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %28,6
- Yayından KEV’e ortanca
- 0 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-617 Reachable Assertion2
- CWE-20 Improper Input Validation2
- CWE-284 Improper Access Control1
- CWE-295 Improper Certificate Validation1
- CWE-347 Improper Verification of Cryptographic Signature1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
40Planlayın | CVE-2018-0608İstismar yok | Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via undena · h2o · CWE-119 | Kritik9,8 | — | %3,8 | 26 Haz 2018 |
39İzleyin | CVE-2024-45402İstismar yok | Picotls is a TLS protocol library that allows users select different crypto backends based on their use case.dena · picotls · CWE-415 | Kritik9,8 | — | %0,5 | 11 Eki 2024 |
37İzleyin | CVE-2016-7835İstismar yok | Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys anddena · h2o · CWE-416 | Kritik9,1 | — | %2,2 | 9 Haz 2017 |
32İzleyin | CVE-2023-30847İstismar yok | H2O vulnerable to read from uninitialized pointer in the reverse proxy handlerdena · h2o · CWE-824 | Yüksek8,2 | — | %0,9 | 27 Nis 2023 |
31İzleyin | CVE-2016-4817İstismar yok | lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to causdena · h2o | Yüksek7,5 | — | %4,4 | 18 Haz 2016 |
31İzleyin | CVE-2017-10908İstismar yok | H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.dena · h2o · CWE-20 | Yüksek7,5 | — | %3,6 | 22 Ara 2017 |
31İzleyin | CVE-2017-10868İstismar yok | H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.dena · h2o · CWE-20 | Yüksek7,5 | — | %3,5 | 22 Ara 2017 |
31İzleyin | CVE-2017-10869İstismar yok | Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.dena · h2o · CWE-119 | Yüksek7,5 | — | %2,7 | 22 Ara 2017 |
31İzleyin | CVE-2016-4864İstismar yok | H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specdena · h2o · CWE-134 | Yüksek7,5 | — | %1,8 | 12 May 2017 |
30İzleyin | CVE-2023-50247İstismar yok | h2o QUIC state exhaustion DoSdena · h2o · CWE-770 | Yüksek7,5 | — | %0,9 | 12 Ara 2023 |
30İzleyin | CVE-2024-45403İstismar yok | H2O assertion failure when HTTP/3 requests are cancelleddena · h2o · CWE-617 | Yüksek7,5 | — | %0,7 | 11 Eki 2024 |
30İzleyin | CVE-2024-45396İstismar yok | Quicly assertion failuresdena · quicly · CWE-617 | Yüksek7,5 | — | %0,6 | 11 Eki 2024 |
30İzleyin | CVE-2024-45397İstismar yok | H2O alllows bypassing address-based access control with 0-RTTdena · h2o · CWE-284 | Yüksek7,5 | — | %0,4 | 11 Eki 2024 |
27İzleyin | CVE-2017-10872İstismar yok | H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.dena · h2o · CWE-118 | Orta6,5 | — | %1,9 | 22 Ara 2017 |
26İzleyin | CVE-2023-41337İstismar yok | h2o vulnerable to TLS session resumption misdirectiondena · h2o · CWE-347 | Orta6,7 | — | %0,2 | 12 Ara 2023 |
24İzleyin | CVE-2021-43848Kavram kanıtı | Unititialized memory access in h2odena · h2o · CWE-908 | Orta5,9 | — | %2,7 | 1 Şub 2022 |
17İzleyin | CVE-2015-5638İstismar yok | Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote atdena · h20 · CWE-22 | Orta4,3 | — | %1,7 | 20 Eyl 2015 |
17İzleyin | CVE-2024-25622İstismar yok | H2O ignores headers configuration directivesdena · h2o · CWE-670 | Orta4,3 | — | %0,5 | 11 Eki 2024 |
14İzleyin | CVE-2016-1133İstismar yok | CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remotedena · h2o | Düşük3,7 | — | %1,5 | 16 Oca 2016 |
14İzleyin | CVE-2022-29482İstismar yok | 'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may allow an attacker to edena · mobaoku-auction \& flea market · CWE-295 | Düşük3,7 | — | %0,4 | 14 Haz 2022 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2018-060840Planlayın
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via un
KritikCVSS 9,8İstismar yokEPSS %4dena · h2o26 Haz 2018
- CVE-2024-4540239İzleyin
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case.
KritikCVSS 9,8İstismar yokEPSS %0dena · picotls11 Eki 2024
- CVE-2016-783537İzleyin
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and
KritikCVSS 9,1İstismar yokEPSS %2dena · h2o9 Haz 2017
- CVE-2023-3084732İzleyin
H2O vulnerable to read from uninitialized pointer in the reverse proxy handler
YüksekCVSS 8,2İstismar yokEPSS %1dena · h2o27 Nis 2023
- CVE-2016-481731İzleyin
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to caus
YüksekCVSS 7,5İstismar yokEPSS %4dena · h2o18 Haz 2016
- CVE-2017-1090831İzleyin
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
YüksekCVSS 7,5İstismar yokEPSS %4dena · h2o22 Ara 2017
- CVE-2017-1086831İzleyin
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
YüksekCVSS 7,5İstismar yokEPSS %4dena · h2o22 Ara 2017
- CVE-2017-1086931İzleyin
Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.
YüksekCVSS 7,5İstismar yokEPSS %3dena · h2o22 Ara 2017
- CVE-2016-486431İzleyin
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string spec
YüksekCVSS 7,5İstismar yokEPSS %2dena · h2o12 May 2017
- CVE-2023-5024730İzleyin
h2o QUIC state exhaustion DoS
YüksekCVSS 7,5İstismar yokEPSS %1dena · h2o12 Ara 2023
- CVE-2024-4540330İzleyin
H2O assertion failure when HTTP/3 requests are cancelled
YüksekCVSS 7,5İstismar yokEPSS %1dena · h2o11 Eki 2024
- CVE-2024-4539630İzleyin
Quicly assertion failures
YüksekCVSS 7,5İstismar yokEPSS %1dena · quicly11 Eki 2024
- CVE-2024-4539730İzleyin
H2O alllows bypassing address-based access control with 0-RTT
YüksekCVSS 7,5İstismar yokEPSS %0dena · h2o11 Eki 2024
- CVE-2017-1087227İzleyin
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.
OrtaCVSS 6,5İstismar yokEPSS %2dena · h2o22 Ara 2017
- CVE-2023-4133726İzleyin
h2o vulnerable to TLS session resumption misdirection
OrtaCVSS 6,7İstismar yokEPSS %0dena · h2o12 Ara 2023
- CVE-2021-4384824İzleyin
Unititialized memory access in h2o
OrtaCVSS 5,9Kavram kanıtıEPSS %3dena · h2o1 Şub 2022
- CVE-2015-563817İzleyin
Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote at
OrtaCVSS 4,3İstismar yokEPSS %2dena · h2020 Eyl 2015
- CVE-2024-2562217İzleyin
H2O ignores headers configuration directives
OrtaCVSS 4,3İstismar yokEPSS %0dena · h2o11 Eki 2024
- CVE-2016-113314İzleyin
CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote
DüşükCVSS 3,7İstismar yokEPSS %1dena · h2o16 Oca 2016
- CVE-2022-2948214İzleyin
'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may allow an attacker to e
DüşükCVSS 3,7İstismar yokEPSS %0dena · mobaoku-auction \& flea market14 Haz 2022