nghttp2 kayıtları
nghttp2 üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %11,1
- Silahlaştırılmış
- 1 · %11,1
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- 0 gün
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption3
- CWE-20 Improper Input Validation1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-617 Reachable Assertion1
- CWE-707 Improper Neutralization1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
46Planlayın | CVE-2024-28182İstismar yok | Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usagenghttp2 · nghttp2 · CWE-770 | Orta5,3 | — | %85,0 | 4 Nis 2024 |
41Planlayın | CVE-2015-8659İstismar yok | The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free nghttp2 · nghttp2 · CWE-119 | Kritik10,0 | — | %4,0 | 12 Oca 2016 |
33İzleyin | CVE-2018-1000168İstismar yok | nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that canghttp2 · nghttp2 · CWE-20 | Yüksek7,5 | — | %10,6 | 8 May 2018 |
32İzleyin | CVE-2020-11080İstismar yok | Denial of service in nghttp2nghttp2 · nghttp2 · CWE-707 | Yüksek7,5 | — | %5,3 | 3 Haz 2020 |
30İzleyin | CVE-2023-35945İstismar yok | Envoy vulnerable to HTTP/2 memory leak in nghttp2 codecenvoyproxy · envoy · CWE-400 | Yüksek7,5 | — | %1,3 | 13 Tem 2023 |
30İzleyin | CVE-2026-27135İstismar yok | nghttp2 Denial of service: Assertion failure due to the missing state validationnghttp2 · nghttp2 · CWE-617 | Yüksek7,5 | — | %0,9 | 18 Mar 2026 |
25İzleyin | CVE-2026-58055İstismar yok | nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Lengthnghttp2 · nghttp2 · CWE-444 | Orta6,3 | — | %0,3 | 27 Haz 2026 |
13İzleyin | CVE-2016-1544İstismar yok | nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).nghttp2 · nghttp2 · CWE-400 | Düşük3,3 | — | %0,9 | 6 Şub 2020 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2024-2818246Planlayın
Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
OrtaCVSS 5,3İstismar yokEPSS %85nghttp2 · nghttp24 Nis 2024
- CVE-2015-865941Planlayın
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free
KritikCVSS 10,0İstismar yokEPSS %4nghttp2 · nghttp212 Oca 2016
- CVE-2018-100016833İzleyin
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that ca
YüksekCVSS 7,5İstismar yokEPSS %11nghttp2 · nghttp28 May 2018
- CVE-2020-1108032İzleyin
Denial of service in nghttp2
YüksekCVSS 7,5İstismar yokEPSS %5nghttp2 · nghttp23 Haz 2020
- CVE-2023-3594530İzleyin
Envoy vulnerable to HTTP/2 memory leak in nghttp2 codec
YüksekCVSS 7,5İstismar yokEPSS %1envoyproxy · envoy13 Tem 2023
- CVE-2026-2713530İzleyin
nghttp2 Denial of service: Assertion failure due to the missing state validation
YüksekCVSS 7,5İstismar yokEPSS %1nghttp2 · nghttp218 Mar 2026
- CVE-2026-5805525İzleyin
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
OrtaCVSS 6,3İstismar yokEPSS %0nghttp2 · nghttp227 Haz 2026
- CVE-2016-154413İzleyin
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
DüşükCVSS 3,3İstismar yokEPSS %1nghttp2 · nghttp26 Şub 2020