Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 23

Количество 23

fstec логотип

BDU:2024-02691

больше 2 лет назад

Уязвимость библиотеки nghttp2, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Высокий
redos логотип

ROS-20240507-08

около 2 лет назад

Уязвимость nghttp2

CVSS3: 5.3
EPSS: Высокий
ubuntu логотип

CVE-2024-28182

больше 2 лет назад

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.

CVSS3: 5.3
EPSS: Высокий
redhat логотип

CVE-2024-28182

больше 2 лет назад

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.

CVSS3: 5.3
EPSS: Высокий
nvd логотип

CVE-2024-28182

больше 2 лет назад

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.

CVSS3: 5.3
EPSS: Высокий
msrc логотип

CVE-2024-28182

почти 2 года назад

CVSS3: 5.3
EPSS: Высокий
debian логотип

CVE-2024-28182

больше 2 лет назад

nghttp2 is an implementation of the Hypertext Transfer Protocol versio ...

CVSS3: 5.3
EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2024:1167-1

больше 2 лет назад

Security update for nghttp2

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2024:1156-1

больше 2 лет назад

Security update for nghttp2

EPSS: Высокий
rocky логотип

RLSA-2024:4252

около 1 года назад

Moderate: nghttp2 security update

EPSS: Высокий
rocky логотип

RLSA-2024:3501

около 2 лет назад

Moderate: nghttp2 security update

EPSS: Высокий
oracle-oval логотип

ELSA-2024-4252

около 2 лет назад

ELSA-2024-4252: nghttp2 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3501

около 2 лет назад

ELSA-2024-3501: nghttp2 security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:2910

около 2 лет назад

Important: nodejs security update

EPSS: Низкий
rocky логотип

RLSA-2024:2853

около 2 лет назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2024:2780

около 2 лет назад

Important: nodejs:18 security update

EPSS: Низкий
rocky логотип

RLSA-2024:2779

около 2 лет назад

Important: nodejs:18 security update

EPSS: Низкий
rocky логотип

RLSA-2024:2778

около 2 лет назад

Important: nodejs:20 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2910

около 2 лет назад

ELSA-2024-2910: nodejs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2853

около 2 лет назад

ELSA-2024-2853: nodejs:20 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-02691

Уязвимость библиотеки nghttp2, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
85%
Высокий
больше 2 лет назад
redos логотип
ROS-20240507-08

Уязвимость nghttp2

CVSS3: 5.3
85%
Высокий
около 2 лет назад
ubuntu логотип
CVE-2024-28182

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.

CVSS3: 5.3
85%
Высокий
больше 2 лет назад
redhat логотип
CVE-2024-28182

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.

CVSS3: 5.3
85%
Высокий
больше 2 лет назад
nvd логотип
CVE-2024-28182

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.

CVSS3: 5.3
85%
Высокий
больше 2 лет назад
msrc логотип
CVSS3: 5.3
85%
Высокий
почти 2 года назад
debian логотип
CVE-2024-28182

nghttp2 is an implementation of the Hypertext Transfer Protocol versio ...

CVSS3: 5.3
85%
Высокий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1167-1

Security update for nghttp2

85%
Высокий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1156-1

Security update for nghttp2

85%
Высокий
больше 2 лет назад
rocky логотип
RLSA-2024:4252

Moderate: nghttp2 security update

85%
Высокий
около 1 года назад
rocky логотип
RLSA-2024:3501

Moderate: nghttp2 security update

85%
Высокий
около 2 лет назад
oracle-oval логотип
ELSA-2024-4252

ELSA-2024-4252: nghttp2 security update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2024-3501

ELSA-2024-3501: nghttp2 security update (MODERATE)

около 2 лет назад
rocky логотип
RLSA-2024:2910

Important: nodejs security update

около 2 лет назад
rocky логотип
RLSA-2024:2853

Important: nodejs:20 security update

около 2 лет назад
rocky логотип
RLSA-2024:2780

Important: nodejs:18 security update

около 2 лет назад
rocky логотип
RLSA-2024:2779

Important: nodejs:18 security update

около 2 лет назад
rocky логотип
RLSA-2024:2778

Important: nodejs:20 security update

около 2 лет назад
oracle-oval логотип
ELSA-2024-2910

ELSA-2024-2910: nodejs security update (IMPORTANT)

около 2 лет назад
oracle-oval логотип
ELSA-2024-2853

ELSA-2024-2853: nodejs:20 security update (IMPORTANT)

около 2 лет назад

Уязвимостей на страницу