Логотип exploitDog
bind:CVE-2019-9517
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-9517

Количество 20

Количество 20

ubuntu логотип

CVE-2019-9517

почти 6 лет назад

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-9517

почти 6 лет назад

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-9517

почти 6 лет назад

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-9517

почти 6 лет назад

Some HTTP/2 implementations are vulnerable to unconstrained interal da ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w6v5-q8c8-52xx

около 3 лет назад

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2019-2893

больше 5 лет назад

ELSA-2019-2893: httpd:2.4 security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2019-03780

около 6 лет назад

Уязвимость реализации сетевого протокола HTTP/2 веб-сервера Apache HTTP Server, связанная с неконтролируемым расходом ресурса, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2019-03647

около 6 лет назад

Уязвимость сетевого протокола HTTP/2 веб-сервера Apache Traffic Server, программной платформы Node.js, связанная с недостатком механизма контроля расхода ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2329-1

почти 6 лет назад

Security update for apache2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2051-1

почти 6 лет назад

Security update for apache2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2237-1

почти 6 лет назад

Security update for apache2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2115-1

почти 6 лет назад

Security update for nodejs8

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2114-1

почти 6 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2260-1

почти 6 лет назад

Security update for nodejs8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2259-1

почти 6 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2254-1

почти 6 лет назад

Security update for nodejs10

EPSS: Низкий
oracle-oval логотип

ELSA-2019-2925

больше 5 лет назад

ELSA-2019-2925: nodejs:10 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0059-1

больше 5 лет назад

Security update for nodejs12

EPSS: Низкий
rocky логотип

RLSA-2019:2925

больше 5 лет назад

Important: nodejs:10 security update

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14246-1

больше 5 лет назад

Security update for Mozilla Firefox

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-9517

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

CVSS3: 7.5
5%
Низкий
почти 6 лет назад
redhat логотип
CVE-2019-9517

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

CVSS3: 7.5
5%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-9517

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

CVSS3: 7.5
5%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-9517

Some HTTP/2 implementations are vulnerable to unconstrained interal da ...

CVSS3: 7.5
5%
Низкий
почти 6 лет назад
github логотип
GHSA-w6v5-q8c8-52xx

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

CVSS3: 7.5
5%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2019-2893

ELSA-2019-2893: httpd:2.4 security update (IMPORTANT)

больше 5 лет назад
fstec логотип
BDU:2019-03780

Уязвимость реализации сетевого протокола HTTP/2 веб-сервера Apache HTTP Server, связанная с неконтролируемым расходом ресурса, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
5%
Низкий
около 6 лет назад
fstec логотип
BDU:2019-03647

Уязвимость сетевого протокола HTTP/2 веб-сервера Apache Traffic Server, программной платформы Node.js, связанная с недостатком механизма контроля расхода ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
5%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2329-1

Security update for apache2

почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2051-1

Security update for apache2

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2237-1

Security update for apache2

почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2115-1

Security update for nodejs8

почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2114-1

Security update for nodejs10

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2260-1

Security update for nodejs8

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2259-1

Security update for nodejs10

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2254-1

Security update for nodejs10

почти 6 лет назад
oracle-oval логотип
ELSA-2019-2925

ELSA-2019-2925: nodejs:10 security update (IMPORTANT)

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0059-1

Security update for nodejs12

больше 5 лет назад
rocky логотип
RLSA-2019:2925

Important: nodejs:10 security update

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2019:14246-1

Security update for Mozilla Firefox

больше 5 лет назад

Уязвимостей на страницу