Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

ubuntu логотип

CVE-2024-2398

больше 2 лет назад

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

CVSS3: 8.6
EPSS: Средний
redhat логотип

CVE-2024-2398

больше 2 лет назад

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2024-2398

больше 2 лет назад

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

CVSS3: 8.6
EPSS: Средний
msrc логотип

CVE-2024-2398

почти 2 года назад

CVSS3: 8.6
EPSS: Средний
debian логотип

CVE-2024-2398

больше 2 лет назад

When an application tells libcurl it wants to allow HTTP/2 server push ...

CVSS3: 8.6
EPSS: Средний
rocky логотип

RLSA-2024:5654

около 1 года назад

Moderate: curl security update

EPSS: Средний
github логотип

GHSA-mq8w-c2j9-rqxc

больше 2 лет назад

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

CVSS3: 8.6
EPSS: Средний
oracle-oval логотип

ELSA-2024-5654

почти 2 года назад

ELSA-2024-5654: curl security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-5529

почти 2 года назад

ELSA-2024-5529: curl security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-02722

больше 2 лет назад

Уязвимость реализации сетевого протокола HTTP/2 утилиты командной строки cURL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.3
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:1151-2

около 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1151-1

больше 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1150-1

больше 2 лет назад

Security update for curl

EPSS: Низкий
redos логотип

ROS-20240708-21

около 2 лет назад

Множественные уязвимости libcurl

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-2398

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

CVSS3: 8.6
36%
Средний
больше 2 лет назад
redhat логотип
CVE-2024-2398

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

CVSS3: 7.5
36%
Средний
больше 2 лет назад
nvd логотип
CVE-2024-2398

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

CVSS3: 8.6
36%
Средний
больше 2 лет назад
msrc логотип
CVSS3: 8.6
36%
Средний
почти 2 года назад
debian логотип
CVE-2024-2398

When an application tells libcurl it wants to allow HTTP/2 server push ...

CVSS3: 8.6
36%
Средний
больше 2 лет назад
rocky логотип
RLSA-2024:5654

Moderate: curl security update

36%
Средний
около 1 года назад
github логотип
GHSA-mq8w-c2j9-rqxc

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

CVSS3: 8.6
36%
Средний
больше 2 лет назад
oracle-oval логотип
ELSA-2024-5654

ELSA-2024-5654: curl security update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2024-5529

ELSA-2024-5529: curl security update (MODERATE)

почти 2 года назад
fstec логотип
BDU:2024-02722

Уязвимость реализации сетевого протокола HTTP/2 утилиты командной строки cURL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.3
36%
Средний
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1151-2

Security update for curl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1151-1

Security update for curl

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1150-1

Security update for curl

больше 2 лет назад
redos логотип
ROS-20240708-21

Множественные уязвимости libcurl

CVSS3: 4.3
около 2 лет назад

Уязвимостей на страницу