cbcvebase.
CVE-2015-5168
published 2017-09-13

CVE-2015-5168: Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.

Affected

3 ranges
VendorProductVersion rangeFixed in
apachetraffic_server
apachetraffic_server
debiantrafficserver< trafficserver 6.0.0-1 (bookworm)trafficserver 6.0.0-1 (bookworm)

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL