cbcvebase.
CVE-2015-8659
published 2016-01-12

CVE-2015-8659: The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.

PriorityP347critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
4.07%
89.5th percentile
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.

Affected

14 ranges
VendorProductVersion rangeFixed in
appleios
appleiphone_os<= 9.2.1
applemac_os_x<= 10.11.3
appleos_x_el_capitan_v10.11.4_and_security_update_2016-002
appletvos<= 9.1
appletvos
applewatchos<= 2.1
applewatchos
debiannghttp2< nghttp2 1.6.0-1 (bookworm)nghttp2 1.6.0-1 (bookworm)
nghttp2nghttp2<= 1.5.0
nghttp2nghttp2>= 0 < 1.6.0-11.6.0-1
nghttp2nghttp2>= 0 < 1.6.0-11.6.0-1
nghttp2nghttp2>= 0 < 1.6.0-11.6.0-1
nghttp2nghttp2>= 0 < 1.6.0-11.6.0-1

CVSS provenance

nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.