CVE-2016-1544 — Uncontrolled Resource Consumption in Nghttp2
Severity
3.3LOWNVD
EPSS
1.6%
top 18.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 6
Latest updateMay 24
Description
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4
Affected Packages3 packages
Also affects: Fedora 22, 23