Debian H2O vulnerabilities
22 known vulnerabilities affecting debian/h2o.
Total CVEs
22
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH5MEDIUM6LOW10
Vulnerabilities
Page 2 of 2
CVE-2016-4817LOWCVSS 7.52016
CVE-2016-4817 [HIGH] CVE-2016-4817: h2o - lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles...
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.
Scope: local
bookworm: resolved
bullseye: resolved
debian
CVE-2015-5638LOWCVSS 4.32015
CVE-2015-5638 [MEDIUM] CVE-2015-5638: h2o - Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-bet...
Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote attackers to read arbitrary files via a crafted URL.
Scope: local
bookworm: resolved
bullseye: resolved
debian
← Previous2 / 2