Show filters
92 Total Results
Displaying 81-90 of 92
Sort by:
Attacker Value
Unknown

CVE-2019-12532

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.
Attacker Value
Unknown

CVE-2018-0608

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2018-11647

Disclosure Date: June 17, 2018 (last updated November 26, 2024)
index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL.
0
Attacker Value
Unknown

CVE-2017-10868

Disclosure Date: December 22, 2017 (last updated November 26, 2024)
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
Attacker Value
Unknown

CVE-2017-10869

Disclosure Date: December 22, 2017 (last updated November 26, 2024)
Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-10908

Disclosure Date: December 22, 2017 (last updated November 26, 2024)
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
0
Attacker Value
Unknown

CVE-2017-10872

Disclosure Date: December 22, 2017 (last updated November 26, 2024)
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-7835

Disclosure Date: June 09, 2017 (last updated November 26, 2024)
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.
0
Attacker Value
Unknown

CVE-2016-4864

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, mruby, proxy, redirect or reproxy.
0
Attacker Value
Unknown

CVE-2016-4817

Disclosure Date: June 19, 2016 (last updated November 25, 2024)
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.
0