Show filters
92 Total Results
Displaying 81-90 of 92
Sort by:
Attacker Value
Unknown
CVE-2019-12532
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.
0
Attacker Value
Unknown
CVE-2018-0608
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-11647
Disclosure Date: June 17, 2018 (last updated November 26, 2024)
index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL.
0
Attacker Value
Unknown
CVE-2017-10868
Disclosure Date: December 22, 2017 (last updated November 26, 2024)
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
0
Attacker Value
Unknown
CVE-2017-10869
Disclosure Date: December 22, 2017 (last updated November 26, 2024)
Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-10908
Disclosure Date: December 22, 2017 (last updated November 26, 2024)
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
0
Attacker Value
Unknown
CVE-2017-10872
Disclosure Date: December 22, 2017 (last updated November 26, 2024)
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-7835
Disclosure Date: June 09, 2017 (last updated November 26, 2024)
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.
0
Attacker Value
Unknown
CVE-2016-4864
Disclosure Date: May 12, 2017 (last updated November 26, 2024)
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, mruby, proxy, redirect or reproxy.
0
Attacker Value
Unknown
CVE-2016-4817
Disclosure Date: June 19, 2016 (last updated November 25, 2024)
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.
0