Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
High

CVE-2020-11100

Disclosure Date: April 02, 2020 (last updated February 21, 2025)
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
Attacker Value
Unknown

CVE-2024-45506

Disclosure Date: September 04, 2024 (last updated October 14, 2024)
HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
Attacker Value
Unknown

CVE-2018-20615

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.
0
Attacker Value
Unknown

CVE-2018-20102

Disclosure Date: December 12, 2018 (last updated November 08, 2023)
An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.
0
Attacker Value
Unknown

CVE-2018-20103

Disclosure Date: December 12, 2018 (last updated November 08, 2023)
An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.
0
Attacker Value
Unknown

CVE-2018-14645

Disclosure Date: September 21, 2018 (last updated November 08, 2023)
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
0