All 14 CVE vulnerabilities found in h2o, with AI-generated Chinese analysis, references, and POCs.
Vendor: Kazuho Oku
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-45403 | H2O assertion failure when HTTP/3 requests are cancelled CWE-617 | 3.7 | Low | 2024-10-11 |
| CVE-2024-45397 | H2O alllows bypassing address-based access control with 0-RTT CWE-284 | 5.9 | Medium | 2024-10-11 |
| CVE-2024-25622 | H2O ignores headers configuration directives CWE-670 | 3.1 | Low | 2024-10-11 |
| CVE-2023-50247 | h2o QUIC state exhaustion DoS CWE-770 | 3.7 | Low | 2023-12-12 |
| CVE-2023-41337 | h2o vulnerable to TLS session resumption misdirection CWE-347 | 6.1 | Medium | 2023-12-12 |
| CVE-2023-30847 | H2O vulnerable to read from uninitialized pointer in the reverse proxy handler CWE-824 | 8.2 | High | 2023-04-27 |
| CVE-2021-43848 | Unititialized memory access in h2o CWE-908 | 7.4 | High | 2022-02-01 |
| CVE-2018-0608 | H2O 缓冲区错误漏洞 | 9.8 | - | 2018-06-26 |
| CVE-2017-10868 | H2O 安全漏洞 | 7.5 | - | 2017-12-22 |
| CVE-2017-10869 | H2O 缓冲区错误漏洞 | 7.5 | - | 2017-12-22 |
| CVE-2017-10872 | H2O 安全漏洞 | 7.5 | - | 2017-12-22 |
| CVE-2017-10908 | H2O 安全漏洞 | 7.5 | - | 2017-12-22 |
| CVE-2016-7835 | H2O 安全漏洞 | 9.1 | - | 2017-06-09 |
| CVE-2016-4864 | H2O 安全漏洞 | 7.5 | - | 2017-05-12 |
All 14 known CVE vulnerabilities affecting h2o with full Chinese analysis, references, and POCs where available.