VendorsDeNAh2oall versions
Vulnerabilities

DeNA H2O

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2018-0608
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.
Published 2018-06-26 · Modified
9.8EPSS 0.038
CVE-2016-7835
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.
Published 2017-06-09 · Modified
9.1EPSS 0.022
CVE-2023-30847
H2O vulnerable to read from uninitialized pointer in the reverse proxy handler
Published 2023-04-27 · Modified
8.2EPSS 0.009
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2016-4817
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.
Published 2016-06-19 · Modified
7.5EPSS 0.044
CVE-2017-10908
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
Published 2017-12-22 · Modified
7.5EPSS 0.036
CVE-2017-10868
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
Published 2017-12-22 · Modified
7.5EPSS 0.035
CVE-2017-10869
Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.
Published 2017-12-22 · Modified
7.5EPSS 0.027
CVE-2016-4864
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, mruby, proxy, redirect or reproxy.
Published 2017-05-12 · Modified
7.5EPSS 0.018
CVE-2023-50247
h2o QUIC state exhaustion DoS
Published 2023-12-12 · Modified
7.5EPSS 0.009
CVE-2024-45403
H2O assertion failure when HTTP/3 requests are cancelled
Published 2024-10-11 · Analyzed
7.5EPSS 0.007
CVE-2024-45397
H2O alllows bypassing address-based access control with 0-RTT
Published 2024-10-11 · Analyzed
7.5EPSS 0.004
CVE-2021-43848
Unititialized memory access in h2o
Published 2022-02-01 · Modified
7.4EPSS 0.027
CVE-2023-41337
h2o vulnerable to TLS session resumption misdirection
Published 2023-12-12 · Modified
6.7EPSS 0.002
CVE-2017-10872
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.
Published 2017-12-22 · Modified
6.5EPSS 0.019
CVE-2016-1133
CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.
Published 2016-01-16 · Modified
4.3EPSS 0.015
CVE-2024-25622
H2O ignores headers configuration directives
Published 2024-10-11 · Analyzed
4.3EPSS 0.005