ZeroHour

CVE-2019-10082

CVSS 3.1
9.1 critical
EPSS
17%p97
Published
()
Modified
Description

In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.

Vendors
apacheoracle
Products
http server, communications element manager, enterprise manager ops center, instantis enterprisetrack, retail xstore point of service
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.