Vulnerability Database

296,138

Total vulnerabilities in the database

CVE-2019-0196

A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.

  • Published: Jun 12, 2019
  • Updated: Apr 13, 2023
  • CVE: CVE-2019-0196
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.3
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
apache / http_server 2.4.17 2.4.38.x
canonical / ubuntu_linux 16.04 16.04.x
canonical / ubuntu_linux 14.04 14.04.x
canonical / ubuntu_linux 18.04 18.04.x
canonical / ubuntu_linux 18.10 18.10.x
debian / debian_linux 9.0 9.0.x