Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2019-9514

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2:

  • Severity: High
  • Score: 7.8
  • AV:N/AC:L/Au:N/C:N/I:N/A:C

CWEs:

Software From Fixed in
apple / swiftnio 1.0.0 1.4.0.x
apache / traffic_server 8.0.0 8.0.3.x
apache / traffic_server 7.0.0 7.1.6.x
apache / traffic_server 6.0.0 6.2.3.x
debian / debian_linux 10.0 10.0.x
canonical / ubuntu_linux 16.04 16.04.x
canonical / ubuntu_linux 18.04 18.04.x
canonical / ubuntu_linux 19.04 19.04.x
debian / debian_linux 9.0 9.0.x
synology / diskstation_manager 6.2 6.2.x
fedoraproject / fedora 29 29.x
fedoraproject / fedora 30 30.x
opensuse / leap 15.0 15.0.x
opensuse / leap 15.1 15.1.x
redhat / enterprise_linux_workstation 7.0 7.0.x
redhat / enterprise_linux_server 7.0 7.0.x
redhat / software_collections 1.0 1.0.x
redhat / openshift_container_platform 3.9 3.9.x
redhat / openshift_container_platform 3.11 3.11.x
redhat / openshift_container_platform 3.10 3.10.x
redhat / jboss_core_services 1.0 1.0.x
redhat / enterprise_linux 8.0 8.0.x
redhat / jboss_enterprise_application_platform 7.2.0 7.2.0.x
redhat / single_sign-on 7.3 7.3.x
redhat / developer_tools 1.0 1.0.x
redhat / openshift_container_platform 4.1 4.1.x
redhat / openshift_container_platform 4.2 4.2.x
redhat / quay 3.0.0 3.0.0.x
redhat / enterprise_linux_eus 8.1 8.1.x
redhat / openshift_service_mesh 1.0 1.0.x
redhat / openstack 14 14.x
redhat / jboss_enterprise_application_platform 7.3.0 7.3.0.x
oracle / graalvm 19.2.0 19.2.0.x
mcafee / web_gateway 7.7.2.0 7.7.2.24
mcafee / web_gateway 7.8.2.0 7.8.2.13
mcafee / web_gateway 8.1.0 8.2.0
f5 / big-ip_local_traffic_manager 14.1.0 14.1.2.1
f5 / big-ip_local_traffic_manager 14.0.0 14.0.1.1
f5 / big-ip_local_traffic_manager 13.1.0 13.1.3.2
f5 / big-ip_local_traffic_manager 15.0.0 15.0.1.1
f5 / big-ip_local_traffic_manager 12.1.0 12.1.5.1
f5 / big-ip_local_traffic_manager 11.6.1 11.6.5.1
nodejs / node.js 8.0.0 8.8.1.x
nodejs / node.js 10.0.0 10.12.0.x
nodejs / node.js 12.0.0 12.8.1
nodejs / node.js 10.13.0 10.16.3
nodejs / node.js 8.9.0 8.16.1
golang.org/x/net/http - 0.0.0-20190813141303-74dc4d7220e7
golang.org/x/net - 0.0.0-20190813141303-74dc4d7220e7