← All CVEs

CVE-2019-10082

critical · 9.1

In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.

9.1
CVSS
16.5%
EPSS (exploit prob.)
97th
EPSS percentile
2019-09-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
apachehttp_server>= 2.4.18, <= 2.4.39
oraclecommunications_element_manager8.0.0
oraclecommunications_element_manager8.1.0
oraclecommunications_element_manager8.1.1
oraclecommunications_element_manager8.2.0
oracleenterprise_manager_ops_center12.3.3
oracleenterprise_manager_ops_center12.4.0
oracleenterprise_manager_ops_center12.4.0.0
oraclehttp_server12.2.1.3.0
oraclehttp_server12.2.1.4.0
oracleinstantis_enterprisetrack>= 17.1, <= 17.3
oracleretail_xstore_point_of_service7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-10082