CVE Database
/

CVE-2019-9514

Back to search

CVE-2019-9514

Published: Aug 13, 2019

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.0

7.5

HIGH

Description

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.

VendorProductVersions

n/a

n/a

affected
n/a

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

References

VU#605641
third-party-advisory
DSA-4503
vendor-advisory
openSUSE-SU-2019:2000
vendor-advisory
FEDORA-2019-5a6a7bc12c
vendor-advisory
FEDORA-2019-6a2980de56
vendor-advisory
DSA-4508
vendor-advisory
openSUSE-SU-2019:2056
vendor-advisory
openSUSE-SU-2019:2072
vendor-advisory
FEDORA-2019-55d101a740
vendor-advisory
FEDORA-2019-65db7ad6c7
vendor-advisory
openSUSE-SU-2019:2085
vendor-advisory
RHSA-2019:2682
vendor-advisory
DSA-4520
vendor-advisory
RHSA-2019:2726
vendor-advisory
RHSA-2019:2594
vendor-advisory
openSUSE-SU-2019:2114
vendor-advisory
openSUSE-SU-2019:2115
vendor-advisory
RHSA-2019:2661
vendor-advisory
RHSA-2019:2690
vendor-advisory
RHSA-2019:2766
vendor-advisory
openSUSE-SU-2019:2130
vendor-advisory
RHSA-2019:2796
vendor-advisory
RHSA-2019:2861
vendor-advisory
RHSA-2019:2925
vendor-advisory
RHSA-2019:2939
vendor-advisory
RHSA-2019:2955
vendor-advisory
RHSA-2019:2966
vendor-advisory
RHSA-2019:3131
vendor-advisory
RHSA-2019:2769
vendor-advisory
RHSA-2019:3245
vendor-advisory
RHSA-2019:3265
vendor-advisory
RHSA-2019:3892
vendor-advisory
RHSA-2019:3906
vendor-advisory
RHSA-2019:4018
vendor-advisory
RHSA-2019:4019
vendor-advisory
RHSA-2019:4021
vendor-advisory
RHSA-2019:4020
vendor-advisory
RHSA-2019:4045
vendor-advisory
RHSA-2019:4042
vendor-advisory
RHSA-2019:4040
vendor-advisory
RHSA-2019:4041
vendor-advisory
RHSA-2019:4269
vendor-advisory
RHSA-2019:4273
vendor-advisory
RHSA-2019:4352
vendor-advisory
RHSA-2020:0406
vendor-advisory
RHSA-2020:0727
vendor-advisory
USN-4308-1
vendor-advisory
DSA-4669
vendor-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now