Advisories
OtherPoC exploitHIGH2019-08-13
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS fra...
CVEs:CVE-2019-9515
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2019-08-13
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this dat...
CVEs:CVE-2019-9512
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2019-08-13
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the pee...
CVEs:CVE-2019-9514
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2019-08-13
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the p...
CVEs:CVE-2019-9513
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2019-08-13
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. The...
CVEs:CVE-2019-9511
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2019-08-13
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater hea...
CVEs:CVE-2019-9516
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2019-08-13
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so t...
CVEs:CVE-2019-9517
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2019-08-13
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTIN...
CVEs:CVE-2019-9518
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swiftnio |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2019-08-01
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past th...
CVEs:CVE-2019-11041
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2019-08-01
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past th...
CVEs:CVE-2019-11042
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2019-08-13
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that ...
CVEs:CVE-2019-9506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |