CVE-2015-8659 REJECTED

The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.

EPSS 2.19% · 84.2th percentile

Risk Scores

EPSS Score
2.19%
84.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSnghttp20, 0.6.7-1, 1.3.4-2

Timeline

References

Open in Interactive Console →