Lucene search

K
nginxNginxNGINX:CVE-2024-35200
HistoryMay 29, 2024 - 4:15 p.m.

NULL pointer dereference in HTTP/3

2024-05-2916:15:10
mailman.nginx.org
101
http/3
null pointer dereference
medium severity
cve-2024-35200
not vulnerable
vulnerable
software

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

15.5%

NULL pointer dereference in HTTP/3
Severity: medium
CVE-2024-35200
Not vulnerable: 1.27.0+, 1.26.1+
Vulnerable: 1.25.0-1.25.5, 1.26.0

Affected configurations

Vulners
Node
f5nginxRange1.25.01.25.5
OR
f5nginx
VendorProductVersionCPE
f5nginx*cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

15.5%