Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46546
HistoryApr 19, 2024 - 9:31 a.m.

HTTP/2 CONTINUATION Frame Processing

2024-04-1909:31:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
http/2
firefox
vulnerability
out of memory

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

6.1 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%

firefox is vulnerable to an HTTP/2 CONTINUATION frame processing vulnerability. The vulnerability is due to an absence of limits on the number of HTTP/2 CONTINUATION frames processed, allowing a server to potentially trigger an Out of Memory condition in the browser.

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

6.1 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%