jbcs-httpd24-mod_http2 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the jbcs-httpd24-mod_http2 package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Incorrect Default Permissions

<0:1.15.19-43.el7jbcs
  • M
Improper Input Validation

<0:1.15.19-43.el7jbcs
  • H
Use After Free

<0:1.15.7-17.jbcs.el7
  • M
Detection of Error Condition Without Action

<0:1.15.19-37.el7jbcs
  • M
Resource Exhaustion

<0:1.15.19-37.el7jbcs
  • M
Improper Validation of Certificate with Host Mismatch

<0:1.15.19-37.el7jbcs
  • M
Missing Release of Resource after Effective Lifetime

<0:1.15.19-37.el7jbcs
  • M
Improper Certificate Validation

<0:1.15.19-37.el7jbcs
  • M
Misinterpretation of Input

<0:1.15.19-37.el7jbcs
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:1.15.19-41.el7jbcs
  • H
Improper Encoding or Escaping of Output

<0:1.15.19-41.el7jbcs
  • H
Server-Side Request Forgery (SSRF)

<0:1.15.7-19.jbcs.el7
  • M
Out-of-Bounds

<0:1.15.7-21.jbcs.el7
  • M
Out-of-bounds Read

<0:1.15.7-21.jbcs.el7
  • M
Incorrect Calculation of Buffer Size

<0:1.15.7-11.jbcs.el7
  • H
Allocation of Resources Without Limits or Throttling

<0:1.15.7-3.jbcs.el7
  • L
Use After Free

<0:1.11.3-8.jbcs.el7
  • H
Use After Free

<0:1.15.7-22.jbcs.el7
  • H
HTTP Request Smuggling

<0:1.15.7-22.jbcs.el7
  • H
Out-of-bounds Write

<0:1.15.7-22.jbcs.el7
  • H
Improper Input Validation

<0:1.15.19-41.el7jbcs
  • H
NULL Pointer Dereference

<0:1.15.19-41.el7jbcs
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:1.15.19-41.el7jbcs
  • H
Improper Encoding or Escaping of Output

<0:1.15.19-41.el7jbcs
  • H
Improper Encoding or Escaping of Output

<0:1.15.19-41.el7jbcs
  • H
Improper Encoding or Escaping of Output

<0:1.15.19-41.el7jbcs
  • L
NULL Pointer Dereference

*
  • M
Detection of Error Condition Without Action

<0:1.15.19-37.el7jbcs
  • M
Improper Validation of Certificate with Host Mismatch

<0:1.15.19-37.el7jbcs
  • M
Missing Release of Resource after Effective Lifetime

<0:1.15.19-37.el7jbcs
  • M
Improper Certificate Validation

<0:1.15.19-37.el7jbcs
  • M
Misinterpretation of Input

<0:1.15.19-37.el7jbcs
  • M
Resource Exhaustion

<0:1.15.19-37.el7jbcs
  • H
Resource Exhaustion

<0:1.15.19-32.el7jbcs
  • H
Information Exposure

<0:1.15.19-32.el7jbcs
  • H
External Control of File Name or Path

<0:1.15.19-32.el7jbcs
  • H
Out-of-Bounds

<0:1.15.19-32.el7jbcs
  • H
Excessive Iteration

<0:1.15.19-32.el7jbcs
  • H
Allocation of Resources Without Limits or Throttling

<0:1.15.19-32.el7jbcs
  • H
Resource Exhaustion

<0:1.15.19-32.el7jbcs
  • H
Resource Exhaustion

<0:1.15.19-32.el7jbcs
  • H
Improper Certificate Validation

<0:1.15.19-32.el7jbcs
  • H
Improper Certificate Validation

<0:1.15.19-32.el7jbcs
  • H
Resource Exhaustion

<0:1.15.19-32.el7jbcs
  • M
Improper Certificate Validation

<0:1.15.7-11.jbcs.el7
  • M
Cleartext Transmission of Sensitive Information

<0:1.15.19-20.el7jbcs
  • M
Double Free

<0:1.15.19-20.el7jbcs
  • M
Expected Behavior Violation

<0:1.15.19-20.el7jbcs
  • M
Improper Validation of Syntactic Correctness of Input

<0:1.15.19-20.el7jbcs
  • M
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<0:1.15.19-20.el7jbcs
  • M
Allocation of Resources Without Limits or Throttling

<0:1.15.19-20.el7jbcs
  • M
Improper Preservation of Permissions

<0:1.15.19-20.el7jbcs
  • M
Arbitrary Command Injection

<0:1.15.19-20.el7jbcs
  • M
Insufficient Verification of Data Authenticity

<0:1.15.19-20.el7jbcs
  • M
Allocation of Resources Without Limits or Throttling

<0:1.15.19-20.el7jbcs
  • M
Integer Overflow or Wraparound

<0:1.15.19-20.el7jbcs
  • M
Integer Overflow or Wraparound

<0:1.15.19-20.el7jbcs
  • M
HTTP Request Smuggling

<0:1.15.19-20.el7jbcs
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:1.15.19-20.el7jbcs
  • M
Arbitrary Command Injection

<0:1.15.19-20.el7jbcs
  • M
Integer Overflow or Wraparound

<0:1.15.19-20.el7jbcs
  • H
HTTP Request Smuggling

<0:1.15.7-22.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:1.15.19-20.el7jbcs
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:1.15.7-22.jbcs.el7
  • H
Use After Free

<0:1.15.7-22.jbcs.el7
  • H
Authentication Bypass

<0:1.15.7-17.jbcs.el7
  • H
Use After Free

<0:1.15.7-17.jbcs.el7
  • H
Information Exposure

<0:1.15.7-17.jbcs.el7
  • M
NULL Pointer Dereference

<0:1.15.7-21.jbcs.el7
  • M
Incorrect Calculation of Buffer Size

<0:1.15.7-11.jbcs.el7
  • M
Information Exposure

<0:1.15.7-21.jbcs.el7
  • H
Server-Side Request Forgery (SSRF)

<0:1.15.7-19.jbcs.el7
  • M
NULL Pointer Dereference

<0:1.15.7-21.jbcs.el7
  • M
Out-of-bounds Read

<0:1.15.7-21.jbcs.el7
  • M
Resource Exhaustion

<0:1.15.7-11.jbcs.el7
  • M
Out-of-Bounds

<0:1.15.7-11.jbcs.el7
  • H
Improper Certificate Validation

<0:1.15.7-17.jbcs.el7
  • H
Improper Certificate Validation

<0:1.15.7-14.jbcs.el7
  • H
NULL Pointer Dereference

<0:1.15.7-14.jbcs.el7
  • M
Open Redirect

<0:1.11.3-22.jbcs.el7
  • M
Resource Exhaustion

<0:1.11.3-22.jbcs.el7
  • H
HTTP Request Smuggling

<0:1.15.7-3.jbcs.el7
  • M
Use After Free

<0:1.11.3-22.jbcs.el7
  • H
Use After Free

<0:1.15.7-3.jbcs.el7
  • M
Buffer Overflow

<0:1.11.3-22.jbcs.el7
  • H
Memory Leak

<0:1.15.7-3.jbcs.el7
  • H
Allocation of Resources Without Limits or Throttling

<0:1.15.7-3.jbcs.el7
  • L
Use After Free

<0:1.11.3-8.jbcs.el7
  • M
Information Exposure

<0:1.11.3-22.jbcs.el7
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:1.15.7-3.jbcs.el7
  • H
Resource Exhaustion

<0:1.15.7-22.jbcs.el7
  • L
NULL Pointer Dereference

<0:1.15.7-12.jbcs.el7
  • H
NULL Pointer Dereference

<0:1.15.7-22.jbcs.el7
  • H
Out-of-bounds Write

<0:1.15.7-22.jbcs.el7
  • H
Use After Free

<0:1.15.7-22.jbcs.el7
  • H
Use After Free

<0:1.15.7-22.jbcs.el7
  • H
Missing Initialization of a Variable

<0:1.15.7-3.jbcs.el7
  • H
Uncontrolled Recursion

<0:1.15.7-17.jbcs.el7
  • H
Information Exposure

<0:1.15.7-17.jbcs.el7
  • L
Heap-based Buffer Overflow

<0:1.11.3-8.jbcs.el7
  • H
Missing Release of Resource after Effective Lifetime

<0:1.15.7-3.jbcs.el7
  • M
Open Redirect

<0:1.11.3-22.jbcs.el7
  • L
Path Equivalence

<0:1.11.3-8.jbcs.el7
  • H
Resource Exhaustion

<0:1.15.7-3.jbcs.el7
  • M
Information Exposure

<0:1.11.3-22.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:1.15.7-11.jbcs.el7
  • M
Client-Side Enforcement of Server-Side Security

<0:1.11.3-22.jbcs.el7
  • H
Heap-based Buffer Overflow

<0:1.15.7-3.jbcs.el7
  • M
Cross-site Scripting (XSS)

<0:1.11.3-22.jbcs.el7
  • M
Improper Input Validation

<0:1.15.7-21.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:1.15.7-21.jbcs.el7
  • M
Out-of-Bounds

<0:1.15.7-21.jbcs.el7
  • M
NULL Pointer Dereference

<0:1.15.7-21.jbcs.el7
  • M
NULL Pointer Dereference

<0:1.15.7-21.jbcs.el7
  • H
Information Exposure

<0:1.15.7-17.jbcs.el7
  • M
Out-of-Bounds

<0:1.15.7-21.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:1.15.7-21.jbcs.el7
  • M
Out-of-bounds Read

<0:1.15.7-21.jbcs.el7
  • M
Improper Authentication

<0:1.15.7-21.jbcs.el7