Kazuho Oku
18 exploits
Active since Apr 2023
Quicly is vulnerable to memory exhaustion
CVSS 5.3
Quicly is vulnerable to stateless reset injection
CVSS 5.3
Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB
CVSS 7.5
Quicly is vulnerable to connection state corruption
CVSS 7.5
h2o is vulnerable to heap overrun
CVSS 5.9
h2o is vulnerable to musl libc stack overflow
CVSS 7.5
h2o has HTTP/2 state amplification
CVSS 7.5
h2o: musl libc stack overflow (QPACK)
CVSS 7.5
h2o - Denial of Service
CVSS 3.7
H2O <2.3.0-beta2 - Memory Corruption
CVSS 8.2
h2o <2.3.0-beta2 - SSRF
CVSS 6.1
Dena H2o < 2.2.6 - Resource Allocation Without Limits
CVSS 3.7
h2o - Info Disclosure
CVSS 3.1
dena quicly < 2024-10-10 - Denial of Service via Reachable Assertion
CVSS 7.5
h2o HTTP Server - Spoofed Source Access Control Bypass
CVSS 5.9
picotls 2024-08-12-2024-10-10 - Double Free in TLS Handshake Message Parsing
CVSS 8.6
h2o - Denial of Service
CVSS 3.7
Quicly < 2026-01-18 - Denial of Service via Reachable Assertion
CVSS 7.5