CVE-2019-10082

CRITICAL

Apache HTTP Server <2.4.40 - Use After Free

Title source: llm
STIX 2.1

Description

In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.

References (16)

Core 16
Core References
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html

Scores

CVSS v3 9.1
EPSS 0.4206
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-416
Status published
Products (12)
apache/http_server 2.4.18 - 2.4.39
oracle/communications_element_manager 8.0.0
oracle/communications_element_manager 8.1.0
oracle/communications_element_manager 8.1.1
oracle/communications_element_manager 8.2.0
oracle/enterprise_manager_ops_center 12.3.3
oracle/enterprise_manager_ops_center 12.4.0
oracle/enterprise_manager_ops_center 12.4.0.0
oracle/http_server 12.2.1.3.0
oracle/http_server 12.2.1.4.0
... and 2 more
Published Sep 26, 2019
Tracked Since Feb 18, 2026