Record summary

CVE-2024-10395 has a selected CVSS score of 8.6 (high).

Description

No proper validation of the length of user input in http_server_get_content_type_from_extension.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List* to ≤ 3.7affected

References

1