7.5

CVE-2021-41524

Warning

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version2.4.49
FedoraprojectFedora Version34
FedoraprojectFedora Version35
NetappCloud Backup Version-
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.77% 0.909
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.