Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dena

First CVE: Sep 20, 2015Active for: 11 yearsTotal CVEs: 21
57.8
VTI Score
TOP TARGET

Dena's vulnerability footprint, while concentrated in a modest product portfolio, carries outsized prominence through its H2O HTTP server and PicoTLS cryptographic library, components that see broad adoption in performance-critical and embedded infrastructure contexts. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, though the exposure is not characterized by widespread public exploitation. The recurring weakness classes—improper input validation, buffer-boundary violations, reachable assertions, and uninitialized pointer access—reflect the low-level demands of network protocol parsers and cryptographic implementations, where memory-safety lapses can cascade into system compromise. Defenders should monitor this vendor's releases closely for its server and TLS components in particular, as updates often address issues in foundational network layers that affect downstream products. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
4.8%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Dena over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 20, 2015
10 years ago
Most Recent CVE
Oct 11, 2024
651 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2016-7835CRITICAL
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.
Jun 9, 20179.130NONO
CVE-2024-45402CRITICAL
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically, b
Oct 11, 20249.829NONO
CVE-2018-0608CRITICAL
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.
Jun 26, 20189.827NONO
CVE-2017-10868HIGH
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
Dec 22, 20177.526NONO
CVE-2023-30847HIGH
H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain type of invalid HTTP request, it tries to build an upstream UR
Apr 27, 20238.225NONO
CVE-2017-10869HIGH
Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.
Dec 22, 20177.525NONO
CVE-2016-4817HIGH
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free an
Jun 19, 20167.525NONO
CVE-2016-4864HIGH
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, m
May 12, 20177.524NONO
CVE-2024-45403HIGH
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3 requests are cancelled by the client, h2o might crash due t
Oct 11, 20247.522NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
10%
24%
52%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (90.5%)
Unknown1 (4.8%)
Physical0 (0.0%)
Adjacent Network1 (4.8%)
Attack Complexity
Low17 (81.0%)
High3 (14.3%)
Unknown1 (4.8%)
User Interaction
None19 (90.5%)
Unknown1 (4.8%)
Required1 (4.8%)
Privileges Required
Low3 (14.3%)
High0 (0.0%)
None17 (81.0%)
Unknown1 (4.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
1 CVE
4.8% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dena.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dena — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dena's Products

View all 3 CNAs →

Top CWEs