Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-4610

Опубликовано: 10 фев. 2014
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:jboss_communications_platform:*:*:*:*:*:*:*:*
Версия до 5.1 (включая)
cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:*
Версия до 5.1.2 (включая)
cpe:2.3:a:redhat:jboss_enterprise_brms_platform:*:*:*:*:*:*:*:*
Версия до 5.1.0 (включая)
cpe:2.3:a:redhat:jboss_enterprise_web_platform:*:*:*:*:*:*:*:*
Версия до 5.1.2 (включая)

EPSS

Процентиль: 81%
0.01496
Низкий

5 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

redhat
около 14 лет назад

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."

debian
почти 12 лет назад

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1 ...

github
больше 3 лет назад

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."

EPSS

Процентиль: 81%
0.01496
Низкий

5 Medium

CVSS2

Дефекты

CWE-119