Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-2313

Опубликовано: 09 авг. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of service (CPU consumption) via a crafted small message, which triggers a "tight" for loop. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-2312.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:capnproto:capnproto:*:*:*:*:*:*:*:*
Версия до 0.4.1.0 (включая)
cpe:2.3:a:capnproto:capnproto:0.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:capnproto:capnproto:0.5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:capnproto:capnproto:0.5.1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00657
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of service (CPU consumption) via a crafted small message, which triggers a "tight" for loop. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-2312.

CVSS3: 7.5
debian
больше 8 лет назад

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an ...

CVSS3: 7.5
github
больше 3 лет назад

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of service (CPU consumption) via a crafted small message, which triggers a "tight" for loop. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-2312.

EPSS

Процентиль: 71%
0.00657
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-400