Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27813

Опубликовано: 02 дек. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gorillatoolkit:websocket:*:*:*:*:*:*:*:*
Версия до 1.4.1 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
redhat
больше 6 лет назад

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

CVSS3: 7.5
debian
около 5 лет назад

An integer overflow vulnerability exists with the length of websocket ...

CVSS3: 7.5
github
больше 4 лет назад

Integer overflow in github.com/gorilla/websocket

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-190
CWE-190