Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-21227

Опубликовано: 01 мая 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ghost:sqlite3:*:*:*:*:*:node.js:*:*
Версия до 5.0.3 (исключая)

EPSS

Процентиль: 80%
0.02068
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

CVSS3: 7.5
redhat
больше 4 лет назад

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

CVSS3: 7.5
debian
больше 4 лет назад

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service ( ...

CVSS3: 7.5
github
больше 4 лет назад

Denial-of-Service when binding invalid parameters in sqlite3

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость компонента V8 системы управления базами данных SQLite позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 80%
0.02068
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo