Описание
The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitIssue TrackingThird Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.6.0 (исключая)
cpe:2.3:a:muhammara_project:muhammara:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 75%
0.00893
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-20
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
muhammara and hummus vulnerable to null pointer dereference on bad response object
EPSS
Процентиль: 75%
0.00893
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-20