Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-14181

Опубликовано: 25 сент. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow.

EPSS

Процентиль: 25%
0.00341
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 6.5
ubuntu
8 дней назад

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow.

CVSS3: 6.5
redhat
8 дней назад

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow.

CVSS3: 6.5
msrc
4 дня назад

Integer overflow to buffer overflow in soap HTTP parsing

CVSS3: 6.5
debian
8 дней назад

The SOAP HTTP client guards its response buffer growth with a check th ...

CVSS3: 6.5
github
9 дней назад

Integer overflow to buffer overflow in soap HTTP parsing

EPSS

Процентиль: 25%
0.00341
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-190