Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-51495

Опубликовано: 29 сент. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.

РелизСтатусПримечание
devel

not-affected

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

not-affected

jammy

needs-triage

noble

needs-triage

questing

ignored

end of life, was needs-triage
resolute

not-affected

2025.12+dfsg-4ubuntu1
upstream

released

2025.12+dfsg-1

Показывать по

EPSS

Процентиль: 33%
0.00399
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
11 месяцев назад

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.

CVSS3: 7.5
nvd
11 месяцев назад

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.

CVSS3: 7.5
debian
11 месяцев назад

An integer overflow vulnerability exists in the WebSocket component of ...

CVSS3: 7.5
github
11 месяцев назад

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.

EPSS

Процентиль: 33%
0.00399
Низкий

7.5 High

CVSS3