Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 31

Количество 31

suse-cvrf логотип

SUSE-SU-2025:01879-1

около 1 года назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01878-1

около 1 года назад

Security update for nodejs22

EPSS: Низкий
rocky логотип

RLSA-2025:8506

около 1 года назад

Important: nodejs:22 security update

EPSS: Низкий
rocky логотип

RLSA-2025:8493

10 месяцев назад

Important: nodejs22 security update

EPSS: Низкий
rocky логотип

RLSA-2025:8467

около 1 года назад

Important: nodejs:22 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8493

около 1 года назад

ELSA-2025-8493: nodejs22 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02045-1

около 1 года назад

Security update for nodejs20

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02039-1

около 1 года назад

Security update for nodejs20

EPSS: Низкий
rocky логотип

RLSA-2025:8514

около 1 года назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2025:8468

около 1 года назад

Important: nodejs:20 security update

EPSS: Низкий
redos логотип

ROS-20251006-11

10 месяцев назад

Множественные уязвимости libuv

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20251006-10

10 месяцев назад

Множественные уязвимости nodejs20

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20251006-09

10 месяцев назад

Множественные уязвимости nodejs

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-23165

около 1 года назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2025-23165

около 1 года назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-23165

около 1 года назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
msrc логотип

CVE-2025-23165

около 1 года назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-23165

около 1 года назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2025-23166

около 1 года назад

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-23166

около 1 года назад

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2025:01879-1

Security update for nodejs22

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01878-1

Security update for nodejs22

около 1 года назад
rocky логотип
RLSA-2025:8506

Important: nodejs:22 security update

около 1 года назад
rocky логотип
RLSA-2025:8493

Important: nodejs22 security update

10 месяцев назад
rocky логотип
RLSA-2025:8467

Important: nodejs:22 security update

около 1 года назад
oracle-oval логотип
ELSA-2025-8493

ELSA-2025-8493: nodejs22 security update (IMPORTANT)

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02045-1

Security update for nodejs20

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02039-1

Security update for nodejs20

около 1 года назад
rocky логотип
RLSA-2025:8514

Important: nodejs:20 security update

около 1 года назад
rocky логотип
RLSA-2025:8468

Important: nodejs:20 security update

около 1 года назад
redos логотип
ROS-20251006-11

Множественные уязвимости libuv

CVSS3: 7.5
10 месяцев назад
redos логотип
ROS-20251006-10

Множественные уязвимости nodejs20

CVSS3: 7.5
10 месяцев назад
redos логотип
ROS-20251006-09

Множественные уязвимости nodejs

CVSS3: 7.5
10 месяцев назад
ubuntu логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
около 1 года назад
msrc логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ...

CVSS3: 3.7
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-23166

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
1%
Низкий
около 1 года назад
redhat логотип
CVE-2025-23166

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
1%
Низкий
около 1 года назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.