Логотип exploitDog
bind:CVE-2017-2922
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-2922

Количество 4

Количество 4

ubuntu логотип

CVE-2017-2922

больше 8 лет назад

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-2922

больше 8 лет назад

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-2922

больше 8 лет назад

An exploitable memory corruption vulnerability exists in the Websocket ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-g5qg-r8q8-9m72

больше 3 лет назад

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-2922

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.

CVSS3: 9.8
3%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-2922

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.

CVSS3: 9.8
3%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-2922

An exploitable memory corruption vulnerability exists in the Websocket ...

CVSS3: 9.8
3%
Низкий
больше 8 лет назад
github логотип
GHSA-g5qg-r8q8-9m72

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу