ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 7
ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 7
CVE-2025-66453
Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1.
CVE-2025-66453
Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1.
CVE-2025-66453
Rhino is an open-source implementation of JavaScript written entirely ...
openSUSE-SU-2026:20297-1
Security update for rhino
SUSE-SU-2025:4390-1
Security update for rhino
GHSA-3w8q-xq97-5j7x
Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
BDU:2026-01706
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ ΡΡΠ½ΠΊΡΠΈΠΈ toFixed() ΡΡΠ΅Π΄Ρ Π²ΡΠΏΠΎΠ»Π½Π΅Π½ΠΈΡ JavaScript-ΠΊΠΎΠ΄Π° Rhino, ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡΡΠ°Ρ Π½Π°ΡΡΡΠΈΡΠ΅Π»Ρ Π²ΡΠ·Π²Π°ΡΡ ΠΎΡΠΊΠ°Π· Π² ΠΎΠ±ΡΠ»ΡΠΆΠΈΠ²Π°Π½ΠΈΠΈ
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ | CVSS | EPSS | ΠΠΏΡΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ | |
|---|---|---|---|---|
CVE-2025-66453 Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1. | CVSS3: 7.5 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 9 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |
CVE-2025-66453 Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1. | CVSS3: 7.5 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 9 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |
CVE-2025-66453 Rhino is an open-source implementation of JavaScript written entirely ... | CVSS3: 7.5 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 9 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |
openSUSE-SU-2026:20297-1 Security update for rhino | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 6 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | ||
SUSE-SU-2025:4390-1 Security update for rhino | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 8 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | ||
GHSA-3w8q-xq97-5j7x Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 9 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | ||
BDU:2026-01706 Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ ΡΡΠ½ΠΊΡΠΈΠΈ toFixed() ΡΡΠ΅Π΄Ρ Π²ΡΠΏΠΎΠ»Π½Π΅Π½ΠΈΡ JavaScript-ΠΊΠΎΠ΄Π° Rhino, ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡΡΠ°Ρ Π½Π°ΡΡΡΠΈΡΠ΅Π»Ρ Π²ΡΠ·Π²Π°ΡΡ ΠΎΡΠΊΠ°Π· Π² ΠΎΠ±ΡΠ»ΡΠΆΠΈΠ²Π°Π½ΠΈΠΈ | CVSS3: 5.3 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | 9 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ |
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ