Логотип exploitDog
bind:"BDU:2025-10619" OR bind:"CVE-2025-23165"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-10619" OR bind:"CVE-2025-23165"

Количество 12

Количество 12

fstec логотип

BDU:2025-10619

4 месяца назад

Уязвимость функции ReadFileUtf8() модели разрешений программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2025-23165

4 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2025-23165

4 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-23165

4 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
msrc логотип

CVE-2025-23165

2 месяца назад

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-23165

4 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ...

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-gcf6-vgcr-474f

4 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01879-1

3 месяца назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01878-1

3 месяца назад

Security update for nodejs22

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8493

3 месяца назад

ELSA-2025-8493: nodejs22 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02045-1

3 месяца назад

Security update for nodejs20

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02039-1

3 месяца назад

Security update for nodejs20

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-10619

Уязвимость функции ReadFileUtf8() модели разрешений программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.7
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
4 месяца назад
msrc логотип
CVSS3: 3.7
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ...

CVSS3: 3.7
0%
Низкий
4 месяца назад
github логотип
GHSA-gcf6-vgcr-474f

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:01879-1

Security update for nodejs22

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:01878-1

Security update for nodejs22

3 месяца назад
oracle-oval логотип
ELSA-2025-8493

ELSA-2025-8493: nodejs22 security update (IMPORTANT)

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02045-1

Security update for nodejs20

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02039-1

Security update for nodejs20

3 месяца назад

Уязвимостей на страницу