Логотип exploitDog
bind:"CVE-2021-22883" OR bind:"CVE-2021-22884"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-22883" OR bind:"CVE-2021-22884"

Количество 30

Количество 30

suse-cvrf логотип

openSUSE-SU-2021:0356-1

больше 4 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0650-1

больше 4 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0648-1

больше 4 лет назад

Security update for nodejs14

EPSS: Низкий
rocky логотип

RLSA-2021:0744

больше 4 лет назад

Important: nodejs:14 security and bug fix update

EPSS: Низкий
rocky логотип

RLSA-2021:0735

больше 4 лет назад

Important: nodejs:10 security update

EPSS: Низкий
rocky логотип

RLSA-2021:0734

больше 4 лет назад

Important: nodejs:12 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-0744

больше 4 лет назад

ELSA-2021-0744: nodejs:14 security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-0735

больше 4 лет назад

ELSA-2021-0735: nodejs:10 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-0734

больше 4 лет назад

ELSA-2021-0734: nodejs:12 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0372-1

больше 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0357-1

больше 4 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0674-1

больше 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0673-1

больше 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0651-1

больше 4 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0649-1

больше 4 лет назад

Security update for nodejs12

EPSS: Низкий
ubuntu логотип

CVE-2021-22883

больше 4 лет назад

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2021-22883

больше 4 лет назад

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2021-22883

больше 4 лет назад

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
EPSS: Критический
debian логотип

CVE-2021-22883

больше 4 лет назад

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to ...

CVSS3: 7.5
EPSS: Критический
ubuntu логотип

CVE-2021-22884

больше 4 лет назад

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
openSUSE-SU-2021:0356-1

Security update for nodejs14

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0650-1

Security update for nodejs14

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0648-1

Security update for nodejs14

больше 4 лет назад
rocky логотип
RLSA-2021:0744

Important: nodejs:14 security and bug fix update

больше 4 лет назад
rocky логотип
RLSA-2021:0735

Important: nodejs:10 security update

больше 4 лет назад
rocky логотип
RLSA-2021:0734

Important: nodejs:12 security update

больше 4 лет назад
oracle-oval логотип
ELSA-2021-0744

ELSA-2021-0744: nodejs:14 security and bug fix update (IMPORTANT)

больше 4 лет назад
oracle-oval логотип
ELSA-2021-0735

ELSA-2021-0735: nodejs:10 security update (IMPORTANT)

больше 4 лет назад
oracle-oval логотип
ELSA-2021-0734

ELSA-2021-0734: nodejs:12 security update (IMPORTANT)

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0372-1

Security update for nodejs10

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0357-1

Security update for nodejs12

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0674-1

Security update for nodejs10

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0673-1

Security update for nodejs10

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0651-1

Security update for nodejs12

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0649-1

Security update for nodejs12

больше 4 лет назад
ubuntu логотип
CVE-2021-22883

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
93%
Критический
больше 4 лет назад
redhat логотип
CVE-2021-22883

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
93%
Критический
больше 4 лет назад
nvd логотип
CVE-2021-22883

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
93%
Критический
больше 4 лет назад
debian логотип
CVE-2021-22883

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to ...

CVSS3: 7.5
93%
Критический
больше 4 лет назад
ubuntu логотип
CVE-2021-22884

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу