Логотип exploitDog
bind:"CVE-2023-44487" OR bind:"CVE-2024-22019"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-44487" OR bind:"CVE-2024-22019"

Количество 107

Количество 107

oracle-oval логотип

ELSA-2024-1444

около 1 года назад

ELSA-2024-1444: nodejs:16 security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2024-22019

больше 1 года назад

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-22019

больше 1 года назад

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-22019

больше 1 года назад

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-22019

больше 1 года назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-22019

больше 1 года назад

A vulnerability in Node.js HTTP servers allows an attacker to send a s ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-44487

больше 1 года назад

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2023-44487

больше 1 года назад

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2023-44487

больше 1 года назад

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS3: 7.5
EPSS: Критический
msrc логотип

CVE-2023-44487

больше 1 года назад

MITRE: CVE-2023-44487 HTTP/2 Rapid Reset Attack

EPSS: Критический
debian логотип

CVE-2023-44487

больше 1 года назад

The HTTP/2 protocol allows a denial of service (server resource consum ...

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-prhj-8562-p8gj

больше 1 года назад

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-1438

около 1 года назад

ELSA-2024-1438: nodejs security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2024-02798

больше 1 года назад

Уязвимость HTTP-сервера программной платформы Node.js, позволяющая нарушителю обойти ограничения безопасности и вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240808-03

11 месяцев назад

Уязвимость nodejs

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4624-1

больше 1 года назад

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:4492-1

больше 1 года назад

Security update for nghttp2

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:4295-1

больше 1 года назад

Security update for nodejs10

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:4200-1

больше 1 года назад

Security update for nghttp2

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:4199-1

больше 1 года назад

Security update for nghttp2

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2024-1444

ELSA-2024-1444: nodejs:16 security update (IMPORTANT)

около 1 года назад
ubuntu логотип
CVE-2024-22019

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-22019

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-22019

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 7.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-22019

A vulnerability in Node.js HTTP servers allows an attacker to send a s ...

CVSS3: 7.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS3: 7.5
94%
Критический
больше 1 года назад
redhat логотип
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS3: 7.5
94%
Критический
больше 1 года назад
nvd логотип
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS3: 7.5
94%
Критический
больше 1 года назад
msrc логотип
CVE-2023-44487

MITRE: CVE-2023-44487 HTTP/2 Rapid Reset Attack

94%
Критический
больше 1 года назад
debian логотип
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consum ...

CVSS3: 7.5
94%
Критический
больше 1 года назад
github логотип
GHSA-prhj-8562-p8gj

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2024-1438

ELSA-2024-1438: nodejs security update (IMPORTANT)

около 1 года назад
fstec логотип
BDU:2024-02798

Уязвимость HTTP-сервера программной платформы Node.js, позволяющая нарушителю обойти ограничения безопасности и вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240808-03

Уязвимость nodejs

CVSS3: 7.5
0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2023:4624-1

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container

94%
Критический
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4492-1

Security update for nghttp2

94%
Критический
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4295-1

Security update for nodejs10

94%
Критический
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4200-1

Security update for nghttp2

94%
Критический
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4199-1

Security update for nghttp2

94%
Критический
больше 1 года назад

Уязвимостей на страницу