Количество 31
Количество 31
SUSE-SU-2025:01879-1
Security update for nodejs22
SUSE-SU-2025:01878-1
Security update for nodejs22
RLSA-2025:8506
Important: nodejs:22 security update
RLSA-2025:8493
Important: nodejs22 security update
RLSA-2025:8467
Important: nodejs:22 security update
ELSA-2025-8493
ELSA-2025-8493: nodejs22 security update (IMPORTANT)
SUSE-SU-2025:02045-1
Security update for nodejs20
SUSE-SU-2025:02039-1
Security update for nodejs20
RLSA-2025:8514
Important: nodejs:20 security update
RLSA-2025:8468
Important: nodejs:20 security update
ROS-20251006-11
Множественные уязвимости libuv
ROS-20251006-10
Множественные уязвимости nodejs20
ROS-20251006-09
Множественные уязвимости nodejs
CVE-2025-23165
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
CVE-2025-23165
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
CVE-2025-23165
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
CVE-2025-23165
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
CVE-2025-23165
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ...
CVE-2025-23166
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.
CVE-2025-23166
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
SUSE-SU-2025:01879-1 Security update for nodejs22 | около 1 года назад | |||
SUSE-SU-2025:01878-1 Security update for nodejs22 | около 1 года назад | |||
RLSA-2025:8506 Important: nodejs:22 security update | около 1 года назад | |||
RLSA-2025:8493 Important: nodejs22 security update | 10 месяцев назад | |||
RLSA-2025:8467 Important: nodejs:22 security update | около 1 года назад | |||
ELSA-2025-8493 ELSA-2025-8493: nodejs22 security update (IMPORTANT) | около 1 года назад | |||
SUSE-SU-2025:02045-1 Security update for nodejs20 | около 1 года назад | |||
SUSE-SU-2025:02039-1 Security update for nodejs20 | около 1 года назад | |||
RLSA-2025:8514 Important: nodejs:20 security update | около 1 года назад | |||
RLSA-2025:8468 Important: nodejs:20 security update | около 1 года назад | |||
ROS-20251006-11 Множественные уязвимости libuv | CVSS3: 7.5 | 10 месяцев назад | ||
ROS-20251006-10 Множественные уязвимости nodejs20 | CVSS3: 7.5 | 10 месяцев назад | ||
ROS-20251006-09 Множественные уязвимости nodejs | CVSS3: 7.5 | 10 месяцев назад | ||
CVE-2025-23165 In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | CVSS3: 3.7 | 0% Низкий | около 1 года назад | |
CVE-2025-23165 In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | CVSS3: 3.7 | 0% Низкий | около 1 года назад | |
CVE-2025-23165 In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | CVSS3: 3.7 | 0% Низкий | около 1 года назад | |
CVE-2025-23165 In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | CVSS3: 3.7 | 0% Низкий | около 1 года назад | |
CVE-2025-23165 In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ... | CVSS3: 3.7 | 0% Низкий | около 1 года назад | |
CVE-2025-23166 The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVE-2025-23166 The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime. | CVSS3: 7.5 | 1% Низкий | около 1 года назад |
Уязвимостей на страницу