Логотип exploitDog
bind:"CVE-2025-23165" OR bind:"CVE-2025-23166"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-23165" OR bind:"CVE-2025-23166"

Количество 21

Количество 21

suse-cvrf логотип

SUSE-SU-2025:01879-1

около 2 месяцев назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01878-1

около 2 месяцев назад

Security update for nodejs22

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8493

около 1 месяца назад

ELSA-2025-8493: nodejs22 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02045-1

около 2 месяцев назад

Security update for nodejs20

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02039-1

около 2 месяцев назад

Security update for nodejs20

EPSS: Низкий
ubuntu логотип

CVE-2025-23165

3 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2025-23165

3 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-23165

3 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
msrc логотип

CVE-2025-23165

27 дней назад

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-23165

3 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2025-23166

3 месяца назад

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-23166

3 месяца назад

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-23166

3 месяца назад

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-23166

20 дней назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-23166

3 месяца назад

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowExce ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gcf6-vgcr-474f

3 месяца назад

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-rrjv-57mm-j6cm

3 месяца назад

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2025-8514

около 2 месяцев назад

ELSA-2025-8514: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8506

2 месяца назад

ELSA-2025-8506: nodejs:22 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8468

2 месяца назад

ELSA-2025-8468: nodejs:20 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2025:01879-1

Security update for nodejs22

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01878-1

Security update for nodejs22

около 2 месяцев назад
oracle-oval логотип
ELSA-2025-8493

ELSA-2025-8493: nodejs22 security update (IMPORTANT)

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02045-1

Security update for nodejs20

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02039-1

Security update for nodejs20

около 2 месяцев назад
ubuntu логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
3 месяца назад
msrc логотип
CVSS3: 3.7
0%
Низкий
27 дней назад
debian логотип
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ...

CVSS3: 3.7
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-23166

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-23166

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-23166

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
0%
Низкий
3 месяца назад
msrc логотип
CVSS3: 7.5
0%
Низкий
20 дней назад
debian логотип
CVE-2025-23166

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowExce ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-gcf6-vgcr-474f

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVSS3: 3.7
0%
Низкий
3 месяца назад
github логотип
GHSA-rrjv-57mm-j6cm

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS3: 7.5
0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2025-8514

ELSA-2025-8514: nodejs:20 security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2025-8506

ELSA-2025-8506: nodejs:22 security update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2025-8468

ELSA-2025-8468: nodejs:20 security update (IMPORTANT)

2 месяца назад

Уязвимостей на страницу