Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26

Количество 26

github логотип

GHSA-xp28-3fv9-33c6

больше 2 лет назад

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-22025

больше 2 лет назад

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-22025

больше 2 лет назад

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-22025

больше 2 лет назад

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-22025

около 2 лет назад

A vulnerability in Node.js has been identified allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory potentially leading to process termination depending on the system configuration.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-22025

больше 2 лет назад

A vulnerability in Node.js has been identified, allowing for a Denial ...

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2024-02698

больше 2 лет назад

Уязвимость функции fetch() программной платформы Node.js, позволяющая нарушителю вызывать отказ в обслуживании (DoS)

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20240916-07

почти 2 года назад

Уязвимость nodejs

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0733-1

больше 2 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0732-1

больше 2 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0731-1

больше 2 лет назад

Security update for nodejs16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0729-1

больше 2 лет назад

Security update for nodejs16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0728-1

больше 2 лет назад

Security update for nodejs16

EPSS: Низкий
rocky логотип

RLSA-2024:2910

около 2 лет назад

Important: nodejs security update

EPSS: Низкий
rocky логотип

RLSA-2024:2853

около 2 лет назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2024:2780

около 2 лет назад

Important: nodejs:18 security update

EPSS: Низкий
rocky логотип

RLSA-2024:2779

около 2 лет назад

Important: nodejs:18 security update

EPSS: Низкий
rocky логотип

RLSA-2024:2778

около 2 лет назад

Important: nodejs:20 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2910

около 2 лет назад

ELSA-2024-2910: nodejs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2853

около 2 лет назад

ELSA-2024-2853: nodejs:20 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp28-3fv9-33c6

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-22025

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-22025

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-22025

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2024-22025

A vulnerability in Node.js has been identified allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory potentially leading to process termination depending on the system configuration.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-22025

A vulnerability in Node.js has been identified, allowing for a Denial ...

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-02698

Уязвимость функции fetch() программной платформы Node.js, позволяющая нарушителю вызывать отказ в обслуживании (DoS)

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
redos логотип
ROS-20240916-07

Уязвимость nodejs

CVSS3: 6.5
1%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:0733-1

Security update for nodejs12

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0732-1

Security update for nodejs14

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0731-1

Security update for nodejs16

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0729-1

Security update for nodejs16

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0728-1

Security update for nodejs16

больше 2 лет назад
rocky логотип
RLSA-2024:2910

Important: nodejs security update

около 2 лет назад
rocky логотип
RLSA-2024:2853

Important: nodejs:20 security update

около 2 лет назад
rocky логотип
RLSA-2024:2780

Important: nodejs:18 security update

около 2 лет назад
rocky логотип
RLSA-2024:2779

Important: nodejs:18 security update

около 2 лет назад
rocky логотип
RLSA-2024:2778

Important: nodejs:20 security update

около 2 лет назад
oracle-oval логотип
ELSA-2024-2910

ELSA-2024-2910: nodejs security update (IMPORTANT)

около 2 лет назад
oracle-oval логотип
ELSA-2024-2853

ELSA-2024-2853: nodejs:20 security update (IMPORTANT)

около 2 лет назад

Уязвимостей на страницу