Логотип exploitDog
bind:CVE-2020-8265
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-8265

Количество 22

Количество 22

ubuntu логотип

CVE-2020-8265

больше 4 лет назад

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2020-8265

больше 4 лет назад

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2020-8265

больше 4 лет назад

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2020-8265

больше 4 лет назад

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerab ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-879w-9vpf-9pw9

около 3 лет назад

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2021-00883

больше 4 лет назад

Уязвимость реализации метода DoWrite программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0107-1

больше 4 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0082-1

больше 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0066-1

больше 4 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0065-1

больше 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0082-1

больше 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0068-1

больше 4 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0061-1

больше 4 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0060-1

больше 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0064-1

больше 4 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0062-1

больше 4 лет назад

Security update for nodejs12

EPSS: Низкий
oracle-oval логотип

ELSA-2021-0549

больше 4 лет назад

ELSA-2021-0549: nodejs:12 security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2021:0551

больше 4 лет назад

Moderate: nodejs:14 security and bug fix update

EPSS: Низкий
rocky логотип

RLSA-2021:0549

больше 4 лет назад

Moderate: nodejs:12 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-0551

больше 4 лет назад

ELSA-2021-0551: nodejs:14 security and bug fix update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-8265

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2020-8265

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-8265

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-8265

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerab ...

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-879w-9vpf-9pw9

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVSS3: 8.1
1%
Низкий
около 3 лет назад
fstec логотип
BDU:2021-00883

Уязвимость реализации метода DoWrite программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0107-1

Security update for nodejs14

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0082-1

Security update for nodejs10

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0066-1

Security update for nodejs14

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0065-1

Security update for nodejs10

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0082-1

Security update for nodejs10

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0068-1

Security update for nodejs12

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0061-1

Security update for nodejs14

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0060-1

Security update for nodejs10

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0064-1

Security update for nodejs12

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0062-1

Security update for nodejs12

больше 4 лет назад
oracle-oval логотип
ELSA-2021-0549

ELSA-2021-0549: nodejs:12 security update (MODERATE)

больше 4 лет назад
rocky логотип
RLSA-2021:0551

Moderate: nodejs:14 security and bug fix update

больше 4 лет назад
rocky логотип
RLSA-2021:0549

Moderate: nodejs:12 security update

больше 4 лет назад
oracle-oval логотип
ELSA-2021-0551

ELSA-2021-0551: nodejs:14 security and bug fix update (MODERATE)

больше 4 лет назад

Уязвимостей на страницу