Логотип exploitDog
bind:CVE-2023-28445
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-28445

Количество 3

Количество 3

nvd логотип

CVE-2023-28445

почти 3 года назад

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in the wild, as the only version affected is Deno 1.32.0. Deno Deploy users are not affected. The problem has been resolved by disabling resizable ArrayBuffers temporarily in Deno 1.32.1. Deno 1.32.2 will re-enable resizable ArrayBuffers with a proper fix. As a workaround, run with `--v8-flags=--no-harmony-rab-gsab` to disable resizable ArrayBuffers.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-c25x-cm9x-qqgx

почти 3 года назад

Deno improperly handles resizable ArrayBuffer

CVSS3: 9.9
EPSS: Низкий
fstec логотип

BDU:2023-02082

почти 3 года назад

Уязвимость среды выполнения для JavaScript и TypeScript Deno, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-28445

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in the wild, as the only version affected is Deno 1.32.0. Deno Deploy users are not affected. The problem has been resolved by disabling resizable ArrayBuffers temporarily in Deno 1.32.1. Deno 1.32.2 will re-enable resizable ArrayBuffers with a proper fix. As a workaround, run with `--v8-flags=--no-harmony-rab-gsab` to disable resizable ArrayBuffers.

CVSS3: 9.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-c25x-cm9x-qqgx

Deno improperly handles resizable ArrayBuffer

CVSS3: 9.9
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-02082

Уязвимость среды выполнения для JavaScript и TypeScript Deno, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.9
0%
Низкий
почти 3 года назад

Уязвимостей на страницу