Логотип exploitDog
bind:CVE-2024-1300
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-1300

Количество 4

Количество 4

redhat логотип

CVE-2024-1300

около 2 лет назад

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-1300

почти 2 года назад

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-9ph3-v2vh-3qx7

почти 2 года назад

Eclipse Vert.x vulnerable to a memory leak in TCP servers

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2024-09483

около 2 лет назад

Уязвимость набора инструментов Eclipse Vert.x, связанная с утечкой памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-1300

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-1300

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-9ph3-v2vh-3qx7

Eclipse Vert.x vulnerable to a memory leak in TCP servers

CVSS3: 5.4
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-09483

Уязвимость набора инструментов Eclipse Vert.x, связанная с утечкой памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 5.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу