Логотип exploitDog
bind:CVE-2024-27983
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-27983

Количество 22

Количество 22

ubuntu логотип

CVE-2024-27983

около 1 года назад

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.

CVSS3: 8.2
EPSS: Средний
redhat логотип

CVE-2024-27983

около 1 года назад

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2024-27983

около 1 года назад

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.

CVSS3: 8.2
EPSS: Средний
msrc логотип

CVE-2024-27983

около 1 года назад

CVSS3: 8.2
EPSS: Средний
debian логотип

CVE-2024-27983

около 1 года назад

An attacker can make the Node.js HTTP/2 server completely unavailable ...

CVSS3: 8.2
EPSS: Средний
github логотип

GHSA-j65r-8hrg-qc6x

около 1 года назад

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.

CVSS3: 8.2
EPSS: Средний
fstec логотип

BDU:2024-02689

около 1 года назад

Уязвимость функции node::http2::Http2Session::~Http2Session() HTTP/2-сервера программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:1355-1

около 1 года назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1346-1

около 1 года назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1308-1

около 1 года назад

Security update for nodejs16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1306-1

около 1 года назад

Security update for nodejs16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1305-1

около 1 года назад

Security update for nodejs16

EPSS: Низкий
redos логотип

ROS-20240425-03

около 1 года назад

Уязвимость nodejs

CVSS3: 5.3
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:1309-1

около 1 года назад

Security update for nodejs18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1307-1

около 1 года назад

Security update for nodejs18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1301-1

около 1 года назад

Security update for nodejs20

EPSS: Низкий
rocky логотип

RLSA-2024:2910

около 1 года назад

Important: nodejs security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2910

около 1 года назад

ELSA-2024-2910: nodejs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2853

около 1 года назад

ELSA-2024-2853: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2780

около 1 года назад

ELSA-2024-2780: nodejs:18 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-27983

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.

CVSS3: 8.2
69%
Средний
около 1 года назад
redhat логотип
CVE-2024-27983

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.

CVSS3: 7.5
69%
Средний
около 1 года назад
nvd логотип
CVE-2024-27983

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.

CVSS3: 8.2
69%
Средний
около 1 года назад
msrc логотип
CVSS3: 8.2
69%
Средний
около 1 года назад
debian логотип
CVE-2024-27983

An attacker can make the Node.js HTTP/2 server completely unavailable ...

CVSS3: 8.2
69%
Средний
около 1 года назад
github логотип
GHSA-j65r-8hrg-qc6x

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.

CVSS3: 8.2
69%
Средний
около 1 года назад
fstec логотип
BDU:2024-02689

Уязвимость функции node::http2::Http2Session::~Http2Session() HTTP/2-сервера программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
69%
Средний
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1355-1

Security update for nodejs14

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1346-1

Security update for nodejs12

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1308-1

Security update for nodejs16

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1306-1

Security update for nodejs16

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1305-1

Security update for nodejs16

около 1 года назад
redos логотип
ROS-20240425-03

Уязвимость nodejs

CVSS3: 5.3
69%
Средний
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1309-1

Security update for nodejs18

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1307-1

Security update for nodejs18

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1301-1

Security update for nodejs20

около 1 года назад
rocky логотип
RLSA-2024:2910

Important: nodejs security update

около 1 года назад
oracle-oval логотип
ELSA-2024-2910

ELSA-2024-2910: nodejs security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2024-2853

ELSA-2024-2853: nodejs:20 security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2024-2780

ELSA-2024-2780: nodejs:18 security update (IMPORTANT)

около 1 года назад

Уязвимостей на страницу