Логотип exploitDog
bind:CVE-2024-52804
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-52804

Количество 11

Количество 11

ubuntu логотип

CVE-2024-52804

7 месяцев назад

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-52804

7 месяцев назад

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-52804

7 месяцев назад

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-52804

7 месяцев назад

Tornado is a Python web framework and asynchronous networking library. ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4137-1

7 месяцев назад

Security update for python-tornado6

EPSS: Низкий
redos логотип

ROS-20250121-06

5 месяцев назад

Уязвимость python3-tornado

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8w49-h785-mj3c

7 месяцев назад

Tornado has an HTTP cookie parsing DoS vulnerability

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2025-2872

3 месяца назад

ELSA-2025-2872: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-2471

3 месяца назад

ELSA-2025-2471: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10590

7 месяцев назад

ELSA-2024-10590: python-tornado security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-00918

7 месяцев назад

Уязвимость асинхронной сетевой библиотеки Tornado, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-52804

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
redhat логотип
CVE-2024-52804

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2024-52804

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-52804

Tornado is a Python web framework and asynchronous networking library. ...

CVSS3: 7.5
0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4137-1

Security update for python-tornado6

0%
Низкий
7 месяцев назад
redos логотип
ROS-20250121-06

Уязвимость python3-tornado

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-8w49-h785-mj3c

Tornado has an HTTP cookie parsing DoS vulnerability

CVSS3: 7.5
0%
Низкий
7 месяцев назад
oracle-oval логотип
ELSA-2025-2872

ELSA-2025-2872: pcs security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2025-2471

ELSA-2025-2471: pcs security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2024-10590

ELSA-2024-10590: python-tornado security update (IMPORTANT)

7 месяцев назад
fstec логотип
BDU:2025-00918

Уязвимость асинхронной сетевой библиотеки Tornado, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
7 месяцев назад

Уязвимостей на страницу