CVE-2015-2311 — Integer Underflow (Wrap or Wraparound) in Capnproto
CWE-191 — Integer Underflow (Wrap or Wraparound)CWE-125 — Out-of-bounds ReadCWE-416 — Use After FreeCWE-352 — Cross-Site Request ForgeryCWE-305 — Authentication Bypass by Primary WeaknessCWE-122 — Heap-based Buffer OverflowCWE-704 — Incorrect Type Conversion or CastCWE-787 — Out-of-bounds Write21 documents6 sources
Severity
9.8CRITICALNVD
EPSS
1.0%
top 23.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 9
Latest updateMay 17
Description
Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information from memory or execute arbitrary code via a crafted message.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9