CVE-2015-2927
published 2017-09-20CVE-2015-2927: node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
PriorityP431medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
4.98%
91.4th percentile
node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| nodejs | node.js | — | — |
| uronode | uro_node | <= 1.0.5 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7c2w-7whc-jvcc: node 0
ghsa_unreviewed·2022-05-13
CVE-2015-2927 [MEDIUM] GHSA-7c2w-7whc-jvcc: node 0
node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
Red Hat
webkitgtk: use-after-free in the HTMLFormElement::prepareForSubmission() (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2013-2927 [MEDIUM] CWE-416 webkitgtk: use-after-free in the HTMLFormElement::prepareForSubmission() (WSA-2015-0001)
webkitgtk: use-after-free in the HTMLFormElement::prepareForSubmission() (WSA-2015-0001)
Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to submission for FORM elements.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Ha
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2927 node: denial of service due to incorrect SIGQUIT
bugzilla·2015-04-08·CVSS 6.5
CVE-2015-2927 [MEDIUM] CVE-2015-2927 node: denial of service due to incorrect SIGQUIT
CVE-2015-2927 node: denial of service due to incorrect SIGQUIT
The following issue was found in node:
The SIGQUIT routine fails to close the app leaving the IP sockets open and in some cases DDOS the remote site if a user "ctrl-]+q" out of a telnet session. Also the app fails to close and more can be spawned by a crafty malicious user thus bringing the system to a point of no memory available.
CVE request:
http://seclists.org/oss-sec/2015/q2/41
Debian tracking bug for this issue:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777013
Discussion:
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Bugzilla
CVE-2015-2927 node: SIGQUIT fails [fedora-all]
bugzilla·2015-04-06·CVSS 6.5
CVE-2015-2927 [MEDIUM] CVE-2015-2927 node: SIGQUIT fails [fedora-all]
CVE-2015-2927 node: SIGQUIT fails [fedora-all]
If a user does "ctrl-]+q" out of a telnet session (forcing it closed),
when node is told to quit via SIGQUIT it does not clean up properly.
For node (unlike, say, a generic telnetd), this is a relatively
important vulnerability because a TCP connection usually occurs over
a very low-bandwidth radio path.
This bug was originally filed against the Debian package, but also
affects the Fedora package. The Debian bug is available at:
* https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777013
This issue has been assigned a CVE: CVE-2015-2927.
* http://www.openwall.com/lists/oss-security/2015/04/06/3
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora 23 development cycle.
Changing version to '23'.
(As we d
Bugzilla
CVE-2013-2927 webkitgtk: use-after-free in the HTMLFormElement::prepareForSubmission() (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 6.8
CVE-2013-2927 [MEDIUM] CVE-2013-2927 webkitgtk: use-after-free in the HTMLFormElement::prepareForSubmission() (WSA-2015-0001)
CVE-2013-2927 webkitgtk: use-after-free in the HTMLFormElement::prepareForSubmission() (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2013-2927
Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to submission for FORM elements.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1186276]
---
Created webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1181092]
---
Statement:
Red
http://www.openwall.com/lists/oss-security/2015/04/06/3https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777013https://bugzilla.redhat.com/show_bug.cgi?id=1209781https://support.f5.com/csp/article/K64462543?utm_source=f5support&%3Butm_medium=RSShttp://www.openwall.com/lists/oss-security/2015/04/06/3https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777013https://bugzilla.redhat.com/show_bug.cgi?id=1209781https://support.f5.com/csp/article/K64462543?utm_source=f5support&%3Butm_medium=RSS
2017-09-20
Published