Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47307
HistoryJun 03, 2024 - 6:25 a.m.

Memory Exhaustion

2024-06-0306:25:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
memory exhaustion
dos attack
input size restrictions
application crash
vulnerability
crafted input

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0

Percentile

15.5%

braces is vulnerable to Memory Exhaustion. The vulnerability is due to improper input size restrictions, which allows an attacker to cause a Denial of Service (DoS) via crafted large imbalanced input to the braces() method, leading to memory exhaustion and eventual application crash.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0

Percentile

15.5%