Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47379
HistoryJun 06, 2024 - 4:12 a.m.

Out-of-Bounds-Read

2024-06-0604:12:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
out-of-bounds-read
org.iq80.snappy
jdk class
unsafe
memory access
bounds checks
non-deterministic behavior
jvm crash
vulnerability

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

9.0%

org.iq80.snappy: snappy is vulnerable to Out-of-Bounds-Read. The vulnerability is due to the usage of the JDK class sun.misc.Unsafe to speed up memory access without performing additional bounds checks, which can result in non-deterministic behavior or a JVM crash.

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

9.0%