Total vulnerabilities in the database
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
Software | From | Fixed in |
---|---|---|
nodejs / node.js | 15.0.0 | 15.10.0 |
nodejs / node.js | 14.0.0 | 14.16.0 |
nodejs / node.js | 12.0.0 | 12.21.0 |
nodejs / node.js | 10.0.0 | 10.24.0 |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |
fedoraproject / fedora | 34 | 34.x |
oracle / peoplesoft_enterprise_peopletools | 8.58 | 8.58.x |
oracle / graalvm | 20.3.1.2 | 20.3.1.2.x |
oracle / graalvm | 21.0.0.2 | 21.0.0.2.x |
oracle / graalvm | 19.3.5 | 19.3.5.x |
oracle / nosql_database | - | 20.3 |
oracle / mysql_cluster | - | 8.0.25.x |
oracle / peoplesoft_enterprise_peopletools | 8.59 | 8.59.x |
oracle / jd_edwards_enterpriseone_tools | - | 9.2.6.0 |
siemens / sinec_infrastructure_network_services | - | 1.0.1.1 |