peter bassill · operator
$ cve CVE-2018-1041 JSON

CVE-2018-1041 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 15.5% (pctl 97)

Patch early

A public exploit exists.

Description

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS15.53% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-835
On CISA KEVno
Public exploityes
Published2018-02-15
Last modified2026-06-17

Affected (3)

VendorProduct
jbossjboss-remoting
redhatjboss enterprise application platform
redhatlinux

Public exploits

SourceTitleDate
exploit-dbJBoss Remoting 6.14.18 - Denial of Service2018-02-16

References

→ the Explorer  ·  watch your stack  ·  NVD