The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade electron
to version 6.1.10, 7.2.2, 8.2.0 or higher.
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.
Affected versions of this package are vulnerable to Out-of-bounds Read. The input to sctp_load_addresses_from_init
is verified by calling sctp_arethere_unrecognized_parameters
, however there is a difference in how these functions handle parameter bounds. The function sctp_arethere_unrecognized_parameters
does not process a parameter that is partially outside of the limit of the chunk, meanwhile, sctp_load_addresses_from_init
will continue processing until a parameter that is entirely outside of the chunk occurs.
This means that the last parameter of a chunk is not always verified, which can lead to parameters with very short plen
values being processed by sctp_load_addresses_from_init
. This can lead to out-of-bounds reads whenever the plen
is subtracted from the header len
.