CVE Database · CVE-2018-1041
CVSS v3.1
N/A
EPSS
15.53%
Published
Feb 15, 2018
Modified
Nov 21, 2024
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.
Weaknesses (CWE)
Affected Products (6)
References (16)