← Volver a CVEs
CVE-2014-0086
N/ADescripcion
The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado3/31/2014
Ultima modificacion4/12/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
redhat:jboss_web_framework_kitredhat:richfaces
Debilidades (CWE)
CWE-20
Referencias
http://rhn.redhat.com/errata/RHSA-2014-0335.html(secalert@redhat.com)
http://secunia.com/advisories/57053(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=1067268(secalert@redhat.com)
https://github.com/pslegr/core-1/commit/8131f15003f5bec73d475d2b724472e4b87d0757(secalert@redhat.com)
https://issues.jboss.org/browse/RF-13250(secalert@redhat.com)
http://rhn.redhat.com/errata/RHSA-2014-0335.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/57053(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=1067268(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/pslegr/core-1/commit/8131f15003f5bec73d475d2b724472e4b87d0757(af854a3a-2127-422b-91ae-364da2661108)
https://issues.jboss.org/browse/RF-13250(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.