CVE-2022-1543
Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
- EPSS probability
- 0.41%
- CWE
- CWE-130
- Published
- 2022-04-29
- Last modified
- 2026-03-13
Affected products
- erudika erudika/scoold
Weakness type
Related vulnerabilities
- CVE-2025-14847 — Zlib compressed protocol header length confusion may allow memory read
- CVE-2026-22861 — iccDEV has a heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-22255 — iccDEV has heap-buffer-overflow in CIccCLUT::Init() at IccProfLib/IccTagLut.cpp
- CVE-2026-22047 — iccDEV has heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-22046 — iccDEV has heap-buffer-overflow in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
- CVE-2025-30659 — Junos OS: SRX Series: A device configured for vector routing crashes when receiving malformed traffic
- CVE-2022-20870 — Cisco IOS XE Software for Catalyst Switches MPLS Denial of Service Vulnerability
- CVE-2024-37305 — Buffer overflow in deserialization in oqs-provider