CVE-2023-2968
A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.46%
- CWE
- CWE-232
- Published
- 2023-05-30
- Last modified
- 2026-03-13
Weakness type
Related vulnerabilities
- CVE-2026-21689 — iccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
- CVE-2025-20314 — A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15...
- CVE-2025-40775 — DNS message with invalid TSIG causes an assertion failure
- CVE-2025-20192 — A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE...
- CVE-2023-39915 — Crashes on parsing certain invalid RPKI objects
- CVE-2023-39914 — BER/CER/DER decoder panics on invalid input
- CVE-2023-36848 — Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet
- CVE-2022-22213 — Junos OS and Junos OS Evolved: Denial of Service (DoS) vulnerability in RPD upon receipt of specific BGP update