CVE-2015-9242
Last modified
CVE-2015-9242 is a vulnerability of currently unknown severity. Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header.. EPSS estimates a 2.09% chance of exploitation in the next 30 days.
Description
Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ecstatic Project | Ecstatic | < 1.4.0 |
References
- https://bugs.chromium.org/p/v8/issues/detail?id=4640Issue Tracking, Third Party Advisory
- https://github.com/jfhbrook/node-ecstatic/pull/179Issue Tracking, Third Party Advisory
- https://nodesecurity.io/advisories/64Third Party Advisory
- https://bugs.chromium.org/p/v8/issues/detail?id=4640Issue Tracking, Third Party Advisory
- https://github.com/jfhbrook/node-ecstatic/pull/179Issue Tracking, Third Party Advisory
- https://nodesecurity.io/advisories/64Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-9242?
How severe is CVE-2015-9242?
How do I fix CVE-2015-9242?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-9235In jsonwebtoken node module before 4.2.2 it is possible for …
- CVE-2015-9236Hapi versions less than 11.0.0 implement CORS incorrectly an…
- CVE-2015-9238secure-compare 3.0.0 and below do not actually compare two s…
- CVE-2015-9239ansi2html is vulnerable to regular expression denial of serv…7.5
- CVE-2015-9240Due to a bug in the the default sign in functionality in the…
- CVE-2015-9241Certain input passed into the If-Modified-Since or Last-Modi…
- CVE-2015-9243When server level, connection level or route level CORS conf…
- CVE-2015-9244Keys of objects in mysql node module v2.0.0-alpha7 and earli…9.8
- CVE-2015-9245Insecure default configuration in Progress Software OpenEdge…
- CVE-2015-9246An issue was discovered in Skybox Platform before 7.5.201. R…
- CVE-2015-9247An issue was discovered in Skybox Platform before 7.5.401. R…
- CVE-2015-9248An issue was discovered in Skybox Platform before 7.5.201. S…
Are you affected by CVE-2015-9242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
