// For flags

CVE-2014-0193

netty: DoS via memory exhaustion during data aggregation

Severity Score

5.3
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames.

WebSocket08FrameDecoder en Netty 3.6.x anterior a 3.6.9, 3.7.x anterior a 3.7.1, 3.8.x anterior a 3.8.2, 3.9.x anterior a 3.9.1 y 4.0.x anterior a 4.0.19 permite a atacantes remotos causar una denegación de servicio (consumo de memoria) a través de un TextWebSocketFrame seguido por una cadena larga de ContinuationWebSocketFrames.

A flaw was found in the WebSocket08FrameDecoder implementation that could allow a remote attacker to trigger an Out Of Memory Exception by issuing a series of TextWebSocketFrame and ContinuationWebSocketFrames. Depending on the server configuration, this could lead to a denial of service.

Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7. A race condition flaw, leading to heap-based buffer overflows, was found in the mod_status httpd module. A remote attacker able to access a status page served by mod_status on a server using a threaded Multi-Processing Module could send a specially crafted request that would cause the httpd child process to crash or, possibly, allow the attacker to execute arbitrary code with the privileges of the "apache" user. A denial of service flaw was found in the way httpd's mod_deflate module handled request body decompression. A remote attacker able to send a request whose body would be decompressed could use this flaw to consume an excessive amount of system memory and CPU on the target system.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-03 CVE Reserved
  • 2014-05-06 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-07-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.6.0
Search vendor "Netty" for product "Netty" and version "3.6.0"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.6.1
Search vendor "Netty" for product "Netty" and version "3.6.1"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.6.2
Search vendor "Netty" for product "Netty" and version "3.6.2"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.6.3
Search vendor "Netty" for product "Netty" and version "3.6.3"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.6.4
Search vendor "Netty" for product "Netty" and version "3.6.4"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.6.5
Search vendor "Netty" for product "Netty" and version "3.6.5"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.6.6
Search vendor "Netty" for product "Netty" and version "3.6.6"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.6.7
Search vendor "Netty" for product "Netty" and version "3.6.7"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.6.8
Search vendor "Netty" for product "Netty" and version "3.6.8"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.7.0
Search vendor "Netty" for product "Netty" and version "3.7.0"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.8.0
Search vendor "Netty" for product "Netty" and version "3.8.0"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.8.1
Search vendor "Netty" for product "Netty" and version "3.8.1"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
3.9.0
Search vendor "Netty" for product "Netty" and version "3.9.0"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.0
Search vendor "Netty" for product "Netty" and version "4.0.0"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.1
Search vendor "Netty" for product "Netty" and version "4.0.1"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.2
Search vendor "Netty" for product "Netty" and version "4.0.2"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.3
Search vendor "Netty" for product "Netty" and version "4.0.3"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.4
Search vendor "Netty" for product "Netty" and version "4.0.4"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.5
Search vendor "Netty" for product "Netty" and version "4.0.5"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.6
Search vendor "Netty" for product "Netty" and version "4.0.6"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.7
Search vendor "Netty" for product "Netty" and version "4.0.7"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.8
Search vendor "Netty" for product "Netty" and version "4.0.8"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.9
Search vendor "Netty" for product "Netty" and version "4.0.9"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.10
Search vendor "Netty" for product "Netty" and version "4.0.10"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.11
Search vendor "Netty" for product "Netty" and version "4.0.11"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.12
Search vendor "Netty" for product "Netty" and version "4.0.12"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.13
Search vendor "Netty" for product "Netty" and version "4.0.13"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.14
Search vendor "Netty" for product "Netty" and version "4.0.14"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.15
Search vendor "Netty" for product "Netty" and version "4.0.15"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.16
Search vendor "Netty" for product "Netty" and version "4.0.16"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.17
Search vendor "Netty" for product "Netty" and version "4.0.17"
-
Affected
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
4.0.18
Search vendor "Netty" for product "Netty" and version "4.0.18"
-
Affected