Vulnerabilities
Vulnerable Software
Erlang:  >> Erlang/otp  >> 19.2  Security Vulnerabilities
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
CVSS Score
6.1
EPSS Score
0.014
Published
2019-12-10
An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.
CVSS Score
9.8
EPSS Score
0.015
Published
2017-03-18


Contact Us

Shodan ® - All rights reserved