CVE-2014-3488

Netty < 3.9.1.1 - Memory Corruption

Title source: rule

Description

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

Exploits (2)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2014-3488-netty-vulnerable
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2014-3488-netty-vulnerable

Scores

EPSS 0.0087
EPSS Percentile 75.2%

Details

CWE
CWE-119
Status published
Products (16)
io.netty/netty-handler 0 - 3.9.2Maven
netty/netty 3.6.0
netty/netty 3.6.1
netty/netty 3.6.2
netty/netty 3.6.3
netty/netty 3.6.4
netty/netty 3.6.5
netty/netty 3.6.6
netty/netty 3.6.7
netty/netty 3.6.8
... and 6 more
Published Jul 31, 2014
Tracked Since Feb 18, 2026