CVE-2014-3742
hapi server framework 2.0.x-2.1.x - Denial of Service via File Descriptor Consumption
Title source: llmDescription
The hapi server framework 2.0.x and 2.1.x before 2.2.0 for Node.js allows remote attackers to cause a denial of service (file descriptor consumption and process crash) via unspecified vectors.
References (4)
Core 4
Core References
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/05/15/2
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/05/13/1
Issue Tracking x_refsource_confirm
https://github.com/spumko/hapi/issues/1427
Vendor Advisory x_refsource_misc
https://nodesecurity.io/advisories/hapi_File_descriptor_leak_DoS_vulnerability
Scores
EPSS
0.0237
EPSS Percentile
82.1%
Details
CWE
CWE-399
Status
published
Products (4)
npm/hapi
2.0.0 - 2.2.0npm
spumko_project/hapi_server_framework
2.0.0 (2 CPE variants)
spumko_project/hapi_server_framework
2.1.1
spumko_project/hapi_server_framework
2.1.2
Published
May 16, 2014
Tracked Since
Feb 18, 2026