CVE-2015-2310

CRITICAL

Capnproto < 0.4.1.1 - Integer Overflow

Title source: rule
STIX 2.1

Description

Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service or possibly obtain sensitive information from memory via a crafted message, related to pointer validation.

References (4)

Core 4

Scores

CVSS v3 9.1
EPSS 0.0049
EPSS Percentile 65.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-190
Status published
Products (1)
capnproto/capnproto < 0.4.1.1
Published Aug 09, 2017
Tracked Since Feb 18, 2026