CVE-2015-9242

HIGH

ecstatic < 1.4.0 - Denial of Service via If-Modified-Since Header

Title source: llm
STIX 2.1

Description

Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header.

References (3)

Core 3
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/jfhbrook/node-ecstatic/pull/179
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/v8/issues/detail?id=4640
Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/64

Scores

CVSS v3 7.5
EPSS 0.0209
EPSS Percentile 79.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-20 CWE-400
Status published
Products (2)
ecstatic_project/ecstatic < 1.4.0
npm/ecstatic 0 - 1.4.0npm
Published May 29, 2018
Tracked Since Feb 18, 2026