Vulnerabilities > CVE-2022-25867 - NULL Pointer Dereference vulnerability in Socket Socket.Io-Client Java

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
socket
CWE-476

Summary

The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.

Vulnerable Configurations

Part Description Count
Application
Socket
1

Common Weakness Enumeration (CWE)