6.4
CVSSv2

CVE-2012-2330

Published: 13/08/2012 Updated: 13/02/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The Update method in src/node_http_parser.cc in Node.js prior to 0.6.17 and 0.7 prior to 0.7.8 does not properly check the length of a string, which allows remote malicious users to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.

Vulnerable Product Search on Vulmon Subscribe to Product

nodejs nodejs

nodejs nodejs 0.7.6

nodejs nodejs 0.7.4

nodejs nodejs 0.7.5

nodejs nodejs 0.7.3

nodejs nodejs 0.7.0

nodejs nodejs 0.7.2

nodejs nodejs 0.7.7

nodejs nodejs 0.7.1