7.5
CVSSv3

CVE-2017-14919

Published: 30/10/2017 Updated: 21/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Node.js prior to 4.8.5, 6.x prior to 6.11.5, and 8.x prior to 8.8.0 allows remote malicious users to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

nodejs node.js 4.8.3

nodejs node.js 4.8.4

nodejs node.js 6.10.2

nodejs node.js 6.10.3

nodejs node.js 8.3.0

nodejs node.js 8.4.0

nodejs node.js 8.5.0

nodejs node.js 8.6.0

nodejs node.js 6.11.1

nodejs node.js 6.11.3

nodejs node.js 8.1.2

nodejs node.js 8.1.4

nodejs node.js 8.2.1

nodejs node.js 8.7.0

nodejs node.js 6.11.4

nodejs node.js 8.0.0

nodejs node.js 8.1.0

nodejs node.js 8.1.1

nodejs node.js 4.8.2

nodejs node.js 6.11.0

nodejs node.js 6.11.2

nodejs node.js 8.1.3

nodejs node.js 8.2.0

Vendor Advisories

Nodejs before 485, 6x before 6115, and 8x before 880 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 129 making 8 an invalid value for the windowBits parameter ...