CVE-2018-7167High· 7.5▾ TwilightCalling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so th…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.1%
Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.
node.js > 6.9.0, < 6.14.3node.js >= 8.9.0, < 8.11.3node.js >= 9.0.0, < 9.11.2Upgrade past the affected range:
node.js 9.11.2Connected by shared product, vendor, weakness, or advisory.
CVE-2018-7164High· 7.5Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM
CVE-2018-7161High· 7.5All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH
CVE-2018-7162High· 7.5All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH
CVE-2018-12121High· 7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed c…
CVE-2018-12122High· 7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated …
CVE-2018-12123Medium· 4.3Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed…