Nodejs Node.js 9.9.0

CPE Details

Nodejs Node.js 9.9.0
9.9.0
2018-08-07
13h06 +00:00
2020-02-10
17h04 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:nodejs:node.js:9.9.0:*:*:*:*:*:*:*

Informations

Vendor

nodejs

Product

node.js

Version

9.9.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-7164 2018-06-13 16h00 +00:00 Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.
7.5
High
CVE-2018-1000168 2018-05-08 13h00 +00:00 nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
7.5
High