Nodejs Node.js 9.8.0

CPE Details

Nodejs Node.js 9.8.0
9.8.0
2018-08-07
13h06 +00:00
2020-02-10
17h04 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:nodejs:node.js:9.8.0:*:*:*:*:*:*:*

Informations

Vendor

nodejs

Product

node.js

Version

9.8.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2018-7164 2018-06-13 16h00 +00:00 Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.
7.5
Haute
CVE-2018-1000168 2018-05-08 13h00 +00:00 nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
7.5
Haute