Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2j2-5fh3-4jrr

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

EPSS

Процентиль: 61%
0.00425
Низкий

3.1 Low

CVSS3

Дефекты

CWE-200
CWE-665

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 7 лет назад

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

CVSS3: 3.7
redhat
больше 7 лет назад

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

CVSS3: 3.1
nvd
больше 7 лет назад

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

CVSS3: 3.1
debian
больше 7 лет назад

Node.js had a bug in versions 8.X and 9.X which caused buffers to not ...

suse-cvrf
больше 5 лет назад

Security update for Mozilla Firefox

EPSS

Процентиль: 61%
0.00425
Низкий

3.1 Low

CVSS3

Дефекты

CWE-200
CWE-665