Vulnerability Details CVE-2017-14919
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 76.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-14919
-
cpe:2.3:a:nodejs:node.js:4.8.2
-
cpe:2.3:a:nodejs:node.js:4.8.3
-
cpe:2.3:a:nodejs:node.js:4.8.4
-
cpe:2.3:a:nodejs:node.js:6.10.2
-
cpe:2.3:a:nodejs:node.js:6.10.3
-
cpe:2.3:a:nodejs:node.js:6.11.0
-
cpe:2.3:a:nodejs:node.js:6.11.1
-
cpe:2.3:a:nodejs:node.js:6.11.2
-
cpe:2.3:a:nodejs:node.js:6.11.3
-
cpe:2.3:a:nodejs:node.js:6.11.4
-
cpe:2.3:a:nodejs:node.js:8.0.0
-
cpe:2.3:a:nodejs:node.js:8.1.0
-
cpe:2.3:a:nodejs:node.js:8.1.1
-
cpe:2.3:a:nodejs:node.js:8.1.2
-
cpe:2.3:a:nodejs:node.js:8.1.3
-
cpe:2.3:a:nodejs:node.js:8.1.4
-
cpe:2.3:a:nodejs:node.js:8.2.0
-
cpe:2.3:a:nodejs:node.js:8.2.1
-
cpe:2.3:a:nodejs:node.js:8.3.0
-
cpe:2.3:a:nodejs:node.js:8.4.0
-
cpe:2.3:a:nodejs:node.js:8.5.0
-
cpe:2.3:a:nodejs:node.js:8.6.0
-
cpe:2.3:a:nodejs:node.js:8.7.0