CVE-2018-21270 PUBLISHED

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

EPSS 0.53% · 67.0th percentile

Risk Scores

EPSS Score
0.53%
67.0th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSnode-stringstream0, 0.0.5-1

Timeline

References

Open in Interactive Console →