napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
2020-07-24T22:15:12.280
2024-11-21T05:38:26.300
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nodejs | node.js | < 10.21.0 | Yes |
Application | nodejs | node.js | < 12.18.0 | Yes |
Application | nodejs | node.js | < 14.4.0 | Yes |
Application | oracle | banking_extensibility_workbench | 14.3.0 | Yes |
Application | oracle | banking_extensibility_workbench | 14.4.0 | Yes |
Application | oracle | blockchain_platform | < 21.1.2 | Yes |
Application | oracle | mysql_cluster | ≤ 7.3.30 | Yes |
Application | oracle | mysql_cluster | ≤ 7.4.29 | Yes |
Application | oracle | mysql_cluster | ≤ 7.5.19 | Yes |
Application | oracle | mysql_cluster | ≤ 7.6.15 | Yes |
Application | oracle | mysql_cluster | ≤ 8.0.21 | Yes |
Application | oracle | retail_xstore_point_of_service | 16.0.6 | Yes |
Application | oracle | retail_xstore_point_of_service | 17.0.4 | Yes |
Application | oracle | retail_xstore_point_of_service | 18.0.3 | Yes |
Application | oracle | retail_xstore_point_of_service | 19.0.2 | Yes |
Application | oracle | retail_xstore_point_of_service | 20.0.1 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | oncommand_insight | - | Yes |
Application | netapp | oncommand_workflow_automation | - | Yes |
Application | netapp | snapcenter | - | Yes |