9.3

CVE-2020-8174

Exploit
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nodejs ≫ Node.Js SwEdition - Version < 10.21.0
Nodejs ≫ Node.Js SwEdition - Version >= 12.0.0 < 12.18.0
Nodejs ≫ Node.Js SwEdition - Version >= 14.0.0 < 14.4.0
Oracle ≫ Blockchain Platform Version < 21.1.2
Oracle ≫ Mysql Cluster Version <= 7.3.30
Oracle ≫ Mysql Cluster Version >= 7.4.0 <= 7.4.29
Oracle ≫ Mysql Cluster Version >= 7.5.0 <= 7.5.19
Oracle ≫ Mysql Cluster Version >= 7.6.0 <= 7.6.15
Oracle ≫ Mysql Cluster Version >= 8.0.0 <= 8.0.21
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Snapcenter Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.65% 0.938
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-191 Integer Underflow (Wrap or Wraparound)

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://security.gentoo.org/glsa/202101-07
Third Party Advisory
https://security.netapp.com/advisory/ntap-20201023-0003/
Third Party Advisory
https://hackerone.com/reports/784186
Third Party Advisory
Exploit