CVE-2017-14919
CADRA, node.js
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
- CVSS
- 7.5
- EPSS
- 8.24% 94.3% percentile
- CISA KEV
- Not listed
- Published
- 2017.10.31