Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-22918
Description:Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of- bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().
Test IDs: 1.3.6.1.4.1.25623.1.0.146280   1.3.6.1.4.1.25623.1.0.844996   1.3.6.1.4.1.25623.1.0.704936   1.3.6.1.4.1.25623.1.1.10.2021.0360  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-22918
https://security.gentoo.org/glsa/202401-23
https://hackerone.com/reports/1209681
https://hackerone.com/reports/1209681
https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/
https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/




© 1998-2025 E-Soft Inc. All rights reserved.