CVE-2014-5256

Nodejs - Memory Corruption

Title source: rule

Description

Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage collection in conjunction with a V8 interrupt, which allows remote attackers to cause a denial of service (memory corruption and application crash) via deep JSON objects whose parsing lets this interrupt mask an overflow of the program stack.

Scores

EPSS 0.0126
EPSS Percentile 79.2%

Classification

CWE
CWE-119
Status draft

Affected Products (50)

nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
... and 35 more

Timeline

Published Sep 05, 2014
Tracked Since Feb 18, 2026