CVE-2019-12207
published 2019-05-20CVE-2019-12207: njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c.
PriorityP337critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.82%
76.2th percentile
njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | njs | <= 0.3.3 | — |
| f5 | njs | <= 0.3.1 | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1709 | — | — |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1903 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_version_1803 | — | — |
| msrc | windows_server_version_1903 | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat6.5MEDIUM
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jqp9-4g4m-74gq: njs through 0
ghsa_unreviewed·2022-05-24
CVE-2019-12207 [CRITICAL] CWE-125 GHSA-jqp9-4g4m-74gq: njs through 0
njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c.
GHSA
GHSA-7q32-cwfh-9pj6: njs through 0
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2019-13067 [CRITICAL] CWE-125 GHSA-7q32-cwfh-9pj6: njs through 0
njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.
Microsoft
Windows Denial of Service Vulnerability
vendor_msrc·2019-11-12·CVSS 4.7
CVE-2018-12207 [MEDIUM] Windows Denial of Service Vulnerability
Windows Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but it could be used to cause a target system to stop responding.
The update addresses the vulnerability by correcting how Windows handles objects in memory.
FAQ: Why is Microsoft documenting a CVE that was issued by Intel?
On November 12, 2019, Intel published a technical advisory around Intel® Processor Machine Check Er
VMware
VMware ESXi, Workstation, and Fusion patches provide Hypervisor-Specific Mitigations for Denial-of-Service and Speculative-Execution Vulnerabilities (CVE-2018-12207, CVE-2019-11135)
vendor_vmware·2019-11-12·CVSS 6.5
CVE-2018-12207 [MEDIUM] VMware ESXi, Workstation, and Fusion patches provide Hypervisor-Specific Mitigations for Denial-of-Service and Speculative-Execution Vulnerabilities (CVE-2018-12207, CVE-2019-11135)
VMSA-2019-0020: VMware ESXi, Workstation, and Fusion patches provide Hypervisor-Specific Mitigations for Denial-of-Service and Speculative-Execution Vulnerabilities (CVE-2018-12207, CVE-2019-11135)
| Advisory Severity | Moderate | Synopsis | VMware ESXi, Workstation, and Fusion patches provide Hypervisor-Specific Mitigations for Denial-of-Service and Speculative-Execution Vulnerabilities (CVE-2018-12207, CVE-2019-11135) | Issue Date | 2019-11-12 | Updated On | 2019-11-12 (Initial Advisory) | CVE(s) | CVE-2018-12207, CVE-2019-11135
CVEs: CVE-2018-12207, CVE-2019-11135
Affected products: VMware ESXi, VMware Fusion, VMware Workstation, vSphere
No detection rules found.
No public exploits indexed.
2019-05-20
Published