CVE-2019-11837 in NGINX and F5 Networks Products
Published on May 9, 2019
njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related to nxt_utf8_next in nxt/nxt_utf8.h and njs_string_offset in njs/njs_string.c.
Products Associated with CVE-2019-11837
stack.watch emails you whenever new vulnerabilities are published in NGINX Njs or F5 Networks Njs. Just hit a watch button to start following.
Exploit Probability
EPSS
0.28%
Percentile
51.37%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.