CVE-2019-11839 in NGINX and F5 Networks Products
Published on May 9, 2019
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling.
Products Associated with CVE-2019-11839
stack.watch emails you whenever new vulnerabilities are published in NGINX Njs or F5 Networks Njs. Just hit a watch button to start following.
Exploit Probability
EPSS
0.39%
Percentile
59.59%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.