nginx njs CVE-2019-13617 in NGINX and F5 Networks Products
Published on July 16, 2019

product logo product logo
njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call.

NVD


Products Associated with CVE-2019-13617

stack.watch emails you whenever new vulnerabilities are published in NGINX Njs or F5 Networks Njs. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
0.29%
Percentile
52.00%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.