CVE-2014-7191
Title: Nodejs Node.Js Denial of Service (DoS)
DoS
Proof Of Concept
No public PoC currently indexed for CVE-2014-7191.
CWE Category
CWE-399
Published Date
Oct 19, 2014
Modified Date
May 06, 2026
Exploit Status
Not Found
Score
5.0
CVSS v2.0
Exploit Probability (EPSS)
0.69%
Vulnerability Summary
CVE-2014-7191: The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
Impacted Vendors
Reference Links
http://secunia.com/advisories/60026
http://secunia.com/advisories/62170
http://www-01.ibm.com/support/docview.wss?uid=swg21685987
http://www-01.ibm.com/support/docview.wss?uid=swg21687263
http://www-01.ibm.com/support/docview.wss?uid=swg21687928
https://access.redhat.com/errata/RHSA-2016:1380
https://exchange.xforce.ibmcloud.com/vulnerabilities/96729
https://github.com/raymondfeng/node-querystring/commit/43a604b7847e56bba49d0ce3e222fe89569354d8
https://github.com/visionmedia/node-querystring/issues/104
https://nodesecurity.io/advisories/qs_dos_memory_exhaustion
http://secunia.com/advisories/60026
http://secunia.com/advisories/62170
http://www-01.ibm.com/support/docview.wss?uid=swg21685987
http://www-01.ibm.com/support/docview.wss?uid=swg21687263
http://www-01.ibm.com/support/docview.wss?uid=swg21687928
https://access.redhat.com/errata/RHSA-2016:1380
https://exchange.xforce.ibmcloud.com/vulnerabilities/96729
https://github.com/raymondfeng/node-querystring/commit/43a604b7847e56bba49d0ce3e222fe89569354d8
https://github.com/visionmedia/node-querystring/issues/104
https://nodesecurity.io/advisories/qs_dos_memory_exhaustion
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
5.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:N/C:N/I:N/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2014-7191 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected Stack
No specific products linked.