Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).
This is a duplicate of GHSA-mf6x-7mm4-x2g7
{
"cwe_ids": [
"CWE-125"
],
"github_reviewed": true,
"github_reviewed_at": "2021-03-18T23:57:13Z",
"nvd_published_at": null,
"severity": "MODERATE"
}