8.1
CVE-2016-10578
- EPSS 0.16%
- Veröffentlicht 29.05.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 02:44:18
- Quelle support@hackerone.com
- CVE-Watchlists
- Unerledigt
unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Unicode Project ≫ Unicode SwPlatformnode.js Version < 9.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.379 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-311 Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.