Nodejs

Node.Js

167 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 11.26%
  • Published 04.05.2017 19:29:00
  • Last modified 20.04.2025 01:37:25

If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can ...

  • EPSS 6.9%
  • Published 04.05.2017 19:29:00
  • Last modified 20.04.2025 01:37:25

There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be...

  • EPSS 0.77%
  • Published 23.01.2017 21:59:00
  • Last modified 20.04.2025 01:37:25

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.

  • EPSS 0.68%
  • Published 23.01.2017 21:59:00
  • Last modified 20.04.2025 01:37:25

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI.

  • EPSS 0.66%
  • Published 23.01.2017 21:59:00
  • Last modified 20.04.2025 01:37:25

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing.

  • EPSS 0.66%
  • Published 23.01.2017 21:59:00
  • Last modified 20.04.2025 01:37:25

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.

Exploit
  • EPSS 0.6%
  • Published 23.01.2017 21:59:00
  • Last modified 20.04.2025 01:37:25

The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters.

  • EPSS 1.02%
  • Published 23.01.2017 21:59:00
  • Last modified 20.04.2025 01:37:25

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

  • EPSS 0.37%
  • Published 23.01.2017 21:59:00
  • Last modified 20.04.2025 01:37:25

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

  • EPSS 0.7%
  • Published 10.10.2016 16:59:01
  • Last modified 12.04.2025 10:46:40

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to ...