Nodejs

Node.Js

174 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 25.07.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. ...

  • EPSS 0.42%
  • Veröffentlicht 07.07.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.

  • EPSS 13%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

  • EPSS 20.28%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

  • EPSS 13.69%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 04.12.2025 17:15:51

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

  • EPSS 7.98%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

  • EPSS 2%
  • Veröffentlicht 04.05.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA...

  • EPSS 10.4%
  • Veröffentlicht 04.05.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can ...

  • EPSS 7.58%
  • Veröffentlicht 04.05.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be...

  • EPSS 0.77%
  • Veröffentlicht 23.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.