Nodejs

Node.Js

167 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Published 10.10.2016 16:59:00
  • Last modified 12.04.2025 10:46:40

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response s...

  • EPSS 19.37%
  • Published 03.10.2016 15:59:03
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

  • EPSS 13.86%
  • Published 26.09.2016 19:59:07
  • Last modified 12.04.2025 10:46:40

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

  • EPSS 9%
  • Published 26.09.2016 19:59:02
  • Last modified 12.04.2025 10:46:40

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

  • EPSS 20.28%
  • Published 26.09.2016 19:59:00
  • Last modified 12.04.2025 10:46:40

Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.

  • EPSS 1.49%
  • Published 25.09.2016 20:59:04
  • Last modified 12.04.2025 10:46:40

The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.

  • EPSS 32.88%
  • Published 16.09.2016 05:59:13
  • Last modified 12.04.2025 10:46:40

Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vect...

Media report
  • EPSS 40.02%
  • Published 01.09.2016 00:59:00
  • Last modified 12.04.2025 10:46:40

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birth...

  • EPSS 2.39%
  • Published 02.07.2016 14:59:19
  • Last modified 12.04.2025 10:46:40

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive ...

  • EPSS 0.33%
  • Published 20.06.2016 01:59:03
  • Last modified 12.04.2025 10:46:40

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.