CVE-2013-7452
- EPSS 0.68%
- Veröffentlicht 23.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI.
CVE-2013-7453
- EPSS 0.66%
- Veröffentlicht 23.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing.
CVE-2013-7454
- EPSS 0.66%
- Veröffentlicht 23.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.
CVE-2014-9772
- EPSS 0.6%
- Veröffentlicht 23.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters.
CVE-2015-8855
- EPSS 1.02%
- Veröffentlicht 23.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."
CVE-2015-8860
- EPSS 0.37%
- Veröffentlicht 23.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
CVE-2016-7099
- EPSS 0.72%
- Veröffentlicht 10.10.2016 16:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to ...
CVE-2016-5325
- EPSS 1%
- Veröffentlicht 10.10.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response s...
CVE-2016-5180
- EPSS 15.55%
- Veröffentlicht 03.10.2016 15:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
CVE-2016-7052
- EPSS 13.86%
- Veröffentlicht 26.09.2016 19:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.