Nodejs

Node.Js

197 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 8.04%
  • Veröffentlicht 10.10.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.

  • EPSS 54.39%
  • Veröffentlicht 28.09.2017 01:29:02
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

  • EPSS 4.98%
  • Veröffentlicht 20.09.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).

  • EPSS 5.48%
  • Veröffentlicht 25.07.2017 13:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. ...

  • EPSS 3.31%
  • Veröffentlicht 07.07.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.

  • EPSS 4.79%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 14.07.2026 12:16:45

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

  • EPSS 7.55%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 14.07.2026 12:16:45

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

  • EPSS 5.2%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 14.07.2026 12:16:46

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

  • EPSS 5.77%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

  • EPSS 14.23%
  • Veröffentlicht 04.05.2017 20:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA...