CVE-2016-2216
- EPSS 1.84%
- Veröffentlicht 07.04.2016 21:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded U...
CVE-2016-2086
- EPSS 0.48%
- Veröffentlicht 07.04.2016 21:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
CVE-2016-0797
- EPSS 34.19%
- Veröffentlicht 03.03.2016 20:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit stri...
CVE-2016-0702
- EPSS 0.46%
- Veröffentlicht 03.03.2016 20:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discov...
CVE-2015-8027
- EPSS 1.39%
- Veröffentlicht 02.01.2016 21:59:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined ...
CVE-2015-3194
- EPSS 51.9%
- Veröffentlicht 06.12.2015 20:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function p...
CVE-2015-3193
- EPSS 30.47%
- Veröffentlicht 06.12.2015 20:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for r...
CVE-2015-6764
- EPSS 13.88%
- Veröffentlicht 06.12.2015 01:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service ...
CVE-2015-5380
- EPSS 0.62%
- Veröffentlicht 09.07.2015 10:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair...
- EPSS 1.59%
- Veröffentlicht 18.05.2015 15:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.