Nodejs

Node.Js

174 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.18%
  • Veröffentlicht 07.04.2016 21:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded U...

  • EPSS 0.45%
  • Veröffentlicht 07.04.2016 21:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

  • EPSS 14.11%
  • Veröffentlicht 03.03.2016 20:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit stri...

  • EPSS 1.62%
  • Veröffentlicht 03.03.2016 20:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discov...

  • EPSS 1.5%
  • Veröffentlicht 02.01.2016 21:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined ...

  • EPSS 56.82%
  • Veröffentlicht 06.12.2015 20:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function p...

  • EPSS 33.78%
  • Veröffentlicht 06.12.2015 20:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for r...

  • EPSS 25.16%
  • Veröffentlicht 06.12.2015 01:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service ...

  • EPSS 0.76%
  • Veröffentlicht 09.07.2015 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair...

  • EPSS 1.59%
  • Veröffentlicht 18.05.2015 15:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.