Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

22232425262024202520262027202820292030

Релизные элементы

KBВерсияБилдДата доступности
24.21.024.21.0
24.20.024.20.0
24.19.024.19.0
24.18.124.18.1
24.18.024.18.0
24.17.024.17.0
24.16.024.16.0
24.15.024.15.0
24.14.124.14.1
24.14.024.14.0

Показывать по

Недавние уязвимости Node.js

Количество 1 270

redhat логотип

CVE-2017-15897

почти 9 лет назад

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2017-15896

почти 9 лет назад

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2021-03037

почти 9 лет назад

Уязвимость процедуры AVX2 Montgomery библиотеки OpenSSL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2017-14919

почти 9 лет назад

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows r ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-14919

почти 9 лет назад

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14919

почти 9 лет назад

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-14352

почти 9 лет назад

Уязвимость модуля zlib компонента Node.js программного обеспечения для проектирования CADRA, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5726-g6r9-5f22

почти 9 лет назад

Potential for Script Injection in syntax-error

EPSS: Средний
github логотип

GHSA-rh6c-q938-3r9q

почти 9 лет назад

Moderate severity vulnerability that affects validator

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-552w-rqg8-gxxm

почти 9 лет назад

Moderate severity vulnerability that affects validator

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2017-15897

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

CVSS3: 3.7
2%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-15896

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

CVSS3: 5.9
2%
Низкий
почти 9 лет назад
fstec логотип
BDU:2021-03037

Уязвимость процедуры AVX2 Montgomery библиотеки OpenSSL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.9
13%
Средний
почти 9 лет назад
debian логотип
CVE-2017-14919

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows r ...

CVSS3: 7.5
8%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-14919

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
8%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14919

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
8%
Низкий
почти 9 лет назад
fstec логотип
BDU:2026-14352

Уязвимость модуля zlib компонента Node.js программного обеспечения для проектирования CADRA, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
8%
Низкий
почти 9 лет назад
github логотип
GHSA-5726-g6r9-5f22

Potential for Script Injection in syntax-error

13%
Средний
почти 9 лет назад
github логотип
GHSA-rh6c-q938-3r9q

Moderate severity vulnerability that affects validator

CVSS3: 6.1
2%
Низкий
почти 9 лет назад
github логотип
GHSA-552w-rqg8-gxxm

Moderate severity vulnerability that affects validator

CVSS3: 6.1
2%
Низкий
почти 9 лет назад

Уязвимостей на страницу


Поделиться