Node.js — программная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 24.21.0 | 24.21.0 | ||
| 24.20.0 | 24.20.0 | ||
| 24.19.0 | 24.19.0 | ||
| 24.18.1 | 24.18.1 | ||
| 24.18.0 | 24.18.0 | ||
| 24.17.0 | 24.17.0 | ||
| 24.16.0 | 24.16.0 | ||
| 24.15.0 | 24.15.0 | ||
| 24.14.1 | 24.14.1 | ||
| 24.14.0 | 24.14.0 |
Показывать по
Количество 1 270
GHSA-q4qq-fm7q-cwp5
Multiple XSS Filter Bypasses in validator
GHSA-gfjr-3jmm-4g9v
Symlink Arbitrary File Overwrite in tar
GHSA-xwg4-93c6-3h42
Directory Traversal in send
GHSA-qpjp-7rp2-9c3f
Moderate severity vulnerability that affects validator
GHSA-jjv7-qpx3-h62q
Denial-of-Service Memory Exhaustion in qs
GHSA-x6fg-f45m-jf5q
Regular Expression Denial of Service in semver
CVE-2017-14919
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
CVE-2014-3744
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
CVE-2014-3744
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
CVE-2015-7384
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a den ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-q4qq-fm7q-cwp5 Multiple XSS Filter Bypasses in validator | CVSS3: 6.1 | 2% Низкий | почти 9 лет назад | |
GHSA-gfjr-3jmm-4g9v Symlink Arbitrary File Overwrite in tar | CVSS3: 7.5 | 5% Низкий | почти 9 лет назад | |
GHSA-xwg4-93c6-3h42 Directory Traversal in send | 4% Низкий | почти 9 лет назад | ||
GHSA-qpjp-7rp2-9c3f Moderate severity vulnerability that affects validator | CVSS3: 6.1 | 2% Низкий | почти 9 лет назад | |
GHSA-jjv7-qpx3-h62q Denial-of-Service Memory Exhaustion in qs | 8% Низкий | почти 9 лет назад | ||
GHSA-x6fg-f45m-jf5q Regular Expression Denial of Service in semver | CVSS3: 7.5 | 6% Низкий | почти 9 лет назад | |
CVE-2017-14919 Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter. | CVSS3: 7.5 | 8% Низкий | почти 9 лет назад | |
CVE-2014-3744 Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path. | CVSS3: 7.5 | 34% Средний | почти 9 лет назад | |
CVE-2014-3744 Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path. | CVSS3: 7.5 | 34% Средний | почти 9 лет назад | |
CVE-2015-7384 Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a den ... | CVSS3: 7.5 | 8% Низкий | почти 9 лет назад |
Уязвимостей на страницу