Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

22232425262024202520262027202820292030

Релизные элементы

KBВерсияБилдДата доступности
24.18.024.18.0
24.17.024.17.0
24.16.024.16.0
24.15.024.15.0
24.14.124.14.1
24.14.024.14.0
24.13.124.13.1
24.13.024.13.0
24.12.024.12.0
24.11.124.11.1

Показывать по

Недавние уязвимости Node.js

Количество 1 146

fstec логотип

BDU:2022-01720

больше 11 лет назад

Уязвимость программной платформы Node.js, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-7192

больше 11 лет назад

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2014-7192

больше 11 лет назад

Eval injection vulnerability in index.js in the syntax-error package b ...

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2014-7192

больше 11 лет назад

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2014-7191

почти 12 лет назад

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-7191

почти 12 лет назад

The qs module before 1.0.0 in Node.js does not call the compact functi ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-7191

почти 12 лет назад

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-6394

почти 12 лет назад

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-6394

почти 12 лет назад

visionmedia send before 0.8.4 for Node.js uses a partial comparison fo ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-6394

почти 12 лет назад

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2022-01720

Уязвимость программной платформы Node.js, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-7192

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

CVSS2: 10
13%
Средний
больше 11 лет назад
debian логотип
CVE-2014-7192

Eval injection vulnerability in index.js in the syntax-error package b ...

CVSS2: 10
13%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-7192

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

CVSS2: 10
13%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-7191

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

CVSS2: 5
8%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-7191

The qs module before 1.0.0 in Node.js does not call the compact functi ...

CVSS2: 5
8%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7191

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

CVSS2: 5
8%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-6394

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

CVSS2: 7.5
4%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-6394

visionmedia send before 0.8.4 for Node.js uses a partial comparison fo ...

CVSS2: 7.5
4%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-6394

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

CVSS2: 7.5
4%
Низкий
почти 12 лет назад

Уязвимостей на страницу


Поделиться