Логотип exploitDog
product: "node.js"
Консоль
Логотип exploitDog

exploitDog

product: "node.js"
Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

2021222324252023202420252026202720282029

Недавние уязвимости Node.js

Количество 1 065

debian логотип

CVE-2021-22940

больше 4 лет назад

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use aft ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-22939

больше 4 лет назад

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-22939

больше 4 лет назад

If the Node.js https API was used incorrectly and "undefined" was in p ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-22931

больше 4 лет назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2021-22931

больше 4 лет назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Co ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2021-22931

больше 4 лет назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2021-22939

больше 4 лет назад

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22940

больше 4 лет назад

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2690-1

больше 4 лет назад

Security update for libcares2

EPSS: Низкий
fstec логотип

BDU:2022-01889

больше 4 лет назад

Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-22940

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use aft ...

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22939

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22939

If the Node.js https API was used incorrectly and "undefined" was in p ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22931

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22931

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Co ...

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22931

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22939

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22940

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:2690-1

Security update for libcares2

0%
Низкий
больше 4 лет назад
fstec логотип
BDU:2022-01889

Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться