Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

22232425262024202520262027202820292030

Релизные элементы

KBВерсияБилдДата доступности
24.18.124.18.1
24.18.024.18.0
24.17.024.17.0
24.16.024.16.0
24.15.024.15.0
24.14.124.14.1
24.14.024.14.0
24.13.124.13.1
24.13.024.13.0
24.12.024.12.0

Показывать по

Недавние уязвимости Node.js

Количество 1 203

fstec логотип

BDU:2022-01889

почти 5 лет назад

Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2022-02171

почти 5 лет назад

Уязвимость компонента API https программной платформы Node.js, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 5.3
EPSS: Средний
redhat логотип

CVE-2021-22931

почти 5 лет назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 5
EPSS: Средний
redhat логотип

CVE-2021-22940

почти 5 лет назад

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2021-22939

почти 5 лет назад

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 3.7
EPSS: Средний
oracle-oval логотип

ELSA-2021-3075

почти 5 лет назад

ELSA-2021-3075: libuv security update (LOW)

EPSS: Средний
rocky логотип

RLSA-2021:3075

почти 5 лет назад

Low: libuv security update

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:14776-1

почти 5 лет назад

Security update for libcares2

EPSS: Низкий
redhat логотип

CVE-2021-3672

почти 5 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2021-22930

около 5 лет назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2022-01889

Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
14%
Средний
почти 5 лет назад
fstec логотип
BDU:2022-02171

Уязвимость компонента API https программной платформы Node.js, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 5.3
15%
Средний
почти 5 лет назад
redhat логотип
CVE-2021-22931

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 5
22%
Средний
почти 5 лет назад
redhat логотип
CVE-2021-22940

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 7.5
14%
Средний
почти 5 лет назад
redhat логотип
CVE-2021-22939

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 3.7
15%
Средний
почти 5 лет назад
oracle-oval логотип
ELSA-2021-3075

ELSA-2021-3075: libuv security update (LOW)

23%
Средний
почти 5 лет назад
rocky логотип
RLSA-2021:3075

Low: libuv security update

23%
Средний
почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:14776-1

Security update for libcares2

3%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
3%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-22930

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 9.8
36%
Средний
около 5 лет назад

Уязвимостей на страницу


Поделиться