Node.js — программная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 064
openSUSE-SU-2018:2117-1
Security update for openssl-1_1
openSUSE-SU-2018:2129-1
Security update for openssl-1_0_0
SUSE-SU-2018:2036-1
Security update for openssl-1_1
SUSE-SU-2018:2041-1
Security update for openssl-1_1
SUSE-SU-2018:1968-1
Security update for openssl
openSUSE-SU-2018:1962-1
Security update for nodejs6
openSUSE-SU-2018:1906-1
Security update for openssl
SUSE-SU-2018:1892-1
Security update for nodejs6
SUSE-SU-2018:1887-1
Security update for openssl
CVE-2018-7167
Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
openSUSE-SU-2018:2117-1 Security update for openssl-1_1 | 81% Высокий | больше 7 лет назад | ||
openSUSE-SU-2018:2129-1 Security update for openssl-1_0_0 | 81% Высокий | больше 7 лет назад | ||
SUSE-SU-2018:2036-1 Security update for openssl-1_1 | 81% Высокий | больше 7 лет назад | ||
SUSE-SU-2018:2041-1 Security update for openssl-1_1 | 81% Высокий | больше 7 лет назад | ||
SUSE-SU-2018:1968-1 Security update for openssl | 81% Высокий | больше 7 лет назад | ||
openSUSE-SU-2018:1962-1 Security update for nodejs6 | 1% Низкий | больше 7 лет назад | ||
openSUSE-SU-2018:1906-1 Security update for openssl | 81% Высокий | больше 7 лет назад | ||
SUSE-SU-2018:1892-1 Security update for nodejs6 | 1% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:1887-1 Security update for openssl | 81% Высокий | больше 7 лет назад | ||
CVE-2018-7167 Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable. | CVSS3: 7.5 | 1% Низкий | больше 7 лет назад |
Уязвимостей на страницу