Логотип exploitDog
product: "node.js"
Консоль
Логотип exploitDog

exploitDog

product: "node.js"
Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

2021222324252023202420252026202720282029

Недавние уязвимости Node.js

Количество 1 025

redhat логотип

CVE-2017-3738

почти 8 лет назад

There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). Note: The impact from this issue is similar to CVE-2017-3736, CVE-2017-3732 and CVE-2015-3193. OpenSSL version 1.0.2-1.0.2m and 1.1.0-1.1.0g are affected. Fixed in OpenSSL 1.0.2n. Due to th...

CVSS3: 5.9
EPSS: Средний
fstec логотип

BDU:2021-03037

почти 8 лет назад

Уязвимость процедуры AVX2 Montgomery библиотеки OpenSSL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2017-14919

около 8 лет назад

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-14919

около 8 лет назад

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows r ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14919

около 8 лет назад

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gfjr-3jmm-4g9v

около 8 лет назад

Symlink Arbitrary File Overwrite in tar

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwg4-93c6-3h42

около 8 лет назад

Directory Traversal in send

EPSS: Низкий
github логотип

GHSA-552w-rqg8-gxxm

около 8 лет назад

Moderate severity vulnerability that affects validator

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-5726-g6r9-5f22

около 8 лет назад

Potential for Script Injection in syntax-error

EPSS: Средний
github логотип

GHSA-jjv7-qpx3-h62q

около 8 лет назад

Denial-of-Service Memory Exhaustion in qs

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2017-3738

There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). Note: The impact from this issue is similar to CVE-2017-3736, CVE-2017-3732 and CVE-2015-3193. OpenSSL version 1.0.2-1.0.2m and 1.1.0-1.1.0g are affected. Fixed in OpenSSL 1.0.2n. Due to th...

CVSS3: 5.9
14%
Средний
почти 8 лет назад
fstec логотип
BDU:2021-03037

Уязвимость процедуры AVX2 Montgomery библиотеки OpenSSL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.9
14%
Средний
почти 8 лет назад
nvd логотип
CVE-2017-14919

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-14919

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows r ...

CVSS3: 7.5
1%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-14919

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
1%
Низкий
около 8 лет назад
github логотип
GHSA-gfjr-3jmm-4g9v

Symlink Arbitrary File Overwrite in tar

CVSS3: 7.5
0%
Низкий
около 8 лет назад
github логотип
GHSA-xwg4-93c6-3h42

Directory Traversal in send

5%
Низкий
около 8 лет назад
github логотип
GHSA-552w-rqg8-gxxm

Moderate severity vulnerability that affects validator

CVSS3: 6.1
1%
Низкий
около 8 лет назад
github логотип
GHSA-5726-g6r9-5f22

Potential for Script Injection in syntax-error

44%
Средний
около 8 лет назад
github логотип
GHSA-jjv7-qpx3-h62q

Denial-of-Service Memory Exhaustion in qs

3%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться