Логотип exploitDog
product: "node.js"
Консоль
Логотип exploitDog

exploitDog

product: "node.js"
Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

2021222324252023202420252026202720282029

Недавние уязвимости Node.js

Количество 1 090

suse-cvrf логотип

openSUSE-SU-2018:1906-1

больше 7 лет назад

Security update for openssl

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2018:1892-1

больше 7 лет назад

Security update for nodejs6

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:1887-1

больше 7 лет назад

Security update for openssl

EPSS: Высокий
nvd логотип

CVE-2018-7167

почти 8 лет назад

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-7167

почти 8 лет назад

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-7164

почти 8 лет назад

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-7164

почти 8 лет назад

Node.js versions 9.7.0 and later and 10.x are vulnerable and the sever ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-7162

почти 8 лет назад

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-7162

почти 8 лет назад

All versions of Node.js 9.x and 10.x are vulnerable and the severity i ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-7161

почти 8 лет назад

All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
suse-cvrf логотип
openSUSE-SU-2018:1906-1

Security update for openssl

79%
Высокий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1892-1

Security update for nodejs6

1%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1887-1

Security update for openssl

79%
Высокий
больше 7 лет назад
nvd логотип
CVE-2018-7167

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-7167

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead ...

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-7164

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-7164

Node.js versions 9.7.0 and later and 10.x are vulnerable and the sever ...

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-7162

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-7162

All versions of Node.js 9.x and 10.x are vulnerable and the severity i ...

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-7161

All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

CVSS3: 7.5
1%
Низкий
почти 8 лет назад

Уязвимостей на страницу


Поделиться