Логотип exploitDog
product: "node.js"
Консоль
Логотип exploitDog

exploitDog

product: "node.js"
Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

2021222324252023202420252026202720282029

Недавние уязвимости Node.js

Количество 1 064

debian логотип

CVE-2017-14849

больше 8 лет назад

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintende ...

CVSS3: 7.5
EPSS: Критический
ubuntu логотип

CVE-2017-14849

больше 8 лет назад

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2015-2927

больше 8 лет назад

node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2015-2927

больше 8 лет назад

node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2015-2927

больше 8 лет назад

node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2017-11499

больше 8 лет назад

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-11499

больше 8 лет назад

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11. ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11499

больше 8 лет назад

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1857-1

больше 8 лет назад

Security update for libcares2

EPSS: Низкий
redhat логотип

CVE-2017-11499

больше 8 лет назад

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2017-14849

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintende ...

CVSS3: 7.5
90%
Критический
больше 8 лет назад
ubuntu логотип
CVE-2017-14849

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

CVSS3: 7.5
90%
Критический
больше 8 лет назад
nvd логотип
CVE-2015-2927

node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2015-2927

node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause ...

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2015-2927

node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-11499

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-11499

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11. ...

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-11499

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1857-1

Security update for libcares2

0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-11499

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад

Уязвимостей на страницу


Поделиться