Логотип exploitDog
product: "node.js"
Консоль
Логотип exploitDog

exploitDog

product: "node.js"
Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

20212223242023202420252026202720282029

Недавние уязвимости Node.js

Количество 1 009

redhat логотип

CVE-2015-6764

больше 9 лет назад

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

CVSS2: 2.6
EPSS: Средний
redhat логотип

CVE-2015-8027

больше 9 лет назад

Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.

CVSS2: 5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2015:1825-2

больше 9 лет назад

Security update for nodejs

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2015:1825-1

больше 9 лет назад

Security update for nodejs

EPSS: Низкий
redhat логотип

CVE-2015-7384

больше 9 лет назад

Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2015-5380

почти 10 лет назад

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-5380

почти 10 лет назад

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-5380

почти 10 лет назад

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2015-5380

почти 10 лет назад

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0278

около 10 лет назад

libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2015-6764

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

CVSS2: 2.6
14%
Средний
больше 9 лет назад
redhat логотип
CVE-2015-8027

Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.

CVSS2: 5
2%
Низкий
больше 9 лет назад
suse-cvrf логотип
openSUSE-SU-2015:1825-2

Security update for nodejs

1%
Низкий
больше 9 лет назад
suse-cvrf логотип
openSUSE-SU-2015:1825-1

Security update for nodejs

1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2015-7384

Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.

CVSS2: 2.6
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5380

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

CVSS2: 7.5
1%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-5380

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in ...

CVSS2: 7.5
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2015-5380

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

CVSS2: 7.5
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2015-5380

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

CVSS2: 4.3
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-0278

libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.

CVSS2: 10
2%
Низкий
около 10 лет назад

Уязвимостей на страницу


Поделиться