Логотип exploitDog
bind:"CVE-2022-35255" OR bind:"CVE-2022-35256"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-35255" OR bind:"CVE-2022-35256"

Количество 43

Количество 43

oracle-oval логотип

ELSA-2022-9945

почти 3 года назад

ELSA-2022-9945: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9944

почти 3 года назад

ELSA-2022-9944: GraalVM Security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2022-35255

почти 3 года назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2022-35255

около 3 лет назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2022-35255

почти 3 года назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2022-35255

почти 3 года назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2022-35256

почти 3 года назад

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-35256

около 3 лет назад

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-35256

почти 3 года назад

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2022-35256

почти 3 года назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-35256

почти 3 года назад

The llhttp parser in the http module in Node v18.7.0 does not correctl ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p36x-w6hr-88jp

почти 3 года назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-rc2m-q589-vpqx

почти 3 года назад

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2023-00348

почти 3 года назад

Уязвимость анализатора HTTP-кода llhttp программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3835-1

почти 3 года назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3616-1

почти 3 года назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3614-1

почти 3 года назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3516-1

около 3 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3503-1

около 3 лет назад

Security update for nodejs12

EPSS: Низкий
rocky логотип

RLSA-2023:0321

больше 2 лет назад

Moderate: nodejs and nodejs-nodemon security, bug fix, and enhancement update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-9945

ELSA-2022-9945: GraalVM Security update (IMPORTANT)

почти 3 года назад
oracle-oval логотип
ELSA-2022-9944

ELSA-2022-9944: GraalVM Security update (IMPORTANT)

почти 3 года назад
ubuntu логотип
CVE-2022-35255

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-35255

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 8.2
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-35255

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
1%
Низкий
почти 3 года назад
debian логотип
CVE-2022-35255

A weak randomness in WebCrypto keygen vulnerability exists in Node.js ...

CVSS3: 9.1
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-35256

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
5%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-35256

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
5%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-35256

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
5%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 6.5
5%
Низкий
почти 3 года назад
debian логотип
CVE-2022-35256

The llhttp parser in the http module in Node v18.7.0 does not correctl ...

CVSS3: 6.5
5%
Низкий
почти 3 года назад
github логотип
GHSA-p36x-w6hr-88jp

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-rc2m-q589-vpqx

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 9.8
5%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-00348

Уязвимость анализатора HTTP-кода llhttp программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
5%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3835-1

Security update for nodejs10

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3616-1

Security update for nodejs12

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3614-1

Security update for nodejs14

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3516-1

Security update for nodejs14

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3503-1

Security update for nodejs12

около 3 лет назад
rocky логотип
RLSA-2023:0321

Moderate: nodejs and nodejs-nodemon security, bug fix, and enhancement update

больше 2 лет назад

Уязвимостей на страницу