Логотип exploitDog
bind:"CVE-2022-35255" OR bind:"CVE-2022-35256"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-35255" OR bind:"CVE-2022-35256"

Количество 43

Количество 43

oracle-oval логотип

ELSA-2022-9945

больше 2 лет назад

ELSA-2022-9945: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9944

больше 2 лет назад

ELSA-2022-9944: GraalVM Security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2022-35255

больше 2 лет назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2022-35255

больше 2 лет назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2022-35255

больше 2 лет назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2022-35255

больше 2 лет назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2022-35256

больше 2 лет назад

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-35256

больше 2 лет назад

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-35256

больше 2 лет назад

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2022-35256

больше 2 лет назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-35256

больше 2 лет назад

The llhttp parser in the http module in Node v18.7.0 does not correctl ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p36x-w6hr-88jp

больше 2 лет назад

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-rc2m-q589-vpqx

больше 2 лет назад

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2023-00348

больше 2 лет назад

Уязвимость анализатора HTTP-кода llhttp программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3835-1

больше 2 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3616-1

больше 2 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3614-1

больше 2 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3516-1

больше 2 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3503-1

больше 2 лет назад

Security update for nodejs12

EPSS: Низкий
rocky логотип

RLSA-2023:0321

больше 2 лет назад

Moderate: nodejs and nodejs-nodemon security, bug fix, and enhancement update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-9945

ELSA-2022-9945: GraalVM Security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-9944

ELSA-2022-9944: GraalVM Security update (IMPORTANT)

больше 2 лет назад
ubuntu логотип
CVE-2022-35255

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-35255

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 8.2
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-35255

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-35255

A weak randomness in WebCrypto keygen vulnerability exists in Node.js ...

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-35256

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
4%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-35256

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
4%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-35256

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 6.5
4%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 6.5
4%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-35256

The llhttp parser in the http module in Node v18.7.0 does not correctl ...

CVSS3: 6.5
4%
Низкий
больше 2 лет назад
github логотип
GHSA-p36x-w6hr-88jp

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-rc2m-q589-vpqx

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

CVSS3: 9.8
4%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-00348

Уязвимость анализатора HTTP-кода llhttp программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
4%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3835-1

Security update for nodejs10

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3616-1

Security update for nodejs12

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3614-1

Security update for nodejs14

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3516-1

Security update for nodejs14

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3503-1

Security update for nodejs12

больше 2 лет назад
rocky логотип
RLSA-2023:0321

Moderate: nodejs and nodejs-nodemon security, bug fix, and enhancement update

больше 2 лет назад

Уязвимостей на страницу