Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24 658

Количество 24 658

msrc логотип

CVE-2018-8119

около 8 лет назад

Azure IoT SDK Spoofing Vulnerability

EPSS: Низкий
msrc логотип

CVE-2018-8118

больше 8 лет назад

Internet Explorer Memory Corruption Vulnerability

EPSS: Низкий
msrc логотип

CVE-2018-8117

около 8 лет назад

Microsoft Wireless Keyboard 850 Security Feature Bypass Vulnerability

EPSS: Низкий
msrc логотип

CVE-2018-8116

больше 8 лет назад

Microsoft Graphics Component Denial of Service Vulnerability

CVSS3: 4.4
EPSS: Низкий
msrc логотип

CVE-2018-8115

около 8 лет назад

Windows Host Compute Service Shim Remote Code Execution Vulnerability

EPSS: Средний
msrc логотип

CVE-2018-8114

около 8 лет назад

Scripting Engine Memory Corruption Vulnerability

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2018-8113

около 8 лет назад

Internet Explorer Security Feature Bypass Vulnerability

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2018-8112

около 8 лет назад

Microsoft Edge Security Feature Bypass Vulnerability

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2018-8111

около 8 лет назад

Microsoft Edge Memory Corruption Vulnerability

CVSS3: 4.2
EPSS: Средний
msrc логотип

CVE-2018-8110

около 8 лет назад

Microsoft Edge Memory Corruption Vulnerability

CVSS3: 4.2
EPSS: Средний
msrc логотип

CVE-2018-7263

больше 1 года назад

The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2018-7167

около 5 лет назад

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron") 8.x (LTS "Carbon") and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-7164

около 5 лет назад

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-7162

около 5 лет назад

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-7161

около 5 лет назад

All versions of Node.js 8.x 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-7159

8 месяцев назад

The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users crafting lower-level HTTP utilities are advised to re-check the length of any input supplied after parsing is complete.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2018-6952

почти 6 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-6951

почти 6 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-5996

больше 4 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2018-5407

3 месяца назад

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2018-8119

Azure IoT SDK Spoofing Vulnerability

1%
Низкий
около 8 лет назад
msrc логотип
CVE-2018-8118

Internet Explorer Memory Corruption Vulnerability

10%
Низкий
больше 8 лет назад
msrc логотип
CVE-2018-8117

Microsoft Wireless Keyboard 850 Security Feature Bypass Vulnerability

1%
Низкий
около 8 лет назад
msrc логотип
CVE-2018-8116

Microsoft Graphics Component Denial of Service Vulnerability

CVSS3: 4.4
1%
Низкий
больше 8 лет назад
msrc логотип
CVE-2018-8115

Windows Host Compute Service Shim Remote Code Execution Vulnerability

34%
Средний
около 8 лет назад
msrc логотип
CVE-2018-8114

Scripting Engine Memory Corruption Vulnerability

CVSS3: 7.5
15%
Средний
около 8 лет назад
msrc логотип
CVE-2018-8113

Internet Explorer Security Feature Bypass Vulnerability

CVSS3: 4.3
5%
Низкий
около 8 лет назад
msrc логотип
CVE-2018-8112

Microsoft Edge Security Feature Bypass Vulnerability

CVSS3: 4.3
3%
Низкий
около 8 лет назад
msrc логотип
CVE-2018-8111

Microsoft Edge Memory Corruption Vulnerability

CVSS3: 4.2
15%
Средний
около 8 лет назад
msrc логотип
CVE-2018-8110

Microsoft Edge Memory Corruption Vulnerability

CVSS3: 4.2
15%
Средний
около 8 лет назад
msrc логотип
CVE-2018-7263

The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service

CVSS3: 9.8
2%
Низкий
больше 1 года назад
msrc логотип
CVE-2018-7167

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron") 8.x (LTS "Carbon") and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.

CVSS3: 7.5
7%
Низкий
около 5 лет назад
msrc логотип
CVE-2018-7164

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

CVSS3: 7.5
6%
Низкий
около 5 лет назад
msrc логотип
CVE-2018-7162

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

CVSS3: 7.5
7%
Низкий
около 5 лет назад
msrc логотип
CVE-2018-7161

All versions of Node.js 8.x 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

CVSS3: 7.5
8%
Низкий
около 5 лет назад
msrc логотип
CVE-2018-7159

The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users crafting lower-level HTTP utilities are advised to re-check the length of any input supplied after parsing is complete.

CVSS3: 5.3
4%
Низкий
8 месяцев назад
msrc логотип
CVSS3: 7.5
8%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 7.5
8%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 7.8
3%
Низкий
больше 4 лет назад
msrc логотип
3%
Низкий
3 месяца назад

Уязвимостей на страницу