Количество 24 658
Количество 24 658
CVE-2018-8119
Azure IoT SDK Spoofing Vulnerability
CVE-2018-8118
Internet Explorer Memory Corruption Vulnerability
CVE-2018-8117
Microsoft Wireless Keyboard 850 Security Feature Bypass Vulnerability
CVE-2018-8116
Microsoft Graphics Component Denial of Service Vulnerability
CVE-2018-8115
Windows Host Compute Service Shim Remote Code Execution Vulnerability
CVE-2018-8114
Scripting Engine Memory Corruption Vulnerability
CVE-2018-8113
Internet Explorer Security Feature Bypass Vulnerability
CVE-2018-8112
Microsoft Edge Security Feature Bypass Vulnerability
CVE-2018-8111
Microsoft Edge Memory Corruption Vulnerability
CVE-2018-8110
Microsoft Edge Memory Corruption Vulnerability
CVE-2018-7263
The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service
CVE-2018-7167
Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron") 8.x (LTS "Carbon") and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.
CVE-2018-7164
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.
CVE-2018-7162
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.
CVE-2018-7161
All versions of Node.js 8.x 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.
CVE-2018-7159
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users crafting lower-level HTTP utilities are advised to re-check the length of any input supplied after parsing is complete.
CVE-2018-6952
CVE-2018-6951
CVE-2018-5996
CVE-2018-5407
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-8119 Azure IoT SDK Spoofing Vulnerability | 1% Низкий | около 8 лет назад | ||
CVE-2018-8118 Internet Explorer Memory Corruption Vulnerability | 10% Низкий | больше 8 лет назад | ||
CVE-2018-8117 Microsoft Wireless Keyboard 850 Security Feature Bypass Vulnerability | 1% Низкий | около 8 лет назад | ||
CVE-2018-8116 Microsoft Graphics Component Denial of Service Vulnerability | CVSS3: 4.4 | 1% Низкий | больше 8 лет назад | |
CVE-2018-8115 Windows Host Compute Service Shim Remote Code Execution Vulnerability | 34% Средний | около 8 лет назад | ||
CVE-2018-8114 Scripting Engine Memory Corruption Vulnerability | CVSS3: 7.5 | 15% Средний | около 8 лет назад | |
CVE-2018-8113 Internet Explorer Security Feature Bypass Vulnerability | CVSS3: 4.3 | 5% Низкий | около 8 лет назад | |
CVE-2018-8112 Microsoft Edge Security Feature Bypass Vulnerability | CVSS3: 4.3 | 3% Низкий | около 8 лет назад | |
CVE-2018-8111 Microsoft Edge Memory Corruption Vulnerability | CVSS3: 4.2 | 15% Средний | около 8 лет назад | |
CVE-2018-8110 Microsoft Edge Memory Corruption Vulnerability | CVSS3: 4.2 | 15% Средний | около 8 лет назад | |
CVE-2018-7263 The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service | CVSS3: 9.8 | 2% Низкий | больше 1 года назад | |
CVE-2018-7167 Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron") 8.x (LTS "Carbon") and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable. | CVSS3: 7.5 | 7% Низкий | около 5 лет назад | |
CVE-2018-7164 Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour. | CVSS3: 7.5 | 6% Низкий | около 5 лет назад | |
CVE-2018-7162 All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation. | CVSS3: 7.5 | 7% Низкий | около 5 лет назад | |
CVE-2018-7161 All versions of Node.js 8.x 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation. | CVSS3: 7.5 | 8% Низкий | около 5 лет назад | |
CVE-2018-7159 The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users crafting lower-level HTTP utilities are advised to re-check the length of any input supplied after parsing is complete. | CVSS3: 5.3 | 4% Низкий | 8 месяцев назад | |
CVSS3: 7.5 | 8% Низкий | почти 6 лет назад | ||
CVSS3: 7.5 | 8% Низкий | почти 6 лет назад | ||
CVSS3: 7.8 | 3% Низкий | больше 4 лет назад | ||
3% Низкий | 3 месяца назад |
Уязвимостей на страницу