Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 170

Количество 56 170

redhat логотип

CVE-2020-7754

почти 6 лет назад

This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-7753

почти 6 лет назад

All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-7746

почти 6 лет назад

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-7743

почти 6 лет назад

The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2020-7733

почти 6 лет назад

The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-7720

около 6 лет назад

The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2020-7711

около 6 лет назад

This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-7693

около 6 лет назад

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2020-7692

около 6 лет назад

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2020-7677

около 4 лет назад

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2020-7676

больше 6 лет назад

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-7663

больше 6 лет назад

websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-7662

больше 6 лет назад

websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-7660

больше 6 лет назад

serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2020-7656

больше 6 лет назад

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-7645

больше 6 лет назад

All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2020-7610

больше 6 лет назад

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2020-7608

больше 6 лет назад

yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2020-7598

больше 6 лет назад

minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2020-7595

больше 6 лет назад

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-7754

This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.

CVSS3: 7.5
3%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-7753

All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().

CVSS3: 7.5
4%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-7746

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.

CVSS3: 7.5
5%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-7743

The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.

CVSS3: 7.3
4%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-7733

The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.

CVSS3: 7.5
4%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-7720

The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.

CVSS3: 7.3
3%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-7711

This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.

CVSS3: 7.5
2%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-7693

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

CVSS3: 5.3
5%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-7692

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

CVSS3: 7.4
2%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-7677

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2020-7676

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.

CVSS3: 5.4
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-7663

websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVSS3: 7.5
5%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-7662

websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVSS3: 7.5
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-7660

serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".

CVSS3: 8.1
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-7656

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.

CVSS3: 5.4
6%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-7645

All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-7610

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

CVSS3: 9.8
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-7608

yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-7598

minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.

CVSS3: 5.6
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-7595

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

CVSS3: 7.5
8%
Низкий
больше 6 лет назад

Уязвимостей на страницу