Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 146

Количество 1 146

redhat логотип

CVE-2016-5325

около 10 лет назад

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2016-5325

почти 10 лет назад

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5325

почти 10 лет назад

CRLF injection vulnerability in the ServerResponse#writeHead function ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-2216

больше 10 лет назад

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2016-2216

больше 10 лет назад

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2216

больше 10 лет назад

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-2216

больше 10 лет назад

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-2086

больше 10 лет назад

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2016-2086

больше 10 лет назад

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2086

больше 10 лет назад

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-2086

больше 10 лет назад

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8860

больше 9 лет назад

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2015-8860

больше 11 лет назад

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-8860

больше 9 лет назад

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-8860

больше 9 лет назад

The tar package before 2.0.0 for Node.js allows remote attackers to wr ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8855

больше 9 лет назад

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2015-8855

больше 11 лет назад

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-8855

больше 9 лет назад

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-8855

больше 9 лет назад

The semver package before 4.3.2 for Node.js allows attackers to cause ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8027

больше 10 лет назад

Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2016-5325

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.

CVSS3: 4.8
4%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5325

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.

CVSS3: 6.1
4%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-5325

CRLF injection vulnerability in the ServerResponse#writeHead function ...

CVSS3: 6.1
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-2216

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.

CVSS3: 7.5
7%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-2216

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.

CVSS2: 4.3
7%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-2216

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.

CVSS3: 7.5
7%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-2216

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 ...

CVSS3: 7.5
7%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-2086

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

CVSS3: 7.5
6%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-2086

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

CVSS2: 4.3
6%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-2086

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

CVSS3: 7.5
6%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-2086

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0 ...

CVSS3: 7.5
6%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8860

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

CVSS3: 7.5
5%
Низкий
больше 9 лет назад
redhat логотип
CVE-2015-8860

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

CVSS2: 4.3
5%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-8860

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

CVSS3: 7.5
5%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-8860

The tar package before 2.0.0 for Node.js allows remote attackers to wr ...

CVSS3: 7.5
5%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8855

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

CVSS3: 7.5
6%
Низкий
больше 9 лет назад
redhat логотип
CVE-2015-8855

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

CVSS2: 4.3
6%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-8855

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

CVSS3: 7.5
6%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-8855

The semver package before 4.3.2 for Node.js allows attackers to cause ...

CVSS3: 7.5
6%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8027

Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.

CVSS3: 7.5
5%
Низкий
больше 10 лет назад

Уязвимостей на страницу