Количество 1 146
Количество 1 146
openSUSE-SU-2016:2752-1
Security update for nodejs
SUSE-SU-2018:2956-1
Security update for openssl-1_1
SUSE-SU-2018:2207-1
Security update for openssl
SUSE-SU-2018:2041-1
Security update for openssl-1_1
SUSE-SU-2018:2036-1
Security update for openssl-1_1
SUSE-SU-2018:1968-1
Security update for openssl
SUSE-SU-2018:1887-2
Security update for openssl
SUSE-SU-2018:1887-1
Security update for openssl
SUSE-SU-2017:1792-1
Security update for libcares2
SUSE-SU-2016:3287-1
Security update for libcares2
SUSE-SU-2016:3286-1
Security update for libcares2
SUSE-SU-2016:2898-1
Security update for nodejs4
RLSA-2021:3075
Low: libuv security update
GHSA-xwg4-93c6-3h42
Directory Traversal in send
GHSA-x3cj-3539-rcpx
Out-of-Bounds Read in Node.js
GHSA-wff4-fpwg-qqv3
Unexpected server crash in Next.js
GHSA-w95h-2gj2-x2p4
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
GHSA-w6xc-jcff-g3vg
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
GHSA-vjr3-54h8-whpv
The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.
GHSA-q85m-543x-pwpc
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second-to-last position of a buffer cause a miscalculation of the maximum length of the input bytes to be written.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
openSUSE-SU-2016:2752-1 Security update for nodejs | 9% Низкий | больше 9 лет назад | ||
SUSE-SU-2018:2956-1 Security update for openssl-1_1 | 49% Средний | почти 8 лет назад | ||
SUSE-SU-2018:2207-1 Security update for openssl | 49% Средний | почти 8 лет назад | ||
SUSE-SU-2018:2041-1 Security update for openssl-1_1 | 49% Средний | около 8 лет назад | ||
SUSE-SU-2018:2036-1 Security update for openssl-1_1 | 49% Средний | около 8 лет назад | ||
SUSE-SU-2018:1968-1 Security update for openssl | 49% Средний | около 8 лет назад | ||
SUSE-SU-2018:1887-2 Security update for openssl | 49% Средний | почти 8 лет назад | ||
SUSE-SU-2018:1887-1 Security update for openssl | 49% Средний | около 8 лет назад | ||
SUSE-SU-2017:1792-1 Security update for libcares2 | 3% Низкий | около 9 лет назад | ||
SUSE-SU-2016:3287-1 Security update for libcares2 | 9% Низкий | больше 9 лет назад | ||
SUSE-SU-2016:3286-1 Security update for libcares2 | 9% Низкий | больше 9 лет назад | ||
SUSE-SU-2016:2898-1 Security update for nodejs4 | 9% Низкий | больше 9 лет назад | ||
RLSA-2021:3075 Low: libuv security update | 23% Средний | почти 5 лет назад | ||
GHSA-xwg4-93c6-3h42 Directory Traversal in send | 4% Низкий | почти 9 лет назад | ||
GHSA-x3cj-3539-rcpx Out-of-Bounds Read in Node.js | CVSS3: 8.2 | 23% Средний | около 5 лет назад | |
GHSA-wff4-fpwg-qqv3 Unexpected server crash in Next.js | CVSS3: 5.3 | 1% Низкий | почти 4 года назад | |
GHSA-w95h-2gj2-x2p4 A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks. | CVSS3: 8.1 | 6% Низкий | около 4 лет назад | |
GHSA-w6xc-jcff-g3vg Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors. | CVSS3: 9.8 | 32% Средний | около 4 лет назад | |
GHSA-vjr3-54h8-whpv The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way. | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-q85m-543x-pwpc In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second-to-last position of a buffer cause a miscalculation of the maximum length of the input bytes to be written. | CVSS3: 7.5 | 8% Низкий | около 4 лет назад |
Уязвимостей на страницу