Логотип exploitDog
product: "node.js"
Консоль
Логотип exploitDog

exploitDog

product: "node.js"

Количество 1 009

Количество 1 009

rocky логотип

RLSA-2020:1317

около 5 лет назад

Important: nodejs:10 security update

EPSS: Низкий
rocky логотип

RLSA-2020:1293

около 5 лет назад

Important: nodejs:12 security update

EPSS: Низкий
rocky логотип

RLSA-2020:0902

больше 5 лет назад

Important: icu security update

EPSS: Низкий
github логотип

GHSA-hghm-3vc3-hppj

около 3 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-8xp2-qvq2-xhpx

около 3 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-5689-v88g-g6rv

почти 3 года назад

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

CVSS3: 9.1
EPSS: Высокий
github логотип

GHSA-5492-mr68-4m2h

почти 3 года назад

The llhttp parser in the http module in Node v17.6.0 does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 9.1
EPSS: Высокий
github логотип

GHSA-4p8g-wmmc-p9f7

около 3 лет назад

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-32215

почти 3 года назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
EPSS: Высокий
redhat логотип

CVE-2022-32215

почти 3 года назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
EPSS: Высокий
nvd логотип

CVE-2022-32215

почти 3 года назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
EPSS: Высокий
debian логотип

CVE-2022-32215

почти 3 года назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module ...

CVSS3: 6.5
EPSS: Высокий
ubuntu логотип

CVE-2022-32213

почти 3 года назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
EPSS: Высокий
redhat логотип

CVE-2022-32213

почти 3 года назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
EPSS: Высокий
nvd логотип

CVE-2022-32213

почти 3 года назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
EPSS: Высокий
debian логотип

CVE-2022-32213

почти 3 года назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module ...

CVSS3: 6.5
EPSS: Высокий
ubuntu логотип

CVE-2021-3672

больше 3 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2021-3672

почти 4 года назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2021-3672

больше 3 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
EPSS: Низкий
debian логотип

CVE-2021-3672

больше 3 лет назад

A flaw was found in c-ares library, where a missing input validation c ...

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2020:1317

Important: nodejs:10 security update

1%
Низкий
около 5 лет назад
rocky логотип
RLSA-2020:1293

Important: nodejs:12 security update

1%
Низкий
около 5 лет назад
rocky логотип
RLSA-2020:0902

Important: icu security update

1%
Низкий
больше 5 лет назад
github логотип
GHSA-hghm-3vc3-hppj

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-8xp2-qvq2-xhpx

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-5689-v88g-g6rv

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

CVSS3: 9.1
89%
Высокий
почти 3 года назад
github логотип
GHSA-5492-mr68-4m2h

The llhttp parser in the http module in Node v17.6.0 does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 9.1
88%
Высокий
почти 3 года назад
github логотип
GHSA-4p8g-wmmc-p9f7

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

CVSS3: 7.5
4%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-32215

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
88%
Высокий
почти 3 года назад
redhat логотип
CVE-2022-32215

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
88%
Высокий
почти 3 года назад
nvd логотип
CVE-2022-32215

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
88%
Высокий
почти 3 года назад
debian логотип
CVE-2022-32215

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module ...

CVSS3: 6.5
88%
Высокий
почти 3 года назад
ubuntu логотип
CVE-2022-32213

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
89%
Высокий
почти 3 года назад
redhat логотип
CVE-2022-32213

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
89%
Высокий
почти 3 года назад
nvd логотип
CVE-2022-32213

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
89%
Высокий
почти 3 года назад
debian логотип
CVE-2022-32213

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module ...

CVSS3: 6.5
89%
Высокий
почти 3 года назад
ubuntu логотип
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation c ...

CVSS3: 5.6
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу