Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 146

Количество 1 146

debian логотип

CVE-2022-32215

около 4 лет назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2022-32213

около 4 лет назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2022-32213

около 4 лет назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2022-32213

около 4 лет назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2022-32213

около 4 лет назад

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2021-3672

больше 4 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2021-3672

почти 5 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2021-3672

больше 4 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
EPSS: Низкий
debian логотип

CVE-2021-3672

больше 4 лет назад

A flaw was found in c-ares library, where a missing input validation c ...

CVSS3: 5.6
EPSS: Низкий
ubuntu логотип

CVE-2020-10531

больше 6 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-10531

больше 6 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-10531

больше 6 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-10531

больше 6 лет назад

An issue was discovered in International Components for Unicode (ICU) ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-15604

больше 6 лет назад

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2019-15604

больше 6 лет назад

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2019-15604

больше 6 лет назад

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2019-15604

больше 6 лет назад

Improper Certificate Validation in Node.js 10, 12, and 13 causes the p ...

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2024-09774

около 3 лет назад

Уязвимость функции fs.statfs программной платформы Node.js, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-09200

около 3 лет назад

Уязвимость методов fs.mkdtemp() и fs.mkdtempSync() программной платформы Node.js, позволяющая нарушителю создать произвольный каталог

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-08734

больше 3 лет назад

Уязвимость метода undici.request клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю внедрить произвольные HTTP-заголовки

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2022-32215

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module ...

CVSS3: 6.5
69%
Средний
около 4 лет назад
ubuntu логотип
CVE-2022-32213

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
42%
Средний
около 4 лет назад
redhat логотип
CVE-2022-32213

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
42%
Средний
около 4 лет назад
nvd логотип
CVE-2022-32213

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

CVSS3: 6.5
42%
Средний
около 4 лет назад
debian логотип
CVE-2022-32213

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module ...

CVSS3: 6.5
42%
Средний
около 4 лет назад
ubuntu логотип
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
3%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
3%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation c ...

CVSS3: 5.6
3%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-10531

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-10531

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-10531

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-10531

An issue was discovered in International Components for Unicode (ICU) ...

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-15604

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

CVSS3: 7.5
20%
Средний
больше 6 лет назад
redhat логотип
CVE-2019-15604

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

CVSS3: 5.9
20%
Средний
больше 6 лет назад
nvd логотип
CVE-2019-15604

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

CVSS3: 7.5
20%
Средний
больше 6 лет назад
debian логотип
CVE-2019-15604

Improper Certificate Validation in Node.js 10, 12, and 13 causes the p ...

CVSS3: 7.5
20%
Средний
больше 6 лет назад
fstec логотип
BDU:2024-09774

Уязвимость функции fs.statfs программной платформы Node.js, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
1%
Низкий
около 3 лет назад
fstec логотип
BDU:2024-09200

Уязвимость методов fs.mkdtemp() и fs.mkdtempSync() программной платформы Node.js, позволяющая нарушителю создать произвольный каталог

CVSS3: 5.3
1%
Низкий
около 3 лет назад
fstec логотип
BDU:2024-08734

Уязвимость метода undici.request клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю внедрить произвольные HTTP-заголовки

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу