Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 146

Количество 1 146

fstec логотип

BDU:2024-02798

почти 3 года назад

Уязвимость HTTP-сервера программной платформы Node.js, позволяющая нарушителю обойти ограничения безопасности и вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-00751

больше 4 лет назад

Уязвимость компонента Relative Distinguished Name (RDN) программной платформы Node.js, позволяющая нарушителю проводить спуфинг-атаки

CVSS3: 7.4
EPSS: Низкий
fstec логотип

BDU:2022-00330

больше 6 лет назад

Уязвимость программной платформы Node.js, связанная с непоследовательной интерпретацией http-запросов, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2022-00316

почти 5 лет назад

Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2021-01895

больше 5 лет назад

Уязвимость программной платформы Node.js, связанная с присутствием localhost6 в белом списке, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2019-03647

больше 7 лет назад

Уязвимость сетевого протокола HTTP/2 веб-сервера Apache Traffic Server, программной платформы Node.js, связанная с недостатком механизма контроля расхода ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2019-03646

почти 7 лет назад

Уязвимость компонента connection.c сетевого протокола HTTP/2 веб-сервера Apache Traffic Server, веб-сервера H2O, программной платформы Node.js, сетевого программного средства SwiftNIO, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Высокий
fstec логотип

BDU:2019-02939

больше 7 лет назад

Уязвимость парсера URL-адресов библиотеки Node.js, позволяющая нарушителю получить несанкционированный доступ к защищаемым данным

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02536-1

около 1 года назад

Security update for boost

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:0839-1

больше 9 лет назад

Security update for java-1_8_0-ibm

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2017:0726-1

больше 9 лет назад

Security update for java-1_6_0-ibm

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2017:0720-1

больше 9 лет назад

Security update for java-1_7_1-ibm

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2017:0719-1

больше 9 лет назад

Security update for java-1_7_1-ibm

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2017:0716-1

больше 9 лет назад

Security update for java-1_7_0-ibm

EPSS: Критический
rocky логотип

RLSA-2025:8395

около 1 года назад

Low: rsync security update

EPSS: Низкий
github логотип

GHSA-wrj6-35fr-8xw5

около 4 лет назад

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w2rw-pv8p-h9c8

около 4 лет назад

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-mjgw-69fr-p4h2

около 4 лет назад

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-jg6g-8j59-vr29

больше 4 лет назад

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-5qpf-4xwh-5775

больше 4 лет назад

Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly.Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the --security-revert command-line option.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-02798

Уязвимость HTTP-сервера программной платформы Node.js, позволяющая нарушителю обойти ограничения безопасности и вызвать отказ в обслуживании

CVSS3: 7.5
3%
Низкий
почти 3 года назад
fstec логотип
BDU:2022-00751

Уязвимость компонента Relative Distinguished Name (RDN) программной платформы Node.js, позволяющая нарушителю проводить спуфинг-атаки

CVSS3: 7.4
больше 4 лет назад
fstec логотип
BDU:2022-00330

Уязвимость программной платформы Node.js, связанная с непоследовательной интерпретацией http-запросов, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
57%
Средний
больше 6 лет назад
fstec логотип
BDU:2022-00316

Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
36%
Средний
почти 5 лет назад
fstec логотип
BDU:2021-01895

Уязвимость программной платформы Node.js, связанная с присутствием localhost6 в белом списке, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.5
32%
Средний
больше 5 лет назад
fstec логотип
BDU:2019-03647

Уязвимость сетевого протокола HTTP/2 веб-сервера Apache Traffic Server, программной платформы Node.js, связанная с недостатком механизма контроля расхода ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
27%
Средний
больше 7 лет назад
fstec логотип
BDU:2019-03646

Уязвимость компонента connection.c сетевого протокола HTTP/2 веб-сервера Apache Traffic Server, веб-сервера H2O, программной платформы Node.js, сетевого программного средства SwiftNIO, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
87%
Высокий
почти 7 лет назад
fstec логотип
BDU:2019-02939

Уязвимость парсера URL-адресов библиотеки Node.js, позволяющая нарушителю получить несанкционированный доступ к защищаемым данным

CVSS3: 7.5
5%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2025:02536-1

Security update for boost

5%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2017:0839-1

Security update for java-1_8_0-ibm

96%
Критический
больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:0726-1

Security update for java-1_6_0-ibm

96%
Критический
больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:0720-1

Security update for java-1_7_1-ibm

96%
Критический
больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:0719-1

Security update for java-1_7_1-ibm

96%
Критический
больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:0716-1

Security update for java-1_7_0-ibm

96%
Критический
больше 9 лет назад
rocky логотип
RLSA-2025:8395

Low: rsync security update

5%
Низкий
около 1 года назад
github логотип
GHSA-wrj6-35fr-8xw5

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

CVSS3: 8.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-w2rw-pv8p-h9c8

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

CVSS3: 7.5
96%
Критический
около 4 лет назад
github логотип
GHSA-mjgw-69fr-p4h2

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
74%
Высокий
около 4 лет назад
github логотип
GHSA-jg6g-8j59-vr29

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.

CVSS3: 5.3
10%
Средний
больше 4 лет назад
github логотип
GHSA-5qpf-4xwh-5775

Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly.Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the --security-revert command-line option.

CVSS3: 7.4
8%
Низкий
больше 4 лет назад

Уязвимостей на страницу