Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2017-16113

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.
0
Attacker Value
Unknown

CVE-2017-1000189

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()
0
Attacker Value
Unknown

CVE-2017-1000228

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
0
Attacker Value
Unknown

CVE-2017-1000188

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection
0
Attacker Value
Unknown

CVE-2014-4616

Disclosure Date: August 24, 2017 (last updated November 26, 2024)
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
Attacker Value
Unknown

CVE-2017-7474

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.
0
Attacker Value
Unknown

CVE-2014-5256

Disclosure Date: September 05, 2014 (last updated October 05, 2023)
Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage collection in conjunction with a V8 interrupt, which allows remote attackers to cause a denial of service (memory corruption and application crash) via deep JSON objects whose parsing lets this interrupt mask an overflow of the program stack.
0
Attacker Value
Unknown

CVE-2013-4450

Disclosure Date: October 21, 2013 (last updated October 05, 2023)
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
0
Attacker Value
Unknown

CVE-2012-2330

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.
0