Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2017-16113
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.
0
Attacker Value
Unknown
CVE-2017-1000189
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()
0
Attacker Value
Unknown
CVE-2017-1000228
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
0
Attacker Value
Unknown
CVE-2017-1000188
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection
0
Attacker Value
Unknown
CVE-2014-4616
Disclosure Date: August 24, 2017 (last updated November 26, 2024)
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
0
Attacker Value
Unknown
CVE-2017-7474
Disclosure Date: May 12, 2017 (last updated November 26, 2024)
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.
0
Attacker Value
Unknown
CVE-2014-5256
Disclosure Date: September 05, 2014 (last updated October 05, 2023)
Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage collection in conjunction with a V8 interrupt, which allows remote attackers to cause a denial of service (memory corruption and application crash) via deep JSON objects whose parsing lets this interrupt mask an overflow of the program stack.
0
Attacker Value
Unknown
CVE-2013-4450
Disclosure Date: October 21, 2013 (last updated October 05, 2023)
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
0
Attacker Value
Unknown
CVE-2012-2330
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.
0