Show filters
234 Total Results
Displaying 181-190 of 234
Sort by:
Attacker Value
Unknown
CVE-2017-15878
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.
0
Attacker Value
Unknown
CVE-2014-3744
Disclosure Date: October 23, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
0
Attacker Value
Unknown
CVE-2015-7384
Disclosure Date: October 10, 2017 (last updated November 26, 2024)
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
0
Attacker Value
Unknown
CVE-2017-14849
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
0
Attacker Value
Unknown
CVE-2015-2927
Disclosure Date: September 20, 2017 (last updated November 08, 2023)
node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
0
Attacker Value
Unknown
CVE-2014-4616
Disclosure Date: August 24, 2017 (last updated November 26, 2024)
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
0
Attacker Value
Unknown
CVE-2017-11499
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.
0
Attacker Value
Unknown
CVE-2017-1000381
Disclosure Date: July 07, 2017 (last updated November 26, 2024)
The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.
0
Attacker Value
Unknown
CVE-2016-9842
Disclosure Date: May 23, 2017 (last updated August 29, 2024)
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
0
Attacker Value
Unknown
CVE-2016-9840
Disclosure Date: May 23, 2017 (last updated November 08, 2023)
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
0