Show filters
234 Total Results
Displaying 221-230 of 234
Sort by:
Attacker Value
Unknown

CVE-2015-3193

Disclosure Date: December 06, 2015 (last updated October 05, 2023)
The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.
Attacker Value
Unknown

CVE-2015-3194

Disclosure Date: December 06, 2015 (last updated November 08, 2023)
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.
Attacker Value
Unknown

CVE-2015-6764

Disclosure Date: December 06, 2015 (last updated October 05, 2023)
The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.
Attacker Value
Unknown

CVE-2015-5380

Disclosure Date: July 09, 2015 (last updated October 05, 2023)
The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.
0
Attacker Value
Unknown

CVE-2015-0278

Disclosure Date: May 18, 2015 (last updated October 05, 2023)
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-7191

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
0
Attacker Value
Unknown

CVE-2014-5256

Disclosure Date: September 05, 2014 (last updated October 05, 2023)
Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage collection in conjunction with a V8 interrupt, which allows remote attackers to cause a denial of service (memory corruption and application crash) via deep JSON objects whose parsing lets this interrupt mask an overflow of the program stack.
0
Attacker Value
Unknown

CVE-2014-0224

Disclosure Date: June 05, 2014 (last updated November 08, 2023)
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
Attacker Value
Unknown

CVE-2013-6668

Disclosure Date: March 05, 2014 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2013-4450

Disclosure Date: October 21, 2013 (last updated October 05, 2023)
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
0