Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Very Low
CVE-2023-31484
Disclosure Date: April 29, 2023 (last updated October 08, 2023)
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
2
Attacker Value
Unknown
CVE-2016-3956
Disclosure Date: July 02, 2016 (last updated November 25, 2024)
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
1
Attacker Value
Unknown
CVE-2024-12668
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability. By using an IO Control, a user space program can trick the driver into writing a 0 into any chosen memory location. In conjunction with information leakage from the WinPmem driver, attackers can discover the location in memory for the g_CiOptions global symbol. This can be leveraged to disable signed driver enforcement on the target system - allowing attackers to load unsigned drivers.
0
Attacker Value
Unknown
CVE-2024-10972
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with admin access can trigger a BSOD with a parallel thread changing the memory’s access right under the control of the user-mode application. This is due to verification only being performed at the beginning of the routine allowing the userspace to change page permissions half way through the routine. A valid workaround is a rule to detect unauthorized loading of winpmem outside incident response operations.
0
Attacker Value
Unknown
CVE-2024-53866
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and installs by default don't revalidate the data (including on first lockfile generation). This can make workspace A (even running with `ignore-scripts=true`) posion global cache and execute scripts in workspace B. Users generally expect `ignore-scripts` to be sufficient to prevent immediate code execution on install (e.g. when the tree is just repacked/bundled without executing it). Here, that expectation is broken. Global state integrity is lost via operations that one would expect to be secure, enabling subsequently running arbitrary code execution on installs. Version 9.15.0 fixes the issue. As a work-around, use separate cache and store dirs in each workspace.
0
Attacker Value
Unknown
CVE-2024-21538
Disclosure Date: November 08, 2024 (last updated November 19, 2024)
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
0
Attacker Value
Unknown
CVE-2024-21534
Disclosure Date: October 11, 2024 (last updated November 18, 2024)
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node.
**Note:**
There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).
0
Attacker Value
Unknown
CVE-2024-21512
Disclosure Date: May 29, 2024 (last updated June 06, 2024)
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
0
Attacker Value
Unknown
CVE-2024-21501
Disclosure Date: February 24, 2024 (last updated March 06, 2024)
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
0
Attacker Value
Unknown
CVE-2023-41915
Disclosure Date: September 09, 2023 (last updated January 09, 2024)
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
0