Записи llhttp
6 опубликованных записей вендора llhttp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2022-32214Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Средняя6,5 | — | 82,5 % | 14 июл. 2022 г. |
47В плане | CVE-2022-32215Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Средняя6,5 | — | 68,8 % | 14 июл. 2022 г. |
39Наблюдать | CVE-2022-32213Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding hellhttp · llhttp · CWE-444 | Средняя6,5 | — | 44,1 % | 14 июл. 2022 г. |
27Наблюдать | CVE-2021-22959Эксплойта нет | The parser in accepts requests with a space (SP) right after the header name before the colon.llhttp · llhttp · CWE-444 | Средняя6,5 | — | 3,2 % | 15 нояб. 2021 г. |
27Наблюдать | CVE-2022-35256Эксплойта нет | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF.llhttp · llhttp · CWE-444 | Средняя6,5 | — | 2,7 % | 5 дек. 2022 г. |
27Наблюдать | CVE-2021-22960Эксплойта нет | The parse function in llhttp < 2.1.4 and < 6.0.6.llhttp · llhttp · CWE-444 | Средняя6,5 | — | 2,5 % | 3 нояб. 2021 г. |
- CVE-2022-3221451В плане
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
СредняяCVSS 6,5Эксплойта нетEPSS 82 %llhttp · llhttp14 июл. 2022 г.
- CVE-2022-3221547В плане
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
СредняяCVSS 6,5Эксплойта нетEPSS 69 %llhttp · llhttp14 июл. 2022 г.
- CVE-2022-3221339Наблюдать
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he
СредняяCVSS 6,5Эксплойта нетEPSS 44 %llhttp · llhttp14 июл. 2022 г.
- CVE-2021-2295927Наблюдать
The parser in accepts requests with a space (SP) right after the header name before the colon.
СредняяCVSS 6,5Эксплойта нетEPSS 3 %llhttp · llhttp15 нояб. 2021 г.
- CVE-2022-3525627Наблюдать
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF.
СредняяCVSS 6,5Эксплойта нетEPSS 3 %llhttp · llhttp5 дек. 2022 г.
- CVE-2021-2296027Наблюдать
The parse function in llhttp < 2.1.4 and < 6.0.6.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %llhttp · llhttp3 нояб. 2021 г.