nodejs records
245 published records for vendor nodejs.
Researcher profile
- Entered KEV
- 1 · 0.4%
- Weaponized
- 3 · 1.2%
- Pre-auth RCE
- 9
- With a fix record
- 98%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-400 Uncontrolled Resource Consumption26
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor14
- CWE-20 Improper Input Validation14
- CWE-284 Improper Access Control12
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')11
- CWE-295 Improper Certificate Validation10
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
245 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
58Plan | CVE-2014-0224Weaponized | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | High7.4 | — | 95.3% | Jun 5, 2014 |
58Plan | CVE-2016-2183Proof of concept | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | High7.5 | — | 94.7% | Aug 31, 2016 |
58Plan | CVE-2022-3786Proof of concept | X.509 Email Address Variable Length Buffer Overflowopenssl · openssl · CWE-120 | High7.5 | — | 92.5% | Nov 1, 2022 |
58Plan | CVE-2024-27983Proof of concept | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 fnodejs · node · CWE-362 | High8.2 | — | 87.2% | Apr 8, 2024 |
57Plan | CVE-2022-3602Proof of concept | X.509 Email Address 4-byte Buffer Overflowopenssl · openssl · CWE-787 | High7.5 | — | 90.8% | Nov 1, 2022 |
56Plan | CVE-2019-9515No exploit | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 87.4% | Aug 13, 2019 |
56Plan | CVE-2019-15605Proof of concept | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformednodejs · node.js · CWE-444 | Critical9.8 | — | 57.1% | Feb 7, 2020 |
55Plan | CVE-2019-9512No exploit | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 83.4% | Aug 13, 2019 |
55Plan | CVE-2019-9514No exploit | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 82.8% | Aug 13, 2019 |
54Plan | CVE-2019-9513No exploit | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 81.6% | Aug 13, 2019 |
52Plan | CVE-2021-22883No exploit | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an nodejs · node.js · CWE-400 | High7.5 | — | 74.4% | Mar 3, 2021 |
52Plan | CVE-2022-0778Proof of concept | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | High7.5 | — | 73.2% | Mar 15, 2022 |
51Plan | CVE-2022-32214No exploit | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Medium6.5 | — | 82.5% | Jul 14, 2022 |
50Plan | CVE-2016-2107Proof of concept | The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding checopenssl · openssl · CWE-200 | Medium5.9 | — | 89.1% | May 4, 2016 |
50Plan | CVE-2021-22930No exploit | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory cnodejs · node.js · CWE-416 | Critical9.8 | — | 36.5% | Oct 7, 2021 |
49Plan | CVE-2016-6304No exploit | Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a dopenssl · openssl · CWE-401 | High7.5 | — | 63.0% | Sep 26, 2016 |
49Plan | CVE-2016-6303No exploit | Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of openssl · openssl · CWE-787 | Critical9.8 | — | 32.0% | Sep 16, 2016 |
48Plan | CVE-2019-9511Proof of concept | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 59.5% | Aug 13, 2019 |
47Plan | CVE-2022-32215No exploit | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Medium6.5 | — | 68.8% | Jul 14, 2022 |
47Plan | CVE-2017-3731No exploit | Truncated packet could crash via OOB readopenssl · openssl · CWE-125 | High7.5 | — | 57.3% | May 4, 2017 |
46Plan | CVE-2017-14849Proof of concept | Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pnodejs · node.js · CWE-22 | High7.5 | — | 54.4% | Sep 27, 2017 |
46Plan | CVE-2020-8277Proof of concept | A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versinodejs · node.js · CWE-400 | High7.5 | — | 54.2% | Nov 18, 2020 |
46Plan | CVE-2021-22931No exploit | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validationnodejs · node.js · CWE-170 | Critical9.8 | — | 22.0% | Aug 16, 2021 |
45Plan | CVE-2021-23840Proof of concept | Integer overflow in CipherUpdateopenssl · openssl · CWE-190 | High7.5 | — | 50.7% | Feb 16, 2021 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2014-022458Plan
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
HighCVSS 7.4WeaponizedEPSS 95%openssl · opensslJun 5, 2014
- CVE-2016-218358Plan
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
HighCVSS 7.5Proof of conceptEPSS 95%redhat · jboss enterprise application platformAug 31, 2016
- CVE-2022-378658Plan
X.509 Email Address Variable Length Buffer Overflow
HighCVSS 7.5Proof of conceptEPSS 92%openssl · opensslNov 1, 2022
- CVE-2024-2798358Plan
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 f
HighCVSS 8.2Proof of conceptEPSS 87%nodejs · nodeApr 8, 2024
- CVE-2022-360257Plan
X.509 Email Address 4-byte Buffer Overflow
HighCVSS 7.5Proof of conceptEPSS 91%openssl · opensslNov 1, 2022
- CVE-2019-951556Plan
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 87%apple · swiftnioAug 13, 2019
- CVE-2019-1560556Plan
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
CriticalCVSS 9.8Proof of conceptEPSS 57%nodejs · node.jsFeb 7, 2020
- CVE-2019-951255Plan
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 83%apple · swiftnioAug 13, 2019
- CVE-2019-951455Plan
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 83%apple · swiftnioAug 13, 2019
- CVE-2019-951354Plan
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 82%apple · swiftnioAug 13, 2019
- CVE-2021-2288352Plan
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an
HighCVSS 7.5No exploitEPSS 74%nodejs · node.jsMar 3, 2021
- CVE-2022-077852Plan
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
HighCVSS 7.5Proof of conceptEPSS 73%openssl · opensslMar 15, 2022
- CVE-2022-3221451Plan
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
MediumCVSS 6.5No exploitEPSS 82%llhttp · llhttpJul 14, 2022
- CVE-2016-210750Plan
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding chec
MediumCVSS 5.9Proof of conceptEPSS 89%openssl · opensslMay 4, 2016
- CVE-2021-2293050Plan
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory c
CriticalCVSS 9.8No exploitEPSS 36%nodejs · node.jsOct 7, 2021
- CVE-2016-630449Plan
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a d
HighCVSS 7.5No exploitEPSS 63%openssl · opensslSep 26, 2016
- CVE-2016-630349Plan
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of
CriticalCVSS 9.8No exploitEPSS 32%openssl · opensslSep 16, 2016
- CVE-2019-951148Plan
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service
HighCVSS 7.5Proof of conceptEPSS 60%apple · swiftnioAug 13, 2019
- CVE-2022-3221547Plan
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
MediumCVSS 6.5No exploitEPSS 69%llhttp · llhttpJul 14, 2022
- CVE-2017-373147Plan
Truncated packet could crash via OOB read
HighCVSS 7.5No exploitEPSS 57%openssl · opensslMay 4, 2017
- CVE-2017-1484946Plan
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the p
HighCVSS 7.5Proof of conceptEPSS 54%nodejs · node.jsSep 27, 2017
- CVE-2020-827746Plan
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versi
HighCVSS 7.5Proof of conceptEPSS 54%nodejs · node.jsNov 18, 2020
- CVE-2021-2293146Plan
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation
CriticalCVSS 9.8No exploitEPSS 22%nodejs · node.jsAug 16, 2021
- CVE-2021-2384045Plan
Integer overflow in CipherUpdate
HighCVSS 7.5Proof of conceptEPSS 51%openssl · opensslFeb 16, 2021