Skip to content
Noroxi

nodejs records

245 published records for vendor nodejs.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

245 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi

    HighCVSS 7.4WeaponizedEPSS 95%

    openssl · opensslJun 5, 2014

  • The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr

    HighCVSS 7.5Proof of conceptEPSS 95%

    redhat · jboss enterprise application platformAug 31, 2016

  • X.509 Email Address Variable Length Buffer Overflow

    HighCVSS 7.5Proof of conceptEPSS 92%

    openssl · opensslNov 1, 2022

  • An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 f

    HighCVSS 8.2Proof of conceptEPSS 87%

    nodejs · nodeApr 8, 2024

  • X.509 Email Address 4-byte Buffer Overflow

    HighCVSS 7.5Proof of conceptEPSS 91%

    openssl · opensslNov 1, 2022

  • Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service

    HighCVSS 7.5No exploitEPSS 87%

    apple · swiftnioAug 13, 2019

  • HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

    CriticalCVSS 9.8Proof of conceptEPSS 57%

    nodejs · node.jsFeb 7, 2020

  • Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service

    HighCVSS 7.5No exploitEPSS 83%

    apple · swiftnioAug 13, 2019

  • Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service

    HighCVSS 7.5No exploitEPSS 83%

    apple · swiftnioAug 13, 2019

  • Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service

    HighCVSS 7.5No exploitEPSS 82%

    apple · swiftnioAug 13, 2019

  • Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an

    HighCVSS 7.5No exploitEPSS 74%

    nodejs · node.jsMar 3, 2021

  • Infinite loop in BN_mod_sqrt() reachable when parsing certificates

    HighCVSS 7.5Proof of conceptEPSS 73%

    openssl · opensslMar 15, 2022

  • The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re

    MediumCVSS 6.5No exploitEPSS 82%

    llhttp · llhttpJul 14, 2022

  • The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding chec

    MediumCVSS 5.9Proof of conceptEPSS 89%

    openssl · opensslMay 4, 2016

  • Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory c

    CriticalCVSS 9.8No exploitEPSS 36%

    nodejs · node.jsOct 7, 2021

  • Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a d

    HighCVSS 7.5No exploitEPSS 63%

    openssl · opensslSep 26, 2016

  • Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of

    CriticalCVSS 9.8No exploitEPSS 32%

    openssl · opensslSep 16, 2016

  • Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service

    HighCVSS 7.5Proof of conceptEPSS 60%

    apple · swiftnioAug 13, 2019

  • The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea

    MediumCVSS 6.5No exploitEPSS 69%

    llhttp · llhttpJul 14, 2022

  • Truncated packet could crash via OOB read

    HighCVSS 7.5No exploitEPSS 57%

    openssl · opensslMay 4, 2017

  • Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the p

    HighCVSS 7.5Proof of conceptEPSS 54%

    nodejs · node.jsSep 27, 2017

  • A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versi

    HighCVSS 7.5Proof of conceptEPSS 54%

    nodejs · node.jsNov 18, 2020

  • Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation

    CriticalCVSS 9.8No exploitEPSS 22%

    nodejs · node.jsAug 16, 2021

  • Integer overflow in CipherUpdate

    HighCVSS 7.5Proof of conceptEPSS 51%

    openssl · opensslFeb 16, 2021