Записи nodejs
245 опубликованных записей вендора nodejs.
Профиль для исследователя
- Попали в KEV
- 1 · 0,4 %
- С эксплойтом
- 3 · 1,2 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 98 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption26
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor14
- CWE-20 Improper Input Validation14
- CWE-284 Improper Access Control12
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')11
- CWE-295 Improper Certificate Validation10
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
245 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
58В плане | CVE-2014-0224Готовый эксплойт | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Высокая7,4 | — | 95,3 % | 5 июн. 2014 г. |
58В плане | CVE-2016-2183Proof of concept | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | Высокая7,5 | — | 94,7 % | 31 авг. 2016 г. |
58В плане | CVE-2022-3786Proof of concept | X.509 Email Address Variable Length Buffer Overflowopenssl · openssl · CWE-120 | Высокая7,5 | — | 92,5 % | 1 нояб. 2022 г. |
58В плане | CVE-2024-27983Proof of concept | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 fnodejs · node · CWE-362 | Высокая8,2 | — | 87,2 % | 8 апр. 2024 г. |
57В плане | CVE-2022-3602Proof of concept | X.509 Email Address 4-byte Buffer Overflowopenssl · openssl · CWE-787 | Высокая7,5 | — | 90,8 % | 1 нояб. 2022 г. |
56В плане | CVE-2019-9515Эксплойта нет | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 87,4 % | 13 авг. 2019 г. |
56В плане | CVE-2019-15605Proof of concept | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformednodejs · node.js · CWE-444 | Критическая9,8 | — | 57,1 % | 7 февр. 2020 г. |
55В плане | CVE-2019-9512Эксплойта нет | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 83,4 % | 13 авг. 2019 г. |
55В плане | CVE-2019-9514Эксплойта нет | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 82,8 % | 13 авг. 2019 г. |
54В плане | CVE-2019-9513Эксплойта нет | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 81,6 % | 13 авг. 2019 г. |
52В плане | CVE-2021-22883Эксплойта нет | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an nodejs · node.js · CWE-400 | Высокая7,5 | — | 74,4 % | 3 мар. 2021 г. |
52В плане | CVE-2022-0778Proof of concept | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | Высокая7,5 | — | 73,2 % | 15 мар. 2022 г. |
51В плане | CVE-2022-32214Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Средняя6,5 | — | 82,5 % | 14 июл. 2022 г. |
50В плане | CVE-2016-2107Proof of concept | The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding checopenssl · openssl · CWE-200 | Средняя5,9 | — | 89,1 % | 4 мая 2016 г. |
50В плане | CVE-2021-22930Эксплойта нет | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory cnodejs · node.js · CWE-416 | Критическая9,8 | — | 36,5 % | 7 окт. 2021 г. |
49В плане | CVE-2016-6304Эксплойта нет | Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a dopenssl · openssl · CWE-401 | Высокая7,5 | — | 63,0 % | 26 сент. 2016 г. |
49В плане | CVE-2016-6303Эксплойта нет | Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of openssl · openssl · CWE-787 | Критическая9,8 | — | 32,0 % | 16 сент. 2016 г. |
48В плане | CVE-2019-9511Proof of concept | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 59,5 % | 13 авг. 2019 г. |
47В плане | CVE-2022-32215Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Средняя6,5 | — | 68,8 % | 14 июл. 2022 г. |
47В плане | CVE-2017-3731Эксплойта нет | Truncated packet could crash via OOB readopenssl · openssl · CWE-125 | Высокая7,5 | — | 57,3 % | 4 мая 2017 г. |
46В плане | CVE-2017-14849Proof of concept | Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pnodejs · node.js · CWE-22 | Высокая7,5 | — | 54,4 % | 27 сент. 2017 г. |
46В плане | CVE-2020-8277Proof of concept | A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versinodejs · node.js · CWE-400 | Высокая7,5 | — | 54,2 % | 18 нояб. 2020 г. |
46В плане | CVE-2021-22931Эксплойта нет | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validationnodejs · node.js · CWE-170 | Критическая9,8 | — | 22,0 % | 16 авг. 2021 г. |
45В плане | CVE-2021-23840Proof of concept | Integer overflow in CipherUpdateopenssl · openssl · CWE-190 | Высокая7,5 | — | 50,7 % | 16 февр. 2021 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2014-022458В плане
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
ВысокаяCVSS 7,4Готовый эксплойтEPSS 95 %openssl · openssl5 июн. 2014 г.
- CVE-2016-218358В плане
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
ВысокаяCVSS 7,5Proof of conceptEPSS 95 %redhat · jboss enterprise application platform31 авг. 2016 г.
- CVE-2022-378658В плане
X.509 Email Address Variable Length Buffer Overflow
ВысокаяCVSS 7,5Proof of conceptEPSS 92 %openssl · openssl1 нояб. 2022 г.
- CVE-2024-2798358В плане
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 f
ВысокаяCVSS 8,2Proof of conceptEPSS 87 %nodejs · node8 апр. 2024 г.
- CVE-2022-360257В плане
X.509 Email Address 4-byte Buffer Overflow
ВысокаяCVSS 7,5Proof of conceptEPSS 91 %openssl · openssl1 нояб. 2022 г.
- CVE-2019-951556В плане
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 87 %apple · swiftnio13 авг. 2019 г.
- CVE-2019-1560556В плане
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
КритическаяCVSS 9,8Proof of conceptEPSS 57 %nodejs · node.js7 февр. 2020 г.
- CVE-2019-951255В плане
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 83 %apple · swiftnio13 авг. 2019 г.
- CVE-2019-951455В плане
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 83 %apple · swiftnio13 авг. 2019 г.
- CVE-2019-951354В плане
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 82 %apple · swiftnio13 авг. 2019 г.
- CVE-2021-2288352В плане
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an
ВысокаяCVSS 7,5Эксплойта нетEPSS 74 %nodejs · node.js3 мар. 2021 г.
- CVE-2022-077852В плане
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
ВысокаяCVSS 7,5Proof of conceptEPSS 73 %openssl · openssl15 мар. 2022 г.
- CVE-2022-3221451В плане
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
СредняяCVSS 6,5Эксплойта нетEPSS 82 %llhttp · llhttp14 июл. 2022 г.
- CVE-2016-210750В плане
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding chec
СредняяCVSS 5,9Proof of conceptEPSS 89 %openssl · openssl4 мая 2016 г.
- CVE-2021-2293050В плане
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory c
КритическаяCVSS 9,8Эксплойта нетEPSS 36 %nodejs · node.js7 окт. 2021 г.
- CVE-2016-630449В плане
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a d
ВысокаяCVSS 7,5Эксплойта нетEPSS 63 %openssl · openssl26 сент. 2016 г.
- CVE-2016-630349В плане
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of
КритическаяCVSS 9,8Эксплойта нетEPSS 32 %openssl · openssl16 сент. 2016 г.
- CVE-2019-951148В плане
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service
ВысокаяCVSS 7,5Proof of conceptEPSS 60 %apple · swiftnio13 авг. 2019 г.
- CVE-2022-3221547В плане
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
СредняяCVSS 6,5Эксплойта нетEPSS 69 %llhttp · llhttp14 июл. 2022 г.
- CVE-2017-373147В плане
Truncated packet could crash via OOB read
ВысокаяCVSS 7,5Эксплойта нетEPSS 57 %openssl · openssl4 мая 2017 г.
- CVE-2017-1484946В плане
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the p
ВысокаяCVSS 7,5Proof of conceptEPSS 54 %nodejs · node.js27 сент. 2017 г.
- CVE-2020-827746В плане
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versi
ВысокаяCVSS 7,5Proof of conceptEPSS 54 %nodejs · node.js18 нояб. 2020 г.
- CVE-2021-2293146В плане
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation
КритическаяCVSS 9,8Эксплойта нетEPSS 22 %nodejs · node.js16 авг. 2021 г.
- CVE-2021-2384045В плане
Integer overflow in CipherUpdate
ВысокаяCVSS 7,5Proof of conceptEPSS 51 %openssl · openssl16 февр. 2021 г.