İçeriğe atla
Noroxi

llhttp kayıtları

llhttp üreticisine ait 6 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

  1. 21
  2. 22

Çubuk: toplam · koyu kısım: CISA KEV.

Tekrar eden sınıflar

Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.

CWE

Saldırı profili

Tüm kayıtlar

6 kayıt
  • CVE-2022-32214
    51Planlayın

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re

    OrtaCVSS 6,5İstismar yokEPSS %82

    llhttp · llhttp14 Tem 2022

  • CVE-2022-32215
    47Planlayın

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea

    OrtaCVSS 6,5İstismar yokEPSS %69

    llhttp · llhttp14 Tem 2022

  • CVE-2022-32213
    39İzleyin

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he

    OrtaCVSS 6,5İstismar yokEPSS %44

    llhttp · llhttp14 Tem 2022

  • CVE-2021-22959
    27İzleyin

    The parser in accepts requests with a space (SP) right after the header name before the colon.

    OrtaCVSS 6,5İstismar yokEPSS %3

    llhttp · llhttp15 Kas 2021

  • CVE-2022-35256
    27İzleyin

    The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF.

    OrtaCVSS 6,5İstismar yokEPSS %3

    llhttp · llhttp5 Ara 2022

  • CVE-2021-22960
    27İzleyin

    The parse function in llhttp < 2.1.4 and < 6.0.6.

    OrtaCVSS 6,5İstismar yokEPSS %2

    llhttp · llhttp3 Kas 2021