nodejs kayıtları
nodejs üreticisine ait 245 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,4
- Silahlaştırılmış
- 3 · %1,2
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %98
- Yayından KEV’e ortanca
- 0 gün
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption26
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor14
- CWE-20 Improper Input Validation14
- CWE-284 Improper Access Control12
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')11
- CWE-295 Improper Certificate Validation10
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
245 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
58Planlayın | CVE-2014-0224Silahlaştırılmış | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Yüksek7,4 | — | %95,3 | 5 Haz 2014 |
58Planlayın | CVE-2016-2183Kavram kanıtı | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | Yüksek7,5 | — | %94,7 | 31 Ağu 2016 |
58Planlayın | CVE-2022-3786Kavram kanıtı | X.509 Email Address Variable Length Buffer Overflowopenssl · openssl · CWE-120 | Yüksek7,5 | — | %92,5 | 1 Kas 2022 |
58Planlayın | CVE-2024-27983Kavram kanıtı | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 fnodejs · node · CWE-362 | Yüksek8,2 | — | %87,2 | 8 Nis 2024 |
57Planlayın | CVE-2022-3602Kavram kanıtı | X.509 Email Address 4-byte Buffer Overflowopenssl · openssl · CWE-787 | Yüksek7,5 | — | %90,8 | 1 Kas 2022 |
56Planlayın | CVE-2019-9515İstismar yok | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Yüksek7,5 | — | %87,4 | 13 Ağu 2019 |
56Planlayın | CVE-2019-15605Kavram kanıtı | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformednodejs · node.js · CWE-444 | Kritik9,8 | — | %57,1 | 7 Şub 2020 |
55Planlayın | CVE-2019-9512İstismar yok | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Yüksek7,5 | — | %83,4 | 13 Ağu 2019 |
55Planlayın | CVE-2019-9514İstismar yok | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Yüksek7,5 | — | %82,8 | 13 Ağu 2019 |
54Planlayın | CVE-2019-9513İstismar yok | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Yüksek7,5 | — | %81,6 | 13 Ağu 2019 |
52Planlayın | CVE-2021-22883İstismar yok | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an nodejs · node.js · CWE-400 | Yüksek7,5 | — | %74,4 | 3 Mar 2021 |
52Planlayın | CVE-2022-0778Kavram kanıtı | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | Yüksek7,5 | — | %73,2 | 15 Mar 2022 |
51Planlayın | CVE-2022-32214İstismar yok | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Orta6,5 | — | %82,5 | 14 Tem 2022 |
50Planlayın | CVE-2016-2107Kavram kanıtı | The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding checopenssl · openssl · CWE-200 | Orta5,9 | — | %89,1 | 4 May 2016 |
50Planlayın | CVE-2021-22930İstismar yok | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory cnodejs · node.js · CWE-416 | Kritik9,8 | — | %36,5 | 7 Eki 2021 |
49Planlayın | CVE-2016-6304İstismar yok | Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a dopenssl · openssl · CWE-401 | Yüksek7,5 | — | %63,0 | 26 Eyl 2016 |
49Planlayın | CVE-2016-6303İstismar yok | Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of openssl · openssl · CWE-787 | Kritik9,8 | — | %32,0 | 16 Eyl 2016 |
48Planlayın | CVE-2019-9511Kavram kanıtı | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Yüksek7,5 | — | %59,5 | 13 Ağu 2019 |
47Planlayın | CVE-2022-32215İstismar yok | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Orta6,5 | — | %68,8 | 14 Tem 2022 |
47Planlayın | CVE-2017-3731İstismar yok | Truncated packet could crash via OOB readopenssl · openssl · CWE-125 | Yüksek7,5 | — | %57,3 | 4 May 2017 |
46Planlayın | CVE-2017-14849Kavram kanıtı | Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pnodejs · node.js · CWE-22 | Yüksek7,5 | — | %54,4 | 27 Eyl 2017 |
46Planlayın | CVE-2020-8277Kavram kanıtı | A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versinodejs · node.js · CWE-400 | Yüksek7,5 | — | %54,2 | 18 Kas 2020 |
46Planlayın | CVE-2021-22931İstismar yok | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validationnodejs · node.js · CWE-170 | Kritik9,8 | — | %22,0 | 16 Ağu 2021 |
45Planlayın | CVE-2021-23840Kavram kanıtı | Integer overflow in CipherUpdateopenssl · openssl · CWE-190 | Yüksek7,5 | — | %50,7 | 16 Şub 2021 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2014-022458Planlayın
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
YüksekCVSS 7,4SilahlaştırılmışEPSS %95openssl · openssl5 Haz 2014
- CVE-2016-218358Planlayın
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
YüksekCVSS 7,5Kavram kanıtıEPSS %95redhat · jboss enterprise application platform31 Ağu 2016
- CVE-2022-378658Planlayın
X.509 Email Address Variable Length Buffer Overflow
YüksekCVSS 7,5Kavram kanıtıEPSS %92openssl · openssl1 Kas 2022
- CVE-2024-2798358Planlayın
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 f
YüksekCVSS 8,2Kavram kanıtıEPSS %87nodejs · node8 Nis 2024
- CVE-2022-360257Planlayın
X.509 Email Address 4-byte Buffer Overflow
YüksekCVSS 7,5Kavram kanıtıEPSS %91openssl · openssl1 Kas 2022
- CVE-2019-951556Planlayın
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
YüksekCVSS 7,5İstismar yokEPSS %87apple · swiftnio13 Ağu 2019
- CVE-2019-1560556Planlayın
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
KritikCVSS 9,8Kavram kanıtıEPSS %57nodejs · node.js7 Şub 2020
- CVE-2019-951255Planlayın
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service
YüksekCVSS 7,5İstismar yokEPSS %83apple · swiftnio13 Ağu 2019
- CVE-2019-951455Planlayın
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
YüksekCVSS 7,5İstismar yokEPSS %83apple · swiftnio13 Ağu 2019
- CVE-2019-951354Planlayın
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
YüksekCVSS 7,5İstismar yokEPSS %82apple · swiftnio13 Ağu 2019
- CVE-2021-2288352Planlayın
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an
YüksekCVSS 7,5İstismar yokEPSS %74nodejs · node.js3 Mar 2021
- CVE-2022-077852Planlayın
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
YüksekCVSS 7,5Kavram kanıtıEPSS %73openssl · openssl15 Mar 2022
- CVE-2022-3221451Planlayın
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
OrtaCVSS 6,5İstismar yokEPSS %82llhttp · llhttp14 Tem 2022
- CVE-2016-210750Planlayın
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding chec
OrtaCVSS 5,9Kavram kanıtıEPSS %89openssl · openssl4 May 2016
- CVE-2021-2293050Planlayın
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory c
KritikCVSS 9,8İstismar yokEPSS %36nodejs · node.js7 Eki 2021
- CVE-2016-630449Planlayın
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a d
YüksekCVSS 7,5İstismar yokEPSS %63openssl · openssl26 Eyl 2016
- CVE-2016-630349Planlayın
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of
KritikCVSS 9,8İstismar yokEPSS %32openssl · openssl16 Eyl 2016
- CVE-2019-951148Planlayın
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service
YüksekCVSS 7,5Kavram kanıtıEPSS %60apple · swiftnio13 Ağu 2019
- CVE-2022-3221547Planlayın
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
OrtaCVSS 6,5İstismar yokEPSS %69llhttp · llhttp14 Tem 2022
- CVE-2017-373147Planlayın
Truncated packet could crash via OOB read
YüksekCVSS 7,5İstismar yokEPSS %57openssl · openssl4 May 2017
- CVE-2017-1484946Planlayın
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the p
YüksekCVSS 7,5Kavram kanıtıEPSS %54nodejs · node.js27 Eyl 2017
- CVE-2020-827746Planlayın
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versi
YüksekCVSS 7,5Kavram kanıtıEPSS %54nodejs · node.js18 Kas 2020
- CVE-2021-2293146Planlayın
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation
KritikCVSS 9,8İstismar yokEPSS %22nodejs · node.js16 Ağu 2021
- CVE-2021-2384045Planlayın
Integer overflow in CipherUpdate
YüksekCVSS 7,5Kavram kanıtıEPSS %51openssl · openssl16 Şub 2021