Unknown · CVSS Not scored
The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop for around 10 seconds.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will cause the node process to error out.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression denial of service when it's passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.
Published Jun 7, 2018 · Updated Sep 17, 2024
Medium · CVSS 5.3
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.
Published Jun 6, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to evaluate a string and takes unescaped separator values, which can be used to create a denial of service attack.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the event loop causing a denial of service condition.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Published Jun 24, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
intsol-package is a file server. intsol-package is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exists in core\admin\modules\developer\extensions\install\unpack.php and core\admin\modules\developer\packages\install\unpack.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.
Published Jun 5, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
fast-http-cli is the command line interface for fast-http, a simple web server. fast-http-cli is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
serve46 is a static file server. serve46 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Buffer might get used after it gets freed due to unlocking the mutex before freeing the buffer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via the index.php/user/1 URI), including its password.
Published Jun 15, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulnerability in hostr 2.3.5 and earlier that allows an attacker to read files outside the current directory by sending `../` in the url path for GET requests.
Published Jun 4, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS.
Published Jun 29, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code.
Published Jun 5, 2017 · Updated Sep 17, 2024
High · CVSS 8.8
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary characters in the pureftpd.passwd file during a username change, which in turn allows for bypassing chroot restrictions in the FTP server. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
Published Jun 29, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
Published Jun 6, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
goserv is an http server. goserv is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
http_static_simple is an http server. http_static_simple is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.safe_load on input. This has been tested in all Puppet-supplied MCollective plugins, but there is a chance that third-party plugins could rely on this insecure behavior.
Published Jun 30, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
dasafio is a web server. dasafio is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. File access is restricted to only .html files.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
calmquist.static-server is a static file server. calmquist.static-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
dmmcquay.lab6 is a REST server. dmmcquay.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In ImageMagick 7.0.5-5, the ReadPALMImage function in palm.c allows attackers to cause a denial of service (memory leak) via a crafted file.
Published Jun 2, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 16, 2024
High · CVSS 8.8
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-Site-Scripting (XSS) is possible in GitBook before 3.2.2 by including code outside of backticks in any ebook. This code will be executed on the online reader.
Published Jun 4, 2018 · Updated Sep 16, 2024
High · CVSS 7.2
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter.
Published Jun 8, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
Published Jun 15, 2018 · Updated Sep 16, 2024
Medium · CVSS 4.3
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
Published Jun 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
serverabc is a static file server. serverabc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Low · CVSS 2.7
Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) author_name parameter in manifest.json. This issue exists in core\admin\modules\developer\extensions\install\unpack.php and core\admin\modules\developer\packages\install\unpack.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.
Published Jun 5, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
sspa is a server dedicated to single-page apps. sspa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024