Unknown · CVSS Not scored
charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due to integer overflow which could lead to local escalation of privilege in the TrustZone with no additional execution privileges needed. User interaction is not needed for exploitation. This issue is rated as high. Version: N/A. Android: A-69480285. Reference: N-CVE-2017-6292.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
dcdcdcdcdc is a static file server. dcdcdcdcdc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent URL, an attacker can get script to run in some browsers.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in modules/Base/Lang/Administrator/update_translation.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) original or (2) new parameter.
Published Jun 14, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next <=1.10.2.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
reecerver is a web server. reecerver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In ImageMagick 7.0.5-5, the ReadICONImage function in icon.c:452 allows attackers to cause a denial of service (memory leak) via a crafted file.
Published Jun 2, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete before a user is deleted.
Published Jun 2, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
hcbserver is a static file server. hcbserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
simple-npm-registry is a local npm package cache. simple-npm-registry is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the check_dst_limits_calc_pos_1 function in misc/regex/regexec.c when processing a crafted regular expression.
Published Jun 16, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added.
Published Jun 27, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.
Published Jun 12, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
earlybird is a web server module for early development. earlybird is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds write due to missing bounds check which could lead to escalation of privilege from the kernel to the TZ. User interaction is not needed for exploitation. This issue is rated as high. Version: N/A. Android: A-69316825. Reference: N-CVE-2017-6294.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.
Published Jun 28, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).
Published Jun 24, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
wffserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms because of their negative effect on performance and throughput. An attacker can forge arbitrary ADS packets when legitimate ADS traffic is observable.
Published Jun 27, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).
Published Jun 5, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly, via an iRule, or via the inflate code from PEM module are subjected to a service disruption via a "Zip Bomb" attack.
Published Jun 1, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
tencent-server is a simple web server. tencent-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
shit-server is a file server. shit-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
Published Jun 5, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
serverxxx is a static file server. serverxxx is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published Jun 7, 2018 · Updated Sep 16, 2024
Medium · CVSS 5.7
Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server (versions 6.1.1 and below, 6.2.0, 6.2.1, and 6.3.0), TIBCO JasperReports Server Community Edition (versions 6.3.0 and below), TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.2.0 and below), and TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.2.0 and below).
Published Jun 29, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.
Published Jun 4, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.
Published Jun 26, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (that performed a aegir-release) GitHub token.
Published Jun 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.
Published Jun 8, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parameter.
Published Jun 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted country data.
Published Jun 14, 2017 · Updated Sep 16, 2024