Vulnerabilities > Joyent

DATE CVE VULNERABILITY TITLE RISK
2017-01-31 CVE-2016-9039 Resource Exhaustion vulnerability in Joyent Smartos 20161110T013148Z
An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
low complexity
joyent CWE-400
4.9
2016-12-14 CVE-2016-9035 Classic Buffer Overflow vulnerability in Joyent Smartos 20161110T013148Z
An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-120
7.0
2016-12-14 CVE-2016-9034 Classic Buffer Overflow vulnerability in Joyent Smartos 20120614/20161110T013148Z
An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-120
7.0
2016-12-14 CVE-2016-9033 Classic Buffer Overflow vulnerability in Joyent Smartos 20161110T013148Z
An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-120
7.0
2016-12-14 CVE-2016-9032 Classic Buffer Overflow vulnerability in Joyent Smartos 20161110T013148Z
An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-120
7.0
2016-12-14 CVE-2016-9031 Integer Overflow or Wraparound vulnerability in Joyent Smartos 20161110T013148Z
An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-190
7.8
2016-12-14 CVE-2016-8733 Integer Overflow or Wraparound vulnerability in Joyent Smartos 20120614/20161110T013148Z
An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
low complexity
joyent CWE-190
8.8
2014-12-11 CVE-2014-7192 Code Injection vulnerability in Joyent Node.Js 0.6.1/0.6.3
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.
network
low complexity
joyent CWE-94
critical
10.0
2014-10-08 CVE-2014-6394 Path Traversal vulnerability in multiple products
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
network
low complexity
fedoraproject apple joyent CWE-22
7.5
2012-06-12 CVE-2012-0217 Buffer Errors vulnerability in Freebsd
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application.
7.2