Vulnerabilities > Nodejs

DATE CVE VULNERABILITY TITLE RISK
2018-05-17 CVE-2018-7160 Authentication Bypass by Spoofing vulnerability in Nodejs Node.Js
The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution.
network
low complexity
nodejs CWE-290
8.8
2018-05-17 CVE-2018-7159 Improper Input Validation vulnerability in Nodejs Node.Js
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`.
network
low complexity
nodejs CWE-20
5.3
2018-05-17 CVE-2018-7158 Unspecified vulnerability in Nodejs Node.Js
The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector.
network
low complexity
nodejs
7.5
2018-05-08 CVE-2018-1000168 NULL Pointer Dereference vulnerability in multiple products
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service.
network
low complexity
nghttp2 nodejs debian CWE-476
7.5
2017-12-11 CVE-2017-15897 Improper Initialization vulnerability in Nodejs Node.Js
Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified.
network
high complexity
nodejs CWE-665
3.1
2017-12-11 CVE-2017-15896 Unspecified vulnerability in Nodejs Node.Js
Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure.
network
low complexity
nodejs
critical
9.1
2017-12-07 CVE-2017-3738 Information Exposure vulnerability in multiple products
There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli.
network
high complexity
openssl debian nodejs CWE-200
5.9
2017-10-30 CVE-2017-14919 Improper Input Validation vulnerability in Nodejs Node.Js
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
network
low complexity
nodejs CWE-20
7.5
2017-10-23 CVE-2014-3744 Path Traversal vulnerability in Nodejs Node.Js
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
network
low complexity
nodejs CWE-22
7.5
2017-10-10 CVE-2015-7384 Resource Exhaustion vulnerability in Nodejs Node.Js 4.0.0/4.1.0/4.1.1
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
network
low complexity
nodejs CWE-400
7.5