Vulnerabilities > Serialize TO JS Project

DATE CVE VULNERABILITY TITLE RISK
2019-12-07 CVE-2019-16772 Cross-site Scripting vulnerability in Serialize-To-Js Project Serialize-To-Js
The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS).
network
low complexity
serialize-to-js-project CWE-79
6.1
2017-10-24 CVE-2017-15871 Infinite Loop vulnerability in Serialize-To-Js Project Serialize-To-Js
The deserialize function in serialize-to-js through 1.1.1 allows attackers to cause a denial of service via vectors involving an Immediately Invoked Function Expression "function()" substring, as demonstrated by a "function(){console.log(" call or a simple infinite loop.
network
low complexity
serialize-to-js-project CWE-835
7.5
2017-02-10 CVE-2017-5954 Deserialization of Untrusted Data vulnerability in Serialize-To-Js Project Serialize-To-Js 0.5.0
An issue was discovered in the serialize-to-js package 0.5.0 for Node.js.
network
low complexity
serialize-to-js-project CWE-502
critical
9.8