Vulnerabilities > UA Parser JS Project

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2022-25927 Unspecified vulnerability in Ua-Parser-Js Project Ua-Parser-Js
Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.
network
low complexity
ua-parser-js-project
7.5
2022-05-24 CVE-2021-4229 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ua-Parser-Js Project Ua-Parser-Js 0.7.29/0.8.0/1.0.0
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0.
network
high complexity
ua-parser-js-project CWE-829
7.6
2021-03-17 CVE-2021-27292 Unspecified vulnerability in Ua-Parser-Js Project Ua-Parser-Js
ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service.
network
low complexity
ua-parser-js-project
5.0
2020-12-11 CVE-2020-7793 The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
network
low complexity
ua-parser-js-project siemens
5.0
2020-09-16 CVE-2020-7733 Resource Exhaustion vulnerability in multiple products
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
network
low complexity
ua-parser-js-project oracle CWE-400
7.5