Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Resourcehacker HIGH 8.1
CVE-2016-10646

resourcehacker is a Node wrapper of Resource Hacker (windows executable resource editor). resourcehacker downloads binary resources over HTTP, which …

Mitigation only
Fix from $1,950 2018-06-04
Node Air Sdk HIGH 8.1
CVE-2016-10647

node-air-sdk is an AIR SDK for nodejs. node-air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possi…

Mitigation only
Fix from $1,950 2018-06-04
Marionette Socket Host HIGH 8.1
CVE-2016-10648

marionette-socket-host is a marionette-js-runner host for sending actions over a socket. marionette-socket-host downloads binary resources over HTTP,…

Mitigation only
Fix from $1,950 2018-06-04
Frames Compiler HIGH 8.1
CVE-2016-10649

frames-compiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (…

Mitigation only
Fix from $1,950 2018-06-04
Debian Linux MEDIUM 5.3
CVE-2016-1000339

In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven ap…

Fix: after 1.55
Fix from $1,600 2018-06-04
Debian Linux HIGH 7.5
CVE-2016-1000343

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If th…

Fix: after 1.55
Fix from $1,950 2018-06-04
Macaca Chromedriver Zxa HIGH 8.1
CVE-2016-10623

macaca-chromedriver-zxa is a Node.js wrapper for the selenium chromedriver. macaca-chromedriver-zxa downloads binary resources over HTTP, which leave…

Fix: after 0.1.9
Fix from $1,950 2018-06-01
Selenium Chromedriver HIGH 8.1
CVE-2016-10624

selenium-chromedriver is a simple utility for downloading the Selenium Webdriver for Google Chrome selenium-chromedriver downloads binary resources o…

Mitigation only
Fix from $1,950 2018-06-01
Headless Browser Lite HIGH 8.1
CVE-2016-10625

headless-browser-lite is a minimal npm installer for phantomjs and slimerjs with no external dependencies. headless-browser-lite downloads binary res…

Fix: 2015.4.18-a+
Fix from $1,950 2018-06-01
Mystem3 HIGH 8.1
CVE-2016-10626

mystem3 is a NodeJS wrapper for the Yandex MyStem 3. mystem3 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may…

Fix: after 1.0.7
Fix from $1,950 2018-06-01
Selenium Wrapper HIGH 8.1
CVE-2016-10628

selenium-wrapper is a selenium server wrapper, including installation and chrome webdriver. selenium-wrapper downloads binary resources over HTTP, wh…

Fix: after 0.0.9
Fix from $1,950 2018-06-01
Nw With Arm HIGH 8.1
CVE-2016-10629

nw-with-arm is a NW Installer including ARM-Build. nw-with-arm downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It m…

Fix: after 0.12.2
Fix from $1,950 2018-06-01
Install G Test MEDIUM 5.9
CVE-2016-10630

install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

Fix: after 2.0.12
Fix from $1,600 2018-06-01
Jvminstall HIGH 8.1
CVE-2016-10631

jvminstall is a module for downloading and unpacking jvm to local system. jvminstall downloads binary resources over HTTP, which leaves it vulnerable…

Fix: after 0.1.0
Fix from $1,950 2018-06-01
Apk Parser2 HIGH 8.1
CVE-2016-10632

apk-parser2 is a module which extracts Android Manifest info from an APK file. apk-parser2 downloads binary resources over HTTP, which leaves it vuln…

Fix: after 0.1.1
Fix from $1,950 2018-06-01
Dwebp Bin HIGH 8.1
CVE-2016-10633

dwebp-bin is a dwebp node.js wrapper that convert WebP into PNG. dwebp-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM a…

Fix: after 0.1.6
Fix from $1,950 2018-06-01
Scalajs Standalone Bin HIGH 8.1
CVE-2016-10634

scala-standalone-bin is a Binary wrapper for ScalaJS. scala-standalone-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM a…

Fix: after 0.4.3
Fix from $1,950 2018-06-01
Node Sauce Connect HIGH 8.1
CVE-2016-10599

sauce-connect is a Node.js wrapper over the SauceLabs SauceConnect.jar program for establishing a secure tunnel for intranet testing. sauce-connect d…

Fix: after 0.1.1
Fix from $1,950 2018-06-01
Webrtc Native HIGH 8.1
CVE-2016-10600

webrtc-native uses WebRTC from chromium project. webrtc-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It m…

Fix: after 1.4.0
Fix from $1,950 2018-06-01
Haxe HIGH 8.1
CVE-2016-10602

haxe is a cross-platform toolkit haxe downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause r…

Fix: after 5.0.10
Fix from $1,950 2018-06-01
Air Sdk HIGH 8.1
CVE-2016-10603

air-sdk is a NPM wrapper for the Adobe AIR SDK. air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be p…

Fix: after 16.0.0-272-16
Fix from $1,950 2018-06-01
Dalekjs HIGH 8.1
CVE-2016-10604

dalek-browser-chrome is Google Chrome bindings for DalekJS. dalek-browser-chrome downloads binary resources over HTTP, which leaves it vulnerable to …

Fix: after 0.0.11
Fix from $1,950 2018-06-01
Dalekjs HIGH 8.1
CVE-2016-10605

dalek-browser-ie is Internet Explorer bindings for DalekJS. dalek-browser-ie downloads binary resources over HTTP, which leaves it vulnerable to MITM…

Fix: after 0.0.5
Fix from $1,950 2018-06-01
Grunt Webdriver Qunit HIGH 8.1
CVE-2016-10606

grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, which leaves…

Fix: after 0.2.6
Fix from $1,950 2018-06-01
Openframe Glslviewer HIGH 8.1
CVE-2016-10607

openframe-glsviewer is a Openframe extension which adds support for shaders via glslViewer. openframe-glsviewer downloads binary resources over HTTP,…

Fix: after 0.2.7
Fix from $1,950 2018-06-01
Robot Js HIGH 7.5
CVE-2016-10608

robot-js is a module for native system automation for node.js. robot-js downloads binary resources over HTTP, which leaves it vulnerable to MITM atta…

Fix: after 2.0.0
Fix from $1,950 2018-06-01
Chromedriver126 HIGH 8.1
CVE-2016-10609

chromedriver126 is chromedriver version 1.26 for linux OS. chromedriver126 downloads binary resources over HTTP, which leaves it vulnerable to MITM a…

Fix: after 1.0.15
Fix from $1,950 2018-06-01
Unicode Json HIGH 8.1
CVE-2016-10610

unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

Fix: 2.0.0+
Fix from $1,950 2018-06-01
Dalekjs HIGH 8.1
CVE-2016-10612

dalek-browser-ie-canary is Internet Explorer bindings for DalekJS. dalek-browser-ie-canary downloads binary resources over HTTP, which leaves it vuln…

Fix: after 0.0.5
Fix from $1,950 2018-06-01
Bionode Sra MEDIUM 5.9
CVE-2016-10613

bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

Fix: after 1.0.3
Fix from $1,600 2018-06-01