Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Httpsync HIGH 8.1
CVE-2016-10614

httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possib…

Mitigation only
Fix from $1,950 2018-06-01
Curses HIGH 8.1
CVE-2016-10615

curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources over HTTP, which leaves it vu…

Fix: after 0.0.10
Fix from $1,950 2018-06-01
Openframe Image HIGH 8.1
CVE-2016-10616

openframe-image is an Openframe extension which adds support for images via fbi. openframe-image downloads data resources over HTTP, which leaves it …

Fix: after 0.2.0
Fix from $1,950 2018-06-01
Box2d Native HIGH 8.1
CVE-2016-10617

box2d-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE…

Fix: after 0.0.8
Fix from $1,950 2018-06-01
Node Browser HIGH 8.1
CVE-2016-10618

node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

Fix: after 0.0.3
Fix from $1,950 2018-06-01
Pennyworth HIGH 8.1
CVE-2016-10619

pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

Fix: after 1.0.1
Fix from $1,950 2018-06-01
Atom Node Module Installer HIGH 8.1
CVE-2016-10620

atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which leaves it …

Fix: after 0.9.0
Fix from $1,950 2018-06-01
Fibjs HIGH 8.1
CVE-2016-10621

fibjs is a runtime for javascript applictions built on google v8 JS. fibjs downloads binary resources over HTTP, which leaves it vulnerable to MITM a…

Fix: after 0.1.8
Fix from $1,950 2018-06-01
Nodeschnaps HIGH 8.1
CVE-2016-10622

nodeschnaps is a NodeJS compatibility layer for Java (Rhino). nodeschnaps downloads binary resources over HTTP, which leaves it vulnerable to MITM at…

Fix: 1.0.3+
Fix from $1,950 2018-06-01
Apk Parser3 HIGH 8.1
CVE-2016-10574

apk-parser3 is a module to extract Android Manifest info from an APK file. apk-parser3 versions before 0.1.3 download binary resources over HTTP, whi…

Fix: 0.1.3+
Fix from $1,950 2018-06-01
Kindlegen HIGH 8.1
CVE-2016-10575

Kindlegen is a simple Node.js wrapper of the official kindlegen program. Kindlegen versions before 1.1.0 download binary resources over HTTP, which l…

Fix: 1.1.0+
Fix from $1,950 2018-06-01
Fuseki HIGH 8.1
CVE-2016-10576

Fuseki server wrapper and management API in fuseki before 1.0.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It …

Fix: 1.0.1+
Fix from $1,950 2018-06-01
Chromedriver HIGH 8.1
CVE-2016-10579

Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTTP, which leaves it vulnerable…

Fix: 2.26.1+
Fix from $1,950 2018-06-01
Nodewebkit HIGH 8.1
CVE-2016-10580

nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be po…

Fix: after 0.11.2-1
Fix from $1,950 2018-06-01
Steroids HIGH 8.1
CVE-2016-10581

Steroids is PhoneGap on Steroids, providing native UI elements, multiple WebViews and enhancements for better developer productivity. steroids downlo…

Fix: after 4.1.27
Fix from $1,950 2018-06-01
Closurecompiler HIGH 8.1
CVE-2016-10582

closurecompiler is a Closure Compiler for node.js. closurecompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. …

Fix: after 1.6.1
Fix from $1,950 2018-06-01
Closure Util HIGH 8.1
CVE-2016-10583

closure-utils is Utilities for Closure Library based projects. closure-utils downloads binary resources over HTTP, which leaves it vulnerable to MITM…

Fix: after 1.26.0
Fix from $1,950 2018-06-01
Libxl HIGH 8.1
CVE-2016-10585

libxl provides Node bindings for the libxl library for reading and writing excel (XLS and XLSX) spreadsheets. libxl downloads zipped resources over H…

Fix: after 0.3.0
Fix from $1,950 2018-06-01
Wasdk HIGH 8.1
CVE-2016-10587

wasdk is a toolkit for creating WebAssembly modules. wasdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may b…

Fix: after 1.0.54
Fix from $1,950 2018-06-01
Nw HIGH 8.1
CVE-2016-10588

nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the re…

Mitigation only
Fix from $1,950 2018-06-01
Jser Stat HIGH 8.1
CVE-2016-10592

jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

Fix: after 4.0.3
Fix from $1,950 2018-06-01
Ipip HIGH 8.1
CVE-2016-10594

ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downloads data resources over HTTP…

Mitigation only
Fix from $1,950 2018-06-01
Jdf Sass HIGH 8.1
CVE-2016-10595

jdf-sass is a fork from node-sass, jdf use only. jdf-sass downloads executable resources over HTTP, which leaves it vulnerable to MITM attacks. It ma…

Fix: after 1.0.18
Fix from $1,950 2018-06-01
Imageoptim HIGH 8.1
CVE-2016-10596

imageoptim is a Node.js wrapper for some images compression algorithms. imageoptim downloads zipped resources over HTTP, which leaves it vulnerable t…

Fix: after 0.5.0
Fix from $1,950 2018-06-01
Arrayfire Js HIGH 7.5
CVE-2016-10598

arrayfire-js is a module for ArrayFire for the Node.js platform. arrayfire-js downloads binary resources over HTTP, which leaves it vulnerable to MIT…

Fix: after 0.21.4
Fix from $1,950 2018-06-01
Jwt Simple MEDIUM 6.5
CVE-2016-10555

Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the ser…

Fix: after 0.3.0
Fix from $1,600 2018-05-31
Appium Chromedriver HIGH 8.1
CVE-2016-10557

appium-chromedriver is a Node.js wrapper around Chromedriver. Versions below 2.9.4 download binary resources over HTTP, which leaves the module vulne…

Fix: 2.9.4+
Fix from $1,950 2018-05-31
Galenframework Cli HIGH 8.1
CVE-2016-10560

galenframework-cli is the node wrapper for the Galen Framework. galenframework-cli below 2.3.1 download binary resources over HTTP, which leaves it v…

Fix: 2.3.1+
Fix from $1,950 2018-05-31
Iedriver HIGH 8.1
CVE-2016-10562

iedriver is an NPM wrapper for Selenium IEDriver. iedriver versions below 3.0.0 download binary resources over HTTP, which leaves the module vulnerab…

Fix: 3.0.0+
Fix from $1,950 2018-05-31
Go Ipfs Dep HIGH 8.1
CVE-2016-10563

During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to comp…

Fix: 0.4.4+
Fix from $1,950 2018-05-31