Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Apk Parser HIGH 8.1
CVE-2016-10564

apk-parser is a tool to extract Android Manifest info from an APK file. apk-parser versions below 0.1.6 download binary resources over HTTP, which le…

Fix: 0.1.6+
Fix from $1,950 2018-05-31
Operadriver HIGH 8.1
CVE-2016-10565

operadriver is a Opera Driver for Selenium. operadriver versions below 0.2.3 download binary resources over HTTP, which leaves it vulnerable to MITM …

Fix: 0.2.3+
Fix from $1,950 2018-05-31
Embedza HIGH 8.1
CVE-2016-10569

embedza is a module to create HTML snippets/embeds from URLs using info from oEmbed, Open Graph, meta tags. embedza versions below 1.2.4 download Jav…

Fix: 1.2.4+
Fix from $1,950 2018-05-31
Bkjs Wand HIGH 8.1
CVE-2016-10571

bkjs-wand is imagemagick wand support for node.js and backendjs bkjs-wand versions lower than 0.3.2 download binary resources over HTTP, which leaves…

Fix: 0.3.2+
Fix from $1,950 2018-05-31
Mongodb Instance HIGH 8.1
CVE-2016-10572

mongodb-instance before 0.0.3 installs mongodb locally. mongodb-instance downloads binary resources over HTTP, which leaves it vulnerable to MITM att…

Fix: 0.0.3+
Fix from $1,950 2018-05-31
Csrf Lite MEDIUM 5.9
CVE-2016-10535

csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail first string comparison, ins…

Fix: after 0.1.1
Fix from $1,600 2018-05-31
Airbrake MEDIUM 5.9
CVE-2016-10530

The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys …

Fix: after 0.3.8
Fix from $1,600 2018-05-31
Roslibjs HIGH 8.1
CVE-2016-10681

roslib-socketio - The standard ROS Javascript Library fork for add support to socket.io roslib-socketio downloads binary resources over HTTP, which l…

Fix: after 0.18.0
Fix from $1,950 2018-05-29
Massif HIGH 8.1
CVE-2016-10682

massif is a Phantomjs fork massif downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code …

Fix: after 0.0.1-1
Fix from $1,950 2018-05-29
Mystem Fix HIGH 8.1
CVE-2016-10698

mystem-fix is a node.js wrapper for MyStem morphology text analyzer by Yandex.ru mystem-fix downloads binary resources over HTTP, which leaves it vul…

Fix: after 0.0.5
Fix from $1,950 2018-05-29
Pngcrush Installer HIGH 8.1
CVE-2016-10570

pngcrush-installer is an installer for Pngcrush. pngcrush-installer versions below 1.8.10 download binary resources over HTTP, which leaves it vulner…

Fix: 1.8.10+
Fix from $1,950 2018-05-29
Baryton Saxophone HIGH 8.1
CVE-2016-10573

baryton-saxophone is a module to install and launch Selenium Server for Mac, Linux and Windows. baryton-saxophone versions below 3.0.1 download binar…

Fix: 3.0.1+
Fix from $1,950 2018-05-29
Ibm Db HIGH 8.1
CVE-2016-10577

ibm_db is an asynchronous/synchronous interface for node.js to IBM DB2 and IBM Informix. ibm_db before 1.0.2 downloads binary resources over HTTP, wh…

Fix: 1.0.2+
Fix from $1,950 2018-05-29
Unicode HIGH 8.1
CVE-2016-10578

unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulner…

Fix: 9.0.0+
Fix from $1,950 2018-05-29
Dalekjs HIGH 8.1
CVE-2016-10584

dalek-browser-chrome-canary provides Google Chrome bindings for DalekJS. dalek-browser-chrome-canary downloads binary resources over HTTP, which leav…

Fix: after 0.0.11
Fix from $1,950 2018-05-29
Macaca Chromedriver HIGH 8.1
CVE-2016-10586

macaca-chromedriver is a Node.js wrapper for the selenium chromedriver. macaca-chromedriver before 1.0.29 downloads binary resources over HTTP, which…

Fix: 1.0.29+
Fix from $1,950 2018-05-29
Selenium Binaries HIGH 8.1
CVE-2016-10589

selenium-binaries downloads Selenium related binaries for your OS. selenium-binaries downloads binary resources over HTTP, which leaves it vulnerable…

Fix: after 0.10.0
Fix from $1,950 2018-05-29
Cue Sdk Node HIGH 8.1
CVE-2016-10590

cue-sdk-node is a Corsair Cue SDK wrapper for node.js. cue-sdk-node downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks.…

Fix: after 1.2.0
Fix from $1,950 2018-05-29
Prince HIGH 8.1
CVE-2016-10591

Prince is a Node API for executing XML/HTML to PDF renderer PrinceXML via prince(1) CLI. prince downloads zipped resources over HTTP, which leaves it…

Fix: 1.4.6+
Fix from $1,950 2018-05-29
Ibapi HIGH 8.1
CVE-2016-10593

ibapi is an Interactive Brokers API addon for NodeJS. ibapi downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. Before …

Fix: after 2.4.2
Fix from $1,950 2018-05-29
Webdrvr HIGH 8.1
CVE-2016-10601

webdrvr is a npm wrapper for Selenium Webdriver including Chromedriver / IEDriver / IOSDriver / Ghostdriver. webdrvr downloads binary resources over …

Fix: after 2.43.0-1
Fix from $1,950 2018-05-29
Strider Sauce HIGH 8.1
CVE-2016-10611

strider-sauce is Sauce Labs / Selenium support for Strider. strider-sauce downloads zipped resources over HTTP, which leaves it vulnerable to MITM at…

Fix: after 0.6.3
Fix from $1,950 2018-05-29
Scala Bin HIGH 8.1
CVE-2016-10627

scala-bin is a binary wrapper for Scala. scala-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possib…

Fix: after 0.3.3
Fix from $1,950 2018-05-29
Broccoli Closure HIGH 8.1
CVE-2016-10635

broccoli-closure is a Closure compiler plugin for Broccoli. broccoli-closure before 1.3.1 downloads binary resources over HTTP, which leaves it vulne…

Fix: 1.3.1+
Fix from $1,950 2018-05-29
Ntfserver HIGH 8.1
CVE-2016-10650

ntfserver is a Network Testing Framework Server. ntfserver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may b…

Fix: after 0.0.18
Fix from $1,950 2018-05-29
Native Opencv HIGH 8.1
CVE-2016-10658

native-opencv is the OpenCV library installed via npm native-opencv downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.…

Mitigation only
Fix from $1,950 2018-05-29
Poco HIGH 8.1
CVE-2016-10659

poco - The POCO libraries, downloads source file resources used for compilation over HTTP, which leaves it vulnerable to MITM attacks. It may be poss…

Fix: after 1.7.7
Fix from $1,950 2018-05-29
Tomita Parser HIGH 8.1
CVE-2016-10666

tomita-parser is a Node wrapper for Yandex Tomita Parser tomita-parser downloads binary resources over HTTP, which leaves it vulnerable to MITM attac…

Fix: after 0.0.3
Fix from $1,950 2018-05-29
Limbus Buildgen HIGH 8.1
CVE-2016-10674

limbus-buildgen is a "build anywhere" build system. limbus-buildgen versions below 0.1.1 download binary resources over HTTP, which leaves it vulnera…

Fix: 0.1.1+
Fix from $1,950 2018-05-29
Selenium Standalone Painful HIGH 8.1
CVE-2016-10679

selenium-standalone-painful installs a start-selenium command line to start a standalone selenium server with chrome-driver. selenium-standalone-pain…

Fix: after 2.39.0-2.7.0
Fix from $1,950 2018-05-29