Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
HIGH 8.1 CVE-2016-10646 resourcehacker is a Node wrapper of Resource Hacker (windows executable resource editor). resourcehacker downloads binary resources over HTTP, which … Resourcehacker Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10647 node-air-sdk is an AIR SDK for nodejs. node-air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possi… Node Air Sdk Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10648 marionette-socket-host is a marionette-js-runner host for sending actions over a socket. marionette-socket-host downloads binary resources over HTTP,… Marionette Socket Host Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10649 frames-compiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (… Frames Compiler Mitigation only Fix from $1,9502018-06-04 MEDIUM 5.3 CVE-2016-1000339 In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven ap… Debian Linux after 1.55 Fix from $1,6002018-06-04 HIGH 7.5 CVE-2016-1000343 In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If th… Debian Linux after 1.55 Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10623 macaca-chromedriver-zxa is a Node.js wrapper for the selenium chromedriver. macaca-chromedriver-zxa downloads binary resources over HTTP, which leave… Macaca Chromedriver Zxa after 0.1.9 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10624 selenium-chromedriver is a simple utility for downloading the Selenium Webdriver for Google Chrome selenium-chromedriver downloads binary resources o… Selenium Chromedriver Mitigation only Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10625 headless-browser-lite is a minimal npm installer for phantomjs and slimerjs with no external dependencies. headless-browser-lite downloads binary res… Headless Browser Lite 2015.4.18-a+ Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10626 mystem3 is a NodeJS wrapper for the Yandex MyStem 3. mystem3 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may… Mystem3 after 1.0.7 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10628 selenium-wrapper is a selenium server wrapper, including installation and chrome webdriver. selenium-wrapper downloads binary resources over HTTP, wh… Selenium Wrapper after 0.0.9 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10629 nw-with-arm is a NW Installer including ARM-Build. nw-with-arm downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It m… Nw With Arm after 0.12.2 Fix from $1,9502018-06-01 MEDIUM 5.9 CVE-2016-10630 install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks. Install G Test after 2.0.12 Fix from $1,6002018-06-01 HIGH 8.1 CVE-2016-10631 jvminstall is a module for downloading and unpacking jvm to local system. jvminstall downloads binary resources over HTTP, which leaves it vulnerable… Jvminstall after 0.1.0 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10632 apk-parser2 is a module which extracts Android Manifest info from an APK file. apk-parser2 downloads binary resources over HTTP, which leaves it vuln… Apk Parser2 after 0.1.1 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10633 dwebp-bin is a dwebp node.js wrapper that convert WebP into PNG. dwebp-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM a… Dwebp Bin after 0.1.6 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10634 scala-standalone-bin is a Binary wrapper for ScalaJS. scala-standalone-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM a… Scalajs Standalone Bin after 0.4.3 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10599 sauce-connect is a Node.js wrapper over the SauceLabs SauceConnect.jar program for establishing a secure tunnel for intranet testing. sauce-connect d… Node Sauce Connect after 0.1.1 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10600 webrtc-native uses WebRTC from chromium project. webrtc-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It m… Webrtc Native after 1.4.0 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10602 haxe is a cross-platform toolkit haxe downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause r… Haxe after 5.0.10 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10603 air-sdk is a NPM wrapper for the Adobe AIR SDK. air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be p… Air Sdk after 16.0.0-272-16 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10604 dalek-browser-chrome is Google Chrome bindings for DalekJS. dalek-browser-chrome downloads binary resources over HTTP, which leaves it vulnerable to … Dalekjs after 0.0.11 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10605 dalek-browser-ie is Internet Explorer bindings for DalekJS. dalek-browser-ie downloads binary resources over HTTP, which leaves it vulnerable to MITM… Dalekjs after 0.0.5 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10606 grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, which leaves… Grunt Webdriver Qunit after 0.2.6 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10607 openframe-glsviewer is a Openframe extension which adds support for shaders via glslViewer. openframe-glsviewer downloads binary resources over HTTP,… Openframe Glslviewer after 0.2.7 Fix from $1,9502018-06-01 HIGH 7.5 CVE-2016-10608 robot-js is a module for native system automation for node.js. robot-js downloads binary resources over HTTP, which leaves it vulnerable to MITM atta… Robot Js after 2.0.0 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10609 chromedriver126 is chromedriver version 1.26 for linux OS. chromedriver126 downloads binary resources over HTTP, which leaves it vulnerable to MITM a… Chromedriver126 after 1.0.15 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10610 unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks. Unicode Json 2.0.0+ Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10612 dalek-browser-ie-canary is Internet Explorer bindings for DalekJS. dalek-browser-ie-canary downloads binary resources over HTTP, which leaves it vuln… Dalekjs after 0.0.5 Fix from $1,9502018-06-01 MEDIUM 5.9 CVE-2016-10613 bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks. Bionode Sra after 1.0.3 Fix from $1,6002018-06-01