Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
HIGH 8.1 CVE-2016-10614 httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possib… Httpsync Mitigation only Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10615 curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources over HTTP, which leaves it vu… Curses after 0.0.10 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10616 openframe-image is an Openframe extension which adds support for images via fbi. openframe-image downloads data resources over HTTP, which leaves it … Openframe Image after 0.2.0 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10617 box2d-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE… Box2d Native after 0.0.8 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10618 node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to MITM attacks. Node Browser after 0.0.3 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10619 pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks. Pennyworth after 1.0.1 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10620 atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which leaves it … Atom Node Module Installer after 0.9.0 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10621 fibjs is a runtime for javascript applictions built on google v8 JS. fibjs downloads binary resources over HTTP, which leaves it vulnerable to MITM a… Fibjs after 0.1.8 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10622 nodeschnaps is a NodeJS compatibility layer for Java (Rhino). nodeschnaps downloads binary resources over HTTP, which leaves it vulnerable to MITM at… Nodeschnaps 1.0.3+ Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10574 apk-parser3 is a module to extract Android Manifest info from an APK file. apk-parser3 versions before 0.1.3 download binary resources over HTTP, whi… Apk Parser3 0.1.3+ Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10575 Kindlegen is a simple Node.js wrapper of the official kindlegen program. Kindlegen versions before 1.1.0 download binary resources over HTTP, which l… Kindlegen 1.1.0+ Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10576 Fuseki server wrapper and management API in fuseki before 1.0.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It … Fuseki 1.0.1+ Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10579 Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTTP, which leaves it vulnerable… Chromedriver 2.26.1+ Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10580 nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be po… Nodewebkit after 0.11.2-1 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10581 Steroids is PhoneGap on Steroids, providing native UI elements, multiple WebViews and enhancements for better developer productivity. steroids downlo… Steroids after 4.1.27 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10582 closurecompiler is a Closure Compiler for node.js. closurecompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. … Closurecompiler after 1.6.1 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10583 closure-utils is Utilities for Closure Library based projects. closure-utils downloads binary resources over HTTP, which leaves it vulnerable to MITM… Closure Util after 1.26.0 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10585 libxl provides Node bindings for the libxl library for reading and writing excel (XLS and XLSX) spreadsheets. libxl downloads zipped resources over H… Libxl after 0.3.0 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10587 wasdk is a toolkit for creating WebAssembly modules. wasdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may b… Wasdk after 1.0.54 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10588 nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the re… Nw Mitigation only Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10592 jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks. Jser Stat after 4.0.3 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10594 ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downloads data resources over HTTP… Ipip Mitigation only Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10595 jdf-sass is a fork from node-sass, jdf use only. jdf-sass downloads executable resources over HTTP, which leaves it vulnerable to MITM attacks. It ma… Jdf Sass after 1.0.18 Fix from $1,9502018-06-01 HIGH 8.1 CVE-2016-10596 imageoptim is a Node.js wrapper for some images compression algorithms. imageoptim downloads zipped resources over HTTP, which leaves it vulnerable t… Imageoptim after 0.5.0 Fix from $1,9502018-06-01 HIGH 7.5 CVE-2016-10598 arrayfire-js is a module for ArrayFire for the Node.js platform. arrayfire-js downloads binary resources over HTTP, which leaves it vulnerable to MIT… Arrayfire Js after 0.21.4 Fix from $1,9502018-06-01 MEDIUM 6.5 CVE-2016-10555 Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the ser… Jwt Simple after 0.3.0 Fix from $1,6002018-05-31 HIGH 8.1 CVE-2016-10557 appium-chromedriver is a Node.js wrapper around Chromedriver. Versions below 2.9.4 download binary resources over HTTP, which leaves the module vulne… Appium Chromedriver 2.9.4+ Fix from $1,9502018-05-31 HIGH 8.1 CVE-2016-10560 galenframework-cli is the node wrapper for the Galen Framework. galenframework-cli below 2.3.1 download binary resources over HTTP, which leaves it v… Galenframework Cli 2.3.1+ Fix from $1,9502018-05-31 HIGH 8.1 CVE-2016-10562 iedriver is an NPM wrapper for Selenium IEDriver. iedriver versions below 3.0.0 download binary resources over HTTP, which leaves the module vulnerab… Iedriver 3.0.0+ Fix from $1,9502018-05-31 HIGH 8.1 CVE-2016-10563 During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to comp… Go Ipfs Dep 0.4.4+ Fix from $1,9502018-05-31