Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Fresh HIGH 7.5
CVE-2017-16119

Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service wh…

Fix: 0.5.2+
Fix from $1,950 2018-06-07
Ua Parser HIGH 7.5
CVE-2017-16086EPSS 9%

ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given …

Mitigation only
Fix from $1,950 2018-06-07
Uri Js MEDIUM 6.5
CVE-2017-16021

uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or not. To do t…

Fix: after 2.1.1
Fix from $1,600 2018-06-04
Decamelize HIGH 7.5
CVE-2017-16023

Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to e…

Mitigation only
Fix from $1,950 2018-06-04
Nes MEDIUM 5.9
CVE-2017-16025

Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerabili…

Fix: after 6.4.0
Fix from $1,600 2018-06-04
Useragent HIGH 7.5
CVE-2017-16030

Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creat…

Fix: after 2.1.12
Fix from $1,950 2018-06-04
Hapi HIGH 7.5
CVE-2017-16013

hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception…

Fix: after 16.1.0
Fix from $1,950 2018-06-04
Big Ip Application Acceleration Manager MEDIUM 5.3
CVE-2017-6153

Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly…

Fix: after 12.1.3
Fix from $1,600 2018-06-01
Negotiator HIGH 7.5
CVE-2016-10539

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Lan…

Fix: after 0.6.0
Fix from $1,950 2018-05-31
Minimatch HIGH 7.5
CVE-2016-10540

Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(…

Fix: after 3.0.1
Fix from $1,950 2018-05-31
Ws HIGH 7.5
CVE-2016-10542EPSS 8%

ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending…

Fix: after 1.1.0
Fix from $1,950 2018-05-31
Uws MEDIUM 5.9
CVE-2016-10544

uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibil…

Fix: after 0.10.8
Fix from $1,600 2018-05-31
Qs HIGH 7.5
CVE-2014-10064

The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested obje…

Fix: 1.0.0+
Fix from $1,950 2018-05-31
Ansi2html HIGH 7.5
CVE-2015-9239

ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.

No fix yet
Fix from $1,950 2018-05-31
Jadedown HIGH 7.5
CVE-2016-10520

jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.

Fix: after 0.0.3
Fix from $1,950 2018-05-31
Jshamcrest HIGH 7.5
CVE-2016-10521

jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator.

Fix: after 0.7.1
Fix from $1,950 2018-05-31
Mqtt Packet HIGH 7.5
CVE-2016-10523

MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible with very li…

Fix: 3.4.6 / 4.0.5+
Fix from $1,950 2018-05-31
I18n Node Angular HIGH 8.2
CVE-2016-10524

i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is used for deve…

Fix: 1.4.0+
Fix from $1,950 2018-05-31
Riot Compiler HIGH 7.5
CVE-2016-10527

The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions.

Mitigation only
Fix from $1,950 2018-05-31
Hapi HIGH 7.5
CVE-2015-9241

Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a …

Fix: 11.1.3+
Fix from $1,950 2018-05-29
Ecstatic HIGH 7.5
CVE-2015-9242

Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads …

Fix: 1.4.0+
Fix from $1,950 2018-05-29
Smart Protection Server HIGH 7.5
CVE-2018-6237EPSS 6%

A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to s…

No fix yet
Fix from $1,950 2018-05-25
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2016-8627

admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via …

Mitigation only
Fix from $1,600 2018-05-11
Litecart HIGH 7.5
CVE-2018-10827

LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/…

Fix: 2.1.2+
Fix from $1,950 2018-05-09
Prime Service Catalog MEDIUM 6.5
CVE-2018-0285

A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the user interfac…

Mitigation only
Fix from $1,600 2018-05-02
Garden Runc MEDIUM 6.5
CVE-2018-1277

Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may …

Fix: 1.13.0 / 1.28.0+
Fix from $1,600 2018-04-30
Debian Linux HIGH 7.5
CVE-2017-7651EPSS 5%

In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. …

Fix: after 1.4.14
Fix from $1,950 2018-04-24
Secure Firewall Threat Defense HIGH 8.6
CVE-2018-0230

A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Secu…

Mitigation only
Fix from $1,950 2018-04-19
Secure Firewall Management Center HIGH 8.6
CVE-2018-0233

A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could al…

Mitigation only
Fix from $1,950 2018-04-19
Ar1200 Firmware HIGH 7.5
CVE-2018-7920

Huawei AR1200 V200R006C10SPC300, AR160 V200R006C10SPC300, AR200 V200R006C10SPC300, AR2200 V200R006C10SPC300, AR3200 V200R006C10SPC300 devices have an…

Mitigation only
Fix from $1,950 2018-04-19