Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2017-16119 Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service wh… Fresh 0.5.2+ Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16086EPSS 9% ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given … Ua Parser Mitigation only Fix from $1,9502018-06-07 MEDIUM 6.5 CVE-2017-16021 uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or not. To do t… Uri Js after 2.1.1 Fix from $1,6002018-06-04 HIGH 7.5 CVE-2017-16023 Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to e… Decamelize Mitigation only Fix from $1,9502018-06-04 MEDIUM 5.9 CVE-2017-16025 Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerabili… Nes after 6.4.0 Fix from $1,6002018-06-04 HIGH 7.5 CVE-2017-16030 Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creat… Useragent after 2.1.12 Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16013 hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception… Hapi after 16.1.0 Fix from $1,9502018-06-04 MEDIUM 5.3 CVE-2017-6153 Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly… Big Ip Application Acceleration Manager after 12.1.3 Fix from $1,6002018-06-01 HIGH 7.5 CVE-2016-10539 negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Lan… Negotiator after 0.6.0 Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10540 Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(… Minimatch after 3.0.1 Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10542EPSS 8% ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending… Ws after 1.1.0 Fix from $1,9502018-05-31 MEDIUM 5.9 CVE-2016-10544 uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibil… Uws after 0.10.8 Fix from $1,6002018-05-31 HIGH 7.5 CVE-2014-10064 The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested obje… Qs 1.0.0+ Fix from $1,9502018-05-31 HIGH 7.5 CVE-2015-9239 ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in. Ansi2html No fix yet Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10520 jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in. Jadedown after 0.0.3 Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10521 jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator. Jshamcrest after 0.7.1 Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10523 MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible with very li… Mqtt Packet 3.4.6 / 4.0.5+ Fix from $1,9502018-05-31 HIGH 8.2 CVE-2016-10524 i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is used for deve… I18n Node Angular 1.4.0+ Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10527 The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions. Riot Compiler Mitigation only Fix from $1,9502018-05-31 HIGH 7.5 CVE-2015-9241 Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a … Hapi 11.1.3+ Fix from $1,9502018-05-29 HIGH 7.5 CVE-2015-9242 Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads … Ecstatic 1.4.0+ Fix from $1,9502018-05-29 HIGH 7.5 CVE-2018-6237EPSS 6% A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to s… Smart Protection Server No fix yet Fix from $1,9502018-05-25 MEDIUM 6.5 CVE-2016-8627 admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via … Jboss Enterprise Application Platform Mitigation only Fix from $1,6002018-05-11 HIGH 7.5 CVE-2018-10827 LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/… Litecart 2.1.2+ Fix from $1,9502018-05-09 MEDIUM 6.5 CVE-2018-0285 A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the user interfac… Prime Service Catalog Mitigation only Fix from $1,6002018-05-02 MEDIUM 6.5 CVE-2018-1277 Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may … Garden Runc 1.13.0 / 1.28.0+ Fix from $1,6002018-04-30 HIGH 7.5 CVE-2017-7651EPSS 5% In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. … Debian Linux after 1.4.14 Fix from $1,9502018-04-24 HIGH 8.6 CVE-2018-0230 A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Secu… Secure Firewall Threat Defense Mitigation only Fix from $1,9502018-04-19 HIGH 8.6 CVE-2018-0233 A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could al… Secure Firewall Management Center Mitigation only Fix from $1,9502018-04-19 HIGH 7.5 CVE-2018-7920 Huawei AR1200 V200R006C10SPC300, AR160 V200R006C10SPC300, AR200 V200R006C10SPC300, AR2200 V200R006C10SPC300, AR3200 V200R006C10SPC300 devices have an… Ar1200 Firmware Mitigation only Fix from $1,9502018-04-19