Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hoek HIGH 8.1
CVE-2020-36604

hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.

Fix: 8.5.1 / 9.0.3+
Fix from $1,950 2022-09-23
Nes MEDIUM 5.9
CVE-2017-16025

Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerabili…

Fix: after 6.4.0
Fix from $1,600 2018-06-04
Hapi HIGH 7.5
CVE-2017-16013

hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception…

Fix: after 16.1.0
Fix from $1,950 2018-06-04
Hapi MEDIUM 5.3
CVE-2015-9236

Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allo…

Fix: 11.0.0+
Fix from $1,600 2018-05-31
Hapi HIGH 7.5
CVE-2015-9241

Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a …

Fix: 11.1.3+
Fix from $1,950 2018-05-29
Hapi MEDIUM 5.9
CVE-2015-9243

When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config …

Fix: 11.1.4+
Fix from $1,600 2018-05-29
Hoek HIGH 8.8
CVE-2018-3728

hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'appl…

Fix: 4.2.0 / 5.0.3+
Fix from $1,950 2018-03-30