CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian NetappNodejs+1 more4Debian Linux Nextgen ApiNode.js+1 moreNov 21, 2024 Oct 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior. |
5Debian NetappNodejs+2 more7Debian Linux GraalvmJd Edwards Enterpriseone Tools+4 moreNov 21, 2024 Aug 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior. |
5Debian NetappNodejs+2 more8Debian Linux GraalvmJd Edwards Enterpriseone Tools+5 moreNov 21, 2024 Aug 16, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted. |
4Netapp NodejsOracle+1 more10Active Iq Unified Manager GraalvmMysql Cluster+7 moreNov 21, 2024 Aug 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can...Show more |