← Back

Node.js

node.js

Vendor: Nodejs • 176 CVEs

CVEs (176)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nodejs
1Node.js
May 13, 2026
Jan 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters.
1Nodejs
1Node.js
May 13, 2026
Jan 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.
1Nodejs
1Node.js
May 13, 2026
Jan 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing.
1Nodejs
1Node.js
May 13, 2026
Jan 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI.
1Nodejs
1Node.js
May 13, 2026
Jan 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.
2Nodejs
Suse
2Linux Enterprise
Node.js
May 6, 2026
Oct 10, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows m...Show more
The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.Show less
2Nodejs
Suse
2Linux Enterprise
Node.js
May 6, 2026
Oct 10, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP heade...Show more
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.Show less
5C Ares
C Ares ProjectCanonical+2 more
5C Ares
C AresDebian Linux+2 more
May 6, 2026
Oct 3, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with a...Show more
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.Show less
3Nodejs
NovellOpenssl
3Node.js
OpensslSuse Linux Enterprise Module For Web Scripting
May 6, 2026
Sep 26, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.
6Canonical
DebianHp+3 more
9Debian Linux
Icewall Federation AgentIcewall Mcrp+6 more
May 6, 2026
Sep 26, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr....Show more
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.Show less
3Nodejs
NovellOpenssl
3Node.js
OpensslSuse Linux Enterprise Module For Web Scripting
May 6, 2026
Sep 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
3Debian
GoogleNodejs
3Chrome
Debian LinuxNode.js
May 6, 2026
Sep 25, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
2Nodejs
Openssl
2Node.js
Openssl
May 6, 2026
Sep 16, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified...Show more
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.Show less
6Cisco
NodejsOpenssl+3 more
9Content Security Management Appliance
DatabaseEnterprise Linux+6 more
May 29, 2026
Sep 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obt...Show more
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.Show less
3Ibm
NodejsNpmjs
3Node.js
NpmSdk
May 6, 2026
Jul 2, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTT...Show more
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.Show less
6Canonical
DebianNodejs+3 more
7Debian Linux
LinuxLinux Enterprise+4 more
May 6, 2026
Jun 20, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timin...Show more
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.Show less
5Canonical
DebianGoogle+2 more
6Chrome
Debian LinuxNode.js+3 more
May 6, 2026
May 14, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to caus...Show more
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.Show less
8Canonical
DebianGoogle+5 more
15Android
Debian LinuxEnterprise Linux Desktop+12 more
May 6, 2026
May 5, 2016
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a...Show more
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.Show less
8Apple
CanonicalDebian+5 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+12 more
May 6, 2026
May 5, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount o...Show more
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.Show less
2Fedoraproject
Nodejs
2Fedora
Node.js
May 6, 2026
Apr 7, 2016
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection...Show more
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.Show less