CVEs (176)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters. |
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings. |
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing. |
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI. |
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag. |
2Nodejs Suse2Linux Enterprise Node.jsMay 6, 2026 Oct 10, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows m...Show more |
2Nodejs Suse2Linux Enterprise Node.jsMay 6, 2026 Oct 10, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP heade...Show more |
5C Ares C Ares ProjectCanonical+2 more5C Ares C AresDebian Linux+2 moreMay 6, 2026 Oct 3, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with a...Show more |
3Nodejs NovellOpenssl3Node.js OpensslSuse Linux Enterprise Module For Web ScriptingMay 6, 2026 Sep 26, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation. |
6Canonical DebianHp+3 more9Debian Linux Icewall Federation AgentIcewall Mcrp+6 moreMay 6, 2026 Sep 26, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr....Show more |
3Nodejs NovellOpenssl3Node.js OpensslSuse Linux Enterprise Module For Web ScriptingMay 6, 2026 Sep 26, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions. |
3Debian GoogleNodejs3Chrome Debian LinuxNode.jsMay 6, 2026 Sep 25, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code. |
2Nodejs Openssl2Node.js OpensslMay 6, 2026 Sep 16, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified...Show more |
6Cisco NodejsOpenssl+3 more9Content Security Management Appliance DatabaseEnterprise Linux+6 moreMay 29, 2026 Sep 1, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obt...Show more |
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTT...Show more |
6Canonical DebianNodejs+3 more7Debian Linux LinuxLinux Enterprise+4 moreMay 6, 2026 Jun 20, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timin...Show more |
5Canonical DebianGoogle+2 more6Chrome Debian LinuxNode.js+3 moreMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to caus...Show more |
8Canonical DebianGoogle+5 more15Android Debian LinuxEnterprise Linux Desktop+12 moreMay 6, 2026 May 5, 2016 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a...Show more |
8Apple CanonicalDebian+5 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+12 moreMay 6, 2026 May 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount o...Show more |
2Fedoraproject Nodejs2Fedora Node.jsMay 6, 2026 Apr 7, 2016 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection...Show more |