CVEs (176)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Nodejs2Fedora Node.jsMay 6, 2026 Apr 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header. |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreMay 6, 2026 Mar 3, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified othe...Show more |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreMay 6, 2026 Mar 3, 2016 N/A· v4 5.1 MEDIUM· v3 1.9 LOW· v2 The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it ea...Show more |
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and se...Show more |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreMay 6, 2026 Dec 6, 2015 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lack...Show more |
3Canonical NodejsOpenssl3Node.js OpensslUbuntu LinuxMay 6, 2026 Dec 6, 2015 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect outpu...Show more |
3Debian GoogleNodejs3Chrome Debian LinuxNode.jsMay 6, 2026 Dec 6, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers...Show more |
The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory availab...Show more |
3Fedoraproject Libuv ProjectNodejs3Fedora LibuvNode.jsMay 6, 2026 May 18, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors. |
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse arr...Show more |
Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage collection in conjunction with a V8 interrupt, which allows remote attackers to cause a...Show more |
9Fedoraproject Filezilla ProjectMariadb+6 more16Application Processing Engine Firmware Cp1543 1 FirmwareEnterprise Linux+13 moreMay 6, 2026 Jun 5, 2014 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more |
3Debian GoogleNodejs4Chrome Debian LinuxNode.js+1 moreApr 29, 2026 Mar 5, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading t...Show more |
4Debian GoogleNodejs+1 more4Chrome Debian LinuxNode.js+1 moreApr 29, 2026 Jul 31, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion." |
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header con...Show more |