Nodejs
nodejs
202 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (202)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by...Show more |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreNov 21, 2024 Jun 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generati...Show more |
2Nodejs Sync Exec Project2Node.js Sync ExecNov 21, 2024 Jun 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp director...Show more |
The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same c...Show more |
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not...Show more |
The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector. The code in question was replaced in Node.js 6.x and later so this vulnerability only impacts...Show more |
3Debian Nghttp2Nodejs3Debian Linux Nghttp2Node.jsJun 9, 2025 May 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears...Show more |
Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly enc...Show more |
Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using th...Show more |
3Debian NodejsOpenssl3Debian Linux Node.jsOpensslMay 13, 2026 Dec 7, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this...Show more |
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value...Show more |
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path. |
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service. |
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules. |
3Debian NodejsUronode3Debian Linux Node.jsUro NodeMay 13, 2026 Sep 20, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption). |
Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given...Show more |
3C Ares C Ares ProjectNodejs3C Ares C AresNode.jsMay 13, 2026 Jul 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particu...Show more |
10Apple CanonicalDebian+7 more24Active Iq Unified Manager Database ServerDebian Linux+21 moreMay 13, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation. |
8Apple CanonicalDebian+5 more19Database Server Debian LinuxEnterprise Linux Desktop+16 moreJul 14, 2026 May 23, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers. |
9Apple CanonicalDebian+6 more39Active Iq Unified Manager Cloud BackupDatabase Server+36 moreJul 14, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |