|
251231
|
7.5 |
HIGH
Network
|
jquery.js_project
|
jquery.js
|
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16045
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251232
|
7.5 |
HIGH
Network
|
d3.js_project
|
d3.js
|
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16044
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251233
|
6.1 |
MEDIUM
Network
|
shout_project
|
shout
|
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.
|
CWE-74
Injection
|
CVE-2017-16043
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251234
|
9.8 |
CRITICAL
Network
|
growl_project
|
growl
|
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
|
CWE-78
OS Command
|
CVE-2017-16042
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251235
|
5.9 |
MEDIUM
Network
|
ikst_project
|
ikst
|
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-16041
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251236
|
8.1 |
HIGH
Network
|
gfe-sass_project
|
gfe-sass
|
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-16040
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251237
|
7.5 |
HIGH
Network
|
hftp_project
|
hftp
|
`hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
|
CWE-22
Path Traversal
|
CVE-2017-16039
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251238
|
7.5 |
HIGH
Network
|
f2e-server_project
|
f2e-server
|
`f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. This is compounded by `f2e-server` requiring el…
|
CWE-22
Path Traversal
|
CVE-2017-16038
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251239
|
7.5 |
HIGH
Network
|
gomeplus-h5-proxy_project
|
gomeplus-h5-proxy
|
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.
|
CWE-22
Path Traversal
|
CVE-2017-16037
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251240
|
7.5 |
HIGH
Network
|
badjs-sourcemap-server_project
|
badjs-sourcemap-server
|
`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" …
|
CWE-22
Path Traversal
|
CVE-2017-16036
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|