|
265991
|
6.1 |
MEDIUM
Network
|
mozilla
|
nunjucks
|
Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape mode. In autoescape mode, all template vars should…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10547
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265992
|
9.8 |
CRITICAL
Network
|
pouchdb
|
pouchdb
|
An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch i…
|
CWE-94
Code Injection
|
CVE-2016-10546
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265993
|
5.9 |
MEDIUM
Network
|
uws_project
|
uws
|
uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibility used compression will shrink said 256mb down t…
|
CWE-20
Improper Input Validation
|
CVE-2016-10544
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265994
|
5.3 |
MEDIUM
Network
|
call_project
|
call
|
call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty parameters, which could result in invalid input bypas…
|
CWE-20
Improper Input Validation
|
CVE-2016-10543
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265995
|
7.5 |
HIGH
Network
|
ws_project
|
ws
|
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server…
|
CWE-20
Improper Input Validation
|
CVE-2016-10542
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265996
|
9.8 |
CRITICAL
Network
|
shell-quote_project
|
shell-quote
|
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious …
|
CWE-94
Code Injection
|
CVE-2016-10541
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265997
|
7.5 |
HIGH
Network
|
minimatch_project
|
minimatch
|
Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(path, pattern)` in Minimatch 3.0.1 and earlier is …
|
CWE-20
Improper Input Validation
|
CVE-2016-10540
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265998
|
7.5 |
HIGH
Network
|
negotiator_project
|
negotiator
|
negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlie…
|
CWE-20
Improper Input Validation
|
CVE-2016-10539
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265999
|
3.5 |
LOW
Network
|
cli_project debian
|
cli debian_linux
|
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
|
CWE-362
Race Condition
|
CVE-2016-10538
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266000
|
5.4 |
MEDIUM
Network
|
backbone_project
|
backbone
|
backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your RESTful API through JSON There exists a potential Cross Site…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10537
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|