|
266001
|
5.9 |
MEDIUM
Network
|
socket
|
engine.io-client
|
engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. The vulnerability is related to the …
|
CWE-295
Improper Certificate Validation
|
CVE-2016-10536
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266002
|
5.9 |
MEDIUM
Network
|
csrf-lite_project
|
csrf-lite
|
csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail first string comparison, instead of a time constant string comparison This ena…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10535
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266003
|
5.9 |
MEDIUM
Network
|
electron-packager_project
|
electron-packager
|
electron-packager is a command line tool that packages Electron source code into `.app` and `.exe` packages. along with Electron. The `--strict-ssl` command line option in electron-packager >= 5.2.1 …
|
CWE-295
Improper Certificate Validation
|
CVE-2016-10534
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266004
|
6.1 |
MEDIUM
Network
|
marked_project
|
marked
|
marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it's possible to bypass marked's content i…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10531
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266005
|
5.9 |
MEDIUM
Network
|
airbrake
|
airbrake
|
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A malicious user could…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2016-10530
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266006
|
8.8 |
HIGH
Network
|
droppy_project
|
droppy
|
Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the current…
|
CWE-352
Origin Validation Error
|
CVE-2016-10529
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266007
|
4.9 |
MEDIUM
Network
|
restafary_project
|
restafary
|
restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it …
|
CWE-22
Path Traversal
|
CVE-2016-10528
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266008
|
8.8 |
HIGH
Network
|
express-restify-mongoose_project
|
express-restify-mongoose
|
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send…
|
CWE-200
Information Exposure
|
CVE-2016-10533
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266009
|
9.8 |
CRITICAL
Network
|
console-io_project
|
console-io
|
console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the con…
|
CWE-287
Improper Authentication
|
CVE-2016-10532
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266010
|
7.5 |
HIGH
Network
|
riot.js
|
riot-compiler
|
The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions.
|
CWE-399
Resource Management Errors
|
CVE-2016-10527
|
2024-11-21 11:44 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|