|
266041
|
8.1 |
HIGH
Network
|
pngcrush-installer_project
|
pngcrush-installer
|
pngcrush-installer is an installer for Pngcrush. pngcrush-installer versions below 1.8.10 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause …
|
CWE-310
Cryptographic Issues
|
CVE-2016-10570
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266042
|
8.1 |
HIGH
Network
|
geoip-lite-country_project
|
geoip-lite-country
|
geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data resources over HTTP, which leaves it vulnerable to MITM att…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10568
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266043
|
8.1 |
HIGH
Network
|
install-nw_project
|
install-nw
|
install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10566
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266044
|
8.1 |
HIGH
Network
|
product-monitor_project
|
product-monitor
|
product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all the information about the status of a product, including live monitoring, statis…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10567
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266045
|
8.1 |
HIGH
Network
|
groupon
|
selenium-download
|
selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10559
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266046
|
8.1 |
HIGH
Network
|
aerospike
|
aerospike
|
aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may be possible to caus…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10558
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266047
|
7.5 |
HIGH
Network
|
sequelizejs
|
sequelize
|
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS In Postgres, SQLite, and Microso…
|
CWE-89
SQL Injection
|
CVE-2016-10556
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266048
|
9.8 |
CRITICAL
Network
|
balderdash
|
waterline-sequel
|
waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-s…
|
CWE-89
SQL Injection
|
CVE-2016-10551
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266049
|
9.8 |
CRITICAL
Network
|
dwyl
|
hapi-auth-jwt2
|
When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2016-10525
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266050
|
9.8 |
CRITICAL
Network
|
partclone_project
|
partclone
|
partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the FAT superblock, related to the mark_reserved_sectors function. An…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10722
|
2024-11-21 11:44 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|