|
254761
|
7.5 |
HIGH
Network
|
node-fabric_project
|
node-fabric
|
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16052
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254762
|
7.5 |
HIGH
Network
|
sqliter_project
|
sqliter
|
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16051
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254763
|
7.5 |
HIGH
Network
|
sqlite.js_project
|
sqlite.js
|
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16050
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254764
|
7.5 |
HIGH
Network
|
nodesqlite_project
|
nodesqlite
|
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16049
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254765
|
7.5 |
HIGH
Network
|
node-sqlite_project
|
node-sqlite
|
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16048
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254766
|
7.5 |
HIGH
Network
|
mariadb
|
mariadb
|
`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
NVD-CWE-noinfo
|
CVE-2017-16046
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254767
|
7.5 |
HIGH
Network
|
jquery.js_project
|
jquery.js
|
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16045
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254768
|
7.5 |
HIGH
Network
|
d3.js_project
|
d3.js
|
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16044
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254769
|
6.1 |
MEDIUM
Network
|
shout_project
|
shout
|
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.
|
CWE-74
Injection
|
CVE-2017-16043
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254770
|
9.8 |
CRITICAL
Network
|
growl_project
|
growl
|
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
|
CWE-78
OS Command
|
CVE-2017-16042
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|