|
269191
|
9.8 |
CRITICAL
Network
|
mysqljs
|
mysql
|
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2015-9244
|
2024-11-21 11:40 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269192
|
5.9 |
MEDIUM
Network
|
hapijs
|
hapi
|
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a hi…
|
CWE-254
7PK - Security Features
|
CVE-2015-9243
|
2024-11-21 11:40 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269193
|
7.5 |
HIGH
Network
|
ecstatic_project
|
ecstatic
|
Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when …
|
CWE-20
Improper Input Validation
|
CVE-2015-9242
|
2024-11-21 11:40 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269194
|
7.5 |
HIGH
Network
|
hapijs
|
hapi
|
Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a HTTP 500 error back to the sender, hapi node modul…
|
CWE-20
Improper Input Validation
|
CVE-2015-9241
|
2024-11-21 11:40 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269195
|
7.5 |
HIGH
Network
|
keystonejs
|
keystone
|
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.
|
CWE-255
Credentials Management
|
CVE-2015-9240
|
2024-11-21 11:40 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269196
|
9.8 |
CRITICAL
Network
|
auth0
|
jsonwebtoken
|
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attack…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2015-9235
|
2024-11-21 11:40 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269197
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9615_firmware mdm9625_firmware mdm9635m_firmware sd_400_firmware sd_600_firmware sd_800_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, SD 400, SD 600, and SD 800, a buffer overflow can occur when processing an audio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-9223
|
2024-11-21 11:40 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269198
|
9.8 |
CRITICAL
Network
|
qualcomm
|
sd_400_firmware sd_800_firmware sd_810_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, SD 800, and SD 810, lack of validation of pointers passed by secure apps could lead to an untrusted …
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-9221
|
2024-11-21 11:40 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269199
|
9.8 |
CRITICAL
Network
|
qualcomm
|
sd_400_firmware sd_800_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, an integer overflow to buffer overflow can occur in a DRM API.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2015-9219
|
2024-11-21 11:40 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269200
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9615_firmware mdm9625_firmware mdm9635m_firmware sd_810_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, and SD 810, improper input validation can cause a null pointer dereference in US…
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-9215
|
2024-11-21 11:40 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|