|
267461
|
8.1 |
HIGH
Network
|
baryton-saxophone_project
|
baryton-saxophone
|
baryton-saxophone is a module to install and launch Selenium Server for Mac, Linux and Windows. baryton-saxophone versions below 3.0.1 download binary resources over HTTP, which leaves it vulnerable …
|
CWE-310
Cryptographic Issues
|
CVE-2016-10573
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267462
|
8.1 |
HIGH
Network
|
pngcrush-installer_project
|
pngcrush-installer
|
pngcrush-installer is an installer for Pngcrush. pngcrush-installer versions below 1.8.10 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause …
|
CWE-310
Cryptographic Issues
|
CVE-2016-10570
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267463
|
8.1 |
HIGH
Network
|
geoip-lite-country_project
|
geoip-lite-country
|
geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data resources over HTTP, which leaves it vulnerable to MITM att…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10568
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267464
|
8.1 |
HIGH
Network
|
install-nw_project
|
install-nw
|
install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10566
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267465
|
8.1 |
HIGH
Network
|
product-monitor_project
|
product-monitor
|
product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all the information about the status of a product, including live monitoring, statis…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10567
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267466
|
8.1 |
HIGH
Network
|
groupon
|
selenium-download
|
selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10559
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267467
|
8.1 |
HIGH
Network
|
aerospike
|
aerospike
|
aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may be possible to caus…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10558
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267468
|
7.5 |
HIGH
Network
|
sequelizejs
|
sequelize
|
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS In Postgres, SQLite, and Microso…
|
CWE-89
SQL Injection
|
CVE-2016-10556
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267469
|
9.8 |
CRITICAL
Network
|
balderdash
|
waterline-sequel
|
waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-s…
|
CWE-89
SQL Injection
|
CVE-2016-10551
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267470
|
9.8 |
CRITICAL
Network
|
dwyl
|
hapi-auth-jwt2
|
When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2016-10525
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|