|
255971
|
9.8 |
CRITICAL
Network
|
growl_project
|
growl
|
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
|
CWE-78
OS Command
|
CVE-2017-16042
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255972
|
5.9 |
MEDIUM
Network
|
ikst_project
|
ikst
|
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-16041
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255973
|
8.1 |
HIGH
Network
|
gfe-sass_project
|
gfe-sass
|
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-16040
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255974
|
7.5 |
HIGH
Network
|
hftp_project
|
hftp
|
`hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
|
CWE-22
Path Traversal
|
CVE-2017-16039
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255975
|
7.5 |
HIGH
Network
|
f2e-server_project
|
f2e-server
|
`f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. This is compounded by `f2e-server` requiring el…
|
CWE-22
Path Traversal
|
CVE-2017-16038
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255976
|
7.5 |
HIGH
Network
|
gomeplus-h5-proxy_project
|
gomeplus-h5-proxy
|
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.
|
CWE-22
Path Traversal
|
CVE-2017-16037
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255977
|
7.5 |
HIGH
Network
|
badjs-sourcemap-server_project
|
badjs-sourcemap-server
|
`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" …
|
CWE-22
Path Traversal
|
CVE-2017-16036
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255978
|
8.1 |
HIGH
Network
|
hubspot
|
hubl-server
|
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are d…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-16035
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255979
|
7.5 |
HIGH
Network
|
socket
|
socket.io
|
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable.…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2017-16031
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255980
|
7.5 |
HIGH
Network
|
useragent_project
|
useragent
|
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing …
|
NVD-CWE-noinfo
|
CVE-2017-16030
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|