|
258101
|
7.5 |
HIGH
Network
|
sqliter_project
|
sqliter
|
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16051
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258102
|
7.5 |
HIGH
Network
|
sqlite.js_project
|
sqlite.js
|
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16050
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258103
|
7.5 |
HIGH
Network
|
nodesqlite_project
|
nodesqlite
|
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16049
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258104
|
7.5 |
HIGH
Network
|
node-sqlite_project
|
node-sqlite
|
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16048
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258105
|
7.5 |
HIGH
Network
|
mariadb
|
mariadb
|
`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
NVD-CWE-noinfo
|
CVE-2017-16046
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258106
|
7.5 |
HIGH
Network
|
jquery.js_project
|
jquery.js
|
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16045
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258107
|
7.5 |
HIGH
Network
|
d3.js_project
|
d3.js
|
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
|
CWE-200
Information Exposure
|
CVE-2017-16044
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258108
|
6.1 |
MEDIUM
Network
|
shout_project
|
shout
|
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.
|
CWE-74
Injection
|
CVE-2017-16043
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258109
|
9.8 |
CRITICAL
Network
|
growl_project
|
growl
|
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
|
CWE-78
OS Command
|
CVE-2017-16042
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258110
|
5.9 |
MEDIUM
Network
|
ikst_project
|
ikst
|
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-16041
|
2024-11-21 12:15 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|