Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-200
Total 6955 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14820 1 Foxitsoftware 1 Foxit Reader 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the tile index of the SOT marker in JPEG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5012.
CVE-2017-16049 1 Nodesqlite Project 1 Nodesqlite 2019-10-09 5.0 MEDIUM 7.5 HIGH
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16051 1 Sqliter Project 1 Sqliter 2019-10-09 5.0 MEDIUM 7.5 HIGH
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16205 1 Coffescript Project 1 Coffescript 2019-10-09 5.0 MEDIUM 7.5 HIGH
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16048 1 Node-sqlite Project 1 Node-sqlite 2019-10-09 5.0 MEDIUM 7.5 HIGH
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16080 1 Nodesass Project 1 Nodesass 2019-10-09 5.0 MEDIUM 7.5 HIGH
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16058 1 Gruntcli Project 1 Gruntcli 2019-10-09 5.0 MEDIUM 7.5 HIGH
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16074 1 Crossenv Project 1 Crossenv 2019-10-09 5.0 MEDIUM 7.5 HIGH
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16068 1 Ffmepg Project 1 Ffmepg 2019-10-09 5.0 MEDIUM 7.5 HIGH
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16052 1 Node-fabric Project 1 Node-fabric 2019-10-09 5.0 MEDIUM 7.5 HIGH
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16075 1 Http-proxy.js Project 1 Http-proxy.js 2019-10-09 5.0 MEDIUM 7.5 HIGH
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16054 1 Nodefabric Project 1 Nodefabric 2019-10-09 5.0 MEDIUM 7.5 HIGH
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16056 1 Mssql.js Project 1 Mssql.js 2019-10-09 5.0 MEDIUM 7.5 HIGH
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16062 1 Node-tkinter Project 1 Node-tkinter 2019-10-09 5.0 MEDIUM 7.5 HIGH
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16057 1 Nodemssql Project 1 Nodemssql 2019-10-09 5.0 MEDIUM 7.5 HIGH
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16069 1 Nodeffmpeg Project 1 Nodeffmpeg 2019-10-09 5.0 MEDIUM 7.5 HIGH
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-15138 1 Redhat 1 Openshift Container Platform 2019-10-09 4.0 MEDIUM 5.0 MEDIUM
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
CVE-2017-16059 1 Mssql-node Project 1 Mssql-node 2019-10-09 5.0 MEDIUM 7.5 HIGH
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16053 1 Fabric-js Project 1 Fabric-js 2019-10-09 5.0 MEDIUM 7.5 HIGH
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16024 2 Nodejs, Sync-exec Project 2 Node.js, Sync-exec 2019-10-09 4.0 MEDIUM 6.5 MEDIUM
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists.