Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-14820 | 1 Foxitsoftware | 1 Foxit Reader | 2019-10-09 | 4.3 MEDIUM | 6.5 MEDIUM |
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the tile index of the SOT marker in JPEG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5012. | |||||
CVE-2017-16049 | 1 Nodesqlite Project | 1 Nodesqlite | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16051 | 1 Sqliter Project | 1 Sqliter | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16205 | 1 Coffescript Project | 1 Coffescript | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. | |||||
CVE-2017-16048 | 1 Node-sqlite Project | 1 Node-sqlite | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16080 | 1 Nodesass Project | 1 Nodesass | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16058 | 1 Gruntcli Project | 1 Gruntcli | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16074 | 1 Crossenv Project | 1 Crossenv | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16068 | 1 Ffmepg Project | 1 Ffmepg | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16052 | 1 Node-fabric Project | 1 Node-fabric | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16075 | 1 Http-proxy.js Project | 1 Http-proxy.js | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16054 | 1 Nodefabric Project | 1 Nodefabric | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16056 | 1 Mssql.js Project | 1 Mssql.js | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16062 | 1 Node-tkinter Project | 1 Node-tkinter | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16057 | 1 Nodemssql Project | 1 Nodemssql | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16069 | 1 Nodeffmpeg Project | 1 Nodeffmpeg | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-15138 | 1 Redhat | 1 Openshift Container Platform | 2019-10-09 | 4.0 MEDIUM | 5.0 MEDIUM |
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens. | |||||
CVE-2017-16059 | 1 Mssql-node Project | 1 Mssql-node | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16053 | 1 Fabric-js Project | 1 Fabric-js | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16024 | 2 Nodejs, Sync-exec Project | 2 Node.js, Sync-exec | 2019-10-09 | 4.0 MEDIUM | 6.5 MEDIUM |
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists. |