Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-200
Total 6955 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16574 1 Foxitsoftware 1 Foxit Reader 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of Image filters. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5079.
CVE-2017-14822 1 Foxitsoftware 1 Foxit Reader 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the xOsiz member of SIZ markers. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5014.
CVE-2017-16203 1 Coffescript Project 1 Coffescript 2019-10-09 5.0 MEDIUM 7.5 HIGH
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16044 1 D3.js Project 1 D3.js 2019-10-09 5.0 MEDIUM 7.5 HIGH
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16067 1 Node-opencv Project 1 Node-opencv 2019-10-09 5.0 MEDIUM 7.5 HIGH
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16204 1 Jquey Project 1 Jquey 2019-10-09 5.0 MEDIUM 7.5 HIGH
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16047 1 Mysqljs Project 1 Mysqljs 2019-10-09 5.0 MEDIUM 7.5 HIGH
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-14818 1 Foxitsoftware 1 Foxit Reader 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
This vulnerability allows remote attackers to disclose sensitive on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4982.
CVE-2017-16077 1 Mongose Project 1 Mongose 2019-10-09 5.0 MEDIUM 7.5 HIGH
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16073 1 Noderequest Project 1 Noderequest 2019-10-09 5.0 MEDIUM 7.5 HIGH
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16202 1 Cofeescript Project 1 Cofeescript 2019-10-09 5.0 MEDIUM 7.5 HIGH
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16081 1 Cross-env.js Project 1 Cross-env.js 2019-10-09 5.0 MEDIUM 7.5 HIGH
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16072 1 Nodemailer.js Project 1 Nodemailer.js 2019-10-09 5.0 MEDIUM 7.5 HIGH
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16065 1 Openssl.js Project 1 Openssl.js 2019-10-09 5.0 MEDIUM 7.5 HIGH
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-14819 1 Foxitsoftware 1 Foxit Reader 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the channel number member of the cdef box. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5011.
CVE-2017-16064 1 Node-openssl Project 1 Node-openssl 2019-10-09 5.0 MEDIUM 7.5 HIGH
node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16225 1 Aegir Project 1 Aegir 2019-10-09 5.0 MEDIUM 7.5 HIGH
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (that performed a aegir-release) GitHub token.
CVE-2017-16070 1 Nodecaffe Project 1 Nodecaffe 2019-10-09 5.0 MEDIUM 7.5 HIGH
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16066 1 Opencv.js Project 1 Opencv.js 2019-10-09 5.0 MEDIUM 7.5 HIGH
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16078 1 Shadowsock Project 1 Shadowsock 2019-10-09 5.0 MEDIUM 7.5 HIGH
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.