Loading HuntDB...

Vulnerabilities

CVE-2017-0938

UNKNOWN

Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.

Published Feb 12, 2019

CVE-2018-16486

UNKNOWN

A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.

Published Feb 01, 2019

CVE-2018-16489

UNKNOWN

A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.

Published Feb 01, 2019

CVE-2018-16492

UNKNOWN

A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.

Published Feb 01, 2019

CVE-2018-16482

UNKNOWN

A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path.

Published Feb 01, 2019

CVE-2018-16484

UNKNOWN

A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.

Published Feb 01, 2019

CVE-2018-16479

UNKNOWN

Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appending extra slashes after the URL.

Published Feb 01, 2019

CVE-2018-16491

UNKNOWN

A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

Published Feb 01, 2019

CVE-2018-16490

UNKNOWN

A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

Published Feb 01, 2019

CVE-2018-16493

UNKNOWN

A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL.

Published Feb 01, 2019

CVE-2018-16481

UNKNOWN

A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.

Published Feb 01, 2019

CVE-2018-16483

UNKNOWN

A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.

Published Feb 01, 2019

CVE-2018-16480

UNKNOWN

A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanitization of the file/folder names before rendering.

Published Feb 01, 2019

CVE-2018-16485

UNKNOWN

Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory tree e.g. /etc/passwd by appending slashes to the URL request.

Published Feb 01, 2019

CVE-2018-16487

UNKNOWN

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

Published Feb 01, 2019

CVE-2018-16469

UNKNOWN

The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a denial of service attack.

Published Oct 30, 2018

CVE-2018-3787

UNKNOWN

Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.

Published Aug 31, 2018

CVE-2018-3774

UNKNOWN

Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.

Published Aug 12, 2018

CVE-2018-3776

UNKNOWN

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

Published Aug 12, 2018

CVE-2018-3775

UNKNOWN

Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.

Published Aug 12, 2018

CVE-2018-3779

UNKNOWN

active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system.

Published Aug 10, 2018

CVE-2018-3778

UNKNOWN

Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.

Published Aug 08, 2018

CVE-2018-3771

UNKNOWN

An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.

Published Jul 20, 2018

CVE-2018-3770

UNKNOWN

A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.

Published Jul 20, 2018

CVE-2018-3760

UNKNOWN

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

Published Jun 26, 2018

CVE-2018-3759

UNKNOWN

private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.

Published Jun 13, 2018

CVE-2018-3758

UNKNOWN

Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.

Published Jun 07, 2018

CVE-2018-3716

UNKNOWN

simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.

Published Jun 07, 2018

CVE-2017-16105

UNKNOWN

serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16081

UNKNOWN

cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16084

UNKNOWN

list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16154

UNKNOWN

earlybird is a web server module for early development. earlybird is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16104

UNKNOWN

citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16058

UNKNOWN

gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16219

UNKNOWN

yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16186

UNKNOWN

360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16118

UNKNOWN

The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression denial of service when it's passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.

Published Jun 07, 2018

CVE-2017-16057

UNKNOWN

nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2018-3731

UNKNOWN

public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2018-3737

UNKNOWN

sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.

Published Jun 07, 2018

CVE-2017-16096

UNKNOWN

serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16066

UNKNOWN

opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16189

UNKNOWN

sly07 is an API for censoring text. sly07 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16159

UNKNOWN

caolilinode is a simple file server. caolilinode is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16174

UNKNOWN

whispercast is a file server. whispercast is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16119

UNKNOWN

Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.

Published Jun 07, 2018

CVE-2017-16158

UNKNOWN

dcserver is a static file server. dcserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16176

UNKNOWN

jansenstuffpleasework is a file server. jansenstuffpleasework is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16214

UNKNOWN

peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16224

UNKNOWN

st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. ("%2e%2e", "%2e.", ".%2e").

Published Jun 07, 2018