Loading HuntDB...

Vulnerabilities

CVE-2017-16115

UNKNOWN

The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop for around 10 seconds.

Published Jun 07, 2018

CVE-2017-16191

UNKNOWN

cypserver is a static file server. cypserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16195

UNKNOWN

pytservce is a static file server. pytservce is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16084

UNKNOWN

list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16076

UNKNOWN

proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2018-3719

UNKNOWN

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Published Jun 07, 2018

CVE-2017-16113

UNKNOWN

The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.

Published Jun 07, 2018

CVE-2017-16089

UNKNOWN

serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16223

UNKNOWN

nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16092

UNKNOWN

Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16065

UNKNOWN

openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16123

UNKNOWN

welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16098

UNKNOWN

charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.

Published Jun 07, 2018

CVE-2017-16072

UNKNOWN

nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2018-3723

UNKNOWN

defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Published Jun 07, 2018

CVE-2017-16136

UNKNOWN

method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.

Published Jun 07, 2018

CVE-2017-16131

UNKNOWN

unicorn-list is a web framework. unicorn-list is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16180

UNKNOWN

serverabc is a static file server. serverabc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16194

UNKNOWN

picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16197

UNKNOWN

qinserve is a static file server. qinserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16199

UNKNOWN

susu-sum is a static file server. susu-sum is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2018-3738

UNKNOWN

protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.

Published Jun 07, 2018

CVE-2017-16184

UNKNOWN

scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16147

UNKNOWN

shit-server is a file server. shit-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16142

UNKNOWN

infraserver is a RESTful server. infraserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16215

UNKNOWN

sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16074

UNKNOWN

crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16083

UNKNOWN

node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16141

UNKNOWN

lab6drewfusbyu is an http server. lab6drewfusbyu is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16128

UNKNOWN

The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.

Published Jun 07, 2018

CVE-2017-16210

UNKNOWN

jn_jj_server is a static file server. jn_jj_server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16119

UNKNOWN

Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.

Published Jun 07, 2018

CVE-2017-16079

UNKNOWN

smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16127

UNKNOWN

The module pandora-doomsday infects other modules. It's since been unpublished from the registry.

Published Jun 07, 2018

CVE-2017-16164

UNKNOWN

desafio is a simple web server. desafio is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url, but is limited to accessing only .html files.

Published Jun 07, 2018

CVE-2017-16146

UNKNOWN

mockserve is a file server. mockserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16217

UNKNOWN

fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16117

UNKNOWN

slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About 50k characters can block the event loop for 2 seconds.

Published Jun 07, 2018

CVE-2017-16095

UNKNOWN

serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16138

UNKNOWN

The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

Published Jun 07, 2018

CVE-2017-16129

UNKNOWN

The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing such responses, it may result in excessive CPU and/or memory consumption. An attacker might exploit such a weakness for a DoS attack. To exploit this the attacker must control the location (URL) that superagent makes a request to.

Published Jun 07, 2018

CVE-2017-16069

UNKNOWN

nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2018-3730

UNKNOWN

mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2017-16143

UNKNOWN

commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16201

UNKNOWN

zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16211

UNKNOWN

lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16177

UNKNOWN

chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16165

UNKNOWN

calmquist.static-server is a static file server. calmquist.static-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16220

UNKNOWN

wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16203

UNKNOWN

The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

Published Jun 07, 2018