Loading HuntDB...

Vulnerabilities

CVE-2017-16069

UNKNOWN

nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16143

UNKNOWN

commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16201

UNKNOWN

zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16211

UNKNOWN

lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16111

UNKNOWN

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.

Published Jun 07, 2018

CVE-2017-16165

UNKNOWN

calmquist.static-server is a static file server. calmquist.static-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16220

UNKNOWN

wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16203

UNKNOWN

The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

Published Jun 07, 2018

CVE-2017-16205

UNKNOWN

The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

Published Jun 07, 2018

CVE-2017-16207

UNKNOWN

discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.

Published Jun 07, 2018

CVE-2017-16175

UNKNOWN

ewgaddis.lab6 is a file server. ewgaddis.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16137

UNKNOWN

The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.

Published Jun 07, 2018

CVE-2017-16130

UNKNOWN

exxxxxxxxxxx is an Http eX Frame Google Style JavaScript Guide. exxxxxxxxxxx is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Accessible files are restricted to those with a file extension. Files with no extension such as /etc/passwd throw an error.

Published Jun 07, 2018

CVE-2017-16135

UNKNOWN

serverzyy is a static file server. serverzyy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16171

UNKNOWN

hcbserver is a static file server. hcbserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16091

UNKNOWN

xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16151

UNKNOWN

Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.

Published Jun 07, 2018

CVE-2017-16071

UNKNOWN

nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16196

UNKNOWN

quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16170

UNKNOWN

liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16106

UNKNOWN

tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16204

UNKNOWN

The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

Published Jun 07, 2018

CVE-2017-16108

UNKNOWN

gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16080

UNKNOWN

nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16068

UNKNOWN

ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16090

UNKNOWN

fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16192

UNKNOWN

getcityapi.yoehoehne is a web server. getcityapi.yoehoehne is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16160

UNKNOWN

11xiaoli is a simple file server. 11xiaoli is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16102

UNKNOWN

serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16059

UNKNOWN

mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16073

UNKNOWN

noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16085

UNKNOWN

tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2018-3739

UNKNOWN

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).

Published Jun 07, 2018

CVE-2018-3713

UNKNOWN

angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2018-3724

UNKNOWN

general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2017-16097

UNKNOWN

tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16157

UNKNOWN

censorify.tanisjr is a simple web server and API RESTful service. censorify.tanisjr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2018-3715

UNKNOWN

glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2018-3732

UNKNOWN

resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths with certain special characters, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2018-3720

UNKNOWN

assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Published Jun 07, 2018

CVE-2018-3725

UNKNOWN

hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2018-3711

UNKNOWN

Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.

Published Jun 07, 2018

CVE-2018-3714

UNKNOWN

node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2017-16168

UNKNOWN

wffserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2018-3721

UNKNOWN

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Published Jun 07, 2018

CVE-2018-3729

UNKNOWN

localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2018-3722

UNKNOWN

merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Published Jun 07, 2018

CVE-2017-16149

UNKNOWN

zwserver is a weather web server. zwserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16163

UNKNOWN

dylmomo is a simple file server. dylmomo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16169

UNKNOWN

looppake is a simple http server. looppake is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018