Loading HuntDB...

Vulnerabilities

CVE-2018-3737

UNKNOWN

sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.

Published Jun 07, 2018

CVE-2018-3739

UNKNOWN

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).

Published Jun 07, 2018

CVE-2017-16189

UNKNOWN

sly07 is an API for censoring text. sly07 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2018-3713

UNKNOWN

angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2018-3724

UNKNOWN

general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2017-16118

UNKNOWN

The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression denial of service when it's passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.

Published Jun 07, 2018

CVE-2017-16162

UNKNOWN

22lixian is a simple file server. 22lixian is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16186

UNKNOWN

360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16148

UNKNOWN

serve46 is a static file server. serve46 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2018-3722

UNKNOWN

merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Published Jun 07, 2018

CVE-2017-16081

UNKNOWN

cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16154

UNKNOWN

earlybird is a web server module for early development. earlybird is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16116

UNKNOWN

The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods.

Published Jun 07, 2018

CVE-2017-16058

UNKNOWN

gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16152

UNKNOWN

static-html-server is a static file server. static-html-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16150

UNKNOWN

wanggoujing123 is a simple webserver. wanggoujing123 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16096

UNKNOWN

serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16161

UNKNOWN

shenliru is a simple file server. shenliru is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16105

UNKNOWN

serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16200

UNKNOWN

uv-tj-demo is a static file server. uv-tj-demo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16219

UNKNOWN

yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16140

UNKNOWN

lab6.brit95 is a file server. lab6.brit95 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16226

UNKNOWN

The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.

Published Jun 07, 2018

CVE-2017-16182

UNKNOWN

serverxxx is a static file server. serverxxx is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2018-3719

UNKNOWN

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Published Jun 07, 2018

CVE-2017-16145

UNKNOWN

sspa is a server dedicated to single-page apps. sspa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16111

UNKNOWN

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.

Published Jun 07, 2018

CVE-2017-16102

UNKNOWN

serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16059

UNKNOWN

mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16073

UNKNOWN

noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16104

UNKNOWN

citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16164

UNKNOWN

desafio is a simple web server. desafio is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url, but is limited to accessing only .html files.

Published Jun 07, 2018

CVE-2017-16085

UNKNOWN

tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 07, 2018

CVE-2017-16097

UNKNOWN

tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16157

UNKNOWN

censorify.tanisjr is a simple web server and API RESTful service. censorify.tanisjr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16168

UNKNOWN

wffserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2018-3729

UNKNOWN

localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.

Published Jun 07, 2018

CVE-2017-16149

UNKNOWN

zwserver is a weather web server. zwserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16094

UNKNOWN

iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16139

UNKNOWN

jikes is a file server. jikes is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Accessible files are restricted to files with .htm and .js extensions.

Published Jun 07, 2018

CVE-2017-16218

UNKNOWN

dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16063

UNKNOWN

node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2017-16067

UNKNOWN

node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Published Jun 07, 2018

CVE-2018-3718

UNKNOWN

serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.

Published Jun 07, 2018

CVE-2017-16185

UNKNOWN

uekw1511server is a static file server. uekw1511server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16109

UNKNOWN

easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file such as /etc/passwd returns a "not supported" error.

Published Jun 07, 2018

CVE-2018-3726

UNKNOWN

crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.

Published Jun 07, 2018

CVE-2017-16086

UNKNOWN

ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.

Published Jun 07, 2018

CVE-2017-16121

UNKNOWN

datachannel-client is a signaling implementation for DataChannel.js. datachannel-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 07, 2018

CVE-2017-16114

UNKNOWN

The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can block for around 6 seconds.

Published Jun 07, 2018