Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 407 respecto a la semana anterior
Críticas / altas1311▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 2.4% | — | Nodejs Node.js | 11/12/2017 | 17/6/2026 | Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption. | |
| Modificada | Media (5.9) | 13% | — | OpensslDebian LinuxNodejs Node.js | 7/12/2017 | 17/6/2026 | There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are… | |
| Modificada | Alta (7.5) | 8.3% | — | Nodejs Node.js | 30/10/2017 | 14/7/2026 | Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter. | |
| Modificada | Alta (7.5) | 34% | — | Nodejs Node.js | 23/10/2017 | 17/6/2026 | Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path. | |
| Modificada | Alta (7.5) | 8.0% | — | Nodejs Node.js | 10/10/2017 | 17/6/2026 | Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service. | |
| Modificada | Alta (7.5) | 54% | — | Nodejs Node.js | 28/9/2017 | 17/6/2026 | Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules. | |
| Modificada | Media (6.5) | 5.0% | — | Nodejs Node.jsUronode URO NodeDebian Linux | 20/9/2017 | 17/6/2026 | node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption). | |
| Modificada | Alta (7.5) | 5.4% | — | Nodejs Node.js | 25/7/2017 | 17/6/2026 | Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default… | |
| Modificada | Alta (7.5) | 3.3% | — | C-aresC-ares Project C-aresNodejs Node.js | 7/7/2017 | 17/6/2026 | The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way. | |
| Modificada | Crítica (9.8) | 5.8% | — | ZlibOpensuse LeapOpensuseDebian Linux+20 | 23/5/2017 | 17/6/2026 | The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation. | |
| Modificada | Alta (8.8) | 5.2% | — | ZlibOpensuse LeapOpensuseDebian Linux+15 | 23/5/2017 | 14/7/2026 | The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers. | |
| Modificada | Crítica (9.8) | 7.5% | — | ZlibOpensuse LeapOpensuseDebian Linux+35 | 23/5/2017 | 14/7/2026 | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | |
| Modificada | Alta (8.8) | 4.8% | — | BoostZlibOpensuse LeapOpensuse+16 | 23/5/2017 | 14/7/2026 | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | |
| Modificada | Crítica (9.8) | 2.5% | — | Keycloak-nodejs-auth-utils | 12/5/2017 | 17/6/2026 | It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks. | |
| Modificada | Media (5.9) | 14% | — | OpensslNodejs Node.js | 4/5/2017 | 17/6/2026 | There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine… | |
| Modificada | Media (5.9) | 15% | — | OpensslNodejs Node.js | 4/5/2017 | 17/6/2026 | There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks… | |
| Modificada | Alta (7.5) | 57% | — | OpensslNodejs Node.js | 4/5/2017 | 17/6/2026 | If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to… | |
| Modificada | Alta (7.5) | 4.9% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive. | |
| Modificada | Alta (7.5) | 6.7% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)." | |
| Modificada | Media (6.1) | 2.6% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters. | |
| Modificada | Media (6.1) | 1.9% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings. | |
| Modificada | Media (6.1) | 1.9% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing. | |
| Modificada | Media (6.1) | 2.0% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI. | |
| Modificada | Media (6.1) | 1.9% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag. | |
| Modificada | Media (5.9) | 2.8% | — | Nodejs Node.jsSuse Linux Enterprise | 10/10/2016 | 17/6/2026 | The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate. |