Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1348▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

215 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)8.1%—Nodejs Node.jsRedhat Openshift Container Platform21/8/201817/6/2026
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second-to-last position…
ModificadaAlta (7.5)7.1%—Nodejs Node.js13/6/201817/6/2026
Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x…
ModificadaAlta (7.5)6.4%—Nodejs Node.js13/6/201817/6/2026
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of…
ModificadaAlta (7.5)6.9%—Nodejs Node.js13/6/201817/6/2026
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This…
ModificadaAlta (7.5)7.8%—Nodejs Node.js13/6/201817/6/2026
All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used…
ModificadaAlta (7.5)49%—OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js12/6/201817/6/2026
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited…
ModificadaMedia (6.5)2.6%—Sync-exec Project Sync-execNodejs Node.js4/6/201817/6/2026
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the…
ModificadaAlta (8.8)9.9%—Nodejs Node.js17/5/201817/6/2026
The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or another computer with network access to the computer running the Node.js process. A…
ModificadaMedia (5.3)3.6%—Nodejs Node.js17/5/201817/6/2026
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into…
ModificadaAlta (7.5)3.4%—Nodejs Node.js17/5/201817/6/2026
The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector. The code in question was replaced in Node.js 6.x and later so this vulnerability only impacts all versions of Node.js 4.x. The regular expression, `splitPathRe`, used within the `'path'` module…
ModificadaAlta (7.5)11%—Nghttp2Nodejs Node.jsDebian Linux8/5/201817/6/2026
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
ModificadaBaja (3.1)2.3%—Nodejs Node.js11/12/201717/6/2026
Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to…
ModificadaCrítica (9.1)2.4%—Nodejs Node.js11/12/201717/6/2026
Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.
ModificadaMedia (5.9)13%—OpensslDebian LinuxNodejs Node.js7/12/201717/6/2026
There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are…
ModificadaAlta (7.5)8.3%—Nodejs Node.js30/10/201714/7/2026
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
ModificadaAlta (7.5)34%—Nodejs Node.js23/10/201717/6/2026
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
ModificadaAlta (7.5)8.0%—Nodejs Node.js10/10/201717/6/2026
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
ModificadaAlta (7.5)54%—Nodejs Node.js28/9/201717/6/2026
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
ModificadaMedia (6.5)5.0%—Nodejs Node.jsUronode URO NodeDebian Linux20/9/201717/6/2026
node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
ModificadaAlta (7.5)5.4%—Nodejs Node.js25/7/201717/6/2026
Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default…
ModificadaAlta (7.5)3.3%—C-aresC-ares Project C-aresNodejs Node.js7/7/201717/6/2026
The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.
ModificadaCrítica (9.8)5.8%—ZlibOpensuse LeapOpensuseDebian Linux+2023/5/201717/6/2026
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
ModificadaAlta (8.8)5.2%—ZlibOpensuse LeapOpensuseDebian Linux+1523/5/201714/7/2026
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
ModificadaCrítica (9.8)7.5%—ZlibOpensuse LeapOpensuseDebian Linux+3523/5/201714/7/2026
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
ModificadaAlta (8.8)4.8%—BoostZlibOpensuse LeapOpensuse+1623/5/201714/7/2026
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.