CVE-2016-10680
Status: ModifiedHigh (8.1)—
adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP, which leaves it vulnerable to MITM attacks. This impacts the integrity and availability of this geoip data that may alter the decisions made by an application using this data.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 8.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.72%
- Percentile among all scored CVEs: 52
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-311
- CWE-310
References
Raw JSON (NVD)
Show
{
"id": "CVE-2016-10680",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "support@hackerone.com",
"affectedData": [
{
"vendor": "HackerOne",
"product": "adamvr-geoip-lite node module",
"versions": [
{
"status": "affected",
"version": "All versions"
}
]
}
]
}
],
"published": "2018-05-29T20:29:01.970",
"references": [
{
"url": "https://nodesecurity.io/advisories/283",
"tags": [
"Third Party Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://nodesecurity.io/advisories/283",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "support@hackerone.com",
"description": [
{
"lang": "en",
"value": "CWE-311"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP, which leaves it vulnerable to MITM attacks. This impacts the integrity and availability of this geoip data that may alter the decisions made by an application using this data."
},
{
"lang": "es",
"value": "adamvr-geoip-lite es una implementación ligera nativa de JavaScript de la API de GeoIP de MaxMind. adamvr-geoip-lite descarga recursos geoip por HTTP, lo que lo deja vulnerable a ataques MITM. Esto impacta en la integridad y disponibilidad de los datos geoip que podrían alterar las decisiones hechas por una aplicación que emplea dichos datos."
}
],
"lastModified": "2026-06-17T00:40:09.227",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adamvr-geoip-lite_project:adamvr-geoip-lite:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "008663B1-DB72-44A6-9B89-75D44622AAA4",
"versionEndIncluding": "1.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "support@hackerone.com"
}