Total
7102 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-16045 | 1 Jquery.js Project | 1 Jquery.js | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16081 | 1 Cross-env.js Project | 1 Cross-env.js | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16060 | 1 Babelcli Project | 1 Babelcli | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16051 | 1 Sqliter Project | 1 Sqliter | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16070 | 1 Nodecaffe Project | 1 Nodecaffe | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16076 | 1 Proxy.js Project | 1 Proxy.js | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16225 | 1 Aegir Project | 1 Aegir | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (that performed a aegir-release) GitHub token. | |||||
CVE-2017-16204 | 1 Jquey Project | 1 Jquey | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. | |||||
CVE-2017-16047 | 1 Mysqljs Project | 1 Mysqljs | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16024 | 2 Nodejs, Sync-exec Project | 2 Node.js, Sync-exec | 2019-10-09 | 4.0 MEDIUM | 6.5 MEDIUM |
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists. | |||||
CVE-2017-16055 | 1 Sqlserver Project | 1 Sqlserver | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16054 | 1 Nodefabric Project | 1 Nodefabric | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16080 | 1 Nodesass Project | 1 Nodesass | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-14821 | 1 Foxitsoftware | 1 Foxit Reader | 2019-10-09 | 4.3 MEDIUM | 6.5 MEDIUM |
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the xTsiz member of SIZ markers. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5013. | |||||
CVE-2017-16048 | 1 Node-sqlite Project | 1 Node-sqlite | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-14820 | 1 Foxitsoftware | 1 Foxit Reader | 2019-10-09 | 4.3 MEDIUM | 6.5 MEDIUM |
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the tile index of the SOT marker in JPEG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5012. | |||||
CVE-2017-14818 | 1 Foxitsoftware | 1 Foxit Reader | 2019-10-09 | 4.3 MEDIUM | 6.5 MEDIUM |
This vulnerability allows remote attackers to disclose sensitive on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4982. | |||||
CVE-2017-16059 | 1 Mssql-node Project | 1 Mssql-node | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16079 | 1 Smb Project | 1 Smb | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |||||
CVE-2017-16062 | 1 Node-tkinter Project | 1 Node-tkinter | 2019-10-09 | 5.0 MEDIUM | 7.5 HIGH |
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |