| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-16093 | Hig | 0.49 | 7.5 | 0.02 | Jun 7, 2018 | cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | ||
| CVE-2017-16092 | — | Hig | 0.49 | 7.5 | 0.02 | Jun 7, 2018 | Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL. | |
| CVE-2017-16091 | — | Hig | 0.49 | 7.5 | 0.02 | Jun 7, 2018 | xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL. | |
| CVE-2017-16090 | Hig | 0.49 | 7.5 | 0.02 | Jun 7, 2018 | fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | ||
| CVE-2017-16089 | Hig | 0.49 | 7.5 | 0.02 | Jun 7, 2018 | serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL. | ||
| CVE-2017-16086 | Hig | 0.52 | 7.5 | 0.09 | Jun 7, 2018 | ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header. | ||
| CVE-2017-16085 | — | Hig | 0.49 | 7.5 | 0.02 | Jun 7, 2018 | tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL. | |
| CVE-2017-16084 | — | Hig | 0.49 | 7.5 | 0.02 | Jun 7, 2018 | list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| CVE-2017-16083 | — | Hig | 0.42 | 7.5 | 0.02 | Jun 7, 2018 | node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL. | |
| CVE-2017-16081 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16080 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16079 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16078 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16077 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16076 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16075 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16074 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16073 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16072 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16071 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16070 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16069 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16068 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16067 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16066 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16065 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16064 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16063 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16060 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16059 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16058 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| CVE-2017-16057 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2017-16056 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2018 | mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | ||
| CVE-2018-5850 | — | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2018 | In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel. | |
| CVE-2018-5846 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2018 | A Use After Free condition can occur in the IPA driver whenever the IPA IOCTLs IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_ADD/IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_DEL/IPA_IOC_NOTIFY_WAN_EMBMS_CONNECTED are called in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD… | ||
| CVE-2018-5845 | Hig | 0.46 | 7.0 | 0.00 | Jun 6, 2018 | A race condition in drm_atomic_nonblocking_commit() in the display driver can potentially lead to a Use After Free scenario in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel. | ||
| CVE-2018-5841 | — | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2018 | dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could lead to an invalid access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel. | |
| CVE-2018-5840 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2018 | Buffer Copy without Checking Size of Input can occur during the DRM SDE driver initialization sequence in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel. | ||
| CVE-2018-3852 | Hig | 0.49 | 7.5 | 0.02 | Jun 6, 2018 | An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A specially crafted TCP packet can cause a process to terminate resulting in denial of service. An attacker can send a crafted TCP packet to trigger this… | ||
| CVE-2018-3580 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2018 | Stack-based buffer overflow can occur In the WLAN driver if the pmkid_count value is larger than the PMKIDCache size in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel. | ||
| CVE-2018-3578 | — | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2018 | Type mismatch for ie_len can cause the WLAN driver to allocate less memory on the heap due to implicit casting leading to a heap buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel. | |
| CVE-2018-3565 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2018 | While sending a probe request indication in lim_send_sme_probe_req_ind() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overflow can occur. | ||
| CVE-2017-18154 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2018 | A crafted binder request can cause an arbitrary unmap in MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel. | ||
| CVE-2018-1265 | Hig | 0.47 | 7.2 | 0.02 | Jun 6, 2018 | Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps… | ||
| CVE-2017-7906 | Hig | 0.57 | 8.8 | 0.01 | Jun 6, 2018 | In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user. | ||
| CVE-2018-1000203 | Hig | 0.49 | 7.5 | 0.01 | Jun 6, 2018 | Soar Labs Soar Coin version up to and including git commit 4a2aa71ee21014e2880a3f7aad11091ed6ad434f (latest release as of Sept 2017) contains an intentional backdoor vulnerability in the function zero_fee_transaction() that can result in theft of Soar Coins by the… | ||
| CVE-2018-1456 | Hig | 0.46 | 7.1 | 0.02 | Jun 6, 2018 | IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 140091. | ||
| CVE-2018-11813 | Hig | 0.49 | 7.5 | 0.03 | Jun 6, 2018 | libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF. | ||
| CVE-2018-7884 | Hig | 0.51 | 7.8 | 0.01 | Jun 5, 2018 | An issue was discovered in DisplayLink Core Software Cleaner Application 8.2.1956. When the drivers are updated to a newer version, the product launches a process as SYSTEM to uninstall the old version: cl_1956.exe is run as SYSTEM on the %systemroot%\Temp folder, where any user… | ||
| CVE-2018-10058 | Hig | 0.58 | 8.8 | 0.04 | Jun 5, 2018 | The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers. |
- risk 0.49cvss 7.5epss 0.02
cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- risk 0.49cvss 7.5epss 0.02
Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- risk 0.49cvss 7.5epss 0.02
xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- risk 0.49cvss 7.5epss 0.02
fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- risk 0.49cvss 7.5epss 0.02
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- risk 0.52cvss 7.5epss 0.09
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
- risk 0.49cvss 7.5epss 0.02
tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- risk 0.49cvss 7.5epss 0.02
list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
- risk 0.42cvss 7.5epss 0.02
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
- risk 0.49cvss 7.5epss 0.01
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.49cvss 7.5epss 0.01
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- risk 0.51cvss 7.8epss 0.00
In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- risk 0.51cvss 7.8epss 0.00
A Use After Free condition can occur in the IPA driver whenever the IPA IOCTLs IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_ADD/IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_DEL/IPA_IOC_NOTIFY_WAN_EMBMS_CONNECTED are called in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD…
- risk 0.46cvss 7.0epss 0.00
A race condition in drm_atomic_nonblocking_commit() in the display driver can potentially lead to a Use After Free scenario in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- risk 0.51cvss 7.8epss 0.00
dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could lead to an invalid access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- risk 0.51cvss 7.8epss 0.00
Buffer Copy without Checking Size of Input can occur during the DRM SDE driver initialization sequence in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- risk 0.49cvss 7.5epss 0.02
An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A specially crafted TCP packet can cause a process to terminate resulting in denial of service. An attacker can send a crafted TCP packet to trigger this…
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow can occur In the WLAN driver if the pmkid_count value is larger than the PMKIDCache size in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- risk 0.51cvss 7.8epss 0.00
Type mismatch for ie_len can cause the WLAN driver to allocate less memory on the heap due to implicit casting leading to a heap buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- risk 0.51cvss 7.8epss 0.00
While sending a probe request indication in lim_send_sme_probe_req_ind() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overflow can occur.
- risk 0.51cvss 7.8epss 0.00
A crafted binder request can cause an arbitrary unmap in MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- risk 0.47cvss 7.2epss 0.02
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps…
- risk 0.57cvss 8.8epss 0.01
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.
- risk 0.49cvss 7.5epss 0.01
Soar Labs Soar Coin version up to and including git commit 4a2aa71ee21014e2880a3f7aad11091ed6ad434f (latest release as of Sept 2017) contains an intentional backdoor vulnerability in the function zero_fee_transaction() that can result in theft of Soar Coins by the…
- risk 0.46cvss 7.1epss 0.02
IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 140091.
- risk 0.49cvss 7.5epss 0.03
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in DisplayLink Core Software Cleaner Application 8.2.1956. When the drivers are updated to a newer version, the product launches a process as SYSTEM to uninstall the old version: cl_1956.exe is run as SYSTEM on the %systemroot%\Temp folder, where any user…
- risk 0.58cvss 8.8epss 0.04
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.